This Data Processing Agreement ("DPA") is entered into between the Controller ([Company Name], [Registered Address]) and the Processor, Oodser Ltd, incorporated in Rwanda ("Oodser"), together referred to as the "Parties".
This DPA forms part of the Terms of Service between the Parties and governs the processing of personal data by Oodser on behalf of the Company in connection with the Oodser Platform.
1Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection law
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion
- "Data Subject" means the individual whose Personal Data is being processed — primarily job candidates, employees, and professionals
- "Sub-processor" means any third party engaged by Oodser to process Personal Data on behalf of the Company
- "Applicable Law" means GDPR, UK GDPR, Rwanda Data Protection Law, India DPDP Act, and any other applicable data protection legislation
2Subject Matter and Purpose
Oodser processes Personal Data on behalf of the Company solely for the purposes of:
- Operating the Applicant Tracking System (ATS) on behalf of the Company
- Facilitating candidate communications and hiring workflows
- Providing event management and career page functionality
- Generating reports and analytics for the Company's internal use
Oodser shall not process Personal Data for any other purpose without the Company's prior written consent.
3Nature of Personal Data Processed
The categories of Personal Data processed under this DPA include:
- Candidate identity data: name, email, phone number, location
- Professional history: work experience, education, skills, certifications
- Application materials: CVs, cover letters, assessment responses
- Communications: messages exchanged between candidates and the Company via the Platform
- Hiring decision data: pipeline stage, interview notes, offer status
- Behavioral data: application interactions, response times, platform activity
4Obligations of Oodser as Processor
Oodser shall:
- Process Personal Data only on documented instructions from the Company, unless required by law
- Ensure that personnel with access to Personal Data are bound by confidentiality obligations
- Implement and maintain appropriate technical and organisational security measures as described in Annex A
- Assist the Company in responding to Data Subject rights requests within the timeframes required by Applicable Law
- Notify the Company without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data breach
- Delete or return all Personal Data upon termination of the Agreement, at the Company's choice, unless retention is required by law
- Make available to the Company all information necessary to demonstrate compliance with this DPA
- Not engage any Sub-processor without the Company's prior written consent (general authorisation for current Sub-processors listed in Annex B)
5Obligations of the Company as Controller
The Company shall:
- Ensure it has a lawful basis for processing Personal Data and instructing Oodser to process on its behalf
- Ensure Data Subjects have been provided with appropriate privacy notices regarding the use of Oodser's Platform
- Comply with all applicable data protection laws in its capacity as Controller
- Not instruct Oodser to process Personal Data in a manner that would violate Applicable Law
- Ensure that the use of AI-assisted screening features complies with applicable employment and anti-discrimination laws in the Company's jurisdiction
6International Data Transfers
Personal Data processed under this DPA is stored on AWS infrastructure in EU North (Stockholm). Where Personal Data is transferred from the EEA, UK, or other jurisdictions with transfer restrictions, the Parties agree to rely on:
- Standard Contractual Clauses (SCCs) as approved by the European Commission (incorporated herein by reference)
- UK International Data Transfer Agreements where applicable
- Any other lawful transfer mechanism as agreed in writing
7AI Processing and Automated Decisions
Where Oodser's Platform uses AI or automated processing in connection with candidate data:
- Oodser provides AI-generated recommendations as inputs to human decision-makers only
- The Company remains responsible for ensuring that final hiring decisions involve human review
- The Company must not use AI recommendations as the sole basis for decisions that significantly affect Data Subjects
- Oodser will provide audit logs of AI-influenced processing upon the Company's reasonable request
- The Company is responsible for conducting bias audits required under applicable law in its jurisdiction
8Security Measures
Oodser maintains the technical and organisational measures described in Annex A to this DPA. The Company acknowledges that security is a shared responsibility and agrees to implement appropriate access controls on its side of the Platform.
9Sub-processors
The Company grants general authorisation for Oodser to engage the Sub-processors listed in Annex B. Oodser will notify the Company of any intended changes to Sub-processors with at least 30 days notice, providing the Company an opportunity to object on reasonable grounds.
10Data Subject Rights
Oodser shall assist the Company in fulfilling Data Subject rights requests, including access, rectification, erasure, restriction, portability, and objection. The Company is the primary point of contact for Data Subjects. Where a Data Subject contacts Oodser directly, Oodser will redirect the request to the Company without undue delay.
11Audit Rights
Oodser shall allow for and contribute to audits and inspections conducted by the Company or a mandated auditor, subject to reasonable notice and confidentiality obligations. Oodser may satisfy this obligation by providing relevant compliance certifications or third-party audit reports.
12Term and Termination
This DPA remains in effect for the duration of the Terms of Service between the Parties. Upon termination, Oodser shall delete or return all Personal Data within 90 days, except where retention is required by Applicable Law.
13Liability
Each Party's liability under this DPA is subject to the limitations set out in the Terms of Service, except where Applicable Law prohibits such limitation in the context of data protection obligations.
14Governing Law
This DPA is governed by the laws of Rwanda, without prejudice to the mandatory application of GDPR or other applicable data protection law.
Annex A — Technical and Organisational Security Measures
- Encryption at rest (AES-256) and in transit (TLS 1.2+)
- Data hosted on AWS EU North (Stockholm) with SOC 2 certified infrastructure
- Role-based access controls with principle of least privilege
- Multi-factor authentication for administrative access
- Regular automated security scanning and vulnerability assessments
- Incident response plan with 72-hour breach notification capability
- Employee security training and confidentiality agreements
- Audit logging of all data access and processing events
Related policies
These documents form part of your agreement with Oodser and explain how we handle your data.