1.Definitions
In this Data Processing Agreement ("DPA"): "Controller" means the entity that determines the purposes and means of processing Personal Data (typically the Customer); "Processor" means the entity that processes Personal Data on behalf of the Controller (BambooHR); "Data Subject" means the identified or identifiable natural person to whom Personal Data relates; "Personal Data" means any information relating to an identified or identifiable natural person; "Processing" means any operation performed on Personal Data; "Security Incident" means any confirmed unauthorized acquisition, access, use, or disclosure of Personal Data.
"GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation) and, where applicable, the United Kingdom version of the GDPR as retained in UK law ("UK GDPR"). "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses adopted by the European Commission for the transfer of Personal Data to processors established in third countries.
2.Scope and Nature of Processing
This DPA applies to the processing of Personal Data by BambooHR as a Processor on behalf of Customer as Controller in connection with BambooHR's provision of the Services. BambooHR will process Personal Data only to the extent necessary to provide the Services and in accordance with Customer's documented instructions, including those set out in the Customer Terms of Service and any applicable Order Form.
BambooHR shall not process Customer's Personal Data for any other purpose, including BambooHR's own commercial purposes, without Customer's prior written consent, except where required by applicable law, in which case BambooHR will inform Customer of that legal requirement before processing unless prohibited by law.
3.Processor Obligations
BambooHR shall: (a) process Personal Data only on documented instructions from Customer; (b) ensure that persons authorised to process the Personal Data have committed themselves to confidentiality; (c) implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk; (d) assist Customer in responding to Data Subject rights requests; (e) assist Customer in ensuring compliance with obligations relating to security, breach notification, data protection impact assessments, and prior consultation; (f) delete or return all Personal Data upon termination; and (g) make available information necessary to demonstrate compliance and allow for audits.
Where BambooHR processes EU or UK Personal Data transferred to BambooHR in the United States, the EU Standard Contractual Clauses (Module 2: Controller to Processor), as may be updated from time to time, are incorporated into this DPA by reference and shall apply to such transfers. Customer and BambooHR shall be deemed to have entered into the SCCs on the Effective Date of this DPA.
4.Controller Obligations
Customer represents and warrants that it has all necessary rights and authority to provide Personal Data to BambooHR and to instruct BambooHR to process such data. Customer shall ensure that all required notices have been provided and all required consents have been obtained from Data Subjects in accordance with applicable data protection law.
Customer is responsible for determining the purposes and means of processing Personal Data and for ensuring that such processing is lawful. Customer shall implement appropriate technical and organisational measures to ensure and demonstrate that processing is performed in accordance with applicable law and this DPA.
5.Sub-Processors
Customer authorises BambooHR to use the sub-processors listed at bamboohr.com/legal/sub-processors (the "Sub-Processor List") to process Personal Data. BambooHR will provide at least thirty (30) days' advance notice of any proposed changes to the Sub-Processor List by updating the list and notifying Customer by email. Customer may object to any proposed addition or replacement of a sub-processor within that period by sending written notice via our contact page.
BambooHR shall impose data protection obligations on each sub-processor equivalent to those in this DPA and shall remain liable to Customer for any failure by a sub-processor to fulfil its data protection obligations. BambooHR shall ensure that sub-processors are subject to appropriate transfer mechanisms for any international transfers.
6.Data Subject Rights
To the extent legally permitted, BambooHR shall promptly notify Customer if BambooHR receives a request from a Data Subject to exercise their rights under applicable data protection law, including rights of access, rectification, erasure, restriction, portability, or objection. BambooHR shall not respond to any such request without Customer's prior authorisation, except to confirm to the Data Subject that BambooHR has forwarded the request.
BambooHR will provide commercially reasonable assistance to Customer in fulfilling its obligations to respond to Data Subject rights requests, taking into account the nature of the processing and the information available to BambooHR. Additional fees may apply for extensive assistance beyond what is reasonably required.
7.Security Measures
BambooHR shall implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Such measures shall be described in BambooHR's Security Exhibit, available at bamboohr.com/legal/security-exhibit, which may be updated from time to time.
Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, BambooHR's security measures shall include encryption of Personal Data in transit and at rest, multi-factor authentication, regular security testing, and access controls.
8.Data Breach Notification
BambooHR shall notify Customer without undue delay, and in any event within seventy-two (72) hours after becoming aware of a Security Incident that affects Customer's Personal Data. Such notification shall include: a description of the nature of the Security Incident; the categories and approximate number of Data Subjects and Personal Data records concerned; the likely consequences of the Security Incident; and the measures taken or proposed by BambooHR to address the Security Incident.
BambooHR's notification of a Security Incident shall not be construed as an acknowledgment of fault or liability. Customer is solely responsible for determining whether and how to notify Data Subjects and supervisory authorities as required by applicable law.
9.Return and Deletion of Data
Upon expiration or termination of the Agreement, BambooHR shall, at Customer's written request, return all Personal Data to Customer in a machine-readable format and/or delete all Personal Data. BambooHR will complete such return or deletion within thirty (30) days of Customer's written request.
Unless applicable law requires continued storage, BambooHR shall delete all remaining copies of Personal Data after completing the return or deletion process. Upon Customer's written request, BambooHR shall certify in writing that all Personal Data has been returned or deleted.
10.Audit Rights
BambooHR shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. Customer shall provide reasonable advance notice (at least thirty (30) days) before conducting any audit and shall ensure that any mandated auditor is subject to appropriate confidentiality obligations.
BambooHR may fulfil its audit obligations by providing Customer with its most recent third-party audit reports (such as SOC 2 Type II) and relevant certifications. Any in-person audit shall be conducted at Customer's expense, during regular business hours, and without disrupting BambooHR's business operations.








































