Data Processing Agreement
This Data Processing Agreement forms part of, and is governed by, the Master Services Agreement (D2) between AIHire365 ("Processor", "we") and the Customer ("Controller", "you"). It governs our processing of Candidate Data on your behalf. Where this DPA conflicts with the MSA on data-protection matters, this DPA prevails.
1. Definitions and roles
- 1.1 Terms such as "personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings in applicable Data Protection Law (including the EU GDPR, UK GDPR, and applicable US state privacy laws).
- 1.2 You are the controller of Candidate Data; we are the processor acting on your documented instructions. Where you are yourself a processor for another controller (for example, a staffing agency acting for an end-employer), we act as sub-processor and you warrant you have authority to engage us.
2. Scope and instructions
- 2.1 We process Candidate Data only to provide the Platform and screening services and on your documented instructions (this DPA, the MSA, your configuration, and the Documentation).
- 2.2 We will inform you if, in our opinion, an instruction infringes Data Protection Law (without obligation to provide legal advice).
- 2.3 The subject matter, duration, nature, purpose, categories of data, and categories of data subjects are described in Annex A.
3. Confidentiality of personnel
We ensure that persons authorized to process Candidate Data are bound by confidentiality and are trained on their data-protection obligations, and we limit access on a need-to-know basis.
4. Security measures
- 4.1 We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the data, as described in Annex C. These include encryption in transit, access controls and least-privilege provisioning, logging and monitoring, secure development practices, and business-continuity measures.
- 4.2 We periodically test and review these measures.
5. Sub-processors
- 5.1 You provide general authorization for us to engage sub-processors to process Candidate Data, listed in Annex B.
- 5.2 We impose data-protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance.
- 5.3 We will give you at least [30] days' advance notice of the addition or replacement of a sub-processor (via the Legal Center or email). You may object on reasonable data-protection grounds; if we cannot reasonably accommodate the objection, you may terminate the affected services.
6. Assisting the controller
- 6.1 Data-subject requests. Taking into account the nature of processing, we will assist you with appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests. If a data subject contacts us directly, we will refer them to you.
- 6.2 We will assist you, taking into account the nature of processing and the information available to us, with your obligations regarding security, breach notification, data-protection impact assessments, and prior consultation (GDPR Arts. 32–36).
7. Personal-data breach
We will notify you without undue delay after becoming aware of a personal-data breach affecting Candidate Data, and provide information reasonably available to help you meet your notification obligations.
8. International transfers
- 8.1 Where our processing involves transfer of Candidate Data out of the EEA, the UK, or another restricted region, the Standard Contractual Clauses (EU Commission Decision 2021/914) and, for UK data, the UK International Data Transfer Addendum are incorporated into this DPA and completed as set out in Annex D, together with supplementary measures where required.
- 8.2 The relevant SCC module applies according to the parties' roles (controller-to-processor, or processor-to-processor where applicable).
9. Audit
- 9.1 We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
- 9.2 Audits are subject to reasonable notice, frequency limits, confidentiality, and our security policies; we may satisfy audit requests through third-party reports where available.
10. Deletion and return
On termination or expiry of the services, we will, at your choice, delete or return Candidate Data and delete existing copies, except to the extent retention is required by law, within the export window stated in the MSA (§9.4).
11. Liability and precedence
- 11.1 Each party's liability under this DPA is subject to the limitations in the MSA (§10), except where Data Protection Law requires otherwise.
- 11.2 This DPA prevails over the MSA on data-protection matters.
Annexes (to be completed before execution)
- Annex A — Details of processing: subject matter, duration, nature and purpose, categories of personal data, categories of data subjects.
- Annex B — Approved sub-processors: name, role/service, location.
- Annex C — Technical and organizational measures (TOMs).
- Annex D — Standard Contractual Clauses / UK Addendum: selected modules and completed appendices.