Third Party Index

Snapshot 25945

Document
Data processing addendum
URL
https://teamhood.com/data-processing-addendum/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
79105 bytes
SHA-256 (raw)
4419fd17efc913d865191e65680d7ef3bd0af307fe8dacc635f118aac2754fd2
SHA-256 (normalized text)
a5fa068c19a6e61938b6d2a4921fb1b4970d94f77d35de3cab36aeddfe52c24b

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Login
Get started
DATA PROCESSING ADDENDUM
This Data Processing Addendum (“DPA”) forms an integral part of the Terms of Use and any and all agreements (collectively – “Agreement”) governing the use of Teamhood, a web-based Software as a Service (SaaS) application available at www.teamhood.com („Teamhood“), executed between UAB Eylean (“Company”) and you (“Client”; each “Party” and together – “Parties”) and applies to the extent that the Company processes Personal Data on behalf of the Client, in the course of the performance of its obligations under the Agreement.
By accepting the Agreement, the Client accepts the terms of this DPA. This DPA forms an integral part of the Agreement.
All capitalized terms not defined herein shall have the meaning set forth in the Agreement or Data Protection Laws.
Definitions
„Data Protection Laws“ mean, as applicable, any and all domestic and foreign laws, rules, directives and regulations, on any local, provincial, state, federal or national level, pertaining to data privacy, data security and/or the protection of Personal Data, including but not limited to the (i) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”); (ii) the GDPR as transposed into UK national law and the Data Protection Act 2018 (collectively – “UK Data Protection Laws”); (iii) the Swiss Federal Data Protection Act of 25 September 2020 and Data Protection Ordinance of 31 August 2022 (“Swiss Data Protection Laws”) and (iv) any other applicable data protection or privacy legislation in any jurisdiction in which the Parties operate or process Personal Data under this Agreement, including any amendments or replacements to the foregoing.
“Data Subject” means an individual to whom Personal Data relates.
“Permitted Purposes” mean any purposes in connection with the Company performing its obligations under the Agreement.
“Personal Data Breach” means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
“Security Measures” means commercially reasonable security policies, standards, and practices that are appropriate and proportionate to the size and complexity of the Company’s business, the sensitivity of the data collected, processed, and stored, and the nature of the Company’s services, as further described in Annex 2 to the DPA.
“Sub-Processor” means any vendor, service provider engaged by the Company that may process Personal Data pursuant to the terms of the Agreement.
„User“ means any individual authorized or invited by the Client to access and use Teamhood under the Client’s account. This includes the Client themself when acting as an individual user of the Teamhood.
The terms „Controller“, „Personal Data“, „Processor“ and shall have the meanings ascribed to them in GDPR, as applicable.
Application of this DPA
This DPA will only apply to the extent all of the following conditions are met: (a) the Company processes Personal Data that is made available by the Client (whether directly by the Client or the User) when using Teamhood under the Agreement; and (b) the Data Protection Laws apply to the processing of Personal Data.
Roles of the Parties
In respect of the Parties’ rights and obligations under this DPA regarding the Personal Data, the Parties hereby acknowledge and agree that the Client is the Controller and the Company is a the Processor of Personal Data submitted or uploaded to Teamhood by the Client and Users while using Teamhood. For avoidance of any doubts, the Company acts as independent Controller of Personal Data when processing Personal Data related to the administration, including support, of the Teamhood platform (e.g., account details, billing details, usage logs, service-related data, contact information, etc.) and processes this Personal Data in accordance with applicable Data Protection Laws and its published Privacy Policy, available at www.teamhood.com.
Compliance with Data Protection Laws
Each Party shall comply with its respective obligations under the applicable Data Protection Laws.
The Company shall provide reasonable cooperation and assistance to the Client in relation to the Company’s processing of Personal Data in order to allow the Client to comply with its obligations as Controller under the Data Protection Laws.
The Company agrees to notify the Client promptly if it becomes unable to comply with the terms of this DPA and will take reasonable and appropriate measures to remedy such non-compliance.
Throughout the duration of the DPA, the Client agrees and warrants that:
Personal Data has been and will continue to be processed by the Client in accordance with the relevant provisions of the applicable Data Protection Laws;
The Client is solely responsible for determining the lawfulness of the data processing instructions (“Processing Instructions”) it provides to the Company and shall provide the Company only instructions that are lawful under Data Protection Laws;
The processing of Personal Data by the Company for the Permitted Purposes, as well as any Processing Instructions issued to the Company in connection with such processing, have been and will continue to be carried out in compliance with the applicable provisions of Data Protection Laws;
The Client has informed the Data Subjects of the processing and transfer of Personal Data pursuant to this DPA and has obtained all necessary consents or established other lawful grounds for such processing and transfer, including, without limitation, any consent required to comply with the Processing Instructions and to fulfil the Permitted Purposes.
Processing Purpose and Instructions
The subject matter of the processing, the nature and purpose of the processing, the type of Personal Data and categories of Data Subjects, are set out in Annex 1 to the DPA.
The Company shall process Personal Data solely for the Permitted Purposes and in accordance with the Client’s written Processing Instructions, the Agreement, and applicable Data Protection Laws. If the Company is required by a law to which it is subject to process Personal Data beyond the Client’s instructions, it shall notify the Client of that legal requirement prior to such processing, unless the law prohibits the Company from providing such notice.
To the extent that any Processing Instructions may result in the processing of any Personal Data outside the scope of the Agreement and/or the Permitted Purposes, then such processing will require prior written agreement between the Company and the Client, which may include any additional fees that may be payable by the Client to the Company for carrying out such Processing Instructions.
The Company shall not retain, use or disclose the Personal Data for any purpose other than for the Permitted Purpose, except as required under applicable laws, or as otherwise permitted under Data Protection Laws.
Reasonable Security and Safeguards
The Company shall use Security Measures (i) to protect the availability, confidentiality, and integrity of any Personal Data processed by the Company in connection with the Agreement, and (ii) to protect such data from Personal Data Breaches. Such Security Measures include, without limitation, the security measures set out in Annex 2 to the DPA.
The Security Measures are subject to technical progress and development and the Company may update or modify the Security Measures from time to time provided that such updates and modifications do not result, in the Company’s discretion, in the material degradation of the overall security of the services procured by the Client. The Company will provide notice of material changes in Security Measures, when possible, at least 10 days before the change will take effect.
The Company shall take reasonable steps to ensure the reliability of its staff and any other person acting under its supervision who processes Personal Data. The Company shall ensure that persons authorized to process Personal Data are under an appropriate obligation of confidentiality.
Personal Data Breaches
Upon becoming aware of a Personal Data Breach, the Company will notify the Client without undue delay and will provide reasonable information relating to the Personal Data Breach as reasonably requested by the Client. The Company will use reasonable endeavors to assist the Client in mitigating, where possible, the adverse effects of any Personal Data Breach as relates to the Company’s services.
Audit
The Company shall provide the opportunity and facilitate conditions for the Client to verify (conduct an audit) at a mutually agreed time, at the Client‘s expense, how the requirements specified in this DPA are being fulfilled.
The scope and conditions of such verification (audit):
The audit may be conducted with reasonable prior notice, which shall be no less than four (4) weeks, except in cases where there are significant obstacles to such notice;
The audit may only be conducted in a manner that does not disrupt the daily operations of the Company;
During the audit, responses will be provided to the Client‘s written questions, and the opportunity will be given to interview the relevant Company specialist.
The Client may engage a third party — an independent auditor — to conduct the audit, provided that such a party is not a competitor of the Company. If the Company objects to the chosen auditor, the Client must select a different auditor.
The Company shall not grant the Client or any third party engaged by the Client access to the Company‘s systems and/or IT infrastructure used to provide services under the Agreement.
Any information obtained by the Client during such audit shall be subject to the provisions of the Agreement (including confidentiality and other applicable provisions). The independent auditor must commit to ensuring the complete confidentiality of any information received from the Company.
Cooperation and Assistance
If Company receives any requests from individuals or applicable data protection authorities relating to the processing of Personal Data under the Agreement, including requests from individuals seeking to exercise their rights under Data Protection Laws, the Company will promptly redirect the request to Client. Company will not respond to such communication directly without the Client’s prior authorization, unless legally compelled to do so. Notwithstanding the foregoing, the Company may acknowledge receipt of the request to the individual. The Client is responsible for verifying that the requestor is the Data Subject whose information is being sought or their duly authorized representative. The Company bears no responsibility for information provided in good faith to the Client in reliance on this Clause.
If the Company receives a legally binding order, demand, or request for the disclosure of Personal Data subject to this DPA, it shall, to the extent permitted by law, promptly notify the Client upon receipt. It is hereby clarified that if the Client does not respond within three (3) business days or within any shorter timeframe required by applicable law or the issuing authority, the Company shall be entitled to disclose the requested information.
Notwithstanding the foregoing, the Company will cooperate with the Client with respect to any action taken by it pursuant to such order, demand or request. The Client shall cover all costs incurred by the Company in connection with its provision of such assistance.
Upon reasonable notice, the Company shall:
Taking into account the nature of the processing, provide reasonable assistance to the Client by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Client’s obligation to respond to requests for exercising Data Subject’s rights, at Client’s expense;
Provide reasonable assistance to the Client in ensuring Client’s compliance with its obligation to carry out data protection impact assessments or prior consultations with data protection authorities with respect to the processing of Personal Data, provided, however, that if such assistance entails material costs or expenses to the Company, the Parties shall first come to agreement on the Client reimbursing the Company for such costs and expenses.
Use of Sub-Processors
The Client provides a general authorization to the Company to appoint Sub-Processors in accordance with this Clause.
The Company may continue to engage those Sub-Processors already contracted as of the effective date of this DPA, as listed in Annex 3 to the DPA, which is available at the following link: [insert link].
The Company undertakes to inform the Client in advance of any intended changes related to the engagement or replacement of a Sub-processor, and the Client shall have the right to raise objections thereto.
The Client must submit any objections to the Company within two (2) weeks from the date of receiving information about the intended changes concerning the Sub-processor. If the Client raises an objection, the Company may, at its discretion, continue to perform its obligations under the Agreement or provide an alternative proposal regarding the Sub-processor for review. If the performance of the Company’s obligations becomes significantly more difficult without the proposed change, for example, if the Company incurs disproportionately high costs, or if the Parties fail to agree on an alternative proposal, the Parties may terminate this Agreement. The Company undertakes to notify the Client of the termination of the Agreement at least one (1) month in advance
With respect to each Sub-Processor, the Company shall ensure that the arrangement between the Company and the Sub-Processor is governed by a written contract, including terms which offer at least the same level of protection as those set out in this DPA and meet the requirements of Data Protection Laws, including the requirements of article 28(3) of the GDPR, as applicable.
The Company will be responsible for any acts, errors or omissions by its Sub-Processors, which may cause the Company to breach any of its obligations under this DPA.
The Company will only disclose Personal Data to Sub-Processors for the specific purposes of carrying out the services on Company’s behalf under the Agreement.
Location of Data Processing
The Company may transfer or access Personal Data from outside the jurisdiction in which the data originated, provided that:
such transfer is necessary for the performance of the services under this Agreement; and
appropriate safeguards are in place to ensure an adequate level of protection for the Personal Data in accordance with applicable Data Protection Laws.
The Company shall inform the Client, upon request, of the applicable safeguards relied upon for such transfers.
Data Transfer Compliance (applicable to the Clients subject to laws other than GDPR, UK Data Protection Laws and Swiss Data Protection Laws)
Notwithstanding section 11 of this DPA, the Client shall be solely responsible for ensuring that all data transfers carried out under this DPA comply with applicable Data Protection Laws to which it is subject. This includes, but is not limited to, the implementation of any legally required safeguards, such as the execution of appropriate transfer mechanisms with the Company recognized under such laws prior any data transfer. The Client agrees to promptly notify the Company of any requirements it must fulfil in relation to such data transfers prior executing the Agreement.
Data Retention and Destruction
Upon the expiration of this DPA and the Agreement, the Company undertakes, at the Client‘s choice, to return the Personal Data received and processed on behalf of the Client or to delete and destroy it, provided that such deletion does not conflict with any laws applicable to the Company. Upon the Client‘s request, the deletion of Personal Data must be documented and confirmed in writing to the Client.
Liability
The Company shall be liable for the confidentiality and security of the Personal Data processed from the moment the Personal Data is received and throughout the term of the Agreement.
The Company shall only be liable for damages caused by the processing of Personal Data if it has failed to comply with obligations specifically imposed on data processors by applicable Data Protection Laws or if it acted in disregard of or in violation of the legitimate Processing Instructions of the Client. In such cases, the Company shall be liable only for the damages directly resulting from breaches of obligations assigned to the Company. The Company‘s liability shall be subject to the liability terms set forth in the Agreement, including any limitations. The Company‘s liability shall be limited to the amount paid by the Client to the Company under the Agreement in the six (6) months preceding the occurrence of the circumstances giving rise to liability under this DPA.
General
Any claims brought under this DPA will be subject to the terms and conditions of the Agreement, including the exclusions and limitations set forth in the Agreement.
In the event of a conflict between the Agreement (or any document referred to therein) and this DPA, the provisions of this DPA shall prevail.
The Company may change this DPA if the change is required to comply with Data Protection Laws, a court order or guidance issued by the regulator, provided that such change does not: (i) seek to alter the categorization of the Company as the Processor; (ii) expand the scope of, or remove any restrictions on, either Party’s rights to process Personal Data; or (iii) have a material adverse impact on the Client, as reasonably determined by the Company.
If the Company intends to amend this DPA and reasonably determines that such amendment will have a material adverse impact on the Client, the Company shall notify the Client at least ten (10) days in advance of the effective date of the change, or within a shorter period if required to comply with applicable law, regulation, court order, or regulatory guidance.
ANNEX 1 TO DPA
DESCRIPTION OF PERSONAL DATA PROCESSED
This Annex forms an integral part of the DPA.
SUBJECT AND PURPOSE OF DATA PROCESSING:
Execution of Agreement and provision of services via Teamhood.
CATEGORIES OF DATA SUBJECTS:
Categories of Data Subjects may vary depending on the Client‘s use of the services and may include any individual whose Personal Data is shared by the Client and Users while using Teamhood.
CATEGORIES OF PERSONAL DATA:
The Company may process any category of Personal Data that the Client and Users choose to provide while using Teamhood, including but not limited to personal identification information, contact information, account details, usage data, and other data submitted at the Client‘s discretion.
NATURE OF THE PROCESSING
Provision of services and data storage.
RETENTION PERIOD
As long as the Company processes Personal Data on behalf of the Client.
ANNEX 2 to DPA
SECURITY MEASURES
This Annex forms an integral part of the DPA.
The Company implements the following technical and organisational measures:
ENCRYPTION MEASURES
Measures by which readable text / information is transformed into unreadable, difficult-to-interpret character strings (encrypted text) through encryption methods.
Description of encryption measures: symmetric / asymmetric encryption is applied to communications between participants and/or servers.
PHYSICAL ACCESS CONTROL
Measures that physically prevent unauthorised persons from accessing IT systems and data processing equipment used to process Personal Data, as well as confidential files and data media.
Description of physical access control measures: restricting unauthorised access to data processing systems by locking premises, using access cards, and other locks.
LOGICAL ACCESS CONTROL
Measures preventing unauthorised persons from processing or using Personal Data.
Description of logical access control measures: managing system access and work sessions, using secure passwords, automatic computer locking mechanisms, and encryption of data media.
DATA ACCESS CONTROL
Measures ensuring that persons authorised to use data processing systems can only access Personal Data according to their granted access rights and that data cannot be read, copied, modified, or removed without permission during processing, use, and storage.
Data access control measures: prohibition of reading, copying, modifying, or deleting data in the system without authorisation, use of authorisation mechanisms and access rights upon request, application of a “clean desk” policy, and automatic device locking when away from the workplace.
SEPARATION RULE
Measures ensuring that data collected for different purposes is processed separately and isolated from other data and systems to prevent unintended use for other purposes than those for which they were collected.
Separation measures: separate processing of data collected for different purposes, based on authorisation measures, use of software and information systems grounded in client separation, and separation of development and production environments.
TRANSMISSION CONTROL
Measures ensuring that it is possible to verify and determine to whom Personal Data may be or has been transferred, using data transfer equipment.
Transmission control measures: during electronic transfer, encryption measures prevent data from being read, copied, modified, or removed, with records kept of data transfers and users conducting the transfer.
ACCESSIBILITY CONTROL
Measures ensuring that Personal Data is protected from accidental destruction or loss.
Accessibility measures: data is stored in a reliable environment with a backup procedure.
DOCUMENTATION AND PROCEDURES
Internal documents ensuring that personal data is processed in compliance with applicable Data Protection Law.
Documents and procedures: Company’s internal procedures for processing Personal Data.
ANNEX 3 TO DPA
LIST OF SUB-PROCESSORS
This Annex forms an integral part of the DPA.
The Company has engaged the following Sub-processors:
COMPANY DETAILS
SUB-PROCESSING SERVICES
LOCATION OF PROCESSING
Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland
Database storage
EU/EEA
Company
Contact Us
About Teamhood
Referral Program
Careers
Customer Stories
Security and Compliance
Release Notes
FAQs
Solutions
Agencies & Services
IT & PMO
Engineering Projects
Kanban System
Defense & Space
Agile Development
Resources
Knowledge Base
Product Videos
Project Management
Kanban
Agile
Team Performance
Comparisons
vs Microsoft Project
vs Asana
vs Trello
vs Monday
vs Businessmap
vs KanbanFlow vs Trello
vs KanbanTool vs Trello
vs Notion vs Asana
vs Jira vs Businessmap
vs MS Planner vs Trello
Featured in Blog
Best Kanban Board Tools
Workload Management Tools
Project Timeline Tools
PM Software with Dependencies
What is Kanban
Kanban vs Scrum vs Scrumban
Agency PM Strategies
Explore our Blog
© 2019-2025 Teamhood ®
DPA | Privacy Policy | Terms of Use
Teamhood uses cookies, to personalize content, ads and analyze traffic. By continuing to browse or pressing "Accept" you agree to our Cookie Policy.