Takes effect 06.08.2026
Takes effect 06.08.2026
This Data Processing Addendum (the "DPA") forms part of the Terms of Service (the "Agreement") between Planfix, Inc., a corporation organized under the laws of the State of California, USA, registered at 4445 Eastgate Mall, Suite 200, San Diego, CA 92121, USA (the "Operator") and the Client, and applies to the extent that Regulation (EU) 2016/679 (the "GDPR") or equivalent data-protection legislation of the European Economic Area, the United Kingdom, or Switzerland applies to the Processing of Personal Data by the Operator on behalf of the Client in connection with the Service.
This DPA is deemed accepted by the Client upon acceptance of the Agreement or upon continued use of the Service after the DPA is published and notified under Clause B.8 of the Agreement. Upon the Client's written request, the Operator will execute this DPA as then published as a separate signed document.
1. DEFINITIONS
1.1. Capitalized terms used but not defined in this DPA (including "Service", "Account", "User", "User Content") have the meanings given in the Agreement and the Privacy Policy ; if both define a term differently, the Privacy Policy meaning applies for the purposes of this DPA. In this DPA, the "Operator" means Planfix, Inc., the entity defined as the "Provider" in the Agreement, and the "Client" means the entity defined as the "Customer" in the Agreement. "User Data" means Personal Data and User Content submitted to the Account (defined in the Privacy Policy as "User data").
1.2. "Personal Data", "Controller", "Processor", "Processing", "Data Subject", "Personal Data Breach", and "Supervisory Authority" have the meanings given in the GDPR.
1.3. "Client Personal Data" means Personal Data contained in User Data that the Operator Processes on behalf of the Client in the course of providing the Service.
1.4. "Subprocessor" means a third party engaged by the Operator to Process Client Personal Data on behalf of the Client.
1.5. "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
2. ROLES AND SCOPE OF PROCESSING
2.1. For the purposes of this DPA, the Client is the Controller of Client Personal Data and the Operator is the Processor. Where the Client acts as a processor for a third-party controller, the Client warrants that its instructions to the Operator are consistent with that controller's instructions, and the Operator acts as the Client's subprocessor.
2.2. The subject matter, duration, nature and purposes of the Processing, and the categories of Personal Data and Data Subjects are set out in Annex I.
2.3. This DPA does not apply to Personal Data that the Operator Processes as an independent controller, including account registration, billing, and marketing data, which are governed by the Privacy Policy. Processing subject to the California Consumer Privacy Act is addressed in the Operator's California Privacy Notice; this DPA does not diminish the commitments in Section 2 of that Notice.
3. PROCESSING ON DOCUMENTED INSTRUCTIONS
3.1. The Operator shall Process Client Personal Data only on the Client's documented instructions, including with regard to transfers to a third country, unless required to do so by law to which the Operator is subject; in such a case, the Operator shall inform the Client of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
3.2. The Client's documented instructions consist of: (a) the Agreement, this DPA, and the Privacy Policy; (b) the Client's configuration of and use of the Service, including Account settings, features, integrations, and the API; and (c) other written instructions agreed by the parties. The Operator shall immediately inform the Client if, in its opinion, an instruction infringes the GDPR or other applicable data-protection provisions.
4. CONFIDENTIALITY OF PERSONNEL
4.1. The Operator shall ensure that persons authorized to Process Client Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and Process Client Personal Data only to the extent necessary to provide the Service.
5. SECURITY OF PROCESSING
5.1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Operator shall implement and maintain the technical and organizational measures set out in Annex II.
5.2. The Operator may update the measures in Annex II from time to time, provided that such updates do not materially reduce the overall level of protection of Client Personal Data during the term of the Agreement.
6. SUBPROCESSORS
6.1. The Client provides a general written authorization for the Operator to engage Subprocessors for the Processing of Client Personal Data. The current list of Subprocessors, including their roles and countries of Processing, is maintained at https://planfix.com/doc/subprocessors/ (Annex III).
6.2. The Operator shall inform the Client of any intended addition or replacement of Subprocessors at least thirty (30) days before the change takes effect, by updating the page referred to in Section 6.1 and by notifying the email address designated for the Account, thereby giving the Client the opportunity to object to such changes.
6.3. If the Client objects on reasonable data-protection grounds, the parties shall discuss the objection in good faith. If no resolution is reached within thirty (30) days of the objection, the Client may terminate the Agreement or, where the affected part is technically and commercially severable, the affected part of the Service, by written notice, and the Operator shall refund the portion of prepaid fees attributable to the unexpired part of the terminated Service or Agreement. The Operator may proceed with the change on the notified date; the Client's remedy for an unresolved objection is termination under this Section 6.3.
6.4. The Operator shall impose on each Subprocessor, by way of a contract, data-protection obligations that are in substance no less protective than those set out in this DPA, and shall remain fully liable to the Client for the performance of the Subprocessor's obligations.
7. INTERNATIONAL TRANSFERS
7.1. The Operator is established in the United States of America, and Processing under this DPA involves the transfer of Client Personal Data to the United States and remote access from the countries listed in Annex I.B. Production data is hosted in data centers located in the European Union, as further described in Annex II and Annex III.
7.2. Where the GDPR applies and Client Personal Data is transferred to a country that is not the subject of an adequacy decision of the European Commission, the parties agree that such transfer is governed by the Standard Contractual Clauses, Module Two (controller to processor), which are incorporated into this DPA by reference. The Client acts as the data exporter and the Operator acts as the data importer.
7.3. For the purposes of the Standard Contractual Clauses as incorporated: (a) the optional docking clause in Clause 7 is included; (b) in Clause 9(a), Option 2 (general written authorization) applies, and the time period is thirty (30) days; (c) the optional language in Clause 11(a) on independent dispute-resolution bodies is not included; (d) in Clause 17, Option 1 applies and the clauses are governed by the law of Ireland; (e) in Clause 18(b), disputes shall be resolved before the courts of Ireland; (f) Annexes I and II to the Standard Contractual Clauses are completed by Annexes I and II to this DPA, and Annex III to the Standard Contractual Clauses is completed by Annex III to this DPA.
7.4. In the event of any conflict between this DPA or the Agreement and the Standard Contractual Clauses, the Standard Contractual Clauses prevail with respect to the transfers they govern.
7.5. Where the transferred data falls within the scope of the UK GDPR, the Standard Contractual Clauses apply as supplemented by the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner. Where the transferred data falls within the scope of the Swiss Federal Act on Data Protection, the Standard Contractual Clauses apply with the adaptations recognized by the Swiss Federal Data Protection and Information Commissioner, including references to the competent Swiss authority and Swiss law where required.
8. ASSISTANCE TO THE CLIENT
8.1. Taking into account the nature of the Processing, the Operator shall assist the Client by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Client's obligation to respond to requests for exercising Data Subjects' rights.
8.2. The Service provides the Client with self-service tools to access, rectify, export, restrict, and delete Personal Data of specific Data Subjects within the Account. If the Operator receives a request from a Data Subject relating to Client Personal Data, the Operator shall forward the request to the Client without undue delay and shall not respond to it on the merits, except to direct the Data Subject to the Client.
8.3. Taking into account the nature of the Processing and the information available to it, the Operator shall assist the Client in ensuring compliance with the Client's obligations regarding security of Processing, notification of Personal Data Breaches, data-protection impact assessments, and prior consultation with Supervisory Authorities.
9. PERSONAL DATA BREACH
9.1. The Operator shall notify the Client without undue delay, and in any event no later than seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Client Personal Data. The notification will be sent to the email address designated for the Account.
9.2. The notification shall, to the extent the information is available to the Operator, describe the nature of the Personal Data Breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its possible adverse effects. Information may be provided in phases as it becomes available.
9.3. The Operator's notification of or response to a Personal Data Breach shall not be construed as an acknowledgment of fault or liability.
10. DELETION AND RETURN OF DATA
10.1. During the term of the Agreement, the Client may export User Data using the built-in export tools of the Service and the API.
10.2. Upon termination or expiry of the Agreement, or upon deletion of the Account, the Operator shall delete Client Personal Data in accordance with the timelines of the Data Deletion Procedure : a copy of the Account is retained for 180 days following deletion, after which it is permanently and irreversibly deleted; residual copies in encrypted offline backups are purged within 180 days of deletion; verified deletion requests are fulfilled within 30 days under and subject to the Data Deletion Procedure. Upon the Client's written request made before deletion, the Operator shall instead enable the Client to export a complete copy of the Account data.
10.3. The Operator may retain Client Personal Data to the extent required by law to which the Operator is subject, for the duration and purposes required by that law, protected by the measures of Annex II.
11. AUDITS AND INFORMATION
11.1. The Operator shall make available to the Client all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA, including the documentation referred to in Annex II and the security documentation published by the Operator.
11.2. The Operator shall allow for and contribute to audits, including inspections, conducted by the Client or an auditor mandated by the Client, under the following conditions: (a) no more than once in any twelve (12) month period, except after a Personal Data Breach affecting Client Personal Data or where required by a Supervisory Authority; (b) upon at least thirty (30) days' prior written notice; (c) during regular business hours, without unreasonable disruption to the Operator's operations; (d) subject to confidentiality obligations; and (e) excluding access to data of other clients, to systems shared with other clients except as necessary, and to the Operator's premises where access is controlled by third-party data-center operators, in which case the Operator shall provide the available attestations of such operators.
11.3. Each party bears its own costs of an audit. The parties shall first seek to satisfy audit requests through written information and existing documentation.
12. SPECIAL CATEGORIES OF DATA
12.1. The Service is a general-purpose work-management service provided independently of the content of the data submitted to it. The Service is not designed or certified for the Processing of special categories of Personal Data within the meaning of Article 9 GDPR, of data relating to criminal convictions and offences, or of data subject to sector-specific regulation (including health records).
12.2. The Client determines the categories of Personal Data submitted to the Account. If the Client chooses to submit special categories of Personal Data, the Client is responsible for ensuring a valid legal basis under Articles 6 and 9 GDPR and for assessing whether the measures set out in Annex II are appropriate for such data. The Operator provides no safeguards, warranties, or conditions specific to special categories of Personal Data beyond the measures set out in Annex II.
13. LIABILITY AND PRECEDENCE
13.1. The liability of each party under this DPA is subject to the exclusions and limitations of liability set out in the Agreement, except where such limitations are prohibited by applicable law or by the Standard Contractual Clauses with respect to the transfers they govern. The exclusions of liability in the Agreement for loss of information or inaccuracy of information do not apply to a party's breach of this DPA; the aggregate monetary cap on liability set out in the Agreement continues to apply.
13.2. In the event of any conflict between this DPA and the Agreement or the Privacy Policy with respect to the Processing of Client Personal Data, this DPA prevails. Section 7.4 governs conflicts with the Standard Contractual Clauses.
13.3. This DPA is effective for as long as the Operator Processes Client Personal Data under the Agreement and automatically terminates upon completion of the deletion described in Section 10.
ANNEX I — DESCRIPTION OF PROCESSING
A. LIST OF PARTIES
Data exporter: the Client (name, address, contact person, and signature as identified in the Account or in a separately executed copy of this DPA), acting as Controller.
Data importer: Planfix, Inc., 4445 Eastgate Mall, Suite 200, San Diego, CA 92121, USA; contact: https://planfix.com/support/ , Attn: Privacy Office; acting as Processor.
B. DESCRIPTION OF TRANSFER
- Categories of Data Subjects: Users of the Account (employees, contractors, and other persons invited by the Client); the Client's customers, suppliers, and other contacts whose data the Client submits to the Account.
- Categories of Personal Data: identification and contact data (names, email addresses, phone numbers), business data, correspondence and other content submitted by Users, usage and log data related to the Account. The Service is content-agnostic: the actual categories are determined by the Client.
- Special categories of data: none intended by design; may be submitted only under the conditions of Section 12 of this DPA, with the responsibilities set out there.
- Frequency of the transfer: continuous, for the duration of the Agreement.
- Nature and purpose of the Processing: hosting, storage, transmission, display, and other operations necessary to provide the work-management Service, including technical support at the Client's request.
- Retention: for the duration of the Agreement and thereafter per Section 10 (180-day deletion cycle; 30-day deletion upon verified request).
- Locations of Processing: Client Personal Data is hosted in the geographic hosting cluster selected by the Client from the options offered by the Operator (currently: European Union (Germany, with file storage and backups in Ireland), United States, Singapore, and Kazakhstan); the providers operating each cluster are identified in the Subprocessor list referred to in Annex III. Backup copies for all clusters are stored in EU regions (Annex II). Technical support, development, administration, and corporate operations are performed from the United States of America.
C. COMPETENT SUPERVISORY AUTHORITY
The Supervisory Authority of the EU Member State in which the data exporter is established, determined in accordance with Clause 13 of the Standard Contractual Clauses.
ANNEX II — TECHNICAL AND ORGANIZATIONAL MEASURES
- Encryption in transit: access to Account data over TLS 1.2 or higher (TLS 1.3 supported), with HTTP Strict Transport Security and modern cipher suites providing forward secrecy.
- Encryption at rest: Client-uploaded files stored on Amazon S3 are encrypted at rest (AES-256); backup archives are encrypted (AES-256).
- Access control on the Client's side: role-based permissions managed by the Client; two-factor authentication (TOTP); single sign-on (SAML 2.0) with SCIM provisioning; restriction of Account access by IP address and by time; Account-level audit logs of user activity available to the Client.
- Access control on the Operator's side: least-privilege access; production access is limited to a small number of authorized engineers, bound by confidentiality (Section 4), with access from the locations listed in Annex I.B; administrative access via key-based SSH or VPN with multi-factor authentication; periodic access reviews; administrative actions are logged.
- Backups and recovery: daily encrypted backups with point-in-time recovery within a 90-day window; all backup copies, for all geographic clusters, are stored in EU regions only, with EU-to-EU cross-region replication; offline backup copies purged within 180 days of account deletion; periodic restore testing.
- Logging and monitoring: centralized security logging with continuous monitoring and alerting; security and audit logs retained for at least one (1) year, progressively de-identified.
- Physical security: data centers of third-party infrastructure providers holding independent certifications (including ISO 27001) with on-site security staff, access controls, video surveillance, redundant power, and automatic fire suppression; physical access controlled by the data-center operators.
- Data separation: each Account operates on a dedicated database schema; file storage is segregated by Account-specific prefixes; tenant-scoped authorization checks are enforced on every request within the multi-tenant architecture.
- Application security: secure development lifecycle with peer code review, static analysis, and dependency scanning; web application firewall and rate limiting; an external responsible-disclosure program.
- Organizational measures: documented incident-response plan with a 24/7 on-call team; documented disaster-recovery and business-continuity plans reviewed at least annually; documented backup and recovery policy; background checks of personnel as permitted by law; confidentiality commitments; recurring security-awareness training; access on a need-to-know basis.
ANNEX III — SUBPROCESSORS
The current list of the Operator's Subprocessors, including their roles and countries of Processing, is maintained at https://planfix.com/doc/subprocessors/ . That list, as updated from time to time in accordance with Section 6, constitutes the agreed list of Subprocessors and completes Annex III to the Standard Contractual Clauses.