GDPR Compliance and Your Data Rights

Data Processing Addendum (GDPR)

Last updated: July 20, 2026

This Data Processing Addendum ("DPA") forms part of the Terms and Conditions or other written agreement ("Agreement") between the customer ("Customer" or "Controller") and WicWac Inc., operating as Crisphive ("Crisphive" or "Processor").

This DPA applies where Crisphive processes Personal Data on behalf of the Customer that is subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, or other applicable European data protection laws.

1. Parties

  • Data Controller: The Customer using the Crisphive Service.
  • Data Processor: WicWac Inc. (Operating as Crisphive), Suite 1420, 99 Bank Street, Ottawa, Ontario, K1P 1H4, Canada

2. Definitions

Capitalized terms not defined in this DPA have the meaning given in the GDPR or the Agreement.

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" has the meaning set out in Article 4(2) GDPR.
  • "Sub-processor" means any third party engaged by Crisphive to process Personal Data on behalf of the Customer.
  • "EEA" means the European Economic Area.
  • "Functional Communications" means emails and SMS messages integral to operating an account and delivering the Service, including account, security (including one-time passcodes), billing, scheduling, service, and legal notices.
  • "Marketing Communications" means promotional emails such as newsletters, product announcements, and offers.

3. Scope and Purpose of Processing

Crisphive processes Personal Data solely for the purpose of providing the Crisphive scheduling and workforce management platform, including:

  • Account management
  • Scheduling and job coordination
  • Notifications and communications, including Functional Communications delivered by email and SMS
  • Platform support and maintenance
  • Security and performance monitoring

Processing is limited to what is necessary to deliver the Service.

4. Categories of Data and Data Subjects

4.1 Data Subjects

  • Customer employees
  • Contractors and field workers
  • Authorized users
  • End-customers (as uploaded by Customer)

4.2 Categories of Personal Data

  • Names, email addresses, phone numbers
  • Communication preferences, consent records, and opt-out status
  • Email and SMS delivery and interaction logs
  • Job assignments, schedules, and locations
  • Account credentials (hashed)
  • Usage and audit logs
  • Support communications

Special categories of data are not intended to be processed unless explicitly agreed in writing.

5. Communications: Roles and Legal Bases

5.1 Functional Communications

Functional Communications are necessary for the performance of the Agreement and the operation and security of the Service. Where Crisphive sends Functional Communications to the Customer's authorized users on the Customer's behalf (for example, schedule and dispatch notifications), Crisphive acts as Processor on the Customer's documented instructions, and the Customer, as Controller, is responsible for ensuring an appropriate lawful basis and for providing required privacy notices to its data subjects. Where Crisphive sends Functional Communications concerning the account relationship itself (for example, billing, security, and legal notices), Crisphive processes the relevant contact data as an independent controller on the legal bases of performance of a contract (Article 6(1)(b) GDPR), compliance with legal obligations (Article 6(1)(c) GDPR), and legitimate interests in the security and administration of the Service (Article 6(1)(f) GDPR). Because Functional Communications are necessary to the Service, they are not subject to marketing consent requirements and continue for the duration of the account.

5.2 Marketing Communications

Crisphive sends Marketing Communications as an independent controller, on the basis of consent (Article 6(1)(a) GDPR) or, where applicable, legitimate interests in business-to-business direct marketing consistent with ePrivacy rules. Data subjects have the right to object to direct marketing at any time (Article 21(2)–(3) GDPR), and every Marketing Communication includes an unsubscribe mechanism. Objection to or withdrawal of consent for Marketing Communications does not affect Functional Communications.

5.3 SMS One-Time Passcodes

Where a user elects SMS-based login, express consent is captured by checkbox at the point of election. OTP messages are processed for identity verification and account security on the bases of performance of a contract and legitimate interests in securing the Service. OTP codes are single-use, time-limited, and not retained after use or expiry.

5.4 Customer Warranties

The Customer represents and warrants that, for any communications it configures, triggers, or instructs Crisphive to send to its employees, contractors, or end-customers, it has established a lawful basis, provided all required notices, and obtained all consents required by applicable law. The Customer shall indemnify and hold harmless Crisphive from any claim, fine, or penalty arising from the Customer's failure to do so, to the maximum extent permitted by applicable law.

6. Controller and Processor Responsibilities

6.1 Customer (Controller)

The Customer represents that it has a lawful basis to collect and process Personal Data, has provided all required privacy notices to data subjects, and that its instructions to Crisphive comply with GDPR.

6.2 Crisphive (Processor)

Crisphive shall process Personal Data only on documented instructions from the Customer, ensure that all personnel authorized to process data are subject to confidentiality obligations, implement appropriate technical and organizational security measures, and assist the Customer in fulfilling its obligations under GDPR.

7. Confidentiality

Crisphive ensures that all personnel authorized to process Personal Data are subject to appropriate confidentiality obligations, whether contractual or statutory.

8. Security Measures (Article 32 GDPR)

Crisphive implements reasonable and appropriate safeguards, including:

  • Role-based access controls
  • Encryption in transit where applicable
  • Secure infrastructure and hosting environments
  • Logging and monitoring
  • Incident response procedures
  • Time-limited, single-use one-time passcodes for SMS-based login

Security measures are reviewed periodically and adjusted as needed.

9. Sub-Processors

9.1 Authorization

The Customer provides general authorization for Crisphive to engage Sub-processors, including email and SMS delivery providers.

9.2 Obligations

Crisphive ensures Sub-processors are bound by written agreements, provide GDPR-level protections, and process data only for authorized purposes.

9.3 Sub-Processor List

A current list of Sub-processors may be provided upon request.

10. International Data Transfers

Personal Data may be processed outside the EEA, including in Canada and the United States. Where required, Crisphive relies on Standard Contractual Clauses (SCCs) and other lawful transfer mechanisms under GDPR. Canada benefits from an adequacy decision of the European Commission for data subject to PIPEDA.

11. Data Subject Rights Assistance

Crisphive will assist the Customer, where reasonably possible, in responding to requests related to:

  • Access
  • Rectification
  • Erasure
  • Restriction
  • Objection, including objection to direct marketing
  • Data portability

Crisphive does not respond directly to Data Subject requests unless legally required. Where Crisphive acts as an independent controller for Marketing Communications and account-relationship Functional Communications, it responds to data subject requests concerning that processing directly, including honoring marketing opt-outs without undue delay.

12. Data Breach Notification

Crisphive shall:

  • Notify the Customer without undue delay upon becoming aware of a Personal Data Breach
  • Provide available information to support compliance with Articles 33 and 34 GDPR

Notification shall include the nature of the breach, likely consequences, and mitigation steps where available.

13. Data Retention and Deletion

Upon termination of the Agreement:

  • Crisphive will delete or return Personal Data within a reasonable timeframe
  • Data may be retained where legally required
  • Backups may persist for a limited period until overwritten
  • Records of consent, opt-outs, and communication logs may be retained as necessary to demonstrate compliance with applicable law

14. Audits and Compliance

Upon reasonable written notice, the Customer may:

  • Request documentation demonstrating compliance
  • Conduct audits limited to one per year (unless required by law)

Audits must not unreasonably disrupt Crisphive's operations.

15. Liability

Liability under this DPA is subject to the limitations and exclusions set out in the Agreement, including its Limitation of Liability provisions, to the maximum extent permitted by applicable law. Without limiting the foregoing, Crisphive is not liable for non-delivery, delay, filtering, or interception of communications by third-party providers or networks, or for consequences arising from a data subject's failure to maintain accurate contact information, and each party is liable only for the portion of any regulatory fine or damages that corresponds to its own responsibility under Article 82 GDPR.

16. Governing Law

This DPA is governed by the laws of Ontario, Canada, and applicable EU/UK data protection law where required.

17. Order of Precedence

In the event of conflict:

  • This DPA
  • The Agreement
  • Any other applicable documents

18. Contact for Data Protection Matters

Email: support@crisphive.com

WicWac Inc. (Operating as Crisphive)

Suite 1420, 99 Bank Street

Ottawa, Ontario K1P 1H4

Canada

Schedule 1 — Summary of Processing

Schedule 1 — Summary of Processing
ItemDescription
Nature of ProcessingHosting, storage, access, transmission, communications delivery
PurposeScheduling & workforce management; account & service communications
DurationTerm of Agreement
Data SubjectsEmployees, contractors, customers
Data TypesContact, scheduling, usage, communication preference & consent data