This Data Processing Agreement ("DPA") supplements the Terms of Service and applies where Customer's use of the Service involves our processing of personal data on Customer's behalf — most commonly, workforce data entered for BRSR Section A/Principle 3, CSRD ESRS S1 (Own Workforce), or similar disclosures that reference identifiable employees, contractors, or other individuals.
For personal data Customer enters into the Service about its own employees, workers, suppliers, or other third parties, Customer is the data controller and we are the data processor (or "business" and "service provider," under frameworks that use that terminology instead). We process that data only as described in this DPA and Customer's documented instructions, given primarily through Customer's own configuration and use of the Service.
Nature of processing: storage, organization, and structured retrieval of ESG/sustainability disclosure data, which may include personal data, for the purpose of enabling Customer's own regulatory reporting and internal ESG tracking.
Categories of data subjects: typically Customer's employees and workers (e.g. headcount, diversity, safety incident, and remuneration data required by BRSR Principle 3 or ESRS S1), and may include named individuals in governance disclosures (e.g. board composition) or supplier/value-chain contacts.
Categories of personal data: depends entirely on what Customer chooses to enter — this can range from purely aggregate/statistical figures (headcount totals, percentages) with no personal data at all, up to named individuals where a disclosure requirement calls for it. Customer controls what is entered and should avoid entering more identifiable detail than a given disclosure genuinely requires.
We process personal data only on Customer's documented instructions, which are given through Customer's configuration and use of the Service (which frameworks are enabled, what data is entered, who is granted access). We will inform Customer if, in our view, an instruction infringes applicable data protection law — though as a general-purpose data platform, we do not review the substance of what Customer enters.
Personnel with access to Customer Data are bound by confidentiality obligations, and access within our own team is limited to what's needed to operate and support the Service — see the internal administration audit log referenced in Section 5.
The technical and organizational measures in place include: encrypted password storage (bcrypt hashing, never plaintext); database-layer tenant isolation, so one customer's data is never queryable by another regardless of any application-layer bug; role-based access control, including a read-only role specifically for third-party assurance providers, enforced at the server rather than only hidden in the interface; brute-force protection on authentication; and a complete, attributable audit trail of every administrative and data-modifying action, including actions taken by our own internal team through the platform administration panel. [This section should be expanded with specifics as formal security certifications (SOC 2, ISO 27001) or a completed penetration test become available — see the parallel note in the Privacy Policy.]
We use the sub-processors listed in our Privacy Policy (Section 3) to operate the Service. We'll notify Customer of any new sub-processor with access to personal data before it goes into effect, and Customer may object on reasonable data-protection grounds. [Standard DPAs typically specify a notice period, e.g. 30 days, and an objection mechanism — to be set explicitly once finalized.]
We'll notify Customer without undue delay — and in any case within the timeframe required by applicable law — after becoming aware of a personal data breach affecting Customer Data, with enough information to let Customer meet its own regulatory notification obligations (for example, DPDP Act or GDPR breach-notification timelines, which are typically measured in hours, not days).
Where an individual exercises a data protection right (access, correction, deletion, etc.) directly against Customer regarding data held in the Service, we'll provide reasonable technical assistance to help Customer respond — for example, tools already in the product to locate, correct, or export a specific record.
Following termination, Customer Data (including personal data processed under this DPA) is available for export for the period specified in the Terms of Service, and deleted thereafter except to the extent retention is required by law.
[Enterprise customers, particularly in the EU, will often expect a contractual audit right or at minimum the right to request a completed security questionnaire or certification report — to be defined based on your actual policy on customer audits, which is easier to commit to once a real certification (Section 5) exists to point to.]