1. Definitions
- Personal Data means information in Customer Content that identifies or relates to an identified or identifiable person.
- Data Protection Laws means the privacy and data protection laws that apply to the processing, including the California Consumer Privacy Act as amended and other U.S. state privacy laws.
- Security Incident means a breach of security that leads to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data.
- Sub-processor means a third party we engage that processes Personal Data for us.
- Other capitalized terms have the meaning given in the Terms.
2. Roles and instructions
- The Customer is the controller (a "business" under the CCPA) and ANNEX ORBIS is the processor (a "service provider" or "contractor").
- We process Personal Data only to provide, secure and support the Services, on the Customer's documented instructions. The Terms, this DPA and the Customer's configuration and use of the Services are those instructions. If we believe an instruction breaks Data Protection Laws, we will tell the Customer.
- We will not sell or share Personal Data, retain, use or disclose it for any purpose other than providing the Services, or combine it with personal information we receive from others, except as Data Protection Laws allow a service provider to do. We may create de-identified data as the Terms describe, and will not attempt to re-identify it.
- The Customer is responsible for having a lawful basis, giving required notices and obtaining required consents for the processing it instructs.
3. Details of the processing
| Item | Description |
|---|---|
| Subject matter and duration | Providing the Services for the term of the Terms, and until deletion under section 9 |
| Nature and purpose | Hosting, storage, transmission, organization, retrieval, analysis and display of Customer Content to operate the features the Customer uses |
| Categories of individuals | The Customer's Users, employees, drivers, applicants, contractors, customers, contacts, message and call participants, meeting guests and document signers |
| Categories of Personal Data | Contact and identity details; communications content and metadata; files and signatures; employment, pay, benefits, leave and compliance records; background screening records; location and device data; financial and bank transaction data; and other data the Customer chooses to process |
| Sensitive data | As the Customer chooses to process it, which may include precise location, government identification status, health and accommodation records, and voluntary EEO information |
4. Confidentiality and personnel
We give access to Personal Data only to personnel who need it to provide the Services, and each is bound by confidentiality obligations.
5. Security
We maintain technical and organizational measures appropriate to the risk, including:
- encryption of data in transit with TLS 1.2 or higher;
- encrypted database disks, AES-256 encryption of database backups, and encryption at rest for stored objects;
- passkey authentication, step-up verification, role-based access and database row-level security that separates each Customer's data;
- restricted, key-only administrative access to servers, firewalls and daily configuration checks;
- security and audit logging; and
- daily backups with restoration tested every week.
We may update these measures as long as the update does not reduce overall protection.
6. Sub-processors
- The Customer authorizes us to use the Sub-processors on our Sub-processors page.
- We bind each Sub-processor to data protection obligations at least as protective as this DPA, and we remain responsible for its performance.
- We will update that page, and email Customers who have asked privacy@annexorbis.com for notice, at least 15 days before a new Sub-processor processes Personal Data. The Customer may object on reasonable data protection grounds within that period; if we cannot address the objection, the Customer may terminate the affected Services and receive a refund of prepaid fees for the unused period.
7. Assistance
- If an individual sends us a request about Personal Data in Customer Content, we will refer them to the Customer and not respond ourselves unless the Customer asks us to or the law requires it.
- We will help the Customer respond to individuals' requests, largely through the Services' own tools for viewing, correcting, exporting and deleting data.
- We will give reasonable help with the Customer's data protection assessments and with inquiries from regulators about our processing.
8. Security Incidents
We will notify the Customer without undue delay, and no later than 72 hours after confirming a Security Incident affecting its Personal Data. The notice will describe what happened, the data and individuals affected as far as known, and the steps we are taking, and we will update it as we learn more. We will take reasonable steps to contain the incident and help the Customer meet its own notification obligations. Notifying the Customer is not an admission of fault.
9. Return and deletion
When the Terms end, the Customer may export its Personal Data or request a copy for 30 days. Within 90 days after that, we delete Personal Data from our active systems, and it expires from backups within 7 more days, except where the law requires us to keep it. Details are in our Data Retention and Deletion Policy. On request, we will confirm the deletion in writing.
10. Audits
On written request, no more than once a year (or after a Security Incident), we will provide information reasonably necessary to show compliance with this DPA, such as answers to a security questionnaire and descriptions of our controls. If that is not enough to satisfy a requirement of Data Protection Laws, the Customer may conduct an audit at its own expense, on 30 days' notice, during business hours, in a way that does not disrupt the Services or expose other customers' data, under confidentiality obligations.
11. Location of processing
We host and process Personal Data in the United States. Some Sub-processors operate global networks, as described on the Sub-processors page. The Services are offered to U.S. businesses; a Customer that needs to transfer Personal Data from the European Economic Area, United Kingdom or Switzerland must contact legal@annexorbis.com before doing so so that appropriate transfer terms can be agreed.
12. General
This DPA lasts as long as we process Personal Data for the Customer. Each party's liability under it is subject to the limitations in the Terms, except where Data Protection Laws do not allow them. We may update this DPA to reflect changes in law or in the Services, with notice as the Terms describe, provided the update does not reduce the Customer's protection. To request a countersigned copy, email legal@annexorbis.com.