Snapshot 27328
Normalized text
Scripts and page chrome removed; this is what change detection compares.
OpenGov Data Processing Addendum Last Modified: 9/1/2026 This Data Processing Addendum (“DPA”) is incorporated by reference into and supplements the Master Services Agreement (“MSA”) or the End User License Agreement (“EULA”), as applicable, by and between OpenGov and the Customer. This DPA applies to the extent OpenGov processes Personal Data on behalf of Customer in connection with the Software Services and/or Professional Services provided by OpenGov. Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. 1.Definitions. 1.1. “Controller” means the party that determines the purpose and means of processing Personal Data, or as otherwise defined in the applicable law or regulation (including a “Business” as such term is defined under any applicable Data Privacy Law). 1.2. “Data Privacy Laws” means any applicable laws, or regulations concerning privacy or data protection in the USA, including but not limited to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, the “CCPA”), the Virginia Consumer Data Protection Act (“VCDPA”), the Colorado Privacy Act (“CPA”), and any equivalent or successor laws. 1.3. “Data Subject” means a natural person whose Personal Data is Processed. 1.4. “Personal Data” means Customer Data that: (a) relates to, describes, identifies, or can reasonably be associated with or linked, directly or indirectly, to an identified or identifiable natural person or household including, without limitation, “personal information,” “personally identifiable information,” “sensitive personal information,” or similar terms as defined under applicable Data Privacy Laws; and (b) is Processed by OpenGov, or its agents or subcontractors, for the purposes of providing the Professional Services and/or Software Services. Notwithstanding the foregoing, Personal Data shall not include any Personal Data provided by Customer (including any such data transmitted through the Software Services) to OpenGov in a manner that makes such data public. 1.5. “Personal Data Breach” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed. 1.6. “Process” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means. “Processing,” “Processes,” and “Processed” shall be interpreted accordingly. 1.7. “Processor” means the entity which Processes Personal Data on behalf of the Controller, or as otherwise defined in the applicable law or regulation (including a “Service Provider”, as such term is defined under any applicable Data Privacy Law). 1.8. “Sub-processor” means an entity appointed by OpenGov to Process Personal Data on its behalf. 2.Purpose. This DPA governs the Processing of Personal Data under the Agreement and is entered into by the parties to ensure compliance with the Data Privacy Laws, where applicable. 3.Roles. For the avoidance of doubt, OpenGov shall be the Processor and the Customer shall be the Controller or Processor, as applicable. 4.Processing of Personal Data. 4.1. Customer’s Processing of Personal Data. Customer, whether acting as Controller or Processor, shall Process Personal Data through the Software Services and/or Professional Services in compliance with all applicable Data Privacy Laws, including any notice obligations regarding OpenGov as Processor. Customer is solely responsible for the accuracy, quality, and lawfulness of the Personal Data and its collection, and warrants that its use of the Services does not infringe on any Data Subject’s rights. 4.2. OpenGov’s Processing of Personal Data. OpenGov, as the Processor, shall only Process Personal Data as permitted by the Agreement and in compliance with all applicable Data Privacy Laws. OpenGov shall maintain the confidentiality of all Personal Data provided or made available by the Controller and shall not disclose the Personal Data except as necessary to perform its obligations under the Agreement, to comply with applicable laws, or as expressly permitted in writing by the Controller. The Processor shall ensure that all persons authorized to process the Personal Data are subject to a duty of confidentiality under applicable laws or the Agreement. 5.Data Processing Restrictions. Customer shall not transmit to OpenGov or otherwise cause OpenGov to Process any data outside the scope of Personal Data, including but not limited to biometric information, criminal justice information, or payment card data governed by the Payment Card Industry Data Security Standard (PCI DSS). Customer will not transmit or cause OpenGov to Process any data related to an individual’s physical or mental health or condition, health treatment, or payment for health care except in connection with OpenGov’s Human Capital Management and/or Payroll product. OpenGov shall have no obligation or liability arising from any such unauthorized data. 6.Business Associate Agreement. Subject to Section 5 of this DPA, to the extent Customer transmits to OpenGov or causes OpenGov to Process any Protected Health Information, as defined by the Health Insurance Portability and Accountability Act (HIPAA), the parties agree to comply with the terms of the Business Associate Agreement, located at https://opengov.com/business-associate-agreement/, which is incorporated into the Agreement by reference. 7.Sub-Processors. OpenGov may engage Sub-processors that Process Personal Data. OpenGov will enter into a written agreement with each Sub-processor imposing data protection obligations to ensure an adequate level of protection for Personal Data, consistent with applicable Data Privacy Laws and no less protective than OpenGov’s obligations under this DPA. 8.Security Measures. OpenGov will use commercially reasonable security measures to protect Personal Data and ensure the confidentiality, integrity, and availability of OpenGov’s systems. These measures include industry-standard encryption, access controls, network monitoring, regular audits, and employee security training. OpenGov reviews and updates its security practices to address emerging threats. 9.Breach Notification. In the event of a Personal Data Breach, OpenGov shall notify Customer in the most expedient time possible and without unreasonable delay. Such notice shall include, to the extent known at the time of notification: (a) the general nature of the incident, including the date; (b) the categories of affected individuals and records; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address and mitigate its adverse effects. OpenGov shall provide regular updates regarding any material developments and shall reasonably cooperate with Customer to ensure compliance with applicable Data Privacy Laws. 10.Processing Obligations. With respect to the processing of Personal Data by OpenGov on behalf of Customer, OpenGov agrees to the following: 10.1. To the extent that a Data Privacy Law applies to OpenGov, OpenGov shall comply with such Data Privacy Law in the processing of Personal Data; 10.2. OpenGov shall adhere to Customer’s instructions regarding the Processing of Personal Data, and shall not use or disclose it for any purpose other than as provided in the Agreement; 10.3. OpenGov will not sell or otherwise make Personal Data available to any third party for monetary or other valuable consideration; 10.4. OpenGov will not share Personal Data with any third party for cross-context behavioral advertising; 10.5. Customer will have sole responsibility in responding to rights asserted by an individual in relation to Personal Data under applicable Data Privacy Laws, and OpenGov shall, to the extent reasonably possible, assist Customer in responding to a Data Subject’s request under applicable Data Privacy Laws; and 10.6. Upon written request, and no more than once per year, OpenGov shall provide Customer’s designee with a copy of OpenGov’s SOC-2 report to demonstrate compliance with Data Privacy Laws, subject to confidentiality obligations. 11.Survival. The obligations of this DPA shall survive so long as OpenGov retains any Personal Data. 12.Legal Effect. Except as expressly amended or modified by this DPA, all other terms of the Agreement shall remain unchanged and in full force and effect. 13.Conflict. In the event of any conflict between the main body of the Agreement and this DPA, this DPA will control.