Data processing addendum
1. Status of this addendum
1.1 This addendum forms part of the terms of service between [registered entity name] trading as Recruit 360 (the Operator) and the customer (the Responsible Party).
1.2 It applies to all personal information that the Operator processes on the Responsible Party’s behalf in a workspace — candidates, client contacts, referees, and anyone else recorded there.
1.3 It does not apply to the personal information of the Responsible Party’s own users, its billing contacts, or visitors to our website. For those the Operator is itself the responsible party, and the privacy policy governs.
1.4 Terms defined in POPIA carry their POPIA meanings. Where this addendum and the terms of service conflict on the processing of personal information, this addendum prevails.
2. Roles
2.1 The Responsible Party determines the purpose and means of processing candidate and client personal information. It is responsible for having a lawful basis, for giving the notice required by section 18, for the accuracy of what it records, and for answering data subjects.
2.2 The Operator processes that information only on the Responsible Party’s documented instructions. Using the features of the service as provided constitutes a documented instruction; so does a written instruction sent to the address in clause 12.
2.3 If the Operator believes an instruction contravenes POPIA it will say so, and may suspend that instruction until it is resolved.
3. What is processed
The detail required by section 20 is set out in Annexure B.
4. Operator obligations
4.1 The Operator will:
- process personal information only for the purposes in Annexure B, and not for its own purposes;
- treat all personal information in a workspace as confidential, and ensure that every person it authorises to process it is bound to confidentiality (section 20(b));
- maintain the security measures in clause 5 and in section 19 of POPIA;
- notify the Responsible Party immediately where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person (section 21(2)), and in any event within 48 hours of establishing that;
- not sell, share, pool or otherwise make available the Responsible Party’s personal information to any other customer or third party except as this addendum permits;
- not use the Responsible Party’s personal information to train artificial-intelligence models for its own or any third party’s benefit.
5. Security measures
5.1 The Operator maintains at least the following, and will not weaken them during the agreement:
- Tenant isolation enforced in the database. Row-level security applies to every table, so a query issued for one workspace cannot return another workspace’s rows even if application code is at fault.
- Encryption. Transport encryption for all traffic, encryption at rest for the database and file storage, and separate key-based encryption for connected mailbox credentials.
- Access control. Role-based access within a workspace, multi-factor authentication available on every account, and time-limited, logged, purpose-bound access by Operator staff to a workspace for support.
- Audit trail. A record of significant actions in a workspace, including exports of candidate data and changes to consent and retention.
- Segregation of environments and no use of live personal information in development or testing.
- Backups taken regularly, encrypted, and overwritten on a cycle not exceeding 35 days.
6. Sub-operators
6.1 The Responsible Party gives the Operator general authorisation to appoint the sub-operators listed in Annexure A.
6.2 The Operator will give at least 30 days’ written notice before adding or replacing a sub-operator that processes personal information in a workspace. The Responsible Party may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, either party may terminate the affected part of the service without penalty, and the Responsible Party is refunded the unused portion of prepaid fees.
6.3 Each sub-operator is bound by written terms no less protective than this addendum, and the Operator remains liable to the Responsible Party for its sub-operators’ acts and omissions.
6.4 Job boards, mailbox providers and other systems that the Responsible Party chooses to connect to its workspace are not sub-operators of the Operator. The Responsible Party appoints them directly and is responsible for its arrangements with them.
7. Transfers outside South Africa
7.1 Where a sub-operator processes personal information outside the Republic, the Operator relies on section 72(1)(a) of POPIA: the recipient is bound by an agreement that upholds principles for lawful processing substantially similar to POPIA and that restricts onward transfer.
7.2 The processing location of each sub-operator is stated in Annexure A.
8. Data subject requests
8.1 The service gives the Responsible Party the means to answer requests itself: to find a data subject’s records, correct them, record and withdraw consent, export the record in a machine-readable format, and erase it.
8.2 Where a data subject approaches the Operator directly, the Operator will not answer on the Responsible Party’s behalf. It will refer the person to the Responsible Party and tell the Responsible Party promptly.
8.3 The Operator will give reasonable assistance, at no charge for ordinary requests, with a data subject request, a security-compromise notification, or an enquiry from the Information Regulator.
9. Retention and deletion
9.1 The Operator retains personal information for as long as the workspace exists, subject to the retention rules the Responsible Party configures in the service, which dispose of records on the schedule it sets.
9.2 On termination the Responsible Party may export its data throughout a 30-day read-only period. At the end of that period the Operator deletes the workspace and its personal information, including files in object storage, retaining only a record of the organisation name, the billing contact, the subscription dates and the fact of deletion.
9.3 Backups containing deleted data are overwritten on the ordinary cycle in clause 5.1 and are not restored for any purpose other than disaster recovery.
9.4 The Operator may retain personal information where a law obliges it to, and only for as long as that obligation lasts.
10. Audit
10.1 On reasonable written notice, and not more than once a year unless a security compromise has occurred, the Operator will give the Responsible Party the information reasonably necessary to demonstrate compliance with this addendum.
10.2 Where an on-site or third-party audit is required, it must be at the Responsible Party’s cost, during business hours, subject to confidentiality, and conducted so as not to compromise the security or confidentiality of any other customer’s data.
11. Liability
11.1 The limitations in clause 14 of the terms of service apply to this addendum, except that nothing limits either party’s liability to a data subject or to the Information Regulator under POPIA.
12. Notices
12.1 Notices and instructions under this addendum go to support@recruit360.co.za, marked for the attention of the Information Officer, [appointed Information Officer].
Annexure A — sub-operators
Current at the date of this draft. Each entry is a provider this service is actually configured to use; the list is updated on notice under clause 6.2.
| Sub-operator | What it does | Processing location |
|---|---|---|
| Supabase | Database, authentication and file storage — the workspace itself | [hosting region to be confirmed] |
| Peach Payments | Card tokenisation and subscription payments. Card numbers are held by Peach, never by us | South Africa |
| [transactional email provider] | Delivery of system email — invitations, notifications, candidate correspondence sent from the service | [to be confirmed] |
| OpenRouter | Routes prompts to language-model providers for CV parsing, summarising, drafting and matching. Content is sent only when a user invokes such a feature | United States |
| Serper | Web search used by the assistant’s research and business-development features. Candidate personal information is not sent to it | United States |
| Google (Places API) | Address and location autocomplete. Receives the partial text typed into an address field | United States |
The Operator will not appoint a language-model provider that reserves the right to train on content submitted to it.
Annexure B — details of processing (POPIA section 20)
Subject matter and duration
Provision of the Recruit 360 applicant tracking service, for the duration of the Responsible Party’s subscription and the 30-day read-only period that follows it.
Nature and purpose
Collection, storage, organisation, retrieval, use, transmission and erasure of personal information for the purposes of recruitment and talent acquisition: advertising vacancies, receiving and assessing applications, corresponding with candidates and clients, arranging interviews and assessments, making placements, and statutory reporting.
Categories of data subject
- Candidates and applicants, including speculative registrations
- Referees and emergency contacts a candidate supplies
- Employees and contacts of the Responsible Party’s clients
- Hiring managers and interviewers
Categories of personal information
- Identifying and contact information — name, identity or passport number, date of birth, email address, telephone number, address
- Career information — CV, employment history, qualifications, references, notice period, current and expected remuneration
- Application information — applications, stages, notes, interview records, assessment results, scores and rankings
- Correspondence between the Responsible Party and the data subject
- Special personal information — race and gender where a candidate volunteers it for Employment Equity reporting, health or disability information where a candidate volunteers it, and criminal record or credit-check outcomes where the Responsible Party lawfully obtains them. These are processed only under section 27 or 28 of POPIA, on the Responsible Party’s instruction, and are never used by the Operator for any purpose of its own
Erasure
On the schedule set by the Responsible Party’s retention rules, on its instruction, or on the timetable in clause 9.2, whichever comes first.