Data Processing Addendum
Eddy Works Data Processing Addendum — processor terms for EU, UK, and NZ data protection law, international transfers, subprocessors, and breach notification.
Key correction: The draft required a signed return before EU/UK processing. The decided direction is an automatic addendum (Xero pattern) — the Data Processing Addendum is incorporated by reference and accepted at signup. No signed return or countersignature step.
What this means
The plain-English summaries in each section ("What this means") are for ease of reading only. They are not legally binding. The full clauses above each summary govern.
1. Incorporation and acceptance
This Data Processing Addendum ("DPA") forms part of the Terms of Use between Eddy Works Limited ("Eddy Works", "Processor") and the Customer ("Controller") and is incorporated by reference into those Terms.
This DPA is accepted automatically when the Customer accepts the Terms of Use. No separate signed return or countersignature is required. The act of accepting the Terms of Use at signup (or for existing customers, continued use of the Service after this DPA takes effect) constitutes the Customer's acceptance of this DPA.
This DPA applies where Eddy Works processes personal data on behalf of the Customer in connection with the Service, and that processing is subject to GDPR, UK GDPR, the Swiss Federal Act on Data Protection (FADP), the NZ Privacy Act 2020, or equivalent legislation.
In the event of any conflict between this DPA and the Terms of Use in relation to data-protection matters, this DPA takes precedence.
What this means
This DPA is the formal agreement governing how we handle personal data on your behalf. It applies automatically when you accept the Terms of Use — no separate signing process is needed. If you are processing personal data of people in the EEA, UK, or New Zealand, this DPA applies to that processing. If it conflicts with the Terms of Use on a data-protection point, this DPA wins.
2. Definitions
Terms used in this DPA have the meanings given in the Definitions, the Privacy Policy, the Terms of Use and, where applicable, in the GDPR. In addition:
"Applicable Data Protection Law" means the GDPR (General Data Protection Regulation (EU) 2016/679), the UK Data Protection Act 2018 and UK GDPR as that term is defined in that Act, the Swiss Federal Act on Data Protection (FADP), the NZ Privacy Act 2020, and any equivalent laws that apply to the processing under this DPA.
"Personal Data" means any information relating to an identified or identifiable natural person that is processed by Eddy Works on behalf of the Customer under this DPA.
"Processing" (and its derivatives) has the meaning given in the GDPR.
"Sub-processor" means any third party engaged by Eddy Works to process Personal Data on behalf of the Customer.
"Security Incident" means a breach of security leading to any accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Personal Data.
What this means
Key terms defined for this document: "Personal Data" is information about an identifiable person; "Sub-processor" is a third-party supplier we use that touches that data; "Security Incident" is any breach or unauthorised access.
3. Dual roles
The parties acknowledge that Eddy Works acts in two roles simultaneously:
- Processor — for Customer Content, Map Configuration, and Process Execution State: the Customer is the controller and Eddy Works processes those data categories on behalf of the Customer. The same applies where we are a data sub-processor when a Customer is itself a processor for its own clients' data, and uses Eddy to store and process that data.
- Controller — for account data, Usage Telemetry, Process Metadata, and Analytical Data (to the extent that data is, or contains, Personal Data): Eddy Works determines the purposes and means of processing and is the controller for those categories. The Privacy Policy governs Eddy Works' processing as controller.
This DPA governs Eddy Works' processing as Processor only. Each category of data and the applicable role are set out on the Data categories and subjects page.
Where Eddy Works is a Controller for any data category, it processes that data as described in the Privacy Policy and is not acting on the Customer's instructions for those categories.
What this means
Eddy Works plays two roles at the same time. For data that goes through your Maps and Sessions (Customer Content, process designs, execution state), you are the controller and we are the processor — we follow your instructions. For account data and platform analytics, we are the controller — the Privacy Policy covers that. This DPA only governs the processor role.
4. Processing instructions
The nature and purpose of the processing, the types of Personal Data and categories of data subjects processed under this DPA are set out in Data categories and subjects.
Eddy Works will process Personal Data only on the documented instructions of the Customer, as set out in the Terms (including this DPA), unless required to process for other purposes by applicable law. In that case, Eddy Works will inform the Customer before processing, unless the law prohibits notification. The Customer instructs Eddy Works to process Personal Data as reasonably necessary to provide the Services in accordance with the Terms. This DPA and the other Terms are the Customer's complete instructions as at the time this DPA takes effect. Any additional or alternate instructions must be agreed between Eddy Works and the Customer separately in writing.
The Customer warrants that it has complied with all Applicable Data Protection Law in instructing Eddy Works to process Personal Data on the terms contemplated by this DPA. The Customer also warrants that is has a lawful basis for each category of Personal Data it instructs Eddy Works to process, and that it has provided all required notices to, and secured all necessary consents and permissions from, data subjects.
If Eddy Works reasonably believes that an instruction from the Customer would breach Applicable Data Protection Law, it will notify the Customer promptly. Eddy Works may suspend processing of that instruction pending resolution.
What this means
We process data only as you instruct us to (as set out in these agreements), unless the law requires otherwise. You are responsible for having a lawful basis for what you ask us to process and for notifying the people whose data it is. If we think an instruction would break the law, we will tell you and may pause that processing.
5. Confidentiality obligations of our personnel
Eddy Works will ensure that members of our personnel authorised to process Personal Data under this DPA are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
Eddy Works will limit access to Personal Data to members of our personnel who need it to perform the Service and otherwise as strictly necessary for the purpose of exercising Eddy Works' rights and performing Eddy Works' obligations under the Terms (including this DPA).
What this means
Eddy Works staff who can access your data are bound by confidentiality obligations. Access is limited to people who need it to deliver the Service.
6. Security
Eddy Works will implement and maintain appropriate technical and organisational measures ("TOMs") to protect the confidentiality, integrity and security of Personal Data (including protection against unauthorised or unlawful processing and against accidental or unlawful destruction, loss or alteration or damage, unauthorised disclosure of, or access to, Personal Data), and to manage Security Incidents affecting Personal Data, taking into account the nature of the processing and the risk to data subjects.
The TOMs in effect at the date of this DPA are described at Security. Eddy Works may update TOMs from time to time provided the updated measures do not materially reduce the level of protection.
Eddy Works will provide reasonable cooperation and assistance to the Customer in meeting its security obligations under Applicable Data Protection Law.
What this means
We maintain documented technical and organisational security measures (TOMs) appropriate to the risk. We can update them, but not in a way that weakens protection. We will cooperate if you need to conduct a data protection impact assessment.
7. Security incidents
Eddy Works will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a Security Incident affecting Personal Data processed under this DPA.
The notification will include, to the extent then available, information reasonably necessary to allow the Customer to comply with its own obligations under Applicable Data Protection Law with respect to the Security Incident. That information may include, to the extent then available: the nature of the Security Incident; the categories and approximate number of data subjects and records affected; the likely consequences; and the measures taken or proposed to address the incident.
Eddy Works will make reasonable efforts to cooperate with the Customer's investigation and provide reasonable updates as further information becomes available. Eddy Works will make reasonable efforts to identify the cause of the Security Incident, cooperate with the Customer in good faith, and provide any assistance reasonably necessary for the Customer to comply with its obligations under Applicable Data Protection Law with respect to the Security Incident, including obligations the Customer may have under Applicable Data Protection Law to report, notify, or investigate the Security Incident. Eddy Works will take steps it considers necessary and reasonable to remediate the cause of the Security Incident, to the extent remediation is within its reasonable control.
The Customer remains responsible for notifying supervisory authorities and affected data subjects as required by Applicable Data Protection Law.
What this means
If there is a data breach affecting your data, we will notify you within 72 hours of becoming aware of it, with as much detail as we have. We will cooperate with your investigation. You remain responsible for notifying your regulator and any affected individuals.
8. Sub-processors
The Customer grants a general written authorisation for Eddy Works to engage Sub-processors to assist in providing the Service, subject to the conditions in this clause.
The current list of Sub-processors is maintained at Subprocessors. Eddy Works will keep this list up to date.
Eddy Works will give the Customer at least 30 days' notice of any intended addition or replacement of a Sub-processor (Change Notice). The Customer may object on reasonable data-protection grounds by notifying Eddy Works within 10 days of the Change Notice, explaining the grounds. The parties will discuss the objection in good faith with a view to resolving it in a commercially reasonable manner. If the objection cannot be resolved and Eddy Works does not revoke the Change Notice before it takes effect, the Customer may terminate the affected part of the Service without penalty. If the Customer does not terminate in accordance with this clause, it is deemed to have agreed to the new Sub-processor.
Notwithstanding clause 8.3, Eddy Works may replace a Sub-processor without prior notice where the replacement is necessary to address a security risk or service continuity issue, provided that Eddy Works notifies the Customer as soon as reasonably practicable after the replacement and provides the Customer with the same rights to object as under clause 8.3.
Eddy Works has entered into (and will, for any new Sub-processor, enter into) written agreements with each Sub-processor containing data-protection obligations which offer at least the same level of protection for Personal Data as set out in this DPA and that meet the requirements of Article 28(3) of the GDPR, Article 28(3) of the UK GDPR, and/or equivalent requirements of other Applicable Data Protection Law, as applicable to the nature of the services provided by that Sub-processor. Eddy Works is liable for the acts and omissions of its Sub-processors to the same extent it would be liable if performing the services of each Sub-processor directly under this DPA, except as otherwise set out in this DPA.
What this means
By accepting these terms, you authorise us to use the sub-processors listed on the Subprocessors page. We will give you at least 30 days' notice before adding or replacing any sub-processor, and you can object. In an emergency (security risk or service continuity), we may replace a sub-processor immediately and notify you as soon as practicable afterwards. We require sub-processors to meet the same standards as this DPA, and we remain accountable to you for their performance.
9. Data subject rights
Taking into account the nature of the processing, Eddy Works will assist the Customer by implementing appropriate technical and organisational measures, to the extent possible, to fulfil the Customer's obligation to respond to data-subject requests under Applicable Data Protection Law (including, where applicable, rights of access, rectification, erasure, restriction, portability, and objection).
The Customer is the primary point of contact for data-subject requests relating to Personal Data forming part of Customer Content. To the extent permitted by law, Eddy Works will forward to the Customer any requests of that kind that it receives directly from data subjects within 5 business days.
Contact data-subject requests: A "Contact" is a person named in Customer Content (e.g. in a form response) who is not an Eddy user. Eddy Works has no direct mechanism to locate or act on data-subject requests from Contacts — Contact data appears as unstructured text in cell values with no foreign-key link to a user record. The Customer (as controller) is responsible for responding to Contact data-subject requests without independent instruction from Eddy Works. We will comply with our obligations under Applicable Data Protection Law to assist the Customer (as controller), to the extent technically feasible.
Eddy Works will not respond to data-subject requests on behalf of the Customer except as instructed in writing by the Customer or if required by applicable law.
What this means
If someone whose data is in your Maps asks to access, correct, or delete it, you are the primary contact — we will help you respond. If someone contacts us directly, we will pass the request to you promptly. Note: for people named in form responses who are not Eddy users ("Contacts"), we have no automated way to locate their data — you will need to handle those requests as the controller.
10. Assistance and audits
Upon Customer's written request, Eddy Works will provide the Customer with reasonable assistance in: (a) responding to data-subject requests; (b) notifying supervisory authorities; (c) completing data protection impact assessments (DPIAs); (d) demonstrating compliance with this DPA.
Eddy Works will maintain records of processing activities to the extent required by Article 30 GDPR and make them available to the relevant Customer to whom the GDPR applies on request.
Upon the Customer's written request, Eddy Works will, at the Customer's cost, submit to the Customer's audits or inspections and provide all information necessary to demonstrate compliance with obligations under Applicable Data Protection Law (including obligations under Article 28 of the GDPR and/or Article 28 of the UK GDPR). The Customer must give reasonable advance notice (at least 30 days), conduct no more than one audit per calendar year during Eddy Works' business hours, and comply with Eddy Works' reasonable security and confidentiality requirements (and procure its auditor to do the same). Eddy Works may satisfy this obligation by providing a current third-party audit report (e.g. SOC 2 Type II) where available, except where an audit is required due to a confirmed Security Incident.
What this means
We will cooperate with your compliance obligations — helping with DPIAs, regulator notifications, and data-subject requests. You can audit our compliance once a year with 30 days' notice (at your cost); we can substitute a current third-party audit report (e.g. SOC 2). We keep Article 30 records and make them available on request.
11. International transfers
Eddy Works will not transfer Personal Data processed under the Terms and this DPA internationally unless that transfer is compliant with Applicable Data Protection Law.
Where the Applicable Data Protection Law of the EEA, Switzerland or the UK apply to the processing of Personal Data under the Terms and this DPA, Eddy Works will not transfer Personal Data to a country outside the EEA or UK unless: (a) the transfer is to a country with an adequacy decision; (b) it is covered by EU Standard Contractual Clauses (SCCs), a UK International Data Transfer Agreement (IDTA) or the UK addendum to the SCCs, as applicable; or (c) another lawful transfer mechanism applies.
For transfers within the Sub-processor list that occur outside the EEA/UK and which involve transfers where an adequacy decision cannot be relied upon, Eddy Works will ensure that appropriate SCCs or equivalent safeguards are in place.
NZ adequacy: New Zealand has an EU adequacy decision under GDPR and has also been recognised as providing adequate protection for the purposes of restricted transfers under the UK GDPR. Transfers between the EU/EEA, the UK and NZ (Eddy Works' jurisdiction) are therefore covered by adequacy. To the extent that any transfer of Data from the Customer to Eddy Works is restricted under the GDPR or UK GDPR and is not covered by an adequacy decision, (i) the EU Standard Contractual Clauses and the UK addendum to the EU Standard Contractual Clauses are incorporated into this DPA as set out in clause 15; and (ii) by entering into this DPA, the Customer and Eddy Works is each deemed to have signed the relevant EU Standard Contractual Clauses and UK addendum (including their Annexes).
What this means
We will not move your data outside the EEA or UK unless there is a legal basis to do so — an adequacy decision (New Zealand has one) or Standard Contractual Clauses with the relevant sub-processor. If your transfer of Personal Data to us needs to be covered by the EU Standard Contractual Clauses or the UK addendum to the EU Standard Contractual Clauses, they are incorporated into this DPA on the terms set out in clause 15 and are deemed to be signed by Eddy Works and you.
12. Return and deletion of data
On termination of the Terms of Use, or on the Customer's written request, Eddy Works will: (a) return or provide an export of Customer Content in a machine-readable format upon the Customer's request in accordance with the Terms of Use; and (b) delete Personal Data processed under this DPA in accordance with the Terms of Use, subject to any retention required by applicable law or for dispute resolution.
Where the Customer has requested deletion, Eddy Works will confirm to the Customer in writing when deletion is complete.
Eddy Works may retain anonymised or aggregated data derived from Customer processing after termination, provided it no longer constitutes Personal Data.
If Eddy Works cannot delete all Personal Data due to technical reasons, it will inform the Customer as soon as reasonably practicable and will take reasonably necessary steps to: (a) come as close as possible to a complete and permanent deletion of the Personal Data; (b) fully and effectively anonymise the remaining data; and (c) make the remaining Personal Data which is not deleted or effectively anonymised unavailable for future processing.
What this means
When your subscription ends or on request, we will export your data in a machine-readable format and delete the personal data we hold as processor. If you requested the deletion, we will confirm in writing when it is done. We may retain anonymised or aggregated data that cannot be linked back to individuals.
13. Liability
Each party's liability under this DPA is subject to the limitations set out in clause 17 of the Terms of Use.
Eddy Works' liability under this DPA will be reduced to the extent that the Customer is responsible for a Security Incident or other data-protection breach or issue giving rise to liability under this DPA.
What this means
Liability under this DPA follows the same caps as in the Terms of Use. If a breach is partly our fault and partly yours, our liability is reduced to the extent that you are responsible.
14. Changes in data protection laws
Eddy Works may, on at least 30 days' written notice to the Customer, make variations to this DPA (including to the construction of the Standard Contractual Clauses) which it reasonably considers are required as a result of any change in, or decision of a competent authority under, Applicable Data Protection Law, in order to allow transfers and processing of Personal Data to continue without breach of that law.
If the Customer objects to a variation under clause 14.1 on reasonable grounds, the Customer may terminate the Terms and its access to the Service without penalty on written notice, provided that notice is received before the effective date of the variation. If the Customer does not terminate in accordance with this clause, it is deemed to have agreed to the variation.
What this means
If data-protection law changes and we need to update this DPA to stay compliant, we will give you at least 30 days' notice. If you disagree with the change, you can terminate without penalty before it takes effect.
15. GDPR Standard Contractual Clauses and UK GDPR Addendum to Standard Contractual Clauses
SCCs governing international transfers of EU/EEA Personal Data:
If clause 11.4 applies, the EU Standard Contractual Clauses approved by the European Commission in Commission Decision (EU) 2021/914 dated 4 June 2021, as updated from time to time (SCCs), are incorporated into this DPA on the terms set out below:
- Module 2 (Controller to Processor) applies where the Customer is the Controller.
- Module 3 (Processor to Processor) applies where the Customer is itself a Processor on behalf of its own clients.
- The data importer is Eddy Works.
- The data exporter is the Customer.
- The Customer's acceptance of the Terms of Use constitutes acceptance of, and entry into, the SCCs where applicable.
- The optional docking clause in clause 7 applies.
- Option 2 (General Written Authorisation) applies to Clause 9 of the SCCs. Sub-processor changes are notified in accordance with clause 8.3 of this DPA.
- The optional provision at Clause 11(a) of the SCCs (independent dispute-resolution body) does not apply.
- In Clause 13 (Supervision), all square brackets are removed with the text remaining.
- In Clause 17 (Governing law), Option 1 applies and the governing law is the law of the Republic of Ireland.
- In Clause 18 (Choice of forum and jurisdiction), disputes arising from the SCCs will be resolved by the courts of the Republic of Ireland.
- This DPA and the Schedules linked below otherwise contain the information required in Annex 1 and 2 of the SCCs. The data importer's address for notices is as determined in accordance with the Terms. Part C of Annex 1 of the SCCs will be deemed to be completed in accordance with Clause 13(a) of the SCCs.
SCCs governing international transfers of UK Personal Data:
If clause 11.4 applies, the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B1.0, in force 21 March 2022, as may be amended, superseded or replaced from time to time) is incorporated into this DPA on the terms set out below:
- The EU SCCs completed as described above apply, as modified by the UK Addendum and with the particular modifications set out in the remainder of this clause.
- The information populated in the EU SCCs in accordance with the section above will apply to tables 1 to 3 of the UK Addendum.
- In table 4 of the UK Addendum, the data importer and the data exporter may end the UK Addendum as set out in section 19 of the UK Addendum.
- The mandatory clauses of the UK Addendum are incorporated by reference into this DPA in accordance with "Alternative Part 2: Mandatory Clauses" in the UK Addendum. Those mandatory clauses are the mandatory clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.
Schedules
| Schedule | Content | Location |
|---|---|---|
| 1 | Data subjects & categories | Data categories and subjects |
| 2 | Sub-processors | Subprocessors |
