Data Processing Agreement
Last updated: June 9, 2026 · Version 1.0
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms & Conditions (the "Agreement") between the PM app ("Processor", "we", "us") and the customer entity that has accepted the Agreement ("Controller", "you"). It governs the Processing of Personal Data by the Processor on behalf of the Controller in connection with the Service.
This DPA is designed to satisfy the requirements of Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR and the UK Data Protection Act 2018, and equivalent obligations under applicable data protection laws (together, "Data Protection Law"). Where Data Protection Law requires a particular form of agreement (for example Standard Contractual Clauses), the relevant module is incorporated by reference in Annex C.
This DPA takes effect automatically when you accept the Agreement and continue to use the Service. You do not need a counter-signed copy for it to be binding. If your organisation requires a counter-signed copy, email info@thepm.app.
1. Definitions
Capitalised terms not defined here have the meaning given in the Agreement or Data Protection Law.
- Customer Content — content the Controller (or its Authorised Users) submits to the Service.
- Personal Data — any information relating to an identified or identifiable natural person contained in Customer Content or otherwise Processed by the Processor on behalf of the Controller.
- Processing (and Process) — any operation performed on Personal Data, as defined in Data Protection Law.
- Data Subject — the identified or identifiable natural person to whom Personal Data relates.
- Subprocessor — any third party engaged by the Processor to Process Personal Data on the Controller's behalf in connection with the Service.
- Standard Contractual Clauses or SCCs — the standard contractual clauses approved by the European Commission (Decision 2021/914) and the UK International Data Transfer Addendum (IDTA), as applicable.
- Security Incident — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data Processed by the Processor.
2. Roles and scope
The parties acknowledge that, for the purposes of Data Protection Law, the Controller is the controller and the Processor is the processor in respect of Personal Data Processed under the Agreement. Each party will comply with its obligations under Data Protection Law in respect of the Processing it carries out.
The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex A.
3. Controller instructions
The Processor will Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do otherwise by applicable law. The Agreement (including this DPA, the Controller's configuration of the Service, and any use of the Service by the Controller's Authorised Users) constitutes the Controller's documented instructions. The Processor will inform the Controller if, in its opinion, an instruction infringes Data Protection Law.
4. Confidentiality
The Processor will ensure that persons authorised to Process Personal Data are bound by appropriate obligations of confidentiality (whether contractual or statutory) and have received appropriate training on data protection.
5. Security
The Processor will implement and maintain appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing. The current measures are described in Annex B. The Processor may update these measures from time to time, provided that the updated measures do not materially reduce the overall level of security.
6. Subprocessors
The Controller provides a general authorisation for the Processor to engage Subprocessors, subject to this section. The current list of authorised Subprocessors, the data Processed by each, and the purpose of each engagement is set out in section 8 ("Subprocessors") of the Terms & Conditions and incorporated into this DPA by reference.
The Processor will:
- impose written terms on each Subprocessor that are no less protective than those set out in this DPA in respect of the relevant Processing;
- remain liable to the Controller for the acts and omissions of its Subprocessors to the same extent as if they were the Processor's own;
- notify the Controller through the Service or by email of any intended addition or replacement of Subprocessors, giving the Controller a reasonable opportunity (at least 14 days) to object on reasonable data-protection grounds. If the Controller objects and the parties cannot resolve the objection, the Controller may terminate the affected portion of the Service for convenience.
7. International transfers
The Processor and its Subprocessors may transfer Personal Data outside the European Economic Area, the United Kingdom, or other restricted regions, subject to appropriate safeguards. Where required, the parties agree that the Standard Contractual Clauses and the UK International Data Transfer Addendum apply on the terms set out in Annex C.
8. Data subject requests
Taking into account the nature of the Processing, the Processor will assist the Controller by appropriate technical and organisational measures, insofar as possible, to fulfil the Controller's obligation to respond to requests from Data Subjects exercising their rights under Data Protection Law. Most data-subject requests can be fulfilled by the Controller directly through the Service (export, edit, delete). For requests the Controller cannot fulfil itself, the Controller may contact info@thepm.app.
If the Processor receives a request directly from a Data Subject relating to Personal Data Processed on the Controller's behalf, the Processor will, unless legally prohibited, redirect the Data Subject to the Controller and notify the Controller without undue delay.
9. Assistance with controller obligations
The Processor will provide reasonable assistance to the Controller, taking into account the nature of the Processing and the information available to the Processor, with the Controller's obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments, prior consultation).
10. Security incidents
The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of any Security Incident affecting the Controller's Personal Data. The notification will include, to the extent then known: the nature of the Security Incident, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address and mitigate it. The Processor will provide reasonable cooperation and updates as the investigation progresses.
11. Return and deletion
On termination or expiry of the Agreement, the Processor will, at the Controller's choice, delete or return all Personal Data Processed on the Controller's behalf, and delete existing copies, unless retention is required by applicable law. Customer Content remains available for export from within the Service for at least 30 days after termination, after which it will be deleted from primary systems within a further 30 days. Backup copies are purged on a rolling basis in line with the Processor's standard retention schedule (no longer than 90 days).
12. Audits and information
The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. Audit rights under Article 28(3)(h) GDPR will be satisfied by the Processor providing, on reasonable written request and no more than once per 12-month period:
- a summary of the Processor's then-current security measures and policies;
- copies of any third-party certifications or audit reports the Processor holds (e.g. SOC 2, ISO 27001) where available; and
- responses to a reasonable security questionnaire covering the topics in Annex B.
On-site audits are only available where required by a competent supervisory authority or where the information above is not, in the Controller's reasonable opinion, sufficient. Each party bears its own costs, except that the Controller will reimburse the Processor's reasonable costs of any on-site audit.
13. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement. For the avoidance of doubt, references in the Agreement's limitation of liability to "the Service" include this DPA.
14. Order of precedence
If there is a conflict between this DPA and the Agreement, this DPA prevails in respect of the Processing of Personal Data. If there is a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
15. Governing law
This DPA is governed by the laws of the jurisdiction stated in the Agreement, subject to mandatory provisions of Data Protection Law in the Data Subject's jurisdiction and to the governing law of the Standard Contractual Clauses where they apply.
Annex A — Description of Processing
- Subject matter: provision of the Service (a product management workspace) to the Controller.
- Duration: the term of the Agreement, plus any post-termination retention period set out in section 11.
- Nature and purpose: hosting, storing, indexing, transmitting, displaying, securing, backing up, and otherwise Processing Customer Content to make the Service available to the Controller and its Authorised Users, including optional AI Features.
- Categories of Personal Data:
- Authorised User account data: name, work email, password hash, profile details, role.
- Workspace content submitted by the Controller: projects, feedback items, use cases, vendors, competitors, accounts, business units, people records, meetings and agendas, notes, attachments, and mentions.
- Stakeholder and customer-contact data the Controller chooses to capture in the Service (typically business contact details, role, account association).
- Calendar event metadata where the Controller connects a calendar account.
- Usage, device and log data: pages visited, features used, IP address, browser and OS, timestamps, error reports.
- Categories of Data Subjects: the Controller's employees, contractors, and other Authorised Users; the Controller's customers, prospects, stakeholders, and other individuals about whom the Controller chooses to record information in the Service.
- Special-category data: the Service is not intended to Process special-category Personal Data (Article 9 GDPR), criminal-conviction data, payment card data, or government-issued identifiers. The Controller must not submit such data.
- Frequency: continuous, for the duration of the Agreement.
Annex B — Technical and organisational measures
- Encryption in transit: all traffic between clients and the Service is encrypted using TLS 1.2 or higher.
- Encryption at rest: Customer Content and backups are encrypted at rest using industry-standard ciphers (AES-256 or equivalent).
- Access control: Row-Level Security on all multi-tenant database tables, role-based access control within each workspace (admin, editor, commenter, viewer), least-privilege access for personnel, and SSO with strong authentication for production systems.
- Tenant isolation: workspace-scoped data partitioning enforced at the database layer.
- Secrets management: production credentials stored in a managed secrets vault and rotated on a defined schedule.
- Network security: production systems hosted with reputable cloud providers behind hardened network controls; admin access limited and audited.
- Monitoring and logging: application and infrastructure logging, error monitoring, and alerting on anomalous activity.
- Backups and recovery: point-in-time recovery and regular automated backups; restore procedures tested periodically.
- Vulnerability management: regular dependency scanning, prompt patching of known vulnerabilities, and periodic security review.
- Personnel: background-appropriate vetting, written confidentiality obligations, and security and privacy training.
- Incident response: documented incident-response process covering detection, containment, eradication, recovery, notification, and post-incident review.
- Secure development: code review on every change, automated tests, and segregated development / production environments.
Annex C — International data transfers
EU Standard Contractual Clauses. Where Personal Data of Data Subjects in the EEA is transferred from the Controller (as data exporter) to the Processor or a Subprocessor located in a country that has not received an adequacy decision from the European Commission, the parties enter into the Standard Contractual Clauses (Module Two: Controller to Processor) as adopted by Commission Implementing Decision (EU) 2021/914, which are incorporated by reference into this DPA with the following selections:
- Clause 7 (docking clause) does not apply.
- Clause 9 — Option 2 (general written authorisation) applies; the change-notification period is set out in section 6 of this DPA.
- Clause 11 — the optional independent dispute-resolution language does not apply.
- Clause 17 — the SCCs are governed by the law of Ireland.
- Clause 18 — disputes are resolved by the courts of Ireland.
- Annex I.A (Parties), I.B (Description of transfer), and II (Security measures) are populated by reference to the Agreement, Annex A, and Annex B of this DPA.
- Annex III lists the Subprocessors identified in section 8 ("Subprocessors") of the Terms & Conditions.
UK transfers. Where the transfer is subject to UK Data Protection Law, the parties enter into the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (the "IDTA"), version B1.0, which is incorporated by reference. The EU SCCs above are appended; the start date is the effective date of the Agreement; the parties' details and the description of the transfer are as set out in this DPA; neither party may end the IDTA when the Approved Addendum changes.
Swiss transfers. Where the transfer is subject to the Swiss Federal Act on Data Protection, references in the EU SCCs to the GDPR are deemed to refer to the FADP, references to EU member states are deemed to include Switzerland, and the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority.
Contact
For any questions about this DPA, to request a counter-signed copy, or to escalate a data-protection matter, contact info@thepm.app.
