Skip to content

Keruja Data Processing Addendum

Version 2.0 · Effective date: 13 August 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between a Customer and WEMOVEON LTD, trading as Keruja, where Keruja processes Customer Personal Data on behalf of that Customer. It supplements the Keruja Business Terms of Service.

1. Parties and scope

The parties are:

WEMOVEON LTD, company number 10061558, registered office at 61 Bridge Street, Kington, United Kingdom, HR5 3DJ, trading as Keruja (“Keruja”, “Processor”, “we”, “us” or “our”); and

the Customer using Keruja under the applicable Customer agreement, Order, subscription or other commercial arrangement (“Customer” or “Controller”).

This DPA applies only to processing where Keruja acts as Processor of Customer Personal Data on behalf of the Customer.

Keruja may separately act as an independent Controller for limited activities undertaken for its own purposes, including customer relationship administration, billing and accounting, security and fraud prevention, website and demo enquiries, legal compliance, contractual records and establishing, exercising or defending legal claims. Those activities are governed by the Keruja Privacy Notice rather than this DPA.

2. Definitions

In this DPA:

“Customer Personal Data” means Personal Data processed by Keruja on behalf of the Customer in connection with the Service.

“Data Protection Laws” means applicable United Kingdom laws governing Personal Data, including the UK GDPR, the Data Protection Act 2018 and other applicable UK data-protection legislation in force from time to time.

“Service” means the Keruja software-as-a-service platform and functionality made available under the Customer’s applicable agreement.

“Sub-processor” means another Processor engaged by Keruja to process Customer Personal Data on behalf of the Customer.

“Controller”, “Processor”, “Personal Data”, “Data Subject”, “Personal Data Breach”, “Processing” and related data-protection expressions have the meanings given by applicable Data Protection Laws.

3. Relationship with other terms

This DPA supplements the Customer’s applicable agreement with Keruja.

If there is a conflict concerning processing of Customer Personal Data, this DPA takes precedence over general terms to the extent of that conflict, unless a later signed agreement between the parties expressly states otherwise and remains compliant with applicable Data Protection Laws.

Nothing in this DPA reduces an obligation imposed directly on either party by applicable Data Protection Laws.

4. Roles of the parties

For Customer Personal Data processed through Keruja for the Customer’s purposes:

  • the Customer normally acts as Controller; and
  • WEMOVEON LTD normally acts as Processor.

The Customer determines the purposes of the relevant processing and is responsible for the lawfulness of its instructions.

Keruja processes Customer Personal Data only to provide, secure, maintain and support the Service and to carry out the Customer’s documented instructions, except where applicable law requires otherwise.

5. Processing details

The processing governed by this DPA is described in Schedule 1 — Processing Details.

The parties acknowledge that the exact categories of Customer Personal Data processed depend on the Keruja functionality selected and used by the Customer.

6. Documented instructions

Keruja will process Customer Personal Data only:

  1. on documented instructions from the Customer;
  2. as reasonably necessary to provide, secure, maintain and support the contracted Service in accordance with those instructions; or
  3. where applicable law requires the processing.

Documented instructions may be contained in the Customer agreement, this DPA, the Customer’s configuration and use of Keruja, support requests, written communications and other instructions capable of being retained as a record.

If applicable law requires Keruja to process Customer Personal Data other than on the Customer’s instructions, Keruja will inform the Customer before the processing unless the law prohibits that information from being given.

If Keruja reasonably believes that an instruction infringes applicable Data Protection Laws, Keruja may inform the Customer and suspend the affected processing while the parties address the issue.

7. Customer obligations and rights

The Customer is responsible for:

  • ensuring it has an appropriate lawful basis for its processing;
  • providing required privacy information to Data Subjects;
  • ensuring its instructions to Keruja are lawful;
  • determining appropriate retention periods for its purposes;
  • data minimisation;
  • deciding whether higher-risk or special-category processing is appropriate;
  • identifying any required additional legal conditions;
  • responding to Data Subjects as Controller;
  • ensuring that it is entitled to collect, upload and otherwise process Customer Personal Data through Keruja; and
  • configuring and using the Service appropriately for its purposes.

The Customer retains the rights and responsibilities of a Controller under applicable Data Protection Laws.

8. Confidentiality of personnel

Keruja will take reasonable steps to ensure that persons authorised to process Customer Personal Data:

  • are subject to an appropriate duty of confidentiality; and
  • access Customer Personal Data only where reasonably necessary for their functions.

9. Security of processing

Keruja will maintain technical and organisational measures reasonably appropriate to the relevant risks, taking into account the nature, scope, context and purposes of processing, available technology, implementation costs and risks to individuals.

Categories of measures are described in Schedule 2 — Technical and Organisational Measures.

Keruja does not promise that no security incident can ever occur. The obligation is to maintain appropriate measures and comply with applicable legal requirements, not to guarantee absolute immunity from all cyber threats.

10. Sub-processors

The Customer gives Keruja general written authorisation to appoint Sub-processors reasonably necessary to provide, secure, support or maintain the Service.

Keruja will:

  • select Sub-processors with regard to the nature of the processing and relevant risks;
  • impose written data-protection obligations on Sub-processors which provide an equivalent level of protection for Customer Personal Data as required by applicable Article 28 obligations;
  • remain responsible to the Customer for performance of the relevant Processor obligations by its Sub-processors to the extent required by applicable law; and
  • provide reasonable prior notice of any intended addition or replacement of a Sub-processor that will process Customer Personal Data, giving the Customer a reasonable opportunity to object on legitimate data-protection grounds before the change takes effect where reasonably practicable.

The Customer may raise a reasonable and evidence-based objection to a new Sub-processor on legitimate data-protection grounds.

The parties will seek in good faith to resolve a legitimate objection. If no reasonable solution can be found, Keruja may stop the affected processing or either party may exercise applicable termination rights where necessary.

11. Principal technology providers

Depending on the functionality used, Keruja’s technology architecture may use providers including:

  • Vercel — web application hosting and delivery;
  • Railway — API and supporting application infrastructure;
  • Neon — managed PostgreSQL database infrastructure;
  • Cloudflare — DNS, security and object/file-storage infrastructure;
  • Resend — transactional email delivery; and
  • Stripe — payment and subscription-processing services where used.

Not every provider processes every category of Customer Personal Data, and the legal role of a provider may vary according to the service supplied.

Optional integrations selected by the Customer may require additional providers.

Keruja may replace or add providers as its architecture develops, subject to the obligations in this DPA.

12. AI providers and AI-enabled processing

AI functionality is not automatically included in every Keruja subscription.

This DPA does not by itself authorise Keruja to submit Customer Personal Data to an external generative-AI provider for Customer-facing AI functionality where the relevant AI functionality has not been enabled or commercially agreed.

Where external AI processing of Customer Personal Data is proposed, Keruja will undertake appropriate commercial, security, privacy and data-processing review before enabling the relevant Customer functionality, and any required additional terms or Sub-processor arrangements will apply.

Rules-based or deterministic functionality that does not involve an external AI provider should not be described as sending Customer Personal Data to an AI provider merely because it provides automated assistance.

13. International transfers

Where Keruja initiates a restricted international transfer of Customer Personal Data, Keruja will use an appropriate lawful transfer mechanism or other lawful basis required by applicable UK Data Protection Laws.

Depending on the circumstances, this may include an applicable UK adequacy regulation, the UK International Data Transfer Agreement, an approved UK Addendum to Standard Contractual Clauses, or another mechanism permitted by law.

The appropriate mechanism depends on the provider, destination and processing involved.

Keruja does not promise that all Customer Personal Data will remain in one country unless that has been expressly agreed in writing for the relevant Customer arrangement.

14. Data-subject rights

Taking into account the nature of processing, Keruja will provide reasonable assistance through appropriate technical and organisational measures to help the Customer respond to requests from Data Subjects to exercise applicable rights.

Such rights may include access, rectification, erasure, restriction, portability, objection and rights relating to certain automated decision-making.

Where Keruja receives a request directly from a Data Subject concerning Customer Personal Data for which the Customer is Controller, Keruja may direct the individual to the Customer unless applicable law requires otherwise.

The Customer remains responsible for determining and communicating the substantive response as Controller.

15. Personal Data Breaches

Keruja will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data where notification is required under applicable Data Protection Laws or this DPA.

Keruja will provide reasonably available information concerning:

  • the nature of the breach;
  • affected Personal Data and Data Subjects where reasonably known;
  • likely consequences where reasonably known;
  • mitigation undertaken or proposed; and
  • relevant contact information.

Information may be provided in phases where it is not immediately available.

Notification of an incident does not itself constitute an admission of legal liability.

Keruja may take urgent containment, security or recovery action before full information is available where reasonably necessary to protect systems or Personal Data.

16. Assistance to the Customer

Taking into account the nature of processing and information reasonably available to Keruja, Keruja will provide reasonable assistance to the Customer in relation to applicable obligations concerning:

  • security of processing;
  • assessment of Personal Data Breaches;
  • regulatory notification where required;
  • notification to affected Data Subjects where required;
  • data-protection impact assessments; and
  • prior consultation with the Information Commissioner’s Office or another competent regulator where legally required.

17. Return and deletion at the end of processing

At the end of the relevant processing services, and subject to applicable law, Keruja will, at the Customer’s choice, return or delete Customer Personal Data and will delete existing copies unless applicable law requires continued storage.

The Customer may communicate its choice through a written request or another documented instruction reasonably available through the Service or Customer relationship.

Where return is requested, Keruja will use a reasonably available and technically feasible format.

Where deletion is requested, or following return where deletion is required, Keruja will delete or irreversibly anonymise Customer Personal Data through applicable active-system and retention processes unless applicable law requires continued retention.

Customer Personal Data may temporarily remain within protected backup, recovery, security or disaster-recovery systems until removed through the ordinary lifecycle of those systems.

Information retained solely within such systems will remain subject to appropriate protection and will not be returned to ordinary active use except where legitimately required for recovery, security, legal compliance or another lawful purpose.

Keruja does not promise a universal fixed 90-day deletion period, fixed backup-deletion period, fixed backup frequency, fixed recovery-point objective or fixed recovery-time objective unless separately agreed in writing and technically supported.

Nothing in this clause permits Keruja to retain Customer Personal Data indefinitely without a lawful purpose.

18. Compliance information, audits and inspections

Keruja will make available information reasonably necessary to demonstrate compliance with applicable Processor obligations.

Where reasonable, compliance should initially be demonstrated through proportionate methods such as documentation, security information, questionnaires, policies or remote review.

Where an audit or inspection is reasonably required under applicable Data Protection Laws:

  • the Customer should ordinarily provide reasonable advance notice unless an urgent incident or regulator requires otherwise;
  • the audit should normally take place during business hours;
  • it must not unnecessarily compromise another customer’s confidentiality, Personal Data, Keruja security or unrelated proprietary information; and
  • it must not unreasonably disrupt the Service.

Where a less intrusive method can adequately demonstrate compliance, the parties should use that method first.

Nothing in this clause removes an audit or inspection right which applicable Data Protection Laws require.

19. Records and regulatory cooperation

Each party will maintain records required of it by applicable Data Protection Laws.

Keruja will cooperate reasonably with a competent supervisory authority in relation to processing covered by this DPA where required by law.

20. Security incidents and urgent protective action

Where Keruja reasonably believes that a Cyber Incident threatens Customer Personal Data, Keruja may take proportionate protective action including restricting access, revoking sessions, blocking suspicious requests, restricting or quarantining files, disabling affected integrations, isolating functionality or carrying out emergency maintenance.

Urgent protective action may be taken without advance notice where reasonably necessary to protect Personal Data, the Service or other users.

Where the event constitutes a Personal Data Breach, clause 15 applies.

21. Liability

The liability provisions in the applicable Customer agreement or Keruja Business Terms of Service apply to this DPA except to the extent that applicable law requires otherwise.

Where the public Business Terms apply and no signed agreement specifies a different lawful contractual cap, Keruja’s aggregate contractual liability to the Customer arising specifically from breach of this DPA is subject to the DPA contractual cap stated in those Terms.

Nothing in this DPA limits:

  • a Data Subject’s rights under applicable law;
  • a regulator’s statutory powers;
  • a liability which applicable law does not permit the parties to limit; or
  • either party’s direct statutory obligations under applicable Data Protection Laws.

22. Changes to this DPA

Keruja may update this DPA where reasonably necessary to reflect changes in law, regulatory guidance, the Service, Sub-processors or processing operations.

We will update the version and effective date when this DPA changes.

Where a material change affects an existing Customer, Keruja will provide reasonable notice where appropriate.

A general website update does not automatically override a specifically negotiated and signed data-processing agreement where that signed agreement governs the same processing.

23. Contact

For privacy, data-protection and DPA matters:

WEMOVEON LTD trading as Keruja
Company number: 10061558
61 Bridge Street
Kington
United Kingdom
HR5 3DJ

contact@keruja.com

General business enquiries: contact@keruja.com


Schedule 1 — Processing Details

1. Subject matter

Provision and operation of the Keruja workforce and operational-management SaaS platform and associated hosting, storage, communications, security, support and recovery activities.

2. Duration

Processing takes place for the duration of the applicable Customer agreement and for a limited period afterwards where reasonably required for return, deletion, technical recovery processes, legal obligations, security, dispute resolution or legal claims.

3. Nature of processing

Processing may include collection, recording, organisation, structuring, storage, retrieval, consultation, transmission, use, modification at the Customer’s instruction, reporting, backup or recovery processing where applicable, restriction and deletion.

4. Purpose

Keruja may process Customer Personal Data as reasonably necessary to:

  • provide the Service;
  • operate Customer-selected functionality;
  • host and store Customer Data;
  • maintain and secure the Service;
  • provide support;
  • support resilience and recovery;
  • prevent fraud or abuse; and
  • fulfil the Customer’s documented instructions.

5. Categories of Data Subjects

Depending on functionality used, Data Subjects may include:

  • the Customer;
  • employees;
  • workers;
  • temporary workers;
  • agency workers;
  • freelancers;
  • contractors;
  • job applicants;
  • managers and supervisors;
  • Customer contacts;
  • the Customer’s clients or business contacts; and
  • other individuals whose Personal Data the Customer legitimately processes through Keruja.

6. Types of Personal Data

Depending on functionality used, Customer Personal Data may include:

  • names;
  • email addresses;
  • telephone numbers;
  • account and membership information;
  • business contact information;
  • employment or engagement information;
  • roles and skills;
  • availability;
  • recruitment and applicant information;
  • CVs;
  • job and shift information;
  • scheduling information;
  • attendance and working-time records;
  • training information;
  • contract and electronic-signature information;
  • compliance information;
  • uploaded documents;
  • communications;
  • expense information;
  • location information where a legitimately enabled function requires it;
  • photographs where a legitimately enabled function requires them;
  • technical and security metadata associated with use of the Service; and
  • other information the Customer legitimately chooses to process through Keruja.

7. Higher-risk information

Depending on Customer use, Customer Personal Data may include special-category Personal Data, criminal-offence information, identity documents, immigration and right-to-work information, or other particularly sensitive information.

The Customer remains responsible for determining that an appropriate lawful basis, additional condition and business need exist where required.


Schedule 2 — Technical and Organisational Measures

Keruja will maintain measures reasonably appropriate to the relevant risks. Specific technologies and controls may evolve as the Service develops, provided the overall approach remains appropriate.

1. Access control

Measures may include authenticated access, membership controls, role-based permissions, restricted administrative access, least-privilege principles, session controls, and organisation and tenant scoping.

2. Multi-tenant access boundaries

Keruja will maintain controls intended to prevent unauthorised access between customer organisations.

3. Transport security

Keruja will use appropriate encrypted transport for production web traffic and other sensitive communications where technically appropriate.

4. Storage and file access

Measures may include controlled cloud-storage access, organisation-scoped storage structures, signed or time-limited access mechanisms where appropriate, access restrictions, file validation and integrity-related controls where implemented.

5. Upload and malware controls

Depending on the relevant Keruja workflow and technical configuration, measures may include file-size restrictions, allowed file-type restrictions, restricted file handling, malware scanning, quarantine states, blocking access to files that have not passed applicable security controls, and security logging.

Keruja does not represent that every upload workflow uses identical malware controls.

No malware-detection technology can guarantee identification of every newly created or previously unknown threat.

6. Application security

Measures may include request and input validation, appropriate output handling, rate limiting, security headers, secret-management controls, automated testing, code review, dependency management, production-hardening measures and vulnerability remediation where reasonably appropriate.

7. Logging and monitoring

Keruja may maintain appropriate operational and security logs for investigation, troubleshooting, security monitoring, access auditing, incident response and contractual or audit records.

Keruja will seek to avoid unnecessary exposure of secrets or sensitive information in logs.

8. Resilience and recovery

Keruja will maintain reasonable resilience and recovery arrangements appropriate to the nature, scale and current maturity of the Service.

Any recovery mechanisms maintained by Keruja are intended to support service resilience. They are not a substitute for a Customer maintaining independent copies of business-critical records where appropriate.

Unless separately agreed, Keruja does not guarantee continuous real-time replication, that every recovery copy contains every recent change, that every record can always be restored, a particular recovery time, a particular recovery point, or a particular backup frequency or retention period.

9. Cyber Incident response

Keruja will maintain processes reasonably intended to support detection, investigation, containment, remediation, recovery and appropriate notification.

10. Provider management

Keruja will take reasonable steps to select appropriate infrastructure and technology providers and to establish appropriate contractual safeguards where required.

11. Secrets and credentials

Keruja will not knowingly expose production secrets or private security credentials through public source code or normal Customer interfaces.

12. Security development

Security measures may evolve as technology, threats and the Keruja platform develop. Keruja may replace individual controls where the resulting overall level of protection remains reasonably appropriate.


© 2026 WEMOVEON LTD. Keruja™ is a trade mark of WEMOVEON LTD.

Data Processing Addendum | Keruja