1. Roles
For workspace content, your organization is the controller and WorkBOS is the processor acting on your documented instructions (the product settings and these terms). For account/billing data, WorkBOS is an independent controller as described in the Privacy Policy.
2. Our processor commitments
- Process workspace personal data only to provide the Service and per your instructions.
- Confidentiality: personnel access is role-limited and bound by confidentiality obligations.
- Security: the technical and organizational measures described on our Security page (tenant isolation via RLS, RBAC, encryption in transit and at rest, AV scanning, audit logging, secure SDLC).
- Subprocessors: engage only those listed on our Subprocessors page under equivalent terms; notify before material changes with the right to object.
- Assistance: reasonable help with data-subject requests, DPIAs and supervisory-authority consultations.
- Breach notice: notify you without undue delay after becoming aware of a personal-data breach affecting your workspace.
- Deletion/return: self-serve export at any time; deletion on termination per the retention schedule.
- Audit: annually, on reasonable notice, via written responses/documentation — or third-party reports as certifications land.
3. International transfers
Where transfers from the EEA/UK occur, we rely on Standard Contractual Clauses (and the UK Addendum) with our subprocessors, plus supplementary measures appropriate to the data.
4. Executing a DPA
Email legal@workbos.com from your workspace owner account with your legal entity name and registered address. We countersign and return a copy for your records. Enterprise and White-Label agreements can incorporate the DPA into the order form directly.