DoWork Data Processing Agreement

Last updated: October 7, 2026

This Data Processing Agreement (DPA) is made of this Cover Page and the Common Paper DPA Standard Terms Version 1.1 (commonpaper.com/standards/data-processing-agreement/1.1), which are incorporated by reference. If this Cover Page and the Standard Terms disagree, this Cover Page controls. This DPA is part of, and applies under, the DoWork Terms of Service (dowork.io/terms) whenever DoWork processes Customer Personal Data on the Customer's behalf. No signature is needed. A Customer that needs a signed copy can ask at support@dowork.io.


Cover Page

Agreement: the DoWork Terms of Service between Provider and Customer, effective on the date Customer accepted them.

Approved Subprocessors: those listed at dowork.io/subprocessors, as updated with at least 30 days' notice by email to Customer.

Provider Security Contact: support@dowork.io.

Security Policy: commercially reasonable administrative, technical and physical safeguards, including the measures in Annex II and in the DoWork Privacy Policy ("How we protect it").

DPA Covered Claim: none. DPA Liability Cap: none (the Agreement's limits apply).

Governing State: the Governing Law and Chosen Courts in the Agreement.

Service Provider Relationship: Provider is a "service provider" (and, where applicable, a "processor" or "contractor") under the California Consumer Privacy Act and similar US state privacy laws. Provider certifies that it understands and will comply with these restrictions. It will not:

Governing Member State: EEA transfers: Ireland. UK transfers: England and Wales.

Annex I(A): Parties

Data Exporter: Customer, as named in the Agreement, acting as Controller (or as Processor on behalf of its own clients). Contact: the main email address on Customer's account.

Data Importer: Provider, DoWork, 12402 N. Division St. PMB 185, Spokane, WA 99218, acting as Processor (or Subprocessor). Contact: support@dowork.io.

Annex I(B): Description of Processing

Service: the DoWork Cloud Service described in the Agreement.

Categories of Data Subjects:

Categories of Personal Data:

Special Category Data: not intended. Customer should not use the Cloud Service to store special categories of personal data. Where it appears incidentally (for example in an email), it receives the same protections as all Customer Personal Data.

Frequency of Transfer: continuous, for as long as Customer uses the Cloud Service.

Nature and Purpose of Processing:

All of it is done only on Customer's documented instructions, as set out in the Agreement.

Duration of Processing: for the term of the Agreement, then until deletion as described in the Privacy Policy: within 30 days of the workspace being closed, and from backups within a further 30 days.

Annex II: Technical and Organizational Security Measures