Data Processing Addendum
Definitions
1.1. Applicable Data Protection Law.
means any privacy, data protection, or data security law or binding regulation applicable to the Processing of Customer Personal Data, including, where applicable, the California Consumer Privacy Act and its implementing regulations ("CCPA"), the Personal Information Protection and Electronic Documents Act ("PIPEDA") and substantially similar Canadian provincial laws, the EU General Data Protection Regulation ("GDPR"), and the UK GDPR.
1.2 Customer Personal Data.
means Personal Data contained in data submitted to or collected through the Services that Ando Processes on behalf of Customer. Customer Personal Data does not include Personal Data that Ando Processes as an independent Controller, which is governed by the Agreement and Ando's applicable privacy notice.
1.3 Personal Data.
means information relating to an identified or identifiable individual and includes "personal information" and similar terms under Applicable Data Protection Law.
1.4 Process or Processing.
means any operation performed on Customer Personal Data, including collection, access, storage, use, analysis, disclosure, transmission, deletion, or destruction.
1.5 Security Incident.
means a confirmed breach of Ando's security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Security Incident does not include unsuccessful attempts or events that do not compromise Customer Personal Data.
1.6 Subprocessor.
means a third party engaged by Ando to Process Customer Personal Data on behalf of Customer. The terms "Controller," "Processor," "Business," "Service Provider," "Contractor," "Consumer," "Data Subject," "Sell," and "Share" have the meanings assigned by Applicable Data Protection Law.
Roles and Instructions
2.1 Roles.
For Customer Personal Data subject to this DPA, Customer is the Controller or Business and Ando is the Processor, Service Provider, or Contractor, as applicable.
2.2 Instructions.
Ando will Process Customer Personal Data only on Customer's documented instructions, as set out in the Agreement, this DPA, Customer's configuration and use of the Services, and any additional lawful written instructions agreed by the parties. If Ando reasonably believes an instruction violates Applicable Data Protection Law, Ando will notify Customer and may suspend the affected Processing until the parties resolve the issue.
2.3 Customer Responsibilities.
Customer is responsible for the lawfulness of its instructions and Customer Personal Data, including providing required notices, obtaining required permissions or consents, and ensuring that Customer has authority to provide Customer Personal Data to Ando.
2.4 Independent Controller Processing.
This DPA applies only when Ando acts as a Processor, Service Provider, or Contractor. When Ando Processes Personal Data as an independent Controller, Ando will do so under its applicable privacy notice and Applicable Data Protection Law.
Limited and Specified Processing Purposes
Artificial Intelligence and Automated Processing
4.1 AI Providers.
Ando may use the commercial or API services of the AI providers listed in Exhibit C to provide the Services. Ando will not authorize an AI provider to use Customer Personal Data to train or fine-tune a model made generally available to other customers without Customer's prior written authorization.
4.2 Ando Models and Service Improvement.
Ando may use Customer Personal Data as permitted by Applicable Data Protection Law to provide, maintain, and improve the Services for Customer. Ando may use deidentified or aggregated data under Section 3.3 to develop, evaluate, and improve Ando's models, analytics, and services.
4.3 Customer Decisions and Human Review.
The Services may generate forecasts, recommendations, and schedules. Customer determines how outputs are used and remains responsible for employment, compensation, hiring, disciplinary, and other significant decisions. Ando will reasonably assist Customer with legally required notices, access, opt-out, appeal, human review, cybersecurity audit, and risk assessment obligations relating to automated decision-making technology, to the extent the relevant information is in Ando's possession, custody, or control.
Confidentiality
5.1 Authorized Personnel.
Ando will limit access to Customer Personal Data to personnel who need access to provide or support the Services. Such personnel will be bound by confidentiality obligations and receive privacy and security guidance appropriate to their responsibilities.
5.2 Government Requests.
Unless prohibited by law, Ando will notify Customer of a legally binding request from a public authority for Customer Personal Data. Ando will disclose only the Customer Personal Data legally required and will reasonably cooperate with Customer regarding the request.
Security and Security Incidents
6.1 Security Measures.
Ando will maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data against unauthorized or unlawful access, use, disclosure, alteration, loss, or destruction. Ando's current security measures are described in Exhibit B. Ando may update those measures provided the overall level of protection is not materially reduced.
6.2 Security Incident Notice.
Ando will notify Customer without undue delay after becoming aware of a Security Incident. The notice will include information reasonably available to Ando regarding the nature of the incident, affected data, likely consequences, and mitigation or remediation steps. Ando may provide information in phases as it becomes available.
6.3 Cooperation.
Ando will take reasonable steps to contain, investigate, mitigate, and remediate a Security Incident and will reasonably assist Customer in meeting applicable notification or reporting obligations. Notification is not an admission of fault or liability.
Sub-processors
7.1 General Authorization.
Customer generally authorizes Ando to use the Subprocessors listed in Exhibit C. Ando will enter into written terms with each Subprocessor that require protection of Customer Personal Data consistent with Applicable Data Protection Law and the relevant obligations of this DPA. Ando remains responsible for each Subprocessor's performance of its data protection obligations to the same extent Ando would be responsible if it performed the Processing itself.
7.2 Changes.
Ando will provide at least thirty (30) days' prior notice before a new Subprocessor begins Processing Customer Personal Data. Customer may object within fifteen (15) days of notice on reasonable grounds relating to data protection. The parties will work in good faith to resolve the objection. If they cannot, Ando may refrain from using the new Subprocessor or Customer may discontinue the affected feature or terminate only the affected Services as provided in the Agreement.
Data Subject Requests and Compliance Assistance
8.1 Requests.
If Ando receives a request from a Data Subject concerning Customer Personal Data, Ando will, unless prohibited by law, direct the request to Customer or act on Customer's documented instructions. Customer is responsible for responding to the request.
8.2 Assistance.
Taking into account the nature of the Processing, Ando will provide reasonable assistance through available product functionality and other reasonable measures to help Customer respond to requests to access, know, delete, correct, restrict, object, opt out, appeal, or obtain a portable copy of Customer Personal Data.
8.3 Assessments and Regulators.
Ando will reasonably assist Customer with data protection impact assessments, risk assessments, cybersecurity audits, automated decision-making assessments, and consultations with regulators when required by Applicable Data Protection Law and related to Ando's Processing. Customer will reimburse Ando for reasonable costs of material assistance that is not caused by Ando's breach of this DPA.
Return and Deletion
9.1 Deletion or Return.
Upon expiration or termination of the Services, or earlier upon Customer's written request where required by Applicable Data Protection Law, Ando will return or delete Customer Personal Data within thirty (30) days, unless retention is required by law or the Agreement.
9.2 Backups and Legal Retention.
Customer Personal Data retained in backups will remain protected under this DPA and will be deleted in the ordinary course of backup rotation. Any Customer Personal Data retained by law will be isolated from further Processing except as required by law. Upon request, Ando will provide reasonable confirmation of deletion.
Information and Audit Rights
10.1 Compliance Information.
Upon reasonable request, Ando will provide information reasonably necessary to demonstrate compliance with this DPA, which may include security documentation, completed questionnaires, and independent assessment reports when available.
10.2 Audit.
If the information provided under Section 10.1 is insufficient to meet Customer's obligations under Applicable Data Protection Law, Customer may conduct an audit no more than once in any twelve-month period, except following a Security Incident or where a regulator requires otherwise. An audit must be conducted on at least thirty (30) days' notice, during normal business hours, by an independent auditor bound by confidentiality, at Customer's expense, and without access to other customers' data, source code, or information unrelated to the Services. The audit must not unreasonably interfere with Ando's operations.
10.3 Remediation.
If an audit identifies a material failure to comply with this DPA, Ando will take reasonable and appropriate steps to remediate the failure. Customer may take reasonable and appropriate steps, upon notice, to stop and remediate unauthorized use of Customer Personal Data.
Data Location and International Transfers
11.1 Data Location.
Customer authorizes Ando and its Subprocessors to Process Customer Personal Data in the United States. Ando's primary hosting environment is located in U.S. East regions. Certain Subprocessors may Process Customer Personal Data in other locations as described in their applicable data processing terms.
11.2 Transfer Mechanisms.
If Applicable Data Protection Law requires a transfer mechanism for Customer Personal Data transferred to the United States or another country, the parties will use a valid mechanism. For transfers subject to the GDPR, the European Commission Standard Contractual Clauses adopted by Decision 2021/914, Module Two or Module Three as applicable, are incorporated by reference, with Exhibit A serving as Annex I, Exhibit B as Annex II, and Exhibit C as Annex III. The general authorization option applies, the notice period is stated in Section 7.2, the optional redress clause does not apply, and the governing law and courts will be those of Ireland unless Applicable Data Protection Law requires otherwise. For UK transfers, the then-current UK International Data Transfer Addendum applies with the same annex information, and Swiss law modifications apply where required.
General
12.1 Conflict.
If this DPA conflicts with the Agreement regarding the Processing of Customer Personal Data, this DPA controls. Otherwise, the Agreement remains unchanged.
12.2 Liability.
The limitations of liability and remedies in the Agreement apply to this DPA and the parties' combined liability under the Agreement and this DPA.
12.3 Term.
This DPA remains in effect for as long as Ando Processes Customer Personal Data. Provisions that by their nature should survive will survive termination.
12.4 Governing Law.
The governing law and dispute resolution provisions of the Agreement apply to this DPA, except to the extent a mandatory provision of Applicable Data Protection Law requires otherwise.
12.5 Electronic Signatures.
This DPA may be executed in counterparts and by electronic signature. If the Agreement incorporates this DPA as an attachment, no separate signature is required.
Exhibit A
Details of processing
Subject matter
Processing of Customer Personal Data to provide Ando’s demand forecasting, labor optimization, scheduling, workforce management, communications, integrations, reporting, analytics, and related support services.
Duration
For the term of the Agreement and any limited period thereafter required for deletion, backup rotation, dispute resolution, or legal compliance.
Nature and purpose
Collection, receipt, storage, organization, retrieval, access, analysis, forecasting, generation of labor requirements and schedules, communication, transmission, support, security, correction, deletion, and other Processing necessary for the limited purposes in Section 3.
Frequency
Continuous or recurring, as Customer and its users use the Services.
Data Subjects
Customer employees, workers, managers, administrators, job applicants, contractors, and other authorized users.
Categories of Personal Data
Names, employee or user identifiers, email addresses, phone numbers, job titles and roles, work locations, profile photos, dates of birth, availability, schedule preferences, shift and work history, skills, qualifications, certifications, compensation ranges, recruiting and talent-management information, geolocation if enabled, authentication data, device and usage data, support communications, uploaded content, and other employment or operational information submitted by Customer or its users.
Sensitive or special-category data
No GDPR special-category data is intended to be required for the core Services. Depending on Customer’s configuration, Customer Personal Data may include precise geolocation, authentication data stored in protected form, demographic information, compensation information, or government-identification and background-check information. Customer will not submit special-category or highly sensitive data unless expressly agreed in writing and legally permitted.
Sources
Customer, Customer’s systems and integrations, authorized users, and data generated through use of the Services.
Retention
As configured by Customer, stated in the Agreement, or reasonably necessary to provide the Services, followed by deletion under Section 9.
Ando privacy contact
privacy@ando.work; legal@ando.work; Ando Technologies, Inc., 440 N Barranca Ave #9660, Covina, CA 91723.
Exhibit B
Technical and organizational security measures
Ando maintains the following measures appropriate to the nature of the Services, the Customer Personal Data
Processed, and the risks presented by the Processing. These measures may evolve as technology and the Services
change, provided the overall level of protection is not materially reduced.
Security Governance
• Maintains administrative security and privacy practices appropriate to the Services and assigns responsibility for
security and incident response.
• Requires confidentiality obligations for personnel with access to Customer Personal Data.
• Provides security and privacy guidance appropriate to personnel roles.
• Maintains incident response and service continuity practices appropriate to Ando's operations.Identity and Access Management
• Uses unique user accounts, role-based access controls, and least-privilege principles for production systems.
• Uses multi-factor authentication for privileged administrative access where supported by the applicable system.
• Limits production access to authorized personnel with a business need and removes access following role changes or
separation.
• Reviews and revokes access based on role and business need.Data Protection
• Encrypts Customer Personal Data in transit using industry-standard transport encryption and encrypts production data
at rest using cloud-provider encryption capabilities.
• Uses logical access controls and tenant separation measures designed to prevent unauthorized cross-customer access.
• Manages credentials, secrets, and encryption keys through controlled systems and limits access to authorized
personnel.
• Applies data minimization and retention practices appropriate to the Services.Application and Infrastructure Security
• Hosts the primary production environment in United States East cloud regions using Amazon Web Services and
Google services, as applicable.
• Uses cloud network controls, security groups, logging, monitoring, and alerting designed to detect unauthorized
activity and operational issues.
• Uses vulnerability and patch-management practices appropriate to identified risk.
• Uses secure software-development practices appropriate to the Services, which may include code review, testing,
controlled deployment, and risk-based remediation of identified security issues.
• Uses backup and recovery mechanisms appropriate to service continuity, where applicable.Vendor and Subprocessor Management
• Evaluates Subprocessors based on the nature and sensitivity of the Customer Personal Data they Process.
• Uses written agreements requiring confidentiality, security, and data protection obligations appropriate to the services
provided.
• Restricts Subprocessor access to Customer Personal Data to what is reasonably necessary to provide the contracted
service.AI Processing Controls
• Uses commercial or API offerings of AI providers rather than consumer accounts for Customer Personal Data.
• Does not authorize third-party AI providers to use Customer Personal Data to train models made generally available to
other customers without Customer's prior written authorization.
• Applies access controls, logging, and data minimization to AI-enabled Processing and limits AI provider access to data
reasonably necessary for the requested function.Physical Security
• Ando does not operate its own production data centers. Physical security for production infrastructure is provided by
Ando's cloud infrastructure Subprocessors under their security programs.
Exhibit C
Authorized Subprocessors
The following Subprocessors may Process Customer Personal Data in connection with the Services. Primary production hosting is in United States East regions. Other providers may Process data in additional locations under their applicable data processing terms.
Amazon Web Services, Inc.
Cloud hosting and infrastructure
United States, primarily U.S. East
Google LLC
Cloud, data processing, analytics, and AI services
United States, primarily U.S. East
where configured
OpenAI OpCo, LLC
AI model inference and related processing
United States; other locations under
provider terms
Anthropic, PBC
AI model inference and related processing
United States; other locations under
provider terms
Bird / Pusher (applicable contracting affiliate)
Real-time application messaging and communications infrastructure
United States and other locations
under provider terms
Twilio Inc. (applicable contracting affiliate)
SMS, voice, email, and notification services
United States and other locations
under provider terms
Functional Software, Inc. d/b/a Sentry
Application error monitoring, diagnostics, and performance monitoring
United States and other locations
under provider terms
Stripe, Inc. (applicable contracting affiliate)
Billing and payment processing, generally limited to account and billing data
United States and other locations
under provider terms
Subprocessor notices:
Ando will provide notice under Section 7.2 to Customer's designated legal, privacy, security, or account contact.