Data Processing Addendum
This DPA template describes the controller/processor relationship for personal data a customer puts into GrowthPPL. It supplements the Terms of Service and is pending counsel review before it is offered as a signable document.
Roles
For candidate and employee data, the customer is the controller and GrowthPPL is the processor. We process such data only on the customer's documented instructions (i.e. their use of the product).
Sub-processors
We use the sub-processors listed in the Privacy Policy. We impose data-protection obligations on them and give customers notice of changes so they can object.
Security measures
Tenant isolation via tenant-scoped queries in the application layer; bcrypt password hashing; encryption in transit (TLS); least-privilege access; soft-delete with purge-on-request. We will describe additional measures as we add them rather than claim them prematurely.
Personal-data breaches
We will notify affected customers without undue delay after becoming aware of a personal-data breach affecting their data, with the information they need to meet their own obligations.
Data-subject requests & deletion
We assist customers in responding to access, correction, export and deletion requests. On termination we delete or return the customer's personal data, subject to legal retention requirements.