Data Processing Addendum
Version 1.0, effective July 22, 2026. To request a countersigned copy of this DPA, or to submit a previously agreed form for execution, email legal@abloomify.com.
1. Introduction and Applicability
This Data Processing Addendum ("DPA") forms part of the agreement between Abloomify Inc. ("Abloomify") and the customer identified in that agreement ("Customer") governing Customer's use of the Abloomify platform and services (the "Agreement"), where the Agreement references this DPA, where the parties have executed it, or where Abloomify processes Personal Data on Customer's behalf in connection with the services. If the parties have executed a negotiated data processing agreement, that agreement prevails over this DPA. In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA prevails, and in the event of a conflict between this DPA and the SCCs where they apply, the SCCs prevail.
The version of this DPA in effect on the effective date of the Agreement (or of the applicable order) governs for the term of that Agreement. Abloomify will provide notice of material changes, and no update will materially reduce the protections of this DPA for an existing Customer during its term without the Customer's consent.
2. Definitions
"Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including, as applicable, Regulation (EU) 2016/679 ("GDPR"), the GDPR as incorporated into United Kingdom law ("UK GDPR"), the Swiss Federal Act on Data Protection, Canada's PIPEDA, and US state privacy laws such as the CCPA/CPRA. "Personal Data" means personal data or personal information, as defined in applicable Data Protection Laws, that Abloomify processes on Customer's behalf in connection with the services. "Subprocessor" means a third party engaged by Abloomify to process Personal Data on Customer's behalf. "SCCs" means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914. "Controller", "processor", "processing", "data subject", "personal data breach" and similar terms have the meanings given in the GDPR.
3. Roles and Scope
Customer is the controller of Personal Data (or, where Customer acts on behalf of its own controllers, a processor), and Abloomify is a processor acting on Customer's behalf. The subject matter, duration, nature and purposes of processing, and the categories of Personal Data and data subjects, are described in Annex 1. Each party will comply with the obligations that apply to it under Data Protection Laws.
Customer is responsible for the lawfulness of the Personal Data and its instructions, including establishing a legal basis, providing any required notices to data subjects (including its employees and other end users), and obtaining any consents, approvals, or agreements required under applicable law, such as employment law requirements applicable to workforce analytics (for example, works council agreements or collective consultation where required). Abloomify provides configuration controls and supporting documentation to assist Customer with these obligations.
4. Processing Instructions
Abloomify will process Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by Union or Member State law (or, for Personal Data subject to the UK GDPR or the Swiss FADP, UK or Swiss law) to which Abloomify is subject; in that case, Abloomify will inform Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest. Customer's documented instructions consist of the Agreement, this DPA, Customer's use and configuration of the services (including collection states, allowlists, integration connections, enabled AI model providers and features, and retention settings), and any additional written instructions the parties agree. Abloomify will immediately inform Customer if, in its opinion, an instruction infringes applicable Data Protection Laws.
5. Confidentiality
Abloomify ensures that persons authorized to process Personal Data are bound by confidentiality obligations (contractual or statutory) and access Personal Data only as needed to provide the services.
6. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects, Abloomify implements and maintains appropriate technical and organizational measures to protect Personal Data, as described in Annex 2. Abloomify may update those measures from time to time, provided the updates do not materially reduce the overall level of protection.
7. Subprocessors
Customer provides a general authorization for Abloomify to engage Subprocessors. The current Subprocessor list is set out in Annex 3 and maintained in Abloomify's Trust Center. Abloomify will impose on Subprocessors, by written contract, data protection obligations that are the same in substance as those set out in this DPA, and remains liable to Customer for the performance of its Subprocessors' obligations.
Abloomify will give Customer at least 30 days' prior notice of the addition or replacement of a Subprocessor (via the Trust Center or email). Customer may object on reasonable data protection grounds within that period, in which case the parties will work in good faith to resolve the objection; if it cannot be resolved, Customer may terminate the affected portion of the services with a pro rata refund of prepaid fees for the terminated portion.
8. Data Subject Requests
Taking into account the nature of the processing, Abloomify will assist Customer through appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to data subject requests (including access, rectification, erasure, restriction, portability, and objection). If Abloomify receives a request directly from a data subject relating to Personal Data processed for Customer, it will promptly forward the request to Customer and will not respond except to direct the data subject to Customer or as required by law.
9. Personal Data Breach
Abloomify will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Personal Data. The notification will describe, to the extent then known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects, with updates as further information becomes available. Abloomify will reasonably cooperate with Customer's notification obligations. Notification is not an acknowledgement of fault or liability.
10. DPIA and Consultation Assistance
Taking into account the nature of the processing and the information available to it, Abloomify will provide reasonable assistance with Customer's data protection impact assessments and prior consultations with supervisory authorities relating to the services. Documentation supporting DPIAs, works council review, and employee notices is available on request at legal@abloomify.com.
11. Return and Deletion
During the term, Customer can access and export Personal Data through the services. Upon termination or expiry of the Agreement, at Customer's choice, Abloomify will return and/or delete Personal Data: export remains available for 30 days after termination (unless a different period is stated in the Agreement), after which Abloomify will delete Personal Data within 30 days, or any shorter period stated in the Agreement, unless Union or Member State law (or, for Personal Data subject to the UK GDPR or the Swiss FADP, UK or Swiss law) requires storage of the Personal Data. Backups containing Personal Data are deleted or overwritten within 90 days of the primary deletion and remain protected under this DPA until then. On written request, Abloomify will confirm deletion in writing.
12. Audit and Information
Abloomify will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. The parties agree that audits are satisfied first through Abloomify's documentation, security summaries, and available third-party materials (see the Trust Center). Where these are insufficient, Customer may conduct an audit no more than once per 12-month period (except following a personal data breach or where required by a supervisory authority), on at least 30 days' written notice, during business hours, under confidentiality obligations, without access to other customers' data, and at Customer's cost. Audits are conducted remotely unless an on-site inspection is required by Data Protection Laws or a supervisory authority.
13. International Transfers
Abloomify operates two production environments: a US environment (AWS us-east-1) and an EU environment (AWS eu-central-1, Frankfurt). Each Customer is provisioned in exactly one region. For Customers on the EU environment, Personal Data processed through the platform is stored and processed in the European Union as described in the Agreement and Abloomify's Privacy Policy.
Transfers of Personal Data from the EEA, the UK, or Switzerland to Abloomify Inc. in Canada are made under the European Commission's adequacy decision for Canada (and its UK and Swiss equivalents), which covers commercial organizations subject to PIPEDA. Where Abloomify transfers Personal Data to Subprocessors in third countries without an adequacy decision, Abloomify relies on the SCCs or other valid transfer mechanisms concluded with the Subprocessor, with supplementary measures where appropriate.
If and to the extent a transfer of Personal Data from Customer to Abloomify requires the SCCs under applicable Data Protection Laws, the parties agree that the SCCs (Module Two, or Module Three where Customer is a processor) are incorporated into this DPA by reference, with Customer as data exporter and Abloomify as data importer, populated with the information in Annexes 1 to 3, and with the optional docking clause included. The competent supervisory authority is determined in accordance with Clause 13 of the SCCs (for an exporter established in the EEA, the supervisory authority of the exporter's establishment; where Clause 13 requires a designation for an exporter not established in the EEA, the Irish Data Protection Commission). The SCCs are governed by Irish law (Clause 17) and disputes under them are resolved before the courts of Ireland (Clause 18).
For transfers subject to the UK GDPR, the UK International Data Transfer Addendum applies, with Tables 1 to 3 deemed completed with the details of the parties, the SCC modules and options selected above, and Annexes 1 to 3, and with neither party selected in Table 4. For transfers subject to the Swiss FADP, the SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner (FDPIC): the FDPIC is the competent supervisory authority for Swiss transfers, references to the GDPR are understood as references to the FADP where applicable, and Swiss data subjects may enforce their rights in Switzerland.
If Abloomify receives a request from a public authority or other third party for access to Personal Data, it will notify Customer before disclosure unless legally prohibited from doing so, will challenge requests it considers unlawful or overbroad where reasonably practicable, and will disclose only the minimum Personal Data required.
14. US State Privacy Laws
Where the CCPA/CPRA or similar US state privacy laws apply, Abloomify acts as Customer's service provider: it will not sell or share Personal Data; will not retain, use, or disclose Personal Data for any purpose other than providing the services under the Agreement (or as otherwise permitted by those laws); will not combine Personal Data with personal information it receives from other sources, except as permitted by those laws; and certifies that it understands and will comply with these restrictions. Abloomify will notify Customer if it determines it can no longer meet its obligations under those laws, and Customer may take reasonable and appropriate steps (including under Section 12) to stop and remediate any unauthorized use of Personal Data.
15. Liability and General
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, to the extent permitted by applicable law. This DPA is effective for as long as Abloomify processes Personal Data on Customer's behalf. This DPA is governed by the law governing the Agreement, except where Data Protection Laws require otherwise. If any provision of this DPA is held invalid, the remainder stays in effect. Updates to this standard DPA are handled as described in Section 1.
Annex 1: Description of Processing
- Subject matter and duration: processing of Personal Data to provide the Abloomify platform and services for the term of the Agreement, plus the return and deletion period in Section 11.
- Nature and purposes: hosting, storage, and processing of Personal Data and other Customer content to provide workforce analytics, productivity insights, AI assistant functionality, integrations connected by Customer, and related services, per Customer's configuration and instructions.
- Categories of data subjects: Customer's employees, contractors, and other end users authorized by Customer.
- Categories of Personal Data: user and device identifiers within Customer's deployment (such as name, work email, device username, and hostname); work-activity telemetry collected by device agents per Customer's configured collection state (application and website usage patterns; optional window titles only where Customer explicitly enables them); data from workplace tools Customer connects (which may include email, calendar, meeting, project, code hosting, and HR data, depending on the integrations and permissions Customer chooses); documents and content uploaded to the platform; AI assistant conversations and outputs; and support communications.
- Special categories: the services are not intended for special categories of Personal Data, and Customer agrees not to instruct their processing. Incidental special category data may be present in content Customer chooses to connect or upload; it is processed only as part of that content.
- Frequency of processing and transfer: continuous, for the duration of the Agreement.
- Retention: as set out in Section 11 and Customer's configuration, which together constitute the retention entry for the purposes of the SCC annexes.
Personal Data that Abloomify processes for its own purposes as a controller (such as customer account administration, billing contacts, product analytics, and support) is described in the Privacy Policy and is outside the scope of this DPA.
Annex 2: Technical and Organizational Measures
- Hosting and isolation: production environments on AWS in us-east-1 (US customers) or eu-central-1, Frankfurt (EU customers), one region per customer, with logical separation of customer data.
- Encryption: encryption in transit (TLS) and at rest for data stores.
- Access control: role-based access on a need-to-know basis, scoped credentials for production access, and logging of production account activity through cloud-managed audit trails.
- Data minimization by design: collection is an explicit administrator choice per platform (collect, allowlist, or collect nothing); EU-environment companies start in the collect-nothing state; allowlists are enforced at capture on the device so out-of-scope activity is never recorded or transmitted; agents cannot capture screenshots, keystrokes, or the content of communications in any configuration; telemetry awaiting transmission is held in a bounded in-memory queue and is not written to disk on the device.
- AI processing: model inference runs within the customer's cloud region; Personal Data is not used to train AI models.
- Availability and resilience: managed cloud services with redundancy, monitoring and alerting, and routine backups with rotation.
- Personnel and process: confidentiality obligations for personnel, least-privilege administration, timely remediation of identified vulnerabilities, and defined procedures for responding to security incidents.
- Further detail is published in the Trust Center.
Annex 3: Subprocessors
Abloomify's Trust Center lists Abloomify's service providers, including vendors that support Abloomify's own operations as a controller. The Subprocessors engaged for Personal Data processed through the platform on Customer's behalf are:
- Amazon Web Services (cloud infrastructure, storage, transactional email via Amazon SES, and AI inference via AWS Bedrock), us-east-1 (US) or eu-central-1 (Germany) per Customer's region.
- PostHog (product analytics for the application), US or EU cloud per Customer's region.
- Pingram (notification and email delivery for messages to Customer's users).
- Unified.to (integration connectivity for certain workplace integrations, engaged only where Customer's administrators connect the relevant integration, such as communications and meeting-recording sources).
- Tavily (web search and crawling for knowledge-base and research features, only where Customer's administrators enable those features; receives the queries and URLs those features use).
- OpenAI and Google (optional AI model providers, disabled by default and engaged only where Customer's administrators enable them; prompts and outputs are not used to train their models).
Third-party services that Customer chooses to connect to the platform (for example, Google Workspace, Microsoft 365, project management, code hosting, or HR tools) act under Customer's own authorization and agreements with those providers and are not Abloomify Subprocessors.