Data Processing Addendum

Last updated: September 9, 2026

This Data Processing Addendum ("DPA") forms part of the Earnest Comp Terms of Service (the "Terms") between Earnest, LLC, a Massachusetts limited liability company ("Earnest"), and the customer that accepts the Terms ("Customer"). It applies to the extent Earnest processes Personal Data on Customer’s behalf that is subject to Data Protection Law. It is incorporated into the Terms by reference and needs no signature to apply; a countersigned copy is available on request from legal@earnestcomp.com.

Part A — Terms of processing

1. Definitions

  • Customer Data has the meaning given in Section 5 of the Terms: the data Customer and its users enter into or generate within the Service.
  • Personal Data means any Customer Data relating to an identified or identifiable natural person.
  • Data Protection Law means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation (2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended by the CPRA ("CCPA").
  • Processing, Controller, Processor, Data Subject and Supervisory Authority have the meanings given in the GDPR; Business, Service Provider, Sell and Share have the meanings given in the CCPA.
  • Sub-processor means a third party engaged by Earnest to process Personal Data on Customer’s behalf.
  • Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed by Earnest.
  • Standard Contractual Clauses or SCCs means the clauses approved by European Commission Decision (EU) 2021/914, and UK Addendum means the International Data Transfer Addendum issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.

2. Roles and scope

Customer is the Controller (or, where Customer acts for its own clients, a Processor) of the Personal Data, and Earnest is a Processor acting on Customer’s behalf. For the purposes of the CCPA, Customer is a Business and Earnest is a Service Provider. The subject matter, duration, nature and purpose of the processing, and the categories of Data Subjects and Personal Data, are set out in Annex 1.

Each party shall comply with its own obligations under Data Protection Law. Customer is responsible for the lawfulness of the Personal Data it submits, including having given its employees and contractors the notices required by Data Protection Law regarding the processing of their compensation data in the Service.

3. Customer instructions

Earnest processes Personal Data only on Customer’s documented instructions, which consist of the Terms, this DPA, and Customer’s configuration and use of the Service (including the plans, teams, imports and publish actions its administrators perform). Earnest will inform Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend the affected processing until the instruction is confirmed or withdrawn. Earnest will not process Personal Data for any other purpose, and will not use Customer Data to train machine-learning models.

4. Confidentiality

Earnest ensures that every person it authorises to process Personal Data is bound by a contractual or statutory duty of confidentiality, and that access is limited to what is necessary to operate, support and secure the Service.

5. Security

Earnest implements and maintains the technical and organisational measures described in Annex 2 and on the Security Practices page. Earnest may update those measures from time to time, provided the update does not materially reduce the overall level of protection during the term.

6. Sub-processors

Customer gives Earnest general authorisation to engage the Sub-processors listed in Annex 3 (also published on the Privacy Policy). Earnest will give the email addresses of Customer’s organisation administrators at least 30 days’ prior notice before adding or replacing a Sub-processor. Customer may object in writing within that period on reasonable, documented data-protection grounds. If the parties cannot resolve the objection in good faith, Customer may terminate the affected subscription on written notice and Earnest will refund any prepaid fees for the remainder of the term.

Earnest imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains responsible to Customer for each Sub-processor’s performance.

7. Data Subject requests

The Service gives Customer’s administrators self-service tools to fulfil most Data Subject requests directly: export of an individual’s data, correction of records, deactivation, and erasure by anonymisation. If Earnest receives a request from a Data Subject relating to Customer’s Personal Data, Earnest will not respond except to direct the individual to Customer, and will promptly notify Customer. Taking into account the nature of the processing, Earnest will provide reasonable further assistance where Customer cannot fulfil a request through the Service.

8. Assistance with impact assessments

Taking into account the nature of the processing and the information available to it, Earnest will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with a Supervisory Authority that concern the Service.

9. Security Incidents

Earnest will notify Customer’s organisation administrators without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Customer’s Personal Data. The notice will describe, to the extent known, the nature of the incident, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Earnest will keep Customer informed as material facts become known and will cooperate reasonably with Customer’s own notification obligations. A notification under this section is not an admission of fault or liability.

10. International transfers

Earnest processes Personal Data in the United States. Where Customer transfers Personal Data from the European Economic Area, the United Kingdom or Switzerland to Earnest, the parties enter into the SCCs, which are incorporated into this DPA by reference, on the following basis:

  • Module Two (controller to processor) applies, or Module Three (processor to processor) where Customer acts as a Processor.
  • Clause 7 (docking clause) does not apply. Clause 9: Option 2 (general written authorisation) with the notice period in Section 6. Clause 11: the optional language does not apply.
  • Clause 17: the SCCs are governed by the law of Ireland. Clause 18: disputes are resolved by the courts of Ireland.
  • Annex I and Annex II of the SCCs are completed by Annex 1 and Annex 2 of this DPA; Annex III by Annex 3. The competent Supervisory Authority is that of the EU member state in which Customer is established.
  • For transfers from the United Kingdom, the UK Addendum applies with the SCCs, and the parties’ details in Part 1 of the Addendum are as set out in this DPA. For transfers from Switzerland, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the Swiss Federal Data Protection and Information Commissioner is the competent authority.

If Earnest adopts an alternative lawful transfer mechanism recognised under Data Protection Law, it may rely on that mechanism instead, and will notify Customer.

11. Return and deletion of Customer Data

During the term, Customer can export its Customer Data at any time through the Service (organisation export in CSV, and per-person export). Following termination or expiry, Customer Data remains available for export for 30 days. After that period Earnest deletes or anonymises Customer Data within 90 days, except to the extent that retention is required by law (for example billing records), and except for copies held in encrypted backups, which are overwritten on their normal retention cycle and are not restored to the live Service. Earnest will confirm deletion in writing on request.

12. Audits and information

Not more than once in any 12-month period, and on written request, Earnest will make available the information reasonably necessary to demonstrate compliance with this DPA, including written responses to a reasonable security questionnaire and any third-party assessment reports Earnest holds at the time. Where Data Protection Law gives Customer a right to audit that cannot be satisfied by that information, Customer (or an independent auditor it appoints, bound by confidentiality) may conduct an audit on at least 30 days’ written notice, during normal business hours, at Customer’s expense, in a manner that does not unreasonably disrupt Earnest’s operations or compromise the security of other customers.

13. CCPA service-provider terms

To the extent the CCPA applies, Earnest will not: Sell or Share Personal Data; retain, use or disclose Personal Data for any purpose other than the business purpose of providing the Service under the Terms, or outside the direct business relationship between the parties; or combine Personal Data with personal information it receives from other sources, except as permitted by the CCPA. Earnest certifies that it understands these restrictions. Earnest will notify Customer if it can no longer meet its obligations under the CCPA, and Customer may take reasonable and appropriate steps to stop and remediate unauthorised use of Personal Data.

14. Liability and precedence

Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Terms, and the parties’ combined liability under the Terms and this DPA is subject to a single aggregate cap. In the event of a conflict, the SCCs prevail over this DPA, and this DPA prevails over the Terms with respect to the processing of Personal Data.

15. Term

This DPA takes effect when the Terms take effect and remains in force for as long as Earnest processes Personal Data on Customer’s behalf, including the return and deletion period in Section 11.

Part B — Annexes

Annex 1 — Details of the processing

  • Subject matter: the provision of the Earnest Comp commission management service to Customer.
  • Duration: the term of the Terms plus the return and deletion period in Section 11.
  • Nature and purpose: storing Customer Data; calculating commission and incentive compensation from the plans, quotas and sales activity Customer configures; generating and publishing payout statements; sending transactional notifications; and providing support, security and billing for the Service.
  • Categories of Data Subjects: Customer’s employees and contractors who are set up as users of the Service (sales representatives, managers and administrators), and any other individuals whose details Customer enters into the Service.
  • Categories of Personal Data: name, work email address, role and job title, team and reporting line, start and end dates, compensation plan parameters, on-target earnings, base salary, quota, sales activity and revenue figures attributed to the individual, calculated commission and payout amounts, adjustments and disputes, notification preferences, and the audit trail of actions taken in the Service. Login credentials are stored only as salted hashes.
  • Special categories of data: none. Customer must not submit special categories of Personal Data, government identifiers, or bank account details to the Service; Earnest does not process payroll or disburse funds.
  • Frequency: continuous, for the duration of the term.

Annex 2 — Technical and organisational measures

  • Encryption: all traffic is encrypted in transit with TLS 1.2 or higher, with HTTP Strict Transport Security enforced. Customer Data is encrypted at rest (AES-256) by the database provider.
  • Tenant isolation: every organisation’s data is separated by database row-level security enforced by the database engine, in addition to organisation scoping in the application. The application connects with a least-privilege database role that cannot bypass those policies.
  • Access control: role-based access (administrator, manager, representative) with per-organisation permissions; passwords hashed with bcrypt; sessions expire after 24 hours; optional sign-in with Google.
  • Application security: Content Security Policy, cross-site request forgery protection, input validation, parameterised queries, and rate limiting on authentication and ingestion endpoints.
  • Auditability: administrative actions (plan changes, payout publication, adjustments, role changes, exports and erasures) are recorded in an append-only audit log with actor and timestamp.
  • Availability and recovery: continuous point-in-time recovery at the database provider; the hosting provider supports immediate rollback of the application to a previous release.
  • Secure development: automated type checking, linting, unit, integration and tenant-isolation test suites run on every change before it can be deployed; production dependencies are scanned for known vulnerabilities on every build.
  • Secrets and configuration: credentials are held only in the hosting provider’s encrypted configuration store and are never committed to source control.
  • Incident response: a documented incident response process with severity levels and escalation; security reports to security@earnestcomp.com are acknowledged within 48 hours.
  • Data minimisation and deletion: self-service export, deactivation and anonymisation tools for administrators; retention windows as set out in Section 11; bounced and complained email addresses are suppressed automatically.

Annex 3 — Sub-processors

Current as of the date at the top of this page. Locations refer to where the Sub-processor processes Customer Data.

  • Vercel, Inc. — application hosting and content delivery — United States.
  • Neon, Inc. — PostgreSQL database hosting (primary storage of Customer Data) — United States (AWS us-east-2).
  • Stripe, Inc. — subscription billing and payment processing (billing contact details only) — United States.
  • Resend, Inc. — transactional email delivery (recipient name and email address, notification content) — United States.
  • Upstash, Inc. — rate-limiting counters keyed by account identifier and IP address; no Customer Data.
  • Functional Software, Inc. (Sentry) — error monitoring; IP addresses, cookies and authorization headers are removed before transmission — United States.

Not Sub-processors: Google LLC acts as an independent identity provider when a user chooses to sign in with Google; ExchangeRate-API supplies currency exchange rates and receives no Personal Data.

Contact

Questions about this DPA, requests for a countersigned copy, and Sub-processor objections: legal@earnestcomp.com. Privacy requests: privacy@earnestcomp.com.