This DPA is drafted to satisfy GDPR Art. 28, the UK GDPR, the Swiss FADP, the CCPA/CPRA service-provider requirements (Cal. Civ. Code §1798.140(ag), regs §7051) and the processor obligations of India's DPDP Act 2023 (§8) and Rules 2025.
This Data Processing Agreement (DPA) is between the organisation that holds a HR Assist workspace (the Customer) and Axion Connect, Registered office address — to be confirmed (the Provider). It forms part of the Terms of Service and applies whenever the Provider processes personal data on the Customer's behalf.
1. Definitions
- Applicable Data Protection Law — the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, the CCPA/CPRA and other US state privacy laws, the DPDP Act 2023 and Rules, the IT Act 2000 and SPDI Rules 2011, and any other data-protection law that applies to the processing.
- Controller, Processor, Data Subject, Personal Data, Processing, Sub-processor, Supervisory Authority and Personal-Data Breach have the meanings in the GDPR; Business, Service Provider and Sell/Share those in the CCPA; Data Fiduciary, Data Processor and Data Principal those in the DPDP Act.
- Customer Personal Data — Personal Data in the Customer's workspace that the Provider processes on the Customer's behalf.
- Standard Contractual Clauses or SCCs — Commission Implementing Decision (EU) 2021/914, with the UK International Data Transfer Addendum and the Swiss amendments.
- DPF — the EU-US Data Privacy Framework, its UK Extension and the Swiss-US DPF.
2. Roles
The Customer is the controller / business / Data Fiduciary of Customer Personal Data; the Provider is its processor / service provider / Data Processor. Where the Provider processes data about the Customer's own users for its own purposes (account security, billing, acceptance records), it does so as an independent controller under its Privacy Policy.
3. Subject matter, duration, nature and purpose
| Subject matter | Personal data of candidates, workspace users and interviewers entered into or generated by the Service |
|---|---|
| Duration | The term of the Customer's subscription plus the deletion period in section 11 |
| Nature | Storage; parsing by AI models; scoring; transcription of interview audio; execution of candidate code in a sandbox; capture of proctoring evidence at the candidate's consent; delivery of email and WhatsApp messages; scheduling |
| Purpose | Provision of the Service to the Customer for its recruitment |
| Data subjects | Candidates and applicants; the Customer's employees and contractors; interviewers |
| Categories | Identity and contact data; résumé and employment history; interview recordings, transcripts and assessments; coding-test submissions and browser activity; biometric-derived evidence (webcam still frames) and audio clips where the Customer enables proctoring evidence; questionnaire answers; communications; consent records |
| Special categories | Biometric data (GDPR Art. 9) and sensitive personal information (CPRA) during a proctored test, processed on the candidate's explicit consent recorded in the test room; the Customer is responsible for confirming it can rely on that basis in each jurisdiction |
| Frequency | Continuous, on each interaction with the Service |
4. Instructions
The Provider processes Customer Personal Data only on the Customer's documented instructions, which are: the Terms, this DPA, the Customer's configuration of the Service, and the Customer's use of its features. Additional instructions require written agreement. The Provider will tell the Customer if it believes an instruction infringes Applicable Data Protection Law and may suspend the affected processing until it is resolved. The Provider will not sell, share, retain, use or disclose the data for any purpose other than performing the Service, nor combine it with data from other sources except as the Service requires, and certifies that it understands these restrictions (CPRA §1798.140(ag)(1); regs §7051).
5. Confidentiality
Persons authorised to process the data are bound by written confidentiality obligations and receive data-protection training. Access is limited to what their role requires and is logged; access is revoked on departure.
6. Security (GDPR Art. 32; DPDP §8(5); SPDI Rule 8)
The Provider maintains the technical and organisational measures in Annex II, which may be improved but not reduced below that baseline without notice. Details are available on request under NDA.
7. Sub-processors
The Customer gives general authorisation for the sub-processors listed at Sub-processors. The Provider will give at least fourteen days' notice of a new or replacement sub-processor by updating that page and notifying workspace administrators; the Customer may object on reasonable data-protection grounds within that period, in which case the parties will discuss in good faith and, failing agreement, the Customer may terminate the affected feature or the subscription without penalty for the unused period. The Provider imposes on each sub-processor written data-protection obligations no less protective than this DPA and remains liable for their performance. Where the Customer supplies its own keys for an AI, speech or meeting provider, that provider is the Customer's own processor, not a sub-processor.
8. Data subject requests
The Provider will forward to the Customer within five business days any request it receives from a data subject about Customer Personal Data, will not respond except to acknowledge and redirect, and will assist the Customer with tools and information to respond within the statutory period (one month under the GDPR; 45 days under the CCPA; the period the DPDP Rules prescribe). Deletion, export and the consent record are available to the Customer in the Service.
9. Assistance
Taking account of the nature of the processing, the Provider will assist the Customer with data-protection impact assessments (in particular for webcam proctoring and AI-assisted scoring), with prior consultation of a supervisory authority, with transfer impact assessments, and with the Customer's own security and breach obligations.
10. Personal-data breach
The Provider will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a personal-data breach affecting Customer Personal Data, giving the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken or proposed, so the Customer can make its own notifications (GDPR Art. 33 — 72 hours; DPDP §8(6) and Rules — the Data Protection Board and affected Data Principals; CCPA §1798.82; other US state laws). The Provider will then cooperate in investigation and remediation.
11. Return and deletion
On termination, or on the Customer's earlier instruction, the Provider at the Customer's option returns (by export) or deletes all Customer Personal Data within thirty days, except copies in backups (which expire automatically within thirty-five days) and records it must keep by law. The Customer can export its data at any time before termination. Deletion of a single candidate through the Service removes the candidate record and its derived records (evaluations, score audits, notes, interview schedules, WhatsApp messages, tasks and joining-risk answers); coding-test records, email threads and notifications lose their link to the candidate; a coding test the candidate claimed keeps the email address they entered until the Customer deletes that test.
12. Audit
The Provider makes available the information necessary to demonstrate compliance, including a completed security questionnaire on reasonable request, and, no more than once a year or after a breach, permits an audit by the Customer or an independent auditor bound by confidentiality, on thirty days' notice, during business hours, at the Customer's cost, in a manner that does not compromise other customers' data. Where an audit finds no material non-compliance the Customer reimburses the Provider's reasonable expenses.
13. International transfers
Where Customer Personal Data originating in the EEA, UK or Switzerland is transferred to a country without an adequacy decision, the parties enter into the SCCs (Module 2 controller-to-processor, or Module 3 where the Customer is itself a processor), which are incorporated by reference with the Customer as data exporter and the Provider as data importer, completed as Annex III sets out. Where a US sub-processor is DPF-certified the Provider may rely on the DPF for the onward transfer. Transfers of data originating in India are made in accordance with DPDP §16.
14. Specific provisions for proctoring and AI scoring
- The Provider provides, and the Customer will not disable or misrepresent, the in-room consent screen for proctored coding tests. The consent record (statements, version, time, IP, user agent) is stored with the test.
- The Customer is responsible for determining the lawful basis for biometric-derived processing in each jurisdiction where its candidates sit tests, and for not enabling evidence capture where none exists.
- The Provider's AI outputs are decision support. The Customer will ensure human review, will give candidates any pre-use notice the law requires (for example under NYC Local Law 144, the Illinois AIVIA, Colorado SB 24-205, the CPPA automated decision-making regulations or the EU AI Act for high-risk recruitment systems), and will not use the Service for emotion recognition.
- On request the Provider will supply the model, prompt-version and score-provenance information the Customer needs for a bias audit, an EU AI Act Article 13 information request, or an explanation to a candidate.
- Neither party will use Customer Personal Data to train or improve AI models; the Provider's model sub-processors are bound to the same.
15. Liability
Liability under this DPA is subject to the limitations in the Terms of Service, except that nothing limits liability to data subjects that cannot be limited by law (including under GDPR Art. 82).
16. Precedence
If this DPA conflicts with the Terms, the DPA prevails for the processing of personal data. If the SCCs conflict with this DPA, the SCCs prevail.
Annex I — Description of the processing
| Data exporter | The Customer (controller / business / Data Fiduciary) |
|---|---|
| Data importer | Axion Connect, Registered office address — to be confirmed (processor / service provider / Data Processor), contact privacy@axionconnect.com |
| Data subjects, categories, special categories, nature, purpose, duration, frequency | As in section 3 |
| Onward transfers | To the sub-processors on the Sub-processors page, for the purposes stated there |
| Competent supervisory authority | The authority of the Customer's main establishment in the EEA; the UK ICO for UK data; the Swiss FDPIC for Swiss data; otherwise as Applicable Data Protection Law designates |
Annex II — Technical and organisational measures
- Encryption in transit — TLS on every connection; HTTP strict transport security.
- Encryption at rest — stored provider credentials and OAuth tokens encrypted with a platform key; database and backups encrypted by the hosting provider.
- Tenant isolation — every query carries the workspace identifier; cross-workspace access is impossible by construction and tested.
- Access control — role-based access with least privilege; platform operators use multi-factor authentication and a separate console; administrative actions are logged.
- Candidate surfaces — coding tests bound to one device by a session secret; candidate code executed in an isolated sandbox with no network or filesystem access to the platform; face analysis performed on the candidate's device.
- Rate limiting and blocking — sign-in, registration and API endpoints rate-limited; IP blocking shared with the operator console.
- Change management — deployment from a reviewed branch with automated tests; dependency updates tracked.
- Backups — regular encrypted backups expiring within 35 days.
- Logging and monitoring — sign-in events and security events retained 12 months; alerting to platform operators.
- Personnel — written confidentiality, data-protection training, access revoked on departure.
- Incident response — a documented process with the 48-hour customer notification in section 10.
- Sub-processor management — written terms and transfer mechanisms for every sub-processor; annual review.
Annex III — Standard Contractual Clauses (Module 2 / Module 3)
Where the SCCs apply, the parties agree:
- Clause 7 (docking) applies.
- Clause 9(a): Option 2, general written authorisation, with the fourteen-day notice period in section 7.
- Clause 11: the optional independent dispute-resolution body is not selected.
- Clause 13: the competent supervisory authority is as in Annex I.
- Clause 17: the law of Ireland.
- Clause 18: the courts of Ireland.
- Annex I.A and I.B: as in Annex I of this DPA; Annex I.C: as in Annex I; Annex II: as in Annex II of this DPA; Annex III: the Sub-processors page.
- UK Addendum: incorporated, Tables 1–4 completed with the same content; the importer may end the Addendum under section 19 of it.
- Swiss transfers: the FDPIC is the competent authority, "Member State" includes Switzerland, and Swiss data subjects may enforce their rights in Switzerland.
Signatures
Where a signed copy is required, the Customer and the Provider sign below; otherwise the DPA takes effect on the Customer's acceptance of the Terms.
| For the Customer | For Axion Connect |
|---|---|
| Name: | Name: |
| Title: | Title: |
| Date: | Date: |
Questions about this document?
Write to privacy@axionconnect.com for anything about data and privacy, or support@axionconnect.com for the agreement itself. We reply within one working day.