Screenata

Data Processing Addendum

Effective August 20, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between WOX LLC, which operates Screenata (“Provider”), and the customer that has entered into that agreement (“Customer”) for use of the Screenata services (the “Services”). It governs Provider’s processing of personal data on Customer’s behalf.

Getting this in place. This DPA applies automatically to customers whose agreement incorporates it by reference. If you need a countersigned copy, or your own paper, email support@screenata.com and we will execute it.

Protected health information is handled under a separate Business Associate Agreement, which takes precedence over this DPA for PHI. Do not send PHI to the Services before a BAA is signed.

1.Definitions

Capitalized terms not defined here have the meaning given in the agreement between the parties.

  • Applicable Data Protection Laws. The privacy, data protection, and data security laws applicable to Provider’s processing under the agreement, including, as applicable, State Privacy Laws and the GDPR.
  • Controller. The entity that determines the purposes and means of processing, including any “business” or “controller” under the CCPA or other State Privacy Laws.
  • Customer Data. Information provided or made available by or on behalf of Customer to Provider for processing on Customer’s behalf to perform the Services.
  • GDPR. Regulation (EU) 2016/679 (“EU GDPR”) and the EU GDPR as it forms part of UK law under the European Union (Withdrawal) Act 2018 (“UK GDPR”), together with national implementing legislation such as the UK Data Protection Act 2018.
  • FADP. The Swiss Federal Act on Data Protection of 25 September 2020, and its implementing ordinances.
  • Information Security Incident. A breach of Provider’s security resulting in accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data in Provider’s possession or control. It does not include unsuccessful attempts that do not compromise security, such as failed log-ins, pings, port scans, or network attacks repelled at the perimeter.
  • Personal Data. Customer Data that constitutes personal data, personal information, or personally identifiable information under Applicable Data Protection Laws.
  • Processor. The entity that processes Personal Data on behalf of the Controller, including any “service provider” or “contractor” under the CCPA.
  • Restricted Transfer. A transfer of Personal Data to a country outside the EEA, UK, or Switzerland that does not benefit from an adequacy decision and would be prohibited without a legal basis under Chapter V of the GDPR or its equivalent.
  • SCCs. The standard contractual clauses approved by the European Commission under implementing Decision (EU) 2021/914.
  • Subprocessor. A Provider affiliate or third party that Provider engages to process Personal Data in connection with the Services.
  • UK Transfer Addendum. Template Addendum B.1.0 issued by the UK Information Commissioner’s Office under section 119A of the Data Protection Act 2018.

2.Duration, scope, and roles

This DPA remains in effect for as long as Provider processes Personal Data, notwithstanding expiry or termination of the agreement. For Personal Data within Customer Data, Customer is the Controller and Provider is the Processor. Processing subject to the GDPR is additionally governed by Section 10; processing subject to State Privacy Laws is additionally governed by Section 11.

3.Customer instructions

Provider will process Personal Data only in accordance with Customer’s documented instructions, including this DPA, the agreement, any order form, and other written instructions consistent with them. By entering into this DPA, Customer instructs Provider to process Personal Data to provide the Services and to perform its obligations and exercise its rights under the agreement.

If Customer requests instructions outside the scope of the Services, or that would require Provider to materially change the Services or undertake additional work, the parties will agree those instructions in a written amendment. Provider will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws, unless legally prohibited from doing so.

4.Security

Security measures

Provider will implement and maintain the technical and organizational measures set out in Section 13, taking into account the state of the art, the cost of implementation, the nature and purposes of processing, and the risks to data subjects. Provider may update these measures, including to improve security or address changes in law, provided the updated measures do not materially decrease overall protection.

Personnel

Provider will ensure that personnel authorized to access Personal Data are bound by appropriate confidentiality obligations and receive training appropriate to their role.

Information security incidents

Provider will notify Customer without undue delay after becoming aware of an Information Security Incident, describing the details then known, the steps taken to mitigate risk, and the steps Provider recommends Customer take. Notification is not an acknowledgement of fault or liability. Provider will reasonably cooperate with Customer’s investigation.

Customer is responsible for meeting its own notification obligations to supervisory authorities, data subjects, and others. Where such a notice identifies or refers to Provider, Customer will, where permitted by law, notify Provider in advance and consider in good faith any corrections Provider reasonably requests that relate to Provider’s involvement and are consistent with applicable law.

Customer's responsibilities

Customer is responsible for its own use of the Services, including configuring them appropriately for the risk presented by its Personal Data, securing its account credentials and the systems and devices it uses to access the Services, and maintaining its own backups where appropriate. Customer confirms it has evaluated the Services and these measures and considers them adequate to meet its obligations under Applicable Data Protection Laws.

5.Data subject rights

Taking into account the nature of the processing, Provider will give Customer the assistance reasonably necessary and technically feasible for Customer to respond to requests from data subjects exercising their rights. Where such assistance requires work beyond the Services, Provider will provide a good-faith fee estimate in advance at its then-current professional services rates.

If Provider receives a request directly from a data subject, it will promptly notify Customer, unless prohibited by law, and direct the individual to Customer. Customer is responsible for responding.

6.Customer responsibilities

  • Customer will provide all notices to, and obtain all consents and permissions from, data subjects and other third parties required under Applicable Data Protection Laws for Provider to process Personal Data as contemplated by the agreement, including any notices required by Articles 12 to 14 of the GDPR.
  • Customer will ensure a valid legal basis exists throughout the term for Provider’s processing, including where applicable under Articles 6, 9(2), and 10 of the GDPR.
  • Customer will not submit to the Services any payment card data subject to PCI DSS, credentials to financial accounts, tax return data, biometric or genetic data, or personal data of children under 16, and will not submit government-issued identification numbers except where a feature of the Services expressly collects them.
  • Protected health information. Customer may submit PHI only where a Business Associate Agreement between the parties is in effect. That BAA governs PHI and prevails over this DPA to the extent of any conflict. Absent a signed BAA, Customer will not submit PHI to the Services.

7.Subprocessors

Customer specifically authorizes Provider to engage its affiliates as Subprocessors, and generally authorizes Provider to engage third parties as Subprocessors in accordance with this section. Current Subprocessors are listed in Section 14.

Provider will enter into a written contract with each Subprocessor imposing data protection obligations no less protective than those in this DPA, to the extent applicable to that Subprocessor’s services. Provider remains responsible for the performance of obligations it subcontracts and is liable for its Subprocessors’ acts and omissions to the same extent as if it had performed the processing itself.

Before engaging a new Subprocessor, Provider will notify Customer of the name, location, and activities involved, by updating Section 14 and giving written notice, including by email, to Customer’s designated contact. If Customer objects within 15 days on reasonable grounds relating to data protection, the parties will work in good faith toward a resolution. If none is reached within a reasonable time, Customer’s sole and exclusive remedy is to terminate the affected Services on written notice, paying amounts due as of the termination date.

8.Audits

Customer may audit Provider’s compliance with this DPA once per year, and on other occasions where Applicable Data Protection Laws or a competent supervisory authority require it. Customer must submit a proposed audit plan describing scope, duration, and start date at least two weeks in advance, and any third-party auditor must sign a customary non-disclosure agreement. Provider may object to an auditor that is, in its reasonable opinion, not independent, a competitor, or otherwise manifestly unsuitable.

Where the controls in question are covered by a SOC 2 Type 2, ISO, NIST, or similar report issued by a qualified third-party auditor within the previous 12 months, and Provider confirms no known material changes to those controls, Customer agrees to accept that report in lieu of an audit. Audits are conducted during business hours, must not unreasonably interfere with Provider’s operations, and are at Customer’s expense, including reasonable documented costs incurred by Provider.

9.Return and deletion

On the date the Services involving processing of Personal Data cease (the “Cessation Date”), Provider will stop processing Personal Data for any purpose other than storage and the steps needed to return, delete, or anonymize it.

On written request made within 30 days after the Cessation Date, and to the extent technically feasible, Provider will either return a complete copy of the Personal Data by a secure method and then delete or anonymize its other copies, or delete or anonymize all Personal Data in its possession, as Customer elects. If Customer gives no instruction within that 30-day window, Provider will delete or anonymize the Personal Data within a commercially reasonable time.

Provider may retain Personal Data where applicable law requires, for no longer than required, provided it keeps the data confidential, protects it under the security measures in Section 13, processes it only for the purpose the law requires, and deletes or anonymizes it once retention is no longer required.

10.Artificial intelligence and automated processing

  • Provider will not use Personal Data to train, fine-tune, develop, or improve any artificial intelligence or machine learning model, whether its own or a third party’s, unless doing so is reasonably necessary to provide the Services under Customer’s documented instructions or Customer authorizes it in writing.
  • Provider will prohibit its Subprocessors, including AI model providers, from using Personal Data for their own model training, fine-tuning, development, or improvement, except as Customer expressly authorizes in writing.
  • The Services generate drafts, findings, and recommendations for human review and do not perform automated decision-making producing legal or similarly significant effects on data subjects. If that changes, Provider will disclose it to Customer, provide meaningful information about the logic involved to the extent reasonably available and without disclosing trade secrets, and cooperate as Applicable Data Protection Laws require.

11.European annex

This section applies to processing of Personal Data subject to the GDPR or the FADP.

Roles and processor obligations

Customer is the controller and Provider the processor. Provider will comply with Article 28 of the GDPR, including by processing only on documented instructions, ensuring confidentiality commitments from personnel, implementing Article 32 security measures, respecting the conditions in Section 7 for engaging Subprocessors, assisting Customer with Articles 32 to 36 obligations taking into account the nature of processing and the information available to Provider, and making available the information necessary to demonstrate compliance.

Restricted transfers

Where a Restricted Transfer occurs, the parties agree the following apply automatically, without further action:

  • EU. The SCCs, Module Two (controller to processor) or Module Three (processor to processor) as applicable, with the docking clause applying, Clause 9 option 2 with a 15-day notice period, Clause 11 optional redress language omitted, Clause 17 governed by the law of Ireland, and Clause 18(b) disputes heard by the courts of Ireland. The annexes are populated by Sections 12 to 14 of this DPA.
  • UK. The SCCs as amended by the UK Transfer Addendum, with Tables 1 to 3 populated by Sections 12 to 14, and Table 4 selecting “neither party” as the party that may end the addendum.
  • Switzerland. The SCCs as amended so that references to the GDPR are read as references to the FADP, the competent authority is the FDPIC, and Swiss residents may enforce their rights as third-party beneficiaries.

If a transfer mechanism is invalidated, superseded, or replaced, Provider may on written notice adopt the replacement mechanism, provided it does not materially reduce the protection afforded to Personal Data.

12.State privacy laws annex

This section applies to processing subject to State Privacy Laws, including the CCPA. Provider acts as a service provider, contractor, or processor as those terms are defined in those laws, and:

  • will not sell or share Personal Data, as those terms are defined in the CCPA and equivalent laws;
  • will not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the agreement, or as otherwise permitted by the CCPA;
  • will not retain, use, or disclose Personal Data outside the direct business relationship between the parties;
  • will not combine Personal Data with personal information received from another source, except as the CCPA permits;
  • certifies that it understands and will comply with these restrictions, and will notify Customer if it determines it can no longer meet its obligations.

Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data, and Provider will grant Customer the rights described in Section 8 for that purpose.

13.Annex 1 — Processing details and security measures

Details of processing

ItemDetail
ControllerCustomer, as identified in the agreement
ProcessorWOX LLC, 539 W. Commerce St #8166, Dallas, TX 75208
Subject matter and natureProvision of the Screenata compliance evidence automation platform, including evidence collection, documentation, review workflows, and reporting
DurationThe term of the agreement, plus the retention period described in Section 9
PurposePerforming the Services in accordance with Customer's documented instructions
Categories of data subjectsCustomer's personnel, contractors, administrators, auditors, and other individuals whose information Customer submits to the Services
Categories of Personal DataNames, business contact details, job titles, account identifiers, access and activity records, and the contents of evidence and documentation Customer submits
Sensitive dataNone, except protected health information where a Business Associate Agreement is in effect
FrequencyContinuous, for the duration of the agreement
Contact for data protectionsupport@screenata.com

Technical and organizational measures

  • Encryption. Personal Data is encrypted in transit using TLS and at rest, with sensitive objects additionally encrypted and served through time-bounded, presigned URLs.
  • Access control. Role-based access on a least-privilege basis, multi-factor authentication for administrative access, and periodic access reviews.
  • Logging and monitoring. Access to Personal Data and administrative actions are logged, retained, and monitored for anomalies.
  • Segregation. Customer environments are logically separated so that one customer’s data is not accessible to another.
  • Resilience. Regular backups, tested restoration procedures, and documented incident response processes.
  • Personnel. Background screening where permitted by law, confidentiality obligations, and security awareness training.
  • Vendor management. Security review of Subprocessors before engagement and on an ongoing basis.

Further detail is published on our security page.

14.Annex 2 — Subprocessors

The following Subprocessors may process Personal Data in connection with the Services. Provider will update this list before engaging a new Subprocessor, as described in Section 7. To be notified of changes, email support@screenata.com.

SubprocessorPurposeLocation
Microsoft Corporation (Azure)Cloud infrastructure hosting, compute, and data storageUnited States
Amazon Web Services, Inc. (SES)Transactional and notification email deliveryUnited States
OpenAI, L.L.C.AI model provider — evidence drafting, analysis, and chatUnited States
Anthropic, PBCAI model provider — evidence drafting, analysis, and chatUnited States
Fireworks AI, Inc.AI model inferenceUnited States
Google LLC (Gemini)AI model provider — evidence drafting, analysis, and chatUnited States
Stripe, Inc.Payment processing and subscription billingUnited States
PostHog, Inc.Product analytics and usage measurementUnited States
Functional Software, Inc. (Sentry)Application error and performance monitoringUnited States
Axiom, Inc.Log management and observabilityUnited States
Microsoft Corporation (Microsoft 365)Business productivity, email, and document collaborationUnited States
GitHub, Inc.Source code management and engineering issue trackingUnited States
Slack Technologies, LLCInternal communication and customer support channelsUnited States

AI model providers listed above are contractually prohibited from using Personal Data to train, fine-tune, or improve their models, as set out in Section 10.

Third parties that receive personal information through the screenata.com marketing site, rather than through the Services, are listed separately in our Privacy Policy.

15.Miscellaneous

Except as expressly modified here, the agreement remains in full force. Where this DPA conflicts with the agreement, this DPA prevails; where SCCs entered into under Section 11 conflict with this DPA or the agreement, the SCCs prevail for the transfer they cover.

Each party’s total aggregate liability under this DPA and any applicable SCCs is subject to the limitations and exclusions of liability agreed in the agreement, except that nothing here affects any person’s rights as a third-party beneficiary under the SCCs.

Provider may vary this DPA on written notice solely to the extent necessary to maintain compliance with Applicable Data Protection Laws, provided the variation does not materially reduce protections for Personal Data or materially increase Customer’s obligations without Customer’s written agreement.

Questions about this DPA: support@screenata.com.