⚙ WagePress Data Processing Addendum (DPA)
Last Updated: November 08, 2025 • Houston, Texas, USA • Contact: support@wagerpess.com • +1 855 551 5253
This Data Processing Addendum (“DPA”) forms part of the agreement between Wagepress (“Processor” or “Service Provider”) and the customer identified in the applicable ordering document (“Controller” or “Business”).
1. Scope and Roles
Wagepress will Process Personal Data solely to provide the Services on documented instructions from Customer, including transfers to Sub-processors as permitted herein. Customer is responsible for the accuracy, quality, and legality of Personal Data and for the means by which it obtained Personal Data.
2. Definitions
“Personal Data,” “Process,” etc., have meanings under applicable data protection laws (e.g., CPRA, Virginia, Colorado, Connecticut, Utah, Oregon, Texas). “Sensitive Personal Data” includes SSN/TIN and bank account numbers. “Sub-processor” means any third party engaged by Wagepress to Process Personal Data on its behalf.
3. Processing Details
Subject Matter: payroll, information reporting, e-filing, and related support.
Duration: term of the underlying Agreement plus retention required by law.
Nature and Purpose: hosting, storage, transmission, printing/mailing, e-delivery, analytics, and support.
Data Subjects: Customer’s personnel, workers, contractors, recipients, and other individuals whose data Customer submits.
Categories: identifiers, contact data, payroll/tax data (including SSN/TIN/EIN), financial data, usage/telemetry.
4. Processor Obligations
- Process only on Customer’s documented instructions;
- Ensure personnel confidentiality;
- Implement appropriate technical and organizational security measures;
- Assist with data subject requests and security obligations, taking into account the nature of processing;
- Notify Customer without undue delay of a Personal Data Breach;
- Delete or return Personal Data at termination, unless law requires retention;
- Make available information necessary to demonstrate compliance and allow audits (maximum one per 12 months, during business hours, subject to confidentiality and reasonable limits).
5. Sub-processors
Customer authorizes Wagepress to engage Sub-processors for the Services. Wagepress will enter a written agreement imposing data protection obligations no less protective than those herein and remains responsible for Sub-processors’ performance. A current list of Sub-processors is available upon request; Customer may subscribe to change notifications and object on reasonable, documented grounds.
6. Cross-border Transfers
Wagepress will implement appropriate safeguards for international transfers as required by law (e.g., contractual clauses, intra-group agreements, or de-identification).
7. Security Measures (Summary)
- Access control (least-privilege; MFA for privileged roles);
- Encryption in transit;
- Segregation of environments;
- Logging and monitoring;
- Vulnerability management and patching;
- Backup and business continuity;
- Secure software development lifecycle;
- Vendor due diligence; and incident response. Further detail available upon request.
8. Government Requests
Where legally permissible, Wagepress will notify Customer of any government requests for Personal Data. Wagepress will challenge unlawful or overbroad requests and disclose only what is legally required.
9. Miscellaneous
In the event of conflict, this DPA controls over the Agreement with respect to data protection. This DPA is governed by the law specified in the Agreement. Execution via electronic acceptance is permitted.
© WagePress. This document is provided for informational purposes and does not constitute legal or tax advice.
Contact for Data Protection: support@wagerpess.com • +1 855 551 5253
WagePress Data Processing Addendum (DPA)