Legal
Data Processing Addendum
If Customer has entered into an Order Form under the Terms, and the Order Form incorporates this Data Processing Addendum (the “DPA”) by reference, this DPA forms part of the Terms by and between Customer and Workloom. All capitalized terms that are not expressly defined in this DPA will have the meanings given to them in the Terms. If and to the extent any language in this DPA conflicts with the Terms, this DPA shall control.
(1) Processing Terms for Customer Personal Data.
(a) Documented Instructions. Workloom shall Process Customer Personal Data to provide the Services in accordance with the Terms, this DPA, and any instructions agreed upon by the parties. If applicable law requires that Workloom Process Customer Personal Data for other purposes, Workloom shall inform Customer of that legal requirement before engaging in such Processing, unless that law prohibits such information on important grounds of public interest.
(b) Use of Subprocessors. Workloom may engage Subprocessors. Workloom shall (i) enter into a written agreement with Subprocessors that imposes data protection requirements on such Subprocessors that are consistent with this DPA; and (ii) remain responsible to Customer for the Subprocessors’ failure to perform their obligations with respect to the Processing of Customer Personal Data.
(c) Right to Object to Subprocessors. Workloom shall notify Customer prior to engaging any material new Subprocessor by sending an email to the email address that is listed as Customer’s account owner or administrator. Within ten (10) days after notice is sent, Customer may reasonably object to the new Subprocessor if such Subprocessor would cause Customer to be in material breach of Data Protection Privacy Laws. If Customer objects to the appointment of any new Subprocessor in accordance with the preceding sentence, the parties shall work together in good faith to resolve the grounds for the objection.
(d) Confidentiality. Any person authorized to Process Customer Personal Data shall be subject to a duty of confidentiality, contractually agree to maintain the confidentiality of such information, or be under an appropriate statutory obligation of confidentiality.
(e) Information Security. Workloom shall implement and maintain reasonable administrative, technical, and physical safeguards designed to protect Customer Personal Data in accordance with the Workloom Information Security Standards attached hereto as Exhibit A.
(f) Security Incidents. Upon becoming aware of a Security Incident, Workloom shall provide written notice without undue delay and within the time frame required under applicable Data Protection Laws to the email address that is listed as Customer’s account owner or administrator. Where possible, such notice will include all available details required under applicable Data Protection Laws for Customer to comply with its own notification obligations to government authorities and/or individuals affected by the Security Incident.
(g) Cross-Border Transfers of Customer Personal Data. Customer authorizes Workloom and its Subprocessors to transfer Customer Personal Data across international borders, including from the European Economic Area, Switzerland, and/or the United Kingdom to the United States. If Customer Personal Data originating in the European Economic Area, Switzerland, and/or the United Kingdom is transferred by Customer to Workloom in a country that has not been found to provide an adequate level of protection under applicable Data Protection Laws, the parties agree that the transfer shall be governed by Module Two’s obligations in the Annex to the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (“Standard Contractual Clauses”) as supplemented by Exhibit B attached hereto, the terms of which are incorporated herein by reference. Each party’s execution of the applicable Order Form shall be considered a signature to the Standard Contractual Clauses to the extent that the Standard Contractual Clauses apply hereunder.
(h) Personal Data Inquiries and Requests. Workloom shall provide reasonable assistance to Customer as required by applicable Data Protection Laws in response to any requests from individuals exercising their rights in Customer Personal Data granted to them under applicable Data Protection Laws.
(i) Data Protection Assessment, Data Protection Impact Assessment, and Prior Consultation. Workloom shall provide reasonable assistance and information to Customer as required by applicable Data Protection Laws where, in Customer’s judgment, the type of Processing performed by Workloom requires a data protection assessment, data protection impact assessment, and/or prior consultation with the relevant data protection authorities.
(j) Demonstrable Compliance. Workloom shall provide information reasonably necessary to demonstrate compliance with this DPA as required by applicable Data Protection Laws upon Customer’s reasonable request.
(k) Audit / Assessment Right. Upon Customer’s written request, not more than once in any twelve-month period, Workloom will provide Customer with its security documentation and will respond to a reasonable written security questionnaire, so that Customer can reasonably verify Workloom’s compliance with the security obligations in this DPA. Such documentation and responses are Workloom’s Confidential Information.
(l) CCPA Terms. To the extent that Workloom’s Processing of Customer Personal Data is subject to the CCPA, and Workloom is acting in its capacity as a “service provider,” this Section 1.12 also applies. Customer discloses or otherwise makes available Customer Personal Data to Workloom for the limited and specific purpose of enabling Workloom to provide the Services to Customer in accordance with the Agreement and this DPA. Workloom shall (i) comply with its applicable obligations under the CCPA; (ii) provide the same level of protection as required under the CCPA; (iii) notify Customer if it can no longer meet its obligations under the CCPA; (iv) not “sell” or “share” (as such terms are defined by the CCPA) Customer Personal Data; (v) not retain, use, or disclose Customer Personal Data for any purpose (including any commercial purpose) other than to provide the Services under the Agreement or as otherwise permitted under the CCPA; (vi) not retain, use, or disclose Customer Personal Data outside of the direct business relationship between Customer and Workloom; and (vii) unless otherwise permitted by the CCPA, not combine Customer Personal Data with Personal Data that Workloom (a) receives from, or on behalf of, another person, or (b) collects from its own, independent consumer interaction. Workloom will permit Customer, upon reasonable request, to take reasonable and appropriate steps to ensure that Workloom Processes Customer Personal Data that is subject to this Section 1.12 in a manner consistent with the obligations of a “business” under the CCPA by requesting that Workloom attest to its compliance with this Section 1.12. Following any such request, Workloom will promptly provide that attestation or an explanation of why it cannot provide it. If Customer reasonably believes that Workloom is engaged in unauthorized Processing of Customer Personal Data that is subject to this Section1.12, Customer will notify Workloom of such belief, and the parties will work together in good faith to remediate the allegedly violative Processing activities, if necessary.
(m) Deletion of Customer Personal Data. At the expiry or termination of the Terms, upon Customer’s request, Workloom shall delete all Customer Personal Data (excluding any backup or archival copies, which shall be deleted in accordance with Workloom’s data retention schedule), except where Workloom is required to retain copies under applicable laws, in which case Workloom restrict any further Processing of such Customer Personal Data except to the extent required by applicable laws.
(2) Definitions. For the purposes of this DPA, the following terms and those defined within the body of this DPA apply.
(a) “Customer Personal Data” means Customer Materials that are Personal Data.
(b) “Data Protection Laws” means the privacy and data protection laws, rules and regulations applicable to a party’s Processing of Customer Personal Data under the Terms. “Data Protection Laws” may include, but are not limited to, the California Consumer Privacy Act of 2018 (as amended by the California Privacy Rights Act) (“CCPA”); the EU General Data Protection Regulation 2016/679 (“GDPR”) and its respective national implementing legislations; other comprehensive US state privacy laws; the Swiss Federal Act on Data Protection; the United Kingdom General Data Protection Regulation; and the United Kingdom Data Protection Act 2018 (in each case, as amended, adopted, or superseded from time to time).
(c) “Personal Data” has the meaning assigned to the term “personal data” or “personal information” under applicable Data Protection Laws.
(d) “Process” or “Processing” means any operation or set of operations that is performed on Personal Data or sets of Personal Data, whether or not by automated means, such as collection; recording; organization; structuring; storage; adaptation or alteration; retrieval; consultation; use; disclosure by transmission; dissemination; or otherwise making available; alignment or combination; restriction; erasure; or destruction.
(e) “Security Incident(s)” means the breach of security leading to the accidental or unlawful destruction, loss, or alteration of, or the unauthorized disclosure of or access to, Customer Personal Data attributable to Workloom.
(f) “Subprocessor” means a vendor that Workloom has engaged to Process Customer Personal Data.
(g) “Terms” means the Workloom Terms of Service available at https://useworkloom.com/legal/terms/.
(3) Miscellaneous. This DPA only applies where Workloom is acting as a “processor” or “service provider” of Customer Personal Data. This DPA applies in addition to, and not in lieu of, Workloom’s rights and obligations under the Terms.
EXHIBIT A TO THE DATA PROCESSING ADDENDUM
Workloom Information Security Standards
These Workloom Information Security Standards (the “Information Security Standards”) form part of the DPA. All capitalized terms that are not expressly defined in the Information Security Standards will have the meanings given to them in the DPA or the Terms.
Workloom shall implement and maintain an information security program (“Information Security Program”) that includes reasonable administrative, technical, and physical safeguards designed to protect Customer Personal Data. At a minimum, the Information Security Program shall include:
(1) Authentication. Workloom shall maintain authentication measures including, as appropriate, multi-factor authentication for key systems that Process Customer Personal Data and industry standard passwords.
(2) Encryption. Workloom shall encrypt Customer Personal Data in transit and at rest using industry standard encryption technologies.
(3) Account Management and Access Controls. Workloom shall maintain account management and access controls.
(4) Inventory and Management of Customer Personal Data and Information Systems. Workloom shall maintain an inventory of Customer Personal Data and the information systems used to Process Customer Personal Data. Workloom shall maintain approval processes designed to prevent the unauthorized connection of hardware and devices to Workloom’s information systems that Process Customer Personal Data.
(5) Secure Configuration of Hardware and Software. Workloom shall maintain controls designed to ensure the secure configuration of Workloom hardware and software that is used to Process Customer Personal Data.
(6) Vulnerability Scans, Penetration Testing, and Vulnerability Disclosure and Reporting. Workloom shall carry out internal and external vulnerability scans, penetration testing, and vulnerability disclosure and reporting for key information systems used to Process Customer Personal Data.
(7) Audit-Log Management. Workloom shall maintain controls for audit-log management.
(8) Network Monitoring and Defenses. Workloom shall maintain controls for monitoring and defending its network.
(9) Malware Protection. Workloom shall implement controls designed to mitigate the risk of malware on personnel workstations, including operating system–level security features, device management controls, secure configuration standards, and access restrictions appropriate to the platforms in use.
(10) Information System Segmentation. Workloom shall maintain controls designed to ensure segmentation of its information systems that Process Customer Personal Data.
(11) Limitation and Control of Ports, Services, and Protocols. Workloom shall maintain controls designed to limit and control ports, services, and protocols used to Process Customer Personal Data.
(12) Security Awareness and Training. Workloom shall maintain a security awareness and training program designed to educate personnel on information security and data protection obligations relevant to their roles. Such training is provided upon hire and periodically thereafter, and completion is tracked in accordance with Workloom’s information security program.
(13) Secure Development. Workloom shall maintain controls designed to ensure secure development.
(14) Vendor Management. Workloom shall maintain oversight of Subprocessors.
(15) Data Retention and Disposal. Workloom shall maintain data retention and disposal processes for Customer Personal Data.
(16) Security Incident Management. Workloom shall maintain processes for the management of Security Incidents.
(17) Business Continuity and Disaster Recovery. Workloom shall maintain industry standard business-continuity and disaster-recovery plans as it relates to the Processing of Customer Personal Data.
EXHIBIT B TO THE DATA PROCESSING ADDENDUM
Supplemental Terms for the Standard Contractual Clauses
This Exhibit B forms part of the DPA and supplements the Standard Contractual Clauses. Capitalized terms not defined in this Exhibit B have the meaning set forth in the DPA.
The parties agree that the following terms shall supplement the Standard Contractual Clauses:
SUPPLEMENTAL TERMS. The parties agree that (i) a new Clause 1(e) is added to the Standard Contractual Clauses, which shall read as follows: “To the extent applicable hereunder, these Clauses also apply mutatis mutandis to the Parties’ processing of personal data that is subject to the Swiss Federal Act on Data Protection. Where applicable, references to EU Member State law or EU supervisory authorities shall be modified to include the appropriate reference under Swiss law as it relates to transfers of personal data that are subject to the Swiss Federal Act on Data Protection.”; (ii) a new Clause 1(f) is added to the Standard Contractual Clauses, which shall read as follows: “To the extent applicable hereunder, these Clauses, as supplemented by Annex III, also apply mutatis mutandis to the Parties’ processing of personal data that is subject to UK Data Protection Laws (as defined in Annex III).”; (iii) the optional text in Clause 7 is deleted; (iv) Option 1 in Clause 9 is struck and Option 2 is kept, and data importer must notify data exporter of any new subprocessors in accordance with Section 1.3 of the DPA; (v) the optional text in Clause 11 is deleted; and (vi) in Clauses 17 and 18, the governing law and the competent courts are those of Ireland (for EEA transfers), Switzerland (for Swiss transfers), or England and Wales (for UK transfers).
ANNEX I. Annex I to the Standard Contractual Clauses shall read as follows:
List of Parties:
Data exporter: Customer.
Address: As set forth in the Notices section of the Terms.
Contact person’s name, position, and contact details: As set forth in the Notices section of the Terms.
Activities relevant to the data transferred under these Clauses: The Services.
Role: Controller.
Data importer: Workloom.
Address: As set forth in the Notices section of the Terms.
Contact person’s name, position, and contact details: As set forth in the Notices section of the Terms.
Activities relevant to the data transferred under these Clauses: The Services.
Role: Processor.
Description of the Transfer:
Categories of data subjects whose personal data is transferred: The categories of data subjects whose personal data is transferred under the Clauses including, but not limited to, data exporter’s customers and leads.
Categories of personal data transferred: The categories of personal data transferred under the Clauses including, but not limited to, name, email address, and professional details.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: To the parties’ knowledge, no sensitive data is transferred.
The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis): Personal data is transferred in accordance with the standard functionality of the Services, or as otherwise agreed upon by the parties.
Nature of the processing: The Services.
Purpose(s) of the data transfer and further processing: The Services.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Data importer will retain personal data in accordance with the DPA.
For transfers to (sub-) processors, also specify subject matter, nature, and duration of the processing: The subject matter, nature, and duration are identified above.
Competent Supervisory Authority: The supervisory authority mandated by Clause 13. If no supervisory authority is mandated by Clause 13, then the supervisory authority is the Irish Data Protection Commission, and if this is not possible, then the supervisory authority is as otherwise agreed by the parties consistent with the conditions set forth in Clause 13.
Clarifying Terms: The parties agree that (i) the certification of deletion required by Clause 8.5 and Clause 16(d) of the Clauses will be provided upon data exporter’s written request; (ii) the measures data importer is required to take under Clause 8.6(c) of the Clauses will only cover data importer’s impacted systems; (iii) the audit described in Clause 8.9 of the Clauses shall be carried out in accordance with Section 1.11 of the DPA; (iv) the termination right contemplated by Clause 14(f) and Clause 16(c) of the Clauses will be limited to the termination of the Clauses; (v) unless otherwise stated by data importer, data exporter will be responsible for communicating with data subjects pursuant to Clause 15.1(a) of the Clauses; and (vi) the information required under Clause 15.1(c) of the Clauses will be provided upon data exporter’s written request.
ANNEX II. Annex II of the Standard Contractual Clauses shall read as follows:
Data importer shall implement and maintain technical and organisational measures designed to protect personal data in accordance with the DPA.
ANNEX III. A new Annex III shall be added to the Standard Contractual Clauses and shall read as follows:
The UK Information Commissioner’s Office International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (“UK Addendum”) is incorporated herein by reference.
Table 1: The start date in Table 1 is the effective date of the DPA. All other information required by Table 1 is set forth in Annex I, Section A of the Clauses.
Table 2: The UK Addendum forms part of the version of the Approved EU SCCs which this UK Addendum is appended to, including the Appendix Information, effective as of the effective date of the DPA.
Table 3: The information required by Table 3 is set forth in Annex I and II to the Clauses.
Table 4: The parties agree that Importer may end the UK Addendum as set out in Section 19.