Document Version: 3.1
Effective Date: January 15, 2024
Last Updated: January 15, 2024
This Subprocessor List identifies third-party subprocessors that WorkDuty engages to process Customer Data. We maintain contractual agreements with all subprocessors that include data protection obligations consistent with our Data Processing Addendum (DPA).
DEFINITIONS
- Subprocessor: Any third party engaged by WorkDuty to process Customer Data
- Customer Data: Personal data submitted to the WorkDuty services
- Processing: Any operation performed on Customer Data
- DPA: Data Processing Addendum between WorkDuty and Customer
SUBPROCESSOR ENGAGEMENT PROCESS
1. Due Diligence
Before engaging any new subprocessor, WorkDuty conducts:
- Security assessment
- Compliance verification
- Data protection capability review
- Contractual obligation alignment
2. Notification Process
- New Subprocessors: 30-day advance notice via email and website update
- Objection Period: Customers may object within 15 days of notification
- Resolution: WorkDuty will address reasonable objections or terminate affected services
3. Contractual Safeguards
All subprocessors are bound by:
- Data Processing Agreements (DPAs)
- Confidentiality obligations
- Security requirements
- Audit rights (where applicable)
CATEGORIES OF SUBPROCESSORS
A. Infrastructure & Hosting
Subprocessors that provide computing infrastructure and hosting services.
B. Communication Services
Subprocessors that facilitate communication with users.
C. Analytics & Monitoring
Subprocessors that help monitor and improve service performance.
D. Payment Processing
Subprocessors that handle payment transactions.
E. Support & Operations
Subprocessors that assist with customer support and business operations.
CURRENT SUBPROCESSORS
A. INFRASTRUCTURE & HOSTING
| Subprocessor | Service Provided | Data Location | Purpose | Security Certification |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud Infrastructure | Multi-region (Customer choice) | Primary hosting, storage, and computing | SOC 1/2/3, ISO 27001, PCI DSS |
| Microsoft Azure | Backup & Disaster Recovery | US-East, EU-West | Secondary backup and DR site | SOC 1/2/3, ISO 27001 |
| Cloudflare | CDN & DDoS Protection | Global edge network | Content delivery and security | SOC 2, ISO 27001 |
| MongoDB Atlas | Database as a Service | Co-located with AWS region | Primary database service | SOC 2, ISO 27001 |
| Redis Labs | Caching Service | Co-located with AWS region | Session and data caching | SOC 2, ISO 27001 |
B. COMMUNICATION SERVICES
| Subprocessor | Service Provided | Data Location | Purpose | Security Certification |
|---|---|---|---|---|
| Twilio | Email & SMS Services | US, EU (Customer choice) | Transactional notifications | SOC 2, ISO 27001 |
| SendGrid (Twilio) | Email Delivery | US, EU, Australia | Marketing communications | SOC 2, ISO 27001 |
| Postmark | Transactional Email | US, EU | Critical system notifications | SOC 2 |
| MessageBird | SMS & Voice | Global | Two-factor authentication | ISO 27001 |
C. ANALYTICS & MONITORING
| Subprocessor | Service Provided | Data Location | Purpose | Security Certification |
|---|---|---|---|---|
| Datadog | Application Monitoring | US, EU | Performance monitoring and logging | SOC 2, ISO 27001 |
| Sentry | Error Tracking | US, EU | Application error monitoring | SOC 2 |
| Amplitude | Product Analytics | US, EU | Usage analytics (anonymized) | SOC 2, ISO 27001 |
| Google Analytics | Website Analytics | Global | Website traffic analysis | ISO 27001 |
| Mixpanel | User Behavior Analytics | US | Feature usage analytics | SOC 2 |
D. PAYMENT PROCESSING
| Subprocessor | Service Provided | Data Location | Purpose | Security Certification |
|---|---|---|---|---|
| Stripe | Payment Processing | US, EU, Australia | Global subscription billing and payments | PCI DSS Level 1, SOC 1/2/3 |
| PayFast | Payment Processing | South Africa (ZA) | Primary payment gateway for South African customers, supporting cards, instant EFT, and local payment methods | PCI DSS Level 1, POPIA compliant, PA-DSS validated |
| PayPal | Payment Processing | Global | Alternative payment method for international customers | PCI DSS Level 1 |
| Chargebee | Subscription Management | US, EU | Billing and invoicing automation | SOC 2, ISO 27001 |
| Xero | Accounting Integration | AU, US, UK, EU | Financial reconciliation and accounting sync | SOC 1, ISO 27001 |
E. SUPPORT & OPERATIONS
| Subprocessor | Service Provided | Data Location | Purpose | Security Certification |
|---|---|---|---|---|
| Zendesk | Customer Support | US, EU | Help desk and support tickets | SOC 2, ISO 27001 |
| Intercom | Customer Communication | US, EU | In-app messaging and support | SOC 2, ISO 27001 |
| Atlassian (Jira) | Issue Tracking | US, EU, Australia | Internal bug and task tracking | SOC 2, ISO 27001 |
| Slack | Internal Communication | US, EU, Australia | Team collaboration | SOC 2, ISO 27001 |
| Google Workspace | Productivity Tools | Global (Customer choice) | Email and document collaboration | SOC 1/2/3, ISO 27001 |
| Notion | Documentation | US | Internal documentation | SOC 2 |
F. SECURITY SERVICES
| Subprocessor | Service Provided | Data Location | Purpose | Security Certification |
|---|---|---|---|---|
| Auth0 (Okta) | Identity Management | US, EU, Australia | Authentication services | SOC 2, ISO 27001 |
| HashiCorp Vault | Secrets Management | Co-located with AWS | Encryption key management | SOC 2 |
| Snyk | Vulnerability Scanning | US, EU | Dependency and container scanning | SOC 2 |
| Tenable | Security Scanning | US | Infrastructure vulnerability scanning | ISO 27001 |
G. INTEGRATION PARTNERS
| Subprocessor | Service Provided | Data Location | Purpose | Security Certification |
|---|---|---|---|---|
| DocuSign | Electronic Signatures | US, EU, Australia | Document signing integration | SOC 1/2/3, ISO 27001 |
| Zapier | Workflow Automation | US | Integration connectivity | SOC 2 |
| Make (Integromat) | Automation Platform | EU | Workflow automation | ISO 27001 |
DATA FLOW DIAGRAM
text
Customer Data Flow:
[Customer] → [WorkDuty Application] → [AWS Primary Region]
↓
[Backups] → [Microsoft Azure DR Site]
↓
[CDN] → [Cloudflare Edge]
↓
[Monitoring] → [Datadog/Sentry]
↓
[Communications] → [Twilio/Postmark]
↓
[Payments] → [Stripe/Chargebee]
DATA LOCATION DETAILS
Primary Processing Locations (Customer Choice):
- United States: AWS us-east-1 (Virginia)
- European Union: AWS eu-central-1 (Frankfurt)
- Asia Pacific: AWS ap-southeast-1 (Singapore)
- Australia: AWS ap-southeast-2 (Sydney) – Q2 2024
- South Africa: AWS af-south-1 (Cape Town) – Q2 2024
Backup Locations:
- US customers: Azure US-East (paired with AWS region)
- EU customers: Azure West Europe (paired with AWS region)
- APAC customers: Azure Australia East (paired with AWS region)
Subprocessor Data Location Compliance:
- All subprocessors maintain data in regions compliant with customer choice
- Cross-border transfers only with appropriate safeguards (SCCs, etc.)
- Subprocessor locations documented in individual DPAs
SECURITY MEASURES BY SUBPROCESSOR CATEGORY
Infrastructure Providers:
- Encryption: All data encrypted at rest and in transit
- Access Controls: Strict IAM policies and MFA enforcement
- Monitoring: 24/7 security monitoring and incident response
- Compliance: Regular third-party audits and certifications
Communication Providers:
- Data Minimization: Only necessary data shared
- TLS Encryption: All communications encrypted
- Retention Policies: Limited data retention periods
- Access Logs: Complete audit trails
Payment Processors:
- PCI Compliance: All providers PCI DSS certified
- Tokenization: Card data never stored in WorkDuty systems
- Fraud Detection: Advanced fraud monitoring
- Compliance: Regular security assessments
SUBPROCESSOR CHANGE LOG
Recent Additions:
| Date | Subprocessor | Category | Reason for Addition |
|---|---|---|---|
| 2024-01-10 | HashiCorp Vault | Security | Enhanced secrets management |
| 2023-12-15 | Make (Integromat) | Integration | Advanced workflow automation |
| 2023-11-20 | Tenable | Security | Expanded vulnerability scanning |
Recent Removals:
| Date | Subprocessor | Category | Reason for Removal |
|---|---|---|---|
| 2023-10-15 | Mailchimp | Communication | Replaced with SendGrid |
| 2023-09-30 | Heroku | Infrastructure | Consolidated to AWS |
Upcoming Changes (Notified):
| Planned Date | Change | Impact | Customer Notice Date |
|---|---|---|---|
| 2024-03-01 | Add AWS South Africa region | New data location option | 2024-02-01 |
| 2024-04-15 | Add Zoom integration | New video conferencing integration | 2024-03-15 |
CUSTOMER CONTROLS & OPTIONS
1. Subprocessor Opt-Outs
Certain subprocessors can be disabled per customer request:
- Google Analytics: Can be disabled for entire organization
- Marketing Communications: Opt-out of SendGrid for marketing emails
- Product Analytics: Disable Mixpanel/Amplitude tracking
2. Data Location Preferences
Customers can specify:
- Primary data processing region
- Backup region preferences
- Communication service regions
3. Integration Controls
- Enable/disable specific integrations
- Configure data sharing permissions per integration
- Set integration-specific retention policies
COMPLIANCE DOCUMENTATION
Available Upon Request:
- Subprocessor DPAs: Individual data processing agreements
- Security Certificates: Current compliance certifications
- Audit Reports: Third-party audit reports (under NDA)
- Penetration Test Reports: Security assessment reports
Access Process:
- Submit request to compliance@workduty.com
- Sign mutual NDA if required
- Receive documentation within 10 business days
EMERGENCY SUBPROCESSOR CHANGES
In exceptional circumstances (security incidents, service failures), WorkDuty may engage temporary subprocessors without prior notice. In such cases:
- Customers will be notified within 24 hours
- Temporary subprocessors will meet equivalent security standards
- Engagement will be limited to emergency duration only
- Regular subprocessor approval process will be followed post-emergency
CUSTOMER RESPONSIBILITIES
Customer-Controlled Subprocessors:
When customers enable third-party integrations through WorkDuty, they become responsible for:
- Reviewing integration security
- Managing integration permissions
- Monitoring integration data access
- Complying with integration terms
Data Sharing Considerations:
Customers should:
- Review subprocessor security documentation
- Understand data flow between subprocessors
- Configure appropriate data sharing settings
- Monitor subprocessor performance and security
FREQUENTLY ASKED QUESTIONS
Q1: How often is this list updated?
A: This list is updated quarterly or whenever subprocessor changes occur. Customers receive email notifications of changes.
Q2: Can I prohibit specific subprocessors?
A: Yes, for certain optional subprocessors. Contact support@workduty.online to discuss options.
Q3: How are subprocessor security incidents handled?
A: WorkDuty monitors all subprocessors for security incidents. If a subprocessor experiences a breach affecting Customer Data, we will notify affected customers within 24 hours.
Q4: Can I get copies of subprocessor DPAs?
A: Yes, all subprocessor DPAs are available under NDA for enterprise customers.
Q5: How do you ensure subprocessor compliance?
A: Through regular security assessments, contractual obligations, and continuous monitoring of subprocessor security postures.
CONTACT INFORMATION
Subprocessor Inquiries:
Email: subprocessors@workduty.online
Phone: +27 87 094 0710
Website: workduty.com/subprocessors
Security Questions:
Email: security@workduty.online
Emergency: security-emergency@workduty.online
Compliance Documentation:
Email: compliance@workduty.online
CHANGE NOTIFICATION SUBSCRIPTION
Customers can subscribe to subprocessor change notifications:
- Log in to WorkDuty
- Navigate to Settings → Security → Subprocessors
- Enable “Change Notifications”
- Choose notification frequency (Immediate, Daily Digest, Weekly)
ACKNOWLEDGEMENT
By using WorkDuty services, customers acknowledge they have reviewed this Subprocessor List and understand how their data is processed through these third-party services.
Last Reviewed: January 15, 2024
Next Scheduled Review: April 15, 2024
Document Owner: Chief Technology Officer
Approved By: Legal & Compliance Committee
This document is part of WorkDuty’s commitment to transparency and compliance with global data protection regulations including GDPR, POPIA, CCPA, and other applicable laws.