Legal
Data Processing Addendum
For Enterprise Tier Customers - This Data Processing Addendum (“Addendum”) forms part of the Subscription Service Terms and Conditions (“Agreement”) between Customer and Permit Inc (“Permit”). Customer may request to sign this Addendum as a separate agreement.
WHEREAS, Customer has entered into an Agreement with Permit;
WHEREAS, pursuant to the Agreement, Permit provides Customer access to use Permit’s proprietary application management software that helps organizations build access-control, permissions management, back-office, and control interfaces into their software products (the “Platform”);
WHEREAS, the Platform involves processing certain personal data of employees and other data subjects of Customer, and the parties wish to regulate Permit’s processing of such personal data, through this Addendum.
THEREFORE, the parties have agreed to this Addendum, consisting of these parts:
Part | Applicability |
|---|---|
Part One – General provisions | Always applies and in force. |
Part Two – US Laws | Applies only where the California Consumer Privacy Act of 2018 ("CCPA"), as amended by the California Privacy Rights Act of 2020 (“CPRA”), and/or other state privacy laws in the United States apply with respect to the personal data processed. |
Part Three – GDPR | Applies only where Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data ("GDPR") applies with respect to the personal data processed. |
In the event of any conflicting provisions between this Addendum and the terms or any other agreement in place between the parties, the provisions of this Addendum shall prevail, except where explicitly agreed otherwise in writing.
Part One (General Provisions)
Interpretation. Capitalized terms used herein but not defined in this Addendum shall have the meaning ascribed to them in applicable privacy laws or in the Agreement.
Scope. This Addendum applies only where Permit is processing Customer's personal data as on behalf of Customer and under the Customer’s instructions that are provided through the Platform’s various control and configuration options. It does not apply to Permit’s processing of data for the purpose of operating its services, marketing or promoting its services, or to administer the business or contractual relationship between Permit and the Customer.
Order of Precedence. In the event of any conflicting provisions between this Part One and the provisions of Part Two or Part Three, the provisions of Part Two or Part Three shall prevail (accordingly).
Processing. Permit is prohibited from retaining, using or disclosing the Customer's personal data for: (a) any purpose other than providing the Platform to Customer, or for any commercial purpose other than as reasonably necessary to perform Customer’s processing instructions; (b) selling the Customer's personal data; and (c) retaining, using or disclosing the Customer's personal data outside of the direct business relationship between the parties.
Data Subject Requests. Permit will follow Customer’s instructions to accommodate data subjects’ requests to exercise their rights in relation to their information within the Customer's personal data, including accessing their data, correcting it, restricting its processing or deleting it. Permit will pass on to Customer requests that it receives (if any) from data subjects regarding their information processed by Permit. Permit shall notify Customer of the receipt of such request as soon as possible, and no later than three (3) business days after receipt of such request, together with the relevant details.
Disclosure. Unless legally prohibited, Permit will provide Customer with prompt notice of any request it receives from authorities to produce or disclose Customer's personal data processed on Customer’s behalf, so that Customer (or its customer) may contest or attempt to limit the scope of the production or disclosure request.
Data security. Considering the state of the art, the costs of implementation and the nature, scope, context and purposes of Permit’s processing of Customer's personal data, Permit shall implement and maintain reasonable security procedures and practices appropriate to the nature of the Customer's personal data, to protect such personal data from unauthorized access, destruction, use, modification, or disclosure (including data breaches).
Data Breaches. Permit shall without undue delay, notify Customer of any actual or reasonably suspected accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer's personal data, of which Permit becomes aware. Permit will thoroughly investigate the breach and take all available measures to mitigate the breach and prevent its recurrence. Permit will cooperate in good faith with Customer on issuing any statements or notices regarding such breaches, to authorities and data subjects.
Subcontracting to suppliers. Customer authorizes Permit to engage other sub-processors for carrying out specific processing activities, provided that Permit informs Customer at least 14 days in advance of any new or substitute sub-processor, in which case Customer shall have the right to object, on reasoned grounds, to that new or substitute sub-processor. If Customer so objects, Permit may not engage that new or substitute sub-processor for the purpose of Processing Personal Data, and Permit may either select another sub-processor in which case the above procedure shall repeat, or if it so chooses, terminate the Agreement with no liability to Customer for such premature termination. At the outset, Customer authorizes Permit to engage with the sub-processors listed in Schedule I below.
Without limiting the foregoing, in any event where Permit engages another sub-processor, Permit will ensure that the same data protection obligations as set out in this Addendum are likewise imposed on that other sub-processor by way of a contract, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the Data Protection Law. Permit shall remain fully liable to Customer for the performance of its sub-processors' obligations.
Data Deletion. Upon Customer’s request, Permit will delete the Customer's personal data that it has processed on Customer’s behalf under this Addendum from its own and its sub-processor’s systems, or, at Customer’s choice, return such Customer's personal data and delete existing copies. Upon Customer’s request, Permit will furnish written confirmation that the Customer's personal data has been deleted or returned pursuant to this section.
Part Two (US State Laws)
Definitions
In this Part Two:
“Applicable State Privacy Laws” means the CCPA and CPRA, and other applicable state privacy laws in the United States, such as (but not limited to): Virginia Consumer Data Protection Act, Connecticut Act Concerning Personal Data Privacy and Online Monitoring, Utah Consumer Privacy Act, and the Colorado Privacy Act, as relevant.
“Consumer” means a natural person, including a natural person in their professional or work capacity.
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
“Collect” (and its cognate terms) means buying, renting, gathering, obtaining, receiving, or accessing any Personal Information pertaining to a Consumer by any means. This includes obtaining information from the Consumer, either actively or passively, or by observing the Consumer’s behavior or interaction.
“Process” (and its cognate terms) means any operation or set of operations that are performed on Personal Information or on sets of personal information, whether or not by automated means.
“Sell” (and its cognate terms) means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's Personal Information for monetary or other valuable consideration.
“Share” (and its cognate terms) means sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's Personal Information for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, including transactions for cross-context behavioral advertising in which no money is exchanged.
Permit’s Obligations
The Parties acknowledge and agree that Permit is a ‘service provider’ and ‘processor’ within the meaning of the terms in Applicable State Privacy Laws. To that end, and unless otherwise required by law:
Permit must not Sell or Share any Personal Information it Collects.
The parties agree that Customer is disclosing the Personal Information to Permit only for the following limited and specified business purposes: to provide and support the operation of the Platform.
Permit is prohibited from retaining, using, or disclosing the Personal Information that it Collects for any commercial purpose other than the foregoing business purposes, unless expressly permitted by Applicable State Privacy Laws and this Part Two. Additionally, Permit is prohibited from retaining, using, or disclosing the Personal Information that it Collects pursuant to this Agreement outside the direct business relationship between Permit and Customer, unless expressly permitted by Applicable State Privacy Laws and this Part Two.
Permit shall comply with all relevant sections of Applicable State Privacy Laws and shall provide, with respect to Personal Information it Collects, the same level of privacy protection as required by Applicable State Privacy Laws.
Permit grants Customer the right to take reasonable and appropriate steps to ensure that Permit uses the Personal Information it Collects in a manner consistent with the obligations under this Part Two and Applicable State Privacy Laws.
Permit must promptly notify Customer if it makes a determination that it can no longer meet its obligations under this Part One or Applicable State Privacy Laws.
Permit grants Customer the right, upon notice, to take reasonable and appropriate steps to stop and remediate Permit’s unauthorized use of Personal Information.
If Permit receives a request from a Consumer about his or her Personal information, Permit shall not comply with the request itself and inform the Consumer that Permit’s basis for denying the request is that the Permit is merely a service provider that follows Customer’s instructions. Permit shall provide the Consumer with the Customer’s contact information and instruct the Consumer to submit the request directly to the Customer.
Assistance in responding to Consumer requests. Permit shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Customer’s obligation to respond to requests for exercising the Consumer rights under Applicable State Privacy Laws.
Part Three (GDPR)
Capitalized terms used in this Part Three but not defined herein or in the Agreement shall have the meaning ascribed to them in the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) applicable as of 25 May 2018 and any national law supplementing the GDPR (collectively referred to in this Part Three as “Data Protection Law”).
Customer commissions, authorizes and requests that Permit Process Customer Personal Data, under the instructions of Customer as the Data Controller. Permit shall Process such Personal Data as a processor, only on Customer’s behalf. Permit and Customer are each responsible for complying with the Data Protection Law as applicable to their roles.
Permit will Process the Personal Data only on instructions from Customer documented in this Addendum, provided through the Platform’s various control and configuration options or otherwise provided in writing, which instructions must be consistent with the nature and characteristics of the Platform. The foregoing applies unless Permit is otherwise required by law to which it is subject (and in such a case, Permit shall inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest). Permit shall immediately inform Customer if, in Permit's opinion, an instruction violates the Data Protection Law.
The nature and purpose of the Processing activities are the provision of the Platform to the Customer. The Personal Data Processed may include the categories described in Schedule I below. The Data Subjects, as defined in the Data Protection Law, are the natural persons in Customer’s production environment, about whom Personal Data is Processed.
Permit will make available to Customer and the Data Controller all information at its disposal that is necessary to demonstrate compliance with the obligations under Data Protection Law. Furthermore, Permit shall maintain all records required by Article 30(2) of the GDPR, and make them available to the Customer upon request.
Permit shall forward to Customer any request from Data Subjects arising out of the processing of Personal Data by Permit, and Customer shall be solely liable for responding to Data Subjects on such requests. Notwithstanding the foregoing, where applicable considering the nature of the Personal Data Processed, Permit will follow Customer’s instructions to accommodate Data Subjects’ requests to exercise their rights in relation to their Personal Data, including accessing their data, correcting it, restricting its processing or deleting it, to the extent reasonable in relation to the Platform. If such instructions entail costs or expenses to Permit, the parties shall first come to agreement on Customer reimbursing Permit for such costs and expenses. Permit will pass on to Customer requests that it receives from Data Subjects regarding their Personal Data Processed by Permit.
Permit and its sub-processors will only Process the Personal Data in Member States of the European Economic Area, in territories or territorial sectors recognized by an adequacy decision of the European Commission (or as applicable, the UK ICO), as providing an adequate level of protection for Personal Data pursuant to Article 45 of the GDPR or using adequate safeguards as required under Data Protection Law governing cross-border data transfers (e.g., Standard Contractual Clauses).
Permit is situated in a territory not recognized by an adequacy decision of the European Commission as providing an adequate level of protection for Personal Data pursuant to Article 45 of the GDPR. Therefore, the parties hereby enter into MODULE TWO of the SCCs, as specified in Schedule I of this Part Three.
Permit will ensure that its staff authorized to Process the Personal Data are contractually bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
Within 30 days of Customer’s written request, Permit shall allow for and contribute to audits, including carrying out inspections conducted by Customer or another auditor mandated by Customer in order to establish Permit's compliance with this Addendum and the provisions of the applicable Data Protection Law, with regards to the Personal Data that Permit processes on behalf of Customer. Such audits or inspections shall be carried out during Permit's ordinary business hours, not more than one business day per year (unless Data Protection Law or a supervisory authority mandate more frequent audits or inspections), shall be conducted with minimal disruption to Permit's business activities, and be subject to confidentiality undertakings satisfactory to Permit.
At Customer’s request, Permit shall provide to Customer a copy of its annual an audit report from an independent reputable third party regarding Permit's data processing and data protection measures. The audit report shall be obtained based on a recognized standard for such audit reports (e.g. ISAE 3000 or SSAE-SOC 2).
Permit will assist Customer with the preparation of data privacy impact assessments and prior consultation as appropriate (if needed).
Schedule I – Standard Contractual Clauses
In Section II (Obligations of the Parties), Clause 9(a) for MODULE TWO: GENERAL WRITTEN AUTHORISATION. The data importer has the data exporter’s general authorization for the engagement of sub-processor(s) from an agreed list.
In Section IV (Final Provisions), Clause 17 for MODULE TWO: Transfer controller to processor: The parties agree that this shall be the law of Ireland.
In Section IV (Final Provisions), Clause 18(b) for MODULE TWO: Transfer controller to processor: The parties agree that those shall be the courts of Ireland.
In Annex I, for MODULE TWO: Transfer controller to processor:
Data Exporter: Customer.
Activities relevant to the data transferred under these Clauses: an organization using the Platform (as described in the Agreement).
Role: Controller.Data Importer: Permit.
Activities relevant to the data transferred under these Clauses: provider and operator of the Platform (as described in the Agreement).
Role: Processor.Description of Transfer: provision, hosting, operation, maintenance, support, enhancement and deployment of the Platform.
Categories of personal data transferred: Names, titles and contact information of Customer’s employees; Authorization logs assigned to each user, including Customer’s employees.
Categories of data subjects whose personal data is transferred: Natural persons relating to Customer’s production environment.
Sensitive data transferred: None.
The frequency of the transfer: ongoing.
Nature of the processing: storing, organizing, accessing, using, transmitting, retrieving, backing up, securing, troubleshooting and deleting or returning personal data.
Purpose(s) of the data transfer and further processing: provision of the Platform to the data exporter.
The period for which the personal data will be retained: personal data will be retained for the duration of the Agreement Term (or earlier, if Customer requests deletion of the data).
Transfers to (sub-) processors:
Name | Subject matter and nature of Processing Activities | Duration of transfer |
|---|---|---|
Amazon Web Services | Cloud Hosting | For the duration of the Customer's use of the Platform. |
DataDog | System monitoring logs | For the duration of the Customer's use of the Platform. |
Anonymized usage analytics | For the duration of the Customer's use of the Platform. | |
Twilio (Segment) | Event management | For the duration of the Customer's use of the Platform. |
MixPanel | Anonymized usage analytics | For the duration of the Customer's use of the Platform. |
Stripe | Billing | For the duration of the Customer relationship. |
Sentry | System error monitoring | For the duration of the Customer's use of the Platform. |
Auth0 | User authentication | For the duration of the Customer's use of the Platform. |
WorkOS | Enterprise single sign-on (SSO) | For the duration of the Customer's use of the Platform. |
Competent Supervisory Authority: the supervisory authority in the EU member state where the data exporter's EU representative under Article 27 of the GDPR is located.
In Annex II, for MODULE TWO: Transfer controller to processor: the data importer implements the following technical and organizational measures:
Technical and organizational measures in accordance with Permit's IT Security Policy.
Revisions
- August 11th, 2024 — Initial publication
- July 1st, 2026 — Replaced DPA with multi-part template including US state privacy laws and EU Standard Contractual Clauses; added Auth0 and WorkOS as sub-processors
