Legal
Last updated: 9 July 2026
Placeholder content, pending legal review
This page is a structural draft. Nothing here is binding or final. The definitive wording is being prepared by our content team and will be published once legal review is complete.
This Data Processing Addendum ("DPA") forms part of the agreement between Workoid Ltd. ("Workoid", "Processor") and the client ("Client", "Controller") for the provision of Workoid services (the "Agreement"). It applies where Workoid processes personal data on the Client's behalf. For clarity, the talent Workoid provides are vetted independent contractors engaged by Workoid, not employees of Workoid or of the Client.
Terms such as "personal data", "processing", "controller", "processor", and "data subject" have the meanings given in applicable data-protection law, including the GDPR where it applies.
The Client is the controller of the personal data it provides or makes accessible to Workoid. Workoid acts as processor and processes that personal data only on the Client's documented instructions, including as set out in the Agreement.
Workoid processes personal data for the duration of the Agreement and only to provide the services. The subject matter, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex A.
Workoid will:
The Client authorizes Workoid to engage subprocessors to help deliver the services. A current list of subprocessors is available at [P: subprocessor list location]. Workoid will inform the Client of any intended change to its subprocessors and give the Client a reasonable opportunity to object. Workoid remains responsible for its subprocessors' compliance with this DPA.
Workoid operates as a distributed business, and personal data may be processed in Hong Kong, the European Union, and the countries where its talent and subprocessors are located. Where personal data is transferred across borders, Workoid puts appropriate safeguards in place, including [P: transfer mechanism, e.g. Standard Contractual Clauses].
Workoid maintains the technical and organizational measures set out in Annex B, which reflect the security controls described on the Workoid Security page, including encrypted company devices, restricted administrator access, cloud-only storage, enterprise password management, and two-factor authentication.
Workoid will notify the Client without undue delay, and in any event within [P: breach-notification timeframe], after becoming aware of a personal data breach affecting the Client's personal data, and will provide reasonable information to help the Client meet its own notification obligations.
On termination of the Agreement, Workoid will delete or return the Client's personal data, at the Client's choice, except where retention is required by law.
Workoid will, on reasonable request and notice, make available information necessary to demonstrate compliance with this DPA, and allow for audits in line with the terms of the Agreement.
This DPA is governed by the law of the Agreement, being the laws of Hong Kong.
The finalized text for this section will be supplied by our content team following legal review.
The finalized text for this section will be supplied by our content team following legal review.