Data Processing Addendum
This pack contains 18 working-draft legal documents. None of them have been reviewed by Texas counsel or counsel licensed in any other jurisdiction. They are a starting point for a real attorney engagement, not a finished publication. Brackets [highlight] indicate custom options to finalize.
This Data Processing Addendum ("DPA") supplements the Terms of Service or Master Services Agreement (the "Agreement") between SiteFlows, LLC ("Processor," "SiteFlows") and the Operator (the "Controller," "Customer") and applies to SiteFlows' processing of Personal Data on behalf of the Controller in connection with the Service.
1. Definitions
Capitalized terms not defined here have the meaning given in the Agreement or in applicable Data Protection Laws. "Personal Data" means information relating to an identified or identifiable natural person processed by SiteFlows on behalf of the Controller. "Data Protection Laws" means all applicable federal and state laws relating to the processing of Personal Data, including the CCPA/CPRA, the Texas Data Privacy and Security Act, and (where applicable) the EU/UK GDPR.
2. Roles & Scope
The Controller is the controller (or "business" under CCPA/CPRA) of Personal Data submitted to the Service. SiteFlows is the processor (or "service provider" under CCPA/CPRA). Where SiteFlows is acting as a controller for its own purposes (e.g., billing, fraud prevention), its Privacy Policy applies.
3. Processing Instructions
SiteFlows processes Personal Data only on documented instructions from Controller, as set forth in the Agreement, this DPA, and the configuration of the Service. SiteFlows will not retain, use, disclose, or sell Personal Data outside the direct business relationship with Controller, and will not combine Personal Data with personal data from other sources except as permitted under the CCPA service-provider exception.
4. Sub-Processors
Controller authorizes SiteFlows to engage the sub-processors listed in the Sub-processor List (Annex III) to process Personal Data. SiteFlows imposes contractual obligations on each sub-processor that are no less protective than those in this DPA. SiteFlows will provide at least 30 days' advance notice of any new sub-processor; Controller may object on reasonable grounds, in which case the parties will work in good faith to resolve, and Controller may terminate the affected portion of the Service if no resolution is reached.
5. Security Measures
SiteFlows will implement and maintain the technical and organizational security measures described in Annex II of this DPA, which are at least equivalent to those described in our Trust & Security documentation.
6. Data Subject Requests
SiteFlows will assist Controller in responding to verifiable consumer or data-subject requests by providing tools and information needed to fulfill access, deletion, correction, and portability requests. SiteFlows will forward to Controller any data-subject request received directly by SiteFlows that relates to Personal Data processed on behalf of Controller.
7. Breach Notification
SiteFlows will notify Controller without undue delay and no later than 72 hours after becoming aware of a Personal Data Breach affecting Controller's Personal Data. Notification will include the nature and scope of the breach, categories and approximate number of data subjects affected, contact information for SiteFlows' security team, and the measures taken or proposed to address the breach.
8. International Transfers
The Service is operated from the United States. If Personal Data of EU/UK data subjects is transferred to SiteFlows, the parties will execute the Standard Contractual Clauses (Module Two: Controller-to-Processor) and the UK International Data Transfer Addendum, which are incorporated by reference. [Counsel: confirm SCC trigger threshold and whether an addendum execution is needed at launch]
Customer will defend SiteFlows against any third-party claim arising from Customer Data, Customer's violation of law, Customer's misuse of the Service, or Customer's relationship with its workers or customers (including worker-classification claims), and will pay any final judgment or settlement, subject to SiteFlows' prompt notice and sole control of defense.
9. Audit
SiteFlows will make available to Controller, upon reasonable request and no more than annually, information necessary to demonstrate compliance with this DPA, including SOC 2 Type II reports (when issued), penetration test summaries (with sensitive details redacted), and security policy summaries. On-site audits are permitted only if remote alternatives are insufficient and at Controller's expense, with at least 30 days' notice and a mutually-agreed scope.
10. Return & Deletion
Within 30 days of termination of the Agreement, SiteFlows will, at Controller's election, delete or return all Personal Data, except as required by law to retain. Backups containing Personal Data will be deleted in the ordinary backup expiration cycle (up to 35 days).
11. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Agreement. Nothing in this DPA limits liability that cannot be limited under applicable law.
Annexes
| Item | Description |
|---|---|
| Subject matter | Provision of the SiteFlows SaaS service to Operators. |
| Duration | For the term of the Agreement plus any retention period required by law. |
| Nature & purpose | Hosting, storing, transmitting, displaying, and analyzing Personal Data to operate the Service. |
| Data categories | Identification (name, email), contact, employment / engagement, payment / payout, geolocation (during active jobs only), photo metadata, dispute statements. |
| Data subjects | Operators, Workers, Operator's end customers (limited fields), site visitors. |
| Frequency | Continuous. |
Annexes
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Least-privilege access controls, MFA on all production access.
- Tenant isolation enforced at the application and database layers.
- Audit logging of administrative actions, retained 13 months.
- Vulnerability management, including dependency scanning and quarterly penetration testing (post-Series A target).
- Background checks and confidentiality agreements for personnel with production access.
- Documented incident response plan with 24-hour internal escalation, 72-hour customer notification target.
- Backup and disaster recovery: daily encrypted backups, 35-day retention, tested quarterly.
Annexes
See Sub-processor List, which is incorporated into this Annex by reference.