This document is in force but still under review by counsel; wording may change. Questions: [email protected].
Data processing addendum
Programmable · Programmable Watch · last updated October 6, 2026
This addendum forms part of the Terms of Service between the customer ("Controller") and Programmable ("Processor") and applies whenever the Service processes personal data on the Controller's behalf. It is written to meet Article 28 GDPR and the UK and US state laws that follow it.
1. Subject matter and nature
Processing supplier lists, decisions, notes, supplier contact details and documents, and the findings, evidence and audit records derived from them, in order to monitor supplier compliance for the Controller. Duration: the term of the account. Data subjects: the Controller's staff, and contact persons at the Controller's suppliers. Categories: business contact data, decision records, and documents a supplier chooses to provide. No special-category data is intended.
2. Instructions
The Processor processes personal data only on the Controller's documented instructions, which are the Terms, this addendum and the Controller's use of the Service, unless law requires otherwise, in which case the Processor will tell the Controller first where it may.
3. Confidentiality and security
People with access are bound by confidentiality. Measures include: encryption in transit (TLS) and at rest for secrets, chat URLs and supplier documents (AES-256-GCM); role-based access within accounts; hashed API keys; an append-only audit log; encrypted off-site backups; network restriction of the origin to the CDN; no request bodies or credentials in logs or error reports; and self-service export and deletion.
4. Subprocessors
The Controller authorises the subprocessors listed at /subprocessors. The Processor will give at least 30 days' notice of a new subprocessor by updating that page and notifying account owners in the Service; the Controller may object on reasonable grounds, and if no resolution is found may terminate and export its data.
5. Data subject requests
The Processor will pass on any request it receives from a data subject and assist the Controller with it. Most requests can be met by the Controller directly through export, correction and deletion in the Service.
6. Breach notification
The Processor will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Controller's data, with what is known at the time and updates as the picture clears.
7. Assistance and audit
The Processor will assist with impact assessments and consultations where reasonably needed. Once a year on request, and after a breach, the Processor will provide the information needed to show compliance with this addendum and allow an audit by the Controller or an auditor it appoints, at reasonable times and with reasonable notice, at the Controller's cost unless the audit finds a material breach.
8. Deletion and return
On termination the Controller may export all data for 30 days, after which the Processor deletes it, apart from what law requires it to keep. Deleting a watchlist or the account in the Service deletes the data concerned.
9. Transfers
Data is hosted in the United States. For data originating in the EEA, UK or Switzerland the parties enter into the EU Standard Contractual Clauses (Module 2, controller to processor) and the UK Addendum by reference, with this addendum supplying the annexes.
10. Liability
Liability under this addendum is subject to the limits in the Terms, except where law does not allow that.