Home · Data Processing Addendum
Terms of Service · Privacy Policy · Security & PCI · Accessibility · Sub-processors · Data Processing Addendum · Copyright Policy
Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Commonwell and each customer community ("Customer") and applies when Commonwell processes personal data on the Customer's behalf.
1. Roles and scope
Customer is the controller (or "business") and Commonwell is the processor (or "service provider") for personal data in the Customer's community workspace. Commonwell processes that data only to provide, secure, and support the Service, as described in the Terms, the Privacy Policy, and Customer's documented instructions, including the configuration choices Customer makes in the Service.
2. Commonwell's commitments
- Instructions. We process Customer personal data only on Customer's documented instructions unless the law requires otherwise, and we tell Customer if we believe an instruction violates applicable law.
- No selling or sharing. We do not sell Customer personal data, share it for cross-context behavioral advertising, or use it outside our direct business relationship with Customer, except as the law permits a service provider.
- Confidentiality. Personnel who can access Customer personal data are bound by confidentiality obligations.
- Security. We maintain the technical and organizational measures described on our Security & PCI page.
- Sub-processors. Customer authorizes the sub-processors listed on our Sub-processors page. We bind each sub-processor to data-protection terms no less protective than this DPA and remain responsible for its performance.
- Assistance. We help Customer respond to data-subject requests, including through the Service's export and deletion tools, and assist with security, impact-assessment, and regulator inquiries where reasonably required.
- Personal data breaches. We notify Customer without undue delay after becoming aware of a breach affecting Customer personal data, with the information Customer reasonably needs to meet its own obligations.
- Deletion and return. Customer can export its data at any time. On an owner's confirmed deletion request we delete or anonymize Customer personal data, except the records the law requires us to keep, as described in the Privacy Policy.
- Audits. We make available the information reasonably necessary to demonstrate compliance with this DPA.
3. International transfers
Where personal data is transferred across borders, we rely on the safeguards applicable law requires, such as standard contractual clauses where they apply.
4. Contact
Questions about this DPA, or requests for a countersigned copy: privacy@commonwell.app.