Data Protection Agreement

Parties and formation

This Data Processing Agreement (the "DPA") is entered into between:

  • the User of the Salary Matrix platform in whose Account Worker Data is uploaded — being the Producer or, where the individuals operating the Account act on behalf of their employer, that employing entity (the "Controller"); and
  • IDH Solutions B.V., registered with the Dutch Chamber of Commerce under number 88809390, with registered office at Arthur van Schendelstraat 500, 3511 MH, Utrecht, the Netherlands (the "Processor" or "IDH Solutions").

This DPA is incorporated by reference into the Salary Matrix Terms of Use (the "Terms") and forms part of the agreement described in Section 3.3 of the Terms (the "Agreement"). It is concluded upon the Controller’s acceptance of the Terms and applies to every Account, including free Accounts, from the first moment Worker Data is uploaded. No separate signature is required; upon written request, IDH Solutions will provide a countersigned copy of this DPA. This DPA applies to the instances where IDH Solutions acts as Processor of Worker Data, but IDH Solutions may act as Controller in respect of other Worker Data processed, or the purpose or means of such processing, in the Salary Matrix tool.

1. Definitions and interpretation

1.1  Capitalised terms not defined in this DPA have the meanings given in the Terms (including "Account", "Affiliate", "Buyer", "Connection", "Facility", "Intermediary", "Platform", "Producer", "Report", "Subscriber", "Visibility Level", "Your Data" and "Anonymised Aggregated Data").

1.2  "GDPR" means Regulation (EU) 2016/679; "Data Protection Law" means the GDPR, the Dutch GDPR Implementation Act (Uitvoeringswet AVG) and any other data protection law applicable to the Processing. "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach", "Supervisory Authority" and "special categories of personal data" have the meanings given in the GDPR.

1.3  "Worker Data" means Personal Data contained in Your Data relating to workers of the Controller’s Facilities, including remuneration, benefits, contract type, working time, job category, gender and worker identifiers, as further described in Annex 1.

1.4  "Sub-processor" means a third party engaged by the Processor to Process Worker Data on the Controller’s behalf.

1.5  In the event of conflict: (a) this DPA prevails over the Terms on the subject of the Processing of Personal Data; (b) where Standard Contractual Clauses adopted by the European Commission apply pursuant to Clause 8, those clauses prevail over this DPA to the extent of any conflict.

2. Roles and subject matter of the Processing

2.1  This DPA governs the Processing of Worker Data by the Processor on behalf of the Controller in connection with the Platform. With respect to Worker Data, the Controller is the controller and the Processor is the processor within the meaning of the GDPR.

2.2  The Processor acts as an independent controller, and not as processor, for: (a) Account, registration, usage, log and security data that it Processes to operate, secure, administer and improve the Platform and to comply with its own legal obligations; and (b) Anonymised Aggregated Data and the anonymisation operation that produces it, as set out in Clause 11. This DPA does not apply to that Processing, which is described in the Privacy Statement.

2.3  The subject matter, duration, nature and purposes of the Processing, and the categories of Data Subjects and of Personal Data, are set out in Annex 1.

3. Documented instructions

3.1  The Processor shall Process Worker Data only on the documented instructions of the Controller, including with regard to transfers to a third country or an international organisation, unless required to do so by Union or Member State law to which the Processor is subject; in that case, the Processor shall inform the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.

3.2  The Controller’s documented instructions consist of: (a) the Agreement, including the Terms and this DPA; (b) the Controller’s use and configuration of the Platform, including the creation, submission and deletion of Salary Matrices; (c) the Controller’s acceptance, modification and revocation of Connections as described in Clause 12; and (d) any further written instructions agreed between the parties. Additional instructions falling outside the functionality of the Platform may be subject to reasonable additional fees.

3.3  The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions, and may suspend execution of that instruction until it is confirmed or amended.

4. Controller obligations

4.1  The Controller is responsible for the lawfulness, accuracy and quality of the Worker Data and for its own compliance with Data Protection Law, and warrants in particular that it: (a) has a valid legal basis under Article 6 GDPR for the Processing of Worker Data via the Platform; (b) has provided the workers concerned with the information required by Articles 13 and 14 GDPR (privacy notice is available at https://salarymatrix.idhtrade.org/privacy-statement; (c) will identify workers using pseudonymous worker IDs and will not upload names or other direct identifiers unless strictly necessary; and (d) will not upload special categories of Personal Data (Article 9 GDPR) or Personal Data relating to criminal convictions and offences (Article 10 GDPR), unless strictly necessary and lawful, in which case the Controller shall inform the Processor in advance.

4.2  The Controller shall handle all Data Subject communications relating to the Worker Data, subject to the Processor’s assistance obligations under Clause 10.

5. Confidentiality of personnel

The Processor shall ensure that all persons authorised to Process Worker Data are bound by contractual or statutory obligations of confidentiality, are granted access on a need-to-know basis only, and receive appropriate data protection training.

6. Security

6.1  Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. The measures currently implemented are described in Annex 2.

6.2  The Processor may update the measures in Annex 2 from time to time, provided the updates do not materially reduce the overall level of protection.

7. Sub-processors

7.1  The Controller grants the Processor general authorisation to engage Sub-processors to Process Worker Data. The Sub-processors engaged at the effective date of this DPA are listed in Annex 3.

7.2  The Processor shall inform the Controller of any intended addition or replacement of a Sub-processor at least 30 days in advance, by updating the list at in Annex 3 and/or by notice to the Account email or via the Platform, so as to give the Controller the opportunity to object on reasonable data-protection grounds. If the Controller objects on such grounds and the parties cannot agree a solution within a reasonable period, the Controller may, as its sole remedy, terminate the part of the services affected by the objected-to Sub-processor (or, where that part cannot reasonably be separated, the Agreement) with respect to the Processing that cannot be performed without that Sub-processor.

7.3  The Processor shall impose on each Sub-processor, by a written contract, data protection obligations that are no less protective than those in this DPA, in particular the obligations required by Article 28(3) GDPR, and shall carry out appropriate due diligence before engagement. Where a Sub-processor fails to fulfil its data protection obligations, the Processor remains fully liable to the Controller for the performance of that Sub-processor’s obligations, subject to Clause 16.

8. International transfers

8.1  The Processor shall not transfer Worker Data to a country outside the European Economic Area, or to an international organisation, except where a valid transfer mechanism under Chapter V GDPR is in place — namely an adequacy decision or appropriate safeguards (in particular the Standard Contractual Clauses adopted by the European Commission), together with any supplementary measures required to ensure an essentially equivalent level of protection.

8.2  The Controller instructs and, to the extent necessary, mandates the Processor to conclude the applicable Standard Contractual Clauses with Sub-processors on the Controller’s behalf and to take the further steps required to give effect to Chapter V GDPR. The transfer mechanism applicable to each Sub-processor is indicated in Annex 3.

8.3  The Platform and the Worker Data are hosted in Europe.

9. Personal Data Breach

9.1  The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Worker Data, to the Account email address (and, where provided, the Controller’s designated security contact).

9.2  The notification shall, to the extent then known (and supplemented as information becomes available), describe the nature of the breach, the categories and approximate numbers of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. The Processor shall take reasonable steps to contain and remediate the breach and shall reasonably cooperate with the Controller in meeting the Controller’s obligations under Articles 33 and 34 GDPR.

9.3  The Processor’s notification of, or response to, a Personal Data Breach is not an acknowledgement of fault or liability. The Controller is responsible for notifying Supervisory Authorities and Data Subjects where required.

10. Assistance

10.1  Taking into account the nature of the Processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests from Data Subjects exercising their rights under Chapter III GDPR. If the Processor receives such a request directly, it shall forward it to the Controller without undue delay and shall not respond to the Data Subject on the merits except on the Controller’s documented instruction or where required by law. The Platform’s self-service functions (viewing, correcting, exporting and deleting data) form part of this assistance.

10.2  Taking into account the nature of the Processing and the information available to it, the Processor shall assist the Controller in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation).

10.3  Assistance under this Clause 10 is provided free of charge to the extent it can be delivered through the Platform’s standard functionality or with limited effort. For assistance requiring material additional effort, the Processor may charge reasonable fees at its then-current rates, notified in advance.

11. Anonymisation instruction

11.1  The Controller hereby instructs and authorises the Processor to create Anonymised Aggregated Data from the Worker Data, in accordance with, and subject to, the cumulative anonymisation and aggregation standard and the small-cell safeguards set out in Section 8 of the Terms.

11.2  Once that standard is met, the resulting Anonymised Aggregated Data is no longer Personal Data and falls outside the scope of the GDPR and of this DPA. The Processor acts as controller for the anonymisation operation and for the resulting Anonymised Aggregated Data, and may use it as permitted by Section 8 of the Terms.

11.3  The Processor shall not attempt to re-identify, and shall contractually require any recipient of Anonymised Aggregated Data not to attempt to re-identify, any Producer, Facility, worker, Intermediary, Subscriber or other individual from that data.

12. Connections; disclosure on the Controller’s instruction

12.1  The Platform enables the Controller to make some or all of its Salary Matrix data visible to a recipient it designates (an Intermediary and/or a Buyer) through a Connection, at a Visibility Level and for a duration chosen by the ControllerIntermediary and/or Buyer, but approved by the Controller, in accordance with Section 7.4 of the Terms.

12.2  The Controller’s acceptance of a Connection in the Platform — identifying the recipient, the Visibility Level (aggregated facility level averages or full granularity) and the duration — constitutes the Controller’s documented instruction to the Processor to disclose the relevant data accordingly. The Controller’s revocation of a Connection constitutes the documented instruction to cease further disclosure. The Processor records these instructions.

12.3  A recipient of data through a Connection Processes that data as an independent controller for its own purposes and is responsible for its own compliance with Data Protection Law. The Processor is not a joint controller with, and does not act as processor for, any such recipient in respect of the disclosed data.

12.4  Revocation stops future access but does not affect the lawfulness of disclosures already made, or of data already exported by a recipient, before revocation. The Terms require recipients to cease access on revocation and to delete exported data where reasonably practicable.

13. Audit

13.1  The Processor shall make available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR and this DPA — in the first instance through up-to-date certifications, third-party audit reports, summaries of penetration tests and completed security questionnaires.

13.2  Where that information is not sufficient to demonstrate compliance, the Controller (itself or through an independent third-party auditor who is bound by confidentiality and is not a competitor of the Processor) may audit the Processor’s Processing of Worker Data, including by on-site inspection, no more than once per calendar year, on at least 30 days’ prior written notice, during normal business hours, in a manner that does not disrupt the Processor’s operations, and subject to confidentiality. The Controller bears its own and the Processor’s reasonable costs of such an audit, except where the audit reveals a material breach by the Processor.

13.3  An audit may be conducted more frequently where required by a Supervisory Authority or following a Personal Data Breach affecting the Controller’s Worker Data.

14. Return and deletion

14.1  On expiry or termination of the Agreement, the Processor shall, at the Controller’s choice, return and/or delete the Worker Data, in accordance with Section 7.7 of the Terms. The Controller may export Worker Data and Reports at any time before deletion, using the Platform’s export functions, in a commonly used, machine-readable format, at no additional charge.

14.2  The Processor shall retain Worker Data for 90 days after termination to enable export (or for a shorter period if the Controller requests earlier deletion in writing), after which it shall securely delete the Worker Data, save that: (a) residual copies in backups are deleted in the ordinary backup cycle of at most 35 days thereafter; (b) data may be retained where and for as long as required by Union or Member State law; and (c) Anonymised Aggregated Data, and Reports already delivered or shared before termination, are not affected — and Worker Data will not be included in any Report created after termination.

14.3  The Processor shall, on the Controller’s written request, confirm in writing that it has complied with this Clause 14.

15. Term and duration

15.1  This DPA takes effect as set out in the "Parties and formation" section and remains in force for as long as the Processor Processes Worker Data on behalf of the Controller under the Agreement.

15.2  Provisions that by their nature are intended to survive termination — including Clauses 5, 11.3, 14, 16 and 17 — survive termination of this DPA and of the Agreement.

16. Liability

16.1  Each party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in Section 12 of the Terms. The liability cap in Section 12 of the Terms applies in the aggregate to all claims under the Terms and this DPA taken together, and not separately to each.

16.2  Nothing in this DPA or the Terms limits or excludes any liability that cannot be limited or excluded under Data Protection or other relevant Law, including the liability of a controller or processor towards a Data Subject under Article 82 GDPR, and including damages or losses arising from gross negligence or wilful misconduct of either Party.

16.3  As between the parties, where both are held responsible for damage caused by Processing, each shall bear the share of the compensation that corresponds to its share of responsibility for the damage, in accordance with Article 82(5) GDPR, subject (as between the parties only) to Clause 16.1.

16.4  The mandatory carve-outs in Section 12 of the Terms — including for intent or deliberate recklessness, death or personal injury caused by negligence, fraud, and any other liability that cannot be excluded or limited under applicable law — apply equally to this DPA.

16.5  For the avoidance of doubt, neither Clause 16.1 nor Section 12 of the Terms limits the Controller’s liability for breach of Clause 4 (lawfulness and permitted content of Worker Data), or under any indemnity the Controller gives under the Terms; such liability is not subject to the cap.

17. General provisions

17.1  Order of precedence. In the event of conflict, this DPA prevails over the Terms on the subject of the Processing of Personal Data; where the Standard Contractual Clauses apply, they prevail over this DPA to the extent of any conflict.

17.2  Changes in law. If a change in Data Protection Law, or guidance or a decision of a Supervisory Authority or court, requires amendment of this DPA, the parties shall negotiate in good faith the amendments necessary to maintain compliance. The Processor may make such amendments on reasonable notice, provided they do not materially reduce the protection of Worker Data.

17.3  Notices. Notices under this DPA are given as provided in the Terms. The Controller shall keep its Account email address current; it serves as the notification address under this DPA unless a designated contact is registered in the Platform.

17.4  No signature required. This DPA is binding without signature. On the Controller’s written request, the Processor will provide a countersigned copy.

17.5  Governing law and forum. This DPA is governed by the laws of the Netherlands. The competent court is the District Court Midden-Nederland, location Utrecht, subject to the dispute-resolution provisions of the Terms.

 

Annex 1 — Description of the Processing (Article 28(3) GDPR)

Subject matter Hosting and Processing of Worker Data submitted to the Salary Matrix platform for the purpose of living wage gap assessment and related Platform functionality.
Duration The term of the Agreement, plus the retention and deletion periods in Clause 14.
Nature of the Processing Collection via data entry and file upload; storage; structuring; calculation (living wage gap and full-time-equivalent computations; LW Contribution calculations where subscribed); generation of Reports and dashboards; disclosure to recipients designated by the Controller via Connections; helpdesk support and remote data quality desk-checks where agreed; backup; deletion.
Purposes Enabling the Controller to calculate, monitor and report living wage gaps for its Facilities; enabling disclosures instructed by the Controller via Connections; providing support and (where agreed) data quality checks; creating Anonymised Aggregated Data pursuant to Clause 11.
Categories of Data Subjects Workers (employees and other workers, whether permanent, temporary, seasonal or piece-rate) engaged at the Controller’s Facilities; contact persons and Authorised Users of the Controller.
Categories of Personal Data Worker-level data: pseudonymous worker ID; job category / work area; gender; contract and worker type; working time and full-time-equivalent basis; wages, bonuses and in-kind benefits; total remuneration; derived gap values. Contact persons: name, business email, role, activity logs. Worker names or other direct identifiers only where the Controller uploads them contrary to guidance (see Clause 4.1(c)).
Special categories None intended or permitted; see Clause 4.1(d). Gender is recorded as workforce composition data.
Frequency Continuous during the term; typically annual submission cycles per Facility.

 

Annex 2 — Technical and Organisational Measures (Article 32 GDPR)

  • Encryption: TLS for all data in transit; encryption at rest on the hosting infrastructure.
  • Access control: role-based access; access to Worker Data restricted to authorised personnel on a need-to-know basis; unique named accounts; multi-factor authentication for administrative access; periodic access reviews; logging of administrative access.
  • Application security: authentication with account activation; session management; input validation; separation of customer data by logical access controls; the Connection invite mechanism requires matching of Account email and Facility ID without disclosure of which element failed.
  • Continuity: automated backups with a maximum retention cycle of 35 days; disaster recovery procedures; capacity and availability monitoring.
  • Assessments: periodic security assessments and/or penetration tests; vulnerability management with prioritised remediation.
  • Organisational: confidentiality undertakings and data protection training for personnel; documented incident response procedure supporting the notification commitment in Clause 9; sub-processor due diligence and contracting per Clause 7; data minimisation guidance to Controllers (pseudonymous worker IDs).

Annex 3 — Approved Sub-processors

The following table lists the Sub-processors currently engaged by IDH Solutions, the nature of the services they provide, and the primary locations where data is hosted or processed:

Sub-processorCorporate EntityService / FunctionPrimary Data LocationSafeguard / Transfer Mechanism
HerokuSalesforce, Inc.Cloud Application Platform & HostingEurope (EU Region)EU Data Residency / EU-U.S. Data Privacy Framework
Amazon S3Amazon Web Services EMEA SARLFile Storage & Asset HostingEurope (EU Region)EU Data Residency / EU-U.S. Data Privacy Framework
ImgixZebrafish Labs, Inc.Image Processing & CDN DeliveryEurope / Global CDNStandard Contractual Clauses (SCCs) / EU-U.S. DPF
Google AnalyticsGoogle Ireland Limited / Google LLCWeb Analytics & Performance TrackingEurope / GlobalEU IP Anonymization / EU-U.S. Data Privacy Framework
ZendeskZendesk, Inc.Customer Support & Ticketing SystemEurope (EU Data Center)EU Data Residency / EU-U.S. Data Privacy Framework
MailgunSinch Email / Mailgun Technologies, Inc.Transactional Email DeliveryEurope (EU Region)EU Data Residency / EU-U.S. Data Privacy Framework