Legal
Data Processing Addendum
Last updated: September 20, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between HELIXWORKS ("Processor") and the client ("Controller") for the provision of automation services, and applies wherever we process Personal Data on the Controller's behalf.
Signature block. This DPA is written to be executed as-is. If the Controller requires its own template, amendments or a negotiated liability position, we will complete and return it — we do not treat the DPA as a negotiating lever.
1. Definitions
"Personal Data", "Data Subject", "Controller", "Processor", "Supervisory Authority" and "Processing" have the meanings given in the GDPR (or, where the CCPA/CPRA applies, the equivalent concepts). "Services" means the automation development, deployment and operation services described in a statement of work. "Sub-processor" means any processor engaged by us to process Personal Data on the Controller's behalf.
2. Roles and Scope
- The Controller determines the purposes and means of processing and warrants that it has a lawful basis for the Personal Data it makes available to us.
- We process Personal Data only to provide the Services, on documented instructions from the Controller, and for no other purpose.
- We do not sell Personal Data, do not share it for cross-context behavioural advertising, and do not use it to train models — ours or a third party's — except where the Controller gives specific written instruction and the data is not Personal Data.
- We do not process Personal Data for our own marketing, profiling or any purpose unrelated to the Services.
3. Categories of Data and Processing
- Data subjects — the Controller's employees, customers, suppliers and other individuals appearing in the data in scope.
- Categories of data — identification and contact data, business transaction records (invoices, orders, tickets, contracts), and any content present in the documents and systems in scope. Special category data is processed only on express written instruction and with documented safeguards.
- Nature and purpose — extraction, classification, matching, drafting, routing, storage of workflow state and generation of audit records. The specific processing is described in the statement of work.
- Duration — the term of the agreement plus the deletion period in Section 9.
4. Our Obligations
- Process Personal Data only on documented instructions, and inform the Controller if an instruction would breach applicable data protection law.
- Ensure personnel authorised to process Personal Data are bound by appropriate confidentiality obligations and receive data protection training.
- Assist the Controller in responding to Data Subject requests, at the Controller's cost where the effort is substantial.
- Assist with data protection impact assessments and prior consultations with Supervisory Authorities, to the extent required.
- Notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Controller data, with the information reasonably required for the Controller's own notification obligations.
- Maintain records of processing carried out on behalf of the Controller and make them available for inspection under Section 8.
5. Security Measures
Taking into account the state of the art and the risks involved, we implement at least:
- Encryption of Personal Data in transit (TLS 1.3) and at rest (AES-256)
- Access control on a least-privilege basis, with SSO, multi-factor authentication and time-boxed access grants reviewed quarterly
- Per-client isolation of environments, credentials, stored data and retrieval indexes
- Redaction or tokenisation of direct identifiers before inference where the task does not require them
- Logging of access and administrative actions, with retention appropriate to security and audit needs
- Secure development practices, dependency scanning and code review before deployment
- Documented incident response runbook, tested at least annually
- Regular backup with restoration testing where we host the data
6. Sub-processors
The Controller grants general authorisation for the engagement of Sub-processors for the categories listed below. We impose data protection obligations on each Sub-processor no less protective than those in this DPA, and remain liable for their performance.
- Cloud infrastructure & hosting — Application hosting, storage, backups. Region: United States or EU (chosen per project).
- Managed database — Project state, audit logs, vector indexes. Region: Same region as the project.
- Frontier model providers — Inference for extraction, classification and drafting tasks. Region: US or EU endpoints; zero-retention configuration.
- Email & calendar — Business correspondence, meeting scheduling. Region: United States.
- Project management & repository hosting — Source control, issue tracking, documentation. Region: United States.
- Accounting & e-signature — Invoicing, contract execution. Region: United States.
The current named list, with legal entity names and change history, is provided as an annex to the executed DPA and on request. We will give at least 30 days' notice before adding or replacing a Sub-processor; the Controller may object on reasonable data protection grounds, and where the objection cannot be resolved we will either continue without that Sub-processor or allow the Controller to terminate the affected Services.
7. International Transfers
Where processing involves a transfer of Personal Data out of the EEA, the UK or Switzerland to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses (and, for the UK, the UK Addendum), with the Controller as data exporter and HELIXWORKS as data importer. The relevant Annexes are completed with the information in Sections 3, 5 and 6. Where the CCPA/CPRA applies to a transfer, we act as a service provider and not as a third party.
8. Audit and Information Rights
We will make available the information reasonably necessary to demonstrate compliance with this DPA, including our security documentation, subprocessor list, and evidence from our internal control testing. A Controller may request an audit no more than once per twelve-month period, with at least 30 days' notice, during business hours, subject to confidentiality, at the Controller's cost, and in a manner that does not compromise the confidentiality of other clients' data. Security questionnaire responses and independent reports satisfy this right wherever they cover the matters raised.
9. Deletion and Return of Data
- On termination or expiry, and at the Controller's written instruction, we delete or return all Personal Data processed on its behalf within 30 days.
- Where return is requested in a machine-readable format, we provide it in the format agreed in the statement of work and delete our copies afterwards.
- We may retain Personal Data where required by law (for example, tax and accounting records) or to the extent it is contained in routine backups, in which case it remains protected by this DPA and is deleted on the normal backup rotation.
- We confirm deletion in writing on request.
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the agreement between the parties, except where applicable law provides otherwise. Nothing in this DPA limits a Data Subject's rights under applicable data protection law.
11. Term and Changes
This DPA takes effect on the date of the agreement and continues until deletion of all Personal Data. We may update it to reflect changes in law or our processing; material changes require the Controller's written agreement.
12. Contact
Data protection enquiries: [email protected]
HELIXWORKS, One Ferry Building, Suite 210, San Francisco, CA 94111
Questions about this document? Write to [email protected] or call +1 (650) 442-5844. Postal address: One Ferry Building, Suite 210, San Francisco, CA 94111.
This document is a template provided for information and does not constitute legal advice. Have it reviewed by qualified counsel before relying on it.