This Data Processing Addendum ("DPA") applies where DIGYUG LLP ("Processor", operating TooHR) processes personal data on behalf of a customer ("Fiduciary", the recruitment/staffing agency) under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). It forms part of, and is governed by, the Terms of Service between the parties.
1. Roles
For candidate, client-contact and related records the Fiduciary enters into the Service ("Customer Data"), the Fiduciary is the Data Fiduciary and determines the purposes and means of processing. The Processor processes Customer Data only on the Fiduciary's documented instructions (which include using the Service as intended and this DPA), and not for its own purposes.
2. Scope and duration
The subject matter is the provision of the Service; the duration is the term of the Terms of Service. The nature and purpose of processing is recruitment-workflow management; the categories of data principals are candidates and client contacts; the categories of personal data are those described in the Privacy Policy.
3. Processor obligations
- Process Customer Data only on the Fiduciary's documented instructions, including as to transfers, unless required by law (in which case it will inform the Fiduciary where permitted).
- Ensure persons authorised to process Customer Data are bound by confidentiality.
- Implement reasonable technical and organisational security safeguards (tenant isolation, role-based access, encryption in transit, private file storage, rate limiting).
- Not engage another processor (sub-processor) except as listed below, and remain responsible for sub-processors' compliance.
- Assist the Fiduciary, taking into account the nature of processing, to respond to Data Principal requests (access, correction, erasure, grievance, nomination) via the Service's tooling and reasonable support.
- Assist the Fiduciary in meeting its security and breach-notification obligations.
- On termination, at the Fiduciary's choice, delete or return Customer Data, save where retention is required by law.
- Make available information reasonably necessary to demonstrate compliance.
4. Sub-processors
The Processor uses the following sub-processors to deliver the Service:
- Cloud hosting (infrastructure) — India.
- Transactional email delivery.
- Razorpay Software Private Limited — payments — India.
- IP-based country lookup — used only to present regional pricing.
The Processor will give the Fiduciary notice of any intended change to sub-processors, and the Fiduciary may object on reasonable data-protection grounds.
5. Personal-data breach
The Processor will notify the Fiduciary without undue delay after becoming aware of a personal-data breach affecting Customer Data, and provide information reasonably available to help the Fiduciary meet its obligations to the Data Protection Board of India and affected Data Principals.
6. Data Principal requests
If the Processor receives a request from a Data Principal relating to Customer Data, it will, unless legally required to respond, direct the request to the Fiduciary and assist the Fiduciary in responding.
7. Deletion and return
On expiry or termination, the Processor will delete Customer Data within a reasonable period, except copies required to be retained by law, and will delete uploaded files from storage.
8. International transfers
The Processor stores Customer Data in India and will not transfer it to any territory restricted by the Central Government under the DPDP Act.
9. Precedence
In the event of a conflict between this DPA and the Terms of Service on the subject of data protection, this DPA prevails.
Questions about this DPA: support@toohr.com.