AcknowledgePoint
FeaturesPricingSecuritySign InGet Started
Back to home
AcknowledgePoint.com

Data Processing Addendum

Effective Date: [Insert Effective Date] Last Updated: [Insert Last Updated Date]

This Data Processing Addendum (“DPA”) supplements the Terms of Service or other written agreement between AcknowledgePoint, LLC, doing business as AcknowledgePoint.com (“AcknowledgePoint,” “Processor,” “Service Provider,” “Contractor,” “we,” “us,” or “our”) and the customer entity using the Services (“Customer,” “Controller,” “Business,” “you,” or “your”).

This DPA applies when AcknowledgePoint processes Personal Data or Personal Information on behalf of Customer in connection with the Services.

1. DEFINITIONS

1.1 “Applicable Data Protection Laws” means privacy, data protection, and data security laws applicable to the processing of Personal Data under this DPA, which may include, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act, other U.S. state privacy laws, and other applicable privacy laws.

1.2 “Customer Data” has the meaning given in the Terms of Service and includes Personal Data processed by AcknowledgePoint on behalf of Customer.

1.3 “Personal Data” or “Personal Information” means information relating to an identified or identifiable person that is processed by AcknowledgePoint on behalf of Customer through the Services.

1.4 “Process” or “Processing” means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, deletion, or destruction.

1.5 “Security Incident” means a confirmed unauthorized access to, acquisition of, or disclosure of Personal Data processed by AcknowledgePoint on behalf of Customer. Security Incident does not include unsuccessful attempts, pings, port scans, denial-of-service attacks, or other events that do not result in confirmed unauthorized access to Personal Data.

1.6 “Subprocessor” means a third party engaged by AcknowledgePoint to process Personal Data on behalf of Customer.

2. ROLES OF THE PARTIES

Customer is the controller or business that determines the purposes and means of processing Customer Data.

AcknowledgePoint is the processor, service provider, or contractor that processes Customer Data on behalf of Customer to provide the Services.

3. SUBJECT MATTER AND DURATION

The subject matter of processing is the provision of the Services, including document creation, template use, assignments, acknowledgements, dashboards, reporting, account management, billing support, security, and support.

Processing will continue for the duration of Customer’s use of the Services and as necessary for retention, deletion, legal compliance, backup, dispute resolution, or as otherwise described in the Terms and Privacy Policy.

4. NATURE AND PURPOSE OF PROCESSING

AcknowledgePoint processes Personal Data to:

  • provide the Services;
  • create and manage user accounts;
  • support document builder and template workflows;
  • assign documents;
  • collect acknowledgements;
  • track due dates and status;
  • generate reports and audit records;
  • provide customer support;
  • maintain security;
  • troubleshoot and improve Services;
  • manage billing and account status; and
  • comply with law and contractual obligations.

5. CATEGORIES OF PERSONAL DATA

Personal Data may include:

  • name;
  • business email address;
  • company name;
  • administrator role;
  • user role;
  • department;
  • location;
  • assignment records;
  • acknowledgement records;
  • due dates;
  • timestamps;
  • login and activity logs;
  • support communications;
  • billing contact information; and
  • other information entered or generated by Customer through the Services.

6. CATEGORIES OF DATA SUBJECTS

Data subjects may include:

  • Customer administrators;
  • Customer employees;
  • contractors;
  • temporary workers;
  • managers;
  • HR personnel;
  • IT personnel;
  • safety personnel;
  • compliance personnel;
  • billing contacts;
  • support contacts; and
  • other users authorized by Customer.

7. CUSTOMER INSTRUCTIONS

AcknowledgePoint will process Personal Data only according to Customer’s documented instructions, including the Terms, this DPA, product configuration, account settings, support requests, and written instructions.

AcknowledgePoint may process Personal Data as required by law, in which case AcknowledgePoint will notify Customer unless legally prohibited.

8. CCPA / CPRA SERVICE PROVIDER TERMS

Where the CCPA applies and AcknowledgePoint processes Personal Information as a service provider or contractor, AcknowledgePoint agrees that it will:

  • not sell or share Personal Information collected pursuant to its agreement with Customer;
  • not retain, use, or disclose Personal Information for any purpose other than the business purposes specified in the agreement;
  • not retain, use, or disclose Personal Information outside the direct business relationship with Customer except as permitted by law;
  • comply with applicable obligations under the CCPA and provide the same level of privacy protection required by the CCPA;
  • notify Customer if AcknowledgePoint determines it can no longer meet its obligations;
  • assist Customer with consumer requests as required by law and contract;
  • implement reasonable security procedures and practices appropriate to the nature of the Personal Information;
  • allow Customer to take reasonable and appropriate steps to help ensure AcknowledgePoint uses Personal Information in a manner consistent with Customer’s obligations; and
  • allow Customer, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information.

9. CONFIDENTIALITY

AcknowledgePoint will ensure that personnel authorized to process Personal Data are subject to confidentiality obligations or professional obligations of confidentiality.

10. SECURITY MEASURES

AcknowledgePoint will implement reasonable administrative, technical, and physical safeguards designed to protect Personal Data from unauthorized access, destruction, use, modification, or disclosure.

Security measures may include:

  • encryption in transit;
  • access controls;
  • role-based access;
  • authentication;
  • logging and monitoring;
  • secure hosting;
  • backup controls;
  • vulnerability management;
  • least privilege access;
  • personnel access limitations; and
  • incident response procedures.

11. SUBPROCESSORS

Customer authorizes AcknowledgePoint to use Subprocessors to provide the Services. Subprocessors may include hosting providers, database providers, email providers, billing providers, analytics providers, support tools, security tools, and infrastructure providers.

AcknowledgePoint will require Subprocessors to protect Personal Data under terms that are no less protective than those required by this DPA in all material respects.

AcknowledgePoint remains responsible for Subprocessor performance of data protection obligations.

12. SUBPROCESSOR CHANGES

AcknowledgePoint may update Subprocessors from time to time. Customer may request a list of current Subprocessors by contacting AcknowledgePoint.

If required by applicable law or written agreement, AcknowledgePoint will provide notice of material Subprocessor changes and allow Customer to object on reasonable data protection grounds.

13. DATA SUBJECT REQUESTS

If AcknowledgePoint receives a request from a data subject relating to Personal Data processed on behalf of Customer, AcknowledgePoint may direct the data subject to Customer unless required by law to respond.

AcknowledgePoint will provide reasonable assistance to Customer in responding to verified data subject requests, subject to technical feasibility, legal limitations, and Customer’s payment of reasonable costs if assistance is excessive or burdensome.

14. CUSTOMER ACCESS AND CONTROLS

The Services may allow Customer to access, correct, delete, export, or manage certain Personal Data directly. Customer is responsible for using available controls to manage its data.

15. SECURITY INCIDENTS

AcknowledgePoint will notify Customer without undue delay after becoming aware of a Security Incident affecting Personal Data processed on behalf of Customer.

Notice may include, if known:

  • nature of the incident;
  • categories of data affected;
  • approximate number of affected records;
  • measures taken or planned;
  • recommended customer actions; and
  • contact information for follow-up.

AcknowledgePoint’s notice of a Security Incident is not an admission of fault or liability.

Customer is responsible for determining whether notification to individuals, regulators, employees, or others is required.

16. AUDITS AND INFORMATION REQUESTS

Upon reasonable request, AcknowledgePoint will provide information necessary to demonstrate compliance with this DPA, subject to confidentiality, security, legal, and operational limitations.

Any audit rights must be reasonable, limited, non-disruptive, and subject to prior written agreement. Customer may not conduct penetration testing or security testing without AcknowledgePoint’s written permission.

17. RETURN OR DELETION OF DATA

Upon termination of Services, AcknowledgePoint will delete, return, archive, or de-identify Customer Data according to the Terms, Privacy Policy, written agreement, and retention practices.

AcknowledgePoint may retain copies as required for legal compliance, backups, security, dispute resolution, accounting, or other legitimate business purposes, subject to continued protection.

18. DE-IDENTIFIED AND AGGREGATED DATA

AcknowledgePoint may use aggregated, anonymized, or de-identified data for analytics, benchmarking, product improvement, security, reporting, and business purposes, provided it does not identify Customer or data subjects.

19. INTERNATIONAL TRANSFERS

AcknowledgePoint primarily intends to provide Services in the United States. If Personal Data is transferred internationally, AcknowledgePoint will use appropriate safeguards where required by law.

20. CUSTOMER RESPONSIBILITIES

Customer is responsible for:

  • providing required notices to users and employees;
  • obtaining required consents or legal bases;
  • responding to employee privacy requests;
  • determining retention requirements;
  • configuring permissions;
  • limiting sensitive data;
  • ensuring lawful use of acknowledgement records;
  • reviewing policy content;
  • complying with employment and privacy laws; and
  • ensuring Customer’s instructions are lawful.

21. ORDER OF PRECEDENCE

If there is a conflict between this DPA and the Terms of Service, this DPA controls with respect to Personal Data processing. If there is a conflict between this DPA and a separately signed agreement, the signed agreement controls to the extent of the conflict.

22. CONTACT

Privacy and data processing questions may be sent to:

Email: [[email protected]] Legal: [[email protected]]

============================================================ DOCUMENT 5 ACCEPTABLE USE POLICY ============================================================

AcknowledgePoint

The smart way to create policies, assign them to employees, and track acknowledgements.

© 2026 AcknowledgePoint. All rights reserved.

Product

FeaturesPricingSecurity

Legal

Privacy PolicyTerms of ServiceSubscription & Billing TermsCancellation PolicyData Processing AddendumAcceptable Use Policy

Trust

AccessibilityCookie / Tracking NoticeSecurity

Support

Help CenterFrequently Asked QuestionsContact Support