Data Processing Addendum

Capitalized terms not defined here have the meaning given in Section Definitions or, where applicable, the executed Master Services Agreement.

This Data Processing Addendum ("DPA") forms part of the Master Services Agreement between Customer and Section, Inc. ("Section", "we", "us", "our") and applies to the extent that Section Processes Personal Data on Customer's behalf in the course of providing the Services.

1. Local definitions

In addition to terms defined in the Definitions document, the following local terms apply:

Personal Data Breach: A confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise Processed.

Restricted Transfer: A transfer of Personal Data from a jurisdiction whose laws require a transfer mechanism (such as the GDPR, the UK GDPR, or the Swiss FADP) to a jurisdiction that has not received an adequacy determination.

2. Roles

Customer is the controller of Personal Data Processed by Section in connection with the Services. Section is the processor. Where Customer acts as processor on behalf of an underlying controller (for example, where Customer's customer is the controller), Section acts as a sub-processor and Module 3 of the Standard Contractual Clauses applies in place of Module 2. The Docking Clause (SCC Clause 7) is enabled to allow accession by additional controllers without requiring a new DPA each time.

3. Subject matter, duration, nature, and purpose of Processing

This section, together with section 4 and the parties' identities in the MSA, constitutes Annex I of the Standard Contractual Clauses.

  • Subject matter: Section's Processing of Personal Data submitted to or generated through the Services on Customer's behalf.
  • Duration: The term of the MSA, plus the retention periods set out in section 14.
  • Nature: Collection, storage, access, transmission, analysis, and deletion of Personal Data via the Services, including web application tier on Render, managed PostgreSQL, event pipeline (Rudderstack), LLM gateway (OpenRouter routing to OpenAI and Anthropic under zero retention), data warehouse (Snowflake), application monitoring (Datadog), authentication (Clerk), transactional email (Knock), customer support ticketing (Freshdesk), and, where enabled by Customer, HRIS integration (Finch).
  • Purpose: Provision of the Services to Customer, including coaching, certification, use case discovery, analytics, and administrative functionality.

4. Categories of data subjects and Personal Data

  • Data subjects: Customer's Authorized Users (typically Customer's employees and contractors).
  • Personal Data categories: first name, last name, business email, authentication metadata, product event metadata, support ticket content, and, for SectionHQ tenants using the optional HRIS integration, employee directory metadata (manager, role, organizational structure).
  • Categories excluded by design: Section does not collect, store, or process protected health information, government-issued identifiers, financial account data, biometric data, or sensitive personal data through the Services. Customer must not submit such data to the Services.

5. Section's obligations

Section will:

  1. Process Personal Data only on Customer's documented instructions, including with regard to Restricted Transfers, unless required to do otherwise by applicable law (and in that case, Section will inform Customer of that legal requirement before Processing, unless that law prohibits notice on important grounds of public interest).
  2. Ensure that personnel authorized to Process Personal Data are bound by confidentiality obligations.
  3. Implement and maintain the technical and organizational measures set out in section 9.
  4. Assist Customer in fulfilling its obligations to respond to data subject requests, conduct data protection impact assessments, and consult with supervisory authorities, taking into account the nature of Processing and the information available to Section.
  5. Engage Sub-processors only in accordance with section 6.
  6. At Customer's choice, delete or return Personal Data on termination as set out in section 14.
  7. Make available to Customer all information reasonably necessary to demonstrate compliance with this DPA as set out in section 13.

6. Sub-processors

Customer grants Section general authorization to engage Sub-processors to Process Personal Data on Section's behalf. Section maintains the current list at Subprocessor List, which serves as Annex III of the Standard Contractual Clauses.

Section will provide at least thirty (30) days' advance notice of any new Sub-processor before that Sub-processor begins Processing Customer Data, except where an unforeseen circumstance (such as a security incident, a material change in the functionality of the Services, or a compliance concern) requires an expedited change.

Customer does not have a general right to object to a new Sub-processor. Where Customer reasonably believes that a new Sub-processor materially decreases the security or functionality of the Services with respect to Customer Data, Customer's sole and exclusive remedy is to terminate the affected Services and receive a pro-rata refund of any prepaid fees attributable to the terminated period.

Section will impose, in writing, data protection obligations on each Sub-processor that are no less protective than those in this DPA. Section will remain liable to Customer for a Sub-processor's breach of its written obligations to Section to the extent that breach would have constituted Section's breach if performed by Section directly.

7. International transfers

Where Customer's transfer of Personal Data to Section, or Section's onward transfer to a Sub-processor, constitutes a Restricted Transfer, the following mechanisms apply:

  1. EU transfers: The EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated by reference. Module 2 (Controller-to-Processor) applies between Customer and Section; Module 3 (Processor-to-Processor) applies between Section and its Sub-processors and, where applicable, between Customer (as processor) and Section. For Clause 17, the governing law is the law of the Republic of Ireland. For Clause 18, the competent forum is the courts of the Republic of Ireland. Clause 7 (Docking Clause) applies.
  2. UK transfers: The UK International Data Transfer Addendum to the EU Standard Contractual Clauses, Version B1.0, in force from 21 March 2022, is incorporated by reference. The jurisdiction is the Republic of Ireland.
  3. Swiss transfers: The EU Standard Contractual Clauses apply with modifications required by the Swiss Federal Act on Data Protection. The Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority, and references to the GDPR are read as including the Swiss FADP.

8. Cooperation with data subject requests

Section will, taking into account the nature of Processing, assist Customer by appropriate technical and organizational measures, insofar as possible, in responding to requests from data subjects to exercise their rights under applicable Data Protection Laws. Reasonable assistance is provided at no additional cost. Bespoke, repetitive, or manifestly unfounded requests may be subject to a reasonable fee or refused as permitted by law.

9. Security measures

This section constitutes Annex II of the Standard Contractual Clauses. Section implements and maintains the following control categories. Detailed control descriptions, evidence, and the underlying Section Compliance Playbook are available to Customer under NDA.

  1. Access control, authentication, and identity management: least privilege, unique accounts, multi-factor authentication, SSO support (SAML / OIDC), SCIM provisioning via Clerk, quarterly access reviews, prompt revocation on termination.
  2. Encryption and key management: TLS 1.2 or higher in transit, AES-256 at rest on Render managed PostgreSQL, platform-managed encryption for environment groups and secrets.
  3. Network and endpoint security: defense-in-depth, network segmentation across Production, Preview, and Development environments via Render Projects, hardened device baselines (FileVault or BitLocker, host firewall, screen lock), CIS benchmarks.
  4. Secure development and change management: documented SDLC, peer code review, OWASP Top 10 alignment, and a three-layer vulnerability pipeline (Pre-Commit, Pre-Merge, Runtime) using Claude Code skills, GitHub Actions, GitHub Dependabot, Datadog Security and Vulnerability Management, and Render PaaS controls.
  5. Logging, monitoring, and incident response: centralized logging and alerting in Datadog, 24Γ—7 monitoring of security-relevant events, documented Security Incident Response Plan with a standing Security Response Team.
  6. Business continuity, vendor management, and personnel: documented Business Continuity and Disaster Recovery Plan with a 24-hour Recovery Time Objective and a 24-hour Recovery Point Objective, periodic Sub-processor reviews, confidentiality agreements, background checks, and annual security and privacy awareness training for all personnel.

10. Security Incident notification

Section will notify Customer without undue delay and in any event within seventy-two (72) hours of confirming a Personal Data Breach affecting Customer Data. The notification will, to the extent then known:

  1. Describe the nature of the Personal Data Breach, including the categories and approximate number of data subjects and records concerned.
  2. Communicate the contact point at Section.
  3. Describe the likely consequences of the Personal Data Breach.
  4. Describe the measures taken or proposed to be taken by Section to address the Personal Data Breach and to mitigate its possible adverse effects.

Section will provide updates as additional information becomes available. Notification is not an acknowledgment of fault or liability.

11. Government access and transparency

If Section receives a binding government or law-enforcement request for Customer Data, Section will:

  1. Notify Customer of the request to the extent legally permitted, so that Customer may seek appropriate protective orders or other remedies.
  2. Challenge any request that, in Section's reasonable judgment, is overbroad, unlawful, or inconsistent with applicable international law.
  3. Disclose only the minimum data legally required to comply.

Section maintains the right to publish aggregated, statistical information about government requests as part of any future transparency reporting it elects to provide.

12. Compliance suspension

Section may screen Customer and Authorized Users against U.S. restricted-party lists (including the OFAC Specially Designated Nationals and Blocked Persons List, the BIS Entity List, the BIS Denied Persons List, and the BIS Unverified List) and may verify the jurisdiction from which the Services are accessed. Where Section reasonably determines that a Customer or any Authorized User is a person designated on or restricted under such a list, is located in or under the control of a country or territory subject to a comprehensive U.S. trade embargo or stringent U.S. sanctions, or is using the Services in a manner that would cause Section to violate U.S. export controls or sanctions laws, Section may suspend or restrict access to the affected portion of the Services. Section will notify Customer following any such suspension or restriction and will work with Customer in good faith to resolve the issue to the extent legally permitted. A suspension under this section is not a breach of the DPA or the MSA.

13. Audits

  1. Section provides its current SOC 2 Type II report and its published security documentation to Customer at least annually, under NDA, in lieu of an on-site audit. Where Customer reasonably requires further information to verify Section's compliance with this DPA, Section will respond to written information requests within a reasonable time.
  2. An on-site audit by Customer or its qualified third-party auditor is permitted only where (i) a Personal Data Breach affecting Customer Data has been confirmed and is attributable to Section, and (ii) remediation requires third-party validation. Any such audit will be conducted during business hours, with reasonable advance notice, scoped narrowly to the Personal Data Breach, at Customer's cost, and subject to Section's facility-of-record and confidentiality controls. Section may exclude information that would compromise Section's security, the confidentiality of other customers, or applicable law.

14. Return and deletion

On termination or expiration of the MSA, or on Customer's earlier written request, Section will delete Customer Data within thirty (30) days and purge it from backups within ninety (90) days, except where retention is required by applicable law or for the establishment, exercise, or defense of legal claims. Section will, on request and at Customer's cost for any bespoke export work, return Customer Data in a commercially reasonable format before deletion.

15. Aggregate and de-identified data

Section may create, retain, and use aggregated, de-identified, and statistical data derived from Customer Data for security monitoring, analytics, benchmarking, and improvement of the Services, provided that the data does not identify Customer, any End User, or any other individual. Such data is not Customer Data for purposes of this DPA.

16. Order of precedence

In any conflict between this DPA and the MSA on data protection matters, this DPA controls. In any conflict between this DPA and the Standard Contractual Clauses (where the Standard Contractual Clauses apply), the Standard Contractual Clauses control.

17. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the MSA. Nothing in this DPA expands or duplicates those caps.

18. SCC Annex mapping

For clarity: sections 3 and 4 of this DPA, together with the parties' identities in the MSA, constitute Annex I (Annex I.A and Annex I.B) of the Standard Contractual Clauses. Section 9 constitutes Annex II. The Subprocessor List, as updated from time to time, constitutes Annex III. References elsewhere in this DPA to specific section numbers (for example, "section 17") refer to the numbered sections of this DPA itself.

19. Governing law

This DPA is governed by the laws of the State of Delaware, without regard to its conflict-of-laws principles. The choice-of-law and forum provisions in section 7 apply only to the Standard Contractual Clauses themselves.

20. Notices

Notices to Section under this DPA are delivered to legal@sectionai.com.

21. Effective date

This DPA becomes effective on the effective date of the MSA and remains in force for the duration of the MSA, plus the retention periods set out in section 14.

Section, Inc. 228 Park Avenue S, PMB 96268 New York, NY 10003-1502 legal@sectionai.com

Word 'section' written in lowercase letters with each letter in different bright colors.

The AI:ROI Conference

Everything you need to make your AI spend defensible.

Torn piece of cream-colored textured paper with uneven edges.