Data Protection Addendum

Effective date: October 7, 2026

During the course of providing Services to, or on behalf of, you as our customer (“Customer”), Vinewave (Pty) Ltd DBA OneDirectory (“OneDirectory”) may process certain Data (as defined below). This Data Protection Addendum (“DPA”) supplements and forms part of the applicable agreement between Customer and OneDirectory (the “Agreement”), if such an Agreement exists. If no separate Agreement exists, this DPA shall serve as the Agreement for the purposes of governing the Parties’ rights and obligations regarding the processing of Data. Where this DPA serves as the Agreement, the Limitations on Liability and Choice of Law and Dispute Resolution sections of the OneDirectory Terms of Service at onedirectory.com/terms apply to it.

The Parties agree that, with regard to the processing of such Data pursuant to the Agreement or this DPA, Customer is the data controller (“Controller”) and OneDirectory is the data processor (“Processor”). In the event of a conflict between the terms of this DPA and the Agreement with respect to the processing of personal data, the terms of this DPA shall control.

IT IS HEREBY AGREED as follows:

1. Definitions

Capitalized terms used but not defined in this DPA will have the meanings set forth in the Agreement. The following capitalized words and expressions shall have the following meanings unless the context otherwise requires:

“Agreement” means the underlying contract or terms between the Controller and the Processor governing the provision of the Services (including, as applicable, the Processor’s Terms of Service, Master Services Agreement, Order Form, or any other written or electronic agreement). If no separate agreement exists, this DPA shall be deemed the Agreement for the purposes of defining the Parties’ rights and obligations.

“Covered Data” means all Data;

“Data” means all personal data processed by (or on behalf of) the Processor for the Controller under or in connection with the Agreement and/or this DPA, including in the provision of the Services;

“Data Protection Legislation” means all applicable privacy, data protection, and data security laws and regulations, including without limitation: (i) the EU General Data Protection Regulation (“GDPR”); (ii) the UK GDPR and UK Data Protection Act 2018; and (iii) United States state privacy laws applicable to the Processor as a service provider or processor, including (where applicable) the California Consumer Privacy Act (CCPA/CPRA).

“Data Security Breach” means a personal data breach affecting Covered Data;

“DPA” means this Data Protection Addendum, its schedules and any other documents attached to or referred to as forming part of this DPA, which are hereby incorporated into this DPA by reference;

“Data Subjects’ Rights” means those rights of data subjects as set out in: (i) the GDPR including, without limitation, rights of access, rectification, erasure, restriction of processing, data portability, objection, and not to be subject to automated decision making (including profiling); and (ii) any other applicable Data Protection Legislation;

“EEA” means European Economic Area;

“EU” means the European Union;

“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC;

“Laws” means all laws, rules, regulations, ordinances, directives, interpretations, judgments, or decisions of or agreements with or by any legislative, administrative, judicial or other governmental authority and legally binding codes of practice;

“Standard Contractual Clauses” means the European Commission’s 2021 standard contractual clauses for international transfers of personal data (Module Two: Controller to Processor), as amended, replaced, or superseded from time to time, and any equivalent or successor clauses approved under applicable Data Protection Legislation.

“Subprocessor” means any third party: (i) who is engaged by the Processor to carry out specific processing activities in respect of the Covered Data for or on behalf of the Controller; or (ii) to whom the Processor subcontracts any of its obligations under or in connection with the Agreement or this DPA; and

“data subject”, “international organisation” “personal data”, “personal data breach”, “process/processing”, “pseudonymisation”, “representative”, “special categories of personal data”, “supervisory authority” and “third country” shall each have the meaning ascribed to them in the GDPR.

2. Scope of Processing

2.1The duration of processing will be the same as the duration of the Agreement, except as otherwise agreed to in the Agreement or in writing by the Parties. The scope and further details of the processing activities to be performed by the Processor under or in connection with the Agreement and this DPA are set out in Schedule 1 to this DPA (Scope of Processing).

2.2To the extent that any additional information is required to be included in Schedule 1 to this DPA pursuant to the GDPR, any other applicable Data Protection Legislation, or any other applicable Laws, or this DPA otherwise requires updating, the Parties will work together in good faith to amend this DPA to ensure continued compliance with all relevant requirements. OneDirectory may update this DPA by publishing a new version where required by Data Protection Legislation, or where the update does not materially reduce the protection afforded to Data. Any other amendment requires the Controller’s prior written consent, not to be unreasonably withheld or delayed.

2.3Notwithstanding anything to the contrary in this DPA or the Agreement, the Processor may create and use aggregated and anonymised data derived from the Services or the Covered Data, such that neither the Controller nor any individual can be identified. Such aggregated and anonymised data is not Covered Data.

3. General Processor Obligations

3.1The Processor shall, and shall procure that each of its employees, permitted Subprocessors and any other individual acting under its authority who has access to the Covered Data shall:

3.1.1only process the Covered Data to the extent and in such a manner as is necessary for the provision of the Services and for no other purpose(s), except as expressly permitted in Section 2.3;

3.1.2only process the Covered Data in accordance with the terms of this DPA;

3.1.3only process the Covered Data in accordance with the written instructions of the Controller from time to time (including in respect of transfers of Covered Data from one jurisdiction to another including, without limitation, to a third country or international organisation outside the EEA), unless otherwise required to do so by any applicable Data Protection Legislation or other applicable Laws (in any such case, the Processor shall promptly inform the Controller of the relevant legal requirement before processing, unless prohibited from doing so on important public interest grounds);

3.1.4take reasonable steps to ensure the reliability of those of its employees, permitted Subprocessors and any other person who may have access to the Covered Data and use all reasonable efforts to ensure that: (i) such persons have sufficient skills and training in the handling of Covered Data; and (ii) comply with all applicable Data Protection Legislation, including the GDPR and any other applicable Laws;

3.1.5keep the Covered Data confidential and ensure that any person authorized to process the Covered Data for or on behalf of the Processor (including but not limited to any Processor employees and staff as well as permitted Subprocessors) have agreed to keep the Covered Data confidential, or are otherwise under an appropriate statutory obligation of confidentiality in respect of the Covered Data; and

3.1.6on request from the Controller, provide a copy of the Covered Data in a standard, commonly used export format.

3.2In carrying out its obligations under the Agreement and this DPA (including, in particular, in the provision of the Services), the Processor shall comply in full with all applicable Data Protection Legislation, including, without limitation, the GDPR and any other applicable Laws.

3.3In providing the Services pursuant to the Agreement and this DPA, the Processor shall comply with all Data Protection Legislation and other Laws to the extent applicable to the Processor.

3.4Processor will without undue delay notify Controller of any complaints received or any notices of investigation or non-compliance from any supervisory authority related to the collection or processing of Covered Data. Unless Controller notifies Processor that Processor will be responsible for handling a particular communication or correspondence with a supervisory authority, Controller will handle all such communications and correspondence relating to Covered Data and the provision or receipt of the Services. Nothing in this DPA prevents the Processor from cooperating with a supervisory authority or complying with its own obligations under Data Protection Legislation.

4. Security

4.1In accordance with all applicable Data Protection Legislation, including, without limitation, the GDPR and any other applicable Laws taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing of the Covered Data to be carried out under or in connection with the Agreement and this DPA, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons and the risks that are presented by the processing, especially from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to the Covered Data transmitted, stored or otherwise processed, the Processor agrees and warrants that it shall implement appropriate technical and organizational security measures appropriate to the risk, including (and at least meeting the minimum criteria of Schedule 1):

4.1.1the encryption of the Covered Data;

4.1.2the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;

4.1.3the ability to restore the availability of and access to the Covered Data in a timely manner in the event of a physical or technical incident; and

4.1.4a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.

4.2The Processor will use industry-standard measures designed to prevent harmful code, such as viruses, spyware and worms (“Viruses”), from being introduced into the systems it uses to process Covered Data. If a Virus is found in those systems and Covered Data may be affected, the Processor will promptly notify the Controller and take reasonable steps to remove the Virus and remediate its effects, subject to the limitations of liability in the Agreement.

4.3Consistent with applicable laws and the Agreement, the Processor will maintain disaster recovery and business continuity measures designed to support the availability of the Services and to enable restoration of processing of Covered Data following a Disaster (the “DR Services”). For the purposes of this DPA, a “Disaster” means an unplanned event that materially disrupts the Processor’s ability to provide the Services in accordance with the Agreement. The Processor will use commercially reasonable efforts to provide the DR Services and to restore the Services as soon as reasonably practicable, taking into account the nature of the incident and the resilience and dependencies of the underlying cloud infrastructure and third-party providers. The Processor’s obligations under this clause are subject to events beyond the Processor’s reasonable control (including Force Majeure) to the extent performance is prevented or materially impeded.

4.4The Processor will maintain and periodically test appropriate disaster recovery plans for the infrastructure utilized in processing Covered Data pursuant to the Agreement and this DPA. Such plans will be reviewed and tested at least annually, or more frequently as required by applicable Data Protection Legislation. Upon the Controller’s request, the Processor will confirm that its disaster recovery plans are in place and operational. The Processor will promptly notify the Controller of any Disaster affecting the processing of Covered Data and, in such event, will implement its disaster recovery plan and provide disaster recovery services to restore processing as soon as reasonably practicable.

4.5The Processor will maintain encrypted, geo-redundant backups of Covered Data in accordance with its Backup and Business Continuity policies and industry best practices.

5. Subprocessors

5.1The Controller authorises the Processor to engage the Subprocessors listed in Schedule 1 in connection with the Agreement. The Processor shall not engage any additional or replacement Subprocessors to carry out processing activities on behalf of the Controller other than in accordance with Section 5.2.

5.2In the case of a general written authorization in Schedule 1, the Processor shall give the Controller at least thirty (30) days prior written notice of any intended changes concerning the addition or replacement of Subprocessors to give the Controller the opportunity to object to such changes. Such notice shall include details of the processing activity or activities to be subcontracted or undertaken by the relevant Subprocessor and the identity, location and contact details of the Subprocessor. The Processor will give such notice by email in accordance with Section 14.3. If the Controller objects on reasonable data protection grounds within the notice period and the Parties cannot resolve the objection in good faith, the Controller may terminate the affected Subscription by written notice before the change takes effect, and the Processor will refund any prepaid fees for the unused portion of the Subscription Term.

5.3Regarding any permitted Subprocessor engaged in accordance with Sections 5.1 and 5.2, for carrying out any specific processing activities on behalf of the Controller, the Processor shall ensure that the same data protection obligations as set out in this DPA as between the Controller and the Processor are imposed on that Subprocessor by way of a written agreement, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a way that the processing will meet the requirements of the GDPR, any other applicable Data Protection Legislation and any other applicable Laws. Where any relevant Subprocessor fails to fulfil its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of the relevant Subprocessor’s obligations.

5.4The Processor shall promptly provide a summary of the relevant data protection terms upon request.

6. Assistance

6.1The Processor shall assist and cooperate with the Controller in ensuring compliance with the obligations referred to below (as required by the GDPR, any other applicable Data Protection Legislation, any other applicable Laws and/or this DPA) taking into account the nature of processing and the information available to the Processor, including in respect of:

6.1.1implementing appropriate technical and organizational security measures to ensure the security of processing in respect of the Covered Data;

6.1.2the notification of any Data Security Breaches in respect of the Covered Data to any relevant supervisory authority and communication of any personal data breaches to any relevant data subjects;

6.1.3carrying out data protection impact assessments; and

6.1.4any consultation with any relevant supervisory authority prior to processing where a data protection impact assessment indicates that the processing would result in a high risk if measures are not taken by the Controller to mitigate the risk.

7. Rights of Data Subjects

7.1The Controller shall be responsible for providing data subjects with the information required under the GDPR or other applicable Data Protection Legislation at the point of collection of their personal data. If required by the Controller, the Processor will provide the relevant information to data subjects on the Controller’s behalf in a form approved in advance by the Controller.

7.2Taking into account the nature of the processing performed by the Processor, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller's obligations to respond to requests for exercising Data Subjects’ Rights.

7.3The Processor shall notify the Controller in writing (including by email) of each such request that it receives. Such written notification shall be made promptly and in any event, not later than two (2) working days following receipt of the request, and shall include any information in the Processor’s custody or control that may assist the Controller to respond to the request.

7.4Unless otherwise required by any applicable Data Protection Legislation, including applicable EU or EU Member State law, the Processor shall not respond to any such requests or other communications that the Processor receives from data subjects, without the prior written consent of and at the direction of the Controller.

8. Data Security Breaches

8.1In the case of any Data Security Breach in respect of the Covered Data, the Processor shall notify the Controller in writing (including by email) without undue delay and in any event within 72 hours of becoming aware. Such notification shall include:

8.1.1the nature of the Data Security Breach, including where possible, the categories and approximate number of data subjects concerned (if any) and the categories and approximate number of Covered Data records concerned;

8.1.2the name and contact details of the Processor’s data protection officer (if applicable) or other contact point where more information can be obtained;

8.1.3details of the likely consequences of the Data Security Breach; and

8.1.4details of the measures taken or proposed to be taken by the Processor to address the Data Security Breach, including, where appropriate, measures to mitigate its possible adverse effects.

8.2The Processor shall document any such Data Security Breaches, comprising the facts relating to the Data Security Breach, its effects and remedial action taken. That documentation shall enable any relevant supervisory authority to verify compliance with any requirements on the Controller to notify Data Security Breaches to the relevant supervisory authority.

8.3At the Controller’s request, the Processor shall assist the Controller with any notification of any Data Security Breach that the Controller decides to make to any relevant supervisory authority.

8.4In addition to the Processor’s obligations as set out in this Clause 8 above, in the event of any Data Security Breach, the Processor shall also:

8.4.1undertake an investigation of such Data Security Breach and reasonably cooperate with the Controller, including by providing the Controller with a summary of the investigation’s findings. Any further participation by the Controller or a third party it nominates must be reasonable, subject to appropriate confidentiality obligations, and must not compromise the security of the Services or the data of the Processor’s other customers;

8.4.2not make any public announcements relating to such Data Security Breach that would imply or reference the Controller’s involvement, without the Controller’s prior written approval;

8.4.3take commercially reasonable corrective actions within its control that are reasonably necessary to remediate the cause of the Data Security Breach and reduce the likelihood of recurrence. Such corrective actions will be implemented at the Processor’s expense to the extent the Data Security Breach was caused by the Processor’s breach of this DPA or failure to comply with applicable Data Protection Legislation. Any liability arising under this clause is subject to the limitations of liability in the Agreement, except to the extent prohibited by law;

8.4.4at the Controller’s request and subject to the Controller’s reasonable instructions, the Processor will provide reasonable assistance to enable the Controller to comply with applicable Data Protection Legislation in relation to a Data Security Breach to the extent such compliance relates to the Services. The Processor will implement remediation measures that are reasonably necessary to address and mitigate the Data Security Breach to the extent caused by the Processor’s breach of this DPA or failure to comply with applicable Data Protection Legislation. Each party will bear its own costs, except that the Processor will bear the reasonable, documented costs of remediation measures it is required to implement under this clause to the extent caused by the Processor, and subject to the Agreement’s limitation of liability (except to the extent prohibited by law);

9. International Transfers of Data

9.1The Processor shall not process in or transfer any Data to any third country or international organization outside the EEA except on the instructions or with the prior written approval of the Controller, and at all times in compliance with the GDPR and any other applicable Data Protection Legislation. The Controller consents to the processing or transfer of Data to the third countries and international organizations outside the EEA as are set forth in Schedule 1.

9.2The Processor shall be responsible for ensuring that any agreed transfers of Data comply with all applicable Data Protection Legislation, including, but not limited to, any cross-border transfer requirements or prohibitions. To the extent required to ensure compliance with the GDPR regarding any agreed transfers of personal data to third countries or international organizations outside the EEA, unless another valid transfer mechanism exists for such transfers which satisfies the GDPR’s requirements, the parties hereby agree to enter into the Module Two (Controller-to-Processor) Standard Contractual Clauses (“SCCs”) as annexed to EU Implementing Decision 2021/914 of 4 June 2021, which are incorporated into this DPA and completed as follows:

9.2.1the data exporter and data importer in the SCCs are the Controller and Processor in this DPA respectively;

9.2.2option 2 of Clause 9 of the SCCs is selected and completed by reference to Section 5.2 of this DPA;

9.2.3For the purposes of the SCCs, Clause 17 shall be governed by the law of Ireland and the courts of Ireland shall have jurisdiction under Clause 18;

9.2.4Annex I of the SCCs is completed by reference to the Parties’ details and the description of the transfer in Schedule 1 (including the categories of data subjects, categories of personal data, purposes of processing, and the frequency and nature of the transfers, which are on a continuous basis);

9.2.5Annex II of the SCCs is completed by reference to Section 4 and the “Technical and Organizational Security Measures” section of Schedule 1;

9.2.6Annex III of the SCCs is completed by reference to the “Subprocessors” section of Schedule 1; and

9.2.7the optional language in Clause 11 of the SCCs is not included.

9.3To the extent the transfer of Data is subject to UK data protection law, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0) is incorporated into this DPA. Tables 1 to 3 of the Addendum are completed by reference to Section 9.2 and Schedule 1, the Addendum is governed by the law of England and Wales, and either party may end the Addendum as set out in its Section 19.

10. Accountability

10.1Upon written request from the Controller, the Processor shall make available all information reasonably necessary to demonstrate its compliance with this DPA and shall allow for and contribute to audits, including inspections, as described in this Section, which may include security questionnaires, independent audit reports (such as SOC 2), penetration test summaries, and relevant policy documents. The Parties agree that the Controller will first exercise its audit rights by reviewing such documentation and, where needed, by conducting remote audits (for example, interviews or evidence reviews by video call). Only where this information is, in the Controller’s reasonable opinion, insufficient to demonstrate compliance, or where required by a competent supervisory authority, may the Controller conduct a further audit of facilities under the Processor’s control. For the avoidance of doubt, the Processor is not required to permit inspections of private residences or facilities not under its control (including third-party data centres). Any such further audit shall be on at least thirty (30) days’ written notice (unless required sooner by law), no more than once in any twelve (12) month period (unless following a confirmed Data Security Breach or as required by a supervisory authority), during normal business hours, under appropriate confidentiality obligations, and at the Controller’s expense.

10.2The Processor shall immediately inform the Controller if, in the Processor's opinion, any instruction from the Controller with respect to the processing of Covered Data under or in connection with this DPA infringes any applicable Data Protection Legislation, including the GDPR, or other applicable Laws.

10.3The Processor shall notify the Controller of all communications it receives from any third party relating to the Covered Data, which suggest non-compliance by the Controller, the Processor or any other person with the GDPR or any other applicable Data Protection Legislation, or other applicable Laws, including communications from data subjects and regulatory bodies, and shall not do anything or enter into any communication with such third party unless expressly authorised to do so by the Controller or required by applicable Laws.

10.4The Processor shall maintain (or procure the maintenance of) a written record (which can be in electronic form) of all categories of processing activities carried out on behalf of the Controller (containing, without limitation, those details specified in Article 30 of the GDPR) and the Processor shall ensure that such record is made available to the Controller on the Controller’s request.

11. Indemnity

11.1The Processor shall indemnify, hold harmless and defend the Controller and its affiliates, directors, officers, employees and agents from and against any third-party claims, damages, liabilities, costs and expenses (including reasonable legal fees) to the extent arising from: (i) a breach by the Processor or its Subprocessors of this DPA or of Data Protection Legislation; or (ii) a Data Security Breach caused by the Processor or its Subprocessors. The Controller’s rights and remedies under this DPA are subject to the limitations of liability in the Agreement, except to the extent prohibited by applicable law.

12. Retention, Return, or Disposal

12.1The Processor shall retain the Covered Data only for as long as necessary to perform the Services, or as otherwise required or permitted by any applicable Data Protection Legislation or other applicable Laws, and in all cases, the terms of this DPA shall continue to apply with respect to such Covered Data during all periods in which it is retained by or accessible to the Processor.

12.2When the Agreement ends, the Processor shall (and shall procure that any permitted Subprocessor shall):

12.2.1if the Controller requests it within thirty (30) days after the Agreement ends, return a copy of the Covered Data in a standard, commonly used export format; and

12.2.2delete the Covered Data from its production systems after that thirty (30) day period, and from its backups as they expire in the normal backup cycle, in each case within ninety (90) days after the Agreement ends, and confirm deletion in writing on request.

The Controller may also ask the Processor to delete Covered Data at any time during the Agreement, and the Processor will do so within the same timescales. These obligations do not apply where Data Protection Legislation or other applicable Laws require the Processor to keep the Covered Data, in which case the Processor shall promptly inform the Controller of that requirement, shall return or delete the Covered Data as soon as possible after the required period ends, and shall not otherwise process it without the Controller’s express prior written consent. Clause 14.2 applies during any such period.

13. US State Privacy Laws (including CCPA/CPRA)

13.1To the extent the Processor processes personal information (i.e. Data relating to identified or identifiable residents of such states) of residents of US states with comprehensive privacy laws (including, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act, and similar state privacy laws) on behalf of the Controller in connection with the Services, the Parties agree that the Processor shall act as the Controller’s “service provider” and/or “processor” (or equivalent term) under such laws.

13.2The Processor shall:

13.2.1process such personal information only for the business purposes of providing the Services and performing its obligations under the Agreement and this DPA, and not for any purposes other than those permitted by the Agreement or applicable law;

13.2.2not “sell” or “share” such personal information, as the terms “sell” and “share” are defined under applicable US state privacy laws;

13.2.3not use or disclose such personal information for cross-context behavioural advertising, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects on individuals, except as permitted by applicable law;

13.2.4not combine such personal information with personal information that the Processor receives from or on behalf of another person, or collects from its own interactions with a consumer, except as permitted under applicable law for business purposes such as providing and improving the Services, detecting security incidents, or preventing fraud or misuse;

13.2.5ensure that each Subprocessor that processes such personal information on behalf of the Processor is bound by written terms that ensure the Subprocessor qualifies as a “service provider” or “processor” (or equivalent term) under applicable law; and

13.2.6notify the Controller without undue delay if the Processor determines that it can no longer meet its obligations as a service provider or processor under applicable US state privacy laws with respect to such personal information.

13.3The Processor shall provide reasonable assistance to the Controller, at the Controller’s cost where appropriate, to enable the Controller to respond to verifiable consumer requests and to otherwise comply with its obligations under applicable US state privacy laws in respect of such personal information.

14. General

14.1Assignment. Neither the Processor nor any permitted Subprocessor shall be entitled to assign its rights or benefits or transfer its obligations or burdens under this DPA, whether in whole or in part, without the prior written consent of the Controller, except in connection with a merger, acquisition, corporate reorganisation, or sale of substantially all of the Processor’s assets, provided that the assignee assumes in writing all obligations under this DPA. Any assignment or other transfer in violation of the foregoing shall be null and void.

14.2Survival. The Processor acknowledges and agrees that, notwithstanding the termination or expiry of the Agreement or this DPA for any reason, the obligations in this DPA shall continue for so long as any Covered Data remains in the Processor’s custody or control, or the Processor (or any permitted Subprocessor) otherwise processes Covered Data under or in connection with the Agreement or this DPA.

14.3Notices. All notices provided by the Processor under this DPA will be sent by email to the security contact designated by the Customer in the Service or, if none is designated, to the Customer’s account administrator, in addition to any method of notice described in the Agreement. The Customer is responsible for keeping these contact details up to date. All notices provided by the Controller will be sent to security@onedirectory.com.

14.4Governing Law. This DPA is governed by the law that governs the Agreement, except where the SCCs or applicable Data Protection Legislation require otherwise.

Schedule 1 to DPA: Scope of Processing

Purpose of Processing and Processing Activities

The purposes of the processing to be carried out by the Processor for the Controller in respect of the Data include the following:

  • Employee information management and search to facilitate organization-wide visibility, synchronization, management, and storage of employee contact details, roles, office locations, departments, skills, and other employee profile data as configured or provided by the Controller.
  • Organizational structure mapping to display, manage, and maintain the organizational structure, reporting lines, and team relationships within the organization.
  • Directory display and discovery to allow authorized users to browse, search, and visualize employee information for collaboration and internal communication purposes.

Data To Be Processed

The Data to be processed by the Processor, as configured by the Controller, may include the following categories of personal data:

  • Employee profile information, as configured or provided by the Controller, which may include name, job title, photo, email address, phone numbers, office locations, departments, professional biography, skills, interests, birthday, hire date, manager, custom fields, and other employee profile data entered into or synchronized with the Service.

The Data to be processed by the Processor on behalf of the Controller includes the following special categories of personal data:

  • None; no special categories of personal data will be processed

Data Subjects

The Data to be processed by the Processor on behalf of the Controller relates to the following categories of data subjects:

  • Employees, contractors, and guest users

International Transfers

The Processor may transfer Data to the following third countries or international organizations outside the EEA, where such transfers are required to provide the Services to the Controller:

  • United States – primary data storage and processing region for non-EU tenants.
  • Australia – optional data storage and processing region available upon request for Controllers requiring Australian data residency.
  • South Africa – the Processor is a company registered in South Africa. Data is not stored or hosted in South Africa. To the extent that the provision of the Services by a Processor established in South Africa constitutes a transfer of Data, it is made under the Standard Contractual Clauses.

For Controllers on EU-region hosting, Data is stored within the EEA, subject to the Processor’s establishment in South Africa and to transfers to the Subprocessors listed below.

All international transfers will be made in accordance with applicable Data Protection Legislation and will rely on appropriate transfer mechanisms, including the Standard Contractual Clauses (Module Two: Controller to Processor) or any successor or equivalent mechanism.

Technical and Organizational Security Measures

The Processor maintains the following technical and organizational security measures, appropriate to the risk of the processing, in accordance with Section 4 of this DPA:

  • Physical security. Hosted in Microsoft Azure data centres, which hold ISO/IEC 27001 and 27018, SOC 1, 2 and 3, and PCI DSS certifications. Physical access controls are operated by Microsoft.
  • Network security. Cloudflare provides edge protection, including TLS, DNS and DDoS protection. Access to production networks and databases is restricted by firewalls and network security groups on a deny-by-default basis.
  • Encryption in transit. All external and internal connections use TLS 1.2 or higher.
  • Encryption at rest. Data and backups are encrypted with AES-256. Encryption keys are managed in Azure Key Vault.
  • Access control. Access to production systems is limited to authorised personnel on a least-privilege basis, approved through access management, protected by multi-factor authentication, logged and reviewed regularly. No third parties have access to production data.
  • Customer user access. Customer users sign in through Microsoft’s identity platform. Trial users of the sample directory sign in with a one-time email code. OneDirectory stores no passwords. Access within the Service is role-based, and requests are restricted to the signed-in organisation.
  • Data minimisation. Microsoft Graph is accessed with least-privilege, read-only permissions to directory profile data. OneDirectory has no access to documents, email or other content. Customers can revoke access at any time in their Microsoft tenant.
  • Availability and backup. Data is replicated within the primary region. Encrypted, geo-redundant backups are stored separately from production. Backup restoration is tested at least annually.
  • Business continuity. A documented business continuity and disaster recovery plan is maintained and tested at least annually.
  • Secure development. Changes to production follow a controlled change management process, with secure coding practices, automated and manual testing, and access-controlled source code repositories.
  • Vulnerability management. Public-facing systems are regularly scanned for vulnerabilities, and vulnerabilities are remediated according to severity. Independent penetration testing is performed regularly.
  • Environment separation. Development and test environments are separate from production. Production customer data is not used in development or testing.
  • Personnel. Personnel are bound by confidentiality obligations and complete security awareness training. Background checks are performed on new personnel with access to production systems, where permitted by law.
  • Vendor management. Vendors that process Covered Data are subject to due diligence and written data protection terms.
  • Incident response. A documented incident response plan covers detection, escalation and resolution. Customers are notified of Data Security Breaches without undue delay and within 72 hours of the Processor becoming aware.
  • Security governance. Information security is overseen by senior management under a policy framework aligned with SOC 2. Risk assessments are performed at least annually.

Upon request, the Processor will provide further information about these measures under NDA.

Subprocessors

The Processor is authorised to subcontract the following processing activities to the following Subprocessors:

  • Microsoft (microsoft.com) – Data storage, web application hosting, backup, firewall, security
  • Cloudflare (cloudflare.com) – Firewall, DDoS protection, SSL/TLS encryption, CDN, DNS management
  • Fin (formerly Intercom) (intercom.com) – Support helpdesk, in-app support, changelog, product tours
  • Amplitude (amplitude.com) – Product analytics
  • WorkOS (workos.com) – Passwordless email sign-in for trial users of the sample directory
Product
Employee Directory Software Org Chart Software Employee Profile Software Employee Search Pricing Free Trial Log In
Support
Live Chat Email Support
Trust
Security Privacy Terms of Service Terms of Use DPA Support Policy
Resources
Blog Reviews Customers Employee Directory Guide Product Updates
Company
About OneDirectory Contact Us
© 2026 Vinewave (Pty) Ltd / OneDirectory®
Terms of Service
Privacy Policy
Cookie settings