Version 1.1 · Effective August 24, 2026 · Last updated: September 07, 2026
This Data Processing Addendum ("DPA") forms part of the Work-A-Beez Terms of Service or other written agreement governing a Customer's use of Work-A-Beez (the "Agreement") between Linton Business Solutions, LLC, doing business as Work-A-Beez ("LBS," "Work-A-Beez," "Processor," "Service Provider," "Contractor," "we," "us," or "our") and the legal entity using the Service ("Customer," "Controller," "Business," "you," or "your").
This DPA applies to the extent LBS processes Personal Data on behalf of Customer in connection with the Service. If a signed Order Form or negotiated data-processing agreement expressly conflicts with this DPA, the signed document controls to the extent of the conflict.
Applicable Data Protection Law means privacy or data-protection law that legally applies to the relevant processing under the Agreement.
Customer Data means information submitted to, stored in, generated through, or otherwise processed by the Service on Customer's behalf, excluding information for which LBS independently determines the purpose and means of processing.
Customer Personal Data means Personal Data contained in Customer Data.
Personal Data means information relating to an identified or identifiable natural person, or equivalent protected personal information under Applicable Data Protection Law.
Process or Processing has the meaning given by Applicable Data Protection Law and includes collection, storage, use, access, disclosure, transmission, deletion, and other operations performed on Personal Data.
Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by LBS. It does not include unsuccessful scans, blocked attacks, failed login attempts, or other events that do not compromise Customer Personal Data.
Subprocessor means a third party engaged by LBS to process Customer Personal Data on LBS's behalf in providing the Service.
For Customer Personal Data, Customer generally acts as the controller, business, or equivalent responsible party and LBS generally acts as the processor, service provider, contractor, or equivalent recipient as applicable. Customer determines the lawful purpose of the workforce processing, the categories of individuals and data submitted, who may access the data, and the Customer's applicable retention and employment requirements.
LBS may act independently as a controller or business for limited information processed for its own legitimate business purposes, including billing/accounting records, fraud prevention, platform security records, legal-compliance records, direct business contacts, and direct support communications. This DPA does not convert those independent activities into processing on Customer's behalf where Applicable Data Protection Law recognizes a different role.
LBS will process Customer Personal Data only to provide, secure, maintain, troubleshoot, support, and administer the Service; to follow Customer's documented instructions as expressed through use and configuration of the Service; to comply with the Agreement; or as required by law. If LBS is required by law to process Customer Personal Data other than on Customer's instructions, LBS will inform Customer before the processing where legally permitted.
If LBS reasonably believes an instruction violates Applicable Data Protection Law, LBS may suspend the affected processing and notify Customer rather than carry out the instruction.
Customer represents that it has all rights, notices, permissions, consents, and lawful bases necessary for LBS to process Customer Personal Data under the Agreement. Customer is responsible for:
The subject matter, nature, purpose, categories of individuals, categories of data, and duration of processing are described in Appendix A below. Customer controls the specific data it chooses to enter into the Service and should avoid uploading information that is unnecessary or not authorized for the intended workforce-management purposes.
LBS will require personnel and contractors who are authorized to process Customer Personal Data to protect confidentiality and use the information only for legitimate business purposes. Access will be limited according to role and need. LBS will use commercially reasonable onboarding, access-removal, and confidentiality practices appropriate to the size and nature of its operations.
LBS will maintain commercially reasonable technical and organizational measures designed to protect Customer Personal Data against unauthorized access, use, alteration, disclosure, and destruction. Current measures are summarized in Appendix B and the Work-A-Beez Trust Center.
Security measures currently include, as applicable to the Service, HTTPS/TLS, production browser/session protections, CSRF protection, rate limiting on selected sensitive endpoints, one-way hashing of administrator passwords and employee PINs, logical organization-level tenant isolation, authorization checks, protected environment-managed secrets, hashed trusted-device tokens, short-lived mobile access credentials with rotating/hashed server-side refresh credentials, selected application/security logging, and managed cloud/database controls.
LBS may modify security measures as technology and threats evolve, provided LBS does not materially reduce the overall protection of Customer Personal Data in a manner inconsistent with the Agreement.
For clarity, this DPA does not represent that Work-A-Beez currently provides customer-facing MFA, SAML/OIDC SSO, customer-managed encryption keys/BYOK, a dedicated database per customer, customer-selectable data-residency regions, an annual independent penetration-test report, SOC 2 attestation, or ISO/IEC 27001 certification unless LBS separately confirms such capability or status in writing.
Customer authorizes LBS to engage Subprocessors as reasonably necessary to provide the Service. LBS will use commercially reasonable efforts to impose data-protection and confidentiality obligations on Subprocessors that are appropriate to the services they perform and the data they process.
Current material Subprocessors and provider functions are identified in the Subprocessor List. Provider arrangements may change as the Service evolves. Where required by Applicable Data Protection Law or a signed agreement, LBS will provide notice of material changes in accordance with the applicable notice process.
Customer may submit a reasonable written objection to a new Subprocessor where Applicable Data Protection Law gives Customer that right. The parties will work in good faith to address the concern. LBS is not required to disclose another party's confidential contract, proprietary security information, or information that would create security risk.
Taking into account the nature of the processing and the functionality available in the Service, LBS will provide commercially reasonable assistance to Customer with verified requests to access, correct, delete, restrict, object to, or export Customer Personal Data where required by Applicable Data Protection Law.
If LBS receives a request directly from an employee or other individual concerning Customer-controlled workforce data, LBS may refer the requester to Customer, notify Customer, or respond only as required by law. Unless legally required, LBS will not independently decide whether Customer must grant the request.
LBS will maintain procedures for identifying, containing, investigating, remediating, recovering from, and documenting Security Incidents. If LBS confirms a Security Incident affecting Customer Personal Data, LBS will notify affected Customer without undue delay as required by Applicable Data Protection Law and the Agreement.
To the extent reasonably available and appropriate, notice may describe the nature of the incident, affected data categories, known impact, containment/remediation measures, and a contact for follow-up. Information may be provided in stages as the investigation develops.
Notification may be delayed or limited where necessary to comply with law, law-enforcement requests, preserve evidence, avoid impeding investigation, or reduce further harm. Notification does not constitute an admission of fault or liability.
To the extent the GDPR or UK GDPR applies to LBS's processing of Customer Personal Data as a processor, LBS will:
LBS's processor notification obligation is to notify Customer without undue delay after confirming a qualifying Security Incident affecting Customer Personal Data. Any separate 72-hour supervisory-authority deadline imposed on a controller remains Customer's responsibility unless the law provides otherwise.
To the extent the California Consumer Privacy Act, as amended, applies and LBS processes Personal Information as a Service Provider or Contractor for Customer, LBS will process the Personal Information for the business purposes described in the Agreement and will not sell or share that Personal Information for cross-context behavioral advertising. LBS will not retain, use, or disclose such Personal Information outside the direct business relationship with Customer or for purposes other than those permitted by applicable law and the Agreement.
LBS will not combine Customer Personal Information with Personal Information received from or on behalf of another person or collected from LBS's own consumer interactions except as permitted by applicable law. Customer may take reasonable and appropriate steps to help ensure LBS uses Customer Personal Information consistently with Customer's obligations, subject to the audit and security protections in this DPA.
Where another U.S. state privacy law applies to the processing and imposes controller/processor obligations, the parties intend this DPA to satisfy those obligations to the extent applicable to the Service. Statutory exemptions, including employment-related exclusions, vary by law and should be evaluated by Customer.
Work-A-Beez is operated primarily from the United States. Unless expressly agreed in writing, LBS does not guarantee that Customer Data will remain in a specific country, state, or economic area and does not currently provide a generally available customer-selectable hosting-region feature.
If Applicable Data Protection Law requires a specific cross-border transfer mechanism, the parties will cooperate in good faith to implement an appropriate lawful mechanism where commercially available. This DPA does not, by itself, automatically incorporate Standard Contractual Clauses or another transfer instrument unless the applicable agreement expressly does so. Customers with mandatory localization or transfer requirements should address those requirements with LBS before submitting regulated data.
LBS will retain Customer Personal Data for as long as reasonably necessary to provide the Service and for legitimate security, accounting, contractual, fraud-prevention, dispute-resolution, enforcement, and legal-compliance purposes. Retention periods vary by data category and operational context.
Customer remains responsible for determining legal retention periods for employment, payroll, wage-and-hour, tax, and workforce records.
Upon termination or verified Customer request, LBS will process deletion or return requests consistent with the Service's functionality, the Agreement, applicable law, and operational constraints. Organization deletion is a reviewed process and is not represented as an instantaneous purge.
Deletion may be delayed for identity/authority verification, billing resolution, legal holds, security/fraud investigations, accounting obligations, dispute resolution, or other lawful retention. Customer Personal Data may remain in backups until overwritten, expired, or removed through normal backup lifecycle processes. Backup data will not be restored for ordinary business use except as necessary for recovery, security, or legal purposes.
Upon reasonable written request and subject to confidentiality and security restrictions, LBS may provide available security, privacy, Trust Center, policy, questionnaire, and compliance information reasonably necessary for Customer to assess LBS's processing.
Where Applicable Data Protection Law requires additional audit rights, the parties will first use available documentation and remote evidence where reasonable. Any additional audit must be reasonable in scope and frequency, avoid disruption and access to other customers' data, occur during normal business hours, and protect LBS confidential and security-sensitive information. Unless law or a signed agreement requires otherwise, Customer bears its own audit costs and any extraordinary LBS assistance may be subject to reasonable fees.
LBS is not required to disclose source code, credentials, private keys, exploit details, confidential vulnerability findings, raw penetration-test materials, another customer's data, or information whose disclosure would materially increase security risk.
Taking into account the nature of processing and information available to LBS, LBS will provide commercially reasonable assistance where Applicable Data Protection Law requires Customer to conduct a data-protection impact assessment, consult a regulator, or respond to a regulator regarding LBS's processing of Customer Personal Data. Customer remains responsible for its legal conclusions and regulatory communications unless law requires otherwise.
LBS may disclose Customer Personal Data when required by legally binding process. Where legally permitted and commercially reasonable, LBS will notify affected Customer before disclosure. LBS may challenge or narrow requests where appropriate but is not required to violate law or a binding governmental directive.
LBS does not determine Customer's legal basis for workforce processing, worker classification, overtime rules, payroll approval, retention schedule, employee discipline, or compliance obligations. Work-A-Beez provides software functionality and records based on Customer configuration and data.
This DPA is subject to the limitations of liability, disclaimers, indemnities, and governing-law provisions in the Agreement except to the extent Applicable Data Protection Law prohibits those limitations. With respect to processing of Customer Personal Data, an executed negotiated DPA or Order Form expressly addressing data protection controls over this public DPA, and this DPA controls over inconsistent general Terms of Service language to the extent of the conflict.
LBS may update this DPA to reflect changes in law, providers, product functionality, or security/privacy practices. Material changes will be handled according to the Agreement's notice provisions. An update will not retroactively remove a specific negotiated right contained in a signed agreement unless the parties agree or law requires the change.
Data-protection questions may be sent to:
Linton Business Solutions, LLC
Work-A-Beez Privacy / Data Protection
616 FM 1960 Road West
Houston, Texas 77090
United States
Email: info@lbsconnect.net
| Subject matter | Provision of the Work-A-Beez workforce-management service. |
|---|---|
| Duration | For the term of the Agreement and thereafter only as permitted for deletion/backup lifecycle, legal obligations, security, accounting, disputes, fraud prevention, and other lawful purposes. |
| Nature and purpose | Account administration, authentication, employee/timekeeping/scheduling/PTO functions, payroll-related reporting, communications, support, security, monitoring, backup/recovery, and other configured service functions. |
| Data subjects | Customer administrators, employees, contractors or other workforce members entered by Customer, and authorized users. |
| Data categories | Business/contact data, employee identifiers and contact data, job/department data, schedules, attendance/time records, PTO data, payroll-related data entered by Customer, internal communications, authentication/security data, device/IP/session information, support records, and related service data. |
| Sensitive data | Customer should not submit sensitive or regulated data beyond what is reasonably necessary and authorized for the Service. If Customer uses the Service for sensitive data, Customer is responsible for determining legal suitability and required safeguards. |
Customers with jurisdiction-specific contractual requirements, including SCCs or negotiated security schedules, should contact LBS before deployment.