Annex B — Content OS
To the House of Work Data Processing Agreement
This Annex B forms part of the Data Processing Agreement (the "DPA") between House of Work LLC ("House of Work," the "Processor") and the Client (the "Controller"). It applies to the Content OS service and to no other service. For Content OS, this Annex modifies Sections 1, 6 and 10 of the DPA as set out below. All other provisions of the DPA apply to Content OS as written.
B.1 Scope of our role (replaces DPA Section 1)
Section 1 of the DPA does not apply to Content OS. Instead:
B.1.1 House of Work provides Content OS as a hosted service running on infrastructure and accounts that House of Work owns and contracts for. For Content OS, House of Work does use its own tools and accounts, and does hold Client data at rest in its own systems. Its responsibilities under this DPA attach to those systems, to the sub-processors listed in B.3, and to the access and credentials the Client grants it.
B.1.2 What Content OS processes. Except where the Client elects the managed email module in B.9, the personal data House of Work processes on the Client's behalf through Content OS is limited to the Client's own personnel who hold portal accounts, as set out in B.2. The research and source material used to generate content is drawn from publicly available sources and from House of Work's own research datasets.
B.1.3 What Content OS does not process. Content OS is not connected to, and does not receive, the Client's client or prospect records, its CRM, its custodial or account data, or its financial planning data. House of Work does not hold, and has no access to, the personal data of the Client's clients through Content OS. B.9 is the sole exception and applies only where the Client elects it in writing.
B.1.4 Client destination systems. The Client owns and contracts for the systems to which approved content is published — its website, its social accounts, and its email service provider where integrated (the "Client Destination Systems"). House of Work is granted publishing access to those systems for the term and operates within them on the Client's behalf. Those platforms are the Client's own sub-processors under the Client's direct agreements with them, and House of Work is not responsible for their performance or security. House of Work's obligations in relation to them attach to the credentials and access it holds, including its breach-notification obligation under DPA Section 7 for any compromise of that access.
B.1.5 Email service provider integration. Where the Client integrates its own email service provider, House of Work's access is used to create draft campaigns in the Client's account for the Client to review and send. House of Work does not send email to the Client's subscribers, does not export, download or retain the Client's subscriber lists, and does not process the Client's subscriber data other than as incidental to creating a draft within the Client's own system. The Client's subscribers are not data subjects under this Annex, and their personal data remains within the Client's own platform under the Client's direct agreement with that provider. The Client sends, and remains the sender of record.
B.1.6 The Client remains the controller and House of Work the processor for personal data processed through Content OS, as set out in DPA Section 2.
B.2 Categories of data subjects and personal data
Subject matter and purpose: Provision of the Content OS service — niche and market research, content generation, automated compliance review, approval workflow, portal delivery, and publication of approved content to the Client's destination systems.
Categories of data subjects: the Client's personnel who hold portal accounts — approvers, administrators and other users the Client invites. Where the Client elects the managed email module, B.9 adds a further category.
Categories of personal data:
- Portal account data: name, business email address, authentication credentials in hashed form, role and permissions, and session and activity data.
- Approval data: the identity of the user who approved each content asset and the date and time of approval.
- Connection data: the name and email address of the person who connected a Client Destination System, and the encrypted access token for it.
- Incidental personal data in content: any personal data the Client chooses to include in briefs, source material or published content — typically the names and biographical detail of the Client's own advisers.
Data the Client will not put into Content OS. The Client will not enter, upload or connect into Content OS — including into content briefs, source material or drafts — any client or prospect records, special-category data such as health information, Social Security numbers, account numbers, or client financial or planning detail. This restriction is what keeps the processing within the scope described in B.1, and the parties will amend this Annex before any change to it. The subscriber list provided under the managed email module in B.9, where elected, is the one permitted exception, and that restriction otherwise continues to apply to it.
Duration: For the term of the Content OS service plus the return and deletion period in B.7.
B.3 Sub-processors (replaces DPA Section 6)
Section 6 of the DPA does not apply to Content OS. For Content OS, the Client gives House of Work general authorisation to engage the sub-processors listed below, and to add or replace sub-processors on the terms of this Section. House of Work keeps the current list on its Security and Sub-processors page.
Notice and objection. House of Work will give the Client at least 14 days' notice before adding or replacing a sub-processor that processes the Client's personal data, by updating its Security and Sub-processors page and emailing the address on the Client's account. The Client may object on reasonable data-protection grounds within that period, in which case House of Work will use reasonable efforts to make the service available without the change; if it cannot, the Client may cancel Content OS with effect from the date the change takes effect, without the notice period in Schedule B, Section B7.3, and without penalty.
Urgent replacement. Where a sub-processor must be replaced sooner to protect the security or continuity of the service — for example because it has suffered a security incident or has stopped providing its service — House of Work may make the replacement immediately and will notify the Client as soon as reasonably possible afterwards. The Client's right to object and cancel then runs from the date of that notice.
House of Work imposes on each sub-processor data-protection obligations equivalent to those in this DPA, and remains responsible to the Client for their performance.
- Supabase — Application database and authentication. Personal data processed: Portal account data; approval data; connection data (tokens encrypted)
- Webflow, including Webflow Cloud — Portal hosting and website publishing. Personal data processed: Portal account data in transit; personal data contained in published content
- Cloudflare — Network and edge delivery for the portal. Personal data processed: Portal account data in transit
- n8n Cloud — Workflow orchestration. Personal data processed: Data in transit through the content and provisioning workflows
- OpenRouter, and the model providers it routes to — Content generation, review and relevance scoring. Personal data processed: Content inputs and drafts; personal data only where incidental under B.2
- Resend — Transactional and portal email. Personal data processed: Portal user name and email address; delivery events
- Ayrshare — Publishing to the social accounts the Client connects. Personal data processed: Social account identifiers; personal data contained in published content
Tools that are not sub-processors. House of Work also uses tools that do not process the Client's personal data on the Client's behalf — for example keyword research and image generation services, and the systems House of Work uses to run its own business, such as its customer relationship management and billing tools. They are not sub-processors under this Annex, and changes to them are not subject to the notice above.
B.4 Model processing
Content briefs, source material and drafts are transmitted to third-party model providers through OpenRouter for the purpose of generating and scoring content. House of Work's routing is configured for zero data retention: providers do not retain submitted data beyond the duration of the request and do not use it to train models. Consistent with B.1.3 and B.2, the Client's client and prospect data is not transmitted to any model provider, because it is never in the system. Subscriber data processed under B.9 is not transmitted to any model provider.
B.5 Multi-tenancy
Content OS is a multi-tenant platform. The Client's portal data and Content are logically separated from those of other clients by row-level access controls enforced at the database layer, and portal users can access only their own firm's data. The Client's Content and portal data are not used to generate content for any other client.
House of Work's own niche, keyword and market research datasets are House of Work's Background IP under Schedule B, are built from publicly available sources, and are maintained across the service.
B.6 Security measures for Content OS (supplements DPA Section 5)
In addition to the measures in DPA Section 5, House of Work applies the following to Content OS:
- row-level security enforced at the database layer, scoping each client's records to its own tenant;
- authenticated portal access with individually provisioned user accounts, revoked when the Client requests or on termination;
- encrypted storage of credentials and tokens for the Client's destination systems, used only on House of Work's servers, with access limited to House of Work personnel who need them;
- encryption in transit for all data moving between Content OS components and sub-processors, and encryption at rest where offered by the underlying platform;
- multi-factor authentication on House of Work's administrative accounts for Supabase and Webflow, the platforms in B.3 that store Client data at rest; and
- source control and change review for the portal codebase.
B.7 Return and deletion (replaces DPA Section 10)
Section 10 of the DPA does not apply to Content OS, and in particular its statement that the Client's data "remains with the Client and is unaffected" is not correct for this service.
On termination or expiry of Content OS, or at the Client's earlier request:
- House of Work will provide the export described in Schedule B, Section B6.3, covering the Client's Content;
- House of Work will delete the Client's portal account data, approval data and connection data from the Content OS platform within 30 days of the end of the final paid period;
- backups containing that data will expire on their ordinary cycle and will be deleted no later than 90 days after the end of the final paid period, and remain subject to this DPA until deleted;
- House of Work will relinquish or transfer back all access and credentials to the Client's destination systems;
- where the managed email module in B.9 was elected, House of Work will export and then delete the subscriber list and associated data in accordance with B.9.6; and
- House of Work may retain personal data where required by law, and will retain it only for as long as required.
B.8 International transfers
The sub-processors in B.3 may process personal data in the United States and in other countries in which they operate. Section 11 of the DPA applies, including the Standard Contractual Clauses where the Client is established in the European Economic Area, the United Kingdom or Switzerland. For the purposes of those Clauses, Annex I is completed by Sections B.1 and B.2 of this Annex, Annex II by Section 5 of the DPA and Section B.6, and Annex III by Section B.3.
B.9 Managed email module (optional, applies only if elected)
B.9.1 When this applies. This Section applies only where the Client has elected the managed email module in writing and is being billed for it. Where the Client has not elected it, this Section has no effect and the scope in B.1.2 and B.1.3 governs.
B.9.2 What changes. Under the managed email module, House of Work provisions and operates a dedicated sending sub-account on the Client's behalf and sends approved email to the Client's subscriber list. House of Work therefore holds and processes the Client's subscriber data, which may include the personal data of the Client's clients and prospects.
B.9.3 Additional data subjects and personal data. Data subjects: the Client's newsletter subscribers, which may include its clients, prospects and contacts. Personal data: name, email address, subscription and consent status, suppression status, and delivery and engagement events, together with any list data the Client provides or connects.
B.9.4 Purpose limitation. House of Work will process the subscriber list solely to send the Client's approved email and to report on its delivery. House of Work will not use the list for any other purpose, will not market to it on its own behalf or on behalf of any other client, will not combine it with any other list, and will not transmit it to any model provider.
B.9.5 The Client's responsibilities. The Client remains the sender of record and the controller of the list. The Client is responsible for having a lawful basis and any required consent for each subscriber, for the accuracy and currency of the list, for honouring unsubscribe and suppression requests in its own records, and for its compliance with the CAN-SPAM Act and any other law applicable to its email. No email is sent without the Client's approval under Schedule B, Section B5.1.
B.9.6 Return and deletion. On termination of the module or of Content OS, or at the Client's earlier request, House of Work will provide the Client with an export of the subscriber list and its subscription and suppression status, and will then delete the list and associated data from the sending sub-account and close the sub-account, within the periods in B.7.
B.9.7 Sub-processor. Before the module starts, House of Work will name to the Client in writing the email sending provider it will use for the module. That provider is a sub-processor for the duration of the election, and B.3 applies to it, including the notice and objection rights for any later change.
Version
annex-b-content-os-2026-10-05
Content hash (SHA-256)
3726f5e9197d1c2eb7bce095421657bc59a903d2e9642d97b29a3be4415f6c8a