LegalData Processing Agreement
Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the agreement between Eroforze Systems Private Limited (“Processor”) and the customer organisation that uses Edgeryt Hire (“Controller”). It applies when the Processor processes personal data on behalf of the Controller. Request a signed copy at privacy@edgeryt.com. Last updated 5 October 2026.
Product-accurate draft pending external counsel review. Entity details and liability clauses may change before launch.
1. Purpose and Scope
This DPA governs processing of personal data that the Controller uploads to or collects through the Platform in connection with hiring and assessments. It does not cover processing where Eroforze Systems Private Limited acts as an independent controller (for example account security logs for Platform users).
2. Definitions
“Personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings in the GDPR (and UK GDPR where applicable). “Services” means Edgeryt Hire and related assessment hosting.
3. Roles of the Parties
Controller determines the purposes and means of processing candidate and hiring data. Processor processes that data only to provide the Services and on documented instructions from Controller (including configuration in the product).
4. Processing Instructions
Controller instructs Processor to process personal data to host applications, assessments, interviews, files, emails and reports as configured in the workspace. Processor will not process personal data for its own marketing. If Processor believes an instruction infringes law, it will inform Controller.
5. Categories of Personal Data
Identity and contact data; application answers; resumes and files; assessment answers and scores; device and network metadata; integrity events; optional camera/microphone/screen media and identity documents; interview metadata; and related support content — as configured by Controller.
6. Categories of Data Subjects
Candidates and applicants; interviewers and workspace members whose data appears in hiring workflows.
7. Processing Activities
Collection via apply/assess/book flows; storage in database and object storage; scoring and optional AI grading; proctoring evidence storage; email delivery; retention enforcement; export and erasure tools; meeting scheduling via connected providers.
8. Customer Responsibilities
Controller warrants it has a lawful basis, provides notices to candidates, configures retention appropriately, and does not instruct Processor to process data unlawfully (including unlawful biometric monitoring).
9. Eroforze Systems / Edgeryt Responsibilities
Processor will process only on instructions; ensure confidentiality of authorised persons; implement security measures in Annex II; assist with data subject requests, DPIAs and breaches as reasonably required; and delete or return data per §18.
10. Confidentiality
Personnel authorised to process personal data are bound by confidentiality obligations.
11. Security Measures
See Annex: Technical and Organizational Security Measures below and the Trust Center.
12. Subprocessors
Controller authorises the subprocessors listed at /legal/subprocessors (Annex III). Processor will impose data protection terms on subprocessors and remain responsible for their performance. Material additions will be reflected on that list; Controller may object on reasonable data-protection grounds as agreed in a signed DPA.
13. International Data Transfers
See Annex: International Transfer Mechanism.
14. Data Subject Requests
Processor will, taking into account the nature of processing, assist Controller by providing product tools (lookup, export, erase) and reasonable cooperation so Controller can respond to data subject requests.
15. Personal Data Breach
Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller personal data, with information reasonably available to assist Controller with its notification duties.
16. Data Retention and Deletion
Processor deletes or anonymises candidate data according to retention rules Controller configures and product defaults for assessment media, plus nightly enforcement jobs.
17. Audits and Compliance
Upon reasonable written request, Processor will make available information necessary to demonstrate compliance with this DPA. On-site audits require reasonable notice, confidentiality and are limited to once per year unless a breach or regulator requires more.
18. Return or Deletion of Data
Upon termination of Services, Controller may export data using product tools while the account remains accessible. Thereafter Processor will delete or anonymise Controller personal data from active systems within a reasonable period, except where law requires retention or data is archived in encrypted backups until rotated.
19. Liability
Liability under this DPA is subject to the limitations in the Terms of Use, except where prohibited by applicable data protection law.
20. Term and Termination
This DPA lasts as long as Processor processes personal data for Controller under the Services.
21. Annex: Processing Details
- Subject matter: hosting hiring and assessment workflows.
- Duration: term of the subscription / account plus deletion period.
- Nature/purpose: provide Services described in product documentation.
- Data/subjects: as in §§5–6.
22. Annex: Technical and Organizational Security Measures
- TLS encryption in transit; access control via authenticated sessions and role checks.
- Integration OAuth tokens encrypted at rest with a dedicated key.
- Object storage for files with signed/proxied access; database stores keys only.
- Rate limiting on sensitive actions; optional malware scanning of uploads.
- Two-factor authentication available for workspace users.
- Nightly retention enforcement and admin export/erase tools.
23. Annex: Subprocessor List
The live list is published at /legal/subprocessors. Current entries:
- Convex, Inc. (active) — Application database and serverless backend
- Cloudflare, Inc. (R2) (active) — Object storage for files and assessment media
- Cloudflare, Inc. (edge hosting / Workers) (optional) — Optional edge hosting and request geo for Assess / Hire
- Vercel Inc. (optional) — Optional Hire app hosting
- Resend (active) — Transactional email delivery
- Razorpay (active) — Subscription billing and payment processing
- Google LLC (Sign-in) (optional) — Optional OAuth sign-in for workspace users
- Google LLC (Calendar / Meet) (optional) — Interview scheduling and Meet links when connected
- Microsoft Corporation (optional) — Teams / Graph meeting scheduling when connected
- Zoom Video Communications, Inc. (gated) — Zoom meeting scheduling when Marketplace app is live and connected
- OpenAI (optional) — Optional LLM for question generation and AI grading
- Google LLC (Gemini API) (optional) — Optional LLM for question generation and AI grading
- DeepSeek (optional) — Optional LLM for question generation and AI grading
- Code execution sandbox (customer-configured host) (optional) — Runs candidate coding submissions for automated tests
- Upload malware scanner (customer-configured host) (optional) — Optional scan of assessment file uploads
24. Annex: International Transfer Mechanism
Where personal data is transferred from the EEA/UK to a country without an adequacy decision, the parties will rely on Standard Contractual Clauses (and UK addendum where required) or another lawful mechanism agreed in a signed DPA. Until countersigned, Controller should contact privacy@edgeryt.com to complete transfer documentation.
All legal documents · Privacy Policy · Terms of Use · Candidate Assessment Terms · Cookie Policy · Support