Version 1.3 · Effective
Data Processing Addendum
This addendum sets out how Shuffl processes personal information in a workspace on behalf of the employer that runs it. It forms part of the Terms of Service between Shuffl LLC and that employer, and applies for as long as Shuffl processes that information.
Where this addendum and the Terms of Service disagree about personal information, this addendum wins. Where the Standard Contractual Clauses apply and disagree with either, the Clauses win.
Roles
The employer is the controller of the personal information in its workspace, and the business under California law. Shuffl is its processor, and its service provider under California law. The employer decides what goes into the workspace, who may see it and how long it is kept, within what the product allows.
Shuffl is a controller only for what it decides itself: sign-in and account security, operating and debugging the service, billing, and support and sales conversations with Shuffl. The Privacy Policy covers that information, and this addendum does not.
If the employer is itself acting as a processor for another company, such as a group company, the employer confirms that company has authorized it to use Shuffl, and the employer passes on to that company anything Shuffl tells it under this addendum.
Details of processing
This section is Annex I to the Standard Contractual Clauses where they apply.
- Subject matter: providing the Shuffl service to the employer under the Terms of Service.
- Duration: while the employer uses Shuffl, and then until the information is erased as described under “Deletion and return”.
- Nature and purpose: storing workspace content, retrieving the knowledge a person may read to answer their question, carrying requests an employee approves to HR, keeping audit records, and synchronising people from a connected directory or Slack workspace.
- People whose information is processed: the employer’s employees, contractors and other people it adds to the workspace, its administrators and HR responders, and anyone named in the documents it uploads.
- Categories of information: sign-in details, the people record the employer keeps for each person, questions and answers with the assistant, HR requests and replies, company documents and knowledge, and audit and usage records.
- Sensitive information: the employer decides whether its documents or its people’s questions may contain health, family, union or other special category information. Shuffl applies the same controls to it as to everything else, and the employer is responsible for having a lawful basis to process it.
- Frequency: continuous, while the workspace is in use.
What Shuffl commits to
Shuffl will:
- Process workspace information only on the employer’s documented instructions. The Terms of Service, this addendum and the way the employer configures its workspace are those instructions. If Shuffl is required by law to process it otherwise, Shuffl tells the employer first, unless the law forbids that.
- Tell the employer if, in Shuffl’s opinion, an instruction breaks data-protection law.
- Make sure everyone at Shuffl who can reach workspace information is bound by confidentiality, and that only people who need it for the purposes in this addendum can reach it.
- Not use workspace information to train models, and not use one employer’s information to improve the service for another.
- Help the employer, taking into account what Shuffl knows about the processing, with data protection impact assessments and prior consultations with a supervisory authority that concern Shuffl.
Security
Shuffl keeps technical and organisational measures in place to protect workspace information against accidental or unlawful destruction, loss, alteration, disclosure or access. The measures in force today are below. Shuffl may change them, but not in a way that lowers the overall protection they give.
This section is Annex II to the Standard Contractual Clauses where they apply.
- Workspace separation: PostgreSQL row-level security keeps each workspace’s records apart, and the application connects through restricted database roles. The API takes the workspace from the credential, not from the request.
- Encryption: connections to the service and to the database use verified TLS. Information is encrypted at rest by the hosting and database providers. Tokens that connect a workspace to other services are encrypted by Shuffl before they are stored.
- Access inside a workspace: roles, a separate grant to read HR requests, and an audience on every piece of published knowledge, enforced the same way in the web app, Slack and the API.
- Sign-in: single sign-on through the employer’s identity provider, two-factor authentication, rate limits on sign-in, and API keys limited to the permissions chosen and to 30 days.
- Access by Shuffl personnel: limited to the people who need it to operate the service, investigate a fault or incident, or meet a legal obligation, and recorded.
- Records: administrative actions in a workspace are recorded with who did what, and an administrator can export the workspace.
- Resilience: backups are kept for no more than 30 days so a fault cannot lose a workspace’s work.
- Changes: every change to the service passes automated tests before it reaches production, and dependencies and code history are scanned for known vulnerabilities and leaked secrets.
Subprocessors
The employer authorizes Shuffl to use the subprocessors on the subprocessor page. That list is Annex III to the Standard Contractual Clauses where they apply.
Before a new subprocessor starts processing workspace information, Shuffl updates the list and tells workspace administrators at least 30 days in advance, unless a change has to be immediate to keep the service safe or lawful, in which case Shuffl tells them as soon as it can.
The employer may object to a new subprocessor on reasonable data-protection grounds by writing to Shuffl within that notice period. Shuffl will then try in good faith to address the objection, for example by not using that subprocessor for the employer’s workspace. If that is not possible, the employer may stop using the part of the service the subprocessor is needed for, and Shuffl refunds the fees already paid for that part for the rest of the period.
Shuffl binds every subprocessor to data-protection obligations that protect workspace information at least as well as this addendum, and remains responsible to the employer for what its subprocessors do.
Personal data breaches
If Shuffl becomes aware of a breach of security that leads to workspace information being accidentally or unlawfully destroyed, lost, altered, disclosed or accessed, Shuffl tells the employer’s workspace owners without undue delay, and within 48 hours of becoming aware of it. Shuffl then tells them, as the information becomes available:
Shuffl takes reasonable steps to contain the breach and limit its effects. Telling the employer about a breach is not an admission of fault.
- what happened, and when Shuffl found out;
- which kinds of information and roughly how many people are affected, as far as Shuffl knows;
- the likely consequences; and
- what Shuffl has done and will do about it, and who at Shuffl the employer can talk to.
Requests and assistance
If a person asks Shuffl directly to see, correct, delete or move information held in an employer’s workspace, Shuffl passes the request to that employer and does not answer it itself, except to tell the person where it went.
The product gives the employer the tools to answer most requests itself: administrators can read and correct people records, export the workspace, and remove people and their access. Where those tools are not enough, Shuffl helps the employer answer the request.
If a supervisory authority or another public body asks Shuffl for workspace information, Shuffl tells the employer, unless the law forbids it, and discloses only what the law requires.
Audits
Shuffl gives the employer the information it reasonably needs to show that this addendum is being kept, including answers to a reasonable security questionnaire once a year.
If that information is not enough, or a supervisory authority requires it, the employer may audit Shuffl’s compliance with this addendum, itself or through an independent auditor bound by confidentiality. The employer gives at least 30 days’ notice, the audit happens during business hours without disturbing the service or other customers’ information, and the employer bears its own costs. Unless a breach or the law requires otherwise, this happens no more than once a year.
International transfers
Shuffl processes workspace information in the United States, as the subprocessor page shows. Where the employer or its people are in a country whose law requires a mechanism for sending personal information to the United States, the employer, as data exporter, and Shuffl, as data importer, agree to the terms below, which are incorporated into this addendum by reference.
Shuffl passes the same obligations on to any subprocessor that receives that information outside the country it came from.
- For the European Economic Area, the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 apply: Module Two where the employer is a controller and Module Three where it is a processor. Clause 7 does not apply. Under Clause 9, option 2 applies, with the notice set out under “Subprocessors”. The option in Clause 11 does not apply. Under Clauses 17 and 18, the law and the courts of Ireland apply. The Annexes are the sections of this addendum named in them.
- For the United Kingdom, the International Data Transfer Addendum to those Clauses, issued by the Information Commissioner, applies, completed with the information above. Either party may end it as its Section 19 allows.
- For Switzerland, the same Clauses apply, with the Federal Data Protection and Information Commissioner as the competent authority and references to member states read to include Switzerland.
US state privacy law
Where the California Consumer Privacy Act or a similar US state privacy law applies to workspace information, including information about employees, Shuffl will:
The employer may take reasonable steps to stop and fix any use of that information that breaks this section, after telling Shuffl.
- Process personal information only for the business purposes in the Terms of Service and this addendum, which are providing and supporting the service.
- Not sell or share it, as those words are defined in the California Consumer Privacy Act, and not use it for advertising.
- Not retain, use or disclose it outside the direct business relationship with the employer, or for any purpose other than those business purposes.
- Not combine it with personal information Shuffl receives from anyone else, except as the law allows a service provider to.
- Give it the same level of privacy protection the law requires of the employer, and tell the employer if Shuffl can no longer meet these obligations.
Deletion and return
While the employer uses Shuffl, an administrator can export the workspace at any time.
A company owner or administrator can delete a workspace. It is kept for 30 days, during which a company owner or administrator can restore it and a workspace administrator can still export it. When the 30 days end, Shuffl erases the workspace records automatically. Backups that hold a copy are gone within a further 30 days. Deleting one workspace leaves the company account, company memberships, shared sign-in and directory configuration, and company billing in place.
Shuffl keeps workspace information after that only where a law requires it to, and then only for as long and as far as that law requires, protected as this addendum describes.
Liability
Each party’s liability under this addendum is subject to the limits in the Terms of Service, except where the Standard Contractual Clauses or the law do not allow liability to be limited.
Changes and contact
This addendum carries a version and an effective date, shown at the top of the page. Shuffl tells workspace administrators at least 30 days before a material change takes effect. A change the law requires may take effect sooner.
An employer that needs a signed copy of this addendum can ask for one. Questions about it go to legal@shuffl.ai.