Data Processing Agreement
Last Updated:
1. Introduction
This Data Processing Agreement ("DPA") forms part of the agreement between Pineway Labs, Inc. ("Pineway," "we," "us," or "our") and the customer entity that uses Pineway's services ("Customer," "you," or "your") (the "Agreement"). By using the Services, Customer agrees to this DPA.
This DPA sets out the terms on which Pineway processes personal data on behalf of Customer. It supplements our Privacy Policy. Capitalized terms not defined here have the meanings given in the Agreement or applicable Data Protection Laws.
2. Definitions
- Customer Personal Data: Personal Data processed by Pineway on behalf of Customer in connection with the Services (for example, data about Customer's end users, clients, or session participants that Customer submits to or generates through Pineway).
- Data Protection Laws: Applicable laws relating to privacy and the processing of Personal Data, including the EU GDPR, UK GDPR, UK Data Protection Act 2018, Swiss FADP, and applicable U.S. state privacy laws (including the CCPA/CPRA), as updated from time to time.
- Personal Data, Controller, Processor, Data Subject, Personal Data Breach, and processing have the meanings given in the GDPR (or equivalent terms under other Data Protection Laws).
- Services: The Pineway platform and related products and features provided under the Agreement.
- Sub-processor: A third party engaged by Pineway to process Customer Personal Data in connection with the Services.
- EU SCCs: The Standard Contractual Clauses approved by European Commission Decision 2021/914.
- UK Addendum: The UK International Data Transfer Addendum to the EU SCCs issued by the ICO.
3. Roles and Scope
With respect to Customer Personal Data, Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Pineway is the Processor (or Sub-processor), except as described below.
Pineway acts as an independent Controller for account, billing, security, support, and product-operations data that relates to Customer's relationship with Pineway (for example, login credentials, subscription status, and service usage needed to operate and secure the platform). That processing is described in our Privacy Policy and is outside the processor obligations in this DPA, except where Data Protection Laws require otherwise.
Customer is responsible for the lawfulness of Customer Personal Data provided to Pineway, including providing any required notices and obtaining any required consents.
4. Details of Processing
Subject matter and nature: Providing the Services, including marketplace transactions, scheduling, session tooling, transcription and AI-assisted features, communications, and related support.
Purpose: Processing Customer Personal Data only to provide the Services, comply with Customer's documented instructions, and meet Pineway's obligations under the Agreement and this DPA.
Duration: For the term of the Agreement and any post-termination retention period required to return or delete data, or as otherwise required by law.
Categories of Data Subjects: Customer's personnel, end customers, clients, session participants, and other individuals whose Personal Data Customer submits to the Services.
Categories of Personal Data: Identifiers (such as name and email), account and profile information, booking and transaction details, communications content, session recordings/transcripts where enabled, and other data Customer chooses to submit to the Services.
Special categories: Pineway does not require special-category data to provide the Services. Customer shall not upload such data unless the Agreement expressly permits it and Customer has a lawful basis under Data Protection Laws.
5. Pineway's Obligations
Pineway will:
- Process Customer Personal Data only on documented instructions from Customer, including with regard to transfers, unless required to do so by applicable law (in which case Pineway will inform Customer unless prohibited).
- Ensure persons authorized to process Customer Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organizational measures to protect Customer Personal Data, taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing.
- Not sell Customer Personal Data, and not retain, use, or disclose it for purposes other than providing the Services, except as permitted by Data Protection Laws (including as a "service provider" under the CCPA/CPRA where applicable).
- Notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide information reasonably available to assist Customer with its notification obligations.
- Provide reasonable assistance to Customer with Data Subject requests, data protection impact assessments, and consultations with supervisory authorities, taking into account the nature of processing and information available to Pineway.
- Upon termination of the Services, and at Customer's choice where technically feasible, delete or return Customer Personal Data, except where retention is required by law.
6. Data Subject Requests
If Pineway receives a request from a Data Subject relating to Customer Personal Data, Pineway will, to the extent legally permitted, promptly notify Customer and will not respond except on Customer's instructions or as required by law. Customer is responsible for responding to such requests. Pineway will provide reasonable assistance through the functionality of the Services where available.
7. Security and Audits
Pineway maintains technical and organizational measures appropriate to the risk, including encryption in transit, access controls based on least privilege, monitoring, and vendor diligence for Sub-processors. Primary application data is stored in the European Union (Zurich and Frankfurt), as described in our Privacy Policy.
Upon reasonable written request at appropriate intervals, and subject to confidentiality, Pineway will make available information reasonably necessary to demonstrate compliance with this DPA. Where required by Data Protection Laws and certifications or reports are insufficient, Customer may request an audit no more than once per twelve (12) month period, on at least thirty (30) days' notice, during business hours, and in a manner that minimizes disruption. Customer bears the cost of such audits unless a material non-compliance attributable to Pineway is found.
8. International Transfers
Customer acknowledges that providing the Services may involve transfers of Customer Personal Data to countries outside the EEA, United Kingdom, or Switzerland. Where such transfers are not covered by an adequacy decision, Pineway relies on Appropriate Safeguards, including the EU SCCs and, where applicable, the UK Addendum, and/or equivalent mechanisms under Data Protection Laws.
Where Module Two (Controller to Processor) of the EU SCCs applies, Option 2 (general written authorization) applies for sub-processing, with prior notice as set out in Section 9. The details of processing and Sub-processors in this DPA serve as the relevant annex information for those Clauses.
9. Sub-processors
Customer authorizes Pineway to engage Sub-processors to process Customer Personal Data as needed to provide the Services. The current list of authorized Sub-processors is set out in Section 10 below. Customer provides general written authorization for Pineway to update that list.
Pineway will enter into a written agreement with each Sub-processor imposing data-protection obligations no less protective than those in this DPA. Pineway remains liable to Customer for the Sub-processor's performance of those obligations.
Pineway will update this page when engaging a new Sub-processor. Where required by Data Protection Laws, Pineway will provide at least thirty (30) days' prior notice (including by updating this page and, where Customer has subscribed to notices, by email). Customer may object in writing on reasonable data-protection grounds within thirty (30) days of notice. If Pineway cannot provide a commercially reasonable alternative, Customer may discontinue the affected Service. Objection to an essential Sub-processor may prevent Pineway from providing the Services.
To subscribe to Sub-processor change notices, email hello@pineway.io with the subject line "Subscribe: Sub-processor notices."
10. Authorized Sub-processors
As of the Last Updated date above, Pineway uses the following Sub-processors in connection with the Services:
| Company | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, and file storage | European Union (Zurich) |
| Fly.io, Inc. | Application hosting and compute | European Union (Frankfurt) |
| OpenAI OpCo, LLC | Artificial intelligence and model inference | United States |
| Deepgram, Inc. | Speech-to-text and meeting transcription | United States |
| PostHog, Inc. | Product analytics, error monitoring, and feature flagging | European Union |
| Trigger.dev, Inc. | Background jobs and workflow processing | United States |
| Stripe, Inc. / Stripe Payments Europe, Limited | Payment processing and payouts | United States / European Economic Area |
| Paystack (a Stripe company) | Payment processing and payouts | Nigeria / United States |
| Cloudflare, Inc. | Bot protection (Turnstile) and edge security | Global |
| Google LLC | Authentication (Google Sign-In), Google Calendar, and Google Meet | United States / Global |
| Apple Inc. / Apple Distribution International Limited | Apple Calendar (iCloud) scheduling and availability sync | United States / Global |
| Zoom Communications, Inc. | Video conferencing | United States |
| Resend, Inc. | Transactional email delivery | United States |
| Peaberry Software, Inc. (Customer.io) | Marketing and lifecycle email | United States |
Self-hosted tools operated solely on Pineway-controlled infrastructure (notifications, search, and blog) are not listed as external Sub-processors.
11. Term, Liability, and Precedence
This DPA remains in effect for as long as Pineway processes Customer Personal Data under the Agreement. Liability arising under this DPA is subject to the limitations and exclusions in the Agreement.
In the event of conflict, the following order of precedence applies: (1) the EU SCCs / UK Addendum (where applicable); (2) this DPA; (3) the Agreement; (4) the Privacy Policy.
12. Contact
Questions about this DPA or our Sub-processors can be sent to hello@pineway.io.