(GDPR / UK GDPR / Swiss FADP / U.S. State Privacy Law Addendum)
Effective: July 1, 2026
This Data Processing Addendum, including its exhibits and appendices (the “Addendum” or “DPA“), is entered into between OAD, LLC, operating as OAD (“OAD,” “we,” “us,” or “Processor“), with a registered address at N24 W30953 Fairway Court, Pewaukee, WI 53072, USA, and the entity or individual accepting OAD’s Platform Terms of Service (the “Client,” “you,” or “Controller“) (each a “Party” and together the “Parties“).
This Addendum is incorporated by reference into, and forms an integral part of, OAD’s Platform Terms of Service (the “Platform Terms“), which govern Client’s subscription to and use of the OAD behavioral assessment platform and related services (the “Platform“). This Addendum takes effect automatically upon Client’s acceptance of the Platform Terms, without further action by either Party, and continues for as long as OAD Processes Personal Data on Client’s behalf.
Where there is a conflict between this Addendum and the Platform Terms, this Addendum will prevail, except with respect to the Disclaimer and Limitation of Liability provisions of the Platform Terms, which will prevail. Where there is a conflict between this Addendum and the Standard Contractual Clauses (“SCCs“) incorporated in Exhibit B, the SCCs shall prevail. This Addendum is intended to operate consistently with, and should be read alongside, OAD’s Acceptable Use Policy, Anti-Spam Policy, and Cookie Notice (together with this Addendum and the Privacy Notice, the “Related Policies“), each of which is incorporated into the Platform Terms and cross-referenced where relevant below.
For the purposes of interpreting this Addendum, the following terms (and their cognates) have the meanings set out below:
The terms “Controller,” “Data Protection Assessment,” “Data Subject,” “Member State,” “Personal Data Breach,” “Processing,” “Processor,” “Rights of the Data Subject,” “Supervisory Authority,” and “Third Country” have the meanings given under Applicable Data Protection Laws, and cognate terms shall be construed accordingly. Capitalized terms not defined herein have the meaning given in the Platform Terms.
AD will act as a Processor (or, where Client is itself a processor of the relevant Personal Data, as a Sub-Processor) of Personal Data Processed in connection with the Platform. Client will act as the Controller (or processor) of that Personal Data, including with respect to its Survey Subjects and Contacts.
OAD shall:
Full details of the Processing are set out in Exhibit A. Client instructs OAD (and authorizes OAD to instruct each Sub-Processor) to Process, and where necessary transfer, Personal Data only as reasonably necessary to provide the Platform and consistent with the Platform Terms and this Addendum.
Compliance and Safety Review. Client’s instructions under this Section 3 include authorization for OAD to access, review, and, where necessary, remove or restrict Content (including Personal Data) to the extent reasonably necessary for OAD to enforce its Acceptable Use Policy and Anti-Spam Policy, investigate a reported violation, or otherwise comply with its legal obligations, consistent with Section “OAD’s Rights” of the Acceptable Use Policy. This authorization does not expand OAD’s role beyond that of a Processor and does not permit OAD to use Personal Data for any independent purpose of its own.
OAD does not knowingly collect or Process protected health information subject to HIPAA through the Platform. Client shall not submit any such information to the Platform, and OAD’s obligations under this Addendum do not extend to HIPAA-regulated data. Consistent with OAD’s Acceptable Use Policy, Client shall also not submit government identification numbers, payment card numbers, account passwords, or other sensitive identifiers as Content unless Client has obtained the consent required to do so and such data is reasonably necessary to provide the Platform.
Automated Decision-Making. The Platform generates behavioral and personality assessment outputs that Client may use as one input into its own decisions concerning Survey Subjects. OAD does not itself make, and the Platform is not designed to make, any decision producing legal or similarly significant effects concerning a Survey Subject, including any hiring, promotion, or other employment decision. As between the Parties, Client is solely responsible for: (i) determining whether and how to use assessment outputs in any decision concerning a Survey Subject; (ii) ensuring that no such decision is based solely on automated Processing where prohibited by Applicable Data Protection Laws; (iii) implementing any human review, meaningful oversight, or safeguards required under Applicable Data Protection Laws; and (iv) providing Survey Subjects with the information and rights required under Article 22 of the GDPR and equivalent provisions of Applicable Data Protection Laws, including the right to obtain human intervention, to express their point of view, and to contest a decision. Taking into account the nature of the Processing, OAD will provide Client with reasonably available information regarding the general logic of the assessment methodology to assist Client in meeting its transparency obligations, subject to OAD’s trade secrets and intellectual property rights.
Service Improvement and Model Development.
(a) OAD may use data derived from the Processing to develop, train, test, evaluate, and improve OAD’s assessment methodologies, models, algorithms, and the Platform, provided that such use is limited to Anonymized Data and/or Aggregated Data.
(b) “Anonymized Data” means data that has been irreversibly altered such that no natural person is identifiable, directly or indirectly, by any party using means reasonably likely to be used, and that therefore does not constitute Personal Data. “Aggregated Data” means data combined across multiple Survey Subjects and/or Clients such that it does not identify, and cannot reasonably be used to identify, any individual, Client, or Survey Subject.
(c) OAD’s creation of Anonymized Data and Aggregated Data from Personal Data is a Processing activity carried out on Client’s documented instructions under Section 3. Once data has been Anonymized in accordance with paragraph (b), it falls outside the scope of Applicable Data Protection Laws and this Addendum, and OAD may retain and use it without limitation for the purposes in paragraph (a).
(d) OAD shall not use Personal Data that has not been Anonymized to develop or train models except where OAD has established a valid legal basis to do so as an independent Controller and the information required under Applicable Data Protection Laws has been provided to the relevant Survey Subjects. Where OAD acts as an independent Controller under this paragraph, it does so under the OAD Privacy Notice and not under this Addendum.
(e) Client may opt out of the use of Aggregated Data derived from its Personal Data for the purposes in paragraph by written notice to privacy@oad.ai. OAD will give effect to such opt-out on a going-forward basis within a reasonable period.
OAD shall take reasonable steps to ensure:
Taking into account the nature of the Processing, OAD shall assist Client, through appropriate technical and organizational measures insofar as reasonably possible, to respond to valid requests to exercise the Rights of Data Subjects under Applicable Data Protection Laws.
With respect to such requests, OAD shall:
Notwithstanding the foregoing, if Client is subject to EU Data Protection Law (as defined in Exhibit B), Client acknowledges and agrees that it has given OAD prior written authorization to respond, at OAD’s discretion, directly to any data subject access request OAD receives from a Survey Subject or Contact under EU Data Protection Law, or, alternatively, OAD may direct such individual to Client so that Client can respond to the request.
Objections via unsubscribe. Where a Contact exercises a right to object to processing by unsubscribing from an assessment invitation or other communication, Client remains responsible, consistent with the Anti-Spam Policy, for actively managing and processing that unsubscribe request within ten (10) days of submission (or such shorter period as Applicable Data Protection Laws require) and for updating its own lists accordingly. OAD’s role is limited to providing the unsubscribe mechanism and honoring Client’s resulting instructions within the Platform.
OAD shall provide Client with reasonably available information and assistance to help Client comply with its own obligations to carry out data protection impact assessments and, where required, prior consultations with Supervisory Authorities — limited to Personal Data Processed by OAD and its Sub-Processors, and taking into account the nature of the Processing and information reasonably available to OAD. OAD may charge Client a reasonable fee for such assistance where it is not commercially reasonable to provide it without charge, and will provide an estimate of any applicable fees in advance.
OAD shall make available to Client information reasonably necessary to demonstrate compliance with this Addendum and shall allow for and contribute to audits, including remote inspections, conducted by Client or an auditor mandated by Client, of OAD’s Processing of Personal Data. OAD may require reasonable advance notice, may limit the frequency of on-site audits to once per twelve-month period (absent a Personal Data Breach or regulatory requirement), and may charge Client for time expended on any audit at OAD’s then-current professional services rates. Where OAD makes available a current third-party audit report or certification evidencing the implementation and effectiveness of its technical and organizational measures, OAD may satisfy an audit request by providing such report or certification in lieu of an on-site audit, save where an on-site audit is required following a Personal Data Breach or by a Supervisory Authority. OAD may require any auditor mandated by Client to enter into an appropriate confidentiality undertaking before the audit, and may object to an auditor that is a competitor of OAD or is otherwise not suitably independent, in which case Client shall appoint an alternative auditor.
To the extent OAD Processes Personal Data originating from or protected by the Applicable Data Protection Laws of a jurisdiction listed in Exhibit B, the corresponding Jurisdiction Specific Terms apply in addition to this Addendum.
OAD confirms that it does not receive Personal Data as consideration for any part of the Platform. As between Client and OAD, Client retains all rights and interests in Personal Data relating to its Survey Subjects and Contacts as against OAD’s role as Processor. OAD shall not “sell” or “share” such Personal Data as those terms are defined under Applicable Data Protection Laws.
OAD may host the Sub-Processor List and the content of the exhibits and appendices to this Addendum online in OAD’s Legal and Policy Center and may update them from time to time, provided that prior notice is given to Client. If no objection is received within fourteen (14) days of such notice, Client is deemed to have consented. If Client objects and the Parties cannot reach a mutually agreeable resolution, Client may terminate the Platform Terms upon written notice, with no further Fees due other than those already accrued. Where hosted online, the latest published version of an exhibit or appendix takes precedence over the version reproduced in this Addendum.
Subject to Applicable Data Protection Laws, each Party’s liability under this Addendum is subject to the exclusions and limitations of liability set out in the Platform Terms.
Details
OAD (Data Importer / Processor)
OAD, LLC, N24 W30953 Fairway Court, Pewaukee, WI 53072, USA
Data Protection Contact — OAD
Privacy Team, privacy@oad.ai
EU Representative
European Data Protection Office (EDPO), Avenue Huart Hamoir 71, 1030 Brussels, Belgium — https://edpo.com/gdpr-data-request/
UK Representative
EDPO UK Ltd, 8 Northumberland Avenue, London WC2N 5BY, United Kingdom — https://edpo.com/uk-gdpr-data-request/
Client (Data Exporter / Controller)
Client’s legal entity name as provided on its OAD Account
Data Protection Contact — Client
The contact details provided by Client in its OAD Account
Details
Subject Matter
Provision of the OAD behavioral assessment Platform under the Platform Terms.
Nature and Purpose
Processing of Personal Data as necessary to administer behavioral and personality assessments, generate assessment reports, manage Client accounts and Admin Users, and provide related coaching, reporting, and support features, in accordance with Client’s instructions.
Duration
For as long as Client maintains an active Account and uses the Platform, plus any post-termination retention period described in Section 10 and the OAD Privacy Notice.
Categories of Data Subjects
Client’s Admin Users and authorized personnel (who must be at least 18 years old under the Platform Terms); Client’s Survey Subjects (e.g., job candidates, employees, or other individuals invited to complete an assessment, who under the Acceptable Use Policy must not be given access to the Platform if under 16 years of age, or any higher minimum age applicable in their jurisdiction); and Client’s Contacts.
Categories of Personal Data
Identifiers such as name, email address, phone number, and job title; employment and professional background information; assessment questionnaire responses and derived behavioral trait scores; assessment reports; and account/usage data. Consistent with the Acceptable Use Policy, Client shall not submit government identification numbers, payment card numbers, account passwords, or similarly sensitive identifiers as Personal Data unless it has obtained the necessary consent and such data is reasonably necessary to provide the Platform.
Special Categories of Personal Data
OAD’s assessments are designed to measure workplace behavioral traits and are not intended to elicit health, medical, or psychotherapeutic information. The Parties do not anticipate the Processing of special category data. Client shall not submit special category data (e.g., health, biometric, or genetic data, or data revealing racial/ethnic origin, religious belief, sexual orientation, or trade union membership) into the Platform unless it has first notified OAD in writing and the Parties have agreed on appropriate additional safeguards. OAD is not a clinical, medical, or psychotherapy service provider. Where a Survey Subject is under 18, Client is responsible for ensuring any additional protections required for minors’ data under Applicable Data Protection Laws (for example, parental or guardian consent where required) have been obtained before submitting that Survey Subject’s Personal Data to the Platform.
Frequency of Transfer
Continuous, for as long as Client uses the Platform.
Sub-Processors
As set out in Section 6 and the Sub-Processor List.
Throughout the term of the Platform Terms, OAD shall implement and maintain at least the following (or superior) technical and organizational measures (“TOMs”) to safeguard Personal Data.
Catgegory
Measures
Encryption
Personal Data is encrypted in transit and at rest using industry-standard encryption protocols.
Access Control
Role-based access controls (RBAC) restricting Personal Data access to Team members who need it to perform their job function; support for multi-factor authentication (MFA) on Client Accounts, which OAD recommends and may require for certain features.
Authentication
For as long as Client maintains an active Account and uses the Platform, plus any post-termination retention period described in Section 10 and the OAD Privacy Notice.
Categories of Data Subjects
Password-protected accounts; MFA available and, where required by OAD, enforced for Account or feature access.
Monitoring
Active monitoring of information systems and shared information to detect and respond to anomalous or unauthorized activity.
Transmission Security
HTTPS/TLS encryption for data transmitted to and from the Platform.
Storage Security
Encryption at rest for stored Personal Data on OAD’s hosting infrastructure.
Confidentiality
Written confidentiality obligations for all Team members and contractors with access to Personal Data.
Data Minimization
Collection limited to fields necessary to administer assessments and operate the Platform.
Backup & Resilience
Regular backups of Platform data to support recovery in the event of a technical incident, consistent with Client’s own obligation to maintain independent backups of its Content.
Incident Response
Documented internal process for identifying, containing, and notifying Client of a Personal Data Breach within the timeframe specified in Section 8.
Governance
Internal accountability for data protection and security compliance, including periodic review of this Addendum and its appendices.
Sub-Processor Oversight
Contractual flow-down of equivalent security obligations to Sub-Processors, as described in Section 6.
1. European Economic Area
Restricted Transfers
With regard to any Restricted Transfer subject to EEA Data Protection Laws, the following mechanisms apply in order of precedence: (i) a valid adequacy decision under Article 45 GDPR; (ii) the appropriate Standard Contractual Clauses adopted by the European Commission from time to time; or (iii) any other lawful transfer mechanism recognized under EEA Data Protection Laws.
Standard Contractual Clauses
This Addendum incorporates by reference the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (“EU 2021 SCCs”). The Parties are deemed to have executed the EU 2021 SCCs in their entirety, including the annexures, with the following selections:
The terms in Appendix I to Exhibit B supplement the SCCs. Where the SCCs conflict with this Addendum, the SCCs prevail as to the Restricted Transfer in question.
EU Representative
OAD has appointed the European Data Protection Office (EDPO) as its representative in the EEA pursuant to Article 27 of the GDPR. EDPO may be contacted regarding GDPR matters via the online request form at https://edpo.com/gdpr-data-request/, or by writing to EDPO at Avenue Huart Hamoir 71, 1030 Brussels, Belgium.
2. United Kingdom
“UK Data Protection Laws” means the UK Data Protection Act 2018 and the UK GDPR. With regard to any Restricted Transfer subject to UK Data Protection Laws, the following mechanisms apply in order of precedence: (i) a valid adequacy decision under Article 45 of the UK GDPR; (ii) the UK International Data Transfer Addendum to the EU 2021 SCCs, as issued under Section 119A of the Data Protection Act 2018; or (iii) any other lawful transfer mechanism under UK Data Protection Laws.
This Addendum incorporates by reference the EU 2021 SCCs together with the UK Transfer Addendum, populated using Exhibit A and Appendix I to Exhibit A, with the UK Information Commissioner’s Office as the competent authority, and governed by the laws of England and Wales.
UK Representative
OAD has appointed EDPO UK Ltd as its representative in the United Kingdom pursuant to the Data Protection Act 2018. EDPO UK may be contacted via the online request form at https://edpo.com/uk-gdpr-data-request/, or by writing to EDPO UK at 8 Northumberland Avenue, London WC2N 5BY, United Kingdom.
3. Switzerland
“Swiss Data Protection Laws” means the Federal Act on Data Protection (FADP) and its implementing ordinance. With regard to any Restricted Transfer subject to Swiss Data Protection Laws, the following mechanisms apply in order of precedence: (i) a valid adequacy decision of the Swiss Federal Data Protection and Information Commissioner (“FDPIC”); (ii) the EU 2021 SCCs as adapted for Switzerland by the FDPIC; or (iii) any other lawful transfer mechanism. Where the EU 2021 SCCs apply, the FDPIC is the competent authority, and the SCCs are governed by the laws of Switzerland, subject to the FDPIC’s required modifications.
4. United States
“United States Data Protection Laws” means applicable U.S. state privacy laws, including but not limited to the California Consumer Privacy Act (as amended by the CPRA), and comparable laws of other states as enacted or amended from time to time.
This Appendix provides additional safeguards and redress mechanisms for Data Subjects whose Personal Data is transferred under the SCCs. It supplements, and does not modify, the SCCs applicable to a given Restricted Transfer.
1. Applicability of Surveillance Laws
2. No Backdoors
OAD certifies that it has not purposefully created backdoors or similar mechanisms that would allow governmental agencies to access Personal Data or its systems, and that it is not required by applicable law or government policy to create or maintain such mechanisms. If this changes, OAD will notify Client, who may terminate the Platform Terms on short notice.
3. Government Access Requests
Where legally required to disclose Personal Data to a public authority, OAD will (i) require an official, signed legal document before considering any request; (ii) scrutinize the request for validity and challenge or narrow overbroad requests; (iii) respond as narrowly as possible; and (iv) notify Client of the request, unless prohibited by law.
4. Termination
This Appendix automatically terminates with respect to a given Restricted Transfer if a competent Supervisory Authority approves an alternative transfer mechanism that does not require these additional safeguards.
This Addendum is accepted electronically by Client upon acceptance of OAD’s Platform Terms of Service (including by clicking “I Agree,” checking an acceptance box, or continuing to use the Platform after notice), and no further signature is required for it to take effect. Clients requiring a manually countersigned copy for internal compliance purposes may request one at support@oad.ai.
OAD
Client
Name
[Authorized Signatory Name]
[Client Authorized Signatory Name]
Title
[Title]
[Title]
Date
Signature