Pebl Data Processing Addendum

June 2026

Introductory Provisions

This Data Processing Addendum (this "Addendum") is incorporated by reference into the Global Hiring Agreement and applies to the processing of Personal Data under the Agreement. It forms an integral part of the Agreement between: (i) Velocity Global, LLC d/b/a Pebl; and (ii) Client (as defined in the Agreement). This Addendum is effective as of the MTOS Effective Date. Pebl and Client may be hereinafter collectively referred to as the "Parties" and individually as a "Party."

 This Addendum outlines the Parties’ respective obligations as independent controllers in relation to Personal Data Processed under the Agreement. Each Party is independently responsible for complying with Applicable Data Protection Laws with respect to the Personal Data it controls and Processes.

By entering into the Agreement, the Parties enter into this Addendum on behalf of themselves and, to the extent required under Applicable Data Protection Laws, in the name and on behalf of their Affiliates and authorized representatives. The terms used in this Addendum shall have the meanings set forth in this Addendum.

Capitalized terms not otherwise defined herein shall have the meaning given to them in the Agreement. Except as modified below, the terms of the Agreement shall remain in full force and effect.

WHEREAS, the Parties acknowledge that each Party may Process Personal Data for the purposes set forth in the Agreement. Since both Parties determine the purpose and means of this processing of Personal Data, the Parties are both deemed to be independent Controllers of the Personal Data; and

WHEREAS, the Parties wish to document their respective responsibilities in connection with such controller-to-controller Processing and to facilitate cooperation in relation to Data Subject requests, security incidents, and international transfers under Applicable Data Protection Laws.

Definitions

In this Addendum:

"Affiliate" means an entity that owns or controls, is owned or controlled by, or is under common control or ownership with a Party, where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise.

"Anonymized Data" means data created from Personal Data that has been de-identified in such a manner that the Data Subject is not or no longer identifiable. For the purposes of this Addendum, the Parties agree that Anonymized Data must be irreversibly de-identified and not used for any profiling of Supported Workers.

"Applicable Data Protection Laws" means any applicable legislative or regulatory regime enacted by a recognized government, or governmental or administrative entity with the purpose of protecting the privacy rights of natural persons or households consisting of natural persons, including without limitation the GDPR, UK GDPR, Swiss DPA, PIPEDA, IT Act 2000, LGPD, PIPL, CCPA, and other applicable privacy and data protection laws.

"Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. For the avoidance of doubt, references in this Addendum to "controller" are to independent controllers unless expressly stated otherwise in the separate Processor Annex.

"Data Subject Rights" means a Data Subject’s rights under Applicable Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making, as applicable.

“De-identify" means information that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual or household.

"Permitted Processing Activities" means the Processing activities undertaken by each Party in connection with its rights and obligations under the Agreement and this Addendum.

"Processed Personal Data" means the Personal Data processed in connection with the Agreement and this Addendum.

  The terms "Data Subject", "Personal Data", "Personal Data Breach", and "Processing" shall have the meanings given to them in the GDPR, and their cognate terms shall be construed accordingly. For the avoidance of doubt, Data Subjects include without limitation any and all Supported Workers performing services for the Client under the Agreement.

1. Roles of the Parties

 The Parties acknowledge that, in relation to the Processed Personal Data exchanged or otherwise made available under the Agreement, each Party acts as an independent Controller and not as the other Party’s Processor. Pebl is the legal employer of the Data Subjects and controls the means of its processing in determining how the Personal Data flows and where it’s stored internally and in Pebl’s Platform. Client also controls the purpose and means of its processing in determining the services the Supported Workers are providing, and its Processing of Supported Worker Personal Data. Each Party independently determines the purposes and means of its Processing for the Permitted Processing Activities and shall comply with Applicable Data Protection Laws in respect of such Processing. For clarity, Pebl does not process any Client Confidential Information or Personal Data that Client shares directly with Supported Workers, and not with Pebl, as part of Client’s day-to-day management under the EOR model, including passwords, devices, login credentials, customer lists, and similar information or materials.

2. General Obligations

 This Addendum captures each Party’s responsibilities and process to ensure the enforceability of Data Subjects’ rights under Applicable Data Protection Laws. With regard to the Parties’ obligations to Data Subjects and the handling of Personal Data, the Parties hereby agree to the following provisions:

  • Each Party shall Process Personal Data lawfully, fairly, and transparently to the extent required by Applicable Data Protection Laws and shall maintain an appropriate legal basis for its Processing.
  • Each Party is independently responsible for providing any required privacy notices, maintaining records of processing where required by Applicable Data Protection Laws, and responding to supervisory authorities regarding its own Processing activities.
  • The Parties agree to only Process the Personal Data to the extent necessary to exercise rights and perform obligations under the Agreement; and not do or omit to do anything that would cause the other Party to breach its obligations under Applicable Data Protection Laws.  Each Party shall promptly notify the other Party of any change in Applicable Data Protection Laws that may reasonably be interpreted as materially adversely affecting that Party’s performance of the Agreement or this Addendum.
  • In no event will either Party sell Personal Data for any valuable consideration or retain, use, or disclose Personal Data for any purpose other than the specific purpose(s) contemplated in this Addendum and the Agreement  or for another purpose permitted by Applicable Data Protection Laws and compatible with the context in which the Personal Data was collected.
  • To the extent the CCPA/CPRA applies to Personal Information disclosed between the Parties under the Agreement or this Addendum, each Party acts as an independent business and third party, and not as a service provider or contractor unless otherwise agreed in writing. Each Party shall use such Personal Information only for the limited and specified purposes set out in the Agreement and this Addendum, provide the level of privacy protection required by the CCPA/CPRA, notify the other Party if it can no longer do so, and cooperate in reasonable remediation steps to address unauthorized use.
  • The Parties agree to implement and maintain appropriate technical and organisational measures in relation to the Processed Personal Data to ensure a level of security appropriate to the risk, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of Processing.

3. Data Subject Requests; Regulatory Cooperation

 A Data Subject may submit to either Party a request to exercise Data Subject Rights with respect to Personal Data Processed under the Agreement (an “Access Request”). The Party receiving the Access Request shall be responsible for responding in respect of the Personal Data it controls. To the extent reasonably necessary and legally permitted, the other Party shall provide reasonable cooperation and relevant information to enable the receiving Party to respond to the Access Request in accordance with Applicable Data Protection Laws. If either Party receives correspondence, an enquiry, or a complaint from a Data Subject, regulator, or third party relating to the disclosure or Processing of Personal Data under the Agreement, it shall promptly inform the other Party to the extent such matter is relevant to the other Party’s Processing. The Parties shall cooperate in good faith to address such matter in compliance with Applicable Data Protection Laws.

4. Details of the Processing

Annex I to this Addendum sets out certain information regarding the Processing of the Processed Personal Data.  Either Party may propose reasonable written updates to Annex I to reflect changes in the Services, data flows, or compliance requirements, provided that no such update confers additional substantive rights or obligations except as expressly agreed in writing.

5. Disclosure of Processed Personal Data

The Parties may disclose Personal Data to their employees, independent contractors, agents, and representatives who require access to such data in connection with the Parties' obligations under the Agreement or this Addendum. Both Parties shall take reasonable steps to ensure the reliability of any employee, independent contractor, agent or representative who may have access to the Processed Personal Data, ensuring that access is strictly limited to those individuals who need to know or access the relevant Personal Data as strictly necessary for the purposes of the Agreement and/or to comply with Applicable Data Protection Laws, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality in respect of the Processed Personal Data, and have undertaken training on the Applicable Data Protection Laws relating to handling Personal Data and how it applies to their particular duties.

6. Service Providers / Processors

Each Party may engage its own Processors service providers to support its Processing activities as an Independent Controller, provided that each Party remain liable for any such Processor’s performance of obligations under this Addendum or the Agreement; such Party remains responsible for ensuring that any such disclosures or transfers are made in accordance with Applicable Data Protection Laws; and that any processor engaged by that Party is bound by written terms providing a level of protection for Personal Data required by Applicable Data Protection Laws.

Pebl may Aggregate, Anonymize, or De-identify Personal Data and use the resulting data for analytics, benchmarking, service improvement, security, product development, and other lawful business purposes, provided that Pebl maintains such data in aggregated, anonymized, or de-identified form and does not attempt to re-identify it except to validate de-identification or as permitted by Applicable Data Protection Laws. Pebl will not use or disclose Aggregated or De-Identified Data in a manner that identifies Client, identifies any Data Subject, or reveals Client Confidential Information. Such data is not Personal Data to the extent it is no longer reasonably capable of identifying or being linked to an individual or household under Applicable Data Protection Laws. 

7. Deletion or Return of Data

 Upon termination or expiration of the Agreement, each Party shall retain, return, or delete Processed Personal Data under its control in accordance with the Agreement, its applicable retention obligations, and Applicable Data Protection Laws. Nothing in this Addendum requires a Party to delete Personal Data to the extent retention is required or permitted by applicable law, regulation, legal process, or legitimate recordkeeping requirements.

8. Incident Management 

Each Party shall notify the other Party without undue delay, and in any event within 72 hours of discovery where feasible, after becoming aware of a Personal Data Breach affecting Processed Personal Data to the extent the breach is reasonably likely to affect the other Party’s obligations, rights, or interests under the Agreement or Applicable Data Protection Laws. Each Party remains independently responsible for assessing the breach and for any notifications to supervisory authorities, affected Data Subjects, counterparties, or regulators that it is required to make under Applicable Data Protection Laws. The Parties shall cooperate in good faith, to the extent reasonably necessary and legally permitted, in investigating, mitigating, and remediating such Personal Data Breach. No notification made under this Section shall constitute an admission of fault or liability.

9. Assessments and Prior Consultations

Upon reasonable request, the Parties will provide one another reasonable assistance in connection with the performance of a data protection impact assessment or similar assessment required under any Applicable Data Protection Laws (each, a "DPIA"). If applicable, each Party will reasonably cooperate with the other Party in any consultation with a government or regulatory authority that arises out of a DPIA. 

10. Compliance with Laws

Upon either Party's reasonable request, the other Party will provide reasonable information necessary to demonstrate its compliance with this Addendum, subject to appropriate confidentiality, security, legal privilege, and commercial sensitivity restrictions. Any audit rights with respect to Pebl’s Processing as a Processor apply only as set out in the Processor Annex.All such information shall be deemed to be the Parties' Confidential Information. 

11. International Transfers

The Parties acknowledge and agree that each Party may Process Personal Data and/or permit Personal Data to be processed in accordance with this Addendum in a territory outside the European Economic Area ("EEA") or Switzerland. Therefore, for the purposes of compliance with Applicable Data Protection Laws relating to cross-border transfers of Personal Data, the Parties have executed the Standard Contractual Clauses published by the European Commission in June 2021 ("SCCs") which are incorporated herein by reference.  Each Party is responsible for ensuring that its own international transfers of Personal Data comply with Applicable Data Protection Laws, including by implementing an appropriate transfer mechanism where required.

Client acknowledges and agrees that Pebl may transfer to and Process Personal Data in the United States and anywhere else in the world where Pebl, its Affiliates, maintain data hosting, support, or operational activities. Pebl shall ensure that such transfers are made in compliance with Applicable Data Protection Laws and this Addendum.

Any transfer of Personal Data from member states of the European Union, EEA and/or Switzerland to a country that the European Commission has decided does not ensure an adequate level of protection for Personal Data ("Third Country") shall be made in accordance with the SCCs, in connection with which the Parties agree to the following:

For purposes of Annex I and the SCCs, the data exporter is the Party (or its relevant Affiliate) established in the EEA, the United Kingdom or Switzerland that sends Processed Personal Data to a Third Country and the data importer is the Party (or its relevant Affiliate) located in a Third Country who receives the Processed Personal Data. Any onward transfers within each Party’s corporate group (for example, a Client entity in the EEA or UK transferring Personal Data to a Client entity in India, or a Pebl entity in the EEA transferring Personal Data to a Pebl entity outside the EEA, UK or Switzerland) shall be subject to that Party’s own intra-group data transfer arrangements and fall outside the scope of this Addendum.

  • In relation to Personal Data that is subject to GDPR and Processed in accordance with this Addendum, Module One (Controller to Controller transfers) of the SCCs shall apply.
  • In Clause 7, the optional docking clause will apply.
  • In Clause 11, the optional language will not apply.
  • In Clause 17, Option 1 will apply and the SCCs will be governed by the law of the Netherlands.
  • In Clause 18(b), disputes will be resolved before the courts of the Netherlands.
  • Annex I of the SCCs shall be deemed completed with the information set out in Annex I to this Addendum.
  • Annex II of the SCCs shall be deemed completed with the information set out in Annex II to this Addendum.

In relation to Personal Data that is subject to the UK GDPR, the SCCs will apply in accordance with the terms set forth above, with the following modifications: Where a Party transfers Personal Data from the UK to a Third Country and the transfer is not permitted by an alternative means pursuant to Applicable Data Protection Laws, the SCCs shall be deemed amended by the UK Addendum attached as Annex IV.

In relation to Personal Data that is subject to the Swiss DPA, the SCCs will apply in accordance with the terms set forth above, with the modifications required for Swiss transfers, including interpreting references to the EU and Member State law as references to Switzerland and Swiss law, respectively, and references to the competent supervisory authority and courts as references to the FDPIC and competent Swiss courts, as applicable.

It is not the intention of either Party to contradict or restrict any of the provisions set forth in the SCCs and, accordingly, if and to the extent the SCCs conflict with any provision of the Agreement (including this Addendum) the SCCs shall prevail to the extent of such conflict.

 The Parties may agree in writing to adopt a replacement transfer mechanism or supplementary measures required by Applicable Data Protection Laws. Each Party shall execute such documents and take such actions as are reasonably necessary to give effect to such replacement mechanism for its own transfers.

12. General

All terms and conditions of the Agreement shall remain unchanged and in full force and effect. Except as expressly stated otherwise, all terms and conditions of the Agreement apply mutatis mutandis to this Addendum. In the event of any conflict or inconsistency between the terms of this Addendum and the Agreement, the terms of this Addendum will control.

For the avoidance of doubt, any controller-processor terms applicable only where Pebl acts as Processor are set out exclusively in the separate Processor Annex.

Annex I - Description of Controller-to-Controller Processing

List of Parties

Party

Details

Role

Pebl

Velocity Global, LLC d/b/a Pebl; 3790 El Camino Real #1010, Palo Alto, CA 94306 U.S.A.; Contact: Data Protection Officer, Privacy@hellopebl.com

EIN: 46-1915233

Controller

Client

Client as defined in the Agreement; contact details as set forth in the Agreement or otherwise provided in writing to Pebl

Controller

Description of Transfer

Topic

Description

Data subjects

Employees, candidates, and other workers whose Personal Data is processed under the Services, including Supported Workers.

Categories of personal data

Name and contact details, location data, payroll and financial details, demographic and employment data, government identification data, and other HR administration data necessary for the Services.

Sensitive data

Where applicable: benefits data, immigration data, background screening information, trade union membership where required by law, and legally permitted diversity/equal opportunity data, subject to Applicable Data Protection Laws.

Frequency

Continuous, as necessary for performance of the Agreement.

Nature and purpose

Controller-to-controller disclosures and related Processing necessary to provide or receive the Services, manage workforce administration, comply with employment, tax, immigration, social security, and legal obligations, and establish, exercise, or defend legal claims.

Retention

As specified in the Agreement and thereafter as required by applicable legal, regulatory, employment, tax, accounting, and record-retention obligations.

Competent supervisory authority

For EU GDPR transfers: the Netherlands supervisory authority, unless another authority is required by Applicable Data Protection Laws based on the exporter’s establishment.

 

Annex II - Technical and Organisational Measures

EXPLANATORY NOTE: Description of the technical and organisational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons.

Pebl maintains technical and organisational measures designed to ensure a level of security appropriate to the risks presented by the Processing of Personal Data, including measures relating to the ongoing confidentiality, integrity, availability and resilience of Processing systems and services, the ability to restore availability and access to Personal Data in a timely manner in the event of an incident, and processes for regularly testing, assessing and evaluating the effectiveness of such measures. Where appropriate, Pebl implements encryption for Personal Data in transit over public networks and at rest within its production systems, and manages encryption keys in accordance with its internal key-management procedures.

Governance

Pebl has an annual 3rd Party Security Assessment performed against ISO 27001 requirements. This assessment helps drive strategic and operational initiatives to continue to improve our Security Program's maturity. These initiatives include policies, security controls and demonstration of compliance with our regulatory drivers.

Authorization and confidentiality

Access Control Policy

Access controls will be established on all sites, systems, system documentation, applications, databases, directories, and files (information assets), using automated systems to enforce a role-based access control model, such that users only have access to the information assets necessary to perform their job function. Further, privileges, for example, Read, Write, Execute, etc., will be set using the principle of least privilege. The default posture will be to deny all access thereby requiring all access that is granted to be granted based on an approved role or access request. Roles are assigned based on user department, team, and job function.

Authentication and Identity Management Policy

All access to information resources shall use an approved method of identification and authentication. All third- party service provider access to the Pebl network and information systems must adhere to the same access restrictions as internal users.

Access rights shall be established, documented, and periodically reviewed based on business needs and external requirements. Access controls should consider:

  1. Security requirements given business needs, anticipated threats, and vulnerabilities.
  2. Relevant legislative and regulatory requirements.
  3. Contractual obligations and service level agreements.
  4. Consistency across Pebl's systems and networks.

 Access control considerations include:

  1. The use of clearly stated rules and rights based on user profiles.
  2. Consistent management of access rights across information resources using an appropriate mix of logical (technical) and physical access controls.
  3. Segregation of access control roles including access request by the appropriate department, access authorization by the data owner, and access administration by the network administrator.
  4. Requirements for the formal authorization and timely removal of access rights.

Personnel

Personnel Security Policy

Information security responsibilities are to be followed by all staff who have access to Pebl's information resources. All staff must acknowledge in writing that they have read the appropriate Acceptable Use Policy.

All staff must acknowledge that they have read and understood Pebl's Security Policies. In addition, all staff shall receive annual security related training.

All staff must sign a Pebl Non-disclosure Agreement prior to beginning work for Pebl.

Code of Conduct

Employees, officers and directors must maintain the confidentiality of confidential information entrusted to them, including our suppliers and customers, except when disclosure is authorized by a supervisor or legally mandated. Unauthorized disclosure of any confidential information is prohibited. Additionally, employees should take appropriate precautions to ensure that confidential or sensitive business information, whether it is proprietary to the company or another company, is not communicated except to employees who have a need to know such information to perform their responsibilities.

Physical security of the operating environment

Pebl maintains ISO 27001-2022 and SOC 2 Type 2 compliance and certification. 

Penetration Testing

Pebl performs third-party penetration tests on an annual basis.  This procedure is part of Pebl’s due diligence to verify the efficacy of its security infrastructure.

Multi-Factor Authentication

Pebl’s platform mandates the use of Multi-Factor Authentication (MFA) for user access.  All users must initialize and configure MFA protocols during the activation phase and upon their initial platform login.

Security tools and procedures

As part of its core offering, Pebl leverages Amazon Web Services to deliver its SaaS solution. Before reaching customer instances, network traffic passes through multiple layers of network protections. These include DDOS protection, isolated VLANs, and firewalls. Production environments are segmented from QA and other non-production environments - this deployment pattern is replicated throughout Pebl's global deployment footprint.

In addition to its core infrastructure as defined above, Pebl maintains its standard approach to secure practices. This is updated annually and includes its coverage of hardware, software, network monitoring protocol and procedure.

 Monitoring and logging

Intrusion Detection and/or Prevention Systems must be deployed on all Production systems. These solutions shall be configured to alert personnel to potential information security events. Alerts and security events shall be reported and responded to. These solutions shall also be maintained with updated patches and signatures on a regular basis – at least weekly when available.

Annex III 

If Pebl acts as Processor in a given service model, subprocessors will be addressed solely in the separate Processor Annex and the subprocessor schedule incorporated there.

Annex IV - UK Addendum

This International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Version B1.0, in force 21 March 2022 (the "Addendum") has been issued by the Information Commissioner for Parties making Restricted Transfers. The Information Commissioner considers that it provides Appropriate Safeguards for Restricted Transfers when it is entered into as a legally binding contract. No revisions have been made to the language of this Addendum.

Part 1: Tables

Table 1: Parties

Field

Exporter (who sends the Restricted Transfer)

Importer (who receives the Restricted Transfer)

Start Date

As of the latest signature on this Addendum.

As of the latest signature on this Addendum.

Parties' Details

As listed in Annex I of this DPA.

As listed in Annex I of this DPA.

Key Contact

As listed in Annex I of this DPA.

As listed in Annex I of this DPA.

Signature (if required for the purposes of Section 2)

As listed in Annex I of this DPA.

As listed in Annex I of this DPA.

Table 2: Selected SCCs, Modules and Selected Clauses

Module

Module in Operation

Clause 7 (Docking Clause)

Clause 11 (Option)

Clause 9a (Prior or General Authorisation)

Clause 9a Time Period

Is personal data received from the Importer combined with personal data collected by the Exporter?

Module 1 (Controller to Controller)

X

X

Does not apply

N/A

N/A

No

 

Table 3: Appendix Information

Appendix Item

Location in this DPA / Annex

Annex IA: List of Parties

As listed in Annex I of this DPA.

Annex IB: Description of Transfer

As listed in Annex I of this DPA.

Annex II: Technical and Organisational Measures

As listed in Annex II of this DPA.

Annex III: List of Sub-processors (Modules 2 and 3 only)

N/A

Table 4: Ending this Addendum when the Approved Addendum Changes

Field

Selection

Which Parties may end this Addendum as set out in Section 19

Importer and Exporter

Alternative Part 2 Mandatory Clauses

Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.

 

Processor Annex 

1. Scope and Order of Precedence

This Processor Annex supplements the Addendum solely to the extent Pebl Processes Personal Data on behalf of Client as a Processor, including with respect to payroll-only services for Client employees, platform hosting, and limited administrative components of contractor management services, in each case only where the applicable Order Form, statement of work, service description, or other ordering document identifies or reasonably contemplates such Processor services. Capitalized terms used but not defined in this Processor Annex have the meanings given in the Addendum or the Agreement, as applicable. In the event of any conflict between this Processor Annex and the Addendum, this Processor Annex controls only with respect to such Processor activities, and the Addendum otherwise remains controller-to-controller.

For purposes of this Processor Annex only, “Subprocessor” means any third-party engaged by or acting under the instructions of a Processor to Process Personal Data and assist in fulfilling obligations with respect to providing Services under the Agreement or this Addendum. The terms, “Business,” “Business Purpose,” “Service Provider,” “Share,” “Sell,” “Sale,” or “Sold,” shall have the meanings given to them in the California Consumer Privacy Act of 2018 (as amended by the California Privacy Rights Act of 2020), Cal. Civil Code § 1798.100 et seq., and its implementing regulations, including any amendments thereto (collectively, the “CPRA”).

2. Subject Matter and Duration of Processing

The subject matter, nature, and purpose of the Processing, the types of Personal Data, the categories of Data Subjects, and the duration of the Processing are described in the Agreement and Annex I, as applicable to the relevant Processor service model. Pebl shall Process Personal Data for the duration of the Agreement and any transition/termination period during which Pebl is required to provide the Processor services. For the avoidance of doubt, Pebl does not act as a Processor in connection with Employer of Record Services.

3. Documented Instructions

Pebl shall Process Personal Data only on documented instructions from Client, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by applicable law to which Pebl is subject. In that case, Pebl shall inform Client of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest. The Agreement, this Processor Annex, and Client’s written directions under the Agreement constitute Client’s complete documented instructions as of the effective date, and any additional instructions requiring material changes to the Services may be subject to mutual agreement on scope, feasibility, and fees.

4. Confidentiality

Pebl shall ensure that persons authorised to Process Personal Data have committed themselves to confidentiality substantially similar to that outlined in the Agreement or are under an appropriate statutory obligation of confidentiality.

5. Security of Processing

Pebl shall implement appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, as described in Annex II of the Addendum, including as appropriate: pseudonymisation and encryption; the ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems and services; the ability to restore availability and access in a timely manner after an incident; and a process for regularly testing, assessing, and evaluating the effectiveness of such measures.

6. Assistance with Data Subject Requests

Taking into account the nature of the Processing, Pebl shall provide reasonable assistance to Client for the fulfilment of Client’s obligation to respond to requests for exercising Data Subject Rights under Applicable Data Protection Laws. If Pebl receives such a request directly, Pebl shall promptly notify Client and shall not respond to the request except on Client’s documented instructions or as required by applicable law.

7. Assistance with Security, Breach, DPIA, and Consultation Obligations

Taking into account the nature of Processing and the information available to Pebl, Pebl shall provide reasonable assistance to Client in ensuring compliance with Client’s obligations under Articles 32 to 36 GDPR and analogous provisions of other Applicable Data Protection Laws, including with respect to security of processing, Personal Data Breach notification, data protection impact assessments, and prior consultations with supervisory authorities.

8. Personal Data Breach Notification

Pebl shall notify Client without undue delay, and where feasible no later than seventy-two (72) hours after becoming aware of a Personal Data Breach affecting Processed Personal Data under this Processor Annex. Pebl shall provide information reasonably available to Pebl to assist Client in meeting any breach notification obligations and shall take reasonable steps to identify the cause of the breach, mitigate its effects, and prevent recurrence.

9. Subprocessors

Client grants Pebl a general authorization to engage subprocessors for the Processor services, provided that Pebl shall maintain an up-to-date list of subprocessors and give Client prior notice of any new subprocessor appointment or replacement. Client may object on reasonable data protection grounds within fourteen (14) days after receipt of notice. Pebl shall impose data protection obligations on each subprocessor by written contract that are no less protective than those set out in this Processor Annex, to the extent applicable to the services performed by the subprocessor. Pebl remains responsible for the performance of each subprocessor’s obligations to the extent required by Applicable Data Protection Laws.

10. International Transfers

Where Pebl transfers Personal Data subject to GDPR, UK GDPR, or Swiss DPA to a third country in connection with Processor services, Pebl shall implement an appropriate transfer mechanism under Applicable Data Protection Laws. For GDPR-restricted transfers from Client as controller to Pebl as processor, Module Two of the 2021 SCCs shall apply, with Clause 7 (optional docking clause) enabled, Clause 9 Option 2 (general authorization) enabled with a fourteen (14) day notice period, Clause 11(a) omitted, Clause 17 Option 1 selecting the laws of the Netherlands, and Clause 18(b) selecting the courts of the Netherlands. For UK transfers, the UK Addendum shall apply to Module Two as required. For Swiss transfers, the SCCs shall be interpreted as required for Swiss law. If and to the extent the SCCs conflict with any provision of the Agreement, Addendum, or this Processor Annex, the SCCs shall prevail to the extent of such conflict.

11. Return and Deletion

At Client’s choice, Pebl shall delete or return all Personal Data after the end of the provision of Processor services, and delete existing copies, unless applicable law requires storage of the Personal Data. Pebl may retain Personal Data only to the extent and for the period required by applicable law and shall continue to ensure the confidentiality of such retained Personal Data, and will not actively process it for any purpose other than complying with applicable law, enforcing legal rights, or completing secure deletion in accordance with Pebl’s standard backup and records-destruction procedures.

Pebl may Aggregate, Anonymize, or De-identify Personal Data processed on behalf of Client and use the resulting data for analytics, benchmarking, service improvement, security, product development, and other lawful business purposes, provided that Pebl: (a) maintains such data in aggregated, anonymized, or de-identified form; (b) does not attempt to re-identify it except to validate de-identification; and (c) requires recipients to comply with substantially similar restrictions. Such data is not Personal Data to the extent it is no longer reasonably capable of identifying or being linked to an individual or household under Applicable Data Protection Laws. Pebl will not use or disclose Aggregated or De-Identified Data in a manner that identifies Client, identifies any Data Subject, or reveals Client Confidential Information.

12. Information and Audit Rights

Pebl shall make available to Client all information reasonably necessary to demonstrate compliance with this Processor Annex and Article 28 GDPR, and shall allow for and contribute to audits conducted by Client or an auditor mandated by Client, subject to reasonable confidentiality, security, and operational safeguards. Pebl may satisfy audit obligations by providing current third-party audit reports, summaries, certifications, or comparable independent attestations where such materials provide Client with reasonably sufficient information, except where Applicable Data Protection Laws require more extensive audit rights. Any such audit shall be conducted no more than once annually, unless required by Applicable Data Protection Laws or following a Personal Data Breach affecting Personal Data processed under this Processor Annex, during normal business hours, on reasonable prior notice, and in a manner designed to avoid unreasonable disruption to Pebl’s business, systems, and other customers.

13. Unlawful Instructions

Pebl shall inform Client without undue delay if, in Pebl’s opinion, an instruction infringes GDPR or other applicable data protection law.

14. CCPA / U.S. Addendum Concepts (Where Applicable)

To the extent U.S. state privacy laws apply and Pebl acts as a processor/service provider/contractor, Pebl shall not sell or share Personal Data, shall not retain, use, or disclose Personal Data outside the direct business relationship between the Parties except as permitted by applicable law and the Agreement, and shall comply with any additional processor/service-provider obligations imposed by such laws.

15. Annex Materials for Processor Configuration

For any Processor service model, the following annexes apply: (a) Annex I description of processing for the Processor services; (b) Annex II technical and organisational measures; (c) Annex III the current subprocessor list; and (d) where applicable, the UK Addendum and Swiss transfer language aligned to Module Two.

 

ANNEX I – LIST OF PARTIES AND DESCRIPTION OF PROCESSING

A. LIST OF PARTIES

Data Importer  /Exporter / Controller

Client (as defined in the Agreement)

Address

Client address as set forth on the Order Form

Contact

As set forth on the Client company profile page in the Platform or otherwise identified in writing to Pebl

Activities relevant to transfer

Receipt of Services under the Agreement

Role

Controller

Data Importer / Exporter / Processor

Velocity Global, LLC d/b/a Pebl

Address

3790 El Camino Real #1010, Palo Alto, CA 94306 U.S.A.

Contact

Data Protection Officer; Privacy@hellopebl.com; +1 (303) 309-2894

Activities relevant to transfer

Performance of Services under the Agreement

Role

Processor

B. DESCRIPTION OF PROCESSING

  • Categories of data subjects: contractors or employees whose data is processed for payroll-only services, platform-hosting services, or other specifically identified processor services.

  • Categories of personal data: name and contact details, location data, payroll and bank account details, job-related data, government identifier data, benefits and leave data, and other personnel administration data necessary for the applicable processor service.

  • Sensitive data, where applicable: benefits data, immigration-related data, trade-union membership where required by law, criminal background data where requested, and certain equal opportunity data where lawful and requested.

  • Nature of processing: onboarding/offboarding support, payroll calculations and administration, benefits administration support, time/attendance or expense administration, platform hosting, and related HR administrative processing as set out in the applicable order documents.

  • Purpose of processing: to provide the relevant Services to Client and comply with applicable employment, labor, tax, social security, immigration, and recordkeeping laws.

  • Duration of processing and retention: for the term of the Services and thereafter for the period required by applicable law and Pebl’s documented retention obligations.

C. COMPETENT SUPERVISORY AUTHORITY

Where the EU GDPR applies, the competent authority shall be the Netherlands Data Protection Authority. Where the UK GDPR applies, the competent authority shall be the UK Information Commissioner’s Office.

Annex II - Technical and Organisational Measures

EXPLANATORY NOTE: Description of the technical and organisational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons.

Pebl maintains technical and organisational measures designed to ensure a level of security appropriate to the risks presented by the Processing of Personal Data, including measures relating to the ongoing confidentiality, integrity, availability and resilience of Processing systems and services, the ability to restore availability and access to Personal Data in a timely manner in the event of an incident, and processes for regularly testing, assessing and evaluating the effectiveness of such measures. Where appropriate, Pebl implements encryption for Personal Data in transit over public networks and at rest within its production systems, and manages encryption keys in accordance with its internal key-management procedures.

Governance

Pebl has an annual 3rd Party Security Assessment performed against ISO 27001 requirements. This assessment helps drive strategic and operational initiatives to continue to improve our Security Program's maturity. These initiatives include policies, security controls and demonstration of compliance with our regulatory drivers.

Authorization and confidentiality

Access Control Policy

Access controls will be established on all sites, systems, system documentation, applications, databases, directories, and files (information assets), using automated systems to enforce a role-based access control model, such that users only have access to the information assets necessary to perform their job function. Further, privileges, for example, Read, Write, Execute, etc., will be set using the principle of least privilege. The default posture will be to deny all access thereby requiring all access that is granted to be granted based on an approved role or access request. Roles are assigned based on user department, team, and job function.

Authentication and Identity Management Policy

All access to information resources shall use an approved method of identification and authentication. All third- party service provider access to the Pebl network and information systems must adhere to the same access restrictions as internal users.

Access rights shall be established, documented, and periodically reviewed based on business needs and external requirements. Access controls should consider:

  • Security requirements given business needs, anticipated threats, and vulnerabilities.
  • Relevant legislative and regulatory requirements.
  • Contractual obligations and service level agreements.
  • Consistency across Pebl's systems and networks.

Access control considerations include:

  1. The use of clearly stated rules and rights based on user profiles.
  2. Consistent management of access rights across information resources using an appropriate mix of logical (technical) and physical access controls.
  3. Segregation of access control roles including access request by the appropriate department, access authorization by the data owner, and access administration by the network administrator.
  4. Requirements for the formal authorization and timely removal of access rights.

 Personnel

Personnel Security Policy

Information security responsibilities are to be followed by all staff who have access to Pebl's information resources. All staff must acknowledge in writing that they have read the appropriate Acceptable Use Policy.

All staff must acknowledge that they have read and understood Pebl's Security Policies. In addition, all staff shall receive annual security related training.

All staff must sign a Pebl Non-disclosure Agreement prior to beginning work for Pebl.

Code of Conduct

Employees, officers and directors must maintain the confidentiality of confidential information entrusted to them, including our suppliers and customers, except when disclosure is authorized by a supervisor or legally mandated. Unauthorized disclosure of any confidential information is prohibited. Additionally, employees should take appropriate precautions to ensure that confidential or sensitive business information, whether it is proprietary to the company or another company, is not communicated except to employees who have a need to know such information to perform their responsibilities.

Physical security of the operating environment

Pebl maintains ISO 27001-2022 and SOC 2 Type 2 compliance and certification. 

Penetration Testing

Pebl performs third-party penetration tests on an annual basis.  This procedure is part of Pebl’s due diligence to verify the efficacy of its security infrastructure.

Multi-Factor Authentication

Pebl’s platform mandates the use of Multi-Factor Authentication (MFA) for user access.  All users must initialize and configure MFA protocols during the activation phase and upon their initial platform login.

Security tools and procedures

As part of its core offering, Pebl leverages Amazon Web Services to deliver its SaaS solution. Before reaching customer instances, network traffic passes through multiple layers of network protections. These include DDOS protection, isolated VLANs, and firewalls. Production environments are segmented from QA and other non-production environments - this deployment pattern is replicated throughout Pebl's global deployment footprint.

In addition to its core infrastructure as defined above, Pebl maintains its standard approach to secure practices. This is updated annually and includes its coverage of hardware, software, network monitoring protocol and procedure.

 Monitoring and logging

Intrusion Detection and/or Prevention Systems must be deployed on all Production systems. These solutions shall be configured to alert personnel to potential information security events. Alerts and security events shall be reported and responded to. These solutions shall also be maintained with updated patches and signatures on a regular basis – at least weekly when available.

 

ANNEX III – CURRENT SUBPROCESSORS

Located at the following address: hellopebl.com/legal/annex-3-current-subprocessors/

Annex IV - UK Addendum

This International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Version B1.0, in force 21 March 2022 (the "Addendum") has been issued by the Information Commissioner for Parties making Restricted Transfers. The Information Commissioner considers that it provides Appropriate Safeguards for Restricted Transfers when it is entered into as a legally binding contract. No revisions have been made to the language of this Addendum.

Part 1: Tables

Table 1: Parties

Field

Exporter (who sends the Restricted Transfer)

Importer (who receives the Restricted Transfer)

Start Date

As of the latest signature on this Addendum.

As of the latest signature on this Addendum.

Parties' Details

As listed in Annex I of this DPA.

Velocity Global, LLC d/b/a Pebl, 3790 El Camino Real #1010, Palo Alto, CA 94306 U.S.A.; EIN 46-1915233.

Key Contact

As listed in Annex I of this DPA.

Data Protection Officer, Privacy@hellopebl.com, 3790 El Camino Real #1010, Palo Alto, CA 94306 U.S.A.

Signature (if required for the purposes of Section 2)

As listed in Annex I of this DPA.

As listed in Annex I of this DPA.

 

Table 2: Selected SCCs, Modules and Selected Clauses

Module

Module in Operation

Clause 7 (Docking Clause)

Clause 11 (Option)

Clause 9a (Prior or General Authorisation)

Clause 9a Time Period

Is personal data received from the Importer combined with personal data collected by the Exporter?

Module 2 (Controller to Processor)

X

X

Does not apply

General authorisation

14 Days

Yes

 

Table 3: Appendix Information

Appendix Item

Location in this DPA / Annex

Annex IA: List of Parties

As listed in Annex I of this DPA.

Annex IB: Description of Transfer

As listed in Annex I of this DPA.

Annex II: Technical and Organisational Measures

As listed in Annex II of this DPA.

Annex III: List of Sub-processors (Modules 2 and 3 only)

As listed in Annex III of this DPA.

 

Table 4: Ending this Addendum when the Approved Addendum Changes

Field

Selection

Which Parties may end this Addendum as set out in Section 19

Importer and Exporter

 

Alternative Part 2 Mandatory Clauses

Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.