Data Processing Addendum
Last updated: July 22, 2026
This Data Processing Addendum, including its schedules and appendices, is entered into between:
The entity executing this Data Processing Addendum, referred to as the “Customer”, “Controller,” or “Data Exporter,”
and
Peterson Technology Partners Inc., referred to as “Rebecca,” the “Company,” “Processor,” or “Data Importer.”
This Data Processing Addendum is incorporated into and forms part of the agreement governing the Customer’s access to and use of Rebecca, including any applicable Terms of Service, Master Services Agreement, order form, subscription agreement, statement of work, or other written services agreement between the parties.
The Customer and the Company may each be referred to as a “Party” and together as the “Parties.”
1. Purpose
This Data Processing Addendum governs the Company’s Processing of Personal Data on behalf of the Customer through Rebecca, an artificial intelligence-powered interviewing, candidate-screening, assessment, recording, transcription, and recruitment-support platform.
The purposes of this Data Processing Addendum are to:
- Define the Parties’ respective data-protection responsibilities.
- Establish the Customer as the party that determines the purposes and means of Processing Candidate Personal Data.
- Establish the Company as the party that Processes Candidate Personal Data on the Customer’s documented instructions.
- Identify the categories of Personal Data and Data Subjects involved.
- establish appropriate security, confidentiality, assistance, retention, deletion, subprocessor, audit, and incident-notification obligations.
- Provide appropriate safeguards for international transfers of Personal Data.
- Support compliance with applicable Data Protection Laws.
2. Definitions
For purposes of this Data Processing Addendum:
2.1 Applicable Data Protection Laws
“Applicable Data Protection Laws” means all privacy, data-protection, data-security, breach-notification, employment-data, biometric, artificial intelligence, electronic-communications, and recording laws applicable to the Processing covered by this Data Processing Addendum.
Applicable Data Protection Laws may include, where relevant:
- Regulation (EU) 2016/679, known as the General Data Protection Regulation or GDPR.
- The United Kingdom General Data Protection Regulation and the United Kingdom Data Protection Act 2018.
- The Swiss Federal Act on Data Protection.
- The Personal Information Protection and Electronic Documents Act of Canada.
- Applicable Canadian provincial privacy laws.
- Applicable United States federal and state privacy laws.
- Applicable employment, labor, video-interview, recording, biometric, and automated-decision laws.
- Any amendment, replacement, or successor legislation.
2.2 Candidate
“Candidate” means an applicant, prospective employee, contractor, consultant, intern, student, interview participant, or other individual whose Personal Data is Processed through the Service.
2.3 Controller
“Controller” means the entity that determines the purposes and means of Processing Personal Data.
The term includes equivalent concepts such as “business,” “organization,” “data owner,” or similar terms under Applicable Data Protection Laws.
2.4 Customer Personal Data
“Customer Personal Data” means Personal Data Processed by the Company on behalf of the Customer in connection with the Service.
Customer Personal Data includes Candidate Personal Data and Personal Data relating to Customer personnel and authorized users.
2.5 Data Subject
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
2.6 Personal Data
“Personal Data” means any information relating to an identified or identifiable individual.
Personal Data includes “personal information,” “personally identifiable information,” and equivalent terms under Applicable Data Protection Laws.
2.7 Personal Data Breach
“Personal Data Breach” means a confirmed breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by the Company.
A Personal Data Breach does not include an unsuccessful attempt or activity that does not compromise the security of Customer Personal Data, such as:
- An unsuccessful login attempt.
- A blocked network scan.
- A rejected request.
- An unsuccessful denial-of-service attempt.
- A vulnerability that has not resulted in unauthorized access.
- An incident involving data that cannot reasonably be associated with the Customer or a Data Subject.
2.8 Process or Processing
“Process” or “Processing” means any operation performed on Personal Data, whether by automated or manual means.
Processing may include collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, analysis, transmission, disclosure, restriction, deletion, or destruction.
2.9 Processor
“Processor” means an entity that Processes Personal Data on behalf of a Controller.
The term includes equivalent concepts such as “service provider,” “contractor,” or similar terms under Applicable Data Protection Laws.
2.10 Restricted Transfer
“Restricted Transfer” means a transfer of Personal Data from one country or legal jurisdiction to another that requires an approved transfer mechanism under Applicable Data Protection Laws.
2.11 Security Incident
“Security Incident” means an event that compromises or is reasonably suspected to compromise the confidentiality, integrity, or availability of the Service or Customer Personal Data.
A Security Incident may or may not constitute a Personal Data Breach.
2.12 Service
“Service” means Rebecca and its related software, websites, applications, dashboards, APIs, AI interviewing features, voice and video functions, recording tools, transcription services, assessment tools, integrations, storage systems, and support services.
2.13 Standard Contractual Clauses
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses approved by the European Commission for transfers of Personal Data to third countries, including the clauses adopted through Commission Implementing Decision (EU) 2021/914, as amended or replaced.
2.14 Subprocessor
“Subprocessor” means a third party engaged by the Company to Process Customer Personal Data on behalf of the Customer.
3. Roles of the Parties
3.1 Customer as Controller
The Parties acknowledge that the Customer acts as the Controller of Customer Personal Data.
The Customer determines:
- Which Candidates are invited or contacted.
- Which Personal Data is uploaded.
- The purpose of the interview or assessment.
- The interview questions and scoring criteria.
- Whether voice, video, screen activity, or other content is recorded.
- The lawful basis for Processing.
- The recipients of interview results.
- The retention period selected by the Customer.
- Whether a Candidate advances, is rejected, or is otherwise affected by an employment decision.
- How the Customer responds to Data Subject requests.
3.2 Company as Processor
The Company acts as the Processor of Customer Personal Data when providing the Service on behalf of the Customer.
The Company will Process Customer Personal Data only:
- To provide the Service.
- On the Customer’s documented instructions.
- As described in the applicable agreement and this Data Processing Addendum.
- As necessary to comply with applicable law.
3.3 Independent Processing
The Company may act as an independent Controller for limited Processing activities where it independently determines the purposes and means of Processing.
These activities may include:
- Account administration.
- Billing and payment records.
- Security monitoring.
- Fraud and abuse prevention.
- Legal compliance.
- Enforcement of contractual rights.
- Service analytics involving appropriately aggregated or de-identified information.
- Communications with Customer administrators.
Such independent Processing will be governed by the Company’s Privacy Policy and Applicable Data Protection Laws.
3.4 No Employment Decision-Making Authority
The Company does not act as the Customer’s employer, recruitment decision-maker, or legal representative.
The Customer retains responsibility for:
- Employment decisions.
- Human review of AI-generated outputs.
- Candidate communications.
- Anti-discrimination compliance.
- Accommodations.
- Candidate consent.
- The validity and job relevance of assessment criteria.
4. Customer Instructions
4.1 Documented Instructions
The Customer instructs the Company to Process Customer Personal Data as necessary to:
- Create and manage Customer accounts.
- Upload and organize Candidate information.
- Schedule and conduct interviews.
- Contact Candidates through authorized communication channels.
- Record authorized voice or video interviews.
- Transcribe Candidate responses.
- Generate interview summaries.
- Generate scores, observations, and assessment reports.
- Store interview content and related metadata.
- Provide Customer-authorized access to reports and recordings.
- Integrate the Service with Customer-authorized systems.
- Provide technical support.
- Maintain Service security.
- Prevent fraud and abuse.
- Delete or return Customer Personal Data.
The applicable agreement, Customer account settings, campaign configuration, support instructions, and authorized API requests constitute documented instructions.
4.2 Unlawful Instructions
If the Company reasonably believes a Customer instruction violates Applicable Data Protection Laws, the Company may:
- Notify the Customer.
- Suspend the affected Processing.
- Decline to carry out the instruction.
- Request that the Customer modify or clarify the instruction.
The Company is not required to provide legal advice to the Customer.
4.3 Required Processing
If the Company is legally required to Process Customer Personal Data beyond the Customer’s documented instructions, the Company will notify the Customer before Processing unless applicable law prohibits that notification.
5. Subject Matter and Duration
5.1 Subject Matter
The subject matter of the Processing is the provision of AI-powered interviewing, candidate screening, recording, transcription, assessment, reporting, scheduling, communication, storage, integration, and recruitment-support services.
5.2 Duration
The Company may Process Customer Personal Data for:
- The term of the applicable agreement.
- Any Customer-selected retention period.
- A reasonable transition or deletion period after termination.
- Any longer period required by applicable law.
The Company will not retain Customer Personal Data longer than necessary for the purposes described in this Data Processing Addendum, except where retention is legally required.
6. Nature and Purpose of Processing
The Company may perform the following Processing activities:
- Receiving Candidate and Customer data.
- Structuring and organizing Candidate profiles.
- Hosting resumes, job descriptions, interview questions, and related documents.
- Placing or receiving authorized calls.
- Sending authorized interview invitations and reminders.
- Capturing audio and video.
- Capturing screen-sharing activity where enabled.
- Converting speech to text.
- Converting text to speech.
- Generating interview follow-up questions.
- Summarizing interviews.
- Evaluating Candidate responses against Customer-defined criteria.
- Generating scores, rankings, or recommendations.
- Storing recordings, transcripts, reports, and metadata.
- Making information available to Customer-authorized users.
- Transferring data through Customer-authorized integrations.
- Detecting fraud, abuse, security threats, or technical problems.
- Responding to Customer support requests.
- Backing up and restoring information.
- Deleting, anonymizing, or returning information.
7. Categories of Data Subjects
Customer Personal Data may relate to:
- Candidates.
- Applicants.
- Prospective employees.
- Prospective contractors or consultants.
- Interns.
- Students or trainees.
- Current employees participating in internal assessments.
- Recruiters.
- Hiring managers.
- Customer administrators.
- Interview panel members.
- Customer support contacts.
- Authorized Customer users.
- Individuals referenced in resumes or interview responses.
The Customer must avoid uploading Personal Data relating to individuals who are not relevant to an authorized recruitment or assessment purpose.
8. Categories of Personal Data
Depending on Customer configuration, Customer Personal Data may include the following categories.
8.1 Identity and Contact Information
- Full name.
- Preferred name.
- Email address.
- Telephone number.
- Mailing address.
- City, state, province, region, or country.
- Candidate identification number.
- Applicant tracking system identifier.
- Account or user identifier.
8.2 Resume and Professional Information
- Resumes and curricula vitae.
- Employment history.
- Education history.
- Certifications.
- Professional licenses.
- Technical skills.
- Languages.
- Work samples.
- Portfolio information.
- Professional profiles.
- References.
- Salary or compensation expectations.
- Availability.
- Work authorization information.
- Preferred work location.
- Role preferences.
8.3 Interview Information
- Candidate answers.
- Interview questions.
- Chat messages.
- Interview transcripts.
- Interview summaries.
- Technical assessment responses.
- Behavioral responses.
- Communication assessments.
- Scores and ratings.
- Recruiter notes.
- Hiring-manager comments.
- AI-generated observations.
- Recommendations.
- Interview status.
- Interview duration and timestamps.
8.4 Voice and Audio Information
- Voice recordings.
- Audio recordings.
- Spoken responses.
- Pronunciation and speech content.
- Background audio captured during an interview.
- Speech-to-text outputs.
Standard voice recordings may be regulated as biometric or sensitive information in some jurisdictions even when the Service does not create a voiceprint or use the voice for identity recognition.
8.5 Video and Image Information
- Video recordings.
- Candidate images visible during an interview.
- Camera streams.
- Screen recordings.
- Shared-screen content.
- Interview thumbnails.
- Visual information appearing in the candidate’s background.
Unless expressly agreed in writing, the Company will not use facial recognition or create facial templates for identity recognition.
8.6 Technical and Usage Information
- IP address.
- Browser type.
- Device type.
- Operating system.
- Connection status.
- Login records.
- Audit logs.
- Interview access records.
- Cookie or session identifiers.
- API request logs.
- Security-event data.
- Approximate time-zone or location information.
- Call-delivery and communications metadata.
8.7 Customer Account Information
- Customer-user names.
- Business contact details.
- Organization name.
- Role and permission level.
- Account activity.
- Authentication records.
- Campaign configuration.
- Integration settings.
- Support communications.
8.8 Special or Sensitive Categories
Customer Personal Data may incidentally contain sensitive information disclosed by a Candidate in a resume or interview response.
Sensitive information may include:
- Health or disability information.
- Race or ethnicity.
- Religious or philosophical beliefs.
- Political opinions.
- Trade union membership.
- Sexual orientation.
- Genetic information.
- Biometric information.
- Government identification information.
- Criminal-history information.
- Immigration information.
The Customer must not instruct the Company to collect or use sensitive information unless:
- The Processing is lawful.
- The information is necessary for a legitimate purpose.
- Required notices have been provided.
- Required consent or authorization has been obtained.
- Appropriate safeguards have been implemented.
9. Customer Responsibilities
The Customer represents, warrants, and agrees that it will:
- Process Personal Data lawfully, fairly, and transparently.
- Maintain a valid lawful basis for the Processing.
- Provide all required privacy notices.
- Obtain all required Candidate consents.
- Ensure that uploaded Personal Data is accurate and relevant.
- Collect only Personal Data reasonably necessary for the stated purpose.
- Avoid uploading unlawful or excessive information.
- Ensure that its instructions comply with Applicable Data Protection Laws.
- Maintain appropriate records of consent and lawful basis.
- Configure reasonable retention periods.
- Respond to Data Subject requests.
- Ensure interview questions and scoring criteria are lawful and job-related.
- Provide required accommodations.
- Use meaningful human review for consequential employment decisions.
- Ensure its authorized users comply with confidentiality and security requirements.
- Protect its account credentials and API keys.
- Notify the Company promptly of unauthorized account access.
- Obtain authorization before connecting third-party integrations.
- Avoid using the Service for unlawful discrimination or prohibited profiling.
- Determine whether a data-protection impact assessment is required.
10. Confidentiality
The Company will ensure that personnel authorized to Process Customer Personal Data:
- Are subject to binding confidentiality obligations.
- Receive access only where reasonably necessary.
- Receive appropriate privacy and security training.
- Process Customer Personal Data only as authorized.
- Are subject to disciplinary or contractual consequences for unauthorized use.
Confidentiality obligations will survive termination of employment, engagement, or access.
11. Security Measures
The Company will implement and maintain reasonable administrative, technical, and organizational safeguards appropriate to:
- The nature of the Customer Personal Data.
- The sensitivity of Candidate information.
- The volume and context of Processing.
- The risks to Data Subjects.
- The Company’s size, resources, and technical environment.
- Applicable contractual and legal requirements.
The Company’s security measures are described in Schedule 2.
The Company may update its security measures provided that an update does not materially reduce the overall protection of Customer Personal Data.
Canadian privacy guidance requires safeguards appropriate to the sensitivity of the information and protection against loss, theft, unauthorized access, disclosure, copying, use, or modification.
12. Access Controls
The Company will use reasonable measures designed to:
- Restrict access to authorized personnel.
- Apply least-privilege principles.
- Use role-based access controls where appropriate.
- Authenticate administrative users.
- Remove access when no longer required.
- Review privileged access periodically.
- Record relevant administrative activity.
- Protect service credentials and API keys.
The Customer is responsible for managing permissions within its own account.
13. Encryption
The Company will use appropriate encryption or equivalent safeguards for Customer Personal Data:
- In transit over public networks.
- At rest where appropriate to the nature and sensitivity of the information.
- In backups where technically and operationally appropriate.
Encryption does not eliminate all security risk and does not replace other administrative, physical, and technical safeguards.
14. Data Segregation
The Company will use logical, technical, or organizational measures designed to prevent Customer Personal Data from being improperly accessed by another customer.
The method of segregation may include:
- Tenant identifiers.
- Logical access controls.
- Account-level authorization.
- Database controls.
- Storage permissions.
- Application-layer restrictions.
15. Availability, Backup, and Recovery
The Company will maintain reasonable processes designed to support:
- Availability of the Service.
- Backup of relevant production data.
- Restoration following a significant incident.
- Business continuity.
- Disaster recovery.
- Monitoring of system health.
- Correction of material vulnerabilities.
No backup or recovery system guarantees that data will never be lost.
16. Security Testing
The Company will maintain a risk-based security program that may include:
- Vulnerability scanning.
- Security monitoring.
- Penetration testing.
- Dependency and patch management.
- Application-security review.
- Incident-response testing.
- Access reviews.
- Security-awareness training.
- Vendor-security review.
- Backup-restoration testing.
Testing frequency and scope may depend on risk, system changes, and operational needs.
17. Subprocessors
17.1 General Authorization
The Customer provides general written authorization for the Company to engage Subprocessors to provide the Service.
Subprocessors may support:
- Cloud hosting.
- Data storage.
- Artificial intelligence models.
- Speech-to-text services.
- Text-to-speech services.
- Voice and video communications.
- Email and SMS delivery.
- Security monitoring.
- Customer support.
- Analytics.
- Error reporting.
- Payment processing.
- Applicant tracking or Customer-authorized integrations.
17.2 Subprocessor List
The Company will maintain a current list of material Subprocessors at: Public Subprocessor List
The list should identify, where appropriate:
- The Subprocessor’s name.
- The services provided.
- The Processing location.
- The categories of Personal Data involved.
17.3 Subprocessor Obligations
The Company will require each Subprocessor to enter into a written agreement containing data-protection obligations that are no less protective, in material respects, than the obligations applicable to the Company under this Data Processing Addendum.
The Company remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Laws.
17.4 Notice of New Subprocessors
The Company will provide notice of a new material Subprocessor by:
- Updating the Subprocessor list.
- Sending an email notice.
- Providing an in-product notice.
- Using another reasonable notification method.
The notice period will be at least 15 days before the new Subprocessor begins Processing Customer Personal Data, unless an urgent security, legal, or operational need requires a shorter period.
17.5 Customer Objections
The Customer may submit a reasonable written objection to a new Subprocessor based on documented data-protection concerns.
The objection must be submitted within 15 days after notice.
The Parties will work in good faith to determine a commercially reasonable solution.
A solution may include:
- Additional safeguards.
- Avoiding the affected Subprocessor where reasonably feasible.
- Discontinuing the affected Service feature.
- Terminating the affected portion of the Service.
An objection does not permit the Customer to require an unreasonable redesign of the Service.
18. Data Subject Requests
Taking into account the nature of the Processing, the Company will provide reasonable assistance to help the Customer respond to valid Data Subject requests.
Requests may concern:
- Access.
- Correction.
- Deletion.
- Restriction.
- Objection.
- Portability.
- Withdrawal of consent.
- Information about Processing.
- Review of automated decision-making.
- Other rights under Applicable Data Protection Laws.
If the Company receives a request directly from a Data Subject concerning Customer Personal Data, the Company will:
- Direct the Data Subject to the Customer where appropriate.
- Notify the Customer where legally permitted.
- Avoid independently responding to the substance of the request unless instructed by the Customer or required by law.
The Customer remains responsible for verifying the request and determining the appropriate response.
The Company may charge reasonable fees for assistance that requires substantial work beyond standard Service functionality, unless prohibited by law or included in the applicable agreement.
19. Assistance with Compliance
The Company will provide reasonable assistance, taking into account the nature of the Processing and information available to the Company, concerning:
- Security obligations.
- Personal Data Breach assessments.
- Regulatory notifications.
- Data Subject notifications.
- Data-protection impact assessments.
- Consultations with supervisory authorities.
- Records of Processing.
- International-transfer assessments.
- Responding to regulatory inquiries.
- Demonstrating compliance with processor obligations.
The Customer remains responsible for its own regulatory decisions, filings, and legal obligations.
20. Personal Data Breach Notification
20.1 Notification Obligation
The Company will notify the Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data.
The Company’s contractual target is to provide initial notice:
- Within 48 hours after confirmation of the Personal Data Breach, where reasonably practicable, and in all cases without undue delay.
The Parties may replace the 48-hour target with another period in an applicable order form or enterprise agreement.
Processor notification should occur without undue delay so the Controller can evaluate its own regulatory deadlines. GDPR and UK GDPR frameworks commonly give Controllers no more than 72 hours to notify the relevant supervisory authority when a reportable breach occurs.
20.2 Initial Notice Content
To the extent known at the time, the initial notice will include:
- The nature of the incident.
- The date or estimated date of occurrence.
- The date the Company became aware of the incident.
- The categories of affected Personal Data.
- The categories of affected Data Subjects.
- The approximate number of affected Data Subjects, where known.
- The approximate number of affected records, where known.
- The likely consequences.
- Containment or remediation measures taken.
- Recommended Customer actions, where appropriate.
- A Company contact for incident coordination.
20.3 Supplemental Information
The Company may provide information in phases as an investigation continues.
The Company will provide material updates concerning:
- Scope.
- Root cause.
- Affected systems.
- Containment.
- Remediation.
- Recovery.
- Data involved.
- Relevant findings.
- Corrective measures.
20.4 No Admission
A notification or investigation does not constitute an admission of fault, liability, or legal responsibility.
20.5 Customer Responsibilities
The Customer is responsible for:
- Determining whether regulatory notification is required.
- Notifying supervisory authorities.
- Notifying affected Data Subjects.
- Notifying customers, employees, insurers, or other parties.
- Complying with applicable notification deadlines.
- Providing the Company with accurate information relevant to the investigation.
20.6 Cooperation
The Company will take reasonable steps to:
- Contain the Personal Data Breach.
- Investigate the cause.
- Mitigate reasonably foreseeable harm.
- Preserve relevant evidence.
- Correct material security weaknesses.
- Assist the Customer with legally required notifications.
20.7 Canadian Breach Requirements
Where Canadian federal private-sector privacy law applies, the Customer is responsible for determining whether an incident creates a real risk of significant harm and whether notification to affected individuals or the Office of the Privacy Commissioner is required.
The Company will provide reasonable information and assistance for that assessment.
PIPEDA requires organizations to report qualifying breaches that create a real risk of significant harm, notify affected individuals, and maintain records of security-safeguard breaches.
21. Security Incident Management
The Company will maintain an incident-response process designed to:
- Receive and assess security reports.
- Classify incidents.
- Escalate material incidents.
- Contain affected systems.
- Investigate cause and scope.
- Preserve evidence.
- Restore Service availability.
- Communicate with affected stakeholders.
- Identify corrective actions.
- Document material incidents.
The Company will not notify Data Subjects or regulators on the Customer’s behalf unless:
- The Customer provides written authorization.
- The Company is legally required to do so.
- Immediate notification is reasonably necessary to prevent material harm and legally permitted.
22. International Data Transfers
22.1 Transfer Authorization
The Customer authorizes the Company and its Subprocessors to Process Customer Personal Data in the countries identified in the applicable agreement, Subprocessor list, or Service documentation.
The Company will use a lawful transfer mechanism where required.
22.2 EEA Restricted Transfers
For a Restricted Transfer subject to the GDPR, the Parties agree that the European Commission Standard Contractual Clauses adopted through Commission Implementing Decision (EU) 2021/914 are incorporated into this Data Processing Addendum.
The SCCs may be used by controllers or processors subject to the GDPR when transferring Personal Data to certain recipients outside the EEA.
Unless the Parties agree otherwise:
- Module Two, Controller to Processor, applies where the Customer is a Controller and the Company is a Processor.
- Module Three, Processor to Processor, applies where the Customer acts as a Processor on behalf of another Controller.
- The optional docking clause will apply.
- The optional independent dispute-resolution language will not apply unless selected in writing.
- The relevant supervisory authority will be determined under the SCCs based on the Customer’s establishment, representative, or affected Data Subjects.
- The governing law for the SCCs will be the law of an EU Member State that permits third-party beneficiary rights.
- The courts identified in the completed SCC annexes will have jurisdiction for claims under the SCCs.
- The information in this Data Processing Addendum and its schedules will populate the applicable SCC annexes.
22.3 United Kingdom Transfers
For Restricted Transfers governed by United Kingdom data-protection law, the Parties will use:
- The United Kingdom International Data Transfer Addendum to the EU SCCs; or
- Another valid transfer mechanism approved under United Kingdom law.
References in the incorporated SCCs will be interpreted as necessary to give effect to the applicable United Kingdom transfer mechanism.
22.4 Swiss Transfers
For Restricted Transfers governed by Swiss data-protection law:
- References to the GDPR will be interpreted to include applicable Swiss data-protection law.
- References to EU Member States will be interpreted to include Switzerland where required.
- The competent Swiss authority will be substituted where appropriate.
- The SCCs will be adapted only to the extent necessary to provide a lawful Swiss transfer mechanism.
22.5 Alternative Transfer Mechanisms
If the SCCs are not required or are replaced, the Company may rely on another lawful transfer mechanism, including:
- An adequacy decision.
- A recognized certification framework.
- Binding corporate rules.
- A statutory derogation.
- Another approved contractual mechanism.
22.6 Transfer Impact Assessments
The Parties will reasonably cooperate in assessing international transfers where required.
The Company may provide information concerning:
- The destination country.
- The nature of the Processing.
- Security safeguards.
- Government-access procedures.
- Subprocessor locations.
- Relevant contractual protections.
- Supplementary safeguards.
The Customer remains responsible for determining whether the transfer is lawful for its use of the Service.
23. Government and Law-Enforcement Requests
Unless prohibited by law, the Company will:
- Review government requests for Customer Personal Data.
- Determine whether the request is legally valid.
- Seek clarification or narrowing where appropriate.
- Notify the Customer before disclosure where legally permitted.
- Disclose only information legally required.
- Document material requests.
- Challenge an unlawful or disproportionate request where reasonably appropriate.
The Company will not voluntarily provide direct, indiscriminate, or unrestricted access to Customer Personal Data.
24. Data Retention
The Company will retain Customer Personal Data according to:
- Customer account settings.
- The applicable order form.
- The Company’s documented retention schedule.
- Customer instructions.
- Applicable legal requirements.
The Customer is responsible for selecting retention periods that are appropriate for:
- Recruitment needs.
- Employment-record obligations.
- Candidate notices.
- Consent terms.
- Applicable legal requirements.
- Litigation or investigation holds.
25. Return and Deletion
Upon termination or expiration of the applicable agreement, and upon the Customer’s written request, the Company will delete or return Customer Personal Data within a commercially reasonable period.
Unless otherwise agreed, the Company’s target is to complete deletion from active systems within 90 days after termination or a valid deletion instruction.
The Company may retain limited information where necessary to:
- Comply with applicable law.
- Resolve disputes.
- Enforce contractual rights.
- Maintain financial or security records.
- Satisfy legal-hold obligations.
- Prevent fraud or abuse.
- Maintain backup integrity.
Personal Data stored in backups may remain until the relevant backup is overwritten or deleted through the Company’s normal backup lifecycle.
During that period, the information will remain protected and will not be restored for ordinary business use unless necessary for recovery, security, or legal compliance.
26. Data Export
During the applicable subscription term, the Customer may use available Service features to export Customer Personal Data.
Exported information may include:
- Candidate profiles.
- Interview transcripts.
- Assessment reports.
- Interview metadata.
- Recordings, where enabled.
- Campaign information.
The Customer is responsible for protecting exported information after it leaves the Service.
27. De-Identification and Aggregation
The Company may create aggregated or de-identified information from Customer Personal Data only where:
- The information cannot reasonably identify the Customer or a Data Subject.
- Reasonable measures are used to prevent re-identification.
- The information is not combined with other data for re-identification.
- The Processing is permitted by Applicable Data Protection Laws and the applicable agreement.
The Company may use appropriately aggregated or de-identified information for:
- Security.
- Reliability.
- Capacity planning.
- Product analytics.
- Service improvement.
- Statistical reporting.
- Fraud prevention.
28. Artificial Intelligence Model Use
Unless expressly authorized in the applicable agreement, the Company will not use identifiable Customer Personal Data to train a general-purpose artificial intelligence model made available to unrelated third parties.
The Company may use Customer Personal Data as necessary to:
- Generate outputs requested by the Customer.
- Operate the Service.
- Maintain conversation or interview context.
- Detect misuse.
- Improve reliability through appropriately controlled testing.
- Evaluate performance using aggregated or de-identified information.
Where third-party AI providers Process Customer Personal Data, they will be treated as Subprocessors and subject to applicable contractual safeguards.
29. Audits and Compliance Information
29.1 Compliance Information
Upon reasonable written request, the Company will make available information reasonably necessary to demonstrate compliance with its processor obligations.
Information may include:
- Security documentation.
- Policies or policy summaries.
- Independent audit reports, where available.
- Penetration-test summaries, where appropriate.
- Certifications.
- Subprocessor information.
- Data-flow information.
- Responses to reasonable security questionnaires.
The Company may redact information that:
- Is confidential.
- Relates to another customer.
- Would create a security risk.
- Is legally privileged.
- Is restricted by a third party.
29.2 Customer Audit Rights
If the information provided is insufficient to demonstrate compliance, the Customer may request an audit.
Audits must:
- Be reasonably scoped.
- Relate to Processing under this Data Processing Addendum.
- Occur no more than once per 12-month period, unless required by law or following a confirmed material Personal Data Breach.
- Be conducted during normal business hours.
- Be subject to reasonable advance notice.
- Avoid unreasonable disruption.
- Protect Company and third-party confidential information.
- Be conducted by an independent, qualified auditor that is not a competitor of the Company.
- Be subject to confidentiality obligations.
The Customer will bear its audit costs unless the audit identifies a material breach by the Company.
29.3 Regulatory Audits
The frequency restrictions above do not limit an audit required by a competent supervisory authority.
30. Data-Protection Impact Assessments
The Company will provide reasonable assistance where the Customer determines that a data-protection impact assessment is required.
Assistance may include information concerning:
- Processing operations.
- Data categories.
- Data flows.
- Retention.
- Security measures.
- Subprocessors.
- International transfers.
- AI-assisted processing.
- Recording and transcription functions.
The Customer remains responsible for completing the assessment and determining whether consultation with a regulator is required.
31. Records of Processing
The Company will maintain records of Processing where required by Applicable Data Protection Laws.
Records may include:
- Customer categories.
- Processing activities.
- Categories of Personal Data.
- Categories of Data Subjects.
- International transfers.
- Security measures.
- Subprocessors.
- Retention information.
32. Regulatory Cooperation
The Company will reasonably cooperate with a competent privacy or data-protection authority concerning Processing under this Data Processing Addendum.
The Company may require the Customer to participate where an inquiry concerns:
- The Customer’s lawful basis.
- Candidate notice.
- Candidate consent.
- Employment decisions.
- Customer retention.
- Customer instructions.
- Customer scoring or assessment criteria.
33. United States State Privacy Terms
Where a United States state privacy law applies and the Customer is a regulated “business” or “controller,” the Company will act as a “service provider,” “contractor,” or “processor,” as applicable.
The Company will:
- Process Personal Data only for the limited and specified purposes described in the agreement.
- Comply with applicable processor or service-provider obligations.
- Provide the same level of privacy protection required by applicable law.
- Notify the Customer if it determines it can no longer meet an applicable obligation.
- Permit the Customer to take reasonable and appropriate steps to stop and remediate unauthorized Processing.
- Avoid selling Customer Personal Data.
- Avoid sharing Customer Personal Data for cross-context behavioral advertising unless expressly authorized and legally permitted.
- Avoid retaining, using, or disclosing Customer Personal Data outside the direct business relationship except as permitted by law.
34. Canadian Privacy Terms
Where Canadian privacy law applies:
- The Customer remains accountable for Personal Data transferred to the Company for Processing.
- The Company will use safeguards appropriate to the sensitivity of the information.
- The Company will Process Personal Data only for the authorized purposes.
- The Company will assist the Customer with access, correction, breach, and complaint obligations where reasonably required.
- The Customer is responsible for providing meaningful notice concerning cross-border Processing where required.
- The Customer is responsible for determining whether consent is valid and appropriate.
35. Liability
The liability of each Party arising from this Data Processing Addendum will be subject to the limitations and exclusions contained in the applicable agreement, except where such limitations are prohibited by Applicable Data Protection Laws.
Nothing in this Data Processing Addendum limits a Data Subject’s rights under the SCCs or Applicable Data Protection Laws.
36. Order of Precedence
If there is a conflict between documents, the following order of precedence will apply concerning data protection:
- The applicable Standard Contractual Clauses.
- A jurisdiction-specific transfer addendum.
- This Data Processing Addendum.
- The applicable order form.
- The main services agreement.
- The Terms of Service.
The SCCs will control only to the extent of a conflict concerning a Restricted Transfer governed by the SCCs.
37. Changes to Applicable Law
If Applicable Data Protection Laws, regulatory guidance, or approved transfer mechanisms change, the Parties will cooperate in good faith to amend this Data Processing Addendum as reasonably necessary.
The Company may update this Data Processing Addendum to:
- Reflect changes in law.
- Adopt a replacement transfer mechanism.
- Improve security commitments.
- Address changes to the Service.
- Add jurisdiction-specific terms.
Material reductions in Customer protections will not apply retroactively without appropriate notice or agreement where required.
38. Term and Termination
This Data Processing Addendum begins when the Customer accepts it or enters into the applicable agreement.
It remains in effect while the Company Processes Customer Personal Data.
Termination of the main agreement does not terminate provisions that must survive to protect retained Personal Data.
The following provisions survive termination as applicable:
- Confidentiality.
- Security.
- Breach cooperation.
- Return and deletion.
- International-transfer protections.
- Audit obligations relating to prior Processing.
- Liability.
- Regulatory cooperation.
39. Electronic Acceptance
The Parties agree that this Data Processing Addendum may be accepted through:
- Electronic signature.
- Acceptance within the Customer portal.
- Execution of an order form incorporating it.
- Execution of a master agreement incorporating it.
- Another legally valid electronic acceptance process.
The individual accepting this Data Processing Addendum represents that they have authority to bind the Customer.
40. Contact Information
Company Data-Protection Contact
Name: Peterson Technology Partners Inc.
Attention: Privacy and Data Protection
Address: 1030 W Higgins Rd, Suite 230, Park Ridge, IL 60068
Email: privacy@petegabi.com
Security incidents: security-1@petegabi.com
Website: www.petegabi.com
Customer Data-Protection Contact
Customer: The entity designated as ‘Customer’ in the underlying Services Agreement. Attention: As provided by Customer in the underlying Services Agreement or Order Form. Address: As provided by Customer in the underlying Services Agreement or Order Form. Email: As provided by Customer in the underlying Services Agreement or Order Form.
SCHEDULE 1
DETAILS OF PROCESSING
A. Parties
Data Exporter or Customer
Name: The entity designated as ‘Customer’ in the underlying Services Agreement. Address: As provided by Customer in the underlying Services Agreement or Order Form. Contact: As provided by Customer in the underlying Services Agreement or Order Form. Email: As provided by Customer in the underlying Services Agreement or Order Form. Role: Controller, or Processor where the Customer acts for another Controller.
Data Importer or Company
Name: Peterson Technology Partners Inc.
Address: 1030 W Higgins Rd, Suite 230, Park Ridge, IL 60068
Email: privacy@petegabi.com
Role: Processor.
B. Data Subjects
The Processing may concern:
- Candidates.
- Applicants.
- Prospective employees.
- Prospective contractors.
- Interns.
- Students.
- Employees participating in internal assessments.
- Recruiters.
- Hiring managers.
- Customer account users.
C. Personal Data Categories
The Processing may include:
- Names.
- Email addresses.
- Telephone numbers.
- Resumes and curricula vitae.
- Employment history.
- Education and certifications.
- Technical and professional skills.
- Work authorization information.
- Availability and compensation expectations.
- Candidate answers.
- Audio and voice recordings.
- Video recordings.
- Screen recordings.
- Interview transcripts.
- AI-generated summaries.
- Assessment scores.
- Recruiter notes.
- Communication metadata.
- IP addresses and device information.
- Account and authentication records.
- Audit logs.
D. Sensitive Data
Sensitive data may be incidentally included in Customer uploads or Candidate responses.
Sensitive data is not required unless expressly stated by the Customer and legally permitted.
Additional safeguards may include:
- Restricted access.
- Encryption.
- Logging.
- Retention controls.
- Prohibition on unauthorized profiling.
- Human review.
E. Processing Frequency
Processing may occur:
- Continuously during the subscription term.
- When the Customer uploads data.
- When an interview is scheduled or conducted.
- When reports are generated.
- When authorized users access the Service.
- When support, security, backup, or deletion functions are performed.
F. Processing Purpose
The purpose is to provide AI-powered recruitment and interviewing services, including:
- Candidate contact.
- Interview scheduling.
- Voice and video interviewing.
- Recording.
- Transcription.
- Assessment.
- Reporting.
- Candidate-management support.
- Security and technical support.
G. Retention Period
Customer Personal Data will be retained according to:
- The Customer’s selected settings.
- The applicable agreement.
- Documented Customer instructions.
- Applicable legal obligations.
Default retention period, if applicable: Based on Customer request.
H. Subprocessor Processing
Subprocessors may support cloud infrastructure, communications, AI processing, transcription, storage, security, analytics, and Customer-authorized integrations.
The current Subprocessor list is available at: Public Subprocessor List
SCHEDULE 2
TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
The Company will maintain a security program that may include the following controls, as appropriate to the Service and risk.
1. Information Security Governance
- Written information-security policies.
- Assigned security responsibilities.
- Periodic policy review.
- Risk assessments.
- Security-awareness training.
- Confidentiality obligations.
2. Identity and Access Management
- Unique user accounts.
- Role-based access.
- Least-privilege access.
- Administrative access restrictions.
- Multifactor authentication for privileged access where available.
- Access reviews.
- Timely deprovisioning.
- Password and credential controls.
3. Encryption and Communication Security
- Encryption in transit using current industry-standard protocols.
- Encryption at rest where appropriate.
- Secure API authentication.
- Protection of encryption keys.
- Secure network configuration.
- Restrictions on insecure protocols.
4. Infrastructure Security
- Cloud and network access controls.
- Firewalls or equivalent filtering.
- Environment separation where appropriate.
- Secure configuration baselines.
- Malware prevention.
- Infrastructure monitoring.
- Patch management.
5. Application Security
- Secure development practices.
- Code review.
- Dependency management.
- Vulnerability scanning.
- Security testing.
- Input validation.
- Authentication and authorization testing.
- Change-management controls.
6. Logging and Monitoring
- Security-event logging.
- Administrative activity logging.
- Authentication logging.
- Alerting for suspicious activity.
- Log-access restrictions.
- Time synchronization.
- Reasonable log retention.
7. Vulnerability Management
- Periodic scanning.
- Risk-based remediation.
- Critical-patch procedures.
- Third-party dependency review.
- Penetration testing where appropriate.
- Responsible vulnerability-reporting processes.
8. Data Protection Controls
- Logical tenant separation.
- Data-minimization procedures.
- Retention and deletion controls.
- Controlled production access.
- Restrictions on copying production data.
- Secure disposal.
- Backup protections.
9. Incident Response
- Documented incident-response procedures.
- Incident classification.
- Escalation procedures.
- Containment and recovery.
- Evidence preservation.
- Customer notification.
- Post-incident review.
- Corrective-action tracking.
10. Business Continuity and Recovery
- Backup procedures.
- Recovery planning.
- System redundancy where appropriate.
- Disaster-recovery testing.
- Service-monitoring procedures.
- Emergency communication procedures.
11. Personnel Security
- Appropriate screening where lawful.
- Confidentiality agreements.
- Security training.
- Role-specific access.
- Disciplinary procedures.
- Access removal following termination.
12. Vendor and Subprocessor Management
- Security and privacy review.
- Written data-protection terms.
- Confidentiality obligations.
- Incident-notification requirements.
- Access restrictions.
- Periodic reassessment based on risk.
13. Physical Security
Where the Company controls physical facilities:
- Controlled facility access.
- Visitor procedures.
- Equipment protection.
- Secure disposal.
Where cloud providers operate data centers, the Company will rely on the provider’s physical-security controls subject to contractual and compliance review.
SCHEDULE 3
INTERNATIONAL TRANSFER DETAILS
1. Transfer Mechanism
For EEA Restricted Transfers:
- EU Standard Contractual Clauses, Module Two or Module Three, as applicable.
For United Kingdom Restricted Transfers:
- UK International Data Transfer Addendum or another approved mechanism.
For Swiss Restricted Transfers:
- EU SCCs as adapted for Swiss law or another approved mechanism.
2. Transfer Frequency
Transfers may occur continuously during the term of the Service.
3. Nature of Transfer
The transfer may involve:
- Hosting.
- Storage.
- Retrieval.
- Interview processing.
- AI analysis.
- Audio and video processing.
- Transcription.
- Support.
- Security monitoring.
- Backup and recovery.
4. Transfer Locations
Primary Processing Location: United States of America
Backup Location: Chicago Illinois
Support Locations: Online support worldwide
Subprocessor Locations: Listed at Public Subprocessor List
5. Competent Supervisory Authority
The competent supervisory authority will be determined according to the applicable SCC module and the Customer’s establishment, representative, or affected Data Subjects.
6. Governing EU Member State Law
For purposes of the SCCs:
- The law of the EU Member State in which the Data Exporter (Customer) is established.
7. Competent Courts
For purposes of the SCCs:
- Courts of the EU Member State in which the Data Exporter (Customer) is established.
SCHEDULE 4
DATA BREACH CONTACT AND ESCALATION
Company Security Contact
Security email: security-1@petegabi.com
Privacy email: privacy@petegabi.com
Emergency telephone: +1 312-778-5006
Customer Security Contact
Name or team: Customer Security Contact Email: As provided by Customer in the underlying Services Agreement or Order Form. Telephone: As provided by Customer in the underlying Services Agreement or Order Form.
Notification Timeline
The Company will provide initial notification:
- Without undue delay and, where reasonably practicable, within 48 hours after confirming a Personal Data Breach affecting Customer Personal Data.
Notification Method
Notification may be made through:
- Email.
- Telephone.
- The Customer portal.
- Another agreed secure communication channel.
Required Customer Escalation Contacts
The Customer should provide at least:
- One primary security contact.
- One privacy or legal contact.
- One backup escalation contact.
ACCEPTANCE
By accepting this Data Processing Addendum, the Parties acknowledge that:
- The Customer is the Controller of Candidate Personal Data unless otherwise stated.
- The Company is the Processor of Candidate Personal Data when providing the Service.
- The Company may use approved Subprocessors.
- International transfers will use lawful transfer mechanisms.
- The Company will maintain reasonable security measures.
- The Company will notify the Customer without undue delay following confirmation of a Personal Data Breach.
- The Customer retains responsibility for its lawful basis, notices, consents, employment decisions, retention instructions, and Data Subject responses.
Customer Legal Name: As provided by Customer in the underlying Services Agreement or Order Form.
Authorized Representative: As provided by Customer in the underlying Services Agreement or Order Form.
Title: As provided by Customer in the underlying Services Agreement or Order Form.
Rebecca Company Legal Name: Peterson Technology Partners
Authorized Representative: Nick Shah
Title: CEO & Founder