LegalData Processing Agreement

Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the agreement between Eroforze Systems Private Limited (“Processor”) and the customer organisation that uses Edgeryt Hire (“Controller”). It applies when the Processor processes personal data on behalf of the Controller. Request a signed copy at privacy@edgeryt.com. Last updated 5 October 2026.

Product-accurate draft pending external counsel review. Entity details and liability clauses may change before launch.

1. Purpose and Scope

This DPA governs processing of personal data that the Controller uploads to or collects through the Platform in connection with hiring and assessments. It does not cover processing where Eroforze Systems Private Limited acts as an independent controller (for example account security logs for Platform users).

2. Definitions

“Personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings in the GDPR (and UK GDPR where applicable). “Services” means Edgeryt Hire and related assessment hosting.

3. Roles of the Parties

Controller determines the purposes and means of processing candidate and hiring data. Processor processes that data only to provide the Services and on documented instructions from Controller (including configuration in the product).

4. Processing Instructions

Controller instructs Processor to process personal data to host applications, assessments, interviews, files, emails and reports as configured in the workspace. Processor will not process personal data for its own marketing. If Processor believes an instruction infringes law, it will inform Controller.

5. Categories of Personal Data

Identity and contact data; application answers; resumes and files; assessment answers and scores; device and network metadata; integrity events; optional camera/microphone/screen media and identity documents; interview metadata; and related support content — as configured by Controller.

6. Categories of Data Subjects

Candidates and applicants; interviewers and workspace members whose data appears in hiring workflows.

7. Processing Activities

Collection via apply/assess/book flows; storage in database and object storage; scoring and optional AI grading; proctoring evidence storage; email delivery; retention enforcement; export and erasure tools; meeting scheduling via connected providers.

8. Customer Responsibilities

Controller warrants it has a lawful basis, provides notices to candidates, configures retention appropriately, and does not instruct Processor to process data unlawfully (including unlawful biometric monitoring).

9. Eroforze Systems / Edgeryt Responsibilities

Processor will process only on instructions; ensure confidentiality of authorised persons; implement security measures in Annex II; assist with data subject requests, DPIAs and breaches as reasonably required; and delete or return data per §18.

10. Confidentiality

Personnel authorised to process personal data are bound by confidentiality obligations.

11. Security Measures

See Annex: Technical and Organizational Security Measures below and the Trust Center.

12. Subprocessors

Controller authorises the subprocessors listed at /legal/subprocessors (Annex III). Processor will impose data protection terms on subprocessors and remain responsible for their performance. Material additions will be reflected on that list; Controller may object on reasonable data-protection grounds as agreed in a signed DPA.

13. International Data Transfers

See Annex: International Transfer Mechanism.

14. Data Subject Requests

Processor will, taking into account the nature of processing, assist Controller by providing product tools (lookup, export, erase) and reasonable cooperation so Controller can respond to data subject requests.

15. Personal Data Breach

Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller personal data, with information reasonably available to assist Controller with its notification duties.

16. Data Retention and Deletion

Processor deletes or anonymises candidate data according to retention rules Controller configures and product defaults for assessment media, plus nightly enforcement jobs.

17. Audits and Compliance

Upon reasonable written request, Processor will make available information necessary to demonstrate compliance with this DPA. On-site audits require reasonable notice, confidentiality and are limited to once per year unless a breach or regulator requires more.

18. Return or Deletion of Data

Upon termination of Services, Controller may export data using product tools while the account remains accessible. Thereafter Processor will delete or anonymise Controller personal data from active systems within a reasonable period, except where law requires retention or data is archived in encrypted backups until rotated.

19. Liability

Liability under this DPA is subject to the limitations in the Terms of Use, except where prohibited by applicable data protection law.

20. Term and Termination

This DPA lasts as long as Processor processes personal data for Controller under the Services.

21. Annex: Processing Details

22. Annex: Technical and Organizational Security Measures

23. Annex: Subprocessor List

The live list is published at /legal/subprocessors. Current entries:

24. Annex: International Transfer Mechanism

Where personal data is transferred from the EEA/UK to a country without an adequacy decision, the parties will rely on Standard Contractual Clauses (and UK addendum where required) or another lawful mechanism agreed in a signed DPA. Until countersigned, Controller should contact privacy@edgeryt.com to complete transfer documentation.

All legal documents · Privacy Policy · Terms of Use · Candidate Assessment Terms · Cookie Policy · Support