Data Processing Addendum
COMPENSIA, INC.
DATA PROCESSING ADDENDUM
Compensia, Inc., a California corporation, whose principal place of business is at 548 Market Street, PMB# 55353, San Francisco, California 94104-5401 (“Compensia”) and the counterparty agreeing to these terms (“Company”) have entered into a letter agreement, or other written or electronic agreement (each, the “Main Agreement”) for the provision of Compensia’s compensation consulting services (collectively, the “Services”) provided by Compensia. This Data Processing Addendum (the “DPA”) forms part of the Main Agreement.
This DPA will be effective and replace any previously applicable terms relating to their subject matter (including any data processing agreement or addendum relating to the Services), from the date on which Company accepted this DPA.
If you are accepting this DPA on behalf of Company, you warrant that: (a) you have full legal authority to bind Company to this DPA; (b) you have read and understand this DPA; and (c) you agree, on behalf of Company, to this DPA. If you do not have the legal authority to bind Company, do not accept this DPA.
The parties have agreed to enter into this DPA in order to ensure that adequate safeguards are put in place with respect to the protection of Personal Data as required by data protection laws, rules, and regulations to the extent applicable (“Data Protection Laws“).
1. Definitions
2. Roles and Compliance with Data Protection Laws
3. Security
4. Information and Audits.
5. Additional Processing Terms
6. Subprocessors
7. International Transfers
8. Access Requests and Data Subject Rights
9. Data Protection Impact Assessments and Prior Consultation
10. Retrieval and Deletion of Company Personal Data
11. General
Company
Compensia, Inc.
SCHEDULE 1
APPENDIX TO THE STANDARD CONTRACTUAL CLAUSES
ANNEX I
ANNEX I.A – LIST OF PARTIES
Data exporter(s) name, contact person’s name, position and contact details: See Main Agreement.
Activities relevant to the data transferred under these Clauses: Data importer provides Services to data exporter as set forth in the Main Agreement.
Signature and date: See Main Agreement.
Role (controller/processor): Controller.
Data importer name, contact person’s name, position and contact details: Compensia, Inc., 548 Market Street, PMB# 55353, San Francisco, CA 94104-5401.
Contact: privacy@Compensia.com.
Activities relevant to the data transferred under these Clauses: Data importer Processes Company Personal Data to provide the Services to data exporter as set forth in the Main Agreement.
Signature and date: See Main Agreement.
Role (controller/processor): Processor.
ANNEX I.B – DESCRIPTION OF TRANSFER
- Categories of data subjects whose personal data is transferred: Potential and current personnel of data exporter, employees of data exporter.
- Categories of personal data transferred: Name, email, telephone number, job title, business address, and compensation information.
- Sensitive categories of data (if appropriate): None.
- The frequency of the transfer: Continuous.
- Nature of the processing: Provision of the Services.
- Purposes of the data transfer and further processing: Refer to DPA.
- The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Personal Data will be processed for the duration of the Agreement, subject to Section 10 of the DPA.
- For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: Refer to DPA and the Main Agreement
ANNEX I.C – COMPETENT SUPERVISORY AUTHORITY
The data protection authority competent for the Data Exporter or, if the Data Exporter is not established in the European Union or has not appointed a representative in the European Union, is the data protection authority competent for the data subjects whose personal data are transferred under the clauses.
ANNEX II
TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA:
- Administrative controls
- Security education, training, and awareness program – data importer trains all employees on hire and on a recurring basis on security concepts. Training exercises are conducted to provide opportunities to use their knowledge.
- Developer security training – Software developers receive additional ongoing training in secure coding concepts.
- User access reviews – Access to critical systems is reviewed for appropriate authorizations regularly on a recurring basis.
- Backup strategy – maintain backups consistent with availability and durability requirements.
- Incident response team – data importer maintains an incident response capability including a specific team to handle such incidents.
- Secure system development lifecycle – System development follows a documented process and includes security considerations throughout the lifecycle.
- Change management process – All changes to software go through a documented change management process.
- Technical Controls
- Encryption in transit – Communication with the web application is performed through a TLS-secured connection with a restricted cipher suite.
- Encryption at rest – Company Personal Data is protected with AES-256 encryption and unique keys for each user.
- Backups – Critical data and system configuration information is backed up on a regular and rolling basis.
- Vulnerability scanning – Web application scanning occurs regularly to identify potential vulnerabilities within data importer’s platform.
- Static code analysis – Source code is subjected to static analysis to uncover errors or security risks which are remediated in accordance with standard processes for secure software development.
- Capacity monitoring – Information assets are monitored to ensure capacity exceeds that needed to meet demand.
- Data segregation – Company Personal Data stored in the Services is logically segregated from data of other data importer clients.
- Physical Controls
- Infrastructure hosted and secured by Hurricane Electric Co-Location facility – infrastructure to deliver Services managed directly by Compensia IT Staff and includes physical measures designed to protect against fire, flood, power interruption, and sabotage.
ANNEX III
LIST OF SUBPROCESSORS
The list of sub-processors engaged by data exporter is available at https://compensia.com/subprocessors.