1. Application and definitions
This Data Processing Addendum (“DPA”) forms part of the agreement between Customer and Union Software when Union Software processes personal information in Customer Data to provide the platform. “Applicable Data Protection Law” means privacy, data-protection, and breach-notification law applicable to that processing, including PIPEDA, substantially similar Canadian provincial private-sector laws, Québec’s private-sector privacy law, and applicable U.S. state privacy laws.
“Customer Personal Information” means personal information or personal data in Customer Data. “Process” and related terms have the meaning given by Applicable Data Protection Law. Terms such as controller, processor, business, service provider, contractor, and organization are used according to the law that applies.
2. Roles and instructions
Customer is the organization, controller, or business that determines the purposes of Customer Personal Information. Union Software acts as Customer’s processor, service provider, contractor, or agent for that information. Customer instructs Union Software to process Customer Personal Information to provide, secure, support, and administer the services in the agreement, respond to documented instructions, and comply with law.
Union Software will notify Customer if it believes an instruction violates Applicable Data Protection Law, unless prohibited from doing so, and may pause the affected processing while the parties resolve the concern. Customer is responsible for the lawfulness, accuracy, quality, and notices associated with Customer Personal Information and its instructions.
3. Processing restrictions
- Process Customer Personal Information only for the business purposes in the agreement and Customer’s documented instructions.
- Not sell or share Customer Personal Information, retain, use, or disclose it outside the direct business relationship, or combine it with personal information received from another source except as permitted by applicable law to provide the service.
- Not use Customer Personal Information for targeted advertising or to train a general-purpose AI model without separate, explicit written authorization.
- Ensure personnel authorized to process Customer Personal Information are bound by confidentiality obligations.
- Provide the same level of privacy protection required of a service provider or processor under Applicable Data Protection Law and notify Customer if Union Software can no longer meet an applicable obligation.
- Certify that Union Software understands these processing restrictions and will comply with them.
4. Security program
Union Software will maintain reasonable administrative, technical, and physical safeguards appropriate to the sensitivity, amount, format, and distribution of Customer Personal Information and the risks of the processing. The current baseline measures are described in Annex B below. Union Software may update controls to reflect new technology and risk, provided overall protection is not materially reduced.
5. Security incidents
Union Software will notify Customer without undue delay after confirming unauthorized access to, acquisition of, use of, disclosure of, loss of, or destruction of Customer Personal Information in Union Software’s custody or control (a “Security Incident”). The notice will include, as information becomes reasonably available, the nature of the incident, affected information and people, likely consequences, containment and remediation, and a contact for follow-up.
Union Software will take reasonable steps to contain, investigate, mitigate, and remediate a Security Incident and will reasonably assist Customer with required risk assessment and notices. Customer is responsible for notifications as the controlling organization unless law requires Union Software to notify directly. An unsuccessful attempt that does not compromise Customer Personal Information is not a Security Incident.
6. Subprocessors
Customer gives general authorization for the subprocessors listed on the Subprocessors page. Union Software will bind each subprocessor that handles Customer Personal Information to written data-protection duties appropriate to its service and remains responsible for its performance to the extent required by the agreement and law.
Union Software will provide at least 30 days’ notice before a new subprocessor begins materially different processing of Customer Personal Information. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate only the affected feature, with a prorated refund of prepaid unused fees for that feature.
7. Individual requests
Taking into account the nature of the processing, Union Software will provide reasonable assistance for Customer to respond to verified access, correction, deletion, portability, opt-out, consent-withdrawal, and appeal requests. If Union Software receives a request concerning Customer Personal Information, it will direct the requester to Customer and will not respond substantively unless instructed or legally required.
8. Compliance assistance
Union Software will provide information reasonably necessary for Customer’s privacy impact assessments, vendor reviews, consultations, and compliance obligations relating to the service, taking into account the nature of processing and information available to Union Software. Additional work beyond standard documentation may be subject to agreed professional-services fees.
9. Information and audits
On request no more than once annually, Union Software will provide its then-current standard security and privacy documentation reasonably sufficient to demonstrate compliance. If that material is insufficient and law requires further verification, Customer may conduct a narrowly scoped audit through an independent, qualified auditor under confidentiality, on at least 30 days’ notice, during normal business hours, without accessing another customer’s data or unreasonably disrupting operations. Customer bears its audit costs unless the audit identifies a material breach by Union Software.
10. Data location and transfers
Union Software will assign the Customer workspace to the supported residency region selected during signup or identified in the order form. Unless the order form states otherwise, a Canadian Customer uses a Canadian regional deployment, a US Customer uses a US regional deployment, and a Customer in another supported market uses the corresponding regional deployment. Union Software will configure its core cloud infrastructure and managed production database services in that supported region, including core Customer Personal Information storage, in-region database replicas, backups, application processing, and private service-to-service network paths. The subprocessors supporting those services are identified in the Subprocessors disclosure incorporated under section 6.
Union Software will not intentionally move, replicate, or route core Customer Personal Information through another hosting region as part of ordinary platform operation. This restriction does not prevent a customer-authorized correction of an incorrectly selected setup region, limited external processing required by documented Customer instructions for an enabled feature as described below, or processing required by applicable law. Where legally permitted, Union Software will notify Customer before responding to a binding requirement that conflicts with this restriction.
The regional commitment applies to the core hosted platform. Customer authorizes remote support access and limited processing in other locations by approved subprocessors where required for public internet delivery or enabled communications, payments, mapping, support, security, or customer-directed integrations. These limited transfers do not change the primary storage region. Union Software will use a lawful transfer mechanism and contractual safeguards where Applicable Data Protection Law requires them.
For Québec information communicated outside Québec, the parties will cooperate on the required privacy impact assessment and written arrangement. For other cross-border transfers, Customer remains responsible for determining whether its use and instructions require an additional assessment or localization term.
11. Return and deletion
During a paid subscription or free trial, Customer may use available export functions. The end of a trial that does not become a paid subscription is a termination for purposes of this section. Union Software will provide the export opportunity described in the Platform Terms and then delete Customer Personal Information from active systems within 90 days after termination, unless law requires retention. Information in encrypted backups will be isolated from ordinary use and deleted through the normal backup cycle. Union Software may retain minimal billing, consent, suppression, security, and agreement records required by law, to prevent abuse, or to establish legal claims.
12. Government requests
If legally compelled to disclose Customer Personal Information, Union Software will, where lawful, notify Customer before disclosure, review the request for validity and scope, and disclose only the information legally required. Union Software will not voluntarily provide Customer Personal Information to an authority except in an emergency involving a credible risk of death or serious bodily harm or with Customer’s instruction.
13. Duration, conflict, and changes
This DPA remains in effect while Union Software processes Customer Personal Information. If it conflicts with another part of the agreement on privacy processing, this DPA controls. A change required by law may be made on written notice; a material reduction of Customer’s protection during a paid term requires Customer’s agreement or a right to terminate the materially affected service.
Annex A — Processing details
| Item | Description |
|---|---|
| Subject and purpose | Providing the modules, hosting, support, security, integrations, and professional services in the agreement |
| Duration | The subscription and the limited return, deletion, backup, legal-retention, and incident-response periods described above |
| People | Members, represented workers, organizers, stewards, officers, employees, retirees, dependants where authorized, employer contacts, vendors, website visitors, payers, and authorized users |
| Information | Identity and contact data; membership, worksite, classification, credential, dues, casework, grievance, discipline, communications, survey, election, organizing, financial, transaction, document, support, audit, and device data chosen for enabled modules |
| Sensitive information | Union membership or affiliation, organizing activity, health and accommodation information, grievance and discipline records, government identifiers, financial information, location and other information treated as sensitive by law |
| Frequency | Continuous or as initiated by Customer and authorized users during the subscription |
| Customer instructions | The agreement, workspace configuration, administrator actions, documented support instructions, and lawful written directions |
Annex B — Baseline security measures
- Access controls based on authenticated identities, roles, least privilege, and administrative separation between customer workspaces.
- Encryption in transit using current transport security and encryption at rest for supported production storage and backups.
- Logging and monitoring for authentication, privileged activity, service health, and security events appropriate to the service.
- Secure software-development practices including review, dependency and vulnerability management, environment separation, secrets management, and controlled deployment.
- Business-continuity measures including backups, recovery procedures, infrastructure redundancy appropriate to the purchased service, and incident escalation.
- Personnel confidentiality commitments, access approval and removal, security awareness, and access limited to a business need.
- Subprocessor review and contracts addressing confidentiality, security, incident reporting, deletion, and processing restrictions.
- Incident response procedures for triage, containment, evidence preservation, remediation, communication, and post-incident improvement.