Data Processing Agreement
Last updated: 8 September 2026
This Data Processing Agreement (“DPA”) applies where a customer organisation uses Awayly to process personal data for which that organisation is the controller and Michael Wood | Web & Automation processes that data on its behalf.
1. Roles
The customer is the controller and Michael Wood | Web & Automation is the processor for customer employee and absence data entered into Awayly, except where we independently act as controller for account administration, billing, security, support or legal obligations.
2. Subject matter and duration
Processing covers the hosting and operation of Awayly for the duration of the customer’s use of the service and any limited post-termination retention needed for security, recovery or legal obligations.
3. Nature and purpose
Processing may include collection, storage, organisation, retrieval, display, calculation, transmission, backup, support, restriction, deletion and other operations needed to provide holiday and absence management.
4. Data subjects
Data subjects may include customer owners, administrators, managers, employees, workers and other authorised users.
5. Personal data
Data may include names, business email addresses, roles, departments, working patterns, holiday allowances, absence dates and types, request notes, decision notes, approval history, account identifiers, audit information and technical logs.
6. Special-category information
Absence information can reveal health or other special-category information. Customers should minimise such data and only enter what is necessary. Awayly is not intended to store detailed medical records.
7. Instructions
We process customer data on documented instructions represented by this DPA, the Terms & Conditions, product settings and reasonable customer support instructions, unless law requires otherwise.
8. Confidentiality
People authorised to process customer data are required to respect confidentiality appropriate to their role.
9. Security
We use reasonable technical and organisational measures appropriate to the service, including HTTPS, access controls, password hashing, secure sessions, restricted administrative access, software maintenance, backups and security monitoring.
10. Sub-processors
The customer authorises the use of sub-processors reasonably required to operate Awayly, including providers for hosting/infrastructure, email delivery, security, backups and payments. We remain responsible for selecting providers appropriate to the service and will update our processing arrangements where material providers change.
11. International transfers
Where a provider processes personal data outside the UK, we will use providers and transfer safeguards intended to comply with applicable UK data-protection requirements.
12. Data-subject requests
Where reasonably possible, we will assist the customer with requests relating to data-subject rights, taking into account the nature of processing and the information available to us.
13. Personal-data breaches
We will notify affected customers without undue delay after becoming aware of a personal-data breach affecting customer data where notification is required and will provide reasonably available information to support the customer’s obligations.
14. DPIAs and regulator enquiries
We will provide reasonable information available to us to assist with data-protection impact assessments or regulator consultations where required by the customer’s use of Awayly.
15. Audit information
We will make reasonable information available to demonstrate compliance with processor obligations. Any audit request must be proportionate, protect other customers and confidential systems, and avoid unnecessary disruption.
16. Return and deletion
On termination, customer data may remain available for a limited period to support closure or recovery, after which it may be deleted or anonymised subject to backups, legal obligations and legitimate security records.
17. Customer responsibilities
The customer is responsible for lawful processing instructions, employee privacy information, lawful bases, permissions, account access, data accuracy and deciding what information is appropriate to enter into Awayly.
18. Priority
If this DPA conflicts with the general Terms & Conditions on matters specifically concerning processing of customer personal data, this DPA takes priority for those matters.
19. Governing law
This DPA is governed by the laws of England and Wales unless applicable law requires otherwise.
Contact
Data-protection enquiries can be sent to hello@awayly.co.uk.