This Data Processing Addendum (“DPA”) supplements the Terms of Service between you (“Customer”, the controller) and Locus Leadership Group LLC, doing business as VisibilityDen (“VisibilityDen”, the processor), when VisibilityDen processes personal data on Customer’s behalf.
1. Definitions
“Applicable Data Protection Law” means the EU GDPR, UK GDPR, the California Consumer Privacy Act (as amended by the CPRA), and any other privacy law applicable to a party. Other capitalized terms have the meanings given in the GDPR.
2. Subject matter & duration
Subject matter: providing the Service. Duration: the term of the underlying Terms. Nature & purpose: hosting, processing, and analyzing Customer Data to compute the Executive Confidence Index™ and related views.
3. Categories of data subjects & data
- Data subjects: Customer’s employees, contractors, and authorized end users.
- Data categories: identifiers (name, work email, role), employment context, project metadata, financial inputs Customer chooses to enter, pulse responses, integration access tokens.
4. Customer instructions
VisibilityDen will process Customer Data only on Customer’s documented instructions, including as set out in the Terms and the Service’s configuration, except where required by law (in which case we will inform Customer unless that law forbids it).
5. Confidentiality
Personnel authorized to process Customer Data are bound by confidentiality obligations and trained on data protection.
6. Security
We implement and maintain the technical and organizational measures described in our Security & Trust page (the “TOMs”). Customer agrees the TOMs provide an appropriate level of security under Article 32 of the GDPR.
7. Subprocessors
Customer authorizes the subprocessors listed at /legal/subprocessors. We will give 30 days’ written notice (via email or in-app) before adding a new subprocessor; Customer may object on reasonable data-protection grounds, and the parties will work in good faith to resolve.
8. International transfers
Where Customer Data originating in the EEA, UK, or Switzerland is transferred to the US, the parties incorporate the EU Standard Contractual Clauses (Module Two: Controller-to-Processor) and the UK IDTA Addendum by reference.
9. Data subject requests
We will assist Customer in responding to data-subject requests under Articles 15–22 GDPR (and equivalent rights under other laws), including via in-product export and deletion tooling.
10. Personal data breach
We will notify Customer without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting Customer Data, with the information required by Article 33(3) GDPR as we have it.
11. DPIAs
We will provide reasonable assistance with DPIAs and prior consultations with supervisory authorities.
12. Audits
We will make available the information necessary to demonstrate compliance with this DPA, including third-party reports, security questionnaires, and annual summaries. On-site audits may be requested at Customer’s expense, no more than once per year, on 30 days’ notice.
13. Return or deletion
On termination, we will return or delete Customer Data within 90 days unless retention is required by law.
14. CCPA
With respect to personal information of California residents, VisibilityDen acts as a “service provider” and will not sell or share such personal information, retain or use it outside the direct business relationship, or combine it with information from other sources except as permitted by the CCPA.
15. Acceptance
This DPA is incorporated by reference into the Terms. By accepting the Terms, Customer accepts this DPA. For an executable counterpart, use our contact form.