Skip to content
CompanyWRX

Data Processing Addendum

Effective 2026-08-20. Version 1.2.0.

This Data Processing Addendum ("DPA") forms part of the Terms of Service between CompanyWRX, LLC ("Processor," "we") and the customer accepting them ("Controller," "you"). It applies where we process personal data on your behalf and you are subject to the GDPR, the UK GDPR, the Swiss FADP, the CCPA/CPRA, or a comparable law.

No signature is required — this DPA is incorporated automatically when it applies. If your procurement process requires a countersigned copy, email privacy@companywrx.com and we will sign one.


1. Definitions

"Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Sub-processor" and "Supervisory Authority" have the meanings in the GDPR. "Business," "Service Provider," "Consumer," "Sell" and "Share" have the meanings in the CCPA/CPRA. "Customer Personal Data" means Personal Data within Customer Data.

2. Roles

You are the Controller (and Business). We are the Processor (and Service Provider). You are responsible for the lawfulness of the Personal Data you provide and of your instructions, including having a lawful basis, giving required notices, and obtaining required consents.

3. Scope of processing

Subject matter: provision of the Services. Duration: the term of the agreement, plus the retention periods in the Privacy Policy. Nature and purpose: hosting, storage, transmission, analysis, AI-assisted generation, messaging delivery, and support — as needed to provide the Services. Types of Personal Data: varies by product — typically names, email addresses, telephone numbers, postal and service addresses, job and appointment records, employment and candidate information, interview transcripts and recordings, voice recordings and device telemetry, and usage and log data. Categories of Data Subjects: your Authorized Users, your End Customers, job candidates, your employees, and household members where a Service operates in a home.

4. Our obligations

We will:

  • (a) process Customer Personal Data only on your documented instructions — this DPA, the Terms, and your configuration and use of the Services constitute those instructions — except where law requires otherwise, in which case we will tell you first unless the law forbids it;
  • (b) never sell or share Customer Personal Data, never retain, use or disclose it for any purpose other than performing the Services, and never combine it with data from another source except as permitted by the CCPA/CPRA;
  • (c) never use Customer Personal Data to train general-purpose AI models, and contract with AI subprocessors on terms prohibiting them from doing so;
  • (d) ensure personnel with access are bound by confidentiality and are trained;
  • (e) implement the technical and organisational measures in Annex A;
  • (f) tell you promptly if we believe an instruction infringes data protection law;
  • (g) assist you, taking into account the nature of processing, with Data Subject requests (Section 6), security (Article 32), breach notification (Articles 33–34), data protection impact assessments and prior consultation (Articles 35–36); and
  • (h) make available the information reasonably necessary to demonstrate compliance, and submit to audits under Section 8.

5. Sub-processors

General authorisation. You authorise us to engage the Sub-processors listed at Subprocessors.

We impose data protection obligations on each Sub-processor that are no less protective than this DPA, and we remain fully liable to you for a Sub-processor's performance.

Changes. We give at least 30 days' notice before adding a Sub-processor that processes Customer Personal Data. You may object on reasonable data protection grounds within that period; if we cannot accommodate you, you may terminate the affected subscription and receive a refund of prepaid, unused fees.

6. Data Subject rights

Taking into account the nature of processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to Data Subject requests. Where a Data Subject contacts us directly about data we process for you, we will not respond substantively — we will refer them to you and notify you promptly.

7. Security incidents

We will notify you without undue delay and within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, describing its nature, the categories and approximate number of Data Subjects and records affected, likely consequences, and the measures taken or proposed. We will provide reasonable cooperation with your own notification obligations. Our notification is not an admission of fault or liability.

8. Audits

On reasonable written notice, no more than once every 12 months (unless a Supervisory Authority requires more or a Personal Data Breach has occurred), we will make available information necessary to demonstrate compliance and will respond to a reasonable security questionnaire. Where an on-site audit is genuinely required by law, it must be conducted during business hours, without unreasonably disrupting our operations, under confidentiality, by an independent auditor who is not our competitor, and at your cost.

9. International transfers

Where Customer Personal Data is transferred from the EEA, the UK or Switzerland to a country without an adequacy decision, the parties incorporate the European Commission Standard Contractual Clauses (Decision 2021/914), which apply as follows:

  • Module Two (Controller to Processor) applies where you are a controller; Module Three (Processor to Processor) applies where you are yourself a processor.
  • Clause 7 (docking) — applies.
  • Clause 9 — Option 2, general written authorisation, with the 30-day notice period in Section 5.
  • Clause 11 — the optional independent dispute resolution body — does not apply.
  • Clause 17 — governed by the law of Ireland.
  • Clause 18(b) — forum: the courts of Ireland.
  • Annex I is populated by Sections 2 and 3 of this DPA and the contact details below; Annex II is Annex A below; Annex III is the Subprocessors page.
  • For UK transfers, the UK International Data Transfer Addendum (version B1.0) applies to the SCCs, with Tables 1–4 populated by this DPA and "Importer" and "Exporter" ending the Addendum as permitted.
  • For Swiss transfers, references to the GDPR are read as references to the FADP, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.

10. Deletion and return

On termination we will, at your choice, return or delete Customer Personal Data in accordance with Section 9.5 of the Terms (90 days to export, then deletion), except where law requires retention and except for routine encrypted backups until they expire on their normal cycle. Data in backups remains protected by this DPA until deleted.

11. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in Section 21 of the Terms, except where applicable data protection law does not permit that limitation.

12. Precedence

This DPA governs over the Terms on the subject of processing Personal Data. The Standard Contractual Clauses govern over this DPA where they conflict.


Annex A — Technical and organisational measures


Contact

CompanyWRX, LLC Data protection contact: privacy@companywrx.com Security: security@companywrx.com

Version 1.2.0 — effective 2026-08-20.