LEGAL CENTER

DPA

Data Processing Addendum

The controller-processor baseline for Corporate Suite: instructions, confidentiality, security, subprocessors, individual rights, incidents, deletion, audits, and international transfers.

Effective
August 3, 2026
Last updated
August 3, 2026
01

Application and parties

This Data Processing Addendum (DPA) forms part of the Terms of Service or other written agreement (Agreement) between the Corporate Suite customer (Customer) and The Working Company, Inc. (TWC) when TWC processes Customer Personal Data on Customer's behalf and data-protection law requires controller-processor terms.

Customer is the controller and TWC is the processor. If Customer acts as a processor for another controller, Customer is a processor and TWC is Customer's subprocessor. This DPA is effective when Customer accepts the Agreement or the parties otherwise incorporate it. A countersigned copy is available by request for enterprise procurement.

02

Definitions

Customer Personal Data means personal data, personal information, or equivalent regulated information contained in Customer Content and processed by TWC on Customer's behalf. Data Protection Law means privacy and data-protection laws applicable to that processing, including where applicable the GDPR, UK GDPR, Swiss FADP, CCPA, and comprehensive US state privacy laws. Process, controller, processor, data subject, and supervisory authority have the meanings given by applicable Data Protection Law.

03

Documented instructions

TWC will process Customer Personal Data only to provide, secure, support, and improve the Service; comply with the Agreement and Customer's documented configuration and requests; and comply with law. The Agreement, Customer's use of features, workspace settings, support requests, and lawful written directions are Customer's documented instructions.

If TWC believes an instruction violates Data Protection Law, it will inform Customer unless prohibited and may pause the affected processing. TWC will notify Customer before processing required by law unless the law prohibits notice.

04

Customer obligations

Customer is responsible for the lawfulness, fairness, and accuracy of Customer Personal Data and instructions; required notices and consents; a valid legal basis; responding to data subjects; configuring access, sharing, connectors, and retention; and ensuring the Service is appropriate for Customer's processing. Customer will not instruct TWC to process data in violation of law or the Agreement.

05

Confidentiality and access

TWC will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations, receive access only as needed for their duties, and process the data only under TWC's instructions. TWC will maintain access controls and review access proportionate to role and risk.

06

Security measures

TWC will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures include, as appropriate to risk:

  • encrypted transport and encrypted production data stores;
  • tenant, workspace, role, and service authorization controls;
  • secret management, least-privilege production access, and access logging;
  • secure development, change review, dependency and image scanning, and release controls;
  • monitoring, incident response, backups, recovery procedures, and retention-bounded logs; and
  • periodic review of safeguards and provider risk.

Customer acknowledges that security measures evolve and TWC may update them without materially reducing the overall protection of Customer Personal Data. The current public summary is the Security Statement.

07

Subprocessors

Customer gives general written authorization for TWC to use the subprocessors listed on the Subprocessors page. TWC will impose data-protection obligations that provide a level of protection appropriate to the processing and will remain responsible for a subprocessor's performance of those obligations to the extent required by law.

TWC will provide notice of a new subprocessor through that page as described there. Customer may object on reasonable data-protection grounds during the notice period. The parties will seek a commercially reasonable solution. If none is available, TWC may avoid the provider, disable the affected feature, or Customer may terminate the affected Service. This is Customer's sole remedy for a subprocessor objection.

08

Data-subject requests

Taking into account the nature of processing, TWC will provide reasonable assistance through product controls and available technical or organizational measures so Customer can respond to requests to access, correct, delete, restrict, object, port, or opt out. If TWC receives a request concerning Customer Personal Data, TWC will direct the person to Customer and will not independently respond except on Customer's instruction or as legally required.

09

Compliance assistance

Taking into account the nature of processing and information available to TWC, TWC will reasonably assist Customer with security obligations, personal-data-breach notifications, data-protection impact assessments, and prior consultation with supervisory authorities. Assistance beyond standard Service functionality may be subject to reasonable fees if the need was not caused by TWC's breach.

10

Personal-data breach

TWC will notify Customer without undue delay after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in TWC's possession or control (Personal Data Breach).

The notice will include available information about the nature of the breach, affected data and individuals, likely consequences, measures taken or proposed, and a contact point. TWC may provide information in phases and will take reasonable steps to contain, investigate, and mitigate the breach. Notice is not an admission of fault. Unsuccessful attacks and events that do not compromise Customer Personal Data are not Personal Data Breaches under this section.

11

Return and deletion

During the term, Customer may use available export and deletion functions. On termination or written request, TWC will delete or return Customer Personal Data as required by the Agreement and Customer's instruction, unless law requires retention. Data may remain temporarily in isolated backups and immutable security records until their normal expiry; it will not be restored to ordinary processing except for disaster recovery or legal necessity. TWC may retain de-identified data that cannot reasonably identify Customer or a person.

12

Information and audits

TWC will make information reasonably necessary to demonstrate compliance with this DPA available to Customer, including this DPA, the Security Statement, subprocessor information, and available independent reports or questionnaires subject to confidentiality.

If that information is insufficient, Customer may request one audit per year by an independent, qualified auditor, with additional audits after a confirmed Personal Data Breach or where required by a supervisory authority. Audits require reasonable advance notice, must avoid disruption and access to other customers' data, and are at Customer's expense unless they identify TWC's material breach. The auditor must sign confidentiality terms.

13

International transfers

TWC may process Customer Personal Data in the United States and other locations used by authorized subprocessors. For a restricted transfer from the EEA to TWC where no adequacy decision applies, the 2021 European Commission Standard Contractual Clauses are incorporated by reference: Module Two applies when Customer is a controller and Module Three when Customer is a processor. The docking clause applies; the optional independent-dispute-resolution language does not; Option 2 general subprocessor authorization applies with the notice period on our Subprocessors page; and the law and courts are those of Ireland.

For UK restricted transfers, the UK International Data Transfer Addendum to the EU SCCs is incorporated, completed using this DPA and with neither party permitted to terminate solely because the UK Addendum changes. For Swiss transfers, references to the GDPR include the Swiss FADP, the competent authority is the Swiss Federal Data Protection and Information Commissioner where applicable, and Swiss data subjects may enforce the clauses.

TWC will implement supplementary measures appropriate to transfer risk and, on request, provide a copy of the completed clauses subject to permitted redactions.

14

US service-provider terms

For Customer Personal Data subject to the CCPA or similar US law, TWC acts as a service provider or processor. TWC will not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship except as permitted by law; combine it with personal information from another source except as permitted; or use it for cross-context behavioral advertising.

TWC will process the data only for the business purposes in the Agreement, provide the same level of privacy protection required by applicable law, notify Customer if it determines it can no longer meet those obligations, and permit Customer to take reasonable steps to stop and remediate unauthorized use. Customer may monitor compliance through Section 12.

15

Annex I — Processing details

Subject matterProvision, security, support, and administration of Corporate Suite.
DurationThe Agreement term plus the limited deletion, backup, legal, and security periods described in the Privacy Policy.
NatureCollection, recording, organization, hosting, retrieval, consultation, transmission, generation, analysis, synchronization, restriction, deletion, and other processing directed through Service features.
PurposesCollaboration, work management, files, planning, communications, AI and agent features, integrations, support, security, audit, and related contracted functionality.
Data subjectsCustomer users, personnel, contractors, applicants, clients, vendors, collaborators, contacts, communication participants, and other individuals whose data Customer submits.
Personal dataIdentity and contact data; organization and role; account and authentication metadata; work records; tasks, files, messages, events, databases, prompts, outputs, audio and transcripts; integration data; technical, usage, support, audit, and security data.
Sensitive dataNot required for ordinary use. May include account tokens and any sensitive or special-category data Customer chooses and is authorized to submit. Customer must minimize and apply appropriate safeguards.
FrequencyContinuous or as initiated by Customer and its users during the Service term.
Controller contactThe Customer account owner or privacy contact identified in the Agreement or account.
Processor contactThe Working Company, Inc.; [email protected]; 718 Calle Lima, San Clemente, CA 92673, USA.
16

Order of precedence and changes

The SCCs control over conflicting DPA terms; this DPA controls over conflicting Agreement terms for covered processing; and the Agreement otherwise controls. Liability under this DPA is subject to the Agreement's liability framework except where the SCCs or law prohibit that limitation. TWC may update this DPA to reflect law or Service changes, but will not materially reduce Customer's data-protection rights during a paid term without reasonable notice.