This translation is provided for convenience. The Spanish version is the binding one.
This Data Processing Agreement (the "Agreement") forms part of the Subscription Agreement between [RAZÓN SOCIAL], S.A.P.I. de C.V. ("waydot" or the "Processor") and the customer purchasing the Services (the "Customer" or the "Controller"). The Agreement governs the processing relationship (relación de encargo) provided for in the Mexican Federal Law on the Protection of Personal Data Held by Private Parties ("LFPDPPP") and other applicable rules.
1. Capacity of the parties
1.1. With respect to personal data contained in Customer Data (the "Personal Data"), the Customer is the controller (responsable), since it decides on the processing and determines its purposes, and waydot is the processor (encargado), since it processes the data solely on the Customer's behalf to provide the Services.
1.2. waydot is a controller in its own right only for the data described in its Privacy Notice, such as data relating to access accounts and billing.
2. Subject matter, nature and duration of processing
- Subject matter: provision of the Services purchased, comprising the hosting, storage, synchronization, processing, display, backup, support and security of Personal Data.
- Nature: automated processing in cloud infrastructure, in the field staff mobile app and in the integrations the Customer enables.
- Duration: the term of the Subscription Agreement and the return and deletion period provided for in section 11.
The categories of data subjects and data are described in Annex A.
3. Customer instructions
3.1. waydot will process Personal Data only on the Customer's documented instructions. The Subscription Agreement, this Agreement, the configuration the Customer sets in the platform and the Customer's written support requests constitute those instructions.
3.2. waydot will not process Personal Data for its own purposes or for purposes other than those instructed, unless required to do so by law. In that case, it will inform the Customer beforehand, if the law allows.
3.3. If waydot considers that an instruction infringes the LFPDPPP, it will inform the Customer and may refrain from carrying it out until the matter is clarified.
4. Customer obligations as controller
The Customer is solely responsible for:
- Having a legal basis for each processing activity and making its privacy notice available to its workers, candidates, beneficiaries, end clients and other data subjects before entering their data into waydot.
- Obtaining the express and, where applicable, written consent required by law to process sensitive personal data (for example, health data or sick leave) and the express consent required to process financial or asset-related data (for example, bank accounts for payroll disbursement).
- Using field staff geolocation only during working hours and for work-related purposes, informing workers accordingly and respecting their privacy and the Federal Labor Law, including, where applicable, its telework provisions.
- Handling requests from data subjects to exercise ARCO rights, withdraw consent or limit use of their data.
- Configuring the platform's roles, permissions and retention periods in line with the principle of proportionality.
- Ensuring that the data it uploads is accurate and that uploading it does not infringe third-party rights.
5. waydot's obligations as processor
waydot will:
- Process Personal Data in accordance with the Customer's instructions and this Agreement.
- Refrain from processing it for any other purpose.
- Implement the security measures in Annex B and keep them up to date.
- Keep Personal Data confidential, an obligation that continues after termination.
- Ensure that its personnel with access to Personal Data are bound by confidentiality obligations and trained in data protection, and restrict access to those who need it to provide the Services.
- Delete or return Personal Data on termination of the relationship, as provided in section 11.
- Refrain from transferring Personal Data unless the Customer instructs it, the transfer is subprocessing carried out under section 6, or a competent authority requires it.
6. Subprocessors
6.1. The Customer gives waydot general authorization to subcontract part of the processing to the providers listed under Subprocessors.
6.2. waydot will enter into a contract with each subprocessor imposing data protection obligations at least equivalent to those in this Agreement, and will remain liable to the Customer for the subprocessor's performance.
6.3. waydot will notify the Customer at least 30 calendar days in advance of any new or replacement subprocessor, by updating the list and notifying administrators who have subscribed to those notices. The Customer may object on reasonable data protection grounds. If the parties cannot agree on a solution, the Customer may terminate the affected Services and receive a refund of the prepaid pro rata portion.
7. International disclosures to processors
Some subprocessors process data outside Mexico. waydot will make those disclosures only to providers that give contractual protection guarantees equivalent to those of Mexican law, and will state their location in the subprocessor list. The primary hosting location is [REGIÓN DEL CENTRO DE DATOS].
8. Security breaches
8.1. waydot will notify the Customer without undue delay and in any event within 72 hours of confirming a security breach affecting the Customer's Personal Data.
8.2. The notice will include, to the extent known, the nature of the incident, the data and data subjects affected, the corrective measures taken and recommended, and a point of contact. waydot will update the information as the investigation progresses.
8.3. waydot will cooperate with the Customer so that the Customer can inform affected data subjects, as the LFPDPPP requires of the controller, and will take the measures necessary to contain the incident and prevent it from recurring.
9. Assistance to the Customer
9.1. ARCO rights. The platform allows the Customer to view, correct, export and delete data. If waydot receives a request directly from a data subject, it will forward it to the Customer within 5 business days and will not respond to it on its own unless instructed by the Customer.
9.2. Authorities. If an authority requests information about Personal Data, waydot will inform the Customer, unless legally prohibited, and cooperate reasonably.
10. Audits
10.1. At the Customer's request, and once a year, waydot will make available information sufficient to demonstrate compliance with this Agreement, such as completed security questionnaires, policy summaries and, where available, third-party audit reports or certifications.
10.2. If that information is not sufficient, or an authority requires it, the Customer may carry out an audit, directly or through an independent auditor bound by confidentiality. The Customer must give at least 30 calendar days' notice of the audit, which will take place during business hours, without compromising the security of the platform or affecting other customers, and at the Customer's cost.
11. Return and deletion
When the Subscription Agreement ends, the Customer will have 30 calendar days to export its data. After that period, waydot will delete Personal Data from its active systems within the following 90 calendar days, and from backups in line with its rotation cycle, and will confirm the deletion in writing at the Customer's request. If a legal provision requires any part of the data to be kept, waydot will keep that part blocked and process it only for that purpose.
12. Liability and term
The parties' liability under this Agreement is governed by the Subscription Agreement. This Agreement remains in force for as long as waydot processes Personal Data on the Customer's behalf. In case of conflict between this Agreement and any other document relating to data protection, this Agreement prevails.
Annex A. Data subjects and data
| Data subjects | Data categories | Possible sensitive or financial data |
|---|---|---|
| Customer personnel (technicians, dispatchers, supervisors, office staff) | Identification and contact; employment data (job title, department, shift, skills, certifications, performance); attendance, breaks and hours; location and routes during working hours; photos and signatures captured as evidence; expenses, mileage and fuel; device and app identifiers | Health data (sick leave, medical exams, emergency contacts) if the Customer enables employee files; bank accounts, salary, loans, deductions and severance if it enables payroll |
| Customer's job candidates | Identification, contact, experience, assessments and interviews | Whatever the Customer chooses to record |
| Personnel's beneficiaries and relatives | Name, relationship, contact, benefit percentage | Not applicable |
| Customer's end clients and their contacts | Name, job title, phone, email, site, sign-off signature, service communications | Not applicable |
| Third parties appearing in evidence | Images captured incidentally in site photos | Not applicable |
Annex B. Security measures
| Area | Measures |
|---|---|
| Isolation | Logical separation of each workspace through row-level security policies in the database, verified by automated tests |
| Encryption | TLS 1.2 or higher in transit; encryption at rest for databases, files and backups; additional encryption of employee file documents |
| Access | Two-factor authentication available to all Users; role-based access control and time-limited permissions; remote revocation of sessions and devices |
| waydot personnel | Least-privilege access, logged and justified; support access to a workspace requires the Customer's temporary authorization and is audited |
| Traceability | Activity log with chain verification that allows tampering to be detected, exportable by the Customer |
| Mobile app | Offline data encrypted on the device; authenticated synchronization; remote sign-out |
| Continuity | Automatic daily backups with defined retention; recovery procedures tested periodically |
| Development | Code review, static analysis and automated tests before each release; vulnerability management for dependencies |
| Incidents | Documented incident response procedure, within the timelines in section 8 |