About this addendum
- This DPA is part of the FabCommand Terms of Service. It applies automatically wherever FabCommand processes personal data in Customer Data on your behalf. There's nothing to sign.
- If your organization needs a countersigned copy for its records, email contact@fabcommand.com.
1. Definitions and Scope
Capitalized terms not defined here have the meanings given in the Terms of Service ("Terms").
- Data Protection Laws means all privacy and data protection laws that apply to the processing of Customer Personal Data under the Terms. These include, where applicable: the EU General Data Protection Regulation 2016/679 ("GDPR"); the UK GDPR and Data Protection Act 2018; the Swiss Federal Act on Data Protection; the California Consumer Privacy Act as amended ("CCPA") and other U.S. state privacy laws; Canada's PIPEDA; and similar laws elsewhere.
- Customer Personal Data means personal data in Customer Data that FabCommand processes on Customer's behalf.
- Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- "Controller", "processor", "data subject", "personal data", "processing", "service provider", and "supervisory authority" have the meanings given in Data Protection Laws.
2. Roles and Instructions
- Customer is the controller, or a processor acting for its own controller, of Customer Personal Data. FabCommand is a processor, or subprocessor, and a "service provider" under the CCPA.
- FabCommand will process Customer Personal Data only on Customer's documented instructions, unless the law requires otherwise. If the law requires otherwise, FabCommand will tell Customer before processing unless the law prohibits that. The Terms, this DPA, and Customer's use and configuration of the Services are Customer's complete instructions. Additional instructions require written agreement.
- FabCommand will tell Customer if, in its opinion, an instruction infringes Data Protection Laws.
- Customer is responsible for the lawfulness of its instructions. It is also responsible for having a lawful basis, and giving any required notices, for the Customer Personal Data it provides, including notices to its own employees.
3. U.S. State Privacy Law Terms
With respect to Customer Personal Data, FabCommand will not:
- sell or share it, as those terms are defined in the CCPA;
- retain, use, or disclose it for any purpose other than the business purposes set out in the Terms and this DPA, including for any other commercial purpose;
- retain, use, or disclose it outside the direct business relationship with Customer; or
- combine it with personal data from other sources, except as Data Protection Laws permit for service providers.
FabCommand will comply with applicable obligations under the CCPA and will give the same level of privacy protection it requires. It will notify Customer if it can no longer meet its obligations. Customer may take reasonable steps to stop and remediate unauthorized use. FabCommand certifies that it understands these restrictions.
4. Personnel
FabCommand will ensure that anyone it authorizes to process Customer Personal Data is bound by confidentiality obligations and accesses the data only as needed to provide the Services.
5. Security
FabCommand will maintain appropriate technical and organizational measures to protect Customer Personal Data, taking into account the state of the art, the costs of implementation, the nature and purposes of processing, and the risks to data subjects. The measures in Annex II are the baseline. FabCommand may update them, as long as the overall level of protection is not materially reduced.
6. Subprocessors
- Customer gives FabCommand general authorization to engage subprocessors. FabCommand uses subprocessors in these categories: cloud hosting and database infrastructure, file storage, payment processing, transactional email delivery, business email and calendar, sign-in, and bot and spam protection. FabCommand will give Customer the current list of subprocessors, with each one's function and location, on request to contact@fabcommand.com. Customer approves the subprocessors in use on the date it accepts the Terms.
- FabCommand will impose data protection obligations on each subprocessor by written contract, at least as protective as this DPA. FabCommand remains responsible for its subprocessors' performance.
- FabCommand will give at least 15 days' notice before a new subprocessor processes Customer Personal Data. It will do so by email to customers who have asked to receive subprocessor notices at the address above.
- Customer may object on reasonable data protection grounds within that period. The parties will discuss the objection in good faith. If it is not resolved, Customer may terminate the affected Services and receive a refund of prepaid fees for the unused period.
7. Data Subject Requests and Assistance
- The Services let Customer's administrators access, correct, export, and delete Customer Personal Data. Customer uses these tools to respond to data subject requests.
- If FabCommand receives a request directly from a data subject about Customer Personal Data, it will direct the person to Customer and will not respond itself, except to confirm that it has passed the request on. Where the law requires, it will also notify Customer.
- FabCommand will provide reasonable assistance, taking into account the nature of the processing and the information available to it, with:
- data subject requests;
- data protection impact assessments;
- prior consultations with supervisory authorities; and
- Customer's security obligations.
8. Security Incidents
FabCommand will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident. The notice will go to Customer's account owner or administrators.
As information becomes available, FabCommand will provide:
- the nature of the incident;
- the categories and approximate number of data subjects and records affected;
- its likely consequences;
- the measures taken or proposed to address it; and
- a contact point.
FabCommand will take reasonable steps to contain and remediate the incident. Notifying Customer is not an admission of fault or liability.
9. Return and Deletion
During the Terms and for 30 days afterward, Customer may export Customer Personal Data. After that, FabCommand will delete Customer Personal Data from the live Services, and backup copies will be overwritten within a further 35 days. Customer may also request earlier deletion.
FabCommand may keep data where the law requires it. Any data it keeps remains protected by this DPA and is processed only for the purpose the law requires.
10. Audits
On written request, FabCommand will give Customer information reasonably needed to show compliance with this DPA. This will include written responses to reasonable security questionnaires, and summaries of any third-party audit reports it holds, including those of its hosting providers.
If that information is not enough to meet Customer's obligations under Data Protection Laws, or a supervisory authority requires it, Customer may conduct an audit, directly or through an independent auditor bound by confidentiality, subject to these conditions:
- no more than once in any 12-month period, unless a Security Incident has occurred;
- on at least 30 days' notice;
- during normal business hours, without unreasonably disrupting FabCommand's operations; and
- at Customer's expense.
11. International Transfers
Customer authorizes FabCommand and its subprocessors to transfer Customer Personal Data to the United States and to other countries where they operate, in compliance with this section.
EEA transfers
Where Customer Personal Data subject to the GDPR is transferred to a country that has no adequacy decision, the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 ("SCCs") are incorporated into this DPA by reference, as follows:
- Module Two (controller to processor) applies where Customer is a controller. Module Three (processor to processor) applies where Customer is a processor.
- In Clause 7, the optional docking clause applies.
- In Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 6 of this DPA.
- In Clause 11, the optional language does not apply.
- In Clause 13, the supervisory authority is the one competent for Customer, as determined by Clause 13.
- In Clauses 17 and 18, the SCCs are governed by the laws of Ireland, and disputes are resolved by the courts of Ireland.
- Annexes I and II of the SCCs are completed by Annex I and Annex II of this DPA. Annex III is FabCommand's list of subprocessors, available to Customer on request under Section 6.
UK transfers
For Customer Personal Data subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner (version B1.0), is incorporated by reference. Table 1 is completed with the parties' details in Annex I. Tables 2 and 3 are completed by the SCC selections above. In Table 4, either party may end the Addendum as set out in Section 19 of the Addendum.
Swiss transfers
For Customer Personal Data subject to Swiss law, the SCCs apply with these adjustments:
- references to the GDPR are read as references to the Swiss Federal Act on Data Protection;
- the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and
- "Member State" includes Switzerland, so data subjects there can enforce their rights.
If the SCCs conflict with this DPA or the Terms, the SCCs prevail.
12. General
- This DPA remains in effect for as long as FabCommand processes Customer Personal Data.
- Each party's liability under this DPA is subject to the limitations of liability in the Terms, except where Data Protection Laws or the SCCs do not allow those limitations.
- If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails.
- FabCommand may update this DPA as Data Protection Laws or its subprocessors change. An update will not materially reduce the protection given to Customer Personal Data without Customer's agreement.
Annex I: Details of Processing
| Data exporter | The Customer that accepted the Terms, as identified in its FabCommand account. Contact: the account owner. Role: controller, or processor. Activities: use of the FabCommand Services. |
|---|---|
| Data importer | FabCommand, Inc., 119 N. Wayne St., Ste. C, Milledgeville, GA 31061, United States. Contact: contact@fabcommand.com. Role: processor, or subprocessor. Activities: providing the FabCommand Services. |
| Categories of data subjects | Customer's employees, contractors, and other Authorized Users. Customer's customers, general contractors, vendors, and other business contacts whose details Customer enters. |
| Categories of personal data | Names, business contact details, job titles and roles, login credentials (hashed), user IDs, time, attendance, and task records, work assignments, notes and comments, profile photos, IP addresses, and usage logs. Any other personal data Customer chooses to include in project files, drawings, or documents. |
| Sensitive data | None intended. Customer agrees not to upload special categories of data. |
| Frequency | Continuous, for as long as Customer uses the Services. |
| Nature and purpose | Hosting, storage, retrieval, organization, display, transmission, backup, and deletion, to provide the Services to Customer under the Terms, and for support and security. |
| Duration and retention | For the term of the Terms, plus the export and deletion periods in Section 9. |
| Transfers to subprocessors | To the subprocessors on FabCommand's list (available on request under Section 6), for the functions stated there, for the duration above. |
Annex II: Technical and Organizational Security Measures
- Encryption: all traffic to the Services uses TLS (HTTPS). Data at rest in our database and file storage is encrypted by our cloud infrastructure provider.
- Credentials: passwords and station PINs are stored only as salted one-way hashes. Failed-login lockouts and rate limiting protect sign-in and public forms, and bot protection guards registration and support forms.
- Tenant isolation: each company's data is scoped to that company. Access checks are enforced on the server for every request, and cross-company access happens only through sharing the customer controls.
- Access control: role-based permissions within each company, managed by the customer's owners and administrators. FabCommand staff access to production systems is limited to those who need it, and uses individual accounts.
- Sessions: signed session cookies, set to secure (HTTPS-only) in production, with a limited lifetime.
- Infrastructure: hosted with major cloud providers, whose physical and environmental controls are independently audited.
- Backups and resilience: regular automated database backups, and the ability to restore.
- Logging and monitoring: application and access logging to detect and investigate errors and misuse.
- Secure development: changes are tested before deployment, and secrets are kept out of source code and supplied through the environment.
- Incident response: a defined process to investigate, contain, and notify, consistent with Section 8.
- Subprocessor management: written data protection terms with each subprocessor on the Annex III list.