Data Processing Addendum
Last updated August 1, 2026 · ManageYourProject, operating manageyourproject.net
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Controller") and ManageYourProject ("Processor") and applies where we process personal data on your behalf. It is accepted automatically when you accept the Terms; a countersigned copy is available on request.
1. Subject matter and duration
The Processor processes personal data contained in Customer Data solely to provide the Service, for the term of the subscription plus the retention periods stated in the Privacy Policy.
2. Nature and purpose
Hosting, storage, transmission, display, backup, search indexing, notification delivery, and — where enabled — AI-assisted generation, all performed on the documented instructions of the Controller.
3. Categories of data subject and data
Data subjects: the Controller's employees, contractors, clients and other collaborators. Data: identifiers (name, email, avatar), workspace role, work content authored by them, time records, and technical metadata (IP address, user agent, timestamps).
4. Processor obligations
- Process only on documented instructions, and inform the Controller if an instruction appears unlawful.
- Impose confidentiality on all personnel with access.
- Implement the technical and organisational measures described in Annex A below.
- Assist with data subject requests, impact assessments and regulator engagement.
- Notify the Controller without undue delay, and in any event within 48 hours, of a personal data breach, with the information needed for the Controller's own notification duties.
- Delete or return personal data at the end of processing, except where retention is legally required.
- Make available the information needed to demonstrate compliance and permit audits no more than once a year, on 30 days' notice, subject to confidentiality — or provide a completed questionnaire in lieu.
5. Sub-processing
The Controller grants general authorisation for the sub-processors listed here. The Processor gives 30 days' notice of additions and remains liable for their performance. If the Controller reasonably objects, it may terminate the affected service without penalty for the unused period.
6. International transfers
Where personal data leaves the EEA, UK or Switzerland, the parties incorporate the EU Standard Contractual Clauses (Module Two, Controller-to-Processor) and the UK International Data Transfer Addendum by reference, with the Processor as data importer. Docking clause: optional. Governing law and forum: Ireland, unless the Controller is established in the UK, in which case England and Wales.
Annex A — technical and organisational measures
- Encryption: TLS 1.3 in transit; AES-256 at rest for database and object storage.
- Access control: unique accounts, least privilege, mandatory two-factor authentication for staff, quarterly access reviews, immediate revocation on offboarding.
- Tenant isolation: every query is scoped by organisation and workspace identifier and enforced in the application layer, with automated tests for cross-tenant access.
- Logging: audit trail of authentication, permission and configuration changes, retained 12 months.
- Resilience: daily encrypted backups, 30-day retention, point-in-time recovery, restore tested quarterly.
- Development: peer-reviewed changes, dependency vulnerability scanning, static analysis in CI, separate production credentials.
- Vendor management: DPA and security review before onboarding any sub-processor.
Questions about this document: [email protected]. Prior versions are available on request.