Dextro Logo

Data Processing Agreement (DPA)

Dextro Compliance Operations

This Data Processing Agreement ("DPA") forms part of the Master Services Agreement between the Client ("Data Controller") and Dextro ("Data Processor").

1. Scope of Processing

Dextro provides a managed Compliance Operations Desk. In providing this service, Dextro will process Personal Data strictly on the documented instructions of the Client for the purpose of verifying candidate or client documentation.

2. Roles and Responsibilities

3. Confidentiality and Security

Dextro ensures that all personnel authorized to process Personal Data have committed themselves to confidentiality. Dextro has implemented appropriate Technical and Organisational Measures (TOMs) to ensure a level of security appropriate to the risk.

4. Subprocessors

The Client authorizes Dextro to engage third-party subprocessors (including Vercel, Supabase, and Resend). Dextro will remain fully liable to the Client for the performance of the subprocessor's obligations.

5. International Data Transfers (Restricted Transfers)

The Client acknowledges that while primary databases are hosted in the UK, Dextro’s human administration operations are located in Nigeria (a country not currently on the UK's Adequacy list). To safeguard this restricted transfer in strict adherence with UK GDPR Chapter V, this DPA incorporates by reference the UK International Data Transfer Addendum (IDTA).

6. Data Subject Rights & Incident Response

7. Data Deletion

Dextro operates an "Automated Document Purging" policy. Upon completion of the verification process, or upon termination of the service, Dextro will return or securely delete all Personal Data within 30 days, unless legally required to retain it.

Dextro Compliance Operations

Document Version: 1.0 (2026)