Data processing addendum

Last updated: TO COMPLETE: Date this DPA took effect

This addendum forms part of the terms of service between TO COMPLETE: Registered legal name, exactly as on the Kbis ("Processor") and Customer ("Controller") and applies where we process personal data on Customer's behalf within the meaning of Regulation (EU) 2016/679 ("GDPR").

Read the scope clause first. Most DPAs cover a vendor's hosting of customer data. This one does not, because we do not host any. InfoIQ runs inside Customer's own Salesforce organisation and we have no access to the data in it. The only personal data we process on Customer's behalf is what Customer sends us in a support request.

1. Scope and roles

Controller determines the purposes and means of processing personal data through InfoIQ. Processor processes personal data only on Controller's documented instructions, which are these terms and any support request Controller sends.

For the avoidance of doubt, personal data stored within Controller's Salesforce organisation is processed by Salesforce, Inc. under Controller's separate agreement with Salesforce. Processor is not a subprocessor of that data and has no technical means of accessing it.

2. Subject matter of the processing

Subject matterProvision of support for InfoIQ
DurationThe subscription term, plus the retention periods below
Nature and purposeReceiving, storing and responding to support correspondence; diagnosing defects
Types of personal dataBusiness contact details of Controller's personnel; any personal data Controller chooses to include in a support message or attachment
Categories of data subjectController's employees, contractors and administrators
Special categoriesNone. Controller must not send special category data in support correspondence.

3. Processor obligations

  • Process personal data only on Controller's documented instructions, including for transfers, unless required otherwise by law — in which case Processor informs Controller first, unless the law forbids it.
  • Ensure that personnel authorised to process personal data are bound by confidentiality.
  • Implement appropriate technical and organisational measures, described in clause 5.
  • Engage a subprocessor only under clause 6.
  • Assist Controller, taking into account the nature of the processing, in responding to data subject requests and in meeting its obligations under Articles 32 to 36 GDPR.
  • At Controller's choice, delete or return all personal data at the end of the provision of services, and delete existing copies, unless law requires storage.
  • Make available the information necessary to demonstrate compliance with Article 28, and allow and contribute to audits under clause 7.

4. Confidentiality and personnel

Access to support correspondence is limited to the personnel who need it to answer the request. All personnel are bound by written confidentiality obligations that survive the end of their engagement.

5. Security measures

The primary measure is architectural: InfoIQ transfers no personal data to Processor, so the volume of data at risk is limited to what Controller voluntarily sends. In addition, Processor applies multi-factor authentication on all business systems, encryption in transit and at rest, least-privilege access, and an incident procedure under which affected Controllers are notified by email at their registered contact without undue delay, and in any event within 72 hours of Processor becoming aware.

6. Subprocessors

Controller gives general authorisation for Processor to engage subprocessors for the services described in clause 2 — currently business email, and no other. Processor imposes on each subprocessor data protection obligations no less protective than this addendum and remains liable for their performance. Processor will give Controller at least 30 days' notice before adding or replacing a subprocessor, during which Controller may object on reasonable data protection grounds; if the objection cannot be resolved, Controller may terminate the affected services and receive a pro rata refund. The current list is available from support@jalonworks.com.

7. Audits

Processor will respond to a reasonable security questionnaire once per twelve-month period, and will provide the information necessary to demonstrate compliance with this addendum. An on-site audit may be conducted once per twelve-month period on 30 days' notice, during business hours, subject to confidentiality, and at Controller's cost — or immediately following a personal data breach affecting Controller.

8. Personal data breach

Processor notifies Controller without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting personal data processed under this addendum, with the information available at the time and updates as the investigation proceeds.

9. International transfers

Processor does not transfer personal data outside the EEA except where covered by an adequacy decision or by the European Commission's Standard Contractual Clauses, which are incorporated by reference where they apply, with Processor as data importer and Controller as data exporter.

10. Return and deletion

On termination, Processor deletes support correspondence containing personal data within 30 days, except records it must retain by law — principally invoicing records held for the statutory accounting period.

11. Order of precedence

In case of conflict, this addendum prevails over the terms of service on matters of data protection. Where Standard Contractual Clauses apply, they prevail over this addendum.

Signing a copy

This addendum applies automatically to every subscription. If your procurement process requires a countersigned copy, or your own DPA template, write to support@jalonworks.com and we will arrange it.

On this page
  1. 1. Scope and roles
  2. 2. Subject matter of the processing
  3. 3. Processor obligations
  4. 4. Confidentiality and personnel
  5. 5. Security measures
  6. 6. Subprocessors
  7. 7. Audits
  8. 8. Personal data breach
  9. 9. International transfers
  10. 10. Return and deletion
  11. 11. Order of precedence
  12. Signing a copy