Data Processing Agreement
Last updated
How we process the employee data your organization keeps in openbranchhq, on your behalf and on your instructions. It forms part of the Terms of Service, so there is nothing to sign.
1. Scope and parties
This Data Processing Agreement ("DPA") forms part of the Terms of Service between PAP SOFTWARE SOLUTIONS L.P. ("Processor", "we") and the Customer ("Controller", "you"). It applies whenever we process Customer Personal Data to provide the hosted Service, and it prevails over the Terms on any conflict about personal data.
It does not apply to self-hosted installations, which we neither operate nor access.
If you need a countersigned copy, write to [email protected].
2. Definitions
Terms such as "controller", "processor", "data subject", "personal data", "processing" and "personal data breach" have the meanings given in the EU General Data Protection Regulation (GDPR).
"Data Protection Laws" means the GDPR and Greek Law 4624/2019, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws including the California Consumer Privacy Act (CCPA), in each case as they apply to the processing. "Customer Personal Data" means the personal data in Customer Data. Other capitalized terms have the meanings given in the Terms.
3. Roles and processing details
You are the controller of Customer Personal Data and we are your processor. If you are yourself a processor for another controller, we are your subprocessor, and you confirm that your instructions are authorized by that controller.
The subject matter, nature, purpose and duration of the processing, the types of personal data and the categories of data subjects are set out in Annex I.
4. Your obligations
You are responsible for the lawfulness of the processing you instruct. That includes having a legal basis, giving your employees the information Data Protection Laws require and, where leave records, attachments or documents contain special-category data such as health information, meeting the conditions of Article 9 GDPR or its equivalent.
You will not instruct us to process personal data in breach of Data Protection Laws.
5. Our obligations
- Instructions: we process Customer Personal Data only on your documented instructions, which are the Terms, this DPA, and your use and configuration of the Service, unless the law requires otherwise. In that case we will tell you first unless the law forbids it. We will tell you if we believe an instruction breaches Data Protection Laws.
- Confidentiality: everyone we authorize to process Customer Personal Data is bound by confidentiality obligations.
- Security: we implement the technical and organizational measures in Annex II and keep them appropriate to the risk.
- Data subject requests: taking into account the nature of the processing, we help you answer requests from data subjects. The Service lets you view, edit, export and delete employee records yourself. We forward to you, without answering them, any requests we receive directly.
- Assistance: we give reasonable help with data protection impact assessments, prior consultations with supervisory authorities, and your other obligations under Articles 32 to 36 GDPR.
- Personal data breaches: we notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. We give you the information you reasonably need to meet your own obligations, and take reasonable steps to contain the breach.
6. Subprocessors
You give us general authorization to engage subprocessors. The current list is on our Subprocessors page and in Annex III. We impose on each subprocessor data-protection obligations no less protective than this DPA, and we remain responsible for its performance.
We will update that page and email you at least 30 days before a new subprocessor processes Customer Personal Data. You may object on reasonable data-protection grounds within that period. If we cannot reasonably accommodate the objection, you may end the affected subscription and receive a refund of prepaid fees for the remaining period.
7. International transfers
We are established in Greece and use subprocessors in the United States (Annex III). Where Customer Personal Data is transferred outside the European Economic Area to a country without an adequacy decision, we make sure the transfer is covered by an appropriate safeguard: the recipient's certification under the EU-U.S. Data Privacy Framework, or the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (Module 3, processor to processor) entered into with that subprocessor.
If you are established outside the European Economic Area in a country without an adequacy decision, Module 4 (processor to controller) of those clauses is incorporated into this DPA by reference for the personal data we transfer to you. For it, the optional wording in clause 11 does not apply, the clauses are governed by the law of Greece and disputes go to the courts of Greece, and Annexes I to III of this DPA complete the clauses' annexes.
For personal data from the United Kingdom, the International Data Transfer Addendum issued by the UK Information Commissioner applies to these clauses. For personal data from Switzerland, they apply with the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority, and references to EU member states include Switzerland.
8. Audits
We make available the information reasonably necessary to show compliance with this DPA, including answers to written security questionnaires. If that is not enough, or a supervisory authority requires it, you may audit our compliance once a year at your own cost, on at least 30 days' written notice, during business hours and under confidentiality obligations.
9. Return and deletion
When your subscription ends, you can export Customer Data for 30 days. After that, or earlier on your written request, we delete Customer Personal Data unless the law requires us to keep it.
Deleting your Organization in the Service deletes its Customer Personal Data straight away: its records immediately, and its uploaded files from storage shortly after.
10. U.S. state privacy laws
Where the CCPA or a similar law applies, we act as your service provider or processor. We will not sell or share Customer Personal Data; retain, use or disclose it outside our direct business relationship with you or for any purpose other than providing the Service; or combine it with personal data we receive from others, except as those laws permit. We will tell you if we can no longer meet these obligations.
11. Liability and term
Each party's liability under this DPA is subject to the limitations in the Terms of Service. This DPA lasts for as long as we process Customer Personal Data for you.
Annex I — Details of processing
Annex II — Technical and organizational measures
- Encryption: TLS for all traffic to the Service; uploaded files are encrypted at rest by our storage provider.
- Authentication: required email verification, salted password hashes, optional two-factor authentication with backup codes, and per-device session listing and revocation. Session cookies are HTTP-only and SameSite=Lax, and marked secure in production.
- Tenant isolation: every organization-scoped query takes the organization from the authenticated session, never from client input.
- Authorization: role-based permissions within each organization.
- Files: a private bucket, with uploads and downloads only through signed links valid for five minutes and sixty seconds respectively, and downloads always served as attachments.
- Auditability: an append-only activity log of changes in each organization, and a log of document views and downloads.
- Secrets: calendar feed links are stored only as hashes, and infrastructure credentials are kept in our hosting provider's configuration, never in source code.
- Logging: server logs mask email addresses, and calendar feed requests are not logged.
- Personnel: access to production systems is limited to people who need it, under confidentiality obligations.
Annex III — Subprocessors
The subprocessors below are authorized at the date of this DPA. Changes are announced on our Subprocessors page.