Data Processing Addendum
Effective 2026-08-20. Version 1.2.0.
This Data Processing Addendum ("DPA") forms part of the Terms of Service between CompanyWRX, LLC ("Processor," "we") and the customer accepting them ("Controller," "you"). It applies where we process personal data on your behalf and you are subject to the GDPR, the UK GDPR, the Swiss FADP, the CCPA/CPRA, or a comparable law.
No signature is required — this DPA is incorporated automatically when it applies. If your procurement process requires a countersigned copy, email privacy@companywrx.com and we will sign one.
1. Definitions
"Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Sub-processor" and "Supervisory Authority" have the meanings in the GDPR. "Business," "Service Provider," "Consumer," "Sell" and "Share" have the meanings in the CCPA/CPRA. "Customer Personal Data" means Personal Data within Customer Data.
2. Roles
You are the Controller (and Business). We are the Processor (and Service Provider). You are responsible for the lawfulness of the Personal Data you provide and of your instructions, including having a lawful basis, giving required notices, and obtaining required consents.
3. Scope of processing
Subject matter: provision of the Services. Duration: the term of the agreement, plus the retention periods in the Privacy Policy. Nature and purpose: hosting, storage, transmission, analysis, AI-assisted generation, messaging delivery, and support — as needed to provide the Services. Types of Personal Data: varies by product — typically names, email addresses, telephone numbers, postal and service addresses, job and appointment records, employment and candidate information, interview transcripts and recordings, voice recordings and device telemetry, and usage and log data. Categories of Data Subjects: your Authorized Users, your End Customers, job candidates, your employees, and household members where a Service operates in a home.
4. Our obligations
We will:
- (a) process Customer Personal Data only on your documented instructions — this DPA, the Terms, and your configuration and use of the Services constitute those instructions — except where law requires otherwise, in which case we will tell you first unless the law forbids it;
- (b) never sell or share Customer Personal Data, never retain, use or disclose it for any purpose other than performing the Services, and never combine it with data from another source except as permitted by the CCPA/CPRA;
- (c) never use Customer Personal Data to train general-purpose AI models, and contract with AI subprocessors on terms prohibiting them from doing so;
- (d) ensure personnel with access are bound by confidentiality and are trained;
- (e) implement the technical and organisational measures in Annex A;
- (f) tell you promptly if we believe an instruction infringes data protection law;
- (g) assist you, taking into account the nature of processing, with Data Subject requests (Section 6), security (Article 32), breach notification (Articles 33–34), data protection impact assessments and prior consultation (Articles 35–36); and
- (h) make available the information reasonably necessary to demonstrate compliance, and submit to audits under Section 8.
5. Sub-processors
General authorisation. You authorise us to engage the Sub-processors listed at Subprocessors.
We impose data protection obligations on each Sub-processor that are no less protective than this DPA, and we remain fully liable to you for a Sub-processor's performance.
Changes. We give at least 30 days' notice before adding a Sub-processor that processes Customer Personal Data. You may object on reasonable data protection grounds within that period; if we cannot accommodate you, you may terminate the affected subscription and receive a refund of prepaid, unused fees.
6. Data Subject rights
Taking into account the nature of processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to Data Subject requests. Where a Data Subject contacts us directly about data we process for you, we will not respond substantively — we will refer them to you and notify you promptly.
7. Security incidents
We will notify you without undue delay and within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, describing its nature, the categories and approximate number of Data Subjects and records affected, likely consequences, and the measures taken or proposed. We will provide reasonable cooperation with your own notification obligations. Our notification is not an admission of fault or liability.
8. Audits
On reasonable written notice, no more than once every 12 months (unless a Supervisory Authority requires more or a Personal Data Breach has occurred), we will make available information necessary to demonstrate compliance and will respond to a reasonable security questionnaire. Where an on-site audit is genuinely required by law, it must be conducted during business hours, without unreasonably disrupting our operations, under confidentiality, by an independent auditor who is not our competitor, and at your cost.
9. International transfers
Where Customer Personal Data is transferred from the EEA, the UK or Switzerland to a country without an adequacy decision, the parties incorporate the European Commission Standard Contractual Clauses (Decision 2021/914), which apply as follows:
- Module Two (Controller to Processor) applies where you are a controller; Module Three (Processor to Processor) applies where you are yourself a processor.
- Clause 7 (docking) — applies.
- Clause 9 — Option 2, general written authorisation, with the 30-day notice period in Section 5.
- Clause 11 — the optional independent dispute resolution body — does not apply.
- Clause 17 — governed by the law of Ireland.
- Clause 18(b) — forum: the courts of Ireland.
- Annex I is populated by Sections 2 and 3 of this DPA and the contact details below; Annex II is Annex A below; Annex III is the Subprocessors page.
- For UK transfers, the UK International Data Transfer Addendum (version B1.0) applies to the SCCs, with Tables 1–4 populated by this DPA and "Importer" and "Exporter" ending the Addendum as permitted.
- For Swiss transfers, references to the GDPR are read as references to the FADP, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
10. Deletion and return
On termination we will, at your choice, return or delete Customer Personal Data in accordance with Section 9.5 of the Terms (90 days to export, then deletion), except where law requires retention and except for routine encrypted backups until they expire on their normal cycle. Data in backups remains protected by this DPA until deleted.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in Section 21 of the Terms, except where applicable data protection law does not permit that limitation.
12. Precedence
This DPA governs over the Terms on the subject of processing Personal Data. The Standard Contractual Clauses govern over this DPA where they conflict.
Annex A — Technical and organisational measures
| Area | Measure |
|---|---|
| Encryption | TLS 1.2+ in transit; encryption at rest for databases and backups |
| Access control | Least privilege; per-service isolated system accounts; no shared admin credentials; MFA on administrative access |
| Process isolation | Each service runs as its own non-root system user with NoNewPrivileges, PrivateTmp and ProtectSystem=strict |
| Network | Host firewall; databases bound to loopback or private network; no public database exposure |
| Monitoring | Automated indicator-of-compromise monitoring with alerting; fail2ban on SSH and web endpoints; centralised logging |
| Vulnerability management | Routine OS and dependency patching; prompt remediation of known-exploited vulnerabilities |
| Backups | Nightly encrypted database backups, replicated off-host; restore tested |
| Secrets | Credentials stored outside source control, file-permission restricted, rotated on personnel change or suspected exposure |
| Personnel | Confidentiality obligations; access removed on departure |
| Incident response | Documented procedure; 72-hour customer notification commitment |
| Deletion | Documented retention schedule; deletion on the timetable in Section 10 |
Contact
CompanyWRX, LLC Data protection contact: privacy@companywrx.com Security: security@companywrx.com
Version 1.2.0 — effective 2026-08-20.
