Last Updated: September 18, 2026
This DPA is incorporated into the Terms of Service or other written services agreement (the “Agreement”) between the entity or person agreeing to these terms (“Customer”) and Esper.io, Inc. (“Esper”). By using the Services, Customer agrees to be bound by this DPA. The DPA applies to all Processing of Customer Personal Data by Esper under the Agreement. Should there be a conflict between this DPA, and the Agreement, this DPA will govern.
In this DPA, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:
Upon Customer request, but no more than once per year, Esper will provide reasonable assistance and information to Customer regarding its Processing of Customer Personal Data to demonstrate its compliance with its obligations under Data Protection Laws and to support Customer with its data protection impact assessments, where the information sought is not provided in the Agreement or this DPA or otherwise accessible to Customer through product documentation. Where and to the extent so required by Data Protection Law and where such need is not met by the foregoing rights, Esper will allow for, contribute to, and cooperate with reasonable audits, assessments, and inspections conducted by or on behalf of Customer.
Esper will take reasonable steps to notify Customer if Esper receives any request from a government entity or regulator that pertains directly to its Processing of Customer Personal Data, provided such notice is not prohibited by law or court order. If Esper receives any requests from a Data Subject, including individual opt-out requests, requests for access and/or deletion and all similar individual rights requests, it will inform that Data Subjects that they should direct Data Subject requests to their Controller.
Upon Customer’s written request, or upon thirty (30) days following termination or expiration of the Agreement, Esper will delete all Customer Personal Data under Esper’s possession or control or provide Customer ability to delete such Customer Personal Data directly through tools or functionality made available by Esper. Esper will not delete Customer Personal Data to the extent that: (a) deletion is not permitted under applicable laws or the order of a governmental or regulatory body; (b) where Esper retains such data for internal record keeping, compliance with any legal obligations, and other lawfully permitted purposes; or (c) while Esper’s then-current data retention or similar back-up system stores Customer Personal Data provided such data will remain protected in accordance with the measures described in the Agreement and this DPA.
EXHIBIT 1
DETAILS OF PROCESSING OF CUSTOMER PERSONAL DATA
This Exhibit 1 supplements the Agreement and DPA, and together, provide details about Customer Personal Data processing by Esper.
| Describe the nature and purpose of the Processing of Customer Personal Data. | The processing of Customer Personal Data in connection with providing the Services to Customer, as further described in the Agreement and the DPA. |
|---|---|
| The types of Customer Personal Data to be Processed | Name and Contact Information (such as name, email and phone number); identifiers and device information (such as IP address, MAC address, diagnostic data, device IP address, device name, etc.). While the Services do not generally process Sensitive Customer Personal Data, the precise geolocation data of managed devices may be processed by Esper solely as necessary to support geolocation-dependent features, such as geofencing and location telemetry, on behalf of Customer. Geofencing is configured and enabled by the Customer’s enterprise administrator. Location telemetry is not enabled by default and, when activated by Esper via remote configuration to support the Services, collects and reports device location to the Customer’s management dashboard. The Services do not process precise geolocation data of managed devices by default. Esper does not access or use this data for the purpose of inferring the precise geolocation of an individual. |
| The types of Sensitive Customer Personal Data to be Processed | n/a – see note above. |
| The categories of Data Subjects to whom the Customer Personal Data relates | Customer’s clients, employees, contractors and representatives |
| The frequency of the transfer of Customer Personal Data from Customer to Esper | Continuous |
| Duration of the Processing of Customer Personal Data | As set forth in the Agreement and this DPA. |
| Location of Processing of Customer Personal Data by Esper | As set forth in the Agreement and this DPA. |
| The obligations and rights of Customer | The obligations and rights of Customer are as set out in the Agreement and this DPA. |
EXHIBIT 2
TECHNICAL AND ORGANIZATIONAL MEASURES
Esper’s personnel will not process Customer Personal Data without authorization. Personnel are obligated to maintain the confidentiality of any Customer Personal Data and this obligation continues even after their engagement ends.
Esper will implement and maintain commercially reasonable administrative, technical, and physical safeguards, including procedures and practices commensurate with the level of sensitivity of Customer Personal Data and the nature of its activities under the applicable Agreement, to protect the security, confidentiality, and integrity of Customer Personal Data processed by Esper or in its possession and control including such safeguards (a) to protect the security of systems upon which such data is processed; and (b) designed to prevent a Data Breach.
Such technical and organizational measures shall include, at a minimum and without limitation:
| Measures for: | Description |
|---|---|
pseudonymisation and encryption of Customer Personal Data | Implement and maintain modern and industry standard encryption mechanism and pseudonymize data as applicable to the Services provided. |
ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services | Implement and maintain a formal information security program that considers the ongoing confidentiality, integrity, availability, and processing of systems. |
ensuring the ability to restore the availability of and access to Customer Personal Data in a timely manner in the event of a physical or technical incident | Implement and maintain measures to ensure the availability of data according to agreed-upon RTO and RPO. Measures should include backup procedures, geographical separation, and redundancy. |
regularly testing, assessing and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing | Implement a review program for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures using a risk-based approach (risk assessment and internal audit) and periodically by a qualified third party (external and penetration test). Mitigation and remediation actions required based on the results of such testing should be documented and executed in a timely manner. |
user identification and authorization | Esper’s personnel will not process Customer Personal Data without authorization. Esper shall, additionally, implement and maintain mechanisms for establishing identity and accountability including unique ID, strong password, and multifactor authentication. |
the protection of data during transmission | Implement and maintain industry standard encryption protocols for encrypting data in transit, including but not limited to logins and sensitive data transfers. |
the protection of data during storage | Implement and maintain industry standard encryption protocols for encrypting data at rest. |
ensuring physical security of locations at which Customer Personal Data are processed | Implement and maintain physical security measures for locations used for data processing and storage. |
ensuring events logging | Implement and maintain controls around logging, monitoring, and alerting based on pre-defined thresholds. |
ensuring system configuration, including default configuration | Implement and maintain a formal hardening standard to ensure that configurations of system align with NIST, ISO, or equivalent guidance. |
internal IT and IT security governance and management | Implement and maintain measures to ensure that IT policy and control are established and communicated, understood, and acknowledged throughout the organization. |
certification/assurance of processes and products | Implement and maintain external certification and attestation of systems and controls used to secure the process information relevant to the services provided (SSAE 18/SOC 2, ISO 27701, ISO 27001, External Pen test, etc.) |
ensuring data minimization | Implement and maintain controls to limit data collected through the Services provided and limit the use of data to the agreed upon uses or for providing the Services. |
ensuring data quality | Implement and maintain controls to maintain the accuracy, completeness, and consistency of data over its life cycle. |
ensuring limited data retention | Implement and maintain controls for deleting data according to request or agreed upon terms of retention post termination of the applicable Agreement. |
ensuring accountability | Implement and maintain measures to ensure accountability and responsibility for security, privacy, and breach notification. |
allowing data portability and ensuring erasure | Implement and maintain measures to allow for portability of data and ensure complete erasure upon request or contract term. |
transfers to (sub-) processors, also describe the specific technical and organizational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter: | Esper shall remain committed to providing commercially reasonable cooperation and assistance to controllers. As set forth in this DPA, Esper will delete or return Customer Personal Data in accordance with the prior written instructions of Customer. In addition, upon request, Esper will, to the extent not prohibited by law, reasonably assist Customer in responding to any Data Subject request. Further, when Esper engages a sub-processor pursuant to this DPA, Esper is required to first enter into an agreement with such a sub-processor that contains data processing obligations substantially similar to those contained in this DPA. |
EXHIBIT 3
SUB-PROCESSORS
This list identifies the Sub-processors authorized to Process Customer Personal Data.
| Sub-processor Name | Sub-processor location (location(s) of processing) | Sub-processor services provided (description of subject matter, nature of Processing of Customer Personal Data) |
|---|---|---|
| Amazon Web Services | United States | Primary Cloud Infrastructure Provider |
| Okta/Auth0 | United States | User Authentication and Authorization Systems |
| Ascend.io | United States | Audits |
| Databricks | United States | Data Platform |
| SendGrid | United States | Email Service |
| ImplyData | United States | Data Platform |
| Pendo | United States | User Behavior Analysis |
| Zendesk | United States | Customer Support Platform |
EXHIBIT 4
STANDARD CONTRACTUAL CLAUSES
The Parties agree that by entering into this DPA, each party is deemed to have executed the of the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as issued by the European Commission on June 4, 2021 (the “SCCs”), and as also adopted by the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) (collectively “EU SCCs”), as applicable. Limited Transfer Data subject to the UK GDPR and UK Data Protection Act 2018 that Customer transfers to Esper will be governed by the EU SCCs and UK Transfer Addendum Version B1.0 (in force 21 March 2022) adopted by the UK Information Commissioner’s Office. The elections and information required for the purposes of the EU SCCs and the UK Transfer Addendum is provided in Table 1 below.
Table 1: EU SCC and UK Transfer Addendum Information.
| SCC Clause | GDPR | Swiss DPA | UK Data Protection Law |
|---|---|---|---|
| Module in Operation | Module Two (Controller to Processor) and Module Three (Processor to Processor) | ||
| Clause 7- Docking Clause | Does not apply | ||
| Clause 9(a)- Use of Sub-processors | GENERAL WRITTEN AUTHORISATION: The data importer has the data exporter’s general authorisation for the engagement of sub-processor(s) from an agreed list. The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of sub-processors at least 30 days in advance, thereby giving the data exporter sufficient time to be able to object to such changes prior to the engagement of the sub-processor(s). The data importer shall provide the data exporter with the information necessary to enable the data exporter to exercise its right to object. | ||
| Clause 11 (Redress) | Optional language in Clause 11 shall not apply. | ||
| Clause 17- Governing Law | These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third-party beneficiary rights. The Parties agree that this shall be the law of Ireland. | These Clauses shall be governed by the law of Switzerland, provided such law allows for third-party beneficiary rights. The Parties agree that this shall be the law of Switzerland. | These Clauses shall be governed by the law of the United Kingdom, provided such law allows for third-party beneficiary rights. The Parties agree that this shall be the law of England and Wales. |
| Clause 18 – Choice of Forum and Jurisdiction | The parties agree that those shall be the courts of Ireland. | The parties agree that those shall be the competent courts of Switzerland. | The parties agree that those shall be the competent courts of England and Wales. |
| Appendix, Annex I.A- List of Parties | The name, address, and contact person’s name, position, and contact details, and each party’s role in Processing Personal Data are as set forth in the DPA to which this Exhibit 4 is attached. | ||
| Annex I.B – Description of Transfer | This information can be found in Exhibit 1 to the DPA to which this Exhibit 4 is attached. To the extent applicable, the descriptions of safeguards applied to the special categories of Personal Data can be found Exhibit 2 to the DPA to which this Exhibit 4 is attached. | ||
| Clause 13 and Annex I.C – Competent Supervisory Authority | Identify the competent supervisory authority/ies in accordance with Clause 13: The Data Protection Commission | Identify the competent supervisory authority/ies in accordance with Clause 13: FDPIC | Identify the competent supervisory authority/ies in accordance with Clause 13: UK Information Commissioner |
| Annex II – Technical and Organizational Measures – Subprocessors | The description of technical and organization measures designed to ensure the security of Personal Data are described in Exhibit 2 to the DPA to which this Exhibit 4 is attached. | ||
| Annex III – List of Subprocessors | As described in Exhibit 3 to the DPA to which this Exhibit 4 is attached. | ||
| Ending the UK Transfer Addendum when the Approved Addendum changes | N/A | Which Parties may end this Addendum as set out in Section 19: ☒ Importer ☐ Exporter ☐ neither Party | |
Revision Date
Last revised September 18, 2026
© Esper.io, Inc. All Rights Reserved.