Skip to main content

Legal · BETIHUT-LEGAL-DPA

Data Processing Addendum

Entity
AUTOMAIZE SOLUTIONS LTD
Reg. No.
HE 480609
Effective
18 August 2026
Status
Version 2.0 · Effective template

This Data Processing Addendum (the "DPA") forms part of the Employer Terms of Service between the Customer and AUTOMAIZE SOLUTIONS LTD. It governs only processing performed by Automaize as a processor on documented instructions; independent-controller processing is governed by the Privacy Notice and applicable law.

This DPA is concluded in accordance with Article 28 GDPR. In the event of conflict between this DPA and the Employer Terms of Service in respect of data protection, this DPA prevails.

1.Definitions

  1. 1.1Terms such as "controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given to them in the GDPR.
  2. 1.2"Applicable Data Protection Law" means the GDPR and the national data-protection laws applicable in Cyprus, Bulgaria and each territory in which the documented processing occurs.
  3. 1.3"Processor" means Automaize only to the extent that it processes personal data on a Controller's documented instructions. "Sub-processor" means an infrastructure provider engaged by Automaize in the documented processing chain.

2.Roles and scope of processing

  1. 2.1For a Customer-controlled workflow, the Customer determines the purposes and essential means and the applicable order identifies Automaize as processor. Automaize processes that data only on the documented instructions applicable to its role.
  2. 2.2This DPA does not apply where Automaize acts as an independent controller for service administration, platform accounts, security, consent and AI-accountability evidence, moderation, fraud prevention, technology compliance or any service Automaize is authorised to provide on its own account.
  3. 2.3The subject matter, duration, nature and purpose of the processing, the categories of data subjects and personal data, are described in Annex 1 (Details of Processing). This includes worker profile data, training and qualification records, medical-fitness outcomes and restrictions, equipment issue, permits, site-presence records, incident and near-miss reports, investigations, corrective actions, assistant transcripts, consent records and audit logs processed for the Customer's workplace-safety programme.
  4. 2.4Processing lasts for the term of the Customer's Service and the documented return/deletion period, subject to legal holds and mandatory retention. Data subjects include the Customer's workers, contractors, site visitors and authorised users; data may include identity and contact data, employment and site assignment, training and qualification evidence, medical-fitness outcomes and restrictions, equipment and permit records, presence records, incident and investigation records, communications, consent and technical-security data. Unlike a general business application, the Service is designed to hold occupational health data, which is special-category personal data under Article 9 GDPR: the Customer must document the Article 9 condition on which it relies, must instruct Automaize accordingly, must restrict that data to the roles that genuinely require it, and must not submit clinical records beyond the fitness outcome and restrictions its safety programme requires.

3.Obligations of each Processor

Automaize, while acting as a Processor, shall:

  1. 3.1process personal data only on the documented instructions of the Controller, including with regard to international transfers, unless required to do otherwise by law;
  2. 3.2ensure that persons authorised to process personal data are bound by an appropriate duty of confidentiality;
  3. 3.3implement the technical and organisational measures described in clause 5 and Annex 2;
  4. 3.4respect the conditions in clause 6 for engaging sub-processors;
  5. 3.5assist the Controller, taking into account the nature of the processing, in fulfilling its obligations to respond to data-subject requests and to ensure security, breach notification and data-protection impact assessments; and
  6. 3.6at the Controller's choice, delete or return all personal data at the end of the provision of the services, save to the extent retention is required by law.

4.Confidentiality

  1. 4.1Each Processor shall treat all personal data as confidential and shall not disclose it except as permitted under this DPA or as required by law.

5.Security

  1. 5.1Automaize shall implement appropriate technical and organisational measures proportionate to its role. Its platform measures are described in Annex 2 and the Information Security Statement.

6.Sub-processors

  1. 6.1The Controller grants Automaize general authorisation to engage the infrastructure providers listed in the Sub-processor Notice for the processing described in the applicable order.
  2. 6.2The appointing Processor shall impose data-protection obligations on each sub-processor that are no less protective than those in this DPA and remains responsible for that sub-processor as required by Article 28 GDPR.
  3. 6.3Automaize shall maintain an up-to-date processing chain and give the Controller prior notice of an intended material change, allowing the Controller to object on reasonable data-protection grounds.

7.Data-subject requests

  1. 7.1The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in responding to requests by data subjects to exercise their rights, and shall promptly forward to the Controller any such request it receives directly.

8.Personal data breach

  1. 8.1The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and shall provide the information reasonably required to enable the Controller to meet its own notification obligations.
  2. 8.2The Processor maintains an internal breach-notification procedure aligned to Articles 33 and 34 GDPR, including severity triage, evidence preservation, controller notice, supervisory-authority assessment, data-subject communication assessment and breach-register completion.

9.International transfers

  1. 9.1The Processor shall not transfer personal data outside the EEA except on the Controller's instructions and subject to appropriate safeguards under Chapter V GDPR, including the Standard Contractual Clauses where applicable.

10.Audit

  1. 10.1The Processor shall make available information necessary to demonstrate Article 28 compliance and shall allow reasonable audits. Audits normally begin with current independent reports and written evidence; an on-site audit may follow where that evidence is insufficient or a material incident reasonably requires it, subject to confidentiality, security, reasonable notice and allocation of exceptional costs.

11.Liability and governing law

  1. 11.1The liability of each party under this DPA is subject to the limitations of liability agreed in the Employer Terms of Service.
  2. 11.2This DPA follows the governing-law allocation in the applicable executed Employer Terms or order, without displacing mandatory GDPR rights or supervisory-authority powers.

12.Annexes

  1. 12.1Annex 1 - Details of Processing: workplace-safety programme hosting; worker, site and asset records; training and qualification tracking with expiry; medical-fitness status and restrictions; equipment issue and inspection; permit-to-work; site presence and roll call; incident and near-miss reporting, investigation and corrective-action tracking; the safety assistant over the Customer's own document library; and support and billing administration for workers, Customer users and invited representatives.
  2. 12.2Annex 2 - Security Measures: encryption in transit and at rest, row-level security, least-privilege and audited access, signed URL expiry controls, provider kill-switches, network and application security, monitoring, backup/resilience controls, incident response and regular review of measures.
  3. 12.3Annex 3 - Processing chain: Automaize may engage Google Cloud / Gemini, Supabase, WorkOS, Vercel, Railway, Stripe, Cal.com, Resend, Meta, Cloudflare and Sentry as published and maintained in the Sub-processor Notice. WorkOS remains disabled until its stated approval gates are complete.
  4. 12.4Annex 4 - Compliance Assistance: assistance with data-subject requests, DPIAs, prior-consultation assessment, breach notifications, audit evidence and deletion/return of personal data at service termination.