Data Processing Agreement (DPA)
Effective Date: May 1, 2026
Last Updated: May 1, 2026
This Data Processing Agreement ("DPA") governs how JivaHire processes personal data on behalf of customers using the JivaHire Candidate Hub platform. This DPA applies to all customers but is mandatory for those subject to GDPR, UK GDPR, CCPA, and India's privacy framework.
1. Parties & Roles
- Data Controller (You): The organization and recruiters using the Service
- Data Processor (JivaHire): We process personal data per your instructions
- Sub-Processors: AWS, SendGrid, OpenRouter, Cloudflare, Candidate Hub (process data on our behalf with same protections)
2. Processing Scope
2.1 What Data We Process
- Recruiter accounts: Email, name, profile, authentication data
- Candidate data: Names, emails, resumes, video interviews, assessment results, application history
- Organization data: Company info, team members, job postings
- Activity logs: API calls, login attempts, feature usage, audit trails
2.2 Processing Purposes
- Provide the Service (candidate profile management, resume upload, interview participation)
- Apply AI/LLM models for profile analysis and interview scoring
- Maintain security and prevent fraud
- Comply with laws and respond to legal requests
- Service improvement (aggregate, de-identified analytics)
2.3 Processing Duration
- Active accounts: Retained while in use
- After deletion/inactivity: 2 years retention
- Data subject requests: We assist you in responding per applicable law (GDPR: 30 days, CCPA: 45 days)
2.4 Data Subjects
- Recruiters (employees of your organization)
- Candidates (external individuals)
- Organization admins and team members
3. Processor Obligations
3.1 Processing Only Per Instructions
We process personal data only as instructed by you via:
- Using the Service API and dashboard
- These Terms and Conditions, Privacy Policy, and DPA
- Written requests (support@jivahire.com)
3.2 Security Measures
We implement industry-standard controls:
- Encryption: HTTPS/TLS in transit; AES-256 at rest
- Authentication: JWT tokens, email verification, password hashing
- Access Controls: Role-based permissions, organization-level isolation
- Audit Logging: 2-year retention, immutable logs
- Monitoring: Real-time alerts, anomaly detection
- Testing: Annual penetration testing, monthly vulnerability scanning
- Personnel Security: Background checks, confidentiality agreements, training
- Incident Response: Breach notification within 24–48 hours
- Subprocessor Management: Contractual protections, 30-day notice of changes
3.3 Confidentiality
All personnel (employees, contractors, agents) processing personal data are bound by confidentiality and data protection obligations.
3.4 Sub-Processor Management
We ensure sub-processors provide equivalent protection:
- AWS: Infrastructure & storage; AWS DPA in effect
- SendGrid: Transactional email; SendGrid DPA in effect
- OpenRouter & LLMs: AI/LLM services; OpenRouter Terms + LLM provider terms
- Cloudflare: Bot protection; Cloudflare DPA in effect
- Candidate Hub: Candidate data storage; internal DPA
When adding/replacing a sub-processor, we provide 30 days' notice and allow objection.
3.5 Data Subject Rights Support
We assist you in responding to data subject requests for:
- Access: Provide data in portable format (JSON, CSV) within 5 business days
- Rectification: Facilitate data updates
- Erasure: Delete data and backups within 30 days (subject to legal holds)
- Portability: Export structured, portable data
- Restriction: Flag data for restricted processing
- Objection: Cease processing for specified purposes
4. Data Breaches
If we discover a confirmed data breach:
1. Notification: We notify you without undue delay (target: 24–48 hours)
2. Details: Nature of breach, data affected, number of individuals, mitigation
3. Assistance: We provide information needed for you to notify data subjects and authorities
4. Investigation: We preserve evidence, conduct forensics, provide logs
5. Remediation: We contain the breach and prevent recurrence
5. Data Protection by Design
5.1 Privacy Principles
- Data minimization: Collect only necessary personal data
- Purpose limitation: Restrict processing to stated purposes
- Pseudonymization: Remove identifiers where feasible for analytics
- Encryption: Sensitive data encrypted in transit and at rest
- Access controls: Organization-scoped isolation, role-based permissions
5.2 Opt-in for Non-Essential Features
- LLM features (question generation, scoring) are opt-in
- You control automation level; we can disable features on request
- We maintain records of your feature selections
6. International Data Transfers
6.1 Mechanisms
EU/EEA to USA:
- EU Standard Contractual Clauses (SCCs, Module Two) incorporated in this DPA
- Supplementary safeguards per Section 3.2 (encryption, access controls, monitoring)
UK to Third Countries:
- UK SCCs or adequacy decisions where applicable
India:
- India Privacy Rules compliance; data processing minimized; consent obtained
6.2 Your Responsibility
You remain responsible for ensuring lawful basis for transferring personal data (e.g., obtaining consent, valid legitimate interest, necessity for contract).
6.3 Monitoring Safeguards
We monitor US government access risks (per Schrems II) and escalate concerns to you if safeguards fail. If transfers become impermissible, we will notify you and work on lawful alternatives.
7. GDPR/CCPA/India Compliance
7.1 GDPR (EU/EEA & UK)
- We comply with Article 28 (Processor obligations)
- Data subject rights support per Article 15–22
- Security per Article 32
- Breach notification per Article 33–34
- Standard Contractual Clauses per Article 46
- International transfers permitted per SCCs
7.2 CCPA/CPRA (California)
- We do not sell or share personal data (no third-party selling, no marketing)
- We support data subject rights: access, deletion, correction, opt-in
- We do not discriminate for exercising CCPA rights
- We maintain subprocessor list (Appendix A)
7.3 India Privacy Framework
- We implement reasonable security practices per IT Rules, 2011
- We comply with emerging digital personal data protection law
- Data processing minimized; consent obtained
- Sensitive personal information encrypted
8. Audit & Compliance
8.1 Your Right to Audit
- You (or your appointed auditor) may audit our compliance with this DPA
- We provide evidence of compliance: SOC 2 reports, AWS audit certifications, penetration test results, incident logs
- We remediate findings within 30 days
- Audits limited to once per year (additional audits at your cost)
8.2 Our Compliance Status
- SOC 2 Type II: Target 2026 Q3
- ISO 27001: Target 2027 Q1
- Penetration Testing: Annual; last conducted [date]
- Vulnerability Scanning: Monthly; critical patches within 7 days
9. Data Return & Deletion
9.1 Upon Termination
- You may request data export within 30 days
- We provide data in portable format (JSON, CSV) within 15 business days
- We delete all personal data (except legally required retention) within 30 days
- We provide written certification that deletion is complete
9.2 Backup Rotation
- Data in backups is overwritten per standard rotation (30–90 days)
- No obligation to delete data from backups during normal lifecycle
9.3 Legal Holds
- We may retain data longer if required by law (litigation, regulatory investigation, tax/employment records)
10. Liability & Indemnification
10.1 Data Protection Liability
JivaHire is liable for damages caused by:
- Unauthorized processing beyond your instructions
- Security failures resulting in breaches
- Failure to implement reasonable safeguards
- Unauthorized disclosure to sub-processors
- Failure to assist with data subject rights
- Failure to notify of breaches
Liability is subject to caps in Terms and Conditions Section 8.3, except:
- Data protection violations (subject to applicable law limits)
- Gross negligence or willful misconduct (unlimited)
- Breaches of confidentiality (unlimited)
10.2 Indemnification
JivaHire will indemnify you from claims, fines, and damages arising from:
- Our unauthorized processing of personal data
- Our security failures or breaches
- Our failure to comply with this DPA or data protection law
- Sub-processor failures (we remain liable to you)
11. Legal Requests & Government Access
11.1 Government & Legal Requests
If a court order, subpoena, warrant, or government request seeks personal data:
1. We will notify you without undue delay (unless legally prohibited)
2. We will challenge the request if unlawful or overly broad
3. We will disclose only the minimum necessary to comply
4. We will provide copies of the legal process
5. We will assist you in challenging or appealing
Exception: If legally prohibited from notifying you (e.g., criminal gag order), we notify you as soon as prohibition expires.
11.2 Regulatory Authority Cooperation
Data protection authorities (ICO, CNIL, etc.) may conduct inspections or audits:
- We comply with inspection requests and provide documentation
- We notify you of authority inspections/requests (unless legally prohibited)
12. Term & Termination
12.1 Duration
This DPA is effective on your Service agreement date and continues through the subscription term.
12.2 Termination
This DPA terminates automatically upon:
- Service agreement termination
- Subscription expiration without renewal
- Either party's 30 days' written notice
12.3 Survival
Data protection obligations continue during the 2-year retention period after termination. Sections on Confidentiality, Liability, Indemnification, Dispute Resolution, and Governing Law survive.
13. Governing Law & Disputes
13.1 Governing Law
This DPA is governed by the laws of the United States (State of Delaware) and India (for data processing compliance), without regard to conflicts of law.
13.2 Dispute Resolution
Disputes regarding data protection are resolved per Terms and Conditions Section 14 (binding arbitration or litigation).
13.3 Conflict
If this DPA conflicts with the Terms and Conditions or Privacy Policy, this DPA takes precedence on data protection matters.
14. EU Standard Contractual Clauses (SCCs)
14.1 Incorporation
This DPA incorporates by reference the EU Standard Contractual Clauses (Module Two: Controller to Processor) as approved by EU Commission Implementing Decision (EU) 2021/914.
14.2 Parties
- Data Exporter: You (EU/EEA/UK organization or recruiter)
- Data Importer: JivaHire (USA-based processor)
14.3 Competent Authority
- Data Subject Rights: Per GDPR Articles 15–22
- Complaints: Your national data protection authority (EU DPA, ICO for UK, etc.)
14.4 Sub-Processors
Sub-processors listed in Appendix A are authorized and provide equivalent protection (via sub-DPAs or SCCs). You are notified 30 days in advance of changes and may object.
15. Appendix A: Sub-Processors & Contacts
| Sub-Processor | Purpose | Data Shared | Location | DPA |
|---|---|---|---|---|
| AWS | Infrastructure, storage, CDN | All personal data | US-East-1 (primary); US-West, EU-West (backups) | AWS DPA |
| SendGrid | Transactional email | Email addresses, names, interview details | US | SendGrid DPA |
| OpenRouter & LLM Providers | AI/LLM services (questions, scoring, matching) | Job descriptions, candidate profiles, resumes, interview responses | Provider-specific | OpenRouter ToS + Provider ToS |
| Cloudflare Turnstile | Bot protection | IP address, device fingerprint | Global CDN | Cloudflare DPA |
| Candidate Hub | Candidate profiles, resumes, talent search | Candidate email, resume, work history, skills, activity logs | TBD | Internal DPA |
16. Entire Agreement
This DPA, together with:
- Terms and Conditions
- Privacy Policy
- Subscription Agreement
constitute the entire agreement on data processing.
End of Data Processing Agreement
Next Steps for Implementation
- Review & Legal: Have your legal counsel review this DPA
- Customize Contacts: Update emails and locations (currently placeholder)
- Obtain SOC 2 / ISO 27001: Pursue certifications for credibility
- Communicate to Customers: Share DPA with existing and new customers; include in contracts
- Monitor Compliance: Track retention dates, subprocessor changes, breach response
- Annual Review: Update DPA annually or when material changes occur