No items found.
Solutions
Services
House of Work offers comprehensive AI solutions tailored to your goals and needs.
Content OS
AI Agents for Advisor Marketing
Marketing Strategy
Website Design and Development
Service OS
Custom AI Automations
Prospecting Automation
Client Servicing Automation
AI-powered Marketing
AI Agents for Advisor MarketingMarketing StrategyWebsite Design and Development
AI Workflow Automation
AI Meeting Assistant SetupSales AutomationCustom AI Automation
ProjectsAbout UsInsightsGet Started
Get Started
Terms of Service
Schedule B — Content OS
Data Processing Agreement
Annex B — Content OS
Security and Sub-processors
Privacy Policy
Fulfillment Policy

Data Processing Agreement

Last updated

October 5, 2026

This Data Processing Agreement ("DPA") is between House of Work LLC ("House of Work," the "Processor") and the client that accepts it (the "Client," the "Controller"). It governs House of Work's handling of personal data in the course of providing services to the Client.

The Client accepts this DPA by accepting our Terms of Service — by checking the box marked "I agree" and starting a subscription, or by signing an agreement that references the Terms or this DPA. It takes effect on the date of that acceptance (the "Effective Date").

This DPA has an Annex for each service. The Annex for a service sets out the details of processing for that service and, where it says so, modifies the sections below for that service. For Content OS, that is Annex B.

1. Scope of our role

For services performed within the Client's own systems, House of Work acts as an integrator and operator of the Client's own tools. The Client owns and contracts directly for all platforms and tools used to process its data (its CRM, form, scheduling, and automation tools). House of Work configures, connects, operates, and maintains automations across those Client-owned systems on the Client's behalf, working only within the Client's own accounts. House of Work does not use its own tools or accounts to process the Client's data and does not hold the Client's data at rest in its own systems; its responsibilities under this DPA attach to the access and credentials it is granted and to any working copies it may temporarily hold in providing the services.

For Content OS, this Section is replaced by Section B.1 of Annex B.

2. Roles of the parties

For personal data processed under the services, the Client is the controller and House of Work is the processor. House of Work processes personal data only on behalf of the Client. Each party will comply with its obligations under applicable data protection law.

3. Processing on documented instructions

House of Work will process personal data only on the Client's documented instructions (including as set out in the parties' services agreement and this DPA), and only to provide the agreed services, unless required to act otherwise by law — in which case House of Work will inform the Client first where legally permitted. House of Work will not sell personal data or use it for its own purposes.

4. Confidentiality

House of Work ensures that its personnel and contractors authorized to process the Client's personal data are bound by appropriate confidentiality obligations and handle the data securely.

5. Security

House of Work applies appropriate technical and organizational security measures to personal data within the systems and accounts it operates or controls in providing the services — including the automation workflows used to route data, the credentials and access granted to it, and any copies or exports it holds. Measures include access on a need-to-know basis, multi-factor authentication on key platforms, secure storage of credentials, and encryption in transit and at rest where offered by the underlying platforms. The Client's own platforms are secured by those providers under the Client's direct agreements with them; House of Work does not control, and is not responsible for the security of, those platforms' infrastructure, but will use them in line with the Client's instructions and their intended use.

6. Sub-processors and tools

For services performed within the Client's own systems, House of Work operates the Client's own tools and accounts and does not engage sub-processors of its own. The platforms used to process personal data (the Client's CRM, form, scheduling, and automation tools) are contracted for and owned by the Client and are the Client's own sub-processors under the Client's direct agreements with them; House of Work is not responsible for those providers' performance or security. If House of Work ever proposes to use a tool or sub-processor of its own to process the Client's personal data for such a service, it will obtain the Client's prior approval and impose data-protection obligations equivalent to those in this DPA.

For Content OS, this Section is replaced by Section B.3 of Annex B, which lists House of Work's sub-processors.

7. Personal data breach

House of Work will notify the Client without undue delay, and no later than 72 hours, of any confirmed security incident affecting personal data within the systems or accounts House of Work operates or controls, or otherwise arising from House of Work's provision of the services, and will cooperate with the Client's efforts to mitigate and remediate the data breach. This includes an incident resulting from the compromise of credentials or access held by House of Work, even where the affected data resides on a Client platform. Incidents affecting the Client's own platforms independently of House of Work are subject to those providers' notification obligations directly to the Client; House of Work will cooperate and share any relevant information it holds.

8. Indemnification

8.1 By the Client. The Client will indemnify, defend, and hold harmless House of Work and its personnel from and against any third-party claims, and any resulting losses, liabilities, damages, and reasonable costs (including reasonable attorneys' fees), arising out of or relating to the processing of personal data under this DPA — except to the extent such claims arise from House of Work's failure to comply with the security measures and obligations set out in this DPA (including any written security requirements provided by the Client), or from House of Work's gross negligence or willful misconduct. This indemnity is subject to the limitations and cap on liability set out in the parties' services agreement.

8.2 By House of Work. House of Work will indemnify the Client for losses to the extent directly caused by House of Work's failure to comply with its obligations under this DPA, subject to the limitations and cap on liability set out in the parties' services agreement.

8.3 Relationship to the services agreement. This Section governs indemnification relating to the processing and security of personal data. To the extent it conflicts with an indemnification provision in the parties' services agreement, this Section controls for data-protection matters, and the services agreement's indemnification provisions control for all other matters.

9. Assistance and data subject requests

Taking into account the nature of the processing, House of Work will provide the Client with reasonable assistance in responding to requests from individuals exercising their rights, and with the Client's obligations regarding security, breach notification, and impact assessments. If House of Work receives a request directly from a data subject, it will not respond except on the Client's documented instructions and will promptly notify the Client.

10. Return and deletion

On termination or expiry of the services, or at the Client's earlier request, House of Work will, at the Client's choice, return and/or securely delete any personal data in its possession or control — such as exports or working copies it holds — and will relinquish or transfer to the Client all access, credentials, and automations provisioned for the engagement, unless continued retention is required by law. For services performed within the Client's own systems, the Client's data resides in those systems, remains with the Client and is unaffected.

For Content OS, this Section is replaced by Section B.7 of Annex B.

11. International transfers

House of Work will not transfer personal data to a country without an appropriate safeguard where one is required by applicable data protection law, or another lawful transfer mechanism.

11.1 Standard Contractual Clauses. Where the Client is established in the European Economic Area and personal data is transferred to House of Work outside it, the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914, Module Two (controller to processor) (the "EU SCCs"), are incorporated into this DPA by reference, with the Client as data exporter and House of Work as data importer. They are completed as follows: the optional docking clause in Clause 7 applies; under Clause 9, option 2 (general written authorisation) applies, with the notice period set out in the applicable Annex to this DPA; the optional wording in Clause 11 does not apply; under Clause 17, the EU SCCs are governed by the law of Ireland; and under Clause 18, disputes are resolved by the courts of Ireland. Annexes I to III of the EU SCCs are completed by the applicable Annex to this DPA.

11.2 United Kingdom and Switzerland. Where the Client is established in the United Kingdom, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner applies to those transfers and is incorporated by reference. Where the Client is established in Switzerland, the EU SCCs apply with the references adapted so that the Swiss Federal Act on Data Protection applies and the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority.

11.3 Onward transfers. Where a sub-processor processes personal data outside the European Economic Area, the United Kingdom or Switzerland, House of Work relies on that sub-processor's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, or on standard contractual clauses in place with that sub-processor.

11.4 Precedence. If the EU SCCs conflict with this DPA, the EU SCCs prevail.

12. Audit and information

House of Work will make available to the Client information reasonably necessary to demonstrate compliance with this DPA, including its written information-security policy and a certificate of insurance, on the Client's reasonable request. House of Work will respond to the Client's reasonable security and due-diligence inquiries on reasonable prior notice, no more than once per year (unless required by a regulator or following a security incident), subject to confidentiality.

13. Term and general

This DPA takes effect on the Effective Date and continues for as long as House of Work processes personal data on the Client's behalf. Provisions that by their nature should survive termination will survive. This DPA is governed by the laws of the State of Iowa. If there is a conflict between this DPA and the parties' services agreement on the subject of data protection, this DPA prevails. House of Work may update this DPA as described in Section 11 of the Terms of Service.

Annexes

  • Annex A — Services within the Client's own systems. Set out below.
  • Annex B — Content OS. Published separately as Annex B — Content OS.

Annex A — Services within the Client's own systems

Subject matter and purpose: Provision of marketing, automation, and integration services, including configuring and operating automations across the Client's systems.

Categories of data subjects: The Client's prospects, leads, and customers, and the Client's personnel.

Categories of personal data: The Client, as controller, determines what personal data is collected in each form and workflow, and House of Work processes whatever the Client instructs. This typically includes contact and identity data (e.g., name, email, phone) and profile or financial-planning information the Client chooses to gather (e.g., age or asset ranges and similar intake details).

Special-category data (e.g., health information) and highly sensitive identifiers (e.g., Social Security numbers or full financial account numbers) are not intended to be processed through House of Work-operated workflows and, where needed, should be collected directly in the Client's own secure systems; if the parties agree to include such data, House of Work will apply the security measures in this DPA to it.

Tools and sub-processors: All platforms used to process personal data are owned by and contracted for by the Client (for example, its form, CRM, scheduling and automation tools), and are operated by House of Work on the Client's behalf. House of Work engages no sub-processors of its own for these services. A current list of tools will be maintained and provided on request.

Duration: For the term of the services plus any return and deletion period.

Version

dpa-2026-10-05

Content hash (SHA-256)

aa2883065e46fed1204b080461ab4fa5c92740b87c11cf32b5294a990386e147

The logo of House of Work.
Follow us on social media to stay up to date with the latest.
Company
About UsInsightsAI BlueprintPrivacy PolicyTerms & Legal
Services
AI StrategyAI AgentsAI Automation
Subscribe To Our Newsletter
By signing up to receive emails from House of Work, you agree to our Privacy Policy. We treat your info responsibly. Unsubscribe anytime.
Thank you! Please check your email inbox.
Oops! Something went wrong while submitting the form.
Copyright © 2026 House of Work LLC
Back to top