Version Date: 8.17.2026
This Data Processing Addendum ("DPA") governs the Processing of Customer Personal Data by Bind Data LLC ("Bind") on behalf of a customer ("Customer") in connection with services provided by Bind under a written agreement between Bind and Customer (the "Agreement").
This DPA forms part of the Agreement only if:
The version of this DPA identified in or attached to the applicable Agreement will govern that Agreement. Publication of a later version on Bind's website does not amend an existing Agreement unless the Agreement expressly provides otherwise or the parties agree to the amendment in writing.
Merely viewing this DPA on Bind's public website does not create a contractual relationship.
This DPA does not govern personal information Bind collects for its own purposes through its public marketing website.
"Applicable Data Protection Law" means a privacy, data protection, or data security law applicable to Bind's Processing of Customer Personal Data under the Agreement.
"Customer Data" has the meaning assigned in the Agreement and includes data, content, credentials, authorizations, and other information provided or made available by or on behalf of Customer in connection with the Services.
"Customer Personal Data" means Personal Data contained in Customer Data that Bind Processes on behalf of Customer in providing the Services.
"Customer-Controlled Platform" means a third-party software platform, application, or system that Customer separately selects, licenses, contracts for, administers, or otherwise controls, and to or from which the Services transfer data at Customer's direction — except to the extent Bind separately engages the operator of that platform to Process Customer Personal Data on Bind's behalf, in which case that operator is a Subprocessor with respect to that Processing. Customer's having a direct agreement with a platform operator does not by itself prevent that operator from being a Subprocessor.
"European Data Protection Law" means, to the extent applicable to the relevant Processing:
"Personal Data" means information relating to an identified or identifiable individual or information otherwise defined as "personal data," "personal information," or a substantially similar term under Applicable Data Protection Law.
"Process" and "Processing" mean an operation performed on Personal Data, including receiving, accessing, transmitting, transferring, synchronizing, mapping, transforming, organizing, storing, retrieving, using, disclosing, securing, or deleting Personal Data.
"Security Incident" means a breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data Processed by Bind.
A Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, such as unsuccessful login attempts, network scans, pings, or unsuccessful attacks.
"Services" means the software integration, middleware, platform, implementation, support, or related services Bind provides to Customer under the Agreement.
"Subprocessor" means a third party engaged by Bind to Process Customer Personal Data on Bind's behalf in connection with the Services.
A Customer-Controlled Platform is not a Subprocessor, and its operator is not a Subprocessor, merely because the Services interoperate with, connect to, or exchange data with that platform.
Terms including "Controller," "Processor," "Business," "Service Provider," "Contractor," "Consumer," "Sell," and "Share" have the meanings assigned under the Applicable Data Protection Law that uses those terms.
Where Customer determines the purposes and means of Processing Customer Personal Data, Customer acts as the Controller or Business and Bind acts as the Processor, Service Provider, or Contractor, as applicable.
Where Customer Processes Customer Personal Data on behalf of another Controller or Business, Customer acts as a Processor or Service Provider and Bind acts as Customer's Subprocessor.
This DPA does not apply to Personal Data Bind Processes independently for its own legitimate business purposes, such as:
except where Applicable Data Protection Law requires otherwise.
Bind will Process Customer Personal Data only:
Bind will not Process Customer Personal Data for a materially unrelated purpose except as authorized by Customer or permitted by Applicable Data Protection Law.
If Bind reasonably believes an instruction violates Applicable Data Protection Law, Bind may notify Customer and suspend the affected Processing until the parties resolve the issue, except where applicable law prohibits Bind from doing so.
To the extent Bind Processes Customer Personal Data as a Processor, Service Provider, or Contractor under an applicable U.S. state privacy law, Bind will:
Bind will require each applicable Subprocessor to protect Customer Personal Data through written contractual obligations as required by Applicable Data Protection Law.
Customer is responsible for:
Customer will not instruct Bind to Process Customer Personal Data in violation of Applicable Data Protection Law.
Bind will ensure that personnel authorized to Process Customer Personal Data:
Bind will implement and maintain commercially reasonable administrative, technical, and organizational measures designed to protect Customer Data within Bind's possession or control against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access.
Bind is responsible for the security of systems, environments, configurations, credentials, and transmission practices under Bind's control.
Bind does not guarantee the independent security, availability, or operation of a Customer-Controlled Platform or any other third-party platform outside Bind's control.
Bind may update its security measures as technology, threats, and the Services change, provided that Bind will not materially decrease the overall level of protection applied to Customer Personal Data during the applicable service term.
The categories of security measures maintained by Bind are described in Schedule 2.
Bind will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.
To the extent information is reasonably available to Bind, Bind will provide information regarding:
Bind may provide information in phases as additional information becomes available.
For a Security Incident originating with a Subprocessor or a Customer-Controlled Platform, Bind's notice and subsequent information may be based on information provided by that third party or otherwise reasonably available to Bind. Bind will not delay an initial notice solely because complete information is unavailable.
Bind will reasonably cooperate with Customer in mitigating a Security Incident.
Customer is responsible for determining whether a Security Incident requires notice or reporting to an individual, employee, regulator, governmental authority, or other third party and for making such notice or report, except to the extent applicable law expressly requires Bind to provide it directly.
Bind's notice of a Security Incident does not constitute an admission of fault or liability.
Customer provides Bind with general authorization to engage Subprocessors in connection with the Services.
Bind will:
Where Applicable Data Protection Law requires advance notice of a new or replacement Subprocessor, Bind will provide Customer with reasonable advance notice.
Customer may object to the new Subprocessor on reasonable and documented data-protection grounds within fifteen (15) days after receiving such notice.
The parties will work in good faith to address a valid objection. If Bind cannot reasonably accommodate the objection, Bind may provide an alternative where commercially reasonable. If no reasonable alternative is available, the parties may exercise any applicable rights under the Agreement with respect to the affected Services.
Bind does not guarantee the independent availability, performance, or security of any Subprocessor or Customer-Controlled Platform, and Bind is not liable for the independent acts or omissions of the operator of a Customer-Controlled Platform.
Bind remains responsible for Bind's own acts and omissions, including its selection of Subprocessors and its configuration, instructions, credential handling, and transmission practices.
Bind is responsible for the performance of a Subprocessor's data-protection obligations only to the extent required by Applicable Data Protection Law or expressly provided in the Agreement.
All responsibility of Bind under this Section is subject to the limitations and exclusions of liability contained in the Agreement to the fullest extent permitted by applicable law.
Taking into account the nature of the Processing, Bind will provide reasonable assistance to Customer in responding to legally valid requests by individuals exercising rights under Applicable Data Protection Law.
If Bind receives a request directly from an individual concerning Customer Personal Data, Bind will ordinarily:
Customer is responsible for determining whether and how a request should be fulfilled.
Taking into account the nature of the Processing and information available to Bind, Bind will provide reasonable assistance to Customer with obligations applicable to Customer involving:
Bind may charge Customer at Bind's then-current professional-services rates for extraordinary assistance that materially exceeds the ordinary operation of the Services, unless the assistance is required because of Bind's breach of the Agreement or this DPA.
Customer remains responsible for retrieving any Customer Data it requires before termination of the applicable Services.
Upon termination or expiration of Services involving Customer Personal Data:
Where Applicable Data Protection Law requires Customer to have the choice between return and deletion, Bind will return or delete Customer Personal Data as Customer directs, subject to any retention required by applicable law.
Customer Personal Data retained in backups or because of a legal obligation will remain protected under this DPA and will not be actively Processed except for recovery, security, legal compliance, or other purposes permitted by Applicable Data Protection Law.
Bind will make information reasonably necessary to demonstrate compliance with this DPA available to Customer.
Where reasonably sufficient, Bind may satisfy a request by providing:
If the information provided is not reasonably sufficient to satisfy an applicable legal requirement, Customer may request an additional audit concerning Bind's relevant Processing activities.
Except to the extent Applicable Data Protection Law or a competent regulatory authority requires otherwise, any audit under this Section is limited to systems, environments, records, and Processing activities under Bind's control. With respect to a Subprocessor or a Customer-Controlled Platform, Bind's obligation is limited to providing compliance information Bind holds or can reasonably obtain from that third party, and this Section does not grant Customer a right to audit any third party.
Unless otherwise required by Applicable Data Protection Law, a regulator, or a material Security Incident affecting Customer Personal Data:
If an audit identifies material noncompliance with this DPA, Bind will take commercially reasonable corrective action.
This Section applies only to the extent European Data Protection Law applies to Bind's Processing of Customer Personal Data.
Bind will:
If Bind reasonably believes a Customer instruction infringes applicable European Data Protection Law, Bind will notify Customer unless legally prohibited from doing so.
Where the EU GDPR applies, Customer grants Bind general written authorization to use Subprocessors subject to Section 9.
Bind will impose on each applicable Subprocessor data-protection obligations substantially equivalent to the obligations required under Article 28 of the EU GDPR with respect to the Processing delegated to that Subprocessor.
Where and to the extent European Data Protection Law so requires, Bind remains responsible to Customer for the performance of that Subprocessor's data-protection obligations. This paragraph applies only to Processing subject to European Data Protection Law, and any resulting liability remains subject to the limitations and exclusions of liability contained in the Agreement to the fullest extent permitted by applicable law.
Neither party will knowingly transfer Customer Personal Data subject to European Data Protection Law in violation of applicable international-transfer requirements.
If a transfer from the European Economic Area to Bind requires an approved transfer mechanism, the parties will implement the then-applicable European Commission Standard Contractual Clauses or another valid transfer mechanism.
If a transfer subject to UK data protection law requires an approved transfer mechanism, the parties will implement the then-current International Data Transfer Agreement, International Data Transfer Addendum, or another valid mechanism approved under UK law.
The parties will reasonably cooperate to complete information required for an applicable transfer mechanism, including information contained in the schedules to this DPA.
This DPA does not itself constitute an international data-transfer mechanism. Where an approved transfer mechanism is required, the parties will execute or incorporate the applicable transfer terms before the restricted transfer occurs.
This DPA does not create or constitute a restricted international transfer where one would not otherwise exist.
If Bind receives a legally binding demand from a governmental or law-enforcement authority seeking Customer Personal Data, Bind will, to the extent legally permitted:
The liability of each party arising from or relating to this DPA, Customer Personal Data, a Security Incident, or Processing performed under the Agreement is subject to the exclusions and limitations of liability contained in the Agreement.
Any defense costs, attorneys' fees, settlements, judgments, notification or remediation costs, refunds, credits, or other monetary amounts arising under this DPA will be treated in accordance with the Agreement's liability provisions.
This DPA does not create a separate or additional liability cap. If the Agreement does not contain a limitation of liability, then to the maximum extent permitted by applicable law each party's total aggregate liability arising from or relating to this DPA will not exceed the fees paid or payable by Customer under the Agreement in respect of the twelve (12) months preceding the first event giving rise to the claim.
Nothing in this DPA limits liability to the extent a limitation is prohibited by Applicable Data Protection Law.
This DPA becomes effective when it is incorporated into or executed as part of the Agreement.
It remains in effect for as long as Bind Processes Customer Personal Data subject to the DPA.
Obligations that by their nature must continue after termination, including confidentiality, security, deletion, and applicable international-transfer obligations, survive for as long as Bind retains the relevant Customer Personal Data.
Except as modified by this DPA, the Agreement remains unchanged.
If this DPA conflicts with the Agreement concerning the Processing or protection of Customer Personal Data, this DPA controls to the extent of the conflict.
Notwithstanding the foregoing, the Agreement's limitations and exclusions of liability continue to apply as provided in Section 16.
If a mandatory international-transfer mechanism conflicts with this DPA or the Agreement, the mandatory transfer mechanism controls with respect to the Processing within its scope.
Except where Applicable Data Protection Law or a mandatory international-transfer mechanism requires otherwise, this DPA is governed by the governing-law and dispute-resolution provisions of the Agreement.
Questions regarding this DPA or Bind's Processing of Customer Personal Data may be sent to Bind Data LLC at privacy@trybind.com.
Processing of Customer Personal Data as necessary for Bind to establish, configure, operate, maintain, monitor, support, troubleshoot, and secure the Services described in the Agreement and applicable statement of work.
For the period during which Bind provides the applicable Services, plus the limited post-termination period during which Bind retains Customer Personal Data in accordance with the Agreement, this DPA, or applicable law.
Depending on Customer's Services and configuration, Processing may include:
Depending on Customer's systems and use of the Services, data subjects may include:
Depending on Customer's configuration, connected systems, and applicable statement of work, Customer Personal Data may include:
Depending on Customer's configuration, Customer Personal Data may include payroll, employment, financial, authentication, or other information treated as sensitive under Applicable Data Protection Law.
Customer will not use the Services to Process categories of sensitive or specially regulated information outside the agreed scope without Bind's prior written agreement where additional safeguards are reasonably required.
Continuous, recurring, or periodic, depending on Customer's configuration and use of the Services.
Bind will maintain commercially reasonable technical and organizational safeguards appropriate to the nature of the Services, Customer Personal Data, and risks associated with the Processing.
Those safeguards will address, as appropriate:
This Schedule does not represent that every security measure is applicable to every component of the Services.
Specific certifications, encryption implementations, recovery objectives, penetration-testing commitments, or other detailed technical requirements are binding only if expressly stated in the Agreement, a security exhibit, or other written document incorporated into the Agreement.
Bind engages a limited number of Subprocessors to support the Services. Depending on the particular Services purchased and the systems Customer elects to connect, these may include providers in the following categories:
The Subprocessors applicable to a particular Customer's Services depend on that Customer's configuration and connected systems. Not every category above applies to every deployment.
Bind maintains a current list of the material Subprocessors applicable to a Customer's Services and will provide that list to Customer on written request to privacy@trybind.com, subject to the confidentiality obligations in the Agreement.
Bind may add or replace Subprocessors in accordance with Section 9 of this DPA.
A Customer-Controlled Platform, including a platform that Customer separately licenses or contracts for, is not a Bind Subprocessor merely because the Services connect to that platform.