Version: 1.1 Effective Date: September 22, 2026
This Data Processing Addendum ("DPA") forms part of the agreement governing the use of PeopleEvo, a software-as-a-service platform provided by NyxDay Inc. ("NyxDay", "PeopleEvo", "we", "us", or "our"), between NyxDay Inc. and the Customer using the PeopleEvo Service ("Customer").
This DPA applies where NyxDay Processes Personal Information contained in Customer Data on behalf of the Customer in connection with providing PeopleEvo.
Where the PeopleEvo Terms and Conditions incorporate this DPA, the Customer's acceptance of those Terms constitutes acceptance of this DPA, and a separate signature is not required unless NyxDay and the Customer expressly agree otherwise.
1. Definitions
For purposes of this DPA:
"Applicable Data Protection Law" means privacy, data-protection, and personal-information laws applicable to the Processing of Personal Information under this DPA.
"Customer Data" has the meaning given to it in the PeopleEvo Terms and Conditions and includes information submitted to, stored in, or Processed through PeopleEvo by or on behalf of the Customer.
"Data Subject" means an identified or identifiable individual to whom Personal Information relates.
"Personal Information" means information about an identifiable individual contained in Customer Data and includes equivalent concepts such as "personal data" where applicable under Applicable Data Protection Law.
"Personal Information Breach" means unauthorized access to, use of, disclosure of, loss of, alteration of, or destruction of Personal Information Processed under this DPA where such event constitutes a breach under Applicable Data Protection Law.
"Processing" or "Process" means any operation performed on Personal Information, including collection, recording, organization, storage, retrieval, consultation, use, transmission, disclosure, modification, restriction, deletion, or destruction.
"Subprocessor" means a third-party service provider engaged by NyxDay to Process Personal Information contained in Customer Data on behalf of the Customer in connection with providing PeopleEvo.
Capitalized terms not defined in this DPA have the meanings assigned to them in the PeopleEvo Terms and Conditions.
2. Scope and Relationship to the Agreement
This DPA applies only to Processing of Personal Information contained in Customer Data by NyxDay on behalf of the Customer in connection with providing PeopleEvo.
This DPA does not apply to Personal Information that NyxDay Processes independently for its own legitimate business purposes, such as:
- managing its contractual relationship with the Customer;
- billing and subscription administration;
- maintaining business, accounting, and transaction records;
- operating the PeopleEvo website;
- responding to general business enquiries;
- protecting the security and integrity of PeopleEvo;
- preventing fraud or abuse;
- establishing, exercising, or defending legal claims; or
- complying with applicable legal obligations,
except to the extent Applicable Data Protection Law requires otherwise.
This DPA forms part of the agreement between NyxDay and the Customer.
If there is a conflict between this DPA and the PeopleEvo Terms and Conditions regarding the Processing or protection of Personal Information contained in Customer Data, this DPA will control only with respect to such Processing or protection.
If NyxDay and the Customer have entered into a separately signed agreement that expressly governs the same Processing and conflicts with this DPA, the separately signed agreement will control only to the extent expressly provided in that agreement.
3. Roles of the Parties
The Customer determines the purposes for which employee, workforce, leave, absence, and related Customer Data is entered into and Processed through PeopleEvo.
Accordingly, where applicable under Applicable Data Protection Law:
- the Customer acts as the controller, organization responsible for the Personal Information, business, or equivalent role; and
- NyxDay acts as the processor, service provider, contractor, or equivalent role when Processing such Personal Information on behalf of the Customer.
Each party is responsible for complying with the obligations applicable to it under Applicable Data Protection Law.
The terminology used by a particular law does not alter the parties' intended allocation of responsibilities under this DPA.
4. Customer Responsibilities
The Customer is responsible for:
- determining that its collection and Processing of Personal Information through PeopleEvo is lawful;
- providing any notices and obtaining any consents, permissions, authorizations, or other lawful basis required for its use of PeopleEvo;
- determining which Personal Information should be entered into PeopleEvo;
- limiting Personal Information to what is appropriate and necessary for the Customer's purposes;
- configuring roles, permissions, leave policies, approval workflows, visibility controls, and other Customer-controlled settings appropriately;
- ensuring that authorized users Process Personal Information appropriately;
- maintaining appropriate internal policies and procedures relating to its personnel;
- responding to employment, workplace, accommodation, human-resources, and other organizational decisions concerning its personnel;
- responding to Data Subject requests where the Customer is responsible for such requests; and
- complying with Applicable Data Protection Law and other laws applicable to the Customer's use of PeopleEvo.
The Customer represents that it has all necessary rights, authority, permissions, and lawful grounds to provide Customer Data to NyxDay for Processing under this DPA.
The Customer will not instruct NyxDay to Process Personal Information in a manner that violates Applicable Data Protection Law.
5. Customer Instructions
NyxDay will Process Personal Information contained in Customer Data only:
- to provide, maintain, secure, support, troubleshoot, and improve the technical operation, reliability, and performance of the contracted PeopleEvo Service;
- according to the Customer's documented instructions;
- as configured or initiated by authorized Customer users;
- as reasonably necessary to prevent or address security, fraud, abuse, or technical issues;
- through authorized Subprocessors as necessary to provide the Service; or
- where required by applicable law.
The agreement governing the Customer's use of PeopleEvo, this DPA, Customer configuration of the Service, actions performed by authorized Customer users, and documented support requests constitute documented instructions for purposes of this DPA.
NyxDay may use aggregated or appropriately de-identified information for analytics, capacity planning, security, Service improvement, and product development where permitted by Applicable Data Protection Law.
If NyxDay reasonably believes that a Customer instruction violates Applicable Data Protection Law, NyxDay may suspend performance of the affected instruction and inform the Customer, unless prohibited by law.
NyxDay is not required to implement an instruction that is technically infeasible, would materially compromise the security or integrity of PeopleEvo, would adversely affect another Customer, or would require functionality not included in the applicable Service, except where Applicable Data Protection Law requires otherwise.
6. Details of Processing
The subject matter, nature, purpose, duration, categories of Data Subjects, and categories of Personal Information Processed under this DPA are described in Schedule A — Details of Processing.
7. Confidentiality
NyxDay will ensure that personnel authorized to Process Personal Information contained in Customer Data are subject to appropriate confidentiality obligations.
Access to Customer Data will be limited to personnel and service providers who require such access for legitimate purposes associated with providing, securing, maintaining, supporting, or administering PeopleEvo or fulfilling applicable legal obligations.
NyxDay will not disclose Customer Data to a third party except:
- as authorized under this DPA;
- through an authorized Subprocessor;
- at the Customer's direction;
- where necessary to provide a Customer-enabled third-party integration;
- where reasonably necessary to protect PeopleEvo, NyxDay, Customers, users, or others from fraud, abuse, or security threats; or
- where required by applicable law or valid legal process.
8. Security Measures
NyxDay will maintain reasonable administrative, technical, and organizational safeguards designed to protect Personal Information contained in Customer Data against unauthorized access, use, disclosure, alteration, loss, or destruction.
Current categories of security measures are described in Schedule B — Technical and Organizational Measures.
NyxDay may update its security measures as PeopleEvo evolves, provided that such updates do not materially reduce the overall level of protection applicable to Customer Data during an active subscription.
Security measures may vary depending on the applicable PeopleEvo functionality, deployment configuration, technical environment, and Customer-selected features.
No internet-based service, software platform, or electronic storage system can guarantee absolute security.
9. Personal Information Breaches
NyxDay will investigate suspected Personal Information Breaches affecting Customer Data and take reasonable steps to contain and remediate confirmed incidents.
Where NyxDay becomes aware of a confirmed Personal Information Breach affecting Customer Data, NyxDay will notify the affected Customer without undue delay, unless notification is prohibited by applicable law.
Where reasonably available, the notification will include information concerning:
- the nature of the Personal Information Breach;
- the categories of Personal Information affected;
- the categories of affected Data Subjects, where known;
- the likely consequences or risks identified by NyxDay;
- containment or remediation measures taken or planned; and
- information reasonably available to assist the Customer in meeting applicable notification or regulatory obligations.
NyxDay may provide information in phases as additional information becomes reasonably available.
NyxDay is not required to delay containment or remediation while gathering all information for an initial notification.
Notification of a Personal Information Breach does not constitute an admission of fault, liability, or breach of contract.
The Customer remains responsible for determining whether it must notify affected individuals, regulators, employees, customers, or other parties, except where Applicable Data Protection Law places such responsibility directly on NyxDay.
10. Subprocessors
The Customer provides general authorization for NyxDay to engage Subprocessors as necessary to provide PeopleEvo.
NyxDay's current material Subprocessors are maintained on the PeopleEvo Subprocessors and International Processing page at:
NyxDay will require Subprocessors that Process Personal Information contained in Customer Data to be subject to appropriate data-protection and confidentiality obligations relevant to the services they provide.
NyxDay remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law and the agreement with the Customer.
10.1 Changes to Subprocessors
NyxDay may add, replace, discontinue, or change Subprocessors as PeopleEvo evolves.
NyxDay will update its Subprocessor List to reflect material changes.
Unless Applicable Data Protection Law or a separately agreed contractual term requires another method, publication of an updated Subprocessor List on the PeopleEvo website constitutes notice of the current Subprocessor List.
Where prior notice of a new or replacement Subprocessor is required by Applicable Data Protection Law, NyxDay may provide such notice through:
- email;
- an in-Service notification;
- publication on the Subprocessor page; or
- another reasonable electronic method permitted by applicable law.
10.2 Customer Objections
Where Applicable Data Protection Law gives the Customer a right to object to a new Subprocessor, the Customer must submit any objection within 10 business days after receiving the applicable notice, unless a longer period is required by law.
The objection must:
- be submitted in writing;
- identify the affected Subprocessor; and
- explain the specific legitimate data-protection grounds for the objection.
NyxDay and the Customer will work in good faith to identify a commercially reasonable resolution.
Where appropriate, potential resolutions may include:
- providing additional information regarding the Subprocessor;
- implementing reasonable additional safeguards;
- disabling the affected optional functionality; or
- identifying another commercially reasonable approach.
If NyxDay cannot reasonably provide the affected Service without using the Subprocessor and the parties cannot resolve the objection, the Customer's remedy is to discontinue the affected functionality or, where the affected functionality is material to the Service as a whole, terminate the affected subscription, subject to the applicable agreement and mandatory legal rights.
Unless required by Applicable Data Protection Law or expressly agreed by NyxDay, a Subprocessor objection does not automatically create an entitlement to a refund for Services already provided, amounts already incurred, or an unused portion of an applicable billing period.
An objection may not be used solely to avoid unrelated contractual or payment obligations.
11. International Processing
Customer Data may be Processed in jurisdictions other than the jurisdiction in which the Customer or Data Subject is located.
Current material Processing locations are identified on the PeopleEvo Subprocessors and International Processing page.
NyxDay will use contractual or other appropriate measures intended to provide protection for Personal Information transferred to Subprocessors for Processing as required by Applicable Data Protection Law.
Where Applicable Data Protection Law requires a specific lawful transfer mechanism for an international transfer, NyxDay will use an applicable mechanism where required and reasonably available.
The Customer acknowledges that the standard PeopleEvo Service does not guarantee that Customer Data will be Processed exclusively within the Customer's country, province, state, territory, or other preferred jurisdiction.
Specific data-residency, regional-hosting, dedicated-infrastructure, private-cloud, customer-specific deployment, or similar requirements must be expressly agreed with NyxDay in writing.
The Customer is responsible for determining whether the standard PeopleEvo Processing locations are appropriate for its use and for satisfying any Customer-specific privacy impact assessment, localization, notice, consent, or similar requirement applicable to the Customer.
12. Data Subject and Privacy Rights Requests
Taking into account the nature of the Processing and functionality reasonably available through PeopleEvo, NyxDay will provide reasonable assistance to the Customer in responding to requests by Data Subjects exercising applicable privacy rights relating to Customer Data.
Where NyxDay receives a request directly from a Data Subject concerning Personal Information controlled by a Customer, NyxDay may direct the individual to the applicable Customer.
NyxDay will not independently respond to such a request on the Customer's behalf unless:
- instructed by the Customer;
- reasonably necessary to identify the applicable Customer;
- required by Applicable Data Protection Law; or
- otherwise permitted under the agreement.
The Customer is responsible for:
- determining whether a request is valid;
- verifying the identity and authority of the requester where required;
- determining what response is legally required;
- applying any applicable exceptions; and
- communicating the final response to the Data Subject,
except where Applicable Data Protection Law requires NyxDay to perform a particular obligation directly.
13. Regulatory and Compliance Assistance
Taking into account the nature of the Processing and information reasonably available to NyxDay, NyxDay will provide reasonable assistance to the Customer with privacy or data-protection obligations relating specifically to PeopleEvo Processing where required by Applicable Data Protection Law.
Such assistance may include reasonably available information concerning:
- Processing activities;
- Subprocessors;
- security measures;
- Personal Information Breaches;
- data location;
- retention and deletion;
- Data Subject requests; and
- relevant compliance documentation.
NyxDay is not responsible for:
- performing the Customer's general legal, employment, privacy, regulatory, or compliance functions;
- providing legal advice;
- preparing the Customer's privacy impact assessments or regulatory filings;
- determining whether the Customer complies with applicable law; or
- certifying the Customer's compliance.
13.1 Costs of Assistance
Assistance that can reasonably be provided through standard PeopleEvo functionality, existing documentation, or ordinary support is included in the applicable Service.
To the extent a Customer requests assistance that requires material:
- custom analysis;
- custom data extraction;
- technical work;
- compliance or regulatory coordination;
- preparation of Customer-specific documentation;
- dedicated personnel time;
- meetings or workshops;
- audit support; or
- other work beyond the ordinary operation and support of PeopleEvo,
NyxDay may charge reasonable fees for that assistance.
Where reasonably practicable, NyxDay will inform the Customer of applicable fees before undertaking chargeable work.
This section does not limit assistance that NyxDay is required to provide without charge under Applicable Data Protection Law.
14. Data Export and Return
During an active subscription and during the applicable recovery period following subscription expiry, an authorized Customer administrator may request a support-assisted export of reasonably available Customer Data.
NyxDay will provide such exports using formats and capabilities reasonably supported by PeopleEvo at the time of the request.
Exports may exclude:
- internal security information;
- fraud-prevention information;
- platform diagnostics;
- proprietary system information;
- information that cannot reasonably be separated from information relating to other Customers;
- aggregated or de-identified information;
- information NyxDay is legally prohibited from providing; and
- information that is not reasonably available through the Service or applicable infrastructure.
NyxDay may verify the identity and authority of the requesting administrator before providing an export.
Custom migration, transformation, extraction, reconstruction, or specially formatted export services are not included unless separately agreed and may be subject to additional fees.
The Customer is responsible for requesting and obtaining any Customer Data it wishes or is legally required to retain before the applicable deletion period expires.
15. Deletion and Retention
Following subscription expiry or termination, Customer Data may be retained for a recovery period of up to 90 days, as described in the PeopleEvo Terms and Conditions and Privacy Policy.
During that recovery period, an authorized Customer administrator may request earlier permanent deletion of the Customer environment and associated Customer Data.
NyxDay may verify the identity and authority of the person requesting deletion.
Once an early deletion request has been processed, restoration of the affected Customer environment may no longer be possible.
If no earlier deletion request is received, Customer Data becomes eligible for permanent deletion after the recovery period.
The Customer acknowledges that the recovery period is provided for account-recovery purposes and is not intended to function as a Customer-controlled archival or backup service.
Deletion obligations are subject to:
- information required or permitted to be retained by applicable law;
- accounting, taxation, billing, or transaction records;
- security and fraud-prevention information;
- information reasonably required for dispute resolution or legal claims;
- information subject to a lawful preservation obligation; and
- residual copies contained in backups until those backups expire or are overwritten through the normal backup lifecycle.
Customer Data remaining solely in backups will remain subject to applicable protection obligations and will not ordinarily be restored except for disaster recovery, continuity, security, or legal purposes.
After Customer Data has been permanently deleted in accordance with the applicable agreement, NyxDay has no obligation to reconstruct, recreate, or recover that Customer Data.
16. Audit and Compliance Information
Upon reasonable written request, NyxDay will provide the Customer with information reasonably necessary to demonstrate compliance with NyxDay's obligations under this DPA.
NyxDay may satisfy an audit or verification request in the first instance by providing reasonably available:
- privacy or security documentation;
- compliance questionnaires;
- Subprocessor information;
- architecture or data-location information;
- summaries of security practices;
- certifications;
- summaries or reports of independent assessments, where available; or
- other appropriate evidence.
A Customer is not entitled to:
- access NyxDay production systems;
- access another Customer's information;
- access NyxDay source code;
- obtain production credentials;
- perform vulnerability scanning;
- perform penetration testing;
- conduct social-engineering testing;
- inspect security-sensitive configurations; or
- obtain information that could reasonably compromise the security of NyxDay, PeopleEvo, or another Customer,
unless expressly agreed by NyxDay or required by Applicable Data Protection Law.
If information reasonably available through documentation is insufficient and Applicable Data Protection Law requires additional verification, the parties will cooperate in good faith regarding an appropriate assessment.
Any audit or assessment must:
- be conducted on reasonable advance written notice;
- occur no more than once annually unless required following a material Personal Information Breach, by a regulator, or by Applicable Data Protection Law;
- be limited to information relevant to the Customer's use of PeopleEvo;
- avoid unreasonable disruption to PeopleEvo, NyxDay, or other Customers;
- protect NyxDay's Confidential Information and information of other Customers;
- comply with NyxDay's reasonable security requirements; and
- occur during normal business hours unless otherwise agreed.
Any third-party auditor must:
- be independent;
- be appropriately qualified;
- not be a competitor of NyxDay or PeopleEvo;
- not have a material conflict of interest; and
- be subject to confidentiality obligations reasonably acceptable to NyxDay.
The Customer is responsible for its own audit and assessment costs.
Where an audit or assessment requires material NyxDay personnel time or custom work beyond ordinary compliance assistance, Section 13.1 applies.
Nothing in this section requires NyxDay to disclose:
- information that would compromise the security of PeopleEvo;
- information belonging to another Customer;
- legally privileged information;
- trade secrets or proprietary source code;
- information subject to another confidentiality obligation; or
- information NyxDay is legally prohibited from disclosing.
17. Government and Legal Requests
If NyxDay receives a legally binding request from a government, court, law-enforcement authority, regulator, or other public authority for Customer Data, NyxDay will evaluate the request and respond as required by applicable law.
Where legally permitted and reasonably practicable, NyxDay will notify the affected Customer before disclosing Customer Data in response to such a request.
NyxDay may challenge or seek clarification of a request where it reasonably considers doing so appropriate, but is not obligated to litigate, appeal, or incur material expense on behalf of the Customer unless separately agreed.
NyxDay will not voluntarily provide Customer Data to a public authority except where:
- authorized by the Customer;
- reasonably necessary to protect rights, property, security, or safety;
- necessary to investigate fraud or abuse; or
- otherwise permitted or required by law.
No contractual provision can prevent information Processed in another jurisdiction from being subject to valid laws and lawful government-access mechanisms applicable in that jurisdiction.
18. Sensitive and Regulated Personal Information
PeopleEvo may Process leave and absence information that reveals or relates to health, disability, pregnancy, family circumstances, accommodation needs, or other sensitive matters.
The Customer is responsible for determining whether such information is necessary and lawful to Process through PeopleEvo.
Customers should not use PeopleEvo to store detailed medical records, diagnoses, clinical notes, or other unnecessary sensitive information unless an applicable PeopleEvo feature expressly supports such information and the Customer has determined that doing so is lawful and necessary.
PeopleEvo is not a medical-record system and does not independently diagnose medical conditions, determine medical eligibility, or make accommodation or employment decisions.
The Customer will not use PeopleEvo as a designated:
- electronic medical-record system;
- clinical-record repository;
- healthcare information system;
- payroll system;
- financial-accounting system; or
- other specialized regulated information system
unless NyxDay has expressly agreed in writing that the applicable PeopleEvo Service supports that use.
The Customer must not submit Personal Information that requires:
- specialized certification;
- specialized hosting;
- specific country or regional residency;
- specialized encryption or key-management requirements;
- industry-specific security controls;
- sector-specific contractual requirements; or
- other safeguards beyond those expressly provided by the applicable PeopleEvo Service
unless NyxDay has expressly agreed to those requirements in writing.
The Customer remains responsible for identifying any specialized legal or regulatory requirements applicable to the information it chooses to Process through PeopleEvo.
19. Optional Third-Party Integrations
Customers or authorized users may choose to connect optional third-party services, including supported Google or Microsoft calendar services.
Where an authorized user enables such an integration, NyxDay may transmit information to or receive information from the applicable provider as necessary to provide the integration.
Customer-directed external integration providers are generally treated separately from PeopleEvo's infrastructure Subprocessors where the Customer or authorized user independently elects to connect the external service.
The Customer is responsible for determining whether enabling an optional integration is appropriate for its organization, users, Data Subjects, and applicable legal requirements.
NyxDay does not guarantee the continued availability, functionality, compatibility, security practices, or terms of an external integration provider.
Where an external provider changes, limits, suspends, or discontinues its service or API, NyxDay may modify, suspend, replace, or discontinue the affected PeopleEvo integration as reasonably necessary.
20. Liability
The liability of each party arising from or relating to this DPA is subject to the exclusions and limitations of liability contained in the PeopleEvo Terms and Conditions or other applicable agreement between the parties, except to the extent such limitation is prohibited by Applicable Data Protection Law.
For clarity:
- this DPA does not create a separate liability cap;
- claims under this DPA are included within the aggregate liability cap applicable under the PeopleEvo Terms and Conditions;
- multiple privacy, security, or data-protection claims arising from the same or related facts, events, circumstances, or failures do not create separate aggregate liability caps; and
- nothing in this DPA increases NyxDay's aggregate contractual liability unless NyxDay expressly agrees otherwise in writing.
Nothing in this section limits liability that cannot legally be limited or excluded.
21. Term and Termination
This DPA becomes effective when the Customer becomes subject to it as part of its agreement for PeopleEvo and remains effective for as long as NyxDay Processes Personal Information contained in Customer Data on behalf of the Customer.
Termination or expiry of a PeopleEvo subscription does not immediately terminate this DPA where Customer Data remains subject to an applicable recovery, retention, backup, deletion, or legal-preservation period.
Provisions relating to confidentiality, security, deletion, liability, government requests, and other obligations that by their nature should continue after termination will survive for as long as relevant Personal Information remains in NyxDay's possession or control.
22. Changes to This DPA
NyxDay may update this DPA from time to time to reflect:
- changes in PeopleEvo;
- changes in Applicable Data Protection Law;
- changes to privacy or security practices;
- changes to Subprocessors or infrastructure;
- changes to standard contractual practices; or
- changes necessary to clarify or improve the DPA.
Where a change materially reduces the protections applicable to Personal Information contained in Customer Data during an active subscription, NyxDay will provide reasonable notice where required by Applicable Data Protection Law or the applicable agreement.
Unless additional consent is required by law, the then-current DPA will apply prospectively in accordance with the PeopleEvo Terms and Conditions.
23. Governing Law
Unless Applicable Data Protection Law requires otherwise, this DPA is governed by the governing-law provisions of the PeopleEvo Terms and Conditions or other applicable agreement between NyxDay and the Customer.
---
Schedule A — Details of Processing
1. Subject Matter
Processing of Personal Information as necessary to provide, operate, secure, maintain, support, troubleshoot, and administer the PeopleEvo workforce and leave-management Service.
2. Duration
For the duration of the Customer's use of PeopleEvo and any applicable recovery, retention, backup, deletion, dispute, security, or legal-preservation period described in the agreement.
3. Nature of Processing
Processing activities may include:
- collection;
- recording;
- organization;
- structuring;
- storage;
- retrieval;
- consultation;
- calculation;
- display;
- modification;
- workflow routing;
- transmission;
- synchronization;
- export;
- backup;
- restriction;
- deletion; and
- other Processing initiated through Customer configuration, authorized user activity, or documented Customer instructions.
4. Purposes
Processing Personal Information to provide functionality such as:
- account and user administration;
- employee administration;
- leave and absence management;
- leave balance calculation and tracking;
- approval workflows;
- backup and coverage management;
- team availability;
- holiday and working-day configuration;
- reporting and exports;
- audit and activity history;
- Customer-configured notifications;
- Customer support;
- troubleshooting;
- security and abuse prevention;
- Service reliability and performance;
- subscription-related functionality; and
- optional integrations enabled by the Customer.
5. Categories of Data Subjects
Depending on Customer use, Data Subjects may include:
- Customer administrators;
- employees;
- workers;
- contractors;
- managers;
- supervisors;
- approvers;
- backup or coverage personnel;
- authorized users; and
- other personnel whose information the Customer lawfully manages through PeopleEvo.
6. Categories of Personal Information
Depending on Customer configuration and use:
- names;
- business email addresses;
- employee identifiers;
- employment or organizational information;
- job or role information;
- group or team membership;
- account and access information;
- roles and permissions;
- leave types;
- leave dates and durations;
- leave balances and adjustments;
- leave-request status;
- approval and rejection information;
- backup and coverage information;
- working-day and holiday information;
- comments and notes;
- uploaded attachments;
- audit and activity information;
- notification information;
- timezone and preference information;
- technical and security information associated with Customer use; and
- other information submitted by or on behalf of the Customer.
7. Sensitive Information
Leave and absence information may reveal or relate to:
- health;
- disability;
- pregnancy;
- family circumstances;
- accommodation needs; or
- other sensitive personal circumstances.
Customers are responsible for limiting collection to information that is necessary, lawful, and appropriate for their purposes.
---
Schedule B — Technical and Organizational Measures
NyxDay maintains measures designed to protect Customer Data appropriate to the nature of the PeopleEvo Service and information Processed.
The measures below describe categories of safeguards and do not constitute a representation that every measure applies identically to every feature, Customer, environment, or deployment configuration.
1. Access and Authentication
Measures may include:
- authenticated access to Customer environments;
- role- and permission-based access controls;
- server-side authorization controls;
- support for multi-factor authentication where provided by the Service;
- separation of Customer and platform-administration access;
- controls intended to prevent unauthorized cross-Customer access;
- credential and account-security controls; and
- access revocation or restriction when no longer required.
2. Application and Data Security
Measures may include:
- logical tenant isolation;
- authorization checks for protected operations;
- encrypted network communication using HTTPS/TLS;
- managed PostgreSQL database infrastructure;
- controlled object-storage access;
- time-limited signed access mechanisms where used for Customer attachments;
- input validation;
- secure application configuration;
- security and anti-abuse protections; and
- reasonable measures designed to reduce unauthorized access or disclosure.
3. Infrastructure and Hosting
PeopleEvo uses third-party infrastructure providers to support functions such as:
- application hosting;
- database hosting;
- object storage;
- transactional email delivery; and
- customer support.
Current material Subprocessors and Processing locations are maintained at:
Specific regional hosting or data-residency commitments apply only where expressly agreed in writing.
4. Operational Controls
Measures may include:
- controlled production configuration;
- restricted access to production credentials and infrastructure;
- logging, audit, error-monitoring, and diagnostic functionality appropriate to the Service;
- separation of environments where applicable;
- infrastructure-provided backup and recovery mechanisms;
- processes for responding to security and privacy incidents;
- access review and removal procedures;
- deployment and change-management practices; and
- operational monitoring appropriate to the Service.
5. Personnel and Confidentiality
Measures include or may include:
- access limited according to legitimate operational requirements;
- confidentiality obligations applicable to personnel with access to Customer Data;
- least-privilege principles where reasonably applicable;
- removal or adjustment of access when no longer required; and
- controls intended to limit unnecessary access to Customer Data.
6. Customer Responsibilities
Security of PeopleEvo also depends on Customer-controlled measures.
Customers are responsible for:
- protecting account credentials;
- configuring roles and permissions appropriately;
- disabling users who should no longer have access;
- maintaining secure endpoint devices and networks;
- controlling which Personal Information is entered into PeopleEvo;
- reviewing Customer-controlled configurations; and
- promptly notifying NyxDay of suspected unauthorized account access.
7. Evolution of Security Measures
NyxDay may modify these measures as:
- technology evolves;
- threats change;
- PeopleEvo functionality changes;
- infrastructure changes; or
- operational requirements evolve.
Such changes will not materially reduce the overall level of protection provided to Customer Data during an active subscription.