Most vendor DPAs are long because the vendor holds a copy of your data. We do not. ControlLayer runs entirely inside your Salesforce org and transmits nothing to us, so the only personal data we process on your behalf is what you hand us during support (a login session, a screenshot, a log excerpt). This document covers that, honestly and without inflation.
Contents
- Scope and order of precedence
- Definitions
- Roles of the parties
- Our processing obligations
- Your obligations
- Security
- Sub-processors
- Data subject requests
- Personal data breach
- International transfers
- Return and deletion
- Audits and assessments
- Liability
- Annex I - Description of processing
- Annex II - Technical and organizational measures
- Annex III - Sub-processors
1. Scope and order of precedence
This Data Processing Addendum (“DPA”) forms part of the Software License Agreement (the “Agreement”) between Interactive Ties LLC (“we,” “us,” “Processor”) and the customer named in that Agreement (“you,” “Customer,” “Controller”).
It applies where we process Personal Data on your behalf in the course of providing the Software or support, and only to the extent Data Protection Laws apply to that processing. In the event of conflict, this DPA prevails over the Agreement on the subject of data protection; the Standard Contractual Clauses, where they apply, prevail over both.
If you require a countersigned copy for your records, email privacy@controllayer.app and we will sign one. Otherwise this DPA is effective automatically as part of the Agreement.
2. Definitions
“Data Protection Laws” means all laws applicable to the processing of Personal Data under this DPA, including Regulation (EU) 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws including the California Consumer Privacy Act as amended.
“Personal Data,” “processing,” “controller,” “processor,” “data subject” and “personal data breach” have the meanings given in the GDPR. “Standard Contractual Clauses” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914, together with the UK International Data Transfer Addendum where relevant. “Customer Personal Data” means Personal Data within your Salesforce org, or that you otherwise provide to us, which we process on your behalf under the Agreement. Capitalized terms not defined here have the meanings in the Agreement.
3. Roles of the parties
3.1 You are the controller. You are the controller of Customer Personal Data. You determine the purposes and means of its processing, and you are responsible for the lawfulness of the data in your Salesforce org.
3.2 We are your processor, narrowly. We act as your processor only in respect of Customer Personal Data we actually process, which is limited to the circumstances in Annex I. We will process it only on your documented instructions, which comprise the Agreement, this DPA, and any support request you make.
3.3 The Software transmits nothing to us. The ControlLayer managed package is fully native and operates exclusively within your Salesforce org. It does not transmit Customer Personal Data to us or to any third party. Salesforce, Inc. is your own processor under your agreement with Salesforce and is not our sub-processor.
3.4 Where we are a controller. We are an independent controller of the business-contact data of your personnel (names, work email addresses, company) that we hold for account management, billing and product communications. That processing is described in our Privacy Policy and is not governed by this DPA.
4. Our processing obligations
We will:
- Process Customer Personal Data only on your documented instructions, including for transfers, unless required otherwise by law, in which case we will tell you first, unless the law forbids it on important grounds of public interest;
- Tell you promptly if, in our opinion, an instruction infringes Data Protection Laws;
- Ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive appropriate training;
- Limit access to those personnel who need it to provide the support you have requested;
- Implement the measures in Annex II;
- Assist you, taking into account the nature of the processing and the information available to us, with your obligations under Articles 32 to 36 of the GDPR, including data protection impact assessments and prior consultation;
- Not sell or share Customer Personal Data as those terms are defined by U.S. state privacy laws, and not retain, use or disclose it for any purpose other than performing under the Agreement.
5. Your obligations
You warrant that you have a lawful basis for the Personal Data in your Salesforce org and for providing it to us, that you have given the notices and obtained the consents required, and that your instructions comply with Data Protection Laws.
One practical point deserves emphasis, because it is the main way this relationship goes wrong: when you send us a log excerpt, an export or a screenshot for support, you decide what is in it. We ask that you send the minimum needed to diagnose the problem, and that you redact or omit special category data, government identifiers and financial account data unless it is genuinely necessary. Granting time-limited Salesforce login access is usually a better option than sending an export, and you can revoke it at any moment.
6. Security
We will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, as described in Annex II. We may update those measures provided the level of protection is not reduced.
7. Sub-processors
You give general authorization for us to engage the sub-processors listed at Sub-processors. We will impose data protection obligations on each of them no less protective than those in this DPA, and we remain fully liable to you for their performance.
We will give at least thirty (30) days' notice before adding or replacing a sub-processor, by updating that page and emailing the contact we hold for you. You may object on reasonable data protection grounds within that period, in which case we will work with you in good faith to find an alternative; if we cannot, you may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused remainder of its term.
8. Data subject requests
Because the Software holds your data in your own Salesforce org, you can respond to access, correction, erasure, restriction, portability and objection requests directly, using your own Salesforce tools, without needing anything from us.
If a data subject contacts us about Customer Personal Data, we will not respond substantively, and will promptly refer them to you. Where you nonetheless need our assistance, we will provide reasonable help taking into account the nature of the processing.
9. Personal data breach
We will notify you without undue delay, and in any case within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data we process on your behalf. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point for more information. Where we cannot provide all of that at once, we will provide it in phases as it becomes available.
We will cooperate with you and take reasonable steps to assist in your investigation and remediation. Our notification is not an acknowledgement of fault or liability.
A breach of your own Salesforce org that does not involve data we hold is yours and Salesforce's to handle; we will assist on request but will not usually know it has happened.
10. International transfers
We are established in the United States. Where you transfer Customer Personal Data from the European Economic Area, the United Kingdom or Switzerland to us, the Standard Contractual Clauses are incorporated into this DPA by reference and apply as follows:
- Module Two (controller to processor) applies, with you as data exporter and us as data importer.
- The optional docking clause in Clause 7 applies. In Clause 9, Option 2 (general written authorization) applies with the notice period in section 7. In Clause 11, the optional independent dispute resolution language does not apply. In Clause 17, the governing law is that of Ireland; in Clause 18(b), the forum is the courts of Ireland.
- Annexes I, II and III to the Clauses are populated by Annex I, Annex II and Annex III of this DPA respectively.
- For UK transfers, the UK International Data Transfer Addendum applies to the Clauses, with Tables 1 to 3 populated by the corresponding information in this DPA and Table 4 selecting neither party as able to end the Addendum. For Swiss transfers, references to the GDPR are read as references to the Swiss FADP and the competent authority is the Swiss FDPIC.
We have no reason to believe that laws applicable to us prevent us from meeting these obligations, and we will notify you if that changes. We have received no government request for Customer Personal Data to date and will challenge any that is unlawful or overbroad.
11. Return and deletion
Data in your Salesforce org is under your control throughout and after the Agreement; you do not need us to return it. On termination, and in line with section 17 of the Agreement, uninstalling the package removes its records from your org, so export anything you need for compliance first.
Any Customer Personal Data we hold from support interactions will be deleted within ninety (90) days of termination, or returned to you on written request made within that period, except where we are legally required to retain it, in which case we will keep it only for that purpose and continue to protect it under this DPA.
12. Audits and assessments
We will make available the information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice, allow for and contribute to audits conducted by you or an independent auditor you appoint who is not our competitor and is bound by confidentiality.
Audits will take place no more than once in any twelve-month period, unless required by a supervisory authority or following a personal data breach, will be conducted during business hours, and will be carried out without unreasonably disrupting our operations. Given the limited scope of our processing, we expect that a written questionnaire will ordinarily satisfy this obligation, and we will respond to one within thirty (30) days.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in section 15 of the Agreement, except where Data Protection Laws prohibit that limitation. Nothing in this DPA limits a data subject's rights under Data Protection Laws or under the Standard Contractual Clauses.
Annex I - Description of processing
| Data exporter | The Customer identified in the Agreement, acting as controller. |
|---|---|
| Data importer | Interactive Ties LLC, 2379 Hobblebush Lane, Lake View, New York 14085-9447. Contact: privacy@controllayer.app. Activities: providing and supporting the ControlLayer managed package. Role: processor. |
| Subject matter | Provision of technical support for the ControlLayer managed package. |
| Nature and purpose | Viewing, and where necessary temporarily storing, data made available to us by the Customer in order to diagnose and resolve a technical issue the Customer has reported. We perform no analysis, enrichment, profiling or automated decision-making, and no processing for our own purposes. |
| Duration | For the term of the Agreement, plus the retention period in section 11. |
| Frequency | Occasional, and only when initiated by the Customer through a support request. |
| Categories of data subjects | Determined by the Customer. Typically the Customer's own personnel (Salesforce users and administrators) and, incidentally, individuals appearing in records the Customer shares during support. For example contacts or leads visible in a screenshot. |
| Categories of personal data | Determined by the Customer. Typically identifiers, contact details, employment and user account information, and record content visible in exports, log excerpts, screenshots or a support login session. |
| Special category data | None requested and none required. The Customer is asked not to include it in support material (section 5). If it appears incidentally, the measures in Annex II apply to it. |
| Competent supervisory authority | That of the EEA member state in which the data exporter is established, or of its Article 27 representative where the exporter is not established in the EEA. |
Annex II - Technical and organizational measures
The single most significant measure is architectural: the Software is fully native and transmits no Customer Personal Data to us, so there is no vendor-side copy of your data to breach. In addition, we maintain:
- Encryption. Data in transit is protected by TLS. Data at rest in our systems is encrypted using the platform encryption provided by our sub-processors. Company devices use full-disk encryption.
- Access control. Multi-factor authentication is required on our Salesforce org, our email and our source control. Access to customer information is limited to personnel who need it, on a least-privilege basis, and is revoked promptly when no longer required.
- Support access. Access to a customer org is taken only with that customer's grant, through Salesforce's own time-limited login access mechanism wherever possible, and is revocable by the customer at any time. We do not retain credentials to customer orgs.
- Data minimization. We ask for the minimum material needed to diagnose an issue, prefer a live session to an export, and delete support material once the issue is resolved.
- Secure development. Changes are version-controlled and reviewed. The package is built for and subject to Salesforce's AppExchange security review, and runs within the Salesforce security model, inheriting the customer's own sharing rules, field-level security and permission sets.
- Auditability. The Software records its own actions in the customer's org, so the customer can see what was bypassed, by whom, when and for how long, without depending on us.
- Personnel. Everyone with access is bound by written confidentiality obligations that survive the end of their engagement.
- Incident response. We maintain a documented process for identifying, assessing and notifying personal data breaches, including the notification obligation in section 9.
- Business continuity. Our systems and source code are backed up. Customer org data is not in scope, as we hold none.
- Sub-processor governance. Sub-processors are limited to those in Annex III and are bound by written terms no less protective than this DPA.
Annex III - Sub-processors
The current list, with each sub-processor's role and processing location, is maintained at Sub-processors and forms part of this DPA. Changes are notified under section 7.
Salesforce, Inc. is deliberately absent from that list in its capacity as your platform provider: it processes your org data under your agreement with Salesforce, as your processor, not ours.