U.S. Data processing Addendum
Last Updated: August 21, 2026
This U.S. Data Processing Addendum (“Addendum”) addresses the processing and transfer of Personal Information under Applicable Privacy Laws and contracts, in connection with the Services provided by RecruitTune acting on its own behalf and as agent for each of its Affiliates (“Service Provider”), to the entity purchasing the Services (“Company”) (each a “Party” and collectively, the “Parties”) subject to the RecruitTune Terms of Service (the “Agreement”). To the extent the terms of this Addendum conflict with the Agreement with regard to the processing of Personal Information, the terms of this Addendum shall prevail.
WHEREAS, Company and Service Provider wish to incorporate this Addendum into the Agreement to describe the additional terms under which Service Provider will handle Personal Information under its obligations outlined in the Agreement and in compliance with Applicable Privacy Laws (as defined below). Capitalized terms used in this Addendum which are not defined in this Addendum have the meanings ascribed to them in the Agreement.
NOW, THEREFORE, for good and valuable consideration, the receipt and sufficiency of which is hereby acknowledged, the Parties agree as follows:
Definitions.
“Applicable Privacy Laws” means as applicable and binding on the Parties (a) any federal, state or local laws of the United States, or regulations governing the protection or privacy of Personal Information including, but not limited to, the California Consumer Privacy Act of 2018 (Cal. Civ. Code §§ 1798.100 et seq.), and as may be amended, supplemented, or otherwise modified from time to time, including by virtue of the California Privacy Rights Act and its implementing regulations (collectively the “CCPA”); Colorado Privacy Act and its implementing regulations; An Act Concerning Personal Data Privacy and Online Monitoring; Delaware Personal Data Privacy Act, Iowa Consumer Data Protection Act; Minnesota Consumer Data Privacy Act; Montana Consumer Data Privacy Act; Nebraska Data Privacy Act; New Hampshire Privacy Act; New Jersey Privacy Act; Oregon Consumer Protection Act; Tennessee Information Protection Act; Texas Data Privacy and Security Act; Utah Consumer Privacy Act; Virginia Consumer Data Protection Act; and (b) any applicable laws replacing, amending, extending, re-enacting or consolidating any of the above laws from time to time.
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household (“data subject”), or that is otherwise deemed personal information under Applicable Privacy Laws, including Sensitive Personal Information, that Service Provider receives, maintains, processes or otherwise has or gains access to in connection with the services specified in the Agreement (including, but not limited to, the definition of “personal data” or other similarly defined terms in Applicable Privacy Laws).
“Process” or “Processing” means any operation or set of operations which is performed on Personal Information or on sets of Personal Information whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“Security Incident” means any compromise of either the security, confidentiality, or integrity of Personal Information. Without limiting the foregoing, a compromise shall include any unauthorized access to or disclosure or acquisition of Personal Information. Security Incident includes, but is not limited to, any “breach of the security of the system”, “breach of personal data”, or “loss of personal data” as defined under Applicable Privacy Laws.
“Sensitive Personal Information” may include, but is not limited to: (a) an individual’s government-issued identification number, including a social security number, driver’s license number, or state-issued identification number; (b) a financial account number, credit card number, or debit card number with or without any required security code, access code, personal identification number, or password, that would permit access to an individual’s financial account; (c) biometric, medical, health, genetic or health insurance information; (d) religious, moral or philosophical beliefs or political opinions; (e) trade union membership; (f) sexual orientation; (g) criminal records; and (h) race or ethnicity information.
“Subcontractors” means any third party engaged by Service Provider to Process any Personal Information relating to this Addendum and/or the Agreement (including the term “Sub-processor” or a similarly defined terms as defined in Applicable Privacy Laws).
Roles. The Parties agree that for purposes of compliance with the Applicable Privacy Laws, Company operates as a “controller” or “business” as those terms are defined in Applicable Privacy Laws and Service Provider operates as a “processor” or “service provider” as those terms are defined in the Applicable Privacy Laws.
Compliance. Service Provider shall comply with Applicable Privacy Laws and Process all Personal Information consistent with the restrictions and obligations on Processors set forth in Applicable Privacy Laws. In the event that Service Provider determines that it can no longer meet its obligations under this Addendum, Service Provider shall notify Company in writing.
Permissible Processing. Service Provider shall Process Personal Information only (i) for the purposes set forth in the Addendum, (ii) in accordance with the terms and conditions of the Agreement and any other documented instructions provided by Company, and (iii) in compliance with Applicable Privacy Laws. Company hereby instructs Service Provider to Process Personal Information in accordance with the foregoing and as set forth in Schedule A herein (“Company’s Business Purpose”). Service Provider may aggregate, de‑identify, and/or anonymize Personal Information it Processes on behalf of Company, and may use and disclose such aggregated, de‑identified, and/or anonymized data for its lawful business purposes, provided that such data does not identify, and is not reasonably capable of being linked to, Company, any consumer, household, or device.
Prohibited Uses of Personal Information. Service Provider may retain, use or disclose Personal Information as allowed by Applicable Privacy Laws. However, Service Provider shall not:
- sell, rent, release, disclose, disseminate, make available, transfer, or otherwise communicate the Personal Information to another business or a third party for monetary or other valuable consideration;
- “share” (as that term is defined under the CCPA) Personal Information to another business or a third party;
- retain, use, or disclose the Personal Information outside the direct business relationship between Company and Service Provider, or for any purpose other than those allowed by Applicable Privacy Laws or for the business purposes specified in this Addendum;
- Process Personal Information contrary to Company’s Business Purpose, unless required to do so by Applicable Privacy Laws; or
- combine the Personal Information that Service Provider receives from, or on behalf of, Company with Personal Information that it receives from, or on behalf of, another person or business or the Personal Information that Service Provider collects from its own interaction with customers, unless otherwise stated by Applicable Privacy Laws.
Certification of Understanding. Service Provider certifies that it understands and shall comply with the Processing restrictions set forth in this Addendum.
Company Obligations. Company shall, in its use of the Services, comply with all Applicable Privacy Laws. For the avoidance of doubt, Company’s Processing instructions to Service Provider for the Processing of Personal Information must comply with all Applicable Privacy Laws. In addition, Company shall have sole responsibility for the accuracy, quality, and legality of Personal Information Company or its affiliates provide and the means by which Company acquired the Personal Information, including providing any required notices to, and obtaining any necessary consent from, its clients, data subjects, employees or contractors who qualify as end-users for the Services. Should Company learn that it has provided Personal Information under the Agreement or this Addendum that may not be shared pursuant to a consent or data privacy notice, Company shall promptly notify Service Provider in writing without unreasonable delay. Company further acknowledges and agrees that:
Service Provider shall not be liable for the Processing of any Personal Information in which Company (i) failed to obtain consent from or provide proper notice to the relevant data subject or (ii) possess a lawful basis to Process such Personal Information. Additionally, Company shall comply with (a) the obligations of a data controller, “business,” or equivalent term (as these terms are defined under applicable laws) under all Applicable Privacy Laws; (b) all terms of the Agreement; and (c) all terms of this Addendum; and
Company’s failure to comply with the obligations under this Section shall be a material breach of this Addendum. Upon such breach, Service Provider may immediately cease Processing of any Personal Information under this Addendum and the Agreement. Service Provider shall also be entitled to all remedies available under Agreement, this Addendum and applicable law.
Information Security.
Access to Personal Information. Service Provider will limit access to Personal Information to: (a) those authorized persons who require Personal Information access to meet Service Provider’s obligations under this Addendum and the Agreement; and (b) the part or parts of the Personal Information that those authorized persons strictly require for the performance of their duties. Service Provider will ensure that all authorized persons: (i) are informed of the Personal Information’s confidential nature and use restrictions; (ii) have undertaken training on all Applicable Privacy Laws relating to handling Personal Information and how it applies to their particular duties; and (iii) are aware both of Service Provider’s duties and their personal duties and obligations under the Applicable Privacy Laws, this Addendum, and the Agreement.
Reasonable Security Measures. Service Provider will implement and maintain commercially reasonable administrative, technical, and physical safeguards designed to reasonably protect the confidentiality, availability, integrity, and resiliency of the Personal Information.
No Admission of Fault. Service Provider’s obligation to report or respond to a Security Incident under this Section is not and will not be construed as an acknowledgement by Service Provider of any fault or liability of Service Provider with respect to such Security Incident.
Assistance. Service Provider agrees to cooperate with Company in responding to any applicable data subject requests pertaining to the access, restriction, limitation or deletion of the Personal Information. Service Provider shall also reasonably assist Company with meeting Company’s compliance obligations under all Applicable Privacy Laws, taking into account the nature of Service Provider’s Processing and the information available to Service Provider.
Requests from Data Subjects. If a known Company data subject submits a request directly to Service Provider relating to Personal Information, Service Provider shall advise Company of the request no later than seventy-two (72) hours after receiving such request.
Security Incident and Response Procedures.
Notification. Service Provider will notify Company of a Security Incident as soon as reasonably practicable, but no later than five (5) days after Service Provider becomes aware of it. The notification will include, at least, the following information, to the extent available: (i) nature of the incident; (ii) the Personal Information compromised or involved in the Security Incident; (iii) initial recommendations to protect data subject’s rights; and (iv) corrective actions initially implemented.
Coordination. Immediately following Service Provider’s notification to Company of a Security Incident, the Parties will coordinate with each other, as necessary, to investigate the Security Incident and Service Provider will take actions as may be required under Applicable Privacy Laws in remediating the impacts of the Security Incident and meeting all of its obligations under such Applicable Privacy Laws.
Communication. If and to the extent Company is referenced by name in any notification, public/regulatory communication or press release concerning a Security Incident, Company shall be provided with an opportunity to review and approve the communication for accuracy, with such approval not to be unreasonably withheld.
Return or Disposal of Personal Information. At any time during the term of this Addendum at Company’s written request or on the termination or expiration of the Agreement, Service Provider will promptly return to Company or securely dispose of all Personal Information in its possession and notify Company that such Personal Information has been returned to Company or disposed of securely. If Service Provider is not reasonably able to return or securely dispose of Personal Information, including, but not limited to, Personal Information stored on backup media, Service Provider will continue to protect such Personal Information in accordance with the terms of this Addendum until such time that it can reasonably return or securely dispose of such Personal Information.
Subcontractors. Company hereby expressly consents to Service Provider engaging Subcontractors to Process Personal Information provided that:
- Upon request from Company to Service Provider, Service Provider provides Company with a list of all Subcontractors engaged to Process Personal Information on Service Provider’s behalf;
- Service Provider provides at least 15 days’ prior notice to Company of the engagement of any new Subcontractor;
- Service Provider imposes data protection terms on any Subcontractor it engages no less protective as the terms contained in this Addendum; and
- Service Provider remains fully liable for any breach of this Addendum or the Agreement that is caused by an act, error, or omission of such Subcontractor.
In the event of any conflicts between the Agreement and this Addendum as it relates to the Processing of Personal Information, this Addendum shall govern. The Parties acknowledge that Applicable Privacy Laws are subject to change. This Addendum may be amended by the Service Provider as necessary to comply with changes in Applicable Privacy Laws.
Should any provisions of this Addendum be invalid or unenforceable, then the remainder of this Addendum shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the Parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained herein.
This Addendum shall expire upon the later of (a) the termination of the Agreement, (b) cessation of any processing of Personal Information by Service Provider on behalf of Company pursuant to the provision of the Services, or (c) delivery of written notice of termination of the Agreement from one Party to the other.
SCHEDULE A
Purpose of Processing:
To provide the Services under the RecruitTune Terms of Service.
Categories of Data Subjects:
Employees, agents, contractors, and other Authorized Users of Company.
Categories of Personal Information
Identification and contact data (name, address, email, title, contact details).
Employment details and administrative data (employer, job title, and other job description information).
Candidate information relating to their assessments.
Sensitive Personal Information:
None
Frequency of Processing:
The Personal Information is processed on a continuous basis from Company to Service Provider to provide the Services.