Application and incorporation
This Data Processing Addendum ("DPA") is intended to supplement an agreement between an AlchemyWorkflow contracting entity and an enterprise customer where AlchemyWorkflow processes Personal Data on the customer’s behalf. It becomes binding only when incorporated into or executed with an applicable agreement.
Roles and instructions
Customer is the controller or business and AlchemyWorkflow is the processor or service provider for Customer Personal Data, except where the parties expressly identify another role. AlchemyWorkflow will process Customer Personal Data only on documented instructions, including the agreement, configured workflows and authorized support requests.
Details of processing
The subject matter is the provision of workflow orchestration, integration, implementation and support services. Duration follows the agreement. Data subjects may include customer employees, prospects, customers, partners, users and other individuals represented in connected systems. Data categories depend on the configured workflow and may include business contact, account, CRM, communications, content, approval, usage and support data.
Confidentiality and security
AlchemyWorkflow will ensure personnel authorized to process Customer Personal Data are bound by confidentiality obligations and will maintain reasonable technical and organizational measures appropriate to the risk. Customer remains responsible for secure configuration, user access, lawful instructions and the security of connected systems.
Subprocessors
Customer authorizes AlchemyWorkflow to use subprocessors to provide the Services. AlchemyWorkflow will impose data-protection obligations appropriate to the services performed and remain responsible for subprocessors as required by applicable law and agreement. A production subprocessor list and change-notification process must be published before this DPA is offered for execution.
Data-subject requests
Taking into account the nature of processing, AlchemyWorkflow will reasonably assist Customer with verified requests to exercise applicable privacy rights. If AlchemyWorkflow receives a request relating to Customer Personal Data, it may direct the requester to Customer unless legally prohibited.
Personal Data incidents
AlchemyWorkflow will notify Customer without undue delay after confirming a Personal Data breach affecting Customer Personal Data and will provide information reasonably available to support Customer’s legal obligations. Notification is not an admission of fault or liability.
Compliance assistance
AlchemyWorkflow will provide reasonable assistance with data-protection impact assessments, regulator consultations and compliance information where required by law and proportionate to the Services. Additional work may be subject to agreed fees.
International transfers
Where a restricted transfer occurs, the parties will use an applicable legal mechanism, which may include the European Commission Standard Contractual Clauses, the UK Addendum or another recognized safeguard. The specific module, annexes, importer, exporter and supplementary measures must be completed for the contracting entity and deployment.
Return and deletion
Upon termination and written request, AlchemyWorkflow will return or delete Customer Personal Data according to the agreement, except where retention is required by law. Backup deletion may follow the applicable backup cycle. Aggregated or de-identified data that no longer identifies Customer or an individual may be retained.
Information and audits
AlchemyWorkflow will make available information reasonably necessary to demonstrate compliance. Audits should first be satisfied through documentation or independent reports where available. On-site audits require reasonable notice, confidentiality, non-disruption and agreement on scope and cost.
Precedence and completion
For Personal Data processing, this DPA controls over conflicting terms in the main agreement unless the DPA expressly states otherwise. Before execution, the parties must complete the contracting entities, notices, security measures, subprocessors, transfer annexes and processing details.