Data Processing Addendum

COMPENSIA, INC.

DATA PROCESSING ADDENDUM

Compensia, Inc., a California corporation, whose principal place of business is at 548 Market Street, PMB# 55353, San Francisco, California 94104-5401 (“Compensia”) and the counterparty agreeing to these terms (“Company”) have entered into a letter agreement, or other written or electronic agreement (each, the “Main Agreement”) for the provision of Compensia’s compensation consulting services (collectively, the “Services”) provided by Compensia. This Data Processing Addendum (the “DPA”) forms part of the Main Agreement.

This DPA will be effective and replace any previously applicable terms relating to their subject matter (including any data processing agreement or addendum relating to the Services), from the date on which Company accepted this DPA.

If you are accepting this DPA on behalf of Company, you warrant that: (a) you have full legal authority to bind Company to this DPA; (b) you have read and understand this DPA; and (c) you agree, on behalf of Company, to this DPA. If you do not have the legal authority to bind Company, do not accept this DPA.

The parties have agreed to enter into this DPA in order to ensure that adequate safeguards are put in place with respect to the protection of Personal Data as required by data protection laws, rules, and regulations to the extent applicable (“Data Protection Laws“).

1. Definitions

1.1.
Company Personal Data” means any Personal Data that Compensia Processes on behalf of Company in the course of utilizing the Services as a Processor.
1.2.
Personal Data”, “Controller”, “Processor”, “Data Subject”, “Process” and “Supervisory Authority” shall have the meanings set out in Data Protection Laws (or any equivalent terms used in those laws). “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, any Company Personal Data by Compensia that compromises the security, confidentiality or integrity of such Company Personal Data.
1.3.
Sensitive Personal Information” has the meaning set out in Data Protection Laws and includes, for example, social security number, driver’s license, and certain other government identifiers, financial account data together with required account access details, and precise geolocation data.
1.4.
Standard Contractual Clauses” means the standard contractual clauses for the transfer of personal data annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
1.5.
Subprocessor” means any Processor engaged by Compensia to Process Company Personal Data on Compensia’s behalf.
1.6.
Third Country” means any destination country outside of a source country in which the Data Protection Laws restrict transfers of Personal Data to such other destination countries, except where the Data Protection Laws and applicable regulatory authorities of the source country adopted an adequacy decision regarding the Data Protection Laws of the destination country such that transfers of Personal Data to that destination country are not restricted. For purposes of this DPA, the United States is a Third Country.
1.7.
UK Addendum” means United Kingdom (“UK”) Information Commissioner’s (“ICO”) International Data Transfer Addendum to the EU Commission Standard Contractual Clauses Version B1.0 in force 21 March 2022.
Any defined terms that are not defined in this DPA are as defined in the Main Agreement.

2. Roles and Compliance with Data Protection Laws

2.1.
Each party and its personnel will use commercially reasonable efforts to comply with Data Protection Laws. As between the parties, Company shall have sole responsibility for the accuracy, quality, and legality of Company Personal Data and the means by which the Company Personal Data was acquired.
2.2.
In the event of any conflict between the terms of this DPA and the terms of the Main Agreement, the terms of this DPA shall prevail so far as the subject matter concerns the processing of Company Personal Data. Each provision of this DPA is only applicable to the extent required by Data Protection Laws.
2.3.
Compensia will only Process Company Personal Data in accordance with the Main Agreement (including any order form), and Company’s written instructions, to the extent necessary to provide the Services to Company, including with respect to international transfers of Company Personal Data, unless Processing is required by other applicable laws, in which case Compensia shall, to the extent permitted by applicable law, inform Company of that legal requirement before so Processing that Company Personal Data. The Agreement (including any order form) and the DPA shall be Company’s complete and final instructions to Compensia in relation to the Processing of Company Personal Data. Processing outside the scope of the foregoing will require prior written agreement between Company and Compensia and may be subject to additional fees.
2.4.
As required by applicable Data Protection Laws, if Compensia believes any Company instructions to Process Company Personal Data will violate applicable Data Protection Laws, or if applicable Data Protection Laws require Compensia to process Company Personal Data relating to Data Subjects in a way that does not comply with Company’s documented instructions, Compensia shall notify Company in writing, unless applicable Data Protection Laws prohibit such notification, provided Compensia is not responsible for performing legal research or providing legal advice to Company.
2.5.
Company Personal Data may not include any Sensitive Personal Information or any data that imposes specific data security or data protection obligations on Compensia in addition to or different from those specified in any documentation or which are not provided as part of the Services. Compensia does not require and does not request any Sensitive Personal Information to provide the Services.
2.6.
Compensia shall Process Company Personal Data for the duration of the provision of Services in accordance with the Main Agreement and thereafter only as set forth in the Main Agreement and this DPA.

3. Security

3.1.
Compensia will, taking into account the state of the art, cost of implementation, and the nature, scope, context and purposes of any data at issue, implement and maintain commercially reasonable and appropriate technical, physical, and organizational safeguards to protect the confidentiality, availability, and integrity of Company Personal Data that is maintained and accessed by Compensia for Company using Compensia’s Services pursuant to the Main Agreement. Compensia’s organizational safeguards, and other data protection policies, are summarized in Annex II.
3.2.
Company is responsible for the security of Company Personal Data in its possession, custody, or control, including while Company Personal Data is in transit over the Internet or other third-party network. In furtherance of meeting its security obligations, Company agrees to employ all commercially reasonable and appropriate physical, administrative, and technical security measures necessary to (i) protect all of its and its Authorized Personnel’s access credentials; (ii) protect Company’s information technology infrastructure, including computers, software, databases, electronic systems (including database management systems) and networks whether operated directly by Company or through the use of third-party services (the “Company Systems”); (iii) protect against any unauthorized access to or use of the Services directly or indirectly through Company Systems or its or its Authorized Personnel’s access credentials; and (iv) protect the confidentiality, integrity, and availability of all Company Personal Data while such data is in transit to Compensia, including while such data is being uploaded or otherwise provided to Compensia for processing.
3.3.
Compensia shall treat Company Personal Data as the Confidential Information of Company, and shall put procedures in place to ensure that any employees or other personnel with access to Company Personal Data have committed themselves to confidentiality of Company Personal Data or are under an appropriate statutory obligation of confidentiality.
3.4.
Personal Data Breach
3.4.1.
If Compensia or any Subprocessor becomes aware of and determines a Personal Data Breach has occurred, Compensia will:
3.4.1.1.
notify Company of the Personal Data Breach without undue delay and, in any case, within 72 hours after such determination, at the contact information on file; and
3.4.1.2.
investigate the Personal Data Breach and provide such reasonable assistance to Company (and any law enforcement or regulatory official) as required to investigate the Personal Data Breach.
3.4.2.
Compensia’s contact point for additional details regarding a Personal Data Breach is privacy@Compensia.com. Compensia’s provision of any notification of a Personal Data Breach shall not constitute an admission of fault.
3.4.3.
Company is solely responsible for fulfilling any Personal Data Breach notification obligations applicable to Company. Company and Compensia shall work together in good faith within the timeframes for Company to provide Personal Data Breach notifications in accordance with Data Protection Laws to finalize the content of any notifications to Data Subjects or Supervisory Authorities, as required by Data Protection Laws. Compensia’s prior written approval shall be required for any statements regarding, or references to, Compensia, Compensia’s systems, or details of the Personal Data breach made by Company in any such notifications.

4. Information and Audits.

4.1.
Upon Company’s request, and subject to the confidentiality obligations set forth in the Main Agreement, Compensia shall in a commercially reasonable timeframe make available to Company information regarding Compensia’s compliance with the obligations set forth in this DPA, which may include either of the following at Compensia's election: (i) responses to a reasonable information security-related questionnaire; or (ii) a summary of Compensia's operational practices related to data protection and security.
4.2.
If required by Data Protection Law, Company may, upon at least 30 days’ advance written notice and at reasonable times, audit (either by itself or using independent third-party auditors) Compensia’s compliance with the security measures set out in this DPA solely for the purpose of confirming Compensia’s compliance with its obligations under this DPA. Compensia shall reasonably assist with any audits conducted in accordance with this Section 4.2. Such audits may be carried out once per year, or more often only if required by Data Protection Law or Company’s applicable Supervisory Authority.
4.3.
Any third party engaged by Company to conduct an audit must be pre-approved by Compensia (such approval not to be unreasonably withheld) and sign Compensia’s confidentiality agreement. Company must provide Compensia with a proposed audit plan at least two weeks in advance of the audit, after which Company and Compensia shall discuss in good faith and finalize the audit plan prior to commencement of audit activities.
4.4.
Audits may be conducted only during regular business hours, in accordance with the finalized audit plan and Compensia’s security and other policies and may not unreasonably interfere with Compensia’s regular business activities. Compensia is not required to grant access to its premises or systems for the purposes of such an audit to any individual unless they produce reasonable evidence of identity and authority. Company shall reimburse Compensia for any costs or expenses incurred by Compensia in connection with the Audit or with granting access to its data processing facilities.
4.5.
Information obtained or results produced in connection with an audit are Compensia confidential information.
4.6.
In lieu of Company auditing a Subprocessor, Company may request that Compensia audit a Subprocessor or provide confirmation that such an audit has occurred (or, where available, obtain or assist Company in obtaining a third-party audit report concerning the Subprocessor’s operations) to verify compliance with the Subprocessor’s obligations.
4.7.
Without prejudice to the rights granted in Section 4.2 above, if the requested audit scope is addressed in a SOC 2 report issued by a qualified third party auditor within the prior twelve months and Compensia provides a summary of such report to Company confirming there are no known material changes in the controls audited, Company agrees to accept the findings presented in the summary in lieu of requesting an audit of the same controls covered by the report.

5. Additional Processing Terms

5.1.
The terms set forth in this Section 5 of the DPA only apply to the extent that Compensia Processes Personal Information subject to applicable Data Protection Laws of US states (“US State Laws”) that require the following terms, such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020 (“CCPA”).
5.2.
If US State Laws apply to Company, and Compensia Processes Company Personal Data on behalf of Company, Company shall be a Business and Compensia shall be a Service Provider to the extent US State Laws define those terms, with respect to the Processing of that Company Personal Data.
5.3.
The limited and specified Business Purposes for which Compensia is Processing Company Personal Data pursuant to the Main Agreement include: (i) helping to ensure security and integrity to the extent the use of the Company Personal Data is reasonably necessary and proportionate for these purposes; (ii) performing the Services and related support services on behalf of Company; (iii) undertaking internal research for technological development and demonstration; and (iv) undertaking activities to verify or maintain the quality or safety of a service that is controlled by the business, and to improve, upgrade, or enhance the service that is controlled by the business.
5.4.
Compensia is prohibited from: (a) selling or sharing (as such terms may be defined in US State Laws) Company Personal Data; (b) retaining, using or disclosing Company Personal Data for any purpose other than providing the Services under the Main Agreement; (c) processing Company Personal Data outside of the direct business relationship between Compensia and Company; and (d) combining Company Personal Data with Personal Data Compensia receives from, or on behalf of, another client or otherwise obtains outside of the scope of the Services, except as permitted by US State Laws. Notwithstanding the foregoing, the Business Purposes include Compensia’s use of Company Personal Data to maintain, enhance, and improve Compensia’s proprietary database, which constitutes part of the Services provided to Company. Except as otherwise expressly provided in the Main Agreement, no Company Personal Data is processed by Compensia as consideration for any service provided to Company. As set forth in Section 4, Company may take reasonable and appropriate steps to help ensure that Compensia uses Company Personal Data in a manner consistent with Compensia’s obligations. As required by US State Laws, Compensia will notify Company if it makes a determination that Compensia can no longer meet its obligations under such laws. Company may, upon written notice to Compensia and as set forth in Section 4, take reasonable and appropriate steps to stop and remediate unauthorized use of Company Personal Data.

6. Subprocessors

6.1.
Company generally authorizes the engagement of third parties as Subprocessors provided such engagement complies with this Section 6. For the avoidance of doubt, this authorization constitutes Company’s prior written consent to the subprocessing of Company Personal Data for purposes of Clause 9, Option 2 of the Standard Contractual Clauses and any similar requirements of other data transfer mechanisms.
6.2.
A current list of Subprocessors is available here (“Subprocessor List”) and may be updated by Compensia from time to time in accordance with this DPA. Compensia will provide notice of additions to the Subprocessor List on the foregoing link.
6.3.
When engaging any Subprocessor, Compensia will:
6.3.1.
execute with Subprocessors a written agreement providing: (a) the Subprocessor Processes Company Personal Data only to the extent required to perform the obligations subcontracted to it and does so in accordance with the Agreement and this DPA; and (b) the Subprocessor utilizes substantially the same level of data protection and security with regard to its Processing of Company Personal Data as described in this DPA; and
6.3.2.
be responsible for the Subprocessor’s violations of this DPA or Data Protection Laws in relation to the services such Subprocessor provides to Compensia to the extent Compensia would be liable for the same violations under the terms of the Agreement.
6.4.
Company may, on reasonable and objective grounds, object to Compensia’s use of a new Subprocessor by providing Compensia with written notice within ten (10) days after Compensia has provided notice to Company as described herein with documentary evidence that reasonably shows that the Subprocessor does not or cannot comply with the requirements in this DPA or Data Protection Laws (“Objection”). In the event of an Objection, Company and Compensia will work together in good faith to find a mutually acceptable resolution to address such Objection, including but not limited to reviewing additional documentation supporting the Subprocessor’s compliance with the DPA or Data Protection Laws. To the extent Company and Compensia do not reach a mutually acceptable resolution within a reasonable timeframe, Compensia will use reasonable endeavors to make available to Company a change in the Services or will recommend a commercially reasonable change to the Services to prevent the applicable Subprocessor from Processing Company Personal Data. If Compensia is unable to make available such a change within a reasonable period of time, which shall not exceed thirty (30) days, Company shall, as its sole remedy, have the right to terminate the relevant Services (i) in accordance with the termination provisions in the Main Agreement; (ii) without liability to Company or Compensia, and (iii) without relieving Company from its payment obligations under the Main Agreement up to the date of termination.

7. International Transfers

7.1.
In accordance with Company’s instructions under Section 2, Compensia may Process Company Personal Data on a global basis as necessary to provide the Services, including for IT security purposes, maintenance and provision of the Services and related infrastructure, technical support, and change management.
7.2.
To the extent that the Processing of Company Personal Data by Compensia involves the transfer of such Company Personal Data from a country whose Data Protection Laws restrict the transfer of Personal Data to Third Countries, then such transfers shall be subject to the protections and provisions of the Standard Contractual Clauses (the Appendix for which is attached to this DPA in Schedule 1), the UK Addendum for transfers from the UK to Third Countries, or other binding and appropriate transfer mechanisms that provide an adequate level of protection in compliance with Data Protection Laws. For purposes of this Section 7, transfers to the United States shall be carried out under the Standard Contractual Clauses and UK Addendum, as applicable.
7.3.
Company shall be deemed to have signed the SCC in Schedule 1, Annex I in its capacity of “data exporter” and Compensia in its capacity as “data importer.” Module One of the SCCs shall apply when Company and Compensia both act as Controller of the Personal Data. Module Two shall apply when Company is Controller of the Company Personal Data and Compensia is Processor of such data. For purposes of Clauses 17 and 18 of the SCCs, the Parties select the Netherlands. Clause 7 is omitted. In Clause 11(a), the optional provision shall not apply. To the extent such a transfer includes Company Personal Data subject to Data Protection Laws of Switzerland, the Standard Contractual Clauses shall be adapted to use for Switzerland (where the Swiss Federal Act on Data Protection shall apply as the applicable Data Protection Law, Clauses 17 and 18 of the SCCs shall refer to Switzerland, and Data Subjects in Switzerland shall be able to avail themselves of any rights conferred by the Standard Contractual Clauses).
7.4.
If the UK Addendum applies, then:
7.4.1.
Table 1 of the UK Addendum is completed with the Parties’ details and Key Contacts of Company (as data exporter) and Compensia (as data importer), as provided above. The “Start date” is the Effective Date or other similar date of the Main Agreement.
7.4.2.
Table 2 of the UK Addendum is completed by selecting “the Approved EU SCCs, including the Appendix Information and with only the following modules, clauses or optional provisions of the Approved EU SCCs brought into effect for the purposes of this Addendum”.
7.4.3.
For the purposes of Table 2 and Table 3 of the UK Addendum, the “Approved EU SCCs” are completed with the Modules, selections, and details set forth above.
7.4.4.
Table 4 of the UK Addendum is completed by selecting “neither party”.
7.5.
The SCC, or UK Addendum, as applicable, will cease to apply if Compensia has implemented an alternative recognized compliance mechanism for the lawful transfer of personal data in accordance with applicable Data Protection Laws.
7.6.
In the event of any conflict between any terms in the SCC or UK Addendum, as applicable, and the DPA, the SCC or UK Addendum, as applicable, shall prevail to the extent of the conflict.

8. Access Requests and Data Subject Rights

8.1.
Save as required (or where prohibited) under applicable law, Compensia shall promptly notify Company of any request received by Compensia or any Subprocessor from a Data Subject in respect of their Personal Data included in Company Personal Data (“Data Subject Request”) and shall not respond to the Data Subject Request where the Data Subject identifies Company as its Controller. If a Data Subject does not identify a Controller, Compensia will instruct the Data Subject to identify and contact the relevant Controller.
8.2.
For the avoidance of doubt, Compensia may communicate, without restriction, with a regulatory or judicial body or a Data Subject if it is not reasonably apparent on the face of the request to which customer of Compensia the request relates.
8.3.
Where applicable, and taking into account the nature of the Processing, Compensia shall use reasonable endeavors to assist Company by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Company’s obligation to respond to Data Subject Requests as required by Data Protection Laws. In order to receive such assistance, Company shall utilize any tools provided by Compensia including those providing Company with the ability to correct, delete, block, access or copy the Personal Data of a Data Subject. If such functionality or other tools are not available, Company may contact privacy@Compensia.com requesting assistance and clearly stating the nature of the Data Subject Request.

9. Data Protection Impact Assessments and Prior Consultation

9.1.
To the extent required under applicable Data Protection Laws, Compensia shall provide reasonable assistance to Company with any data protection impact assessments or prior consultations to any Supervisory Authority of Company, in each case solely in relation to Processing of Company Personal Data and taking into account the nature of the Processing and information available to Compensia.
9.2.
Such cooperation and assistance are provided to the extent Company does not otherwise have access to the relevant information, and to the extent such information is available to Compensia. Compensia may fulfill its above obligations by providing Company with documentation regarding its Processing operations.

10. Retrieval and Deletion of Company Personal Data

10.1.
Except as retained for use in Compensia’s proprietary databases on a deidentified basis, backup storage, and archival and legal copies, after (a) cessation of Processing of Company Personal Data by Compensia on Company’s written request or (b) termination or expiration of the Main Agreement, except as otherwise permitted by applicable Data Protection Laws, Compensia shall delete and use all reasonable efforts to procure the deletion of Company Personal Data Processed by Compensia or any Subprocessors, and where deletion is not possible, sufficiently de-identify Company Personal Data such that it is no longer Personal Data.
10.2.
Compensia may retain Company Personal Data to the extent and for such period required by applicable Data Protection Laws, provided that Compensia shall ensure the confidentiality of all such Company Personal Data and that such Company Personal Data is only Processed as necessary for the purpose(s) specified in the applicable Data Protection Laws requiring its storage.

11. General

11.1.
This DPA does not confer any third-party beneficiary rights. It is intended for the benefit of the parties and their respective permitted successors and assigns only, and is not for the benefit of, nor may any provision be enforced by, any other person.
11.2.
In the event of any conflict between the terms of this DPA and the terms of the Main Agreement, the terms (including definitions and the Schedules) of this DPA shall prevail so far as the subject matter concerns the processing of Personal Data. This DPA is the final, complete, and exclusive agreement of the parties with respect to this subject matter and supersedes and merges all prior discussions and agreements between the parties with respect to this subject matter. Other than fraudulently made statements, no other representations or terms apply or form part of this DPA. No modification of, amendment to, or waiver of any rights under the DPA will be effective unless in writing and signed by an authorized signatory of each party.
11.3.
Each party represents and warrants to the other that the execution and delivery of this DPA, and the performance of the party’s obligations under this DPA, have been duly authorized and that this DPA is a valid and legally binding agreement on each party, enforceable in accordance with its terms.
11.4.
This DPA may be executed in counterparts, each of which shall be deemed to be an original, but all of which, taken together, shall constitute one and the same agreement.

Company

Signature:
Title:
Printed Name:
Date:
 

Compensia, Inc.

Signature:
Title:
Printed Name:
Date:

SCHEDULE 1

APPENDIX TO THE STANDARD CONTRACTUAL CLAUSES

ANNEX I
ANNEX I.A – LIST OF PARTIES

Data exporter(s) name, contact person’s name, position and contact details: See Main Agreement.
Activities relevant to the data transferred under these Clauses: Data importer provides Services to data exporter as set forth in the Main Agreement.
Signature and date: See Main Agreement.
Role (controller/processor): Controller.

Data importer name, contact person’s name, position and contact details: Compensia, Inc., 548 Market Street, PMB# 55353, San Francisco, CA 94104-5401.
Contact: privacy@Compensia.com.
Activities relevant to the data transferred under these Clauses: Data importer Processes Company Personal Data to provide the Services to data exporter as set forth in the Main Agreement.
Signature and date: See Main Agreement.
Role (controller/processor): Processor.

ANNEX I.B – DESCRIPTION OF TRANSFER

  • Categories of data subjects whose personal data is transferred: Potential and current personnel of data exporter, employees of data exporter.
  • Categories of personal data transferred: Name, email, telephone number, job title, business address, and compensation information.
  • Sensitive categories of data (if appropriate): None.
  • The frequency of the transfer: Continuous.
  • Nature of the processing: Provision of the Services.
  • Purposes of the data transfer and further processing: Refer to DPA.
  • The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Personal Data will be processed for the duration of the Agreement, subject to Section 10 of the DPA.
  • For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: Refer to DPA and the Main Agreement

ANNEX I.C – COMPETENT SUPERVISORY AUTHORITY

The data protection authority competent for the Data Exporter or, if the Data Exporter is not established in the European Union or has not appointed a representative in the European Union, is the data protection authority competent for the data subjects whose personal data are transferred under the clauses.

ANNEX II
TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA:

  • Administrative controls
    • Security education, training, and awareness program – data importer trains all employees on hire and on a recurring basis on security concepts. Training exercises are conducted to provide opportunities to use their knowledge.
    • Developer security training – Software developers receive additional ongoing training in secure coding concepts.
    • User access reviews – Access to critical systems is reviewed for appropriate authorizations regularly on a recurring basis.
    • Backup strategy – maintain backups consistent with availability and durability requirements.
    • Incident response team – data importer maintains an incident response capability including a specific team to handle such incidents.
    • Secure system development lifecycle – System development follows a documented process and includes security considerations throughout the lifecycle.
    • Change management process – All changes to software go through a documented change management process.
  • Technical Controls
    • Encryption in transit – Communication with the web application is performed through a TLS-secured connection with a restricted cipher suite.
    • Encryption at rest – Company Personal Data is protected with AES-256 encryption and unique keys for each user.
    • Backups – Critical data and system configuration information is backed up on a regular and rolling basis.
    • Vulnerability scanning – Web application scanning occurs regularly to identify potential vulnerabilities within data importer’s platform.
    • Static code analysis – Source code is subjected to static analysis to uncover errors or security risks which are remediated in accordance with standard processes for secure software development.
    • Capacity monitoring – Information assets are monitored to ensure capacity exceeds that needed to meet demand.
    • Data segregation – Company Personal Data stored in the Services is logically segregated from data of other data importer clients.
  • Physical Controls
    • Infrastructure hosted and secured by Hurricane Electric Co-Location facility – infrastructure to deliver Services managed directly by Compensia IT Staff and includes physical measures designed to protect against fire, flood, power interruption, and sabotage.

ANNEX III
LIST OF SUBPROCESSORS

The list of sub-processors engaged by data exporter is available at https://compensia.com/subprocessors.

Interested in working with us?