Data processing addendum · updated 2026-07-28
Customer instructions govern customer data.
This addendum becomes binding when incorporated into an executed order with the operator identified in the order. The contracting entity and governing law are identified on that order.
Roles and instructions
The customer is controller or business; the service operator is processor or service provider for customer data submitted to the service. Data is processed only to provide, secure, support, and improve the contracted service, or as required by law.
Confidentiality and security
Access is limited to authorized personnel and service providers under confidentiality duties. Controls include tenant scoping, encrypted retained sources, hashed credentials and tokens, immutable source and event records, audit events, retention settings, and backup procedures.
Subprocessors and transfers
Infrastructure, email, payment, authentication, and connected-source providers may process limited data for their service. The current subprocessor and hosting-region schedule is supplied with the order.
Requests, incidents, and deletion
The operator will reasonably assist with data-subject requests and confirmed incidents appropriate to the processing. Workspace deletion removes application records and retained objects; backup expiration follows the recovery schedule.
Return and audit
Customers can export execution and audit reports. Reasonable security documentation is provided under confidentiality before an on-site audit is considered.