DoWork Data Processing Agreement
Last updated: October 7, 2026
This Data Processing Agreement (DPA) is made of this Cover Page and the Common Paper DPA Standard Terms Version 1.1 (commonpaper.com/standards/data-processing-agreement/1.1), which are incorporated by reference. If this Cover Page and the Standard Terms disagree, this Cover Page controls. This DPA is part of, and applies under, the DoWork Terms of Service (dowork.io/terms) whenever DoWork processes Customer Personal Data on the Customer's behalf. No signature is needed. A Customer that needs a signed copy can ask at support@dowork.io.
Cover Page
Agreement: the DoWork Terms of Service between Provider and Customer, effective on the date Customer accepted them.
Approved Subprocessors: those listed at dowork.io/subprocessors, as updated with at least 30 days' notice by email to Customer.
Provider Security Contact: support@dowork.io.
Security Policy: commercially reasonable administrative, technical and physical safeguards, including the measures in Annex II and in the DoWork Privacy Policy ("How we protect it").
DPA Covered Claim: none. DPA Liability Cap: none (the Agreement's limits apply).
Governing State: the Governing Law and Chosen Courts in the Agreement.
Service Provider Relationship: Provider is a "service provider" (and, where applicable, a "processor" or "contractor") under the California Consumer Privacy Act and similar US state privacy laws. Provider certifies that it understands and will comply with these restrictions. It will not:
- sell or share Customer Personal Data;
- retain, use or disclose it for any purpose other than providing the Cloud Service, including any other commercial purpose;
- retain, use or disclose it outside the direct business relationship with Customer;
- combine it with personal information it receives from anyone else, except as those laws allow.
Governing Member State: EEA transfers: Ireland. UK transfers: England and Wales.
Annex I(A): Parties
Data Exporter: Customer, as named in the Agreement, acting as Controller (or as Processor on behalf of its own clients). Contact: the main email address on Customer's account.
Data Importer: Provider, DoWork, 12402 N. Division St. PMB 185, Spokane, WA 99218, acting as Processor (or Subprocessor). Contact: support@dowork.io.
Annex I(B): Description of Processing
Service: the DoWork Cloud Service described in the Agreement.
Categories of Data Subjects:
- Customer's Users (owners, managers and team members);
- Customer's clients and their contacts;
- other people who correspond with Customer by email, appear in its calendars or documents, or are named in its records.
Categories of Personal Data:
- names, email addresses, job titles and roles;
- email metadata (sender, recipients, dates) and, where Customer uses the features that need it, email and document content about Customer's clients;
- calendar events;
- notes, tasks and records Customer creates;
- for Users: working hours, pay rates (visible to Customer's owners only), sign-in and usage data;
- advertising and analytics account data, which is mostly aggregate and non-personal.
Special Category Data: not intended. Customer should not use the Cloud Service to store special categories of personal data. Where it appears incidentally (for example in an email), it receives the same protections as all Customer Personal Data.
Frequency of Transfer: continuous, for as long as Customer uses the Cloud Service.
Nature and Purpose of Processing:
- hosting, storage and display;
- synchronizing data from services Customer connects;
- AI-assisted analysis, drafting and summarizing (by Provider's AI subprocessor, which may not train models on Customer Content and deletes it within 30 days);
- sending messages Customer approves;
- support, security and billing.
All of it is done only on Customer's documented instructions, as set out in the Agreement.
Duration of Processing: for the term of the Agreement, then until deletion as described in the Privacy Policy: within 30 days of the workspace being closed, and from backups within a further 30 days.
Annex II: Technical and Organizational Security Measures
- Encryption in transit (TLS) and at rest.
- Each customer's data logically separated and enforced by row-level security in the database.
- Credentials for connected accounts encrypted.
- Least-privilege access for Provider personnel, and multi-factor authentication on Provider's administrative accounts.
- Read-only access to connected advertising accounts. Changes are made only by Customer's Users in their own browser, with the User confirming each save.
- Logging of reads of client data from connected accounts.
- Subprocessors bound by written data protection terms (see Approved Subprocessors).
- Incident response: notice to Customer without undue delay after Provider becomes aware of a Security Incident affecting Customer Personal Data.