Data Processing Addendum
Effective August 21, 2026.
This Data Processing Addendum (**“DPA”**) forms part of the agreement between Workforce Catalyst LLC (**“Workforce Catalyst”**) and Customer governing the Services (**“Agreement”**). It applies when Workforce Catalyst processes Customer Personal Data as a service provider, contractor, or processor on Customer's behalf. By accepting the Agreement or using the Services to process Customer Personal Data, Customer enters into this DPA on behalf of itself and any covered affiliate authorized to use the Services. ## 1. Definitions **“Applicable Data Protection Law”** means a U.S. federal or state privacy or data-security law that applies to the processing of Customer Personal Data under the Agreement. **“Customer Personal Data”** means personal information or personal data contained in Customer Content that Workforce Catalyst processes on Customer's behalf, excluding information for which Workforce Catalyst independently determines the purposes and means of processing. **“Data Subject”** means the person to whom Customer Personal Data relates. **“Process”** and **“processing”** mean any operation performed on personal information, including collecting, storing, using, accessing, transmitting, analyzing, deleting, or otherwise handling it. **“Security Incident”** means unauthorized access to or acquisition, use, disclosure, alteration, or destruction of Customer Personal Data in Workforce Catalyst's custody or control. It does not include unsuccessful attempts that do not compromise Customer Personal Data, such as blocked scans or failed login attempts. **“Subprocessor”** means a third party engaged by Workforce Catalyst to process Customer Personal Data on Customer's behalf. Terms such as **“business,” “controller,” “contractor,” “consumer,” “personal data,” “personal information,” “processor,” “sale,” “service provider,”** and **“share”** have the meanings given by applicable law. ## 2. Roles and Scope Customer is the controller or business for Customer Personal Data and Workforce Catalyst is the processor, service provider, or contractor, except where law assigns a different role for a specific activity. Customer determines the purposes of processing and instructs Workforce Catalyst through the Agreement, configuration and use of the Services, and documented lawful instructions. Workforce Catalyst acts independently for account administration, billing, fraud prevention, security, legal compliance, service analytics using appropriately aggregated or de-identified data, and its own business records, as described in the Privacy Policy. The processing details are in Schedule 1. ## 3. Customer Instructions Workforce Catalyst will process Customer Personal Data only: - to provide, secure, maintain, support, and improve the Services; - according to Customer's documented instructions; - to comply with the Agreement and this DPA; and - as required by applicable law. If law requires processing beyond Customer's instructions, Workforce Catalyst will notify Customer before processing unless legally prohibited. Workforce Catalyst will promptly inform Customer if, in its reasonable opinion, an instruction violates Applicable Data Protection Law. Workforce Catalyst may suspend the affected processing while the parties address the issue. The Agreement and Customer's authorized use constitute Customer's complete instructions at the effective date. Additional instructions that impose material cost, risk, or technical change require mutual written agreement. ## 4. Customer Obligations Customer represents and warrants that: - it has a lawful basis and all necessary rights, notices, authorizations, and consents for processing Customer Personal Data; - its instructions comply with Applicable Data Protection Law; - it will not submit prohibited data identified in the Terms or Acceptable Use Policy; - it will use reasonable access controls and assign permissions appropriately; - it will respond to Data Subjects and regulators as controller or business; - it will not attempt to re-identify anonymous survey responses; and - it will use the Services consistently with employment, labor, anti-discrimination, disability, leave, safety, and other applicable laws. Customer is responsible for the accuracy, quality, legality, collection, and use of Customer Personal Data. Customer will not use the Services for information regulated by HIPAA, GLBA, FERPA, CJIS, PCI DSS, or similar specialized regimes unless Workforce Catalyst expressly agrees in a signed writing that identifies the required safeguards. ## 5. Confidentiality Workforce Catalyst will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and access the information only as reasonably necessary for their duties. Workforce Catalyst will provide appropriate privacy and security direction to personnel with access. ## 6. Security Measures Workforce Catalyst will maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, alteration, or disclosure. Current measures are summarized in Schedule 2. Customer acknowledges that security evolves and that Workforce Catalyst may update safeguards, provided the overall protection is not materially reduced during a paid term. No system is completely secure. ## 7. Subprocessors Customer grants general authorization for Workforce Catalyst to use Subprocessors needed to provide the Services. Workforce Catalyst will: - conduct reasonable diligence appropriate to the provider and service; - enter into a written agreement requiring data-protection obligations appropriate to the processing; - remain responsible for the Subprocessor's performance of Workforce Catalyst's obligations under this DPA, subject to the Agreement; and - maintain a current Subprocessor list or provide one upon request. Workforce Catalyst may add or replace a Subprocessor. When a change is reasonably likely to materially affect Customer Personal Data, Workforce Catalyst will provide notice through the Services, email, or an updated list. Customer may object on reasonable data-protection grounds within 15 days. The parties will work in good faith on a reasonable solution. If no solution is available, Customer may terminate the affected Service without penalty before the new Subprocessor begins materially processing Customer Personal Data. This is Customer's sole remedy for a Subprocessor objection. Current provider categories and known providers are listed in Schedule 3. Customer acknowledges that Stripe may act independently for certain payment, fraud, and legal-compliance activities under Stripe's own terms. ## 8. Data Subject Requests Taking into account the nature of processing, Workforce Catalyst will provide reasonable assistance through available functionality and support so Customer can respond to verified requests to access, correct, delete, restrict, or obtain Customer Personal Data. If Workforce Catalyst receives a request directly concerning Customer Personal Data, it will, when legally permitted, direct the requester to Customer or notify Customer. Workforce Catalyst will not independently fulfill the request unless Customer instructs it or law requires it. Customer is responsible for verifying identity, determining whether a right applies, and responding. If assistance requires material work beyond standard functionality, the parties may agree on reasonable fees unless law prohibits charging them. ## 9. Compliance Assistance Taking into account the nature of processing and information available, Workforce Catalyst will provide reasonable information and assistance with Customer's legally required privacy impact assessments, regulator consultations, and demonstrations of compliance. Customer remains responsible for determining whether such duties apply. ## 10. Security Incidents Workforce Catalyst will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data and within any shorter period required by applicable law. Notice will be sent to the account owner, designated security contact, or another reasonable contact. To the extent reasonably available, notice will describe: - the nature of the incident; - categories of affected information and Data Subjects; - known or estimated scope; - likely consequences; - containment and remediation measures; and - a contact for follow-up. Workforce Catalyst may provide information in phases as the investigation continues. Notification is not an admission of fault or liability. Customer is responsible for notices to individuals, employees, regulators, unions, or other parties unless law assigns that duty to Workforce Catalyst. The parties will reasonably cooperate. ## 11. Government and Legal Requests If Workforce Catalyst receives a legally binding request for Customer Personal Data, it will notify Customer before disclosure when legally permitted. Workforce Catalyst may disclose information necessary to comply with law and will seek to limit disclosure to the required scope where reasonably possible. ## 12. Return and Deletion During the term, Customer may use available export functionality. Customer should export needed information before requesting deletion. Upon an authorized organization-deletion request, Workforce Catalyst deactivates the organization and provides a 30-day recovery period. After that period, Workforce Catalyst begins permanent deletion following eligibility, approval, and safety verification. The purge deletes or irreversibly anonymizes tenant content and stored file objects, subject to technical completion and permitted retention. Workforce Catalyst may retain limited information necessary for billing, taxes, fraud prevention, security, audit integrity, proof of consent, contract enforcement, legal claims, and compliance. Retained information remains protected and is used only for those purposes. Backup copies expire under provider schedules and are not returned to active use except for disaster recovery, legal necessity, or security. ## 13. Audits and Information Upon reasonable written request, Workforce Catalyst will provide information reasonably necessary to demonstrate compliance with this DPA, such as relevant policies, security summaries, Subprocessor information, and available independent reports. Customer may request an audit no more than once in a 12-month period, unless a confirmed Security Incident or regulator requires more. Audits must: - be limited to processing under this DPA; - occur during normal business hours with reasonable advance notice; - avoid access to other customers' information, systems, trade secrets, or security-sensitive details; - use an independent auditor bound by confidentiality; - not unreasonably disrupt operations; and - be at Customer's expense unless the audit identifies a material breach by Workforce Catalyst. The parties will first use available documentation and remote review. On-site inspection is permitted only when legally required or when documentation cannot reasonably resolve a material concern. ## 14. U.S. State Privacy Terms ### 14.1 Service Provider and Contractor Restrictions Where the California Consumer Privacy Act applies, Workforce Catalyst will act as a service provider or contractor for Customer Personal Data and will not: - sell or share Customer Personal Data; - retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a purpose other than the specific business purposes described in the Agreement, except as permitted by law; - combine Customer Personal Data with personal information received from another person or from Workforce Catalyst's own consumer interactions, except as permitted by law; or - use Customer Personal Data for cross-context behavioral advertising. Workforce Catalyst certifies that it understands and will comply with these restrictions. Customer may take reasonable and appropriate steps to help ensure compliant use, may request information described in Section 13, and may require reasonable remediation of unauthorized use. Workforce Catalyst will notify Customer if it determines it can no longer meet applicable service-provider or contractor obligations. ### 14.2 Other U.S. State Processor Terms Where another U.S. state privacy law applies, Workforce Catalyst will process Customer Personal Data according to Customer's instructions; maintain confidentiality; use appropriate safeguards; engage Subprocessors under written obligations; assist with applicable rights requests and assessments; delete or return data as described above; and provide information reasonably necessary to demonstrate compliance. Workforce Catalyst does not sell Customer Personal Data, use it for targeted advertising, or profile Data Subjects in furtherance of decisions producing legal or similarly significant effects. ## 15. Liability and Order of Precedence Each party's liability under this DPA is subject to the exclusions and limitations in the Agreement. If this DPA conflicts with the Agreement on processing Customer Personal Data, this DPA controls. An SOW controls only if it expressly identifies the provision of this DPA it replaces and applicable law permits the change. ## 16. Duration This DPA begins when Workforce Catalyst first processes Customer Personal Data and continues until that processing ends, subject to permitted retention and provisions that must survive to protect retained information. ## Schedule 1: Processing Details ### Subject Matter and Duration Processing Customer Personal Data to provide the Services during the Agreement and any deletion, backup, dispute, or legally required retention period. ### Nature and Purpose Hosting, organizing, storing, securing, displaying, transmitting, analyzing, scoring through deterministic rules, generating customer-requested AI output, sending communications, producing reports and exports, supporting users, and deleting or anonymizing Customer Personal Data. ### Data Subjects Customer personnel, account users, owners, administrators, managers, employees, workers, contractors, survey respondents, meeting participants, support contacts, prospects, and other individuals whose information Customer submits. ### Types of Personal Data - names, business contact information, employee numbers, job titles, roles, teams, and reporting relationships; - account, authentication, role, permission, consent, device, and security information; - survey invitations, completion status, anonymous answers, and free-text comments; - assessment answers, scores, scoring bands, recommendations, and roadmap information; - performance, goal, task, scorecard, meeting, coaching, and one-on-one information; - Issue Coach narratives, evidence descriptions, previous actions, business impact, desired outcomes, notes, escalation records, and AI outputs; - uploaded files and generated documents; - support communications; and - subscription and billing metadata, excluding complete payment-card data held by Stripe. ### Sensitive Information The Services are not designed for prohibited regulated data. Customer may choose to submit limited workplace descriptions involving allegations, discipline, safety, protected activity, accommodations, leave, health-related workplace needs, protected characteristics, or other sensitive matters. Customer must minimize such information and submit it only when lawfully authorized and reasonably necessary. ### Processing Frequency Continuous or at Customer's direction while the Services are used. ## Schedule 2: Security Measures Workforce Catalyst's current safeguards include, as appropriate to the Services: - HTTPS/TLS through production hosting and domain infrastructure; - provider-managed database and infrastructure protections, including encryption at rest where configured by the provider; - bcrypt password hashing; - signed session cookies configured Secure in production, HttpOnly, and SameSite=Lax; - anti-forgery protections for state-changing requests; - role-based access controls and organization-tenant isolation; - password-reset tokens with limited lifetime and invalidation safeguards; - security headers, including content-security, framing, content-type, referrer, and transport protections; - audit logging for significant account and administrative activity; - environment-variable secret management and production-readiness checks; - file type and size restrictions, randomized storage keys, and authorized download controls; - rate limiting and abuse controls for selected public and authentication routes; - error and incident monitoring when enabled; - data-export authorization; - backup and restoration controls provided by configured hosting and database providers; - separate survey invitation and anonymous-response storage with a five-response reporting threshold; - versioned, immutable policy-acceptance records; and - controlled, approved, dry-run-capable tenant data purging. Workforce Catalyst does not represent that file validation is malware scanning or that any safeguard eliminates all risk. ## Schedule 3: Subprocessor Categories The production configuration must be verified before this schedule is published as a definitive current list. Workforce Catalyst's architecture supports or uses the following: - **Railway Corporation:** application hosting, networking, infrastructure logs, and potentially managed PostgreSQL database services. - **Stripe, Inc.:** hosted checkout, subscription billing, invoices, payment processing, fraud prevention, and billing portal. - **Twilio Inc. / SendGrid:** transactional email delivery. - **Anthropic PBC:** customer-requested AI text generation through a commercial API. - **Functional Software, Inc. / Sentry:** error monitoring, only if enabled in production. - **Configured S3-compatible storage provider:** uploaded-file object storage, only if enabled in production. The specific provider and region must be added to the definitive Subprocessor list before activation. ## 17. Contact Workforce Catalyst LLC · 4919 W Stanford St · Springfield, Missouri 65802 · United States Email: dyami.pike@theworkforcecatalyst.com
See also: Terms of Service · Privacy Policy · AI Disclaimer · HR and Legal Disclaimer · Acceptable Use Policy · Cookie Notice
