Legal

Data Processing Agreement

Provisional. Not yet in effect.

Effective date: not yet in effect

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Repoify entity ("Repoify", "Processor") and the Customer ("Controller"). Where they conflict, this DPA controls for the processing of Customer Personal Data.

1. Definitions

"Data Protection Laws" means all laws applicable to the processing of personal data under this DPA. Repoify is a US-only service (see the Terms), so this means US federal and state law. Should either party become subject to a non-US regime, the parties will negotiate an addendum before that processing begins.

"Customer Personal Data" means personal data that Repoify processes on behalf of the Customer under the Terms.

"Controller", "processor", "data subject", "personal data", "processing", "personal data breach", and "supervisory authority" have the meanings given in the GDPR. "Business", "service provider", "sale", and "share" have the meanings given in the CCPA/CPRA.

2. Roles, and the important limit on this DPA

Customer is the controller and Repoify is the processor for Customer Personal Data, which comprises: candidate notes, pipeline stages, custom fields, outreach content, and any information the Customer uploads or creates about an individual within its workspace.

This DPA does not cover developer profile information that Repoify collects from public sources. For that processing Repoify is an independent controller, and it is governed by the Privacy Policy rather than by this DPA. The two categories are described in Section 4 of that policy.

Each party is independently responsible for compliance with Data Protection Laws applicable to it in its own role.

3. Processing details

Subject matter: provision of the Service. Duration: the term of the Terms, plus the deletion period in Section 11. Nature and purpose: hosting, storage, analysis, transmission of outreach, and related functions necessary to provide the Service. Categories of data subject: Customer personnel, and candidates the Customer manages in its workspace. Categories of personal data: name, professional contact details, employment and skills information, communication content, pipeline status, and notes. Special categories: none are required or requested. The Customer must not upload special category data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, sex life, or sexual orientation) or criminal offence data into the Service.

4. Customer obligations

The Customer:

  1. Is responsible for the lawfulness, accuracy, and provenance of Customer Personal Data, and for having a valid lawful basis for the processing it instructs;
  2. Warrants that it has provided all required notices and obtained all required consents;
  3. Is responsible for its own compliance with anti-spam, employment, and anti-discrimination law, as set out in the Acceptable Use Policy;
  4. Will not instruct processing that would cause either party to breach Data Protection Laws.

5. Repoify's obligations

Repoify will:

  1. Process Customer Personal Data only on the Customer's documented instructions, which comprise the Terms, this DPA, and use of the Service's features, unless required otherwise by law, in which case it will inform the Customer unless legally prohibited;
  2. Not sell or share Customer Personal Data as those terms are defined by the CCPA/CPRA, and not retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by Data Protection Laws;
  3. Not combine Customer Personal Data with personal data received from other sources, except as permitted for a service provider under the CCPA/CPRA;
  4. Ensure personnel authorized to process are bound by confidentiality;
  5. Implement the technical and organizational measures in Annex A;
  6. Assist the Customer, taking into account the nature of processing, with data subject requests, data protection impact assessments, and consultations with supervisory authorities;
  7. Make available information reasonably necessary to demonstrate compliance.

6. Subprocessors

The Customer grants general authorization for Repoify to engage subprocessors. A current list naming each subprocessor is available to the Customer on request at dev@repoify.com.

Repoify will give the Customer at least thirty (30) days' notice, in writing, before adding a subprocessor that processes Customer Personal Data. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Service without penalty and receive a pro-rata refund of prepaid fees.

Repoify imposes data protection obligations on each subprocessor no less protective than this DPA, and remains liable for its subprocessors' acts and omissions.

7. Data subject requests

Repoify will, to the extent legally permitted, promptly notify the Customer if it receives a request from a data subject relating to Customer Personal Data, and will not respond to that request itself except to direct the data subject to the Customer. Repoify will provide reasonable assistance, using the Service's self-service features where available.

8. Personal data breach

Repoify will notify the Customer without undue delay, and in any event within seventy-two (72) hours, of becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point, to the extent known. Repoify will provide reasonable cooperation with the Customer's notification obligations. Notification is not an acknowledgement of fault.

9. Data location

Repoify processes and stores Customer Personal Data in the United States, and the Service is offered only to US-based customers. No cross-border transfer mechanism is engaged.

If the Customer's use ever involves personal data of individuals outside the United States, the Customer must tell us before that processing begins, so the parties can put an appropriate transfer mechanism in place. Do not sign first and paper it afterwards.

10. Audit

Repoify will make available information necessary to demonstrate compliance, and will contribute to audits conducted by the Customer or an independent auditor mandated by it. Audits are limited to once per twelve (12) months unless required by a supervisory authority or following a personal data breach, must be on at least thirty (30) days' written notice, during business hours, subject to confidentiality, and must not unreasonably disrupt operations. Repoify may satisfy an audit request by providing a current third-party audit report or completed security questionnaire where one is available.

11. Deletion and return

On termination, Repoify will delete Customer Personal Data within ninety (90) days, or return it on the Customer's written request made within thirty (30) days of termination. Repoify may retain data where required by law, and will continue to protect it for as long as it is retained. Backup copies are deleted on the ordinary backup cycle.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms.

13. Term

This DPA takes effect when the Customer accepts the Terms and continues until all Customer Personal Data is deleted or returned.


Annex A: Technical and organizational measures

Encryption. TLS for all data in transit. Encryption at rest for stored personal data. [[VERIFY: encryption at rest is a roadmap item]]

Access control. Role-based access. Least-privilege credentials. Access to production restricted to authorized personnel. Unique accounts, no shared credentials.

Authentication. Managed identity provider. Multi-factor authentication available for Customer accounts and required for administrative access.

Network and application security. Segregated production environment. Managed hosting with provider-level protections. Dependency and vulnerability monitoring.

Logging. Access and administrative actions are logged and retained for twelve (12) months. [[VERIFY: per-record access logging is a roadmap item]]

Data minimization. Only data necessary for the Service is collected. Retention limits are applied and enforced by scheduled deletion. [[VERIFY: the purge job is a roadmap item]]

Personnel. Confidentiality obligations for all personnel with access. Onboarding and offboarding procedures, including prompt access revocation.

Business continuity. Managed database backups with point-in-time recovery per the provider's standard offering.

Incident response. Documented plan covering detection, containment, assessment, notification, and remediation. [[VERIFY: roadmap item]]

Vendor management. Subprocessors are contracted with equivalent obligations, and a current list naming each of them is available to Customers on request.

Questions about this document: dev@repoify.com.