Data Privacy Addendum (DPA)

This Data Processing Addendum (“DPA“) is incorporated into and forms a part of the agreement between WorkZone, LLC (“Workzone“) and Customer that governs Customer’s access to and use of the online Services (“Agreement“).  Capitalized terms not defined herein have the meaning given in the Agreement.

1.       Definitions. In this DPA, the following terms (and derivations thereof) have the meanings set out below:

  • Affiliate” means any person or entity that owns or controls, is owned or controlled by, or is under common control or ownership with, a party to this Agreement, where “control” is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract, or otherwise.
  • Controller” means the individual or entity that determines the purposes and means of the Processing of Personal Data.
  • Customer” means the individual or entity that has entered into the Agreement and agreed to the incorporation of this DPA into the Agreement.
  • Customer Content” means any data, file attachments, text, images, reports, personal information, or other content that is uploaded or submitted to an online Service by Customer or Users and is Processed by Workzone on behalf of Customer. For the avoidance of doubt, Customer Content does not include usage, statistical, learned, or technical information that does not reveal the actual contents of Customer Content.
  • Customer Personal Data” means Personal Data that is contained within Customer Content.
  • Data Breach” means a breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Content.
  • Data Protection Laws” means, to the extent applicable to a Party, the data protection or privacy laws of any country regarding the Processing of Customer Personal Data.
  • Data Subject” means an identified or identifiable natural person. 
  • Parties” or “Party” means Customer and/or Workzone as applicable.
  • Personal Data” means any information relating to, identifying, describing, or capable of being associated with a Data Subject or a household. 
  • Process” means any operation or set of operations performed upon Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, alignment, combination, restriction, erasure, destruction or disclosure by transmission, dissemination or otherwise making available.
  • Processor” means the individual or entity that Processes Personal Data on behalf of a Controller.
  • Professional Services” means implementation, configuration, integration, training, advisory, and other professional services related to the online Services that are provided or controlled by Workzone.
  • Services” means the Professional Services and the Subscription Service and any other online service or application provided or controlled by Workzone for use with the Subscription Services. 
  • Workzone Personnel” means any individual authorized by Workzone to Process Customer Personal Data.
  • Subprocessor” means any individual or entity (including any third party but excluding Workzone Personnel) appointed by or on behalf of Workzone to Process Customer Personal Data in connection with the Agreement.
  • Subscription Services” means the subscription-based online services and applications that are provisioned and controlled by Workzone. 
  • Supervisory Authority” means an independent competent public authority established or recognized under Data Protection Laws.
  • User” means any individual authorized or invited by Customer or another User to access and use the online Services available to Customer under an Order and the terms of the Agreement. 

2.       Roles of Parties.

2.1    Customer and Workzone agree that, as between the Parties, Customer is a Controller and Workzone is a Processor of Customer Personal Data and that each Party is solely responsible for its compliance with Data Protection Laws applicable to it and for fulfilling any of its related obligations to third parties, including Data Subjects and Supervisory Authorities.

2.2    Customer as Controller

  • 2.2.1    Customer is solely responsible for the accuracy of Customer Personal Data and the legality of the means by which Customer acquires, discloses, and processes Customer Personal Data.
  • 2.2.2   Customer’s instructions to Workzone to Process Customer Personal Data will comply with Data Protection Laws and be duly authorized, with all necessary rights, permissions, and consents secured. 

2.3    Workzone as Processor.

  • 2.3.1    Workzone will Process Customer Personal Data only: (a) as instructed by Customer in writing or as initiated by authorized Users via an online Service; (b) as necessary to provide the Services and prevent or address technical problems with an online Service or violations of the Agreement or this DPA; or (c) as required by applicable law. Schedule 1 (Details of Processing of Customer Personal Data) sets out a description of Workzone’s Processing of Customer Personal Data. Workzone agrees to immediately inform Customer if Workzone reasonably believes that any instruction to Process Customer Personal Data violates, or would violate, Data Protection Laws.
  • 2.3.2   Workzone will ensure that Workzone Personnel: (a) access Customer Personal Data only to the extent necessary to perform Workzone’s Processing obligations under this DPA and the Agreement; (b) are bound by confidentiality obligations with respect to Customer Personal Data substantially as protective as those set forth in this DPA and the Agreement; and (c) are subject to appropriate training relating to the Processing of Customer Personal Data. 
  • 2.3.3    Workzone will not sell or share Customer Personal Data in violation of Data Protection Laws. 
  • 2.3.4   Workzone will not assess the type or substance of Customer Content to identify whether it is Customer Personal Data and/or subject to any specific legal requirements.
  • 2.3.5    Following termination of the DPA, Workzone will return or delete Customer Content in accordance with the Agreement.

3.       Security.

3.1    Workzone will implement and maintain technical, physical, and organizational measures and controls designed to protect and secure Customer Content (including the return and deletion thereof) in accordance with the Agreement. Notwithstanding the foregoing, Customer is solely responsible for independently assessing and ultimately implementing such security configuration settings made available to Customer by Workzone as it deems necessary to meet its requirements and legal obligations under applicable Data Protection Laws.

3.2    Customer acknowledges that, through its Users, Customer: (a) controls the type and substance of Customer Content; and (b) sets User permissions to access Customer Content; and therefore, Customer is responsible for reviewing and evaluating whether the documented functionality of an online Service meets Customer’s required security obligations relating to Customer Personal Data under Data Protection Laws.

4.       Subprocessors.

4.1    Workzone’s Subprocessors will be identified and may be updated by Workzone from time to time in accordance with this DPA. Customer authorizes Workzone Affiliates to act as Subprocessors and to use any identified Subprocessors subject to the terms and conditions of this Section 4.

4.2    Workzone will carry out appropriate due diligence on each Subprocessor and have a written agreement with each Subprocessor that includes provisions for Processing Customer Personal Data that are at least as protective as those set out in this DPA. 

4.3    In accordance with Data Protection Laws, Workzone is liable for Subprocessors’ acts and omissions, including a Subprocessor’s appointment of another Subprocessor.

5.       Data Subject Requests.

5.1    Workzone will provide Customer access to Customer Personal Data via the online Services to allow Customer to respond to Data Subject requests relating to Customer Personal Data.

5.2    Workzone will notify Customer in writing without undue delay, and in any event within 10 business days, following receipt and verification of any requests Workzone receives directly from a Data Subject relating to Customer Personal Data, and Workzone may only respond directly to a Data Subject request: (a) to confirm that such request relates to Customer; (b) as required by applicable law; or (c) with the written consent of Customer. Except as provided herein, Workzone, as processor, has no intention to respond to or fulfill any Data Subject requests.

5.3    At Customer’s written request and to the extent Customer is unable to access Customer Personal Data on its own, Workzone will provide reasonable assistance to Customer in accessing Customer Personal Data for Customer to respond to such Data Subject requests. To the extent legally permitted, Customer will be responsible for any expenses attributable to Workzone’s assistance efforts outside the normal course of business.

6.       Data Breach.

6.1    Workzone will notify Customer in writing without undue delay, and in any event within 72 hours, upon Workzone becoming aware of a Data Breach.

6.2    Workzone will investigate and, as necessary, mitigate or remediate a Data Breach in accordance with Workzone’s security incident policies and procedures (“Breach Management”).

6.3    Subject to Workzone’s legal obligations, Workzone will provide Customer with information available to Workzone as a result of its Breach Management, including the nature of the incident, specific information disclosed (if known), and any relevant mitigation efforts or remediation measures (“Breach Information”), for Customer to comply with its obligations under Data Protection Laws as a result of a Data Breach.  

6.4    If Customer requires specific information relating to a Data Breach in addition to the Breach Information, at Customer’s written request and to the extent Customer is unable to access the additional information on its own, Workzone will reasonably cooperate with Customer as requested by Customer to attempt to collect and provide such additional information.

7.      International Provisions.

7.1    The Parties acknowledge and agree that the Processing of Customer Personal Data by Workzone may involve an international transfer of Customer Personal Data from Customer to Workzone (“International Transfer”). Customer acknowledges that, as of the Effective Date, Workzone’s primary processing activities are in the United States.

7.2     To the extent that Workzone Processes Customer Personal Data originating from and protected by applicable Data Protection Laws in one of the Jurisdictions listed in Schedule 4 (Jurisdiction Specific Terms), then the terms specified therein with respect to the applicable jurisdiction(s) will apply in addition to the terms of this DPA.

7.3     To the extent that Customer’s use of the Services requires a valid transfer mechanism to lawfully transfer Customer Personal Data from a jurisdiction (i.e., the European Economic Area (“EEA”), the UK, Switzerland or any other jurisdiction listed in Schedule 4) to Workzone located outside of that jurisdiction (a “Transfer Mechanism”), the terms and conditions of Schedule 3 (Cross Border Transfer Mechanisms) will apply.

7.4     If any Transfer Mechanism fails as a lawful data transfer mechanism for an International Transfer, the Parties will act in accordance with Section 9.8 (Variations in Data Protection Laws) of this DPA.

8.      General.

8.1    Amendment; Waiver. Unless otherwise expressly stated herein, this DPA may be modified only by a written agreement executed by an authorized representative of each Party.  The waiver of any breach of this DPA will be effective only if in writing, and no such waiver will operate or be construed as a waiver of any subsequent breach. 

8.2    Severance. If any provision of this DPA is held to be unenforceable, then that provision is to be construed either by modifying it to the minimum extent necessary to make it enforceable (if permitted by law) or disregarding it (if not permitted by law), and the rest of this DPA is to remain in effect as written. Notwithstanding the foregoing, if modifying or disregarding the unenforceable provision would result in failure of an essential purpose of this DPA, the entire DPA will be considered null and void.

8.3    Order of Precedence. Regarding the subject matter of this DPA, in the event of any conflict between this DPA and any other written agreement between the Parties (including the Agreement), this DPA will govern and control. Any data processing agreements that may already exist between Parties are superseded and replaced by this DPA in their entirety. To the extent there is any conflict between the Standard Contractual Clauses and any other terms in this DPA, including Schedule 4 (Jurisdiction Specific Terms), the provisions of the applicable Standard Contractual Clauses will prevail.

8.4    Notices. Unless otherwise expressly stated herein, the parties will provide notices under this DPA in accordance with the Agreement, provided that all such notices may be sent via email.

8.5    Governing Law and Jurisdiction. Unless prohibited by Data Protection Laws, this DPA is governed by the laws stipulated in the Agreement and the Parties to this DPA hereby submit to the choice of jurisdiction and venue stipulated in the Agreement, if any, with respect to any dispute arising under this DPA.

8.6    Enforcement.  Regardless of whether Customer or its affiliate(s) or a third-party is a Controller of Customer Personal Data, unless otherwise required by law: (a) only Customer will have any right to enforce any of the terms of this DPA against Workzone; and (b) Workzone’s obligations under this DPA, including any applicable notifications, will be to only Customer. 

8.7    Liability. As between the Parties to this DPA, each Party’s liability and remedies under this DPA are subject to the aggregate liability limitations and damages exclusions set forth in the Agreement.

8.8    Variations in Data Protection Laws. If any variation is required to this DPA as a result of a change in or subsequently applicable Data Protection Law, then either Party may provide written notice to the other Party of that change in law. The Parties will then discuss and negotiate in good faith any variations to this DPA necessary to address such changes, with a view to agreeing and implementing those or alternative variations as soon as practicable, provided that such variations are reasonable with regard to the functionality and performance of the Services and Workzone’s business operations.

8.9    Reservation of Rights. Notwithstanding anything to the contrary in this DPA: (a) Workzone reserves the right to withhold information the disclosure of which would pose a security risk to Workzone or its customers or is prohibited by applicable law or contractual obligation; and (b) Workzone’s notifications, responses, or provision of information or cooperation under this DPA are not an acknowledgement by Workzone of any fault or liability.

8.10  Regulatory Requests. In the event Workzone is required by law or legal process to disclose Customer Personal Data, Workzone, to the extent legally permitted, agrees to give Customer prior notice of such disclosure to afford Customer a reasonable opportunity to appear, object, and obtain a protective order or other appropriate relief regarding such disclosure.



SCHEDULE 1: DETAILS OF PROCESSING OF CUSTOMER PERSONAL DATA

This Schedule 1 includes certain details of the Processing of Personal Data as required by Article 28(3) of the GDPR.

Subject matter and duration of the Processing of Personal Data:

  • The subject matter and duration of the Processing of Personal Data are set out in the Agreement and this DPA.

The nature and purpose of the Processing of Personal Data

  • Processing of Personal Data by Workzone is reasonably required to facilitate or support the provision of the Services as described under the Agreement and this DPA.

Type of Personal Data and Categories of Data Subjects:

  • The types of Personal Data and categories of Data Subject about whom the Personal Data relates are determined and controlled by Customer in its sole discretion. 

Obligations and Rights of the Controller:

  • The obligations and rights of Customer are set out in the Agreement and this DPA.


SCHEDULE 2: TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

 

Where applicable, this Schedule 2 will serve as Annex II to the Standard Contractual Clauses.

The full text of Workzone’s technical and organizational security measures is available at https://workzone.com/security/



SCHEDULE 3: CROSS BORDER TRANSFER MECHANISMS

1.       Definitions.

1.1    “Standard Contractual Clauses” means, depending on the circumstances unique to any particular Customer, any of the following:

  • 1.1.1    EEA Standard Contractual Clauses; and
  • 1.1.2    UK Standard Contractual Clauses.

1.2    “EEA Standard Contractual Clauses” or “Approved EU SCCs” means the Standard Contractual Clauses approved by the European Commission in decision 2021/914.

1.3    “UK Standard Contractual Clauses” means the template Addendum issued by the Information Commissioner’s Office (ICO) and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section ‎18.

2.      The EEA Standard Contractual Clauses.  For data transfers from the European Economic Area that are subject to the EEA Standard Contractual Clauses, the EEA Standard Contractual Clauses will apply in the following manner:

2.1   Module One (Controller to Controller) will apply where Workzone is processing online Services usage data as a Controller. For clarity, usage data is analytical statistical, learned, or technical information derived from a customer’s use of the Service that does not include or reveal the contents of Customer Content. Such data is owned by Workzone and used to provide support, secure, and/or defend the Services.

2.2   Module Two (Controller to Processor) will apply where Customer is a Controller of Customer Personal Data and Workzone is a Processor of Customer Personal Data;

2.3   For each module, where applicable:

  • 2.3.1    in Clause 7, the optional docking clause will not apply;
  • 2.3.2    in Clause 9, Option 2 will apply, and the process for providing notice and the time period for objections of sub-processor changes will be as set forth in Section 4 (Subprocessors) of this DPA;
  • 2.3.3    in Clause 11, the optional language will not apply;
  • 2.3.4    in Clause 17, the EEA Standard Contractual Clauses will be governed by the laws of Germany.
  • 2.3.5    in Clause 18(b), disputes will be resolved before the courts of Germany.
  • 2.3.6    In Annex I, Part A: 
  • 2.3.7    In Annex I, Part B: 
  • The categories of data subjects are described in Schedule 1.
  • The sensitive data transferred is described in Schedule 1.
  • The frequency of the transfer is a continuous basis for the duration of the Agreement.
  • The nature of the processing is described in Schedule 1.
  • The purpose of the processing is described in Schedule 1.
  • The period of the processing is described in Schedule 1.

  • 3.3.8    In Annex I, Part C: in accordance with clause 13, the competent supervisory authority is identified as follows:
  • Where the data exporter is established in an EU Member State: The supervisory authority with responsibility for ensuring compliance by the data exporter with Regulation (EU) 2016/679 as regards the data transfer shall act as competent supervisory authority.
  • Where the data exporter is not established in an EU Member State, but falls within the territorial scope of application of Regulation (EU) 2016/679 in accordance with its Article 3(2) and has appointed a representative pursuant to Article 27(1) of Regulation (EU) 2016/679: The supervisory authority of the Member State in which the representative within the meaning of Article 27(1) of Regulation (EU) 2016/679 is established shall act as the competent supervisory authority.
  • Where the data exporter is not established in an EU Member State, but falls within the territorial scope of application of Regulation (EU) 2016/679 in accordance with its Article 3(2) without however having to appoint a representative pursuant to Article 27(2) of Regulation (EU) 2016/679: Commission nationale de l’informatique et des libertés (CNIL) – 3 Place de Fontenoy, 75007 Paris, France shall act as the competent supervisory authority.
  • Where the data exporter is established in the United Kingdom or falls within the territorial scope of application of UK Data Protection Laws and Regulations, the Information Commissioner’s Office shall act as the competent supervisory authority.
  • Where the data exporter is established in Switzerland or falls within the territorial scope of application of Swiss Data Protection Laws and Regulations, the Swiss Federal Data Protection and Information Commissioner shall act as competent supervisory authority insofar as the relevant data transfer is governed by Swiss Data Protection Laws and Regulations.
  • 2.3.9    Schedule 2 serves as Annex II of the Standard Contractual Clauses. 

3.      The UK Standard Contractual Clauses.  For data transfers from the UK that are subject to the UK Standard Contractual Clauses, the UK Standard Contractual Clauses will apply in the following manner:  

  • 3.1    The EEA Standard Contractual Clauses, which are incorporated by reference into this DPA, will also apply to UK data transfers, subject to this Schedule 3.
  • 3.2   The UK Addendum will be deemed executed between the parties, and the EEA SCCs will be deemed amended as specified by the UK Addendum in relation to the UK data transfers.


SCHEDULE 4: JURISDICTION SPECIFIC TERMS

1.       United States.

1.1    The definition of “Data Protection Law” includes any federal or state data protection laws in effect and applicable to Workzone’s Processing of Customer Personal Data in the United States.

1.2    The terms “business”, “commercial purpose”, “service provider”, “sell”, and “personal information” have the meanings given in the applicable Data Protection Law and in the context of Customer Personal Data that is Processed pursuant to this DPA. 

1.3    With respect to Customer Personal Data, Workzone is a service provider under applicable Data Protection Law.

1.4    Workzone will not (a) sell or share Customer Personal Data; (b) retain, use, or disclose any Customer Personal Data for any purpose other than for the specific purpose of providing the Services, including retaining, using or disclosing the Customer Personal Data for a commercial purpose other than providing the Services, including to provide services to a different customer; (c) retain, use, or disclose the Customer Personal Data outside of the direct business relationship between Workzone and Customer; or (d) combine Customer Personal Data with other Personal Data that Workzone receives from another entity or collects from individuals, except as permitted by applicable law or as authorized by Customer.

1.5    The parties acknowledge and agree that the Processing of Customer Personal Data authorized by Customer’s instructions described in this DPA is integral to and encompassed by Workzone’s provision of the Services and the direct business relationship between the parties. Workzone agrees to inform Customer if, in its reasonable opinion, Workzone can no longer meet its applicable obligations under this Data Protection Law.

1.6    Notwithstanding anything in the Agreement or any Order Form entered in connection therewith, the parties acknowledge and agree that Workzone’s access to Customer Personal Data does not constitute part of the consideration exchanged by the parties in respect of the Agreement.

1.7    To the extent that any online Services usage data is considered Customer Personal Data, Workzone is the business with respect to such data and will Process such data in accordance with its Privacy Notice. For clarity, usage data is analytical statistical, learned, or technical information derived from a customer’s use of the Service that  does not include or reveal the contents of Customer Content. Such data is owned by Workzone and used to provide support, secure, and/or defend the Services.

1.8    Remediation Requirements. Customer shall have the right to take reasonable and appropriate steps to (a) verify that Workzone uses the personal information that it received from, or on behalf of, Customer in a manner consistent with this DPA so that Customer can meet its obligations under Data Protection Law. This right may encompass performing Customer Audits in accordance with this DPA; (b) stopping and remediating Workzone’s unauthorized use of Customer Personal Data; and (c) taking any such other remediation efforts reasonably agreed upon by the parties. By way of example, and in accordance with the Agreement, Customer may require Workzone to provide documentation that verifies that Workzone no longer retains or uses Customer personal information of Data Subjects who have made a valid request of Customer to delete their personal information.

1.9    Certification. Workzone certifies that it understands and will comply with the obligations set forth in this the DPA and the Agreement, including the restrictions on its Processing of Customer personal information.

2.      EEA.

2.1     The definition of “Data Protection Laws” includes the General Data Protection Regulation (EU 2016/679) (“GDPR”).

2.2     When Workzone engages a Subprocessor, it will:

  • 2.2.1    require any appointed Subprocessor to protect Customer Personal Data to the standard required by applicable Data Protection Laws, such as including the same data protection obligations referred to in Article 28(3) of the GDPR, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the GDPR; and
  • 2.2.2    require any appointed Subprocessor to agree in writing to only process data in a country that the European Union has declared to have an “adequate” level of protection; or to only process data on terms equivalent to the Standard Contractual Clauses.

2.3    GDPR Penalties. Notwithstanding anything to the contrary in this DPA or in the Agreement (including, without limitation, either party’s indemnification obligations), neither party will be responsible for any GDPR fines issued or levied under Article 83 of the GDPR against the other party by a regulatory authority or governmental body in connection with such other party’s violation of the GDPR.

3.      Switzerland.

3.1    The definition of “Data Protection Laws” includes the Swiss Federal Act on Data Protection.

3.2   When Workzone engages a Subprocessor, it will

  • 3.2.1    require any appointed Subprocessor to protect Customer Personal Data to the standard required by applicable Data Protection Laws, such as including the same data protection obligations referred to in Article 28(3) of the GDPR, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the GDPR; and
  • 3.2.2    require any appointed Subprocessor to agree in writing to only process data in a country that the European Union has declared to have an “adequate” level of protection; or to only process data on terms equivalent to the Standard Contractual Clauses.

3.3    To the extent allowed and required by the Swiss Federal Act on Data Protection, a Data Subject may bring legal proceedings against the data exporter and/or data importer before the courts of Switzerland.

3.4    To the extent required by the version of the Swiss Federal Act on Data Protection then in effect, the applicability of the Standard Contractual Clauses will be interpreted to include data pertaining to legal entities as Customer Personal Data.

4.      United Kingdom.

4.1     References in this DPA to GDPR will to that extent be deemed to be references to the corresponding laws of the United Kingdom (including the UK GDPR and Data Protection Act 2018).

4.2     When Workzone engages a Subprocessor, it will

  • 4.2.1    require any appointed Subprocessor to protect Customer Personal Data to the standard required by applicable Data Protection Laws, such as including the same data protection obligations referred to in Article 28(3) of the GDPR, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the GDPR; and
  • 4.2.2    require any appointed Subprocessor to agree in writing to only process data in a country that the European Union has declared to have an “adequate” level of protection; or to only process data on terms equivalent to the Standard Contractual Clauses.
     

Last Updated: September 1, 2023