Data Processing Addendum
Draft safeguards for personal information in company workspaces.
Updated October 7, 2026. This notice describes the current website and Pinheads pilot. Commercial customer agreements are being prepared. Contact Bondidos Support for questions about the operating company or your data.
Roles & Instructions
The order must identify the company’s role and the provider’s role for each processing activity. Where the provider acts as processor, it processes personal data only on documented company instructions and only to provide the agreed service, subject to applicable law.
Processing Schedule
Complete a schedule of purposes, duration, data categories, individuals concerned, processing locations, and authorized integrations. Potential workspace information includes employee identifiers and guest or event details; collect only what the selected feature requires. Sensitive categories require a separate suitability assessment.
Safeguards & Confidentiality
The executed addendum must describe access controls, confidentiality duties, secure transfer and storage, backup practices, isolation between companies, logging, and vulnerability or incident processes. These controls must be verified operationally rather than inferred from this template.
Providers & Transfers
Maintain a verified subprocessor schedule with services and locations, notification and objection terms, and required contractual protections. Any cross-border transfer needs the applicable legal mechanism. This draft does not execute standard contractual clauses or certify a transfer framework.
Requests, Incidents & Assistance
Agree a procedure for assisting with data-subject requests, incident notification without undue delay, assessments, and regulatory inquiries. Exact notification contacts, timelines, responsibilities, and supporting evidence must be finalized before processing customer data.
Return, Deletion & Assurance
Define export and deletion instructions, retention exceptions, backup expiry, and a proportionate assurance or audit process. Records should not be retained indefinitely without a documented reason. This preview does not provide a certification or independent audit report.
Contact
For privacy questions, data requests, or agreement questions, contact [email protected]. Do not send passwords, payment-card details, or sensitive guest information by email.
