Data Processing Agreement
Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Automate America, Inc. ("Processor" or "Company") and the user ("Controller" or "Client") for the processing of personal data in connection with the Automate America platform services.
This DPA applies where the Company processes personal data on behalf of the Client in the course of operating the Automate America marketplace.
1. Definitions
For the purposes of this DPA:
"Personal Data" means any information relating to an identified or identifiable natural person processed through the Automate America platform.
"Processing" means any operation performed on Personal Data, including collection, recording, storage, modification, retrieval, use, disclosure, or deletion.
"Data Subject" means the identified or identifiable natural person to whom Personal Data relates, including contractors, professionals, and client employees.
"Sub-processor" means any third party engaged by the Company to process Personal Data on behalf of the Client.
"Applicable Data Protection Law" means all applicable laws relating to the processing of Personal Data, including GDPR (EU), CCPA (California), and other state and federal privacy laws.
2. Scope of Processing
Categories of Data Subjects:
- Professionals and contractors registered on the platform
- Client employees who use the platform
- Candidates and applicants
Types of Personal Data Processed:
- Identity data: name, email, phone number, address
- Professional data: work history, skills, certifications, resume
- Financial data: payment information, tax identifiers (W-9/1099)
- Usage data: platform activity, search history, application history
- Communication data: messages, notifications, correspondence
Purposes of Processing:
- Facilitating contractor-client matching and placement
- Managing contracts, timesheets, and invoices
- Processing payments and tax reporting
- Platform operation, security, and improvement
- Compliance with legal obligations
3. Company Obligations
The Company shall:
- Process Personal Data only on documented instructions from the Client
- Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Assist the Client in responding to Data Subject rights requests
- Delete or return all Personal Data upon termination of services, at the Client's choice
- Make available all information necessary to demonstrate compliance with this DPA
- Notify the Client without undue delay of any Personal Data breach
Security Measures Include:
- Encryption of data in transit (TLS 1.2+)
- Access controls and authentication requirements
- Regular security assessments and vulnerability scanning
- Incident response procedures
4. Sub-processors
The Client authorizes the Company to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and infrastructure | United States |
| Stripe | Payment processing | United States |
| SendGrid | Email delivery | United States |
| Google Analytics | Platform analytics | United States |
The Company shall:
- Provide prior notice before engaging new sub-processors
- Impose equivalent data protection obligations on sub-processors
- Remain liable for the acts of its sub-processors
- Provide the Client with the opportunity to object to new sub-processors
5. Data Subject Rights
The Company shall assist the Client in fulfilling Data Subject requests for:
- Access: Providing copies of Personal Data held
- Rectification: Correcting inaccurate Personal Data
- Erasure: Deleting Personal Data ("right to be forgotten")
- Portability: Providing Personal Data in a structured, machine-readable format
- Restriction: Limiting the processing of Personal Data
- Objection: Ceasing processing based on legitimate interests
The Automate America platform provides self-service tools for users to exercise these rights, including data export and account deletion features.
Response time: Within 30 days of receiving a verified request.
6. Data Breach Notification
In the event of a Personal Data breach, the Company shall:
- Notify the Client within 72 hours of becoming aware of the breach
- Provide details of the nature of the breach, categories of data affected, and approximate number of Data Subjects affected
- Describe the likely consequences and measures taken to address the breach
- Cooperate with the Client in meeting any notification obligations to Data Subjects or supervisory authorities
All breach notifications should be directed to privacy@automateamerica.com.
7. International Data Transfers
Personal Data is processed and stored in the United States. For transfers of Personal Data from the European Economic Area (EEA), the Company relies on:
- Standard Contractual Clauses (SCCs) as adopted by the European Commission
- Adequacy decisions where applicable
- Binding Corporate Rules where implemented
The Company ensures that any international transfer of Personal Data is subject to appropriate safeguards as required by applicable law.
8. Term and Termination
This DPA remains in effect for the duration of the Company's processing of Personal Data on behalf of the Client.
Upon termination:
- The Company will cease processing Personal Data within 30 days
- All Personal Data will be deleted or returned to the Client, at the Client's election
- The Company may retain Personal Data as required by applicable law
- Confidentiality obligations survive termination indefinitely
