Data Processing Addendum

Last updated: July 12, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between To Work & Keep, LLC (“Processor,” “we,” “us”), operator of the Typing Insights platform, and the Customer (“Controller,” “you”). It applies where we process personal data of your Participants on your behalf. If there is a conflict between this DPA and the Terms with respect to data processing, this DPA controls. Capitalized terms not defined here have the meaning given in the Terms.

This DPA is a template intended to reflect how the Services operate. It is not legal advice; have it reviewed and, where a signed instrument is required, executed by counsel before relying on it.

1. Roles and Scope

For Participant personal data, you are the controller (or “business”) and we are the processor (or “service provider”). We process such data only to provide the Services and only on your documented instructions, which include the Terms, this DPA, and your configuration and use of the Services. We will notify you if we believe an instruction violates applicable data-protection law. This DPA incorporates the terms required by the EU/UK GDPR (Article 28) and by U.S. state privacy laws (including the CCPA/CPRA) for a service provider.

2. Nature of Processing

  • Subject matter: provision of the typing-assessment Services.
  • Duration: the term of the Terms, plus any retention period you configure.
  • Purpose: hosting, administering assessments, generating results, and related support.
  • Categories of data subjects: your Participants and Authorized Users.
  • Categories of personal data: Participant identifiers (first name, last name, email) and assessment activity and results.

3. Service Provider Commitments (U.S.)

We will not sell or share Participant personal data, will not retain, use, or disclose it for any purpose other than providing the Services (or as otherwise permitted by law), will not combine it with data from other sources except as permitted by the CCPA/CPRA, and will comply with applicable obligations. We certify that we understand and will comply with these restrictions.

4. Confidentiality

We ensure that personnel authorized to process Participant personal data are bound by confidentiality obligations and are trained appropriately, and we limit access to those who need it to provide the Services.

5. Security

We implement appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, field-level encryption of Participant identity data, access controls, and secure development and operational practices. You are responsible for configuring and using the Services securely, including managing Authorized User access.

6. Sub-processors

You authorize us to engage the sub-processors listed on our Sub-processors page to help provide the Services. We impose data-protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance. We will provide a mechanism to learn of changes to sub-processors and a reasonable opportunity to object to a new sub-processor on reasonable data-protection grounds.

7. Assistance to the Controller

Taking into account the nature of the processing, we will provide reasonable assistance to help you: (a) respond to data-subject requests to access, correct, delete, or port their data; (b) fulfill your security, breach-notification, data-protection-impact-assessment, and prior- consultation obligations. Because we process Participant data on your behalf, requests we receive directly from Participants will be referred to you.

8. Personal Data Breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Participant personal data we process for you, and will provide information reasonably available to us to help you meet your notification obligations.

9. International Transfers

Where we process personal data subject to the EU or UK GDPR and transfer it out of the EEA or UK, such transfers are made under the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated into this DPA by reference and completed with the details of the parties and processing described here.

10. Return and Deletion

On expiry or termination, and upon your request, we will delete or return Participant personal data in accordance with your configured retention settings and the Services’ export and deletion functionality, except where retention is required by law.

11. Audit and Records

We will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality, scheduling, and scope limitations.

12. Contact

For questions about this DPA or to make a data-protection request, contact privacy@typinginsights.com.