Strictly necessary
Required for authentication, security, sessions, forms, and storing your privacy choices.
This Data Processing Addendum (“DPA”) forms part of the agreement between:
Processor: InnOneWeb OÜ, an Estonian private limited company (OÜ), registry code 16826593, registered address Sakala 7-2, 10141 Tallinn, Estonia, doing business as FieldCosts (“FieldCosts”); and
Controller: the customer entity that has entered into the FieldCosts Terms of Service or an applicable Order (“Customer”).
FieldCosts and Customer are each a “Party” and together the “Parties.”
1.1. This DPA applies where FieldCosts processes Personal Data on behalf of Customer in connection with the FieldCosts Service.
1.2. This DPA supplements the FieldCosts Terms of Service and applicable Orders.
1.3. In the event of conflict:
Terms such as Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Subprocessor, and Supervisory Authority have the meanings given in applicable Data Protection Law.
“Applicable Data Protection Law” means all data-protection and privacy laws applicable to the Processing under this DPA, including, where applicable:
“Customer Personal Data” means Personal Data contained in Customer Content and processed by FieldCosts on Customer’s behalf.
“Restricted Transfer” means a transfer of Personal Data requiring an approved transfer mechanism under Applicable Data Protection Law.
“Service” means the FieldCosts websites, web application, mobile applications, APIs, integrations, support, and related services covered by the agreement.
3.1. Customer is the Controller or Business of Customer Personal Data.
3.2. FieldCosts is the Processor or Service Provider of Customer Personal Data.
3.3. Each Party will comply with the obligations applicable to its role.
3.4. Customer is solely responsible for:
3.5. FieldCosts may process certain account, security, billing, support, and business-contact data as an independent Controller, as described in the FieldCosts Privacy Policy.
4.1. FieldCosts will process Customer Personal Data only:
4.2. The agreement, Customer’s use and configuration of the Service, enabled integrations, support requests, and written instructions constitute documented instructions.
4.3. If FieldCosts reasonably believes an instruction violates Applicable Data Protection Law, FieldCosts will notify Customer and may suspend the affected Processing until the instruction is confirmed, modified, or withdrawn.
4.4. FieldCosts will not:
The details required by Article 28 GDPR are set out in Annex 1.
6.1. FieldCosts will ensure that persons authorized to process Customer Personal Data:
6.2. Confidentiality obligations survive termination of employment, engagement, or access.
7.1. FieldCosts will maintain technical and organizational measures appropriate to the risk, taking into account:
7.2. The current measures are described in the FieldCosts Security and Technical & Organizational Measures document and Annex 2.
7.3. FieldCosts may update security measures provided the overall level of protection is not materially reduced.
7.4. Customer acknowledges that no system can guarantee absolute security and is responsible for:
8.1. Customer grants FieldCosts general written authorization to use Subprocessors.
8.2. FieldCosts will maintain a public Subprocessor List at https://fieldcosts.com/subprocessors.
8.3. FieldCosts will provide at least 15 days advance notice of a new Subprocessor that will process Customer Personal Data, except where urgent replacement is necessary for security, continuity, or legal compliance.
8.4. Customer may object within the notice period on reasonable data-protection grounds.
8.5. The Parties will work in good faith to resolve an objection. If no reasonable resolution is available, Customer may terminate the affected Service before the new Subprocessor begins Processing. Customer’s exclusive remedy is termination of the affected Service and a pro-rata refund of prepaid fees for the unused terminated period.
8.6. FieldCosts will impose materially equivalent data-protection obligations on each Subprocessor.
8.7. FieldCosts remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.
9.1. Taking into account the nature of Processing, FieldCosts will provide reasonable assistance for Customer to respond to requests to exercise privacy rights.
9.2. If FieldCosts receives a request concerning Customer Personal Data:
9.3. Assistance beyond standard Service functionality may be charged at reasonable professional-services rates where legally permitted and agreed in advance.
10.1. FieldCosts will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data.
10.2. Notification will include, to the extent known and available:
10.3. FieldCosts may provide information in phases.
10.4. Notification does not constitute an admission of fault or liability.
10.5. Customer is responsible for determining whether notice to a Supervisory Authority, Data Subject, customer, insurer, or other person is legally required, unless FieldCosts acts as Controller for the affected data.
Taking into account the nature of Processing and information available, FieldCosts will reasonably assist Customer with:
12.1. FieldCosts will make available information reasonably necessary to demonstrate compliance with this DPA.
12.2. Customer should first rely on:
12.3. If those materials are insufficient, Customer may request one audit per 12-month period, unless a confirmed Personal Data Breach or Supervisory Authority requires more frequent review.
12.4. Audits must:
12.5. FieldCosts may charge reasonable costs for audit support beyond ordinary compliance assistance.
13.1. During the subscription, Customer may use available export and deletion functions.
13.2. On termination, FieldCosts will, at Customer’s choice and subject to the agreement:
13.3. A workspace closure request starts a 30-day read-only export and cancellation period. After that period, organization-owned rows and files are erased by the scheduled deletion process.
13.4. FieldCosts may retain limited data where required by law, for legal claims, security, or fraud prevention. A documented workspace legal hold pauses scheduled cleanup and final deletion for that workspace until the hold is reviewed and released. Application-managed backups expire after 30 days when enabled; provider snapshots expire under the provider contract.
13.5. Retained data remains protected, access-restricted, and is not used for unrelated purposes.
14.1. FieldCosts will not make a Restricted Transfer without a valid transfer mechanism.
14.2. Valid mechanisms may include:
14.3. Where the European Commission Standard Contractual Clauses are required:
14.4. FieldCosts will provide reasonable information needed for transfer-risk assessments, subject to confidentiality and security limitations.
Where a U.S. state privacy law applies and FieldCosts processes Personal Data as a service provider, contractor, or processor:
Liability arising under this DPA is subject to the exclusions and limitations of liability in the Terms of Service, except to the extent prohibited by Applicable Data Protection Law.
This DPA remains effective while FieldCosts processes Customer Personal Data.
---
Provision of the FieldCosts business operations, job-costing, receipt, expense, approval, reimbursement, invoicing, reporting, file, mobile, and integration Service.
For the subscription term and the post-termination export, backup, legal-hold, and deletion periods described in the agreement and Retention Policy.
The Service is not intended for special-category data, protected health information, biometric identifiers, full payment-card data, or criminal-offence data. Customer must not submit such data unless expressly authorized in writing.
Continuous or recurring during use of the Service.
As described in the FieldCosts Data Retention Policy, Customer configuration, and applicable Order.
---
The FieldCosts Security and Technical & Organizational Measures document is incorporated into this Annex.
---
The FieldCosts public Subprocessor List is incorporated into this Annex.