Breathe HR
Last Reviewed: 27 Jul 2026
At a Glance
Breathe's EULA reserves the right to anonymise and aggregate Client Data for its own product development, marketing, and benchmarking purposes, beyond processing on the Client's instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.
Company & Product Details
HQ
United Kingdom
Products
HR & People Management Software
Product description
Cloud-based HR management platform for employee records, absence, rota, and performance management.
What data is being processed?
Account Data (contact and billing information, for which Breathe is controller) and Client Data (employee data and other data submitted by the Client/Users, for which Breathe is processor)
Document Details
Date of DPA
01 Sept 2024
Additional date information
The data processing terms (clause 4 of the EULA) do not state an explicit effective date within the document text; the date is inferred from the document filename ("September 2024") published on Breathe's website. No exact day is specified.
What jurisdictions are covered?
Data Protection Legislation is defined to include UK GDPR, the Data Protection Act 2018, and PECR 2003; the EEA is referenced for Account Data transfer conditions and Client Data storage restrictions; governing law and jurisdiction are England and Wales (clauses 1, 4.4, 4.6, 27.1).
Is the DPA incorporated into service or customer agreements?
Link
https://www.breathehr.com/hubfs/Breathe_EULA_September%202024.pdf
Location & Transfers
Where is data held or processed?
EEA Breathe will not transfer Personal Data within Client Data outside the EEA (clause 4.6). Account Data (billing/contact information, for which Breathe is itself the controller) may be processed outside the EEA provided adequate protection is maintained (clause 4.4).
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Measures include pseudonymising and encrypting Personal Data, ensuring confidentiality, integrity, availability and resilience of systems, ability to restore availability and access after an incident, and regularly assessing the effectiveness of measures adopted (clause 4.5.II).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Breathe must notify the Client without undue delay upon becoming aware of a Personal Data breach; no specific time limit (e.g. a number of hours) is stated (clause 4.5.V).
What happens to the data on termination?
On anticipated termination, Breathe will return or delete Personal Data unless required by law to retain it (clause 4.5.VI). On actual termination, the Client can download Client Data beforehand; termination itself is treated as an instruction for Breathe to securely delete the data, and Breathe disclaims liability for data lost as a result. Data may be retained where legally required, with notice to the Client where possible (clauses 16.1–16.3).