Draft template. This document describes how the product works today but has not yet been reviewed by legal counsel. It is not a binding agreement until finalised and, where relevant, signed.

Data Processing Addendum

Last updated 28 September 2026

This DPA template describes the controller/processor relationship for personal data a customer puts into GrowthPPL. It supplements the Terms of Service and is pending counsel review before it is offered as a signable document.

Roles

For candidate and employee data, the customer is the controller and GrowthPPL is the processor. We process such data only on the customer's documented instructions (i.e. their use of the product).

Sub-processors

We use the sub-processors listed in the Privacy Policy. We impose data-protection obligations on them and give customers notice of changes so they can object.

Security measures

Tenant isolation via tenant-scoped queries in the application layer; bcrypt password hashing; encryption in transit (TLS); least-privilege access; soft-delete with purge-on-request. We will describe additional measures as we add them rather than claim them prematurely.

Personal-data breaches

We will notify affected customers without undue delay after becoming aware of a personal-data breach affecting their data, with the information they need to meet their own obligations.

Data-subject requests & deletion

We assist customers in responding to access, correction, export and deletion requests. On termination we delete or return the customer's personal data, subject to legal retention requirements.