Skip to content
All legal drafts

Startup draft · not approved for use

Data Processing Addendum

This template addresses agency-controlled personal data that NHIP processes to provide the service. Counsel must align it with the customer agreement, architecture, security program, subprocessors, and transfer routes.

Draft date · August 5, 2026

Qualified legal review required

This startup template does not provide legal advice. Qualified counsel must adapt it to the NHIP legal entity, product behavior, subprocessors, contracts, and each launch jurisdiction before publication or use.

01

Parties and scope

This Data Processing Addendum would apply between the agency customer identified in an order form, the Customer, and [insert NHIP legal entity name], NHIP. It forms part of [insert customer agreement name and date].

The addendum covers personal data that NHIP processes for the Customer to provide agency ATS, career-page, application, communication, import, matching, and reporting functions. It does not govern data for which NHIP acts as an independent controller, subject to counsel's role analysis.

02

Roles and governing law

The Customer acts as controller or business for Customer Personal Data. NHIP acts as processor or service provider under the Customer's documented instructions. Each party will meet the duties that apply to its role under [insert applicable EU, UK, US state, and other privacy laws].

If the Customer acts as a processor for another controller, NHIP acts as a subprocessor. The Customer confirms that it may appoint NHIP and give the instructions in this addendum.

03

Customer instructions

NHIP will process Customer Personal Data to provide, secure, support, and improve the contracted service as described in the agreement and Annex 1. Additional instructions require written agreement and may require a fee where the request exceeds the contracted service.

NHIP will tell the Customer if an instruction appears to violate applicable data protection law, unless law prevents notice. NHIP will not sell or share Customer Personal Data for cross-context behavioral advertising and will not use it outside the permitted business purpose.

04

Personnel and confidentiality

NHIP will limit Customer Personal Data access to personnel and contractors who need access for the service. NHIP will bind those persons to confidentiality and give them data protection and security guidance suited to their work.

The Customer controls its agency memberships, roles, recruiter assignments, and read-only access. The Customer must remove access when a person no longer needs it.

05

Security measures

NHIP will maintain technical and organizational measures designed to protect Customer Personal Data against unauthorized access, loss, alteration, and disclosure. Annex 2 must list the approved measures.

Expected measures include:

  • organization-scoped authorization and database row-level rules;
  • encryption in transit and approved encryption at rest;
  • private file storage with time-limited signed access;
  • input, file type, and file size validation with a malware-scanning integration point;
  • rate limits, audit logs, secret management, backup, and recovery controls;
  • access review, vulnerability handling, and incident response procedures.
06

Subprocessors

The Customer gives NHIP general authorization to use subprocessors listed at [insert subprocessor schedule URL]. NHIP will impose data protection terms that protect Customer Personal Data to the standard required by applicable law.

NHIP will give [insert notice period] notice of a new subprocessor. The Customer may object on documented data protection grounds within [insert objection period]. The agreement must state the available remedy if the parties cannot resolve the objection.

07

Restricted transfers

Each party will use a lawful transfer tool when Customer Personal Data moves to a country without an applicable adequacy finding. The parties may incorporate approved contractual clauses and a UK addendum or other jurisdiction-specific terms.

[Insert transfer module, exporter and importer roles, governing member state, UK addendum selections, and supplementary measures].

08

Data subject requests

NHIP will send a request concerning Customer Personal Data to the Customer unless law requires NHIP to respond. Taking account of the processing, NHIP will provide product functions or other assistance that helps the Customer answer verified requests.

The Customer remains responsible for the response and for deciding whether an exception applies. [Insert support channel, response target, and fee rule].

09

Personal data incidents

NHIP will notify the Customer after NHIP confirms a breach of security that affects Customer Personal Data. The notice will include available information about the event, affected data, identified consequences, containment, and a contact for follow-up.

[Insert contractual notice period and security contact]. NHIP's notice does not admit fault. The Customer controls notices to regulators and affected persons unless law assigns that duty to NHIP.

10

Compliance assistance

Taking account of the service and information available to NHIP, NHIP will assist the Customer with security duties, breach assessment, data protection impact assessments, and regulator consultations where the law requires assistance.

The Customer will give NHIP the information and decisions needed to provide that assistance. [Insert scope, fees, and response process].

11

Information and audits

NHIP will provide information needed to demonstrate compliance with its processor duties. The parties should use current independent reports, certifications, and written responses before requesting an on-site audit.

An audit must protect other customers, avoid service disruption, follow confidentiality terms, and occur during business hours with [insert notice period] notice. Counsel must set frequency, cost, auditor qualification, and regulatory exceptions.

12

Return and deletion

At the end of the service, NHIP will return or delete Customer Personal Data according to the Customer's choice, unless law requires retention. The agreement must define export format, export window, production deletion, backup expiry, legal holds, and confirmation.

[Insert export window, production deletion target, and backup retention period].

A1

Annex 1: Processing details

  • Subject matter: agency recruitment and public application services.
  • Duration: the service term plus approved deletion and backup periods.
  • People: candidates, prospects, agency users, client contacts, interview participants, and support contacts.
  • Data: identity, contact, employment, education, skills, preferences, applications, communications, interview, offer, placement, account, and audit data.
  • Operations: collection, storage, organization, extraction, matching, search, communication, disclosure to authorized recipients, export, and deletion.

[Confirm special-category data prohibition, permitted exceptions, frequency, retention, and Customer instructions].

A2

Annex 2: Security schedule

Counsel and the security owner must replace this placeholder with the approved security schedule. It should cover governance, access, encryption, tenancy, software development, infrastructure, files, logging, incident response, resilience, vendor review, and personnel security.

[Attach approved technical and organizational measures with owner and review date].

A3

Annex 3: Subprocessor schedule

List each provider's legal name, service, data categories, processing location, and transfer safeguard. The list should match deployed production providers and configured optional integrations.

[Insert hosting, database, storage, email, payment, AI, monitoring, and support subprocessors].