Back to home

Data Processing Addendum

Our processor commitments for customers subject to GDPR/UK GDPR and similar laws. Last updated July 23, 2026.

1. Roles

For workspace content, your organization is the controller and WorkBOS is the processor acting on your documented instructions (the product settings and these terms). For account/billing data, WorkBOS is an independent controller as described in the Privacy Policy.

2. Our processor commitments

  • Process workspace personal data only to provide the Service and per your instructions.
  • Confidentiality: personnel access is role-limited and bound by confidentiality obligations.
  • Security: the technical and organizational measures described on our Security page (tenant isolation via RLS, RBAC, encryption in transit and at rest, AV scanning, audit logging, secure SDLC).
  • Subprocessors: engage only those listed on our Subprocessors page under equivalent terms; notify before material changes with the right to object.
  • Assistance: reasonable help with data-subject requests, DPIAs and supervisory-authority consultations.
  • Breach notice: notify you without undue delay after becoming aware of a personal-data breach affecting your workspace.
  • Deletion/return: self-serve export at any time; deletion on termination per the retention schedule.
  • Audit: annually, on reasonable notice, via written responses/documentation — or third-party reports as certifications land.

3. International transfers

Where transfers from the EEA/UK occur, we rely on Standard Contractual Clauses (and the UK Addendum) with our subprocessors, plus supplementary measures appropriate to the data.

4. Executing a DPA

Email legal@workbos.com from your workspace owner account with your legal entity name and registered address. We countersign and return a copy for your records. Enterprise and White-Label agreements can incorporate the DPA into the order form directly.