Breathe HR

Last Reviewed: 27 Jul 2026

Data Use Review

At a Glance

Breathe's EULA reserves the right to anonymise and aggregate Client Data for its own product development, marketing, and benchmarking purposes, beyond processing on the Client's instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

Company & Product Details

HQ

United Kingdom

Products

HR & People Management Software

Product description

Cloud-based HR management platform for employee records, absence, rota, and performance management.

What data is being processed?

Account Data (contact and billing information, for which Breathe is controller) and Client Data (employee data and other data submitted by the Client/Users, for which Breathe is processor)

Document Details

Date of DPA

01 Sept 2024

Additional date information

The data processing terms (clause 4 of the EULA) do not state an explicit effective date within the document text; the date is inferred from the document filename ("September 2024") published on Breathe's website. No exact day is specified.

What jurisdictions are covered?

Data Protection Legislation is defined to include UK GDPR, the Data Protection Act 2018, and PECR 2003; the EEA is referenced for Account Data transfer conditions and Client Data storage restrictions; governing law and jurisdiction are England and Wales (clauses 1, 4.4, 4.6, 27.1).

Is the DPA incorporated into service or customer agreements?

Yes
The data processing terms form clause 4 of the main EULA itself (not a separate addendum), and together with Breathe's processing policy comprise the entire agreement governing the Products and Services (clauses 4.1, 27.5).

Location & Transfers

Where is data held or processed?

EEA Breathe will not transfer Personal Data within Client Data outside the EEA (clause 4.6). Account Data (billing/contact information, for which Breathe is itself the controller) may be processed outside the EEA provided adequate protection is maintained (clause 4.4).

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

No
SCCs are not currently incorporated. Breathe reserves the right, on 30 days' notice, to revise this clause by adopting applicable controller-to-processor standard clauses or similar certification-scheme terms in future. Client Data transfers outside the EEA are prohibited outright, so no transfer mechanism is currently needed (clauses 4.6, 4.10).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Measures include pseudonymising and encrypting Personal Data, ensuring confidentiality, integrity, availability and resilience of systems, ability to restore availability and access after an incident, and regularly assessing the effectiveness of measures adopted (clause 4.5.II).

Non Processor Data Use

Does the company process data solely as a processor?

No
Clause 4.7 grants Breathe the right to anonymise Client Data (personal data provided in Breathe's capacity as processor) and aggregate it with other sources for Breathe's own product development, strategy, analytics, marketing, research and benchmarking purposes; once anonymised, Breathe treats this data as no longer being personal data processed on the Client's behalf. This is a use of Processor/Customer Data for Breathe's own purposes and warrants manual review (clause 4.7). Separately, for Account Data (billing/contact information), Breathe is itself the data controller (clause 4.3.I) — a normal User/Account Data arrangement that does not itself trigger this concern.

Subprocessing

General authorization

General
The Client consents in advance to Breathe appointing three defined classes of third-party processors: EEA-based IT/hosting/system administration providers, UK-based professional advisers (lawyers, bankers, auditors, insurers), and UK authorities/regulators such as HMRC. There is no ongoing notification or objection mechanism for new subprocessors within these classes (clause 4.8).

Do all the DPA terms flow down to sub-processors?

Yes
Breathe confirms it has entered, or will enter, into a written agreement incorporating terms substantially similar to this clause with any third-party processor accessing Client Data, and remains fully liable for their failure to meet those obligations as if it were Breathe's own (clause 4.9).

Is data only processed on the instruction of the controller?

Yes
Breathe will process Personal Data within Client Data only on the Client's written instructions; entering into the Agreement itself constitutes written instructions to process Client Data in order to operate and provide the Services (clause 4.5.I).

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Breathe will assist the Client, at the Client's cost, in responding to data subject requests and in meeting compliance obligations relating to security, breach notification, and impact assessments (clause 4.5.IV).

Does the contract include staff confidentiality clauses?

Yes
Breathe ensures all personnel with access to Personal Data are obliged to keep it confidential (clause 4.5.III), and Client Data may only be disclosed to employees, contractors and subcontractors who are legally bound to confidentiality (clause 18.1).

Are there audit rights for the data?

Yes
Breathe must maintain complete and accurate records and information demonstrating compliance, and allow for audits by the Client or the Client's designated auditor; no specific limits on frequency, notice period, or scope are stated in the DPA (clause 4.5.VII).

Is there assistance with DPIA requests?

Yes
Breathe agrees to assist the Client, at the Client's cost, with compliance obligations including impact assessments and consultations with supervisory authorities or regulators (clause 4.5.IV).

How much notice is provided for data breaches?

Breathe must notify the Client without undue delay upon becoming aware of a Personal Data breach; no specific time limit (e.g. a number of hours) is stated (clause 4.5.V).

What happens to the data on termination?

On anticipated termination, Breathe will return or delete Personal Data unless required by law to retain it (clause 4.5.VI). On actual termination, the Client can download Client Data beforehand; termination itself is treated as an instruction for Breathe to securely delete the data, and Breathe disclaims liability for data lost as a result. Data may be retained where legally required, with notice to the Client where possible (clauses 16.1–16.3).