Data Processing Agreement
Legal
Dock Data Processing Agreement
THIS DATA PROCESSING AGREEMENT, including the selected modules of the Model Clauses and Annexes (“DPA”) forms part of and is subject to the Dock Terms of Service or other written or electronic agreement (“Main Agreement”) between Customer and Dock Labs, Inc. (“Dock,” “we,” “us,” “our”). Customer and Dock may be referred to herein as a “party” and together as the “parties.”
In the course of providing the Services to Customer under the Main Agreement, Dock may process Customer Personal Data (defined below) on behalf of Customer and the parties agree to comply with the following provisions with respect to any processing of Customer Personal Data by Dock. This DPA shall not replace any comparable or additional rights relating to processing of Customer Personal Data contained in the Main Agreement.
Annex 1 - Details of Processing
Annex 2 - Security Measures
Annex 3 - List of Sub-Processors
- Definitions
- Affiliate means an entity that directly or indirectly Controls, is Controlled by or is under common Control with an entity.
- Business Purpose has the meaning attributed to in Section 1798.140(d) of the CCPA.
- CCPA means Sections 1798.100 et seq. of the California Civil Code and any attendant regulations issued thereunder as may be amended from time to time.
- Customer Personal Data means any Customer Content that: (i) relates to an identified or identifiable natural person; or (ii) that is otherwise protected as "personal data" or "personal information" (as such terms are defined in applicable Data Protection Laws), that Dock processes on behalf of Customer in the course of providing the Service.
- Control means an ownership, voting or similar interest representing fifty percent (50%) or more of the total interests (as measured on a fully-diluted basis) then outstanding of the entity in question.
- Data Protection Laws means all data protection and privacy laws regulations applicable to a party and its processing of Personal Data under the Main Agreement, including, where applicable, GDPR (or in respect of the United Kingdom, any applicable national legislation that replaces or converts in domestic law the GDPR or any other law relating to data protection and privacy as a consequence of the United Kingdom leaving the European Union), implementations of the GDPR into national law, and the CCPA;
- EEA means for the purposes of this DPA the European Economic Area, United Kingdom and Switzerland.
- GDPR means Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation).
- Model Clauses means the selected and applicable modules, attached as Exhibit 1 to this DPA, from the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council C/2021/3972).
- Security Incident means any unauthorized or unlawful breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Personal Data, stored or otherwise processed by Dock in connection with the provision of the Service.
- Subprocessor means any Processor having access to Customer Personal Data and engaged by Dock to assist in fulfilling its obligations with respect to providing the Service pursuant to the Main Agreement or this DPA.
- Controller, processor, processing and personal data shall have the meanings given to them in Data Protection Laws or if not defined therein, the GDPR.
Roles and Scope of Processing
Processing Description. The type of personal data processed pursuant to this DPA and the subject matter, duration, nature and purpose of the processing, and the categories of data subjects, are as described in Annex 1 to the Model Clauses, in Exhibit 1 of this DPA.
- Data Processing Roles. In respect of the parties’ rights and obligations under this DPA regarding the Customer Personal Data, the parties acknowledge and agree that Customer is the controller and Dock is the processor.
- Compliance with Laws. Dock shall process Customer Personal Data in accordance with this DPA and Data Protection Laws applicable to its role under this DPA.
- Processing Instructions. Dock shall process Customer Personal Data in accordance with Customer’s written lawful instructions and only for the following purposes: (i) processing to provide the Services; (ii) processing to perform any steps necessary for the performance of the Main Agreement; (iii) processing initiated by Authorized Users in their use of the Service; (iv) processing to comply with other reasonable instructions provided by Customer.
- Customer Responsibilities. Customer is responsible for the accuracy, quality, and legality of the Customer Personal Data, the means by which Customer acquired such Customer Personal Data, and the instructions it provides to Dock regarding the processing of such Customer Personal Data.
Subprocessing
Notification of New Subprocessors. Dock’s authorized Subprocessors are listed in this Data Processing Agreement.
- Subprocessor Obligations. Dock will enter into a written agreement with each Subprocessor imposing data protection obligations no less protective of Customer Personal Data as this DPA or the Data Protection Laws.
- Subprocessor Objection Right. If Customer objects on reasonable grounds relating to data protection to Dock’s use of a new Subprocessor, then Customer shall promptly provide written notice of such objection to Dock.
Security Measures and Security Incident Response
Security Measures. Dock has implemented and will maintain appropriate technical, and organizational security measures intended to protect Customer Personal Data from Security Incidents.
- Personnel. Dock restricts its personnel from processing Customer Personal Data without authorization by Dock as set forth in the Security Measures.
- Customer Responsibilities. Customer is responsible for its secure use of the Service, including securing its account authentication credentials.
- Security Incident Response. Upon becoming aware of a Security Incident, Dock will notify Customer without undue delay and provide information relating to the Security Incident to Customer promptly as it becomes known.
Audit and Records.
Audit Rights. Dock shall make available to Customer all information in Dock’s possession or control and provide all assistance in connection with audits of Dock’s systems as Customer may reasonably request.
- Audit Procedures. Customer may, on giving at least thirty (30) days prior written notice, request that Customer’s personnel or a third party conduct an audit of Dock’s facilities, equipment, documents and electronic data relating to the processing of Customer Personal Data.
- Data Transfers.
Customer acknowledges and agrees that Dock may transfer and process Customer Personal Data to and in the United States and other locations in which Dock maintains data processing operations as more particularly described in the Subprocessor Site.
- Return or Deletion of Data.
Promptly upon Customer’s request, or within one hundred eighty (180) days after the termination or expiration of the Main Agreement, Dock shall delete or return Customer Personal Data in its possession or control.
Cooperation
Data Subject Rights Requests. Dock shall, taking into account the nature of the processing, reasonably assist Customer in responding to any requests from individuals relating to the processing of Customer Personal Data.
- Requests by Law Enforcement. Dock will inform a government agency that Dock is a processor or service provider of the Customer Personal Data if compelled to disclose Customer Personal Data to a law enforcement agency and will give Customer reasonable notice of the demand to allow Customer to seek a protective order or other appropriate remedy unless legally prohibited from doing so.
- Data Protection Impact Assessments (DPIAs). To the extent required under Data Protection Laws applicable to the EEA, Dock will provide requested information regarding the Service necessary to enable Customer to carry out data protection impact assessments.
Europe
Scope. The terms in this Section apply only if and to the extent Customer is established in the EEA or Customer Personal Data is subject to Data Protection Laws applicable to the EEA.
- Processing Instructions. Dock shall notify Customer in writing, unless prohibited from doing so under Data Protection Laws, if it becomes aware or believes that any processing instructions from Customer violates applicable Data Protection Laws.
- Transfer Mechanism. The parties agree that Dock shall abide by and process such Customer Personal Data in compliance with the Model Clauses.
- Model Clauses. The parties agree that: (i) Dock is a "data importer" and Customer is the "data exporter"; (ii) it is not the intention of either party to contradict or restrict any provisions of the Model Clauses.
- UK and Swiss Data Transfers. Dock shall process Customer Data originating in the UK in accordance with terms set forth in Annex 4.
Controller Affiliates
Affiliate Communications. Customer is responsible for coordinating all communications with Dock on behalf of its Affiliates regarding this DPA.
- Affiliate Enforcement. Customer Affiliates may enforce the terms of this DPA directly against Dock, subject to certain provisions.
Limitation of Liability
In no event shall any party limit its liability with respect to individual’s data protection rights under this DPA.
- Any claim or remedies Customer or its Affiliates may have against Dock arising under or in connection with this DPA will be subject to any limitation and exclusion of liability provisions that apply under the Main Agreement.
RESTRICTIONS
Dock is prohibited from:
- selling Customer Personal Data;
- retaining, using, or disclosing Customer Personal Data for any purposes other than specified.
General
This DPA is incorporated into and subject to the terms of the Main Agreement and shall be effective for the term of the Main Agreement or the duration of the Service.
- Each party acknowledges that the other party may disclose the Model Clauses, this DPA, and any privacy related provisions in the Main Agreement to any regulator upon request.
- Dock may periodically make modifications to this DPA as may be required to comply with Data Protection Laws.
- This DPA does not confer any third-party beneficiary rights and is intended for the benefit of the parties only.
- Other than as required by the Model Clauses, the dispute mechanisms in the Main Agreement govern any dispute pertaining to this DPA.
ANNEX 1
DETAILS OF PROCESSING
A. LIST OF PARTIES
Data exporter:
- Name: The entity listed as “Customer” in the applicable Order Form and/or Main Agreement
- Address: The address listed on any applicable Order Form.
- Contact person’s name, position and contact details: The point of contact listed on any applicable Order Form or the Main Agreement.
- Activities relevant to the data transferred: Receive Dock Services as specified in the Main Agreement and Order Form.
- Role (controller/processor): Controller.
Data importer(s):
- Name: Dock Labs, Inc.
- Address: 548 MARKET STREET PMB36932, SAN FRANCISCO, CA, 94104
- Contact person’s name, position and contact details: Victor Kmita, CTO, legal@dock.us
- Activities relevant to the data transferred: Provide Dock Services to Customer as specified in the Main Agreement and applicable Order Form.
- Role (controller/processor): Processor.
B. DESCRIPTION OF TRANSFER
- Categories of data subjects: Dock Customers and Employees of Dock Customers.
- Categories of personal data transferred: The information specified in the Dock Privacy Policy.
- Sensitive data transferred: N/A.
- The frequency of the transfer: Continuous.
- Nature of the processing: Software as a Service for collaborative online workspaces.
- Purpose(s) of the data transfer and further processing: To provide the Dock Software as a Service to Customers.
- The period for which the personal data will be retained: From the Effective Date of the Main Agreement until its termination.
- For transfers to (sub-) processors: From the Effective Date of the Main Agreement until its termination.
C. COMPETENT SUPERVISORY AUTHORITY
The supervisory authority of one of the Member States in which the data subjects whose personal data is transferred are located shall act as competent supervisory authority.
ANNEX 2
SECURITY MEASURES
The technical and organizational measures implemented by Dock to ensure an appropriate level of security are as follows:
- Encryption of personal data: Data at rest encrypted using AES-256 algorithm. Employee laptops are encrypted. HTTPS encryption on web login interfaces.
- Measures for ensuring availability: Strong access controls, unique accounts, multi-factor authentication, and regular audits.
- Processes for regularly testing and evaluating effectiveness: Logs are generated, stored securely, and monitored.
- Measures for user identification and authorisation: Unique user accounts, strong passwords, and MFA are required.
- Measures for the protection of Data during transmission: HTTPS encryption for data in transit.
- Measures for the protection of Data during storage: Customer instances are logically separated; security measures are enforced.
- Measures for ensuring events logging: Remote logging is maintained and monitored.
- Measures for ensuring system configuration management: Change Management Policy and Access Control Policy are maintained.
- Measures for ensuring data minimisation: Data collection is limited to necessary purposes, with strict data retention protocols.
- Measures for ensuring Data quality: Processes are in place to allow updates and ensure data integrity.
- Measures for ensuring limited data retention: Data is retained for a maximum of 180 days after service termination.
- Measures for ensuring accountability: Privacy Assessments are required for new services involving personal data processing.
ANNEX 3
SUBPROCESSORS
- Pendo (Product analytics) - Website - US
- Vercel (Cloud hosting and data storage) - Website - US
- Courier (Product emails) - Website - US
- Postmark (Email delivery) - Website - US
- FullStory (Product analytics) - Website - US
- GitHub (Issue management) - Website - US
- HelpScout (Customer support) - Website - US
- Heroku (Application hosting) - Website - US
- Loom (Video sharing) - Website - US
- Hubspot (Customer relationship management) - Website - US
- Outreach (Email outreach) - Website - US
- Linear (Issue management) - Website - US
- Slack (Internal communication) - Website - US
- Salesforce (Customer relationship management) - Website - US
- Stripe (Billing) - Website - US
- Polytomic (Data sync) - Website - US
- WorkOS (Single-sign on connections) - Website - US