Data Processing Addendum

This Addendum governs the personal data you put into Lattney. It forms part of the Terms of Service between you and HiWork LLC and applies automatically from the date below. No signature is required. If your procurement process needs a countersigned copy, write to [email protected] and we will sign one.

Version 1.0. Effective August 20, 2026.

Who this is between

Party Detail
Processor HiWork LLC, trading as Lattney, a Florida limited liability company. Referred to as "we", "us" and "our"
Controller The organization or person that holds the Lattney account. Referred to as "you" and "your"
Contact for data protection [email protected]

The two roles, and which one this Addendum covers

Lattney holds two different kinds of data and our responsibility differs for each. Our Privacy Policy sets out the same split.

Data Role Governed by
The contacts, notes, tasks, custom fields, files, mail and form responses you put into your CRM You are the controller. We are your processor This Addendum
Your account, your users, your billing details, and how you use the product We are the controller Our Privacy Policy, not this Addendum

Everything below concerns the first row only. We call it your content.

1. Definitions

Term Meaning
Data Protection Law Every law on the protection of personal data that applies to our processing of your content, including the EU General Data Protection Regulation (2016/679), the UK GDPR and the Data Protection Act 2018, and the US State Privacy Laws
US State Privacy Laws The California Consumer Privacy Act as amended by the CPRA, and the comprehensive privacy statutes of other US states, in each case as they apply
SCCs The Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021
UK Addendum The International Data Transfer Addendum to the EU SCCs, template Addendum B1.0, issued by the Information Commissioner and laid before Parliament under section 119A of the Data Protection Act 2018 on 2 February 2022, as revised from time to time under section 18 of its Mandatory Clauses
Sub-processor A third party we engage to process your content on your behalf
Security Incident A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, your content
Restricted Data The categories listed in section 8.3

"Controller", "processor", "personal data", "data subject", "processing" and "supervisory authority" carry the meanings Data Protection Law gives them.

2. Duration

This Addendum applies for as long as we process your content, and its terms survive the end of your subscription until that processing has stopped.

3. Processing on your instructions

We process your content only on your documented instructions, which are: this Addendum, the Terms of Service, your use of the product and its features, and any further written instruction you send us that is consistent with them. Opening an account instructs us to process your content in order to provide the Services.

We do not process your content for our own purposes. We do not sell it, and we do not share it for cross-context behavioral advertising.

Three narrow exceptions, each of which is an instruction you give us here:

Exception Scope
Support Where you ask us for help with a case, we access what is needed to answer it
Fault diagnosis Where an error report or a log line surfaces your content while we are fixing a fault. We aim to fix the root cause rather than look again
Legal compulsion Where a US legal process compels us. We tell you first unless we are legally prohibited from doing so

If we need to process your content for anything else, or if the law requires us to process it beyond your instructions, we will tell you before we do, unless that law forbids the notice.

If an instruction infringes Data Protection Law in our reasonable opinion, we will tell you. We are not obliged to give you legal advice and we are not responsible for your assessment of your own lawfulness.

If you ask for something outside the Services as they are built, we will agree it with you in writing before doing it.

4. Confidentiality

Everyone we authorize to access your content is bound by a duty of confidentiality, whether by contract or by statute, and that duty outlives their engagement with us. We authorize access only where it is needed for a purpose in section 3.

5. Security

We implement and maintain the technical and organizational measures set out in Annex 4, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing alongside the risk to data subjects.

We may update those measures, including to improve security or to meet a change in Data Protection Law, so long as an update does not materially reduce the overall protection of your content.

Annex 4 describes what we do. It is not a list of everything a security program can contain, and we do not assert measures we have not implemented.

What is yours to do. You are responsible for configuring the account you control: who you invite, what role you give them, which API tokens exist and what permissions they carry, and the security of the devices and credentials your users sign in with. Roles, permissions and tokens are all managed from your account settings.

6. Security Incidents

We will notify you without undue delay after becoming aware of a Security Incident affecting your content. The notice will describe what we know at the time, including the nature of the incident, the categories and approximate volume of data and data subjects affected so far as we can tell, the likely consequences, and the steps taken or proposed. Where we cannot give all of it at once, we will send it in stages as it becomes available.

We will cooperate with you, and take the steps you reasonably request, to investigate and mitigate the incident.

Notifying you is not an admission of fault or liability.

Notifying a supervisory authority or the affected data subjects is yours to do, because you are the controller. Where your notice names us or identifies us indirectly, tell us first and consider in good faith any correction we suggest to the part that describes our involvement.

7. Assistance we owe you

Taking account of the nature of the processing and the information available to us, we will give you reasonable assistance with:

Obligation What we do
Data subject requests (Articles 12 to 22) Section 9
Security of processing (Article 32) Annex 4, and the information in section 11
Notifying a breach (Articles 33 and 34) Section 6
Data protection impact assessments (Article 35) Provide the information about our processing that you need to complete one
Prior consultation with a supervisory authority (Article 36) Provide the information you need to conduct one

We do not charge you for this assistance where it is met by the Services, by this Addendum, by our published documentation, or by a request that is not manifestly unfounded or excessive. Where you ask for work substantially beyond that, we will tell you before starting and agree the cost with you first. We will not withhold assistance while a fee is being discussed.

8. Your responsibilities as controller

8.1 Lawfulness. You are responsible for having a valid legal basis for the processing you instruct, and for keeping it valid throughout. Where you rely on consent, obtaining and recording it is yours.

8.2 Transparency. You are responsible for giving data subjects the information Articles 13 and 14 require. This matters most for our public share links: when you send one to a contact, that contact's data reaches us because you sent it, they have no relationship with us, and in most cases they will not know HiWork LLC exists. The Article 14 duty is yours. We publish our Privacy Policy and our sub-processor list so that you can point to them in your own notice.

8.3 Restricted Data. You must not put any of the following into Lattney:

Restricted Data Why
Payment card numbers and card security codes We are not assessed under the Payment Card Industry Data Security Standard, and nothing in Lattney is built to hold cardholder data
Government-issued identification numbers, including Social Security, national insurance, passport, driver's license and taxpayer numbers The harm from disclosure is severe and disproportionate to any CRM purpose
Protected health information subject to HIPAA We are not a business associate and will not sign a business associate agreement
Credentials to financial accounts, and passwords or access tokens for third-party services A CRM note is not a password manager
Personal data of children under 16 We operate no age verification and no parental consent mechanism

If you put Restricted Data in anyway, you remain the controller of it, this Addendum still applies to it, and we may ask you to remove it.

8.4 Special category and criminal offence data. We say plainly what the prohibition above does not cover. Notes, comments, task descriptions, custom field values and uploaded files accept whatever you type. We do not ask for special category data, we design no field for it, and we cannot prevent it reaching us. So rather than ban what we cannot police, we allocate it:

  • Where your content includes personal data within Article 9(1), you are responsible for satisfying a condition in Article 9(2), and for any supplementary condition your national law adds.
  • Where it includes personal data within Article 10, you are responsible for the official authority or the legal authorization that permits it.
  • You confirm you have assessed whether that processing needs a data protection impact assessment, and completed one where it does.

The security measures in Annex 4 apply to all of your content and are not varied by its sensitivity.

9. Data subject requests

Requests that come to you. We give you the tools to answer most requests yourself. Every record in your account can be found, read, corrected and deleted from the interface. For access and portability, the two return routes in section 12 apply: CSV export for contact records, and the API for everything else. Where a request needs something the product does not reach, write to [email protected] and we will help.

Requests that come to us. If a data subject contacts us directly about content in your account, we will not answer it on the merits. We will tell them to contact you, and tell you that they approached us, unless we are legally prohibited from doing so. Answering is yours, because we do not know why you hold the record or what you have told the person about it.

10. Sub-processors

Your authorization. You give us general written authorization to engage the sub-processors on our published list, and to engage new ones subject to the notice and objection rights below. That list, what each vendor does, where it processes, and in what capacity, is at app.lattney.com/sub-processors and is incorporated into this Addendum as Annex 5.

Our terms with them. Before a sub-processor receives your content we put a written contract in place imposing data protection obligations no less protective than those in this Addendum, so far as they apply to what that vendor does. We remain fully liable to you for their performance.

Changes.

Commitment Detail
Notice At least 30 days before a new sub-processor begins processing your content. Notice goes to the email address on record for your account, and the published list and its change log are updated at the same time
Objection Within those 30 days, on reasonable grounds relating to data protection
Resolution We will work with you in good faith to address the objection
Remedy If we cannot resolve it, you may terminate your subscription without penalty and we will refund the unused portion of any fees you have already paid

We will not remove a vendor from our infrastructure for one customer, so the remedy for an objection is an exit rather than a change to the list. We would rather say that plainly than imply otherwise.

11. Information and audit

Information first. We will make available to you the information reasonably necessary to demonstrate our compliance with Article 28 and with this Addendum. Our published sub-processor list, our Privacy Policy and this Addendum are the first place to look, and we will answer a reasonable security questionnaire or written request beyond them.

Audit. Where that information does not satisfy an obligation Data Protection Law places on you, or a supervisory authority with jurisdiction over you requires it, you may audit our compliance, or appoint an auditor to do so, once in any twelve month period and additionally where a Security Incident affecting your content has occurred.

Condition Detail
Notice At least 30 days in advance, with a proposed scope, duration and start date, which we will work with you in good faith to agree
Auditor We may object to a third-party auditor who is a competitor of ours or is not independent, in which case you appoint another or audit yourself
Confidentiality A third-party auditor signs a confidentiality agreement first. Nothing requires us to breach a duty of confidentiality we owe another customer or a vendor
Conduct During business hours, without unreasonable interference with our business, and subject to the agreed plan
Findings Tell us promptly about any non-compliance found, and give us the report
Cost Yours, including our reasonable documented time

If we hold a current third-party audit report or certification covering the controls you want to examine, and no material change has occurred since, you agree to accept it in place of an audit of those controls. We hold none today, and we will not imply otherwise.

12. Return and deletion

Deletion in Lattney is immediate and irreversible. There is no trash, no recovery window and no restore. When you delete a record it is gone. When you delete your account, your content goes with it. We cannot get it back for you, for any reason, at any price.

So exercise your choice before you cancel, not after. Article 28(3)(g) gives you the choice between the return of your content and its deletion. Because deletion is immediate, the return limb is available continuously throughout your subscription rather than in a window after it ends:

Route What it returns
CSV export, from account settings Your contact records: names, companies, job titles, birthdays, email addresses, phone numbers, postal addresses, links and your custom fields with their values
The API, with a token you create Everything else, including notes, comments, tasks, uploaded files, mail sent and received through the product, and form responses. A full-permission token reaches everything in the account

Both are self-service and available at any time while your subscription is live. If you would rather we produced a copy for you, ask before you cancel and we will.

What happens when the subscription ends. Your content becomes inaccessible immediately on cancellation and is deleted from our active systems. After that we retain nothing of it except:

What we keep Why, and for how long
Backups Copies persist in our database backups until those backups cycle out on their own schedule. They are not restored to serve anyone, and they go when the backup they sit in goes
Delivery records for mail the Services sent Kept with their links to your account cleared, for accounting and for answering delivery disputes
Raw inbound email A message sent into the product is held in its original form for 30 days from the point we process it, then destroyed automatically. That clock runs from when the message arrived, not from when you cancel, so a message received the day before you leave goes 30 days after it arrived. The parsed copy in your account goes with the account, immediately
Anything a law requires us to keep Only for as long as that law requires, processed only for that purpose, and under the same measures

We will confirm deletion in writing if you ask.

13. Artificial intelligence

We do not train on your content. We do not use it, and we do not permit our sub-processors to use it, to train, fine-tune, develop or evaluate any artificial intelligence or machine learning model, whether ours or anybody else's.

The MCP endpoint and API tokens are your onward disclosure, not our sub-processing. Lattney has an API and an MCP endpoint, both reachable with a token you create. If you connect Lattney to an AI assistant over MCP, that assistant and its model provider can read the contacts, notes and tasks the token's permissions allow, and can create and change them. We cannot see where that data goes once it leaves us and we have no relationship with whoever receives it. You choose the connection, so as between us you are the controller of that disclosure and responsible for the mechanism that makes it lawful. Tokens are listed and can be revoked in your account settings.

Lattney makes no automated decision producing legal or similarly significant effects on a data subject.

14. International transfers

We are a United States company and everything runs in the United States: the application, the database, file storage, backups and mail. Where a vendor processes somewhere else, our sub-processor list says where. We do not offer an EU or UK hosting region and none is planned.

You are the party that sends your content to us, so where your own law treats that as a restricted transfer, the transfer is yours to make lawful and the mechanism is ours to offer. Annex 2 offers it: the EU SCCs, and the UK Addendum where the UK GDPR applies. Both take effect automatically, with no separate signature, wherever Annex 2 says they do.

15. Liability

Each party's liability under this Addendum, and under the SCCs where they apply, is subject to the exclusions and limitations of liability in the Terms of Service. Nothing here affects any person's rights as a third-party beneficiary under the SCCs, or any liability that cannot be limited under Data Protection Law.

16. General

Precedence. Where this Addendum conflicts with the Terms of Service, this Addendum prevails for your content. Where the SCCs conflict with either, the SCCs prevail for the transfer they cover.

Changes to this Addendum. We may update it to keep it accurate or to meet a change in Data Protection Law, provided the update does not materially reduce the protection of your content or materially increase your obligations. We will post the new version here with a new version number and effective date. That constraint, rather than a notice, is what protects you from a change you would not have agreed to. Adding a sub-processor is a different commitment and carries its own notice, in section 10.

Notices. We may give notice under this Addendum to the email address on record for your account or to your data protection contact if you have given us one. Keeping that address current is yours. Write to us at [email protected].

Governing law. The Terms of Service govern this Addendum, except that the SCCs are governed as they themselves provide.


Annex 1: Details of the processing

This Annex is also Annex I to the SCCs where Annex 2 applies.

A. The parties

Role Details
Data exporter You, the account holder. Your activities relevant to this Addendum are your use and receipt of the Services. Your role is controller, or processor where you hold the content on behalf of your own client. Your contact details are those on record for your account, or the data protection contact you have given us
Data importer HiWork LLC, trading as Lattney, a Florida limited liability company, United States. Our activity relevant to this Addendum is providing the Lattney customer relationship management service. Our role is processor, or sub-processor where you are a processor. Contact: [email protected]. Our registered postal address is not published. It is stated in any executed copy of the Clauses, which we provide on written request under section 6 of Annex 2

B. Description of the processing

Field Detail
Categories of data subjects The people whose records you keep: your clients, prospects, suppliers, candidates, and anyone else you choose to record. The contacts who respond to your public share links. Your own users, as the authors of notes and tasks and the senders of mail. Third parties copied on a message you send or receive through the product
Categories of personal data Names, companies, job titles, birthdays. Postal addresses, email addresses, phone numbers, saved links. Your custom fields and the values in them. Contact lists and the relationships you record between contacts. Free text: notes, comments, and tasks with their titles and descriptions. Uploaded files, and the contents of those files. Mail sent and received through the product, including sender, recipients, subject and full body. Responses your contacts give on public share links. The account activity log, which records who changed what, together with the acting user's IP address and browser user agent
Special category data Not requested, not designed for, and prohibited only to the extent set out in section 8.3. Free-text fields may nevertheless contain data within Articles 9 or 10, and section 8.4 allocates responsibility for it. No additional restriction or safeguard applies beyond Annex 4, which applies to all content alike
Frequency of transfer Continuous, as you use the Services
Nature of the processing Collection, recording, organization, structuring, storage, retrieval, consultation, use, transmission by email, restriction, erasure and destruction, in each case as needed to operate the Services
Purpose of the processing Providing the Services to you under the Terms of Service and this Addendum, and nothing else
Duration For as long as your account exists. Deletion is immediate on your instruction and on cancellation, subject to section 12
Sub-processor transfers As set out in Annex 5, for the purposes and durations described there

C. Competent supervisory authority

Where you are established in an EU member state, the supervisory authority of that state. Where you are not established in the EU but have appointed a representative under Article 27, the supervisory authority of the state where your representative is established. Where neither applies, the supervisory authority of the state in which the data subjects are located. Where the UK GDPR applies, the Information Commissioner.


Annex 2: European Annex

This Annex applies to the extent your content is subject to the GDPR or the UK GDPR.

1. When the SCCs apply

Where your transfer of content to us is a restricted transfer under the GDPR, the SCCs apply and are incorporated into this Addendum. Where it is a restricted transfer under the UK GDPR, the SCCs as varied by the UK Addendum apply and are incorporated.

2. Signature

Each party is deemed to have signed the SCCs, and the UK Addendum where it applies, at the relevant signature block, on the date this Addendum first applies between us.

3. Modules

Module When it applies
Module Two, controller to processor Where you are a controller of the content in your own right
Module Three, processor to processor Where you are yourself a processor acting on behalf of another controller

The module is determined by your role for the content in question, as recorded in Annex 1.

4. How the SCCs are completed

Clause Election
Clause 7, docking Does not apply
Clause 9, sub-processors Option 2, general written authorization, with the notice period in section 10 of this Addendum. Your authorization under section 10 is your instruction to disclose and onward-transfer content to those sub-processors for the purposes of the Services, for the purposes of Clause 8.8
Clause 11(a), redress The optional paragraph on an independent dispute resolution body does not apply
Clause 13 and Annex I.C The supervisory authority identified in Annex 1.C
Clause 17, governing law The law of Ireland
Clause 18(b), forum The courts of Ireland
Annex I Annex 1 of this Addendum
Annex II, technical and organizational measures Annex 4 of this Addendum
Annex III, sub-processors, Module Three Annex 5 of this Addendum

Where Module Three applies, "controller" in the SCCs refers to your own controller and Clause 8.1 instructions reach us through you.

5. The UK Addendum

Where the UK GDPR applies, the SCCs are varied by the UK Addendum as follows. Tables 1, 2 and 3 are completed with the corresponding details in Annex 1 and in section 4 above. In Table 4, the box marked "Importer" is deemed ticked, so we are the party that may end the UK Addendum when the Information Commissioner issues a revised version. The parties are bound by the Mandatory Clauses in Part 2 of the UK Addendum.

The Information Commissioner has said it plans to update the Addendum. Section 18 of its Mandatory Clauses amends this Addendum automatically when a revised version takes effect, and nothing here is intended to freeze us on version B1.0.

6. Practical matters under the SCCs

Point Position
Executed copy On written request, and with evidence of the request made of you by a supervisory authority, a data subject or your own controller, we will provide an executed copy of the applicable SCCs within a reasonable time
Transparency, Clause 8.3 In meeting your transparency obligations you will protect our confidential and commercially sensitive information
Notifying data subjects, Clause 15.1(a) Where a public authority approaches us, you are responsible for any notification to data subjects, except where the law or the authority prevents us from telling you at all
Audits, Clauses 8.9(c) and (d) Conducted under section 11 of this Addendum
Deletion certificate, Clauses 8.5 and 16(d) Provided on written request
Replacement mechanism If the SCCs or the UK Addendum are replaced or invalidated, we may on notice substitute the successor mechanism, or another valid mechanism, without reducing the protection of your content

7. Instructions that infringe

Where an instruction you give us would in our reasonable opinion infringe the GDPR or the UK GDPR, we will tell you, as section 3 provides.


Annex 3: US State Privacy Laws

This Annex applies where your content is subject to the US State Privacy Laws. "Business", "controller", "processor", "service provider", "contractor", "commercial purpose", "sell" and "share" carry the meanings those laws give them.

You are the business or controller. We are the service provider, contractor or processor. We process personal information only for the business purpose of providing the Services under the Terms of Service and this Addendum, which is the purpose set out in Annex 1.

Commitment Detail
No sale, no share We do not sell your content and do not share it for cross-context behavioral advertising. We receive no monetary or other valuable consideration for it
Purpose limitation We do not retain, use or disclose it for any purpose other than providing the Services, or as the law otherwise permits a service provider
No combining We do not combine it with personal information from another source, except as a service provider is permitted to do
Outside the direct relationship We do not use it outside the direct business relationship between us
Compliance We will comply with the obligations these laws place on a service provider, contractor or processor, and provide the same level of protection they require
Notice We will tell you if we determine we can no longer meet those obligations
Your right to check Section 11 gives you the right to take reasonable and appropriate steps to confirm we use your content consistently with your obligations, and to stop and remediate unauthorized use
Sub-processors Engaged under section 10, under a written contract imposing the same obligations
Deidentified data We produce none from your content. If we ever did, we would not attempt to reidentify it

Annex 4: Security measures

These are the technical and organizational measures we implement, and they are also Annex II to the SCCs where Annex 2 applies. This describes what we do today. We do not list measures we have not implemented.

Measure What it means
Encryption in transit HTTPS is forced for the whole application. Traffic between your browser and Lattney is encrypted in transit
Password storage Passwords are stored only as a bcrypt hash, which cannot be reversed. We never hold a password in a form we can read
Credential storage API token secrets are stored only as a hash and cannot be recovered after they are issued, including by us
Access control within the product Every action against the API runs an authorization check, and every query is scoped to a single account. Those policies are the single source of truth, and the interface derives what it shows from the same policies, so what the interface offers and what the server permits cannot drift apart
Bounded credential lifetime OAuth access tokens expire one hour after issue. A refresh token unused for 90 days is revoked, and deleted 30 days after that, so a dormant connection cannot be refreshed back indefinitely
Secret management Application secrets are held in encrypted credentials. None is stored in readable form in our source code
File storage Uploaded files are held in private object storage and served only through short-lived signed URLs. There is no public bucket path to a customer file
Data minimization in diagnostics Our error monitoring and logging filter sensitive parameters before they leave the application, and that filter list names the CRM field names specifically as well as the framework defaults
Runtime hardening The production application runs as an unprivileged, non-root user in its container
Supply chain and code scanning Every change runs static security analysis, a dependency vulnerability audit and a JavaScript dependency audit in continuous integration, and cannot merge unless all three pass
Segregation by account Your content is logically separated from every other customer's by the account scoping above. We do not operate a shared unscoped data path
Deletion Deletion is immediate and destructive rather than a soft-delete flag, so a deleted record is gone rather than hidden

Section 5 sets out what remains yours to configure, and section 10 covers the measures our sub-processors apply.


Annex 5: Sub-processors

The current list, with what each vendor does, where it processes your content and in what capacity, is published at app.lattney.com/sub-processors and forms part of this Addendum. That page also carries the change log, so you can see what changed and when.

Section 10 sets out how we add to it and what you can do about it.