Data Processing Addendum
Last updated: July 2026 (draft)
This Data Processing Addendum (“DPA”) describes how The Workaround Collective (the “Collective”) processes personal data and the providers it relies on. For personal data about our members, the Collective is the data controller and our Privacy Policy governs. This DPA additionally sets out the Article 28 (GDPR) terms that apply where the Collective processes personal data on behalf of another party (a “Controller”) — for example a partner organization — and lists our sub-processors.
1. Subject matter & roles
This processor role applies only where a separate organization — for example a partner or an employer running a program with us — engages the Collective to process personal data on their behalf. It does not apply to our members or content creators: for their personal data the Collective is the controller (see the Privacy Policy). Where the Collective does process personal data on a Controller’s documented instructions, the Collective acts as processor and the other party as controller. The subject matter is the provision of the agreed services; the duration is the term of the underlying agreement plus any legally required retention.
2. Nature, purpose, data & subjects
- Nature/purpose: hosting, storing, and processing personal data to provide the services.
- Data subjects: the Controller’s members, contacts, or end users.
- Categories of data: identity and contact details, profile and account data, and content submitted through the services. No special-category data is intended.
3. Processor obligations
- Process personal data only on the Controller’s documented instructions, including for transfers, unless required by law (in which case we’ll inform the Controller where permitted).
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (Art. 32) — see §4.
- Assist the Controller, insofar as possible, in responding to data-subject requests and in meeting its security, breach-notification, and DPIA obligations (Arts. 32–36).
- Notify the Controller without undue delay after becoming aware of a personal-data breach.
- At the Controller’s choice, delete or return personal data at the end of the services, except where retention is legally required.
- Make available information necessary to demonstrate compliance and allow for and contribute to audits.
4. Security measures
We apply measures appropriate to the risk, including: hashed passwords; access controls and least-privilege; encryption in transit; an append-only audit log of administrative actions; data minimization and pseudonymization where practical; and a documented deletion/retention process. Measures are reviewed as the platform matures.
5. Sub-processors
The Controller provides general authorization for the Collective to engage the sub-processors listed below to deliver the services. We impose data-protection obligations on each sub-processor equivalent to those in this DPA, and remain responsible for their performance. We will give notice before adding or replacing a sub-processor so the Controller can object on reasonable data-protection grounds.
Current sub-processors (categories):
- Cloud hosting & database — runs the application and stores data. Providers: Vercel (application hosting & CDN) and Neon (managed PostgreSQL), both serving/storing data in the EU (Frankfurt) under EU SCCs.
- Transactional email — verification, reset, and notification emails. Provider: Microsoft 365 (SMTP mailbox), a Microsoft Corporation service; the mailbox is purchased and administered through GoDaddy (reseller), which therefore has administrative access to it. Microsoft is a US company; transfers rely on EU SCCs, and on the EU-US Data Privacy Framework (under which Microsoft is certified) as an additional basis.
- Video conferencing — one-to-one call rooms for booked sessions. Provider: Whereby (EEA-based, Norway), which processes call media to connect the session.
- Payments & payouts (planned) — creator sessions and payouts. Provider: Stripe, including Stripe Connect for creator payouts and KYC.
The named, current list is maintained on our Sub-processors page and updated as providers are onboarded.
6. International transfers
The Collective is administered from Germany and serves US members, so processing may occur in the US and elsewhere. Where personal data is transferred out of the EEA/UK, we rely primarily on the European Commission’s Standard Contractual Clauses, with supplementary technical and organizational measures where needed. For providers that are certified under the EU-US Data Privacy Framework, we may also rely on that Framework as an additional basis; because its long-term status is subject to ongoing legal challenge, the Standard Contractual Clauses remain our primary safeguard. We require sub-processors to provide equivalent protection.
7. Term & contact
This DPA remains in effect for as long as the Collective processes personal data on a Controller’s behalf. Questions or to request the applicable transfer safeguards: contact us here. See also our Legal Notice (Impressum).