Go back to the homepage

Simple Work Apps - Data Processing Agreement

Effective Date: March 2025

1. Scope

This data processing agreement (the "Addendum") applies exclusively to the processing of personal data (the "Customer Personal Data") by Simple Work Apps on behalf of the Customer where such processing is subject to European Union (EU) or Swiss data privacy law. This Addendum, including its annexes, forms part of, and is subject to, the provisions of the agreement between the parties (the "Services Agreement") in respect of the performance of services (the "Services") by Simple Work Apps to the Customer that include the processing of such Customer Personal Data.

2. Binding Character of this Addendum

The Parties hereby agree to be bound by the provisions and obligations set forth in this Addendum in respect of all their data protection obligations and agree that any data protection and data processing obligations as agreed to previously amongst the Parties shall be deleted and repealed in its entirety and be replaced with this Addendum.


Any changes to this Addendum shall be made in accordance with the provisions of the applicable Services Agreement.

3. Details of Processing

3.1 Subject matter of processing
Employee Engagement services by means of an online software application (the "Application") and the fulfillment of contractual obligations under the Services Agreement and this Addendum.


3.2 Duration of processing
For the duration of the Services Agreement until terminated or once processing by Simple Work Appsof any Customer Personal Data is no longer required for the performance of its relevant obligations under the Services Agreement or Addendum.


3.3 Purpose of processing
The provision of the Services.


3.4 Categories of Personal Data
Employee Engagement data: Employees information (including their General Personal Data).

General Personal Data: data about an identified or identifiable Data Subject, including, but not limited to name, surname, title, date of birth, country of origin, telephone number, email.

Any other personal data requested by the Customer through its use of the Services and Application, provided always that the Customer should not use the Services or Application to process special category data.


3.5 Categories of Data Subjects
Employees and any other natural persons who access and use your account (e.g., advisors).

4. Limitations on Data Storage and Access

4.1 Storage Limitations
Simple Work Apps confirms that it does not retain any sensitive data accessible from Slack, such as organization members' names and channel names. This includes any personal data that might be visible or accessible through integration with Slack's services. Specifically, Simple Work Apps only stores IDs and does not retain user names or channel names.


4.2 Message Content
Simple Work Apps does not have access to read or store the content of messages sent within the Customer's Slack workspace. Messages exchanged within Slack channels and direct messages remain solely within the control and access of the Customer and its authorized users.


4.3 Compliance with Slack's Terms
Simple Work Apps adheres to Slack's terms of service and privacy policy regarding the handling and access to data within Slack workspaces. Any processing of Customer Personal Data through the Application does not involve accessing or storing message content or member information from Slack beyond what is strictly necessary for the provision of the Services under the Services Agreement and this Addendum.


4.4 Data Retention and Automatic Deletion
Simple Work Apps retains Customer Personal Data for a maximum period of one (1) year of inactivity. If a user has not accessed the Services or Application within this timeframe, their data will be automatically deleted.

To ensure transparency, Simple Work Apps will send a notification to the user two (2) weeks prior to the scheduled deletion, informing them of the impending data removal and providing an opportunity to reactivate their account if desired.

5. Roles of the Parties

The Customer and Simple Work Apps hereby agree that for the purposes of this Addendum, the Customer shall be the Controller and Simple Work Apps shall be the Processor.

6. Simple Work Apps' obligations

Simple Work Apps, acting as Processor, shall:

6.1: Only process Customer Personal Data on documented instructions from the Customer, unless required to do so by applicable laws to Simple Work Apps (provided that Simple Work Apps first informs the Customer of that legal requirement before processing, unless that law prohibits this on important grounds of public interest). The Services Agreement, this Addendum along with the Customer' s use of the Services constitute the Customer's documented instructions to Simple Work Apps for the purpose of providing the Services. Simple Work Apps shall immediately inform the Customer if instructions given by the Customer, in the opinion of Simple Work Apps, contravene Data Privacy Law.

6.2: Ensure that all personnel who have access to Customer Personal Data have committed themselves to appropriate obligations of confidentiality;

6.3: Maintain appropriate technical and organizational measures to protect the Customer Personal Data. The Parties acknowledge that security requirements are constantly changing and that effective security requires frequent evaluation and regular improvements of outdated security measures. Simple Work Apps will, therefore, evaluate the measures on an on-going basis and will tighten, supplement and improve these measures as it deems necessary or appropriate in its sole discretion.

6.4: Assist the Customer, to the extent possible, to fulfill the Customer's obligations in responding to requests for exercising of Data Subject rights set out in the applicable Data Privacy Law;

7. The Customer's obligations

The Customer, acting as the Controller, hereby warrants and represents:

7.1: That all processing of Customer Personal Data will be in compliance with all Data Privacy Law, and that the processing of the Customer Personal Data by Simple Work Apps in accordance with this Addendum will not breach Data Privacy Law;

7.2: That Customer Personal Data provided to Simple Work Apps are accurate and will be updated to ensure continued accuracy as and when required;

7.3: That it has notified Data Subjects of any applicable period for which Customer Personal Data or any element of Customer Personal Data will be stored by Simple Work Apps.

7.4 That the Customer has the right to provide Customer Personal Data to Simple Work Apps and has provided Data Subjects with all necessary information and data protection notices on or in connection with the collection of such Customer Personal Data from data subjects including, but not limited to, the supply of Customer Personal Data to Simple Work Apps and details of the purposes for which such Customer Personal Data will be processed by Simple Work Apps including, if applicable, as set out in Simple Work Apps's retention policy;

7.5: That the Customer will not provide Simple Work Apps with nor request Simple Work Apps to process the types and categories of Personal Data listed, defined, or referenced to in Articles 8–10 of the GDPR or respective definitions in the UK and the Swiss Data Privacy Law, and that where applicable, the Customer will not enter any personal data into free text fields embedded in relevant Simple Work Apps products and/or Services and will not incorporate any personal data outside of the scope of Personal Data as contemplated in the Services Agreement and this Addendum into any attachments that are to be uploaded into Simple Work Apps' Application;

7.6: That the Customer shall, and shall procure its employees, contractors, and/or agents to keep the login credentials used to access to the Services secure and shall be liable for the access to the Services through such login credentials. The Customer further shall promptly notify Simple Work Apps of any unauthorized use of any login credentials, or other breaches of security, including loss, theft or unauthorized disclosure of login credentials.

8. Use of Sub-Processors

8.1 Consent to Use of Sub-Processors

The Customer hereby grants to Simple Work Apps permission to utilize Sub-Processors to fulfill Simple Work Apps's contractual obligations under this Addendum, and the Services Agreement. If Simple Work Apps proposes to utilize a Sub-Processor, Simple Work Apps will inform the Customer of any addition, replacement, or deletion of the Sub-Processor and give the Customer the opportunity to object to such changes. The Customer understands and agrees that its consent to this use is a condition of Simple Work Apps's processing of Customer Personal Data.

8.2 Security and Control

Simple Work Apps is responsible for its Sub-Processors' compliance with the obligations of this Addendum, and Simple Work Apps shall remain responsible for such compliance, except for the Customer's request, as per instructions given to Simple Work Apps in the provision of Services to the Customer.

8.3 Documentation

To the extent that a Sub-Processor fails to fulfill its data protection obligations,Simple Work Apps shall remain liable to the Customer for the performance of the Sub-Processor's obligations, unless the Sub-Processor is not under any obligation of confidentiality and security when processing Customer Personal Data, then, for this matter, Simple Work Apps is exempt.

8.4 List of Sub-Processors

Name of sub-processorsLocation of serversPurposeData processed
Google CloudNorth Virginia, US (Google)HostingPlatform and service configuration data
Amazon Web ServicesFrankfurt, Germany (Amazon)HostingPlatform and service configuration data
Amazon Web ServicesNorth Virginia, US (Amazon)
HostingPlatform and service configuration data

9. International Transfers and Standard Contractual Clauses

9.1 Application of Standard Contractual Clauses

The Parties acknowledge that the processing of Customer Personal Data by Simple Work Appsmay involve transfers to sub-processors located in countries outside the European Economic Area (EEA), United Kingdom, or Switzerland that have not been recognized by the European Commission as providing an adequate level of protection for personal data. For any such transfers of Customer Personal Data, the Standard Contractual Clauses (SCCs) adopted by the European Commission in Decision 2021/914/EU, or any set of clauses approved by the European Commission which amends, replaces or supersedes these, shall apply and are hereby incorporated by reference.

9.2 Structure and Applicability of the SCCs

For the purposes of the SCCs:

(a) Simple Work Apps acts as the 'data exporter' and the Sub-Processor acts as the 'data importer';

(b) Module Three (Processor to Processor) of the SCCs shall apply where Simple Work Appstransfers Customer Personal Data to a Sub-Processor;

(c) For transfers to Sub-Processors established in the United States, the Parties acknowledge that they rely on the SCCs to provide appropriate safeguards for such transfers;

(d) Under Clause 9 of Module Three (Use of Sub-processors), the Parties select Option 2 (General Written Authorization) and the time period for prior notice of Sub-processor changes shall be 30 days;

(e) Under Clause 11 of Module Three (Redress), the optional language requiring data subjects to lodge complaints with an independent dispute resolution body shall not apply;

(f) Under Clause 17 of Module Three (Governing Law), the Parties choose Option 1, and the SCCs shall be governed by the laws of a Member State of the EU that allows for third-party beneficiary rights. The Parties select the law of Ireland;

(g) Under Clause 18 of Module Three (Choice of Forum and Jurisdiction), the Parties select the courts of Ireland.

9.3 Updates to the SCCs

The Parties agree that if the European Commission issues new Standard Contractual Clauses replacing those referenced in Section 9.1, Simple Work Apps may update the terms of this Addendum to incorporate such new clauses, provided that the level of protection afforded to Customer Personal Data is not materially reduced as a result of such update.

9.4 Transfer Impact Assessment

Prior to transferring Customer Personal Data to any Sub-Processor located outside the EEA, UK, or Switzerland, Simple Work Apps shall conduct and document a transfer impact assessment analyzing the risks associated with such transfer, taking into account:

(a) The nature of the Customer Personal Data being transferred;

(b) The laws and practices of the destination country relevant to the transferred data;

(c) Any supplementary technical, organizational, and contractual measures implemented to protect the transferred Customer Personal Data.

Upon reasonable request by the Customer, Simple Work Apps shall provide the Customer with a summary of such transfer impact assessment.

9.5 Supplementary Measures

In addition to the SCCs, Simple Work Apps shall implement the following supplementary measures when transferring Customer Personal Data to Sub-Processors located in countries outside the EEA, UK, or Switzerland:

(a) Encryption of Customer Personal Data during transfer and at rest using industry-standard encryption methods;

(b) Pseudonymization of Customer Personal Data where appropriate and feasible;

(c) Contractual commitments from Sub-Processors to:
(i) Process Customer Personal Data only for the specified purposes;
(ii) Implement appropriate technical and organizational measures to protect Customer Personal Data;
(iii) Notify Simple Work Apps promptly of any legally binding request for disclosure of Customer Personal Data by a public authority, unless prohibited from doing so;
(iv) Notify Simple Work Apps promptly if the Sub-Processor is unable to comply with the SCCs.

10. Safety Breaches

Simple Work Apps shall notify the Customer, without undue delay after becoming aware of any security incident involving personal data (the "Incident"). Simple Work Apps shall provide the Customer with the following information:

(a) notify the Customer after it (or any of the Sub-Processors' or Simple Work Apps' personnel) becomes aware of a Personal Data Breach in respect of any Customer Personal Data;

(b) provide all information as the Customer requires (to the extent that it is available to Simple Work Apps) to report the circumstances to a supervisory authority and to notify affected data subjects under Data Privacy Law; and

(c) provide the Customer with reasonable assistance in responding to and mitigating the Personal Data Breach.

11. Liability

The Customer acknowledges that Simple Work Apps is reliant on the Customer for instructions as to the extent to which Simple Work Apps is entitled to use and process the Customer Personal Data.

Consequently, Simple Work Apps will not be liable for losses (including indirect losses, loss or corruption of data, loss of reputation, goodwill and profits), actions, proceedings and liabilities of whatsoever nature incurred by Simple Work Apps or for which Simple Work Apps may become liable due to any claim brought by a Data Subject or Supervisory Authority arising from the Customer's instructions or use of the Services or Application in breach of the Data Privacy Law.

12. Order of Precedence

To the extent of any conflict between this Addendum and any parts of the Services Agreement, this Addendum shall prevail, govern, and supersede.

13. Survival

This Addendum and the obligations hereunder shall survive the termination or expiry of the Services Agreement however effected or arising, and shall continue until Simple Work Apps no longer processes any Customer Personal Data. The Customer Personal Data will be returned to the Customer and deleted by Simple Work Apps in accordance with the Services Agreement.

If you have any questions, concerns, or requests regarding this Terms of use, please contact us at:

Simple Work Apps

Schimmelstrasse 2 Zürich 8003

security@simpleworkapps.com

© 2026 Simple Work AppsCompany UID: CHE-255.395.128