Data processing terms
These terms apply whenever Accolgo processes personal information on behalf of a customer organization. Under the CCPA the customer is the business and Accolgo is its service provider. The CCPA requires that relationship to be set out in a written contract containing specific terms, and this page is that contract.
Subject matter and duration
Processing of onboarding check-in information (identities and contact details of starters, managers and buddies; worded check-in replies; optional notes; follow-up records) for the duration of the customer’s subscription plus the deletion window in the retention policy.
The service provider commitments
- Accolgo processes personal information only on the customer’s documented instructions, and for the specific purpose of running the onboarding check-in service.
- Accolgo does not sell personal information and does not share it for cross-context behavioral advertising, as both terms are defined in the CCPA.
- Accolgo does not retain, use or disclose personal information for any purpose other than performing the service, and specifically not for its own commercial purposes.
- Accolgo does not combine personal information received from one customer with information received from another, or from any other source, except as the CCPA expressly permits.
- Accolgo will notify the customer if it determines it can no longer meet these obligations.
- The customer may take reasonable and appropriate steps to confirm that Accolgo uses personal information consistently with these obligations.
Confidentiality and security
Everyone with access is bound by confidentiality. The security measures are set out in full on the security page and are applied to every customer alike, not tiered by plan.
The private word. When a new starter asks to speak with someone senior who is not their line manager, that message is a restricted category. It is accessible only to the organization’s head of people (and owner). This is enforced at the database layer, not only in the interface: the underlying field carries no grant to the line-manager role, so a manager cannot read it through the application, an export, or a direct query. The person’s manager is not told that a private word was raised.
Security compromises (breach notification)
Draft only, not legal advice. For Dermot’s own review and his solicitor’s confirmation before this is relied on or shown to any customer. The specific timeframe below is stated from general knowledge, not independently verified live in this session, and must be checked against the current law of every US state Accolgo actually has customers or data subjects in before this is treated as final.
Where Accolgo has reasonable grounds to believe personal information it processes on the customer’s behalf has been accessed, acquired, or disclosed without authorization, Accolgo will notify the customer without unreasonable delay, and in any event within 30 days of becoming aware, so that the customer can meet its own notification duties to affected individuals and to any state attorney general or regulator, under whichever US state law applies to them. Accolgo will provide the information reasonably available to it about the nature of the incident, the categories and approximate number of individuals and records involved, and the steps Accolgo has taken or plans to take in response, and will assist the customer’s own notification efforts as reasonably requested.
This commitment is Accolgo’s own to the customer, separate from and in addition to whatever the customer’s own applicable state law requires of the customer directly.
Sub-processors
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, storage | EU (Dublin, Ireland) |
| Vercel | Application hosting | EU functions region |
| Resend | Transactional email | US / per sending configuration |
| Sentry | Error monitoring | EU data residency |
| Anthropic | Drafting of manager nudges (when enabled) | US / per API region |
Each is bound by written terms at least as protective as these. We will tell you before adding or replacing one.
Helping you meet your own obligations
Accolgo will assist the customer, taking into account the nature of the processing, in responding to requests from individuals to know, access, correct or delete their information, and in meeting the customer’s own security and breach-notification duties under applicable state law.
Return and deletion
On termination, personal information is deleted on the schedule in the retention policy, or returned or deleted earlier at the customer’s written request, save for anything the law requires us to keep.