Data Processing Agreement (DPA)

Data Processing Agreement (DPA)

Last Updated: August 4, 2023

This Data Processing Agreement (“DPA”) forms part of the Terms of Service and any applicable service agreement between Worksnaps and the Customer and applies where Worksnaps processes Personal Data on behalf of the Customer in connection with the Services.

For purposes of this DPA:

Terms not otherwise defined shall have the meaning given in the Terms of Service.

This DPA applies to the processing of Personal Data necessary for Worksnaps to provide time tracking, productivity monitoring, reporting, screenshot capture, and related support services.

Processing shall continue for the duration of the Customer’s subscription and for any lawful retention period thereafter.

Processing may include:

Processor shall process Personal Data only on documented instructions from Customer unless otherwise required by law.

Depending on Customer configuration, Personal Data may include:

Processor does not intentionally collect sensitive personal data unless Customer configures or uploads such data.

Data Subjects may include:

Customer is responsible for:

Processor does not provide legal advice regarding Customer’s compliance obligations.

Processor shall maintain reasonable and appropriate safeguards including, where applicable:

A summary of current security measures may be provided upon reasonable request

Customer authorizes Processor to engage Subprocessors necessary for service delivery.

Current Subprocessors are listed at here .

Customer acknowledges that Personal Data may be processed in the United States and other countries where Processor or its Subprocessors operate.

Where required by Applicable Data Protection Law, Processor shall implement appropriate safeguards for international transfers, including Standard Contractual Clauses (SCCs) where applicable.

Additional transfer documentation may be provided upon reasonable request.

Where Processor receives a request directly from a Data Subject relating to Personal Data processed on behalf of Customer, Processor may:

Customer remains primarily responsible for responding to such requests.

In the event of a confirmed Personal Data Breach affecting Customer Personal Data, Processor shall:

Processor is not responsible for breaches caused by Customer systems, Customer misuse, or third-party systems outside Processor’s control.

For small-business SaaS operations, formal on-site audits are generally not supported unless required by law.

Processor shall instead provide reasonable documentation, compliance information, and responses to standard privacy/security questionnaires where appropriate.

Additional audit requests may be subject to reasonable limitations and cost recovery.

During the Agreement term, Customer may retrieve Customer Data at any time using the Service’s available controls.

Upon termination of Services and subject to lawful retention requirements, Processor shall:

This requirement shall not apply to the extent Worksnaps is required by applicable law to retain some or all of the Personal Data, or to Personal Data it has archived on back-up systems, which such Personal Data Worksnaps shall securely isolate and protect from any further processing, except to the extent required by applicable law.

The liability of each party under this DPA shall be subject to the limitations and exclusions set forth in the Terms of Service unless otherwise required by Applicable Data Protection Law.

This DPA shall be governed by the laws specified in the Terms of Service unless otherwise required by applicable privacy law.

Recommended articles