Work-A-Beez Data Processing Addendum
How Linton Business Solutions LLC processes Customer Personal Data on behalf of Work-A-Beez customers.
This Data Processing Addendum ("DPA") forms part of the Work-A-Beez agreement between Linton Business Solutions LLC ("LBS" or "Processor") and the subscribing customer ("Customer" or "Controller").
1. Scope and Roles
Customer determines the purposes and essential means of processing Customer Personal Data. LBS processes Customer Personal Data to provide Work-A-Beez, follow documented instructions, secure and support the service, and comply with law.
For information LBS uses independently for billing, account security, business administration, and direct customer relationships, LBS may act as an independent controller.
2. Processing Details
Subject Matter
Hosting and operating workforce-management software.
Duration
The subscription term plus documented export, deletion, backup, dispute, and legal-retention periods.
Nature and Purpose
Collection, recording, organization, storage, retrieval, access, calculation, display, transmission, reporting, backup, support, security monitoring, deletion, and related processing necessary to provide the service.
Data Subjects
Customer employees, contractors, applicants where enabled, administrators, managers, payroll or HR users, and other authorized users.
Data Categories
- names and contact details;
- employee or contractor identifiers;
- job title, department, manager, location, and status;
- schedules and availability;
- clock-in, clock-out, break, timecard, attendance, and punctuality records;
- PTO and leave requests;
- pay rate, payroll-related calculations, deductions or pay-summary information entered by Customer;
- messages, announcements, recognition, performance, and workflow records;
- device, IP, login, audit, and security records;
- support communications.
Sensitive Data
The service is not designed to require Social Security numbers, financial-account credentials, medical records, biometric identifiers, or precise geolocation unless LBS expressly documents and enables a feature after legal review. Customer must not upload unnecessary sensitive data.
3. Customer Instructions
LBS will process Customer Personal Data only on documented instructions, including the agreement, Customer configuration, support requests, and lawful use of service features.
If LBS believes an instruction violates law, it may notify Customer and suspend the affected processing where legally permitted.
4. Customer Obligations
Customer represents that it:
- has a lawful basis and authority for processing;
- has provided required notices;
- has obtained required consent;
- will not use the service unlawfully;
- will respond to worker and regulator requests;
- will configure retention and access appropriately;
- will not instruct LBS to process prohibited data.
5. Confidentiality
Personnel authorized to process Customer Personal Data will be subject to confidentiality obligations.
6. Security
LBS will maintain reasonable technical and organizational measures designed to protect confidentiality, integrity, and availability. Measures may include:
- access controls and least privilege;
- secure authentication;
- encryption in transit;
- encryption at rest where appropriate;
- tenant isolation;
- logging and monitoring;
- backups and recovery procedures;
- change and vulnerability management;
- incident response;
- personnel and vendor controls.
7. Subprocessors
Customer authorizes LBS to use subprocessors listed in the Subprocessor and Security Disclosure.
LBS will impose data-protection obligations appropriate to the service. LBS remains responsible for subprocessor performance to the extent required by applicable law and contract.
LBS will provide reasonable notice of a new subprocessor that materially processes Customer Personal Data. Customer may object on reasonable data-protection grounds. The parties will work in good faith; if no reasonable solution exists, Customer may terminate the affected service.
8. Data Subject Requests
Taking into account the nature of processing, LBS will reasonably assist Customer with requests to access, correct, delete, or obtain Customer Personal Data. LBS may direct an employee requester to Customer.
9. Security Incidents
LBS will notify Customer without undue delay after confirming a breach of Customer Personal Data for which notice is required under the agreement or applicable law.
Notice may include, as information becomes available:
- nature of the incident;
- affected systems and data;
- likely consequences;
- containment and remediation;
- contact information.
LBS's notice is not an admission of fault or liability.
10. Assistance
LBS will provide reasonable information to assist Customer with security, breach, privacy-impact, and regulatory obligations appropriate to the processing. Extraordinary assistance may be chargeable if not caused by LBS's breach.
11. Return and Deletion
On termination and written request made before the deletion deadline, LBS will make supported exports available. LBS will then delete or deidentify Customer Personal Data, except information required by law or retained in protected backups until overwritten.
12. Audits
LBS will provide available security and compliance information reasonably necessary to demonstrate DPA compliance.
No more than once annually, unless required by a regulator or material incident, Customer may request a reasonable audit. Audits must protect other customers, security information, and LBS confidentiality; avoid production disruption; and use qualified independent auditors.
Customer bears audit costs unless material noncompliance is found.
13. International Transfers
If Customer Personal Data is transferred across borders and a legally required transfer mechanism applies, the parties will execute the appropriate mechanism.
14. U.S. State Privacy Terms
Where a U.S. state privacy law applies and Customer is a controller or business:
- LBS will process data only for specified business purposes;
- LBS will not sell Customer Personal Data;
- LBS will not retain, use, or disclose it outside the business relationship except as permitted;
- LBS will assist Customer with applicable requests;
- LBS will impose appropriate terms on subprocessors;
- Customer may take reasonable steps to verify compliance.
15. Conflict
This DPA controls over conflicting general terms solely for personal-data processing.
16. Contact
Linton Business Solutions LLC
616 FM 1960 Road West, Suite 101
Houston, Texas 77090-3048
Phone: (281) 836-5357
Email: info@lbsconnect.net