CarbonApps LLC | Carbon Web Print LLC (d/b/a CarbonWeb)
Effective: date of first Application installation | Version: July 1, 2026
This Data Processing Agreement (“Agreement”) is entered into between:
CarbonApps LLC, an Ohio limited liability company, and Carbon Web Print LLC (doing business as CarbonWeb), an Ohio limited liability company (together, “Processor”, “we”, “us”); and
The entity that has installed one or more of the Applications identified in Section 2 on their monday.com account (“Controller”, “you”).
This Agreement is pre-executed by the Processor and takes effect when the Controller installs any Application, without requiring a countersignature. Controllers who require a separately executed copy may request one at support@carbonapps.co.
Note on scope: This Agreement governs only the Customer Data the Processor handles as a processor on the Controller’s instructions — the data the Controller routes through the Applications from its monday.com boards and connected services (defined in Section 1). It does not govern the personal data the Processor itself controls about the Controller’s account administrators and end users (such as name, email, and account metadata); that data is processed by CarbonApps LLC and Carbon Web Print LLC as joint controllers and is governed by the Privacy Policy at carbonapps.co/legal/apps/privacy.
| Art. | Obligation | Where addressed |
|---|---|---|
| 28(3)(a) | Process only on controller instructions | Section 3.1 |
| 28(3)(b) | Confidentiality of authorized personnel | Section 3.2 |
| 28(3)© | Security measures (Art. 32) | Sections 3.3 and 6 |
| 28(3)(d) | Sub-processor conditions | Section 3.4 |
| 28(3)(e) | Assist with data subject rights | Section 3.5 |
| 28(3)(f) | Assist with security, breach, DPIA | Section 3.6 and 6 |
| 28(3)(g) | Delete or return data at end of services | Section 3.7 |
| 28(3)(h) | Provide information; allow audits | Section 3.8 |
“Applications” means the monday.com Marketplace applications operated by the Processor — including automation and view apps, third-party integration apps, and board template solutions — together with their associated automations, integrations, and views. A current list of the Applications is available on the monday.com Marketplace.
“Customer Data” means personal data that passes through the Applications during the execution of automations, rendering of views, or operation of third-party integrations, as directed by the Controller. It includes board item content; update content (message threads attached to board items); and messages, call events, records, and other content transmitted to or from integrated third-party services the Controller subscribes to (for example calling/dialer, SMS, accounting, or lead-sourcing services), whether or not that content is also stored on a board. Customer Data does not include account administrator or end user information collected by the Processor as a controller.
“GDPR” means EU Regulation 2016/679 (General Data Protection Regulation). References to GDPR include UK GDPR (as defined in the UK Data Protection Act 2018) and the Swiss Federal Act on Data Protection (revDSG) where applicable.
“Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing”, and “Personal Data Breach” have the meanings given in Art. 4 GDPR.
“Sub-Processor” means any third party engaged by the Processor to process Customer Data on behalf of the Controller.
“Sensitive Data” means personal data requiring heightened protection, comprising: the special categories of personal data in Art. 9 GDPR (personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership; genetic data; biometric data processed for the purpose of uniquely identifying a natural person; and data concerning health, sex life, or sexual orientation); personal data relating to criminal convictions and offences (Art. 10 GDPR); government-issued identifiers (such as social security, passport, national insurance, or other national identification numbers); financial-account or payment-card numbers; account passwords or authentication credentials in unhashed form; and “protected health information” as defined under the US Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”).
“Services” means the Applications and related support services provided by the Processor.
Subject matter: Processing of Customer Data by the Processor acting as a processor on the Controller’s instructions.
Applications that do not route data through the Processor: Some Applications — for example, board templates and Applications that operate solely through monday.com’s native automations — do not route any data through the Processor; the data remains within monday.com. For those Applications no Customer Data is processed by the Processor, and the Processor acts as neither processor nor sub-processor for that data; it is governed by the Controller’s own agreement with monday.com, not this Agreement.
Nature and purpose: Execution of automations, rendering of views, and facilitation of integrations with third-party services the Controller subscribes to independently (for example calling/dialer, SMS, accounting, or lead-sourcing services), as configured by the Controller through the Applications. The integrated service for each Application is identified in that Application’s monday.com Marketplace listing.
Types of personal data: Any personal data that the Controller places on monday.com boards and directs through the Applications. The Processor does not determine the categories of personal data processed — the Controller determines this through their configuration of the Applications. Categories may include contact information, names, phone numbers, email addresses, messages, call events, update content, and any other data the Controller chooses to process.
Categories of data subjects: Any individuals whose personal data appears on the Controller’s monday.com boards, which may include the Controller’s customers, contacts, employees, or other individuals.
Duration: This Agreement is in effect for as long as any Application remains installed on the Controller’s monday.com account. It terminates automatically and immediately upon uninstallation of all Applications (see Section 8).
The Processor shall process Customer Data only on documented instructions from the Controller — being the automations, views, and integrations the Controller configures within the Applications. The Controller’s configuration of the Applications constitutes its documented processing instructions.
If the Processor is required by applicable law to process Customer Data other than on the Controller’s instructions, the Processor shall notify the Controller of that legal requirement before processing, unless prohibited by law from doing so.
The Processor shall ensure that persons authorized to process Customer Data are subject to appropriate obligations of confidentiality, whether by contract or professional duty.
The Processor shall implement and maintain the technical and organizational measures described in Section 6, consistent with Art. 32 GDPR.
The Processor shall not engage a new Sub-Processor without providing the Controller at least 14 days’ prior written notice by email to the Controller’s account administrator or other contact the Controller has designated. The current list of Sub-Processors engaged to process Customer Data is maintained at carbonapps.co/legal/apps/subprocessors.
For clarity, this Agreement and this list concern only Sub-Processors involved in processing Customer Data on the Controller’s instructions. Third parties involved in processing account administrator, end user, marketing, or operational data — for which CarbonApps LLC and Carbon Web Print LLC act as joint controllers rather than as processor — are outside the scope of this Agreement and are addressed in the Privacy Policy.
The Controller may object to a new Sub-Processor by contacting support@carbonapps.co within the 14-day notice period, stating the grounds for objection. If the Processor proceeds with the new Sub-Processor despite a timely objection that cannot be accommodated, the Controller may terminate this Agreement and the Services.
The Processor shall impose data protection obligations on each Sub-Processor equivalent to those set out in this Agreement (Art. 28(4) GDPR). The Processor remains fully liable to the Controller for the performance of each Sub-Processor’s obligations.
The Processor shall provide reasonable assistance to the Controller in fulfilling the Controller’s obligations to respond to data subject rights requests under Arts. 15–22 GDPR.
The Processor’s ability to assist is shaped by the nature of the processing (Art. 28(3)(e)). Because Customer Data is generally not persistently stored beyond the time required to complete each operation (see Section 2 and Section 3.7), assistance for that transient processing is limited to confirming the scope and nature of processing performed on the Controller’s instructions. Where Customer Data has been captured in diagnostic logs (Section 3.7), the Processor will, on the Controller’s instruction, cease further diagnostic capture and confirm the applicable retention and automatic-purge date. However, because diagnostic logs are held in shared, retention-bound logging infrastructure that does not permit selective extraction or deletion of individual records, the Processor cannot delete specific Customer Data from those logs before the end of the retention period, after which it is automatically purged. Rights requests relating to data held by monday.com or by any third-party service the Controller connects through the Applications must be directed to those services by the Controller.
Breach notification: The Processor shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data Breach affecting Customer Data (Art. 33(2) GDPR). The notification shall include, to the extent available: (a) the nature of the breach and categories and approximate number of data subjects and records affected; (b) likely consequences; © measures taken or proposed. The Processor shall provide further information in phases as it becomes available. Because Customer Data is processed content-blind, the Processor does not and cannot assess the sensitivity of affected data; any Personal Data Breach affecting Customer Data is notified under this Section without content-based triage, and the assessment of severity and of any Art. 33(1)/34 obligation rests with the Controller.
DPIA assistance: The Processor shall provide reasonable assistance to the Controller in conducting data protection impact assessments and prior consultations with supervisory authorities under Arts. 35–36 GDPR, to the extent that such assessments relate to processing performed by the Processor under this Agreement.
Customer Data is not persistently stored by the Processor beyond the time required to complete each processing operation (typically seconds to minutes). Upon completion of each operation, Customer Data is discarded. Because Customer Data is not retained, no separate return or deletion step arises on termination beyond the cessation of processing.
Configuration data and authentication credentials are not Customer Data; they are controller-side data that CarbonApps LLC and Carbon Web Print LLC hold as joint controllers, and their retention and deletion are addressed in the Privacy Policy, not this Agreement.
Automation execution audit logs (retained for 90 days under the Processor’s sub-processor obligations) will be purged in the ordinary course at the end of their retention period.
Where diagnostic logging has been enabled with consent, any Customer Data captured in diagnostic logs is similarly retained for up to 90 days and then automatically purged, and cannot be readily purged earlier. Such logging is scoped by filter — by board, and optionally by specific item and automation — to minimize the Customer Data captured. Creating and testing with non-production (dummy) data is the Controller’s responsibility, undertaken in coordination with the Processor; the Processor provides the scoping controls and support to enable this, but does not create the Controller’s test data.
The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this Agreement and Art. 28 GDPR.
The Controller may audit the Processor’s processing activities on written notice of no less than 30 days, at the Controller’s cost and no more than once per year. Following a confirmed Personal Data Breach affecting Customer Data, the Controller may conduct one additional audit beyond that annual limit, on the same notice and cost terms. The Processor may satisfy this obligation by providing a third-party audit report or certification in lieu of direct audit access. Audits must not unreasonably disrupt the Processor’s operations or compromise the security or confidentiality of other customers’ data.
The Processor’s own infrastructure is located in the United States. Where the Controller is established in, or directs Customer Data concerning data subjects located in, the EEA, the United Kingdom, or Switzerland, processing of Customer Data on that infrastructure involves a restricted transfer of personal data to the US (a “Restricted Transfer”). The position for Applications hosted on monday code, whose Customer Data sub-processor is monday.com Ltd in Israel, is addressed in Section 4.2.
For Restricted Transfers to the Processor, the Processor’s standing basis is the Standard Contractual Clauses set out in Schedule 1 (as supplemented by the UK International Data Transfer Addendum in Schedule 2 and the Swiss amendments in Schedule 3). The Standard Contractual Clauses take effect automatically without further action by either party, are incorporated into this Agreement by reference as completed by the Annexes in Schedule 1, and govern the relevant Restricted Transfer to the exclusion of any conflicting provision of this Agreement. They remain the standing transfer safeguard whether or not any adequacy framework is in force.
Each Sub-Processor maintains its own transfer mechanism(s) (Standard Contractual Clauses or other Art. 46 GDPR safeguards) under its respective data processing agreement with the Processor.
For Applications hosted on monday code, the Customer Data Sub-Processor is monday.com Ltd (Israel). Applications hosted on monday code are identified as “hosted by monday.com” in the Security and Compliance section of their monday.com Marketplace listing. The transfer to monday.com Ltd relies on the European Commission’s adequacy decision for Israel (Art. 45 GDPR); monday.com’s onward transfers to its own sub-processors are covered by monday.com’s Standard Contractual Clauses (with the UK and Swiss addenda) under its Developer Storage data processing terms.
For data the Controller directs to third-party services it subscribes to through the Applications, the Controller is responsible for ensuring its own agreements with those services include appropriate transfer safeguards.
The Processor maintains a transfer impact assessment and related transfer records supporting the mechanisms described in this Section. These records are made available to the Controller and to competent supervisory authorities on request. They are not incorporated into this Agreement and may be updated by the Processor from time to time.
The Controller represents and warrants that:
(a) Lawful basis: It has a lawful basis under Art. 6 GDPR (and Art. 9 GDPR where applicable) for each processing activity it directs through the Applications.
(b) Transparency: It has provided appropriate notice to data subjects whose personal data it processes through the Applications, consistent with Arts. 13–14 GDPR.
© Data minimization: It will not direct the Processor to process personal data beyond what is necessary for the configured purpose.
(d) Third-party integrations: Where it uses the Applications to connect to a third-party service it subscribes to, it maintains its own direct relationship with that service and is responsible for ensuring the integration complies with applicable data protection law. Where an integrated service restricts use of its platform to particular jurisdictions or does not address the data protection requirements of the Controller’s jurisdiction, the Controller is responsible for assessing whether routing personal data to that service is permissible under its obligations as data controller. For example, PhoneBurner states that its system is intended for use in the United States and Canada only; Controllers who sync personal data of EEA or UK individuals to PhoneBurner should make that assessment before doing so.
(e) Minors: The Applications are not made available for use by anyone under 18. The Controller is responsible for any personal data of children or other minors it directs through the Applications, including having a lawful basis and obtaining any consents required under applicable law.
(f) Imported data: Where an integration imports personal data into the Controller’s monday.com boards from an external source (for example a lead-sourcing service), the Controller is the controller of that data and is responsible for having a lawful basis for the processing (Art. 6 GDPR), for providing any information required to the individuals concerned (Arts. 13–14 GDPR), and for compliance with applicable ePrivacy and direct-marketing rules in any subsequent outreach to those individuals.
(g) No Sensitive Data: It will not use the Applications to process, and will not direct, submit, or route through the Applications, any Sensitive Data (as defined in Section 1). The Applications are not designed or intended for Sensitive Data, and the Processor offers no agreement permitting its processing.
The Processor is not a “business associate” within the meaning of HIPAA, offers no Business Associate Agreement, and makes no representation of HIPAA compliance; the Applications must not be used to create, receive, maintain, or transmit protected health information. Because the Processor processes Customer Data content-blind (Section 6) and at most transiently (Section 3.7), it does not and cannot inspect, detect, or filter Sensitive Data; ensuring Sensitive Data is not directed through the Applications is the Controller’s responsibility. Directing Sensitive Data through the Applications is a breach of this Agreement and falls outside the documented processing instructions the Processor is authorized to act on (Section 3.1), and the Processor applies no Sensitive-Data-specific safeguards beyond the measures in Section 6. This restriction is in addition to, and does not limit, any restriction on sensitive or special-category data in the Controller’s agreement with monday.com.
(h) Compliance with monday.com terms: The Controller’s use of the Applications, and the personal data it places on monday.com and directs through the Applications, comply with the Controller’s own agreement with monday.com.
The Processor implements and maintains the following technical and organizational measures:
Encryption: Data in transit is encrypted using TLS. For Applications hosted on the Processor’s own cloud infrastructure, all data at rest is encrypted: personal data under AWS-managed KMS keys, and other stored data under provider-owned keys; message queues holding Customer Data pending processing are KMS-encrypted at rest, while queues carrying only non-personal routing events use the provider’s default at-rest encryption. For Applications hosted on monday code (the monday.com platform’s developer-hosting environment), encryption at rest and key management are performed by monday.com as part of its Developer Storage infrastructure, under monday.com’s own technical and organizational measures evidenced by its SOC 2 and ISO 27001 certifications.
Access controls: Access to customer data is restricted to authorized personnel on a need-to-know basis.
No persistent storage of Customer Data (limited diagnostic exception): Customer Data is not stored beyond the time required to complete each processing operation, except that, where diagnostic logging is enabled with consent, Customer Data captured for diagnostics is retained in logs for up to 90 days before automatic deletion. Such logging is scoped (by board, and optionally by item and automation) to minimize the Customer Data captured.
Incident response: The Processor maintains procedures for detecting, reporting, and investigating Personal Data Breaches, consistent with its obligations under Section 3.6.
The Processor may update these measures from time to time, provided that updates do not materially reduce the level of protection afforded to Customer Data.
This Agreement is governed by the laws of the State of Ohio, without regard to its conflict of law provisions. Any disputes arising under this Agreement shall be subject to the dispute resolution provisions in the Processor’s Terms of Service. This is subject to Schedule 1: where the Standard Contractual Clauses apply, the governing law and choice of forum specified in Clauses 17 and 18 of those Clauses (as completed in Schedule 1, and as amended by Schedules 2 and 3 for UK and Swiss transfers) govern the relevant Restricted Transfer.
Nothing in this Agreement limits the rights of data subjects or supervisory authorities under applicable data protection law.
This Agreement takes effect when the Controller first installs any Application on their monday.com account.
This Agreement terminates automatically and immediately upon uninstallation of all Applications from the Controller’s monday.com account. Upon uninstallation, the Processor can no longer process Customer Data, and the deletion obligations in Section 3.7 apply.
Sections 3.6 (breach notification), 3.7 (deletion), 3.8 (audit rights), 4 (international transfers), and 7 (governing law) survive termination to the extent necessary to fulfill any post-termination obligations under applicable data protection law.
In the event of conflict between this Agreement and the Privacy Policy or Terms of Service, this Agreement prevails with respect to the processing of Customer Data as processor. For matters relating to the processing of account administrator and end user data as joint controller, the Privacy Policy prevails.
This Agreement, together with the Privacy Policy and Terms of Service, constitutes the entire agreement between the parties with respect to the processing of personal data under the Services. It supersedes all prior agreements, representations, or understandings on that subject.
The Processor may update this Agreement from time to time. Material changes will be communicated with at least 14 days’ notice. Continued use of the Applications after the effective date of an update constitutes acceptance of the revised Agreement.
This Agreement is pre-executed and authorized by the Processor — CarbonApps LLC and Carbon Web Print LLC (doing business as CarbonWeb). It takes effect automatically when the Controller installs any Application, is binding on the Processor from that time, and requires no further signature by the Processor and no countersignature by the Controller.
A Controller that requires a separately signed copy for its own records may sign and return this Agreement; the Processor’s signature is not required for it to take effect.
The standard contractual clauses for the transfer of personal data to third countries set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the “EU SCCs”) are hereby incorporated into this Agreement by reference and form part of it, completed and configured as set out in this Schedule. The full text of the EU SCCs is available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj and is deemed reproduced here. In the event of any conflict between the EU SCCs and the other provisions of this Agreement, the EU SCCs prevail with respect to the relevant Restricted Transfer.
By installing any Application, the Controller (as data exporter) is deemed to have entered into the EU SCCs with the Processor (as data importer). Where the Processor engages a Sub-Processor that is itself a data importer in a third country, the corresponding module of the EU SCCs applies between the Processor and that Sub-Processor under the relevant sub-processing agreement.
Module: Module Two (Controller to Processor) applies. The Controller is the data exporter; the Processor is the data importer. (Where a Restricted Transfer occurs between two processors — for example, onward transfer to a Sub-Processor — Module Three, Processor to Processor, applies on equivalent terms.)
Clause 7 (Docking clause): Included. Additional entities may accede to the EU SCCs as data exporter or data importer with the agreement of the parties.
Clause 9 (Use of sub-processors): Option 2 — General written authorization applies. The Processor has the Controller’s general authorization to engage Sub-Processors. The time period for prior notice of Sub-Processor changes is 14 days, consistent with Section 3.4 of this Agreement. The current list of Sub-Processors is set out in Annex III.
Clause 11 (Redress): The optional language permitting data subjects to lodge a complaint with an independent dispute resolution body is not selected. This does not limit any right of a data subject to lodge a complaint with a supervisory authority or to pursue a judicial remedy under Clauses 11–12 and applicable law.
Clause 17 (Governing law): Option 1 applies. The EU SCCs are governed by the law of Ireland. This choice applies to the EU SCCs only and operates notwithstanding the governing law of this Agreement stated in Section 7.
Clause 18 (Choice of forum and jurisdiction): Disputes arising from the EU SCCs shall be resolved before the courts of Ireland.
Clause 8.9 / audits: The audit arrangements in Section 3.8 of this Agreement satisfy the audit obligations under Clause 8.9 of the EU SCCs.
Data exporter
| Field | Detail |
|---|---|
| Name | The Controller — the entity that has installed one or more Applications on its monday.com account, as identified by the account name and account administrator details received by the Processor at installation. |
| Address | The registered address of the Controller entity identified by the account name received at installation; available from the Controller on request. |
| Contact person | The Controller’s account administrator (name and email received via monday.com at installation). |
| Activities relevant to the transfer | Use of the Applications to configure and run automations, render views, and operate third-party integrations involving Customer Data. |
| Role | Controller. |
Data importer
| Field | Detail |
|---|---|
| Name | CarbonApps LLC and Carbon Web Print LLC (d/b/a CarbonWeb), Ohio limited liability companies. |
| Address | 4135 Erie St, Willoughby, OH 44094, United States (registered address of both entities). |
| Contact person | Privacy contact, support@carbonapps.co. |
| Activities relevant to the transfer | Provision of the Applications and related support; transient processing of Customer Data to execute automations, render views, and facilitate third-party integrations on the Controller’s instructions. |
| Role | Processor. |
Categories of data subjects: Any individuals whose personal data the Controller places on its monday.com boards and directs through the Applications — which may include the Controller’s customers, contacts, prospects, employees, or other individuals.
Categories of personal data: Determined by the Controller through its configuration of the Applications. May include names, contact details, email addresses, phone numbers, message and update content, call events, and any other personal data the Controller chooses to process. The Processor does not determine the categories of personal data transferred.
Sensitive data: The Applications are not intended for, and the Controller must not direct through them, any Sensitive Data (as defined in Section 1 — including the special categories of personal data under Art. 9 GDPR, criminal-offence data under Art. 10 GDPR, and protected health information under HIPAA). This is a prohibition under Section 5(g), not a permitted-but-at-risk processing: the Processor offers no agreement permitting Sensitive Data and maintains no HIPAA Business Associate Agreement. The Processor processes Customer Data content-blind and applies no Sensitive-Data-specific safeguards beyond the measures in Annex II; responsibility for keeping Sensitive Data out of the Applications rests with the Controller.
Frequency of the transfer: Continuous — on each occasion that the Controller’s configured automations, views, or integrations execute.
Nature of the processing: Transient receipt, processing, and onward transmission of Customer Data to execute automations, render views, and facilitate third-party integrations. Customer Data is not persistently stored beyond the time required to complete each operation.
Purpose of the transfer and further processing: To provide the Applications and related support services as configured by, and on the documented instructions of, the Controller.
Retention period: Customer Data is not retained beyond the time required to complete each processing operation (typically seconds to minutes); diagnostic logs (where enabled with consent) and automation execution audit logs are retained for up to 90 days. Configuration data and authentication credentials are controller-side data, not Customer Data, and their retention is addressed in the Privacy Policy. See Section 3.7.
Sub-processor transfers: For transfers to Sub-Processors, the subject matter, nature, and duration of processing are as described in Annex III and the applicable Sub-Processor agreement.
The competent supervisory authority is the supervisory authority of the EEA Member State in which the data exporter (Controller) is established. Where the data exporter is not established in an EEA Member State but falls within the territorial scope of the GDPR under Art. 3(2), the competent supervisory authority is that of the Member State in which the data exporter’s Art. 27 GDPR representative is established. For transfers governed by the UK Addendum, the competent authority is the UK Information Commissioner’s Office (ICO); for transfers subject to the Swiss FADP, the Swiss Federal Data Protection and Information Commissioner (FDPIC) (see Schedules 2 and 3).
The Processor implements and maintains at least the following technical and organizational measures, consistent with Art. 32 GDPR and Section 6 of this Agreement:
Encryption: Personal data in transit is encrypted using TLS. For Applications hosted on the Processor’s own infrastructure, all data at rest is encrypted under AWS key management — personal data under AWS-managed KMS keys, other data under provider-owned keys; queues holding Customer Data pending processing are KMS-encrypted at rest, while queues carrying only a non-personal routing event (an account identifier and the notification type to be dispatched) use provider-default encryption. For Applications hosted on monday code, encryption at rest and key management are performed by monday.com under its Developer Storage infrastructure (SOC 2 and ISO 27001 certified).
Minimization through architecture (no persistent storage, narrow diagnostic exception): Customer Data is processed transiently and is not stored beyond the time required to complete each operation — materially limiting the volume of data at rest — save for consented diagnostic logging, which is scoped by filter (board, item, automation) and purged after 90 days.
Access control: Access to customer data is restricted to authorized personnel on a need-to-know, least-privilege basis. Authorized personnel are bound by confidentiality obligations (Section 3.2).
Pseudonymization: Where feasible, account-level usage metrics are aggregated and not used to identify individual data subjects.
Logging and accountability: Automation execution is logged by account, board, automation ID, and executing user to support auditability (retained 90 days).
Breach detection and response: The Processor maintains procedures for detecting, reporting, and investigating personal data breaches, including notification to the Controller within 72 hours of becoming aware (Section 3.6).
Measures for transfers to sub-processors: Sub-Processors are bound by data protection terms equivalent to those in this Agreement and maintain their own Art. 46 transfer safeguards (Annex III; Section 3.4).
The Processor may update these measures from time to time provided the level of protection is not materially reduced.
The Controller has authorized the engagement of the Sub-Processors identified in the Processor’s current Customer Data sub-processor list, published at carbonapps.co/legal/apps/subprocessors. This Annex covers only Sub-Processors engaged to process Customer Data. As of the date of this Agreement these are: Amazon Web Services, Inc. (United States), the Processor’s cloud infrastructure provider for Applications hosted on the Processor’s own infrastructure; and monday.com Ltd (Israel), the platform’s developer-hosting sub-processor for Applications hosted on monday code, relying on the Israel adequacy decision with monday.com’s own onward transfer safeguards. The list is the authoritative record and specifies, for each Sub-Processor, its name, the processing it performs on the Controller’s behalf, its location, and the transfer mechanism it relies on.
Third parties involved in processing account, marketing, or operational data (for which the Processor and Carbon Web Print LLC act as joint controllers) are not Customer Data Sub-Processors and are disclosed separately in the Privacy Policy.
The Processor notifies the Controller of any intended addition or replacement of a Customer Data Sub-Processor in accordance with Clause 9 of the EU SCCs and Section 3.4 of this Agreement (at least 14 days’ prior notice), enabling the Controller to object.
For Restricted Transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the Information Commissioner under S119A(1) of the Data Protection Act 2018 and in force from 21 March 2022 (the “UK Addendum”), applies to and amends the EU SCCs in Schedule 1. The full text is available at https://ico.org.uk/media/for-organizations/documents/4019539/international-data-transfer-addendum.pdf and is deemed incorporated. Where the UK Addendum conflicts with the EU SCCs, the UK Addendum prevails for UK transfers.
Table 1 — Parties: As set out in Annex I.A of Schedule 1 (Exporter: the Controller; Importer: the Processor).
Table 2 — Selected SCCs, Modules and Clauses: The EU SCCs incorporated in Schedule 1, Module Two (Controller to Processor), as configured in Section 2 of Schedule 1, including the Clause 9 Option 2 general authorization (14 days) and the Clause 11 selection.
Table 3 — Appendix Information: As set out in Annexes I, II, and III of Schedule 1.
Table 4 — Ending this Addendum when the Approved Addendum changes: The Importer may end this Addendum as set out in Section 19 of the UK Addendum’s Mandatory Clauses — that is, where the Information Commissioner issues a revised Approved Addendum that, as a direct result of the change, would have a substantial, disproportionate and demonstrable increase in the Importer’s cost or risk and the parties cannot agree a variation. The Exporter does not hold that right.
For UK transfers, references in the EU SCCs to the GDPR are read as references to the UK GDPR; the governing law is the law of England and Wales; the competent courts are the courts of England and Wales; and the competent supervisory authority is the Information Commissioner’s Office.
For Restricted Transfers subject to the Swiss Federal Act on Data Protection (FADP), the EU SCCs in Schedule 1 apply with the following amendments, consistent with the guidance of the Swiss Federal Data Protection and Information Commissioner (FDPIC):
(a) Supervisory authority: The competent supervisory authority in Annex I.C is the FDPIC insofar as the transfer is governed by the FADP. Where a transfer is subject to both the GDPR and the FADP, the EDPB-route supervisory authority applies to the GDPR-governed part and the FDPIC to the FADP-governed part.
(b) Applicable law: References to the GDPR are to be understood as references to the FADP insofar as the transfer is governed by Swiss law.
© References to Member States: The term “Member State” must not be interpreted in a way that excludes data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland), in accordance with Clause 18© of the EU SCCs.
(d) Legal entities: Until the entry into force of the revised FADP, the EU SCCs also protected the personal data of legal entities. The revised FADP (in force since 1 September 2023) protects the personal data of natural persons only; to the extent any residual protection of legal-entity data is required for transfers concerning periods before that date, the EU SCCs are read accordingly.
For Swiss transfers, the governing law is Swiss law where required by the FADP, and the competent courts are the Swiss courts insofar as permitted.