Overview
This Data Processing Agreement ("DPA") is incorporated into the WorkProduct Terms of Service and applies whenever WorkProduct, Inc. ("Processor") processes personal data on behalf of you or your organization ("Controller") in connection with the WorkProduct.ai platform.
This DPA reflects the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection laws. By using the Service, you agree to the terms of this DPA.
Roles
Controller — you, the customer, who determines the purposes and means of processing personal data in connection with your use of the Service.
Processor — WorkProduct, Inc., which processes personal data only on your instructions and as described in this DPA.
Nature and purpose of processing
WorkProduct processes personal data solely to provide the Service described in the Terms of Service. Processing activities include:
- Authenticating users and managing accounts.
- Processing documents uploaded by the Controller to generate AI-assisted outputs (Policy Compiler analysis, redlines, bookmarks).
- Storing outputs and making them available to authorized users.
- Providing technical support and communicating about the Service.
WorkProduct does not process personal data for any purpose other than providing the Service, and never uses Controller data to train, fine-tune, or evaluate AI models.
Types of personal data processed
- User identifiers: name, work email address, job title, firm name.
- Authentication data: hashed credentials, session tokens.
- Content data: text and metadata contained in uploaded documents (which may include references to individuals named in policy or claims documents).
- Usage logs: IP addresses, timestamps, and feature interactions, retained for up to 90 days.
Data subjects
The individuals whose personal data may be processed include:
- The Controller's authorized employees and users of the Service.
- Third parties named in documents uploaded by the Controller (e.g., insureds, claimants, counsel).
Processor obligations
WorkProduct will:
- Process personal data only on documented instructions from the Controller.
- Ensure that personnel authorized to process personal data are bound by confidentiality obligations.
- Implement and maintain appropriate technical and organizational security measures (see Section 7).
- Assist the Controller in responding to data subject rights requests, to the extent feasible given the nature of the processing.
- Notify the Controller without undue delay upon becoming aware of a personal data breach.
- Delete or return all personal data upon termination of the Service, at the Controller's election.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
Security measures
- Encryption in transit: TLS 1.2 or higher on all connections.
- Encryption at rest: AES-256 on all stored data.
- Tenant isolation: Each customer's data is held in a logically isolated environment. No data is commingled across organizations.
- Access controls: Role-based access; employee access to production data requires documented business justification.
- Audit logging: All access to production systems is logged and retained for 12 months.
- Bermuda Form policies: Processed exclusively on UK-provisioned Azure infrastructure. No data transits US servers.
Sub-processors
WorkProduct uses the following sub-processors. We will notify the Controller of any intended changes at least 14 days in advance, giving the Controller the opportunity to object.
| Sub-processor |
Purpose |
Location |
| Microsoft Azure |
Cloud infrastructure, storage, model inference |
US / UK (Bermuda Form: UK only) |
| Stripe |
Payment processing |
US |
| Postmark / SendGrid |
Transactional email |
US |
International transfers
Personal data originating in the European Economic Area or the United Kingdom is transferred to the United States under the EU-US Data Privacy Framework and UK adequacy decision where applicable, or under Standard Contractual Clauses incorporated herein by reference. Bermuda Form data is not transferred outside the UK.
Term and termination
This DPA is effective for the duration of the Terms of Service. Upon termination, WorkProduct will delete all Controller personal data within 30 days, unless retention is required by law. The Controller may request a written confirmation of deletion.