Data Processing Addendum
Effective date: July 27, 2026 · Last updated: July 27, 2026
Contents
- Definitions
- Scope, roles & precedence
- Processing & documented instructions
- Confidentiality of personnel
- Security measures
- Subprocessors
- Assistance with individuals' requests
- Security incident notification
- Assessments, audits & information rights
- International transfers
- Return & deletion
- US state privacy laws (CCPA)
- Liability, term & general
- Annex I — Details of processing
- Annex II — Technical & organizational measures
- Annex III — Subprocessors
1. Definitions
Capitalized terms not defined here have the meaning given in the Terms of Service (the "Agreement"). "Pishik" means Pishik Labs, the operator of the Service. "Customer Personal Information" means personal information, personal data, or personally identifiable information within Customer Data that Pishik processes on Customer's behalf under the Agreement — principally reviewer records and the personal details of Customer's own workspace members. "Data Protection Law" means any law applicable to the processing of Customer Personal Information, including the California Consumer Privacy Act as amended (the "CCPA") and its regulations, and the EU and UK General Data Protection Regulation (the "GDPR"). "Business," "Service Provider," "sell," "share," and "consumer" have the meanings given in Cal. Civ. Code § 1798.140. "Controller," "Processor," "data subject," and "personal data breach" have the meanings given in the GDPR. "Subprocessor" means a third party engaged by Pishik to process Customer Personal Information. "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Information.
2. Scope, roles & precedence
Roles. With respect to Customer Personal Information, Customer is the Business and Controller, and Pishik is the Service Provider and Processor. Pishik processes Customer Personal Information solely on Customer's behalf and pursuant to this Addendum. This Addendum is a written contract for the purposes of Cal. Civ. Code § 1798.100(d) and § 1798.140(ag)(1), of 11 CCR § 7051, and of Article 28 GDPR, and is entered into in writing, including in electronic form. Acceptance of the Agreement constitutes acceptance of this Addendum.
What this Addendum does not cover. This Addendum applies only to Customer Personal Information that Pishik processes on Customer's behalf. It does not apply to personal information Pishik processes as a business or controller in its own right — including account registration details of Customer's administrators, billing and subscription records, support correspondence with us, and visitors to our marketing site. That processing is governed by our Privacy Policy. Keeping this line clear matters: it is what stops our own records from being mischaracterized, and yours from being treated as ours.
Not a sale or a share. Pishik is not a Third Party with respect to Customer Personal Information. We do not receive it for our own purposes, we provide no cross-context behavioural advertising, and we receive no monetary or other valuable consideration in exchange for personal information. Customer's disclosure of Customer Personal Information to Pishik is neither a sale nor a share.
Precedence. In the event of a conflict concerning the processing of personal data, the Standard Contractual Clauses referred to in Section 10 prevail over this Addendum, and this Addendum prevails over the remainder of the Agreement. Everything else in the Agreement continues to apply.
Severability with intent. If any provision of this Addendum is held unenforceable, the parties will substitute a valid provision that most nearly achieves the same effect, it being the parties' express intention that Pishik qualify at all times as a Service Provider under Cal. Civ. Code § 1798.140(ag) and as a Processor under Article 28 GDPR.
3. Processing & documented instructions
Limited and specified purposes. Customer discloses Customer Personal Information to Pishik only for, and Pishik processes it only for, the following business purposes:
- creating and maintaining reviewer records — name, business email address, and any title, department, or note Customer adds — within Customer's workspace;
- routing contracts through the review stages Customer defines, issuing single-use review links, and recording reviewer decisions and the notes reviewers write;
- storing the contract records Customer's users create — titles, types, counterparties, notes, to-dos, and reminders — and share links to documents held in Customer's own storage, together with the associated workflow state, comments, @mentions, delegations, reassignments, and audit trail;
- generating and transmitting review-request, reminder, and notification email through the delivery channel Customer configures, and recording what was sent and whether it arrived;
- authenticating Customer's users, enforcing mandatory two-factor authentication, and managing sessions;
- providing technical support at Customer's request;
- administering Customer's subscription and seats; and
- securing the Service — detecting, preventing, and investigating security incidents and fraudulent, malicious, or unlawful activity — and maintaining backups and disaster recovery.
Documented instructions. Pishik processes Customer Personal Information only on Customer's documented instructions, including as to any transfer to a third country, unless required to do otherwise by law to which Pishik is subject; in that case Pishik will inform Customer of the legal requirement before processing, unless the law prohibits that on important grounds of public interest. The Agreement, this Addendum, and Customer's use and configuration of the Service together constitute Customer's documented instructions.
Restrictions. Pishik will not:
- sell or share Customer Personal Information;
- retain, use, or disclose it for any purpose other than the business purposes listed above, including for any commercial purpose other than those purposes, except as Data Protection Law expressly permits;
- retain, use, or disclose it outside the direct business relationship between Pishik and Customer;
- use it to perform services on behalf of any other person, or disclose it to anyone other than Customer, Customer's authorized users, and Subprocessors engaged under Section 6; or
- combine or update it with personal information received from or on behalf of anyone else, or collected from Pishik's own interaction with any individual, except to perform a business purpose that Data Protection Law permits. Pishik does not enrich, append, or cross-reference Customer Personal Information against any external data source, data broker, or advertising identifier.
Proportionality. Pishik's retention, use, and disclosure of Customer Personal Information is limited to what is reasonably necessary and proportionate to achieve the purposes set out above.
No AI training. Pishik may use Customer Personal Information for its internal use to build and improve the quality of the Service, and will not use it to perform services on behalf of any other person. For the avoidance of doubt, and as a binding commitment rather than a marketing claim: Pishik does not use Customer Personal Information, Customer Data, share links, document contents, or workflow metadata to train, fine-tune, or evaluate any machine-learning or artificial-intelligence model, whether its own or a third party's, and discloses none of it to any AI provider. Pishik employs no automated decisionmaking technology and makes no significant decision about any individual.
Unlawful instructions. Pishik will immediately inform Customer if, in its opinion, an instruction from Customer infringes Data Protection Law, and may suspend performance of that instruction until it is confirmed or withdrawn.
Government and law-enforcement requests. If Pishik receives a legally binding demand for Customer Personal Information, it will notify Customer before disclosing unless legally prohibited, will seek to redirect the requesting party to Customer, will challenge demands that are overbroad or unlawful, and will disclose only the minimum the demand requires.
Each party's own compliance. Each party is responsible for its own compliance with Data Protection Law. Pishik is not responsible for Customer's obligations as a Business or Controller — including giving notice at collection to reviewers, responding to requests directed to Customer, and maintaining Customer's own privacy notice. Customer warrants that it has given all notices and holds all rights and permissions necessary to disclose Customer Personal Information to Pishik for the purposes set out above.
4. Confidentiality of personnel
Pishik ensures that every person authorized to process Customer Personal Information is bound by a written obligation of confidentiality that survives the end of their engagement, and processes Customer Personal Information only on Customer's documented instructions. Access is granted on a least-privilege, need-to-know basis and withdrawn promptly on change of role or departure.
Pishik's own internal tooling is built to be metadata-only: the console our staff use to keep the Service running does not read the contents of your workspace — not document text, not contract titles, not parties, not comments. The exception is support: if you send us a message, we read what you wrote, so please keep confidential contract text out of support requests.
5. Security measures
Pishik implements and maintains reasonable security procedures and practices appropriate to the nature of Customer Personal Information, to protect it from unauthorized or unlawful access, destruction, use, modification, or disclosure, in accordance with Cal. Civ. Code § 1798.81.5 and Article 32 GDPR. Pishik provides sufficient guarantees to implement appropriate technical and organizational measures such that processing meets the requirements of Data Protection Law and protects the rights of data subjects. The measures in effect are described in Annex II. Pishik may update them provided the overall level of security is not materially reduced. Pishik regularly tests and evaluates their effectiveness.
6. Subprocessors
Authorization. Customer grants Pishik general written authorization to engage Subprocessors. Those currently engaged are listed in Annex III.
Notice and objection. Pishik will give Customer at least thirty (30) days' notice before adding or replacing a Subprocessor, by updating Annex III and by notifying each workspace owner by email and inside the app. Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith, Customer may terminate the affected Service without penalty and receive a pro-rata refund of prepaid fees for the unused remainder of the term — an exception to the no-refund provision of the Agreement.
Flow-down and liability. Pishik will engage a Subprocessor only under a written contract that complies with Data Protection Law — including 11 CCR § 7051(a) and Article 28(3) GDPR — and imposes obligations no less protective than those in this Addendum. Pishik will notify Customer of any Subprocessor engaged by a Subprocessor. Pishik remains fully liable to Customer for the acts and omissions of its Subprocessors.
Not Subprocessors. Services that Customer itself directs the Service to use are not Pishik's Subprocessors: Customer's own Microsoft 365 tenant, Customer's own SharePoint, OneDrive, or Google Drive, and any SMTP provider Customer designates. Customer's use of those services is governed by its own agreements with them.
7. Assistance with individuals' requests
Taking into account the nature of the processing, Pishik assists Customer by appropriate technical and organizational measures, insofar as possible, in meeting Customer's obligation to respond to requests from individuals — to know, access, correct, delete, port, restrict, object, opt out, or limit — under the CCPA, Chapter III GDPR, and other Data Protection Law. The Service's export, correction, and deletion functionality is provided for this purpose, and Pishik gives reasonable additional assistance at no charge where that functionality is insufficient.
If Pishik receives a request directly from an individual concerning Customer Personal Information, Pishik will not respond substantively. It will promptly refer the individual to Customer, tell them that the request must be directed to the organization that holds the record, and act only on Customer's documented instructions. Where Customer has notified Pishik of a valid deletion request, Pishik will delete the personal information from its systems and, on request, provide written confirmation that it and its Subprocessors no longer retain or use it.
8. Security incident notification
Pishik will notify Customer of a Security Incident affecting Customer Personal Information without undue delay and in any event within twenty-four (24) hours of becoming aware of it, and — consistent with Cal. Civ. Code § 1798.82(b) — immediately following discovery where Customer Personal Information was, or is reasonably believed to have been, acquired by an unauthorized person. Notice will describe, so far as known at the time: the nature of the incident, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed. Where the full picture is not yet available, Pishik will notify within the same period with what it knows and provide further detail in phases as the investigation proceeds.
Pishik maintains a documented incident-response process and will reasonably assist Customer in meeting Customer's own notification obligations to individuals and regulators. Pishik will not notify any regulator or individual on Customer's behalf without Customer's prior written instruction, except where the law requires Pishik to do so directly.
9. Assessments, audits & information rights
Verifying our compliance. Customer may take reasonable and appropriate steps to satisfy itself that Pishik uses Customer Personal Information consistently with Customer's own obligations. Pishik will make available all information reasonably necessary to demonstrate compliance with this Addendum, Article 28 GDPR, and 11 CCR § 7051. In the first instance Customer should request Pishik's then-current security documentation, its completed security questionnaire, and a written attestation of compliance, which Pishik will provide once per year at no charge and after any Security Incident affecting Customer Personal Information.
Audit. Where those materials are insufficient to demonstrate compliance, Customer may audit Pishik's processing of Customer Personal Information — no more than once in any twelve (12) month period, and additionally following a Security Incident or where a supervisory authority requires it — on thirty (30) days' written notice, during business hours, subject to reasonable confidentiality obligations, at Customer's cost, and conducted so as not to unreasonably disrupt Pishik's operations or compromise the confidentiality of other customers' data. Customer may appoint an independent auditor, who must not be a competitor of Pishik.
Assessments. Pishik will assist Customer in complying with Articles 32 to 36 GDPR, including by providing the information Customer reasonably needs to carry out a data protection impact assessment and, where required, to consult its supervisory authority. Where Customer is subject to the CCPA's cybersecurity-audit, risk-assessment, or automated-decisionmaking requirements, Pishik will make available to Customer and its auditor all relevant information in Pishik's possession, custody, or control that they request, and will not misrepresent any fact relevant to that audit or necessary to that assessment. Pishik uses no automated decisionmaking technology, which we state here so it can be relied on.
If we can no longer comply. Pishik will notify Customer in writing promptly, and in any event within five (5) business days, after determining that it can no longer meet its obligations under Data Protection Law or this Addendum — by email to the billing contact and by notice to workspace owners inside the app. On notice from Customer of any unauthorized use of Customer Personal Information, Customer may take reasonable and appropriate steps to stop and remediate it, including requiring Pishik to cease the processing identified, to delete or return the affected information, and to provide written verification that it has done so.
10. International transfers
Pishik operates the Service from the United States, and Customer Personal Information is stored and processed there.
Where Customer transfers Customer Personal Information from the European Economic Area, the United Kingdom, or Switzerland to Pishik and the destination lacks an adequacy decision, the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 are incorporated into this Addendum and apply to that transfer. Module Two applies where Customer is a controller and Module Three where Customer is a processor; Customer is the data exporter and Pishik the data importer. Clause 7 (docking) applies. Under Clause 9, Option 2 (general written authorization) applies with the thirty (30) days' notice period in Section 6. Under Clause 11, the optional independent dispute-resolution paragraph does not apply. Under Clause 17 the governing law is that of Ireland, and under Clause 18(b) the forum is the courts of Ireland. Annexes I, II, and III to this Addendum serve as the corresponding annexes to those Clauses. For transfers from the United Kingdom, the UK International Data Transfer Addendum (version B1.0) applies to the Standard Contractual Clauses; for transfers from Switzerland, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Federal Data Protection and Information Commissioner.
Pishik has assessed the risk of those transfers. The information involved is business-contact-level — names, work email addresses, job titles, and review decisions. It includes no special categories of data, no government identifiers, no financial account data, and no document contents, since contract files never leave Customer's own storage. Pishik has received no government request for Customer Personal Information and will report on that in the attestation described in Section 9.
11. Return & deletion
Customer may export a complete copy of its workspace at any time during the term, and for at least forty-five (45) days after the Agreement ends, using the Service's own export functionality — see Export and restore your data. No Customer workspace record — contracts and share links, reviewers, decisions, comments and their history — is deleted on a timer; that is a deliberate design decision so that an audit trail can be relied on. The exceptions are operational, and are set out here for accuracy: sign-in sessions and email verification codes are swept once they expire; payment-webhook replay markers are pruned after thirty (30) days; a workspace's audit trail is capped by volume rather than by age, so the oldest routine entries are evicted once that cap is reached; and operational copies age out as described below.
At Customer's election, made at any time during the term or after it, Pishik will delete or return all Customer Personal Information and delete existing copies, except where the law requires it to be kept. Pishik will action a verified deletion request within thirty (30) days and will confirm in writing when it is done. Pishik takes periodic operational copies of the database for disaster recovery; each copy supersedes the one before it, so a copy taken before a deletion persists only until the next is taken, and it remains subject to this Addendum while it does.
What we keep, and why. Erasing a workspace removes its accounts, sessions, contracts and share links, reviewers and their decisions, comments and their history, @mentions, delegations, reassignments, notifications, and audit history. Pishik retains its own business records — support tickets and their messages, internal account notes, trial-code redemption records, and the subscription event timeline — together with a single log entry recording that the erasure took place. Those are Pishik's records rather than Customer Personal Information processed on Customer's behalf, and Pishik keeps them for legal, tax, accounting, and security purposes. Customer may ask for them too, and Pishik will remove what the law permits it to remove.
Absent an election. If Customer makes no election, Pishik retains Customer Personal Information in accordance with the retention section of the Privacy Policy until Customer requests deletion. We would rather say that plainly than promise an automatic erasure we do not perform.
12. US state privacy laws
This section applies where Customer is subject to the CCPA. Customer is the Business; Pishik is the Service Provider. The commitments in Sections 3 to 11 are given as the terms required by Cal. Civ. Code § 1798.100(d) and § 1798.140(ag)(1) and by 11 CCR § 7051(a), and in particular Pishik:
- will not sell or share Customer Personal Information;
- processes it only for the limited and specified business purposes set out in Section 3, and Customer discloses it for no other purpose;
- will not retain, use, or disclose it for any purpose — including any commercial purpose — other than those business purposes, except as the CCPA permits;
- will not retain, use, or disclose it outside the direct business relationship between the parties;
- will not combine it with personal information from another source except as the CCPA permits;
- will comply with the applicable provisions of the CCPA and its regulations and provide the same level of privacy protection that the CCPA requires of a Business, including maintaining reasonable security under Cal. Civ. Code § 1798.81.5 and assisting Customer with its cybersecurity-audit, risk-assessment, and automated-decisionmaking obligations;
- grants Customer the rights in Section 9 to take reasonable and appropriate steps to ensure that Pishik's use is consistent with Customer's obligations, and to stop and remediate any unauthorized use;
- will notify Customer after determining that it can no longer meet its obligations; and
- enables Customer to comply with requests from consumers, as set out in Section 7.
Certification. Pishik certifies that it understands the restrictions set out in this Section and in Section 3, and will comply with them.
Where Customer is subject to another US state privacy law, Pishik acts as a processor or service provider as that law defines the role, and complies with the equivalent obligations that law imposes.
13. Liability, term & general
This Addendum takes effect when Customer accepts the Agreement and continues for as long as Pishik processes Customer Personal Information. Sections 8, 9, and 11 survive termination. Each party's liability under this Addendum is subject to the limitations and exclusions in the Agreement, except that nothing in the Agreement limits either party's liability to a data subject or a supervisory authority under Data Protection Law, and nothing purports to waive any right that Cal. Civ. Code § 1798.84 makes non-waivable. If Data Protection Law changes materially, the parties will negotiate in good faith to amend this Addendum accordingly; Pishik may update it to reflect a change in law or in its Subprocessors on the notice described in Section 6 and in the Privacy Policy. Except as Section 10 provides for the Standard Contractual Clauses, this Addendum is governed by the law and venue stated in the Agreement.
Annex I — Details of processing
| Item | Detail |
|---|---|
| Parties | Data exporter and Business/Controller: Customer, as identified in its Pishik workspace. Data importer and Service Provider/Processor: Pishik Labs, operator of the Pishik service, United States. Contact for both roles: the Pishik contact form, Privacy & data topic. |
| Subject matter | Provision of the Pishik contract-review workflow service under the Agreement. |
| Duration | The term of the Agreement, plus the retention and deletion periods in Section 11. |
| Nature and purpose | Hosting, storage, structuring, retrieval, transmission, and deletion of workflow records and share links; routing of review requests, reminders, and notifications; authentication and two-factor authentication; support; billing administration; security monitoring and backup. The business purposes are enumerated in Section 3. |
| Categories of data subject | Customer's employees, contractors, in-house and external counsel, workspace administrators, and the contract reviewers and approvers Customer routes contracts to. |
| Types of personal data | Name; business email address; job title, department, and role; workspace user identifier; optional profile photo; user preferences including a reply-to address and reminder schedule; review decisions and the notes reviewers write; comments and @mentions; the contract record Customer's users create — contract title and type, counterparty name, document and reference-document titles, and the free-text notes, to-dos, and reminders written on a contract; delegation and reassignment records; authentication material (hashed password, authenticator secret, hashed backup codes); session and audit metadata; the content and delivery record of email the Service sends; and share-link URLs pointing to documents held in Customer's own storage. |
| Special categories | None. The Service has no field for special-category or sensitive data and Customer is instructed not to submit any. Free-text fields hold whatever Customer's users type into them. |
| Document contents | Not processed. Contract files remain in Customer's own SharePoint, OneDrive, or Google Drive. Pishik stores links and workflow metadata; there is no file upload. |
| Frequency | Continuous, for the duration of the Agreement. |
Annex II — Technical & organizational measures
These are the measures in effect as of the effective date above. A plain-language walkthrough of most of them, written for end users rather than auditors, is in Security & privacy.
- Encryption. All traffic is served over HTTPS with HTTP Strict Transport Security. Data at rest is encrypted by the hosting platform.
- Access control and authentication. Two-factor authentication is mandatory on every account and cannot be switched off — not by the user, not by an administrator, not by Pishik. Passwords are stored as bcrypt hashes and backup codes as one-way hashes; neither is ever stored in readable form. Administrators may set a minimum password length for passwords set in their workspace. Roles are least-privilege, and Pishik staff access is granted by explicit, revocable capability grants.
- Session security. Sessions are server-side records with a 30-day maximum life, renewed only by genuine activity. Workspaces may enforce an idle sign-out that the server applies, so an abandoned browser tab cannot hold a session open. Changing a password signs out other devices; resetting one ends every session.
- Tenant isolation. Every record is keyed to its organization and every query is scoped to the session's own tenant; the tenant is derived from the server-side session, never from anything the client sends. A dedicated automated test suite guards this boundary on every change. A suspended workspace fails closed — sign-in, live sessions, and outstanding review links all stop answering at once.
- Review-link security. Reviewer links are personal, single-use, and expire on their own (90 days by default). Nothing is recorded until the reviewer confirms on the decision page, so a mail scanner that fetches links cannot record a decision. Restarting a review mints a new link and permanently retires the old one. Live tokens are stripped from every export.
- Audit logging. An audit trail records security-relevant events — sign-ins, membership and role changes, ownership transfer, credential and two-factor changes, delegations, and data exports — attributed to the person who actually performed each action, never to somebody else on their behalf.
- Data minimization by design. Contract files never enter the Service; only links and workflow metadata are held. Pishik does not log IP addresses. Card data never touches Pishik's servers. Internal operator tooling is metadata-only and cannot read workspace content.
- Network and application hardening. A strict Content Security Policy permits no off-origin scripts, styles, fonts, frames, or images; the site loads no third-party resources at all, and an automated test fails the build if one is ever introduced. Rate limiting protects sign-in, password reset, verification, and public form endpoints.
- Change control and testing. Changes are version-controlled and reviewed, and an automated test suite gates every deployment; a failing suite blocks release. Deployments are stamped and verified against the running service.
- Backup and recovery. The database is copied on a regular operational schedule and a copy can be restored in place; there is no automated off-site rotation today. Customers can additionally export a complete copy of their own data at any time.
- Personnel. Everyone with access is bound by written confidentiality obligations that survive their engagement, and access is removed promptly on departure or change of role.
- Incident response. Pishik maintains a documented incident-response process, including the notification commitments in Section 8.
- Vendor management. Every vendor that processes personal information on Pishik's behalf is contractually bound to maintain reasonable security appropriate to the nature of that information, reviewed before onboarding and on renewal.
Pishik holds no third-party security certification such as SOC 2 or ISO 27001. We would rather tell you that than imply otherwise; this Annex describes the controls that actually ship.
Annex III — Subprocessors
The complete list of third parties that process Customer Personal Information on Pishik's behalf. We update this list at least thirty (30) days before any addition or replacement takes effect, and notify workspace owners by email and in the app (Section 6).
| Subprocessor | What it does | What it processes | Location |
|---|---|---|---|
| Microsoft Corporation (Microsoft Azure) | Cloud hosting and infrastructure — the Service runs here and workspace data rests here | All Customer Personal Information | United States |
| Stripe, Inc. | Payment processing on Stripe-hosted pages | The email address of the administrator who starts checkout, the workspace name, and its identifier. No reviewer data. Card details are collected by Stripe directly and never reach Pishik. | United States |
| Microsoft Corporation (Azure Communication Services) | Email delivery, where a workspace uses this channel rather than its own Microsoft 365 tenant or its own SMTP provider | Recipient address, subject, and message content of email the Service sends | United States |
Not Subprocessors, because Customer directs them: Customer's own Microsoft 365 tenant used for email delivery through Microsoft Graph, any SMTP provider Customer designates, and Customer's own SharePoint, OneDrive, or Google Drive where its documents live.