If a Customer requires this DPA as a signed document, write to legal@recruitsphere.space and we will counter-sign the substantive form below. For convenience, this online version is binding by reference from our Terms of Service.
1. Roles
The Customer is a data fiduciary under the Digital Personal Data Protection Act, 2023 (or controller under the GDPR, where applicable) for the personal data it submits to the Platform. Darwix AI Technologies is a data processor acting on the Customer's documented instructions.
2. Subject matter, duration, nature, and purpose
| Subject matter | Processing of candidate and recruiter personal data in connection with the Customer's use of RecruitSphere. |
|---|---|
| Duration | The term of the Customer's subscription or pilot, plus any post-termination retention described in the Privacy Policy. |
| Nature and purpose | Hosting, indexing, AI screening, AI-assisted interviewing, assessment grading, communication, scheduling, analytics, audit, and support. |
| Types of personal data | Identification and contact data, work history, education, skills, application content, interview responses (text, audio, video), assessment submissions, scheduling data, communications metadata, and product telemetry. |
| Categories of data subjects | Candidates applying to the Customer, recruiters, hiring managers, interviewers, and other Authorised Users. |
3. Customer instructions
We process personal data only on the Customer's documented instructions, including those given through Platform settings and configuration. The Terms of Service, this DPA, and any signed order form constitute the Customer's initial documented instructions. If we believe an instruction violates applicable data protection law, we will inform the Customer.
4. Confidentiality
We ensure that personnel authorised to process personal data are bound by written confidentiality obligations and receive data-protection training appropriate to their role.
5. Security
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, scoped role-based access, audited admin operations, secret and key management, vulnerability scanning, and a documented incident response process. A current overview lives at /security.
6. Subprocessors
The Customer authorises us to engage subprocessors to process personal data. The current set is described at /subprocessors, and the named list is available to the Customer on request. We will:
- Impose data protection obligations on each subprocessor that are no less protective than this DPA.
- Notify Customers at least 15 days before adding or replacing a subprocessor that processes Customer personal data.
- Remain responsible for each subprocessor's performance of its obligations.
A Customer may object to a new subprocessor on reasonable data protection grounds by writing to privacy@recruitsphere.space. If we cannot resolve the objection, the Customer may terminate the affected subscription on a pro-rata basis.
7. Assistance with data subject requests
The Platform provides tools that let a Customer access, export, correct, and delete personal data inside its workspace. We will also assist the Customer, taking into account the nature of the processing, in responding to requests from data subjects to exercise their rights, including access, correction, erasure, objection, and portability. Where a data subject contacts us directly about Customer Data, we will redirect them to the Customer.
8. Personal data breach notification
We will notify the affected Customer without undue delay, and not later than 72 hours, after becoming aware of a personal data breach that affects the Customer's personal data. The notification will describe the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
9. DPIAs and prior consultation
We will provide reasonable assistance to the Customer in conducting data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to us.
10. Audit
We will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA. Once per calendar year and at the Customer's expense, the Customer or its qualified auditor (under written confidentiality) may inspect our compliance with this DPA, subject to reasonable scope, notice, and security requirements.
11. International transfers
Where personal data is transferred outside India, we rely on the cross-border transfer mechanisms permitted under the DPDP Act, and on Standard Contractual Clauses where the GDPR applies. The current list of transfer destinations is reflected in the subprocessor list at /subprocessors.
12. Return and deletion
On termination, we will, at the Customer's choice, delete or return the Customer's personal data, and delete existing copies, unless retention is required by law. Default deletion of production data occurs within 30 days of termination. Backups are cycled out within 90 days.
13. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. Caps apply on an aggregate basis to claims under the Terms and this DPA combined.
14. Conflict
In case of conflict between this DPA and the Terms of Service, this DPA governs in relation to processing of personal data. Conflict between this DPA and a signed Customer-specific DPA is resolved in favour of the signed Customer-specific DPA.
Reach our legal and privacy team at legal@recruitsphere.space. For data protection and DPDP Act requests, write to grievance@recruitsphere.space.