Data Processing Addendum
Applies where HarmonyWFM processes personal data on a customer's behalf. Incorporated by reference into every HarmonyWFM Service Agreement; countersigned copies are available on request.
Last updated: August 16, 2026
1. Roles and scope
The customer is the controller (or, where applicable, processor) of personal data in its workspace. HarmonyWFM ("HarmonyWFM", the "Provider") is the processor and processes that data only to provide the service and on the customer's documented instructions, including instructions given through platform configuration. This addendum forms part of the Service Agreement between HarmonyWFM and the customer.
2. Nature of processing
- Subject matter: provision of workforce management software.
- Duration: the term of the subscription plus the deletion window below.
- Data subjects: the customer's employees, managers, administrators, and applicants or candidates it onboards.
- Data types: identity and contact details, employment and organizational details, working-time and absence records, compensation configuration the customer enters, documents and attachments it uploads.
3. Confidentiality and personnel
Personnel with access to customer data are bound by confidentiality obligations and receive access only where needed to operate or support the service.
4. Security measures
We maintain the technical and organizational measures described on the Security page, including row-level tenant isolation in the database, role-based access control, encryption in transit, and audit logging of privileged actions. Measures may be updated, but not in a way that materially reduces protection.
5. Subprocessors
The customer authorizes the subprocessors listed on the Subprocessors page. We impose data protection obligations on each subprocessor equivalent to those in this addendum and remain responsible for their performance. We will give notice before adding a new subprocessor so the customer can object on reasonable data-protection grounds.
6. Data subject requests
The platform lets administrators access, correct, export, and delete records directly. Where a data subject contacts us instead, we forward the request to the customer and assist as reasonably needed.
7. Incident notification
We will notify the customer's administrative contacts without undue delay after becoming aware of a personal data breach affecting their workspace, with the information we have at the time and updates as the investigation progresses.
8. Return and deletion
Customers can export data at any time during the subscription. After termination, data remains available for export for 30 days, after which it is deleted from active systems in the ordinary course, with backup copies aging out on their normal cycle.
9. Hosting location and international transfers
Customer workspace data is stored in Canada (AWS ca-central-1) on managed Postgres infrastructure. Supporting providers listed on the Subprocessors page may process limited data in the United States. Where personal data is transferred out of its region, we rely on an approved transfer mechanism such as the EU Standard Contractual Clauses, incorporated by reference into this addendum.
10. Audits
On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide the information reasonably necessary to demonstrate compliance with this addendum.
11. Contact
To request a countersigned DPA, email admin@harmonywfm.com.