Product
Core Pillars
Communication
Events
Directory
Knowledge
Haystack AI
Key Features
Universal Search
Secure Delivery
Emergency Alerts
Freshness Engine
Recognition
Company Glossary
MOre
Mobile Apps
Integrations
Security & Compliance
Implementation
Platform Overview
Key Integrations
Google Workspace
Okta
Workday
Slack
Confluence
Microsoft 365
Solutions
Challenges We Solve
Single Source of Truth
Employee Onboarding
Frontline Support
Legacy Replacements
Employee Engagement
Building Culture
Industries WE Serve
Technology
Construction
Healthcare
Retail
Financial Services
View All
People We Help
Internal Communications
Human Resources
Information Technology
Executive Leadership
Platform Overview
Video
Company
Haystack
Mission
About Us
Newsroom
Connect
Contact Us
Support
LinkedIn
Featured Items
Founder Letter
Bloomberg Feature
G2 Awards
Our Company
About Us
Resources
Helpful Resources
Resource Center
Haystack Blog
Customer Stories
Tools and Downloads
What Is an Intranet?
Intranet Buyer's Guide
RFP Builder
Featured Stories
Thumbtack
Everbridge
NerdWallet
BuzzFeed
MB2 Dental
Customer Video
Pricing
Book a Demo
Get Started
<- Legal Center

Data Processing Agreement

Last Updated
April 22, 2024

This Data Processing Agreement (DPA) is entered into by the Client and Haystack Team, Inc. (“Data Processor”), as referenced in the Order Form and associated Master Subscription Agreement (the “Principal Agreement”). The effectiveness of this Agreement and its term are as specified in the Order Form and the associated Master Subscription Agreement. This DPA specifies the Parties’ data protection obligations, which arise from the Data Processor’s processing of personal data on behalf of the Data Controller under the quote, service agreement, or other agreement between the Parties. The DPA is adopted as an appendix to the main agreement.

Purpose, Scope & Responsibilities

This Data Processing Agreement forms part of the Contract for Services between the “Client” and the “Data Processor”, collectively referred to as the “Parties”. Whereas the Client acts as a Data Controller and wishes to subcontract certain Services, which imply the processing of personal data, to the Data Processor. The Parties seek to implement a data processing agreement that complies with the requirements of the current legal framework in relation to data processing and with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). The Parties wish to lay down their rights and obligations.

Definitions & Interpretation

Unless otherwise defined, capitalized terms and expressions used in this Agreement shall have the meanings assigned to them here. For example, “Agreement” refers to this Data Processing Agreement and all its Schedules. “Client Personal Data” is any Personal Data Processed by a Contracted Processor on behalf of Client pursuant to or in connection with the Principal Agreement, with “Contracted Processor” meaning a Subprocessor. Definitions also include terms for Data Protection Laws, the European Economic Area (EEA), EU Data Protection Laws including GDPR, Data Transfer, Services, and Subprocessor. Terms such as “Commission”, “Controller”, “Data Subject”, “Member State”, “Personal Data”, “Personal Data Breach”, “Processing”, and “Supervisory Authority” shall have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.

Processing of Client Personal Data

The Processor is obliged to comply with all applicable Data Protection Laws in the Processing of Client Personal Data and not Process Client Personal Data other than on the Client’s documented instructions.

Processor Personnel

The Processor must take reasonable steps to ensure the reliability of any of its employees, agents, or contractors who may have access to the Client Personal Data, with access strictly limited to those individuals who need to know/access the relevant Client Personal Data, as strictly necessary for the purposes of the Principal Agreement, and to comply with Applicable Laws in the context of that individual’s duties.

Security

Considering the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing as well as the risk to the rights and freedoms of natural persons, the Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including measures referred to in the GDPR.

Subprocessing

The Client grants the Processor general authorization to engage Subprocessors to Process Client Personal Data, subject to this section.

Subprocessor list.  The Processor maintains a current list of its Subprocessors. That list is Confidential Information of the Processor and is made available to the Client on request, subject to the confidentiality obligations of this Agreement.

Notice and objection.  The Processor shall notify the Client at least thirty (30) days in advance of engaging a new Subprocessor to Process Client Personal Data. If the Client objects within that period on reasonable grounds relating to the protection of Client Personal Data, the Processor will use commercially reasonable efforts not to use that Subprocessor to Process Client Personal Data, and this shall be the Client’s sole and exclusive remedy in respect of such objection.

Flow-down and liability.  The Processor shall impose on each Subprocessor data protection obligations materially equivalent to those set out in this Agreement, and remains responsible for a Subprocessor’s Processing of Client Personal Data as if performed by the Processor.

Client-directed AI integrations.  Where the Client or its administrator enables an optional integration that connects the Client’s workspace to a third-party artificial-intelligence assistant or platform (an “AI Integration”, as described in the Principal Agreement), any Client Personal Data disclosed to that provider solely because of that enabled connection is disclosed to it as a recipient acting at the Client’s direction and on the Client’s instruction, and does not constitute Processing by a Subprocessor engaged by the Processor for that purpose. The list, notice, objection, and flow-down provisions of this section do not apply to such a disclosure. The Client’s enablement of the AI Integration constitutes the Client’s authorization and documented instruction for that disclosure. The Client remains the Controller in respect of that disclosure and is responsible for its lawfulness. For clarity, this paragraph does not change the status of any provider that Processes Client Personal Data as a Subprocessor in any other capacity under this Agreement.

Data Subject Rights

The Processor shall assist the Client by implementing appropriate technical and organizational measures, insofar as possible, for the fulfillment of the Client’s obligations to respond to Data Subject rights under the Data Protection Laws. The Processor must promptly notify the Client if it receives a request from a Data Subject in respect of Client Personal Data and shall not respond to that request without the Client’s documented instructions.

Personal Data Breach

The Processor shall notify the Client without undue delay upon becoming aware of a Personal Data Breach affecting Client Personal Data, cooperating with the Client and taking reasonable steps as directed by the Client to assist in the investigation, mitigation, and remediation of each such Personal Data Breach.

Data Protection Impact Assessment & Prior Consultation

The Processor shall provide reasonable assistance to the Client with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, solely in relation to Processing of Client Personal Data by the Contracted Processors.

Deletion or Return of Client Personal Data

Upon the cessation of any Services involving the Processing of Client Personal Data, the Processor shall promptly delete and procure the deletion of all copies of those Client Personal Data.

Audit Rights

The Processor shall make available to the Client all information necessary to demonstrate compliance with this Agreement and shall allow for and contribute to audits, including inspections, by the Client or an auditor mandated by the Client in relation to the Processing of the Client Personal Data.

Data Transfer

The Processor Processes Client Personal Data principally in the United States. The Client acknowledges this and, by entering into this Agreement, authorizes the transfer of Client Personal Data to the United States and to any other location in which the Processor or its Subprocessors Process Client Personal Data in order to provide the Services.

Where the Client is established in the European Economic Area, the United Kingdom or Switzerland, or is otherwise subject to Data Protection Laws requiring an approved mechanism for the transfer of personal data to the United States, the Parties shall, upon the Client’s request, enter into such a mechanism, including where applicable the European Commission’s Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum, or such other transfer mechanism as the Parties agree or as Data Protection Laws then permit. Any such mechanism agreed between the Parties is incorporated into this Agreement by reference and prevails over this section in respect of transfers of Client Personal Data.

Where Data Protection Laws so require, the Processor shall not otherwise transfer Client Personal Data to a third country without an applicable transfer mechanism or the prior written consent of the Client.

Client-directed AI Integrations.  Where the Client or its administrator enables an AI Integration (as described in the Principal Agreement), any transfer of Client Personal Data to the relevant AI provider occurs at the Client’s direction and on the Client’s instruction. The Client acknowledges that such provider may Process that data in the United States or other locations under the provider’s own terms and privacy policy, and that the transfer mechanisms in this section apply to the Processor’s and its Subprocessors’ Processing of Client Personal Data, not to the AI provider’s subsequent Processing as a recipient under that AI Integration.

General Terms

Confidentiality.  Each Party must keep this Agreement and information it receives about the other Party and its business (“Confidential Information”) confidential and must not use or disclose that Confidential Information without the prior written consent of the other Party except as required by law or if the information is already in the public domain.

Notices.  All notices and communications must be in writing and delivered personally, sent by post, or sent by email to the address or email address set out in the heading of this Agreement.

Governing Law and Jurisdiction.  This Agreement is governed by, and construed in accordance with, the internal laws of the State of California, without regard to its choice of laws principles. Any action related to or arising from this Agreement shall take place exclusively in the courts situated in Los Angeles, California, and the Parties submit to the venue of those courts. Where this Agreement and the Principal Agreement conflict, this Agreement controls in respect of the Processing of Client Personal Data.

Mailing Address
1301 N Broadway STE 32493, Los Angeles, CA 90012
Privacy Contact
privacy@haystackteam.com
General Inquiries
hello@haystackteam.com
Legal Contact
legal@haystackteam.com
Haystack
About UsSecurityFounder LetterNewsroomLinkedIn
Product
CommunicationsEventsDirectoryKnowledgeHaystack AIMobile Apps
Features
Universal SearchSecure DeliveryEmergency AlertsFreshness EngineRecognitionGlossary
Solutions
Single Source of TruthEmployee OnboardingFrontline SupportLegacy ReplacementsEmployee EngagementBuilding Culture
Resources
Resource CenterHelp CenterCustomer StoriesRFP BuilderRecorded Demo
Copyright Haystack Team, Inc. 2026
Terms of ServicePrivacy PolicyCookiesGDPR