Data processing addendum
Version 2.0 · Updated
This addendum governs Knotfix's processing of the personal data of the Client's roster and of its employees' answers. It forms part of the Terms of service and is incorporated by reference: it is accepted when the contract is accepted and needs no separate signature.
It is written to work under two frameworks at once, because the service is sold outside Costa Rica:
- Costa Rican Law No. 8968 and its implementing regulation, Executive Decree No. 37554-JP;
- Regulation (EU) 2016/679 (GDPR), its UK equivalent (UK GDPR) and the Swiss FADP, where they apply to the Client.
Which of those applies depends on where the Client's employees are, and the Client is the one who knows that. Knotfix's obligations are the same under all of them: where the rules differ, the stricter one is met. Where this addendum says «responsable» it also says controller, and where it says «encargado» it also says processor.
The role of each party
The Client is the controller. It decides who is measured, what is asked, what the results are used for and how long they are kept. It is for the Client to inform its employees, to establish a valid legal basis and to complete whatever employee-consultation formalities its country requires.
Knotfix processes that data on the Client's behalf, on its instructions, and not for purposes of its own.
That split does not release Knotfix: article 11 of Law 8968 reaches anyone involved at any stage of processing, article 28 of the GDPR imposes obligations on the processor that are its own and directly enforceable, and under both the duty of secrecy survives the end of the relationship.
⚠️ There is one part where Knotfix is a controller and not a processor: ACCOUNT data —who administers it, with what email, what was invoiced. That is not covered here but in the Privacy policy. Mixing the two relationships is where nearly every question comes from.
Subject matter, duration and nature
| Subject matter | Providing the workplace climate survey service |
| Duration | That of the contract, plus the return and deletion periods in the corresponding section |
| Nature | Collection, storage, statistical computation, aggregation, suppression and deletion |
| Purpose | Producing aggregate workplace climate results for the Client |
Data and data subjects
Data subjects: the Client's employees within the scope of each study.
Categories of data:
- From the roster: name, job title, position in the organizational structure and email where the survey is applied by that route.
- From participation: whether the person was selected and whether they have answered.
- From the answers: the values given and the segment attributes captured with them.
Answers are not stored linked to the person. Participation and answers live apart, with no link between them; the date is stored without a time, so they cannot be rejoined by order of arrival either. It is not a permissions restriction: the link does not exist in the database and therefore cannot be restored.
⚠️ FREE-TEXT answers are delivered to the Client exactly as written, accompanied by the branch of the organization they belong to and with no filtering of identifying details. They are still not linked to a person, but a text can identify whoever wrote it by its content or its style, and the confidentiality threshold protects aggregates, not individual records. If the Client uses open questions, that circumstance must appear in the notice it gives its employees.
Sensitive data / special categories: the service is not designed to process it and the Client undertakes not to configure it, under the Terms. No data of minors and no criminal-conviction data is processed either.
Documented instructions
Knotfix processes the data only in accordance with the Client's documented instructions, which are this addendum, the contract and the actions the Client performs inside the product. That includes the international transfers described below.
If an instruction from the Client were contrary to applicable data protection law, we tell the Client and do not carry it out.
If an authority compelled us to hand over this data, we notify the Client before doing so, unless the rule itself forbids us to; in that case we do what is reasonable to have that prohibition lifted and we keep a record of what was handed over.
Confidentiality
Knotfix personnel with access to this data are bound by confidentiality, which survives the end of their employment. Access is granted on a need-to-know basis and is logged.
Security
We apply the measures of article 10 of Law 8968 and article 32 of the GDPR. They are set out one by one in Annex II of this document: it is the list a vendor assessment asks for, which is why it is written as a list and not as a paragraph.
Anonymity as a technical measure
Beyond the above, Knotfix maintains two guarantees that belong to the product itself:
- Structural separation. Who took part and what was answered are stored with no link.
- Confidentiality threshold. Results for groups below the threshold are not published, and the rule also applies where a hidden result could be deduced by subtracting visible ones.
Neither can be switched off —not by Client configuration, not by role, not by support action, not on the Client's express request. It is the condition for the measurement to be worth anything, which is why it is a Knotfix obligation and not a Client option.
Sub-processors
The Client generally authorizes Knotfix to rely on the providers listed in Annex III. With all of them we maintain contractual obligations equivalent to those in this addendum, and Knotfix remains liable for their acts as for its own.
Before bringing in a new one or replacing an existing one we give 30 days notice. If the Client objects on reasonable grounds related to data protection, it may terminate the contract without penalty before the change takes effect, and the proportional part of what was paid and not provided is refunded.
This general authorization is Option 2 of clause 9(a) of the Standard Contractual Clauses, with the 30-day period stated there.
International transfers
Knotfix is domiciled in Costa Rica and part of the infrastructure is in the United States (see Annex III). What covers that transfer depends on where the data leaves from.
From Costa Rica
Article 14 of Law 8968, with the authorization the Client gives by accepting this addendum. The Client represents that it has informed its employees of this.
From the European Economic Area
⚠️ The European Commission has not found Costa Rica adequate, so the transfer needs article 46 safeguards and neither the Client's consent nor the data subjects' will do: article 49 is for occasional cases, and this is permanent infrastructure.
The parties therefore incorporate into this addendum the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, which are deemed signed on acceptance of the contract. The choices those clauses leave open are made as follows:
| Module | Module 2 (controller to processor) where the Client is a controller. Module 3 (processor to processor) where the Client itself acts as a processor for a third party. Whichever matches the Client's actual position applies |
| Exporter | The Client, as per Annex I.A |
| Importer | Knotfix, as per Annex I.A |
| Clause 7 (docking) | Included |
| Clause 9(a) | Option 2, general authorization, with 30 days notice |
| Clause 11(a) | The optional independent dispute resolution body paragraph is not included |
| Clause 13 | The competent supervisory authority is the one in Annex I.C |
| Clause 17 | The law of the Member State in which the exporter is established. If that law does not allow third-party beneficiary rights, the law of Ireland |
| Clause 18(b) | The courts of that same Member State; failing that, those of Ireland |
| Annexes I, II and III to the clauses | These are Annexes I, II and III of this document |
Transfer impact assessment. We have assessed whether the law of Costa Rica and of the United States prevents compliance with those clauses and concluded that it does not in the concrete case of this processing, taking into account: that Costa Rica has a data protection law and a supervisory authority (PRODHAB); that the data processed is of no interest to government surveillance programmes; that there is no way in the system to link an answer to a person, so not even a court order could produce one; and that the supplementary measures in Annex II —encryption in transit and at rest, per-organization isolation and the product's structural separation— reduce what a compelled disclosure could yield. Should we ever become unable to comply with them, we notify the Client and it may suspend the transfer or terminate the contract, as clause 14(f) requires.
From the United Kingdom
The same clauses, completed by the ICO's International Data Transfer Addendum (version B1.0, in force since 21 March 2022), whose tables are filled in by this addendum: Table 1 by Annex I.A, Table 2 by the choices above, Table 3 by Annexes I, II and III, and in Table 4 the Addendum may be ended by either party.
From Switzerland
The same clauses with the adaptations the FADP requires: the competent supervisory authority is the FDPIC, references to the GDPR are read as references to the FADP, and «Member State» is not to be read so as to prevent people domiciled in Switzerland from bringing claims where they live.
Order of precedence
⚠️ If anything in this addendum contradicts the Standard Contractual Clauses, the clauses prevail. This is not courtesy: an amended standard clause stops being a standard clause, and the basis for the transfer falls with it.
Data subject rights
If an employee exercises any of their rights with Knotfix —access, rectification, erasure, portability, restriction or objection— we route it to the Client, which is the controller, and assist it with appropriate technical and organizational measures to answer within the five business days of article 7 of Law 8968 — shorter than the one month of article 12 of the GDPR, which is why it applies to everyone.
For survey answers that assistance has a structural limit: because the link between person and answer does not exist, it is not possible to locate, rectify or delete a particular person's answer. The Client knows and accepts this consequence, which is the flip side of the anonymity guarantee, and it is for the Client to explain it to its employees in the prior notice.
Assisting the Client with its own obligations
Beyond the above, and taking into account the nature of the processing and the information available to us, we assist the Client in complying with articles 32 to 36 of the GDPR:
- Security of processing (art. 32): with the measures in Annex II and with the information the Client needs to assess whether they are enough for it.
- Breach notification (arts. 33 and 34): with what the next section describes, which is what the Client needs in order to notify its authority and, where required, the people affected.
- Impact assessment and prior consultation (arts. 35 and 36): a climate survey usually calls for a DPIA, so we hand over the description of the processing, the security measures and the explanation of the two anonymity guarantees, which is precisely what that assessment has to weigh. The DPIA is the Client's: it belongs to the controller and only the Client knows the context it is measuring in.
Security incidents
On an incident affecting the Client's personal data, we notify it without undue delay and at the latest within 72 hours of detecting it, stating what happened, which categories and roughly how much data and how many people may be affected, the likely consequences, what measures we took and which we recommend, and a point of contact. If we do not have all of that at the outset, we send what we have and complete it afterwards.
It is for the Client, as controller, to notify the authority and anyone else required.
Return and deletion
For as long as the account exists, the Client can export its results with the product's export tools, in commonly used formats (spreadsheet and PDF). No full dump of the database is provided by any other route.
Deletion is carried out by the Client itself: the account owner deletes it from the product and the data is erased immediately and irreversibly from production systems, with no grace period. What a legal obligation requires us to keep is excepted; in that case what is kept is limited to what is strictly necessary and remains protected by this addendum.
Copies existing in infrastructure backups are not erased in that same act: they disappear when the backup rotation cycle overwrites them. Until then they remain encrypted, protected by this addendum and used for nothing but disaster recovery.
On deleting the account, the product returns a breakdown of what was erased, which serves as evidence of deletion and satisfies the certification clause 8.5 of the Standard Contractual Clauses asks for.
Information and verification
On the Client's reasonable request we provide the information needed to demonstrate compliance with this addendum and with the Standard Contractual Clauses.
The Client may also audit that compliance once a year, with 30 days notice, during business hours, over the systems that process its data and at its own cost. The audit may not reach other clients' data or compromise the security of the service, and whoever carries it out is bound by confidentiality. Where an incident affecting its data prompts it, the audit proceeds without waiting for the annual cadence or the full notice period.
California
With respect to measurement data, Knotfix acts as a service provider within the meaning of the CCPA/CPRA. Accordingly: we do not sell or share personal information —including cross-context behavioural advertising—; we do not retain, use or disclose it for any purpose other than providing the service to the Client, nor outside the direct business relationship with it; and we do not combine it with another client's data or with data from another source, except as that law itself permits. The Client may take reasonable and appropriate steps to verify this, and those are the ones in the previous section.
Term and precedence
This addendum applies for as long as Knotfix processes data on the Client's behalf, and its confidentiality, security and deletion obligations survive it.
On a contradiction the following prevail, in this order: (1) the Standard Contractual Clauses, (2) this addendum, (3) the Terms of service.
Annex I — Parties, processing and authority
A. List of parties
Data exporter. The Client, with the name, address and contact it declared on contracting and which are held in its account. Activity: contracting a workplace climate survey service for its own workforce. Role: controller (Module 2) or processor (Module 3), according to its actual position. Signature and date: those of the acceptance of the Terms, recorded by the product together with the version number accepted.
Data importer.
| Name | José Alejandro Chaves Ramírez, an individual, trading as Knotfix |
| National ID (cédula) | 5-0448-0254 |
| Address | Guanacaste province, Liberia canton, Liberia district, La Cruz. Postal code 50101, Costa Rica |
| Data protection contact | knotfixservice@knotfix.com · +506 8791 7066 |
| Activity | Provision of the Censuma service |
| Role | Processor |
B. Description of the transfer
| Categories of data subjects | The Client's employees within the scope of each study |
| Categories of data | Roster: name, job title, position in the structure, email where the survey is applied by that route. Participation: whether selected and whether answered. Answers: the values given and the segment attributes captured with them |
| Sensitive data | None. The service is not designed to process it and the Client undertakes not to configure it |
| Frequency | Continuous, while the contract is in force |
| Nature | Collection, storage, statistical computation, aggregation, suppression and deletion |
| Purpose | Producing aggregate workplace climate results for the Client |
| Retention | For as long as the account exists; the owner deletes it from the product and the erasure is immediate and irreversible, except for what a legal obligation requires to be kept and what survives in backups until the rotation cycle overwrites them |
| Sub-processors | Those in Annex III, for the purposes and durations stated there |
C. Competent supervisory authority
That of the Member State in which the exporter is established or, where it is not established in the Union, that of the Member State where the data subjects are or where it has designated a representative. For the United Kingdom, the Information Commissioner's Office; for Switzerland, the FDPIC; for Costa Rica, PRODHAB.
Annex II — Technical and organizational measures
These are what article 10 of Law 8968 and article 32 of the GDPR require, and what clause 8.6 of the Standard Contractual Clauses asks to be described in specific terms.
Encryption. In transit, TLS on every connection —browser to application and application to each provider. At rest, encryption of the database storage and of file storage.
Access control. Authentication delegated to a specialist identity provider, with two-step verification available; Knotfix never sees anyone's password. Inside the product, permissions by role and by branch of the org chart, enforced on the server and not in the interface.
Isolation between clients. Every read and every write is scoped to the requester's organization at the data layer. The scoping is the default and its absence makes the query fail rather than opening it up.
Card details never pass through our servers. They are entered in our payment processor's form and travel from the browser straight to it.
Logs. Infrastructure access logs, plus a dedicated results-consultation log —who consulted which segment of which study— which exists to detect attempts to re-identify respondents. That log does not record the values consulted and is purged after 12 months.
Environment separation. Development, staging and production are separate, and real client data is not copied into the first two.
Backups. Automatic and daily, with the database provider's retention, and encrypted. Used for disaster recovery only.
Minimization. The roster asks for the minimum needed to sample and to administer: there are no demographic fields in the roster, and the ones used for segmentation are asked inside the questionnaire and travel with the answer, not with the person.
Structural pseudonymization. Participation and answers are stored with no foreign key between them, and the date of the answer is stored without a time. It is not a permissions restriction: the link does not exist.
Statistical suppression. Results for groups below the confidentiality threshold are not published, and the rule extends to what could be deduced by subtracting visible results. It cannot be switched off by role, plan or support action.
Personnel. Access on a need-to-know basis, with a duty of confidentiality that survives the end of employment.
Incident management. Notice to the Client without undue delay and at the latest within 72 hours of detection, with the content described in this addendum.
Review. These measures are reviewed periodically and on any change of infrastructure provider.
⚠️ Measures this addendum does NOT promise, so that nobody assumes them: there is no SOC 2 or ISO 27001 certification, no uptime percentage commitment unless separately agreed, and infrastructure access logs are operational and ephemeral —discarded with each deployment— and are not archived.
Annex III — Sub-processors
| Sub-processor | What for | Country |
|---|---|---|
| Hostinger | Application hosting (private server) | United States |
| PlanetScale | Database: roster, answers and results | United States |
| Clerk | Identity and authentication of the account's users | United States |
| Resend | Sending system email, including survey invitations | United States |
| Cloudflare (R2) | Storage of the organization's logo | United States |
| Polar | Card payment processing and subscription invoicing as merchant of record | United States |
| Allegra | Issuing and delivering the electronic invoice to the Costa Rican tax authority | Costa Rica |
⚠️ The last three do NOT process measurement data. Polar and Allegra process account billing data, and Cloudflare R2 stores the logo the organization uploads. They are listed anyway because a sub-processor list that names only some of them is useless for assessing a vendor.
This list is what underpins the general authorization in the «Sub-processors» section and clause 9 of the Standard Contractual Clauses. Any addition or replacement is notified 30 days in advance.