Smarthub Data Processing Addendum
SMARTHUB DATA PROCESSING ADDENDUM
This Data Processing Addendum (“DPA”) forms part of the Smarthub End User Licence Agreement (“Agreement”) between you (“Customer”, “you”, or “Data Controller”) and Prodactive Labs Ltd (“Prodactive Labs”, “we”, “us”, “Data Processor”) and governs the processing of Personal Data by Prodactive Labs on behalf of Customer in connection with the provision of Smarthub services.
This DPA is effective as of the date you accept the Agreement (the “Effective Date”).
- DEFINITIONS AND INTERPRETATION
1.1 In this DPA, the following terms have the meanings given to them in the UK GDPR and the Data Protection Act 2018 (“Data Protection Laws“):
“Controller”, “Processor”, “Data Subject“, “Personal Data“, “Personal Data Breach“, “Processing” (and related terms such as “Process“), “Supervisory Authority“, and “Sub-processor“.
1.2 “UK GDPR” means the UK General Data Protection Regulation as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018.
1.3 “Customer Data” has the meaning set out in the Agreement and includes any Personal Data contained therein that Smarthub processes transiently on Customer’s behalf.
1.4 Terms not defined in this DPA have the meanings given to them in the Agreement.
- ROLES AND SCOPE OF PROCESSING
2.1 Roles of the Parties:
(a) With respect to Personal Data contained in Customer Data: Customer is the Controller and Prodactive Labs is the Processor. Prodactive Labs shall Process such Personal Data solely on behalf of Customer and in accordance with Customer’s documented instructions as set forth in this DPA and the Agreement.
(b) With respect to Account Data (including your contact details and Smartsheet API credentials) and Usage Data that contains Personal Data: Prodactive Labs is the Controller and processes such Personal Data for its own purposes as described in the Privacy Policy available at https://www.getprodactive.com/legal/data-privacy/.
2.2 Processing Details for Customer Data:
The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects for Smarthub’s processing on Customer’s behalf are:
(a) Subject matter: Provision of Smarthub automation services that execute actions triggered by events in Customer’s Smartsheet account.
(b) Nature of Processing: Transient processing within isolated Containers, including reading, analysing, transforming, and acting upon Customer Data to execute configured automations, followed by immediate and automatic deletion upon completion of each action.
(c) Purpose: To execute automated actions in Customer’s Smartsheet account as configured and triggered by Customer through Smarthub.
(d) Duration: For the duration of the Agreement and during any retention periods specified in Clause 10.3 of the Agreement.
(e) Types of Personal Data: Any Personal Data residing in Customer’s Smartsheet account that Smarthub accesses during execution of actions, which may include names, email addresses, contact details, phone numbers, job titles, employment information, financial data, project data, business records, performance data, and any other Personal Data Customer stores in Smartsheet.
(f) Categories of Data Subjects: Customer’s employees, contractors, customers, suppliers, business partners, and any other individuals whose Personal Data Customer stores in its Smartsheet account.
- CUSTOMER’S OBLIGATIONS AS CONTROLLER
3.1 Customer represents, warrants and undertakes that:
(a) it has complied and shall continue to comply with all Data Protection Laws in relation to its Processing of Personal Data, including in relation to the instructions it gives to Prodactive Labs under this DPA;
(b) it has all necessary rights, consents, and legal bases under Data Protection Laws to: (i) collect and Process the Personal Data; (ii) disclose the Personal Data to Prodactive Labs; and (iii) instruct Prodactive Labs to Process the Personal Data as contemplated by this DPA and the Agreement;
(c) it has provided (or will provide) appropriate privacy notices to Data Subjects regarding the Processing of their Personal Data by Smarthub as a Processor on Customer’s behalf, including information required by Articles 13 and 14 of the UK GDPR;
(d) it is responsible for ensuring that its instructions to Prodactive Labs comply with Data Protection Laws and that the Processing contemplated by this DPA is lawful;
(e) it is responsible for the accuracy, quality, and legality of Personal Data it provides to Smartsheet and that Smarthub processes on Customer’s behalf; and
(f) it shall implement appropriate security measures to protect its Smartsheet API credentials and prevent unauthorised access to its Smartsheet account.
- PRODACTIVE LABS’ OBLIGATIONS AS PROCESSOR
4.1 Processing Instructions:
(a) Prodactive Labs shall Process Personal Data only in accordance with Customer’s documented instructions as set forth in this DPA and the Agreement. Customer’s instructions are deemed to authorise Processing to: (i) provide, maintain, support, and improve Smarthub in accordance with the Agreement; (ii) execute the specific automated actions Customer configures through Smarthub; (iii) prevent or address security threats, technical problems, or violations of the Agreement; (iv) comply with Applicable Law; or (v) as otherwise expressly instructed by Customer in writing.
(b) If Prodactive Labs believes that any instruction from Customer violates Data Protection Laws, it shall promptly inform Customer. Prodactive Labs may refuse to Process Personal Data where it reasonably believes that doing so would cause it to violate Data Protection Laws.
(c) Additional instructions outside the scope of this DPA require prior written agreement between the parties and may result in additional fees.
4.2 Confidentiality and Training:
Prodactive Labs shall ensure that all personnel authorised to Process Personal Data on behalf of Customer are subject to binding obligations of confidentiality (whether contractual or statutory) and have received appropriate training on Data Protection Laws and their obligations under this DPA.
4.3 Restrictions on Disclosure:
Prodactive Labs shall not transfer, disclose, or provide access to Personal Data to any third party except: (a) to Sub-processors in accordance with Clause 6; (b) as instructed by Customer in writing; (c) as required by Applicable Law, in which case Prodactive Labs shall (to the extent permitted by Applicable Law) inform Customer of the legal requirement before Processing; or (d) with Customer’s prior written consent.
- SECURITY MEASURES
5.1 General Security Obligations:
Prodactive Labs shall implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data, taking into account: (a) the state of the art; (b) the costs of implementation; (c) the nature, scope, context and purposes of Processing; and (d) the risk of varying likelihood and severity for the rights and freedoms of Data Subjects, as required by Article 32 of the UK GDPR.
5.2 Smarthub Security Architecture:
The security measures implemented by Prodactive Labs for Smarthub include:
(a) Encryption: Encryption of Personal Data in, and encryption of Personal Data at rest where applicable to stored Account Data, using industry-standard encryption protocols.
(b) Access Controls: Multi-factor authentication, role-based access controls ensuring only authorised personnel with legitimate business need can access Personal Data, unique user credentials for each individual, and regular review and revocation of access rights.
(c) Container Isolation and Transient Processing: Isolation of Containers to ensure Personal Data processed in one Container cannot be accessed by other Containers or users; automatic and immediate deletion of Customer Data from Containers upon completion of each action; no persistent storage of Customer Data; and data minimisation by design – Smarthub retrieves only the minimum Personal Data necessary to execute each action.
(d) Monitoring and Incident Response: Logging of access to and Processing of Personal Data for security monitoring and audit purposes; monitoring for anomalous activity and potential security threats; and incident response procedures to detect, investigate, and respond to Personal Data Breaches.
(e) Personnel Security: Background checks on personnel with access to Personal Data where permitted by law; security awareness training for all personnel; and binding confidentiality obligations for all personnel with access to Personal Data.
(f) Infrastructure Security: Use of reputable Sub-processors (Supabase, Amazon Web Services) with appropriate security measures and industry certifications (SOC 2, ISO 27001); physical security controls at facilities housing systems that Process Personal Data.
(g) Vulnerability Management: Regular security assessments of Smarthub; timely application of security patches and updates; and secure software development practices including code reviews and security testing.
5.3 Transient Processing Architecture as Security Measure:
Customer acknowledges that Smarthub’s transient processing architecture, whereby Personal Data is immediately deleted from Containers after each action completes, constitutes a security-by-design measure that minimises the risk of Personal Data Breaches by ensuring that Customer Data is not persistently stored, archived, or retained beyond the minimum duration necessary to execute each action.
5.4 Updates to Security Measures:
Prodactive Labs may update the security measures described in this Clause 5 from time to time, provided that such updates do not result in a material degradation of the overall security of the Processing. Prodactive Labs shall notify Customer of any material changes to security measures that may affect Customer’s compliance obligations.
- SUB-PROCESSORS
6.1 General Authorisation:
Customer hereby provides general authorisation for Prodactive Labs to engage Sub-processors to Process Personal Data on Customer’s behalf in connection with Smarthub, subject to the requirements of this Clause 6.
6.2 Current Sub-processors:
Prodactive Labs currently engages the following Sub-processors for Smarthub:
(a) Supabase Inc. (United States) – Database, authentication, and backend infrastructure services for Smarthub. Website: https://supabase.com
(b) Amazon Web Services, Inc. (United States) – Cloud computing infrastructure and hosting services for Smarthub. Website: https://aws.amazon.com
6.3 Sub-processor Requirements:
Prodactive Labs shall:
(a) enter into a written agreement with each Sub-processor imposing data protection obligations substantially equivalent to those in this DPA, including obligations relating to security, confidentiality, Data Subject rights, Personal Data Breaches, and international data transfers;
(b) remain fully liable to Customer for the performance of each Sub-processor’s obligations as if Prodactive Labs were performing such obligations directly; and
(c) ensure that each Sub-processor implements appropriate technical and organisational measures to protect Personal Data.
6.4 Changes to Sub-processors:
(a) Prodactive Labs shall provide Customer with at least 30 days’ prior written notice via email before appointing any new Sub-processor or replacing any existing Sub-processor.
(b) Customer may object to the appointment or replacement on reasonable data protection grounds by notifying Prodactive Labs in writing within 15 days of receiving notice.
(c) If no resolution is reached within 30 days, either party may terminate the Agreement.
- DATA SUBJECT RIGHTS
7.1 Assistance with Data Subject Requests:
Taking into account the nature of Smarthub’s transient processing architecture and the information available to Prodactive Labs, Prodactive Labs shall provide reasonable assistance to Customer in fulfilling Customer’s obligations to respond to requests from Data Subjects exercising their rights under Data Protection Laws (including rights of access, rectification, erasure, restriction, data portability, objection, and rights related to automated decision-making).
7.2 Handling Procedures:
If Prodactive Labs receives a Data Subject request relating to Personal Data Processed under this DPA, Prodactive Labs shall promptly (within 2 Business Days) inform Customer, unless prohibited by Applicable Law. Prodactive Labs shall not respond directly except to acknowledge receipt and redirect the Data Subject to Customer, unless instructed by Customer or required by Applicable Law.
7.3 Limitations Due to Transient Processing:
Customer acknowledges that because Customer Data is not persistently stored by Smarthub and is automatically deleted from Containers immediately after each action, Prodactive Labs has limited ability to assist with certain Data Subject requests relating to Customer Data (such as requests for access, rectification, or erasure). Such requests should be addressed by Customer directly through its Smartsheet account. Prodactive Labs can assist with requests relating to Account Data and Usage Data stored in Smarthub’s systems.
- PERSONAL DATA BREACHES
8.1 Notification Obligation:
Prodactive Labs shall notify Customer without undue delay, and in any event within 72 hours, after becoming aware of any Personal Data Breach affecting Personal Data Processed under this DPA.
8.2 Breach Information:
The notification shall include, to the extent possible and as information becomes available: (a) a description of the nature of the breach, including categories and approximate number of Data Subjects and Personal Data records affected; (b) contact details for obtaining further information; (c) a description of the likely consequences; (d) measures taken or proposed to address the breach and mitigate adverse effects; and (e) any other information reasonably requested by Customer.
8.3 Cooperation:
Prodactive Labs shall provide reasonable cooperation and assistance to enable Customer to: (a) comply with obligations under Data Protection Laws regarding notification to Supervisory Authorities and Data Subjects; (b) investigate the breach; (c) implement remedial measures; and (d) respond to enquiries from authorities or Data Subjects.
This Clause 8 does not constitute an acknowledgement by Prodactive Labs of any fault or liability. Customer acknowledges that automatic deletion of Customer Data from Containers in accordance with Smarthub’s documented transient processing architecture does not constitute a Personal Data Breach.
- DATA PROTECTION IMPACT ASSESSMENTS
Prodactive Labs shall, taking into account the nature of Smarthub’s Processing and information available to Prodactive Labs, provide reasonable assistance to Customer in ensuring compliance with Customer’s obligations under Articles 35 and 36 of the UK GDPR (or equivalent provisions of other Data Protection Laws) concerning data protection impact assessments and prior consultation with Supervisory Authorities. Such assistance may include providing information about Smarthub’s technical and organisational measures, transient processing architecture, security controls, Sub-processors, and international data transfers. Customer is solely responsible for determining whether a data protection impact assessment is required and for conducting any such assessment or prior consultation.
- DELETION OR RETURN OF PERSONAL DATA
10.1 Upon termination or expiry of the Agreement, Prodactive Labs shall delete or return Personal Data in accordance with Clause 10.3 of the Agreement. At Customer’s written election (specified before or within 30 days after termination), Prodactive Labs shall: (a) delete all Personal Data and certify deletion in writing; or (b) return Account Data and Usage Data in commonly used electronic format, followed by deletion of all remaining copies, and certify completion in writing. Customer acknowledges that Customer Data is not available for return as it is not persistently stored by Smarthub.
10.2 The obligations in Clause 10.1 shall not apply to the extent Prodactive Labs is required by Applicable Law to retain Personal Data, in which case Prodactive Labs shall: (a) inform Customer of the legal requirement where possible; (b) retain only the minimum Personal Data necessary; (c) continue to ensure confidentiality and security; and (d) Process only to the extent and duration required by law.
- AUDIT RIGHTS
11.1 Prodactive Labs shall, upon Customer’s reasonable written request and subject to at least 30 days’ advance notice (no more than once per year), make available to Customer information reasonably necessary to demonstrate Prodactive Labs’ compliance with its obligations under this DPA by:
(a) providing Customer with copies of relevant third-party audit reports or certifications (such as SOC 2 Type II, ISO 27001, or similar) that Prodactive Labs has obtained for Smarthub systems and controls;
(b) completing information security questionnaires or audit questionnaires provided by Customer (provided such questionnaires are reasonable in scope); or
(c) other reasonable means agreed between the parties.
11.2 If the measures in Clause 11.1 are insufficient and Customer has reasonable grounds (supported by documented evidence) to believe Prodactive Labs is not complying with its obligations under this DPA, Customer may request to conduct or appoint an independent auditor to conduct an on-site audit of relevant systems and controls, subject to: (a) audit being at Customer’s expense; (b) Prodactive Labs’ prior written approval (not to be unreasonably withheld); (c) use of an independent, reputable auditor bound by confidentiality duties; (d) conduct during normal business hours with minimal disruption; (e) limitation to matters relevant to data protection obligations under this DPA; (f) execution of Prodactive Labs’ standard confidentiality agreement; (g) compliance with Prodactive Labs’ reasonable security and confidentiality requirements; (h) limitation to once per year unless prior audit revealed unremediated material non-compliance; and (i) provision of audit report to Prodactive Labs.
11.3 Prodactive Labs may charge reasonable fees for audit assistance beyond providing standard audit reports and completing reasonable questionnaires.
- INTERNATIONAL DATA TRANSFERS
12.1 Acknowledgement of Transfers:
Customer acknowledges and agrees that: (a) Prodactive Labs may Process Personal Data in the United Kingdom and, through Sub-processors, in the United States; (b) Personal Data may be transferred from the United Kingdom to the United States in connection with Smarthub; (c) the United States is not currently subject to an adequacy decision under Article 45 of the UK GDPR; and (d) such transfers are necessary for the performance of the Agreement.
12.2 Transfer Safeguards:
Prodactive Labs shall ensure that all international transfers of Personal Data comply with Chapter V of the UK GDPR by implementing appropriate safeguards, including:
(a) Standard Contractual Clauses: Where required, Prodactive Labs shall enter into the UK International Data Transfer Agreement (IDTA) or EU Standard Contractual Clauses (as applicable) with Customer and Sub-processors. Either party may request execution of such clauses, and the parties shall negotiate and execute them in good faith. Prodactive Labs shall ensure each Sub-processor processing Personal Data outside the UK (or countries with adequacy decisions) is subject to equivalent safeguards.
(b) Adequacy Decisions: Prodactive Labs may rely on adequacy decisions issued by the UK Secretary of State or European Commission regarding the recipient country where such decisions are in effect at the time of transfer.
(c) Supplementary Measures: In addition to Standard Contractual Clauses, Prodactive Labs shall implement supplementary technical and organisational measures to ensure adequate protection for transferred Personal Data, including: Smarthub’s transient processing architecture minimising data retention; encryption of Personal Data in transit and at rest; Container isolation; access controls and multi-factor authentication; immediate deletion of Customer Data from Containers; and contractual commitments from Sub-processors regarding legal obligations and transparency regarding government access requests (to extent permitted by law).
12.3 Information and Monitoring:
Upon Customer’s reasonable request, Prodactive Labs shall provide: (a) copies of Standard Contractual Clauses or transfer mechanisms; (b) information about supplementary measures; (c) information about Sub-processor locations and safeguards; and (d) reasonable assistance to enable Customer to provide transparency to Data Subjects under Articles 13 and 14 of the UK GDPR. Prodactive Labs shall monitor legal developments relating to international transfers and shall notify Customer and work in good faith to implement alternative mechanisms if any development materially affects transfer lawfulness.
- TERM AND TERMINATION
13.1 This DPA shall commence on the Effective Date and remain in effect for so long as Prodactive Labs Processes Personal Data on behalf of Customer, including during retention periods specified in the Agreement.
13.2 This DPA shall terminate automatically upon termination or expiry of the Agreement, subject to survival of the following provisions: Clause 10 (Deletion or Return); Clause 12 (International Data Transfers, to extent necessary for ongoing transfers); and any other provisions which by their nature are intended to survive.
- GENERAL PROVISIONS
14.1 Order of Precedence:
In the event of any conflict or inconsistency between this DPA and the Agreement, this DPA shall prevail with respect to the Processing of Personal Data within Customer Data.
14.2 Amendments for Compliance:
If changes to Data Protection Laws require amendments to this DPA, the parties shall negotiate such amendments in good faith. Prodactive Labs may make unilateral amendments if reasonably necessary to comply with Data Protection Laws, provided such amendments do not materially reduce Customer’s rights or materially increase Customer’s obligations. Prodactive Labs shall provide Customer with reasonable notice of any such amendments.
14.3 Liability:
Each party’s liability under this DPA shall be subject to the limitations and exclusions set out in Clause 11 of the Agreement, except to the extent prohibited by Data Protection Laws.
14.4 Governing Law and Jurisdiction:
This DPA shall be governed by the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction over disputes arising from this DPA.
14.5 Severability:
If any provision of this DPA is held invalid, illegal, or unenforceable, the remaining provisions shall remain in full force and effect, and the invalid provision shall be deemed modified to the minimum extent necessary to make it valid and enforceable while preserving its intent.
—
Version 1.0
Effective Date: 4/11/2025
Last Updated: 4/11/2025
IMPORTANT: This DPA forms part of the Smarthub End User Licence Agreement. For information about how Prodactive Labs processes Account Data as a Controller, please see our Privacy Policy at https://www.getprodactive.com/legal/data-privacy/.