Legal
Data Processing Addendum
For Organizations and Workspaces with team members — how PV0T processes their data on your behalf.
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (acting on behalf of an Organization or Workspace with team members, “Controller”) and PV0T OÜ (“PV0T,” “Processor”), and applies whenever PV0T processes personal data on your behalf as part of providing the Service to your Organization’s members. It’s incorporated into the Terms of Service by reference — see Terms of Service, Section 4.3.
If you use PV0T only as an individual, with no Organization or Workspace members besides yourself, this DPA doesn’t apply — PV0T is the controller for your own account, governed by the Privacy Policy.
1. Definitions
“Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” and “Sub-processor” have the meanings given in the GDPR. “Organization Data” means personal data of your Organization’s members, invitees, and any other individuals that PV0T processes on your behalf through the Service.
2. Subject matter and duration
PV0T processes Organization Data for the duration of your Organization’s subscription, for the purpose of providing the Service described in the Terms of Service, covering the categories of data subjects and personal data described in the Privacy Policy, Section 3, to the extent that data relates to individuals other than you personally.
3. Processor obligations
PV0T will:
- Process Organization Data only on your documented instructions, as given through your use of the Service’s features, except where required to do otherwise by EU or member state law.
- Ensure that people authorized to process Organization Data are subject to confidentiality obligations.
- Implement the technical and organizational security measures described in the Privacy Policy, Section 13.
- Assist you, to the extent reasonably possible, in responding to data subject rights requests concerning Organization Data.
- Assist you in meeting your own obligations under GDPR Articles 32–36 (security, breach notification, and data protection impact assessments), taking into account the nature of processing and the information available to PV0T.
- Notify you without undue delay after becoming aware of a personal data breach affecting Organization Data.
- At the end of your Organization’s subscription, delete Organization Data in line with the Privacy Policy, Section 9, unless EU or member state law requires us to retain it.
- Make available the information reasonably necessary to demonstrate compliance with this DPA.
4. Sub-processors
You authorize PV0T to engage the sub-processors listed in the Privacy Policy, Section 7 — excluding Google Analytics, which only processes marketing-site visitor data, never Organization Data — for the purposes described there. We’ll update that list if it changes and, for material additions, give reasonable advance notice so you can object.
5. International transfers
Where a sub-processor processes Organization Data outside the EU/EEA, PV0T relies on the safeguards described in the Privacy Policy, Section 8.
6. Liability
Each party’s liability under this DPA is subject to the limitations set out in the Terms of Service, Section 9.
7. Governing law
This DPA is governed by the laws of Estonia, consistent with the Terms of Service, Section 10.