Data Processing Addendum (DPA)
Last updated: June 27, 2026 · version 2026-06-27
This Data Processing Addendum ("DPA") forms part of the Terms of Use between Personally LLC ("Personally," "Processor") and the employer customer ("Customer," "Controller") and applies where Personally processes personal data on the Customer's behalf in providing the Service. Terms not defined here have the meaning given in the GDPR.
1. Roles & scope
For candidate personal data submitted to the Customer's requisitions, the Customer is the Controller and Personally is the Processor. Personally processes such data only on the Customer's documented instructions, as set out in the Terms, this DPA, and the Customer's use of the Service.
2. Subject matter, duration, nature & purpose
- Subject matter / nature & purpose: hosting, screening, scheduling, and recruitment-transparency processing to provide the Service.
- Duration:for the term of the Customer's subscription, plus the limited retention described below.
- Categories of data subjects:job seekers/candidates and the Customer's hiring users.
- Categories of personal data: identity and contact details, résumé references, questionnaire answers, scheduling data, and interview notes. Special-category data is not requested or intended.
3. Processor obligations (Art. 28(3))
- Process personal data only on documented instructions, including for transfers.
- Ensure persons authorised to process are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Section 5).
- Respect the conditions for engaging sub-processors (Section 4).
- Assist the Controller, by appropriate measures, to respond to data-subject requests (Section 6).
- Assist with security, breach notification, and data-protection impact assessments.
- Delete or return personal data at the end of the engagement (Section 7).
- Make available information necessary to demonstrate compliance and allow for audits.
4. Sub-processors
The Customer authorises Personally to engage sub-processors to provide the Service. Personally imposes data-protection terms on each sub-processor equivalent to those in this DPA and remains liable for their performance. Current categories of sub-processors include:
- Cloud hosting & database infrastructure (Vercel, Neon)
- File storage for candidate résumé uploads (Vercel Blob)
- Email delivery (Resend)
- Calendar / scheduling integration (e.g. Calendly or Google/Microsoft Calendar)
- Video conferencing for booked calls (e.g. Whereby) — planned
- Human-verification (reCAPTCHA)
- Payment processing (Stripe)
- HR/talent-system sync (e.g. Workday, Greenhouse)
Personally will give the Customer reasonable notice of new sub-processors and an opportunity to object on reasonable data-protection grounds.
5. Security measures (Art. 32)
- Passwords stored only as salted hashes; encrypted transport (HTTPS/TLS).
- Masked relay emails so recruiters' real addresses are not exposed.
- Access controls and least-privilege administration.
- An immutable compliance audit trail for requisition publishing.
- Regular review of technical and organisational measures.
6. Data-subject requests
Taking into account the nature of the processing, Personally assists the Controller with appropriate technical and organisational measures to fulfil data-subject requests (access, rectification, erasure, restriction, portability, and objection). The Service includes self-service deletion and consent controls that support these rights.
7. International transfers
Where personal data is transferred outside the EEA/UK (including to the United States), the parties rely on the European Commission's Standard Contractual Clauses and/or the EU-US Data Privacy Framework, with any supplementary measures required by law. The SCCs are incorporated by reference and take precedence in the event of conflict.
8. Breach notification
Personally will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, with information reasonably available to assist the Controller's own obligations under Articles 33-34.
9. Return & deletion
On termination, Personally will, at the Controller's choice, delete or return the personal data and delete existing copies, except where retention is required by law.
10. Contact
To execute this DPA or request the SCCs and sub-processor list, contact contact@personallyhired.com.