This Data Processing Agreement ("DPA") supplements the Terms of Service between Simcoe House Inc. ("Salt", "Processor") and Customer ("Controller"). It applies when Salt processes personal data on behalf of Customer under data protection laws including the GDPR, UK GDPR, and Swiss DPA.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person that Salt processes on behalf of Customer in connection with the Service.
"Processing" means any operation performed on Personal Data, including collection, storage, use, and deletion.
"Data Protection Laws" means the GDPR (Regulation 2016/679), UK GDPR, Swiss Federal Act on Data Protection, and other applicable data protection laws.
"Subprocessor" means a third party engaged by Salt to process Personal Data.
2. Scope and Roles
Customer is the Controller of Personal Data. Salt is the Processor. This DPA applies to all Personal Data processed by Salt in providing the Service.
Processing Details
| Element | Description |
|---|---|
| Subject Matter | Provision of the Salt proactive AI operating layer |
| Duration | The term of the Subscription Agreement |
| Nature and Purpose | Processing Customer Data from connected accounts to provide insights, prepare work, and enable approval workflows |
| Categories of Data Subjects | Customer's clients, contacts, employees, and other individuals whose data is in connected accounts |
| Categories of Personal Data | Contact information, communications, calendar events, business records, and other data from connected services |
3. Customer Obligations
Customer will:
- Ensure it has a lawful basis to transfer Personal Data to Salt
- Provide any required notices to data subjects
- Respond to data subject requests (with Salt's assistance per Section 7)
- Ensure its instructions comply with Data Protection Laws
4. Salt Obligations
Salt will:
- Process Personal Data only on Customer's documented instructions, unless required by law
- Ensure personnel are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Assist Customer with data subject requests
- Notify Customer without undue delay upon becoming aware of a Personal Data breach
- Delete or return Personal Data upon termination, per Section 6 of the Subscription Agreement
- Make available information necessary to demonstrate compliance and allow for audits
5. Security
Salt implements security measures appropriate to the risk, including:
- Encryption of Personal Data in transit and at rest
- Access controls and authentication
- Regular security assessments
- Incident response procedures
Details of our security practices are available on request.
6. Subprocessors
Customer authorizes Salt to engage subprocessors listed at /subprocessors.
Notice of Changes: Salt will notify Customer at least 14 days before engaging a new subprocessor. Customer may object by providing written notice within 14 days. If Salt cannot accommodate the objection, Customer may terminate the affected Service with a pro-rata refund.
Subprocessor Obligations: Salt ensures subprocessors are bound by data protection obligations no less protective than this DPA.
7. Data Subject Requests
Salt will assist Customer in responding to data subject requests to the extent legally permitted and technically feasible. If Salt receives a request directly, it will redirect the data subject to Customer unless legally prohibited.
8. Data Transfers
Personal Data may be transferred to countries outside the EEA, UK, or Switzerland. Salt relies on:
- Standard Contractual Clauses (EU Commission Decision 2021/914)
- UK International Data Transfer Agreement or Addendum where applicable
- Other valid transfer mechanisms under Data Protection Laws
Copies of transfer safeguards are available on request.
9. Audits
Customer may audit Salt's compliance with this DPA once per year, with reasonable notice and during business hours. Audits must not interfere with Salt's operations or compromise confidentiality of other customers.
Alternatively, Salt may provide a SOC 2 Type II report or equivalent third-party audit report, which Customer agrees to accept in lieu of an on-site audit for the matters covered by the report.
10. Liability
Liability under this DPA is subject to the limitations in the Subscription Agreement, except where Data Protection Laws require otherwise.
11. Term
This DPA remains in effect for the duration of the Subscription Agreement and continues until all Personal Data is deleted or returned.
Contact
Data protection inquiries: hello@usesalt.io
Simcoe House Inc.
1130 SE Morrison St, Apt 612
Portland, Oregon 97214
United States