Data Processing Agreement
Formal data processing terms for customers requiring GDPR compliance
Legal Notice for Enterprise Customers
This Data Processing Agreement (DPA) is incorporated into and forms part of the ResumeAI Terms of Service. It applies where ResumeAI processes Personal Data on behalf of Customer as a Processor under GDPR and other data protection laws.
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the ResumeAI Terms of Service (the "Agreement") between Customer and ResumeAI. This DPA reflects the parties' agreement with respect to the terms governing the processing of personal data under the Agreement.
This DPA is effective as of the Effective Date and replaces any previously applicable data processing agreement.
Definitions
This Data Processing Agreement (DPA) reflects the parties' agreement with respect to the terms governing the processing of personal data under the ResumeAI Terms of Service.
- •Controller: The entity which determines the purposes and means of the processing of Personal Data
- •Processor: The entity which processes Personal Data on behalf of the Controller
- •Data Subject: An identified or identifiable natural person
- •Personal Data: Any information relating to an identified or identifiable natural person
- •Processing: Any operation performed on Personal Data
- •Subprocessor: Any third party engaged by the Processor to process Personal Data
Processing Details
The parties agree that with regard to the processing of Personal Data, Customer is the Controller and ResumeAI is the Processor.
- •Subject Matter: Provision of AI-powered resume building and career services
- •Duration: For the term of the Customer's subscription to the Services
- •Nature and Purpose: Processing necessary to provide the contracted Services
- •Types of Personal Data: Name, contact information, professional history, education, skills, and other resume-related data
- •Categories of Data Subjects: Customers and their authorized users
Processor Obligations
ResumeAI shall process Personal Data only on documented instructions from Customer, unless required to do so by applicable law.
- •Process Personal Data only in accordance with Customer's documented instructions
- •Ensure that persons authorized to process Personal Data have committed themselves to confidentiality
- •Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk
- •Assist Customer in ensuring compliance with Data Subject rights obligations
- •Make available to Customer all information necessary to demonstrate compliance
Subprocessing
Customer provides a general authorization for ResumeAI to engage Subprocessors. ResumeAI shall inform Customer of any intended changes concerning the addition or replacement of Subprocessors.
- •ResumeAI shall impose data protection terms on any Subprocessor it engages
- •Customer may object to Subprocessor appointments on reasonable grounds relating to data protection
- •Current Subprocessors include AWS (cloud infrastructure), Google Analytics (analytics), and SendGrid (email delivery)
- •ResumeAI remains liable for Subprocessor breaches
Data Subject Rights
ResumeAI shall assist Customer in responding to requests from Data Subjects to exercise their rights under applicable data protection laws.
- •Implement technical and organizational measures to assist with Data Subject requests
- •Promptly notify Customer if it receives a request from a Data Subject
- •Provide Customer with the ability to correct, delete, or restrict processing of Personal Data
- •Assist Customer in data portability requests where feasible
Security Measures
ResumeAI shall implement and maintain appropriate technical and organizational security measures to protect Personal Data.
- •Encryption of Personal Data in transit and at rest
- •Measures for ensuring ongoing confidentiality, integrity, and resilience
- •Processes for regularly testing and evaluating the effectiveness of security measures
- •Measures for user identification and authorization
- •Physical access controls to facilities containing Personal Data
Personal Data Breach
ResumeAI shall notify Customer without undue delay upon becoming aware of a Personal Data breach.
- •Provide information to allow Customer to meet breach notification obligations
- •Include details of the breach, categories of data affected, and approximate number of Data Subjects
- •Describe likely consequences of the breach and measures taken to address it
- •Cooperate with Customer and provide reasonable assistance in investigating the breach
International Data Transfers
ResumeAI shall ensure that international transfers of Personal Data are subject to appropriate safeguards.
- •Use of EU Standard Contractual Clauses for transfers outside the EEA
- •Implementation of supplementary measures where required
- •Compliance with local data protection laws in jurisdictions where processing occurs
- •Transparency regarding data storage locations and transfer mechanisms
Audit Rights
Customer may audit ResumeAI's compliance with this DPA once per year and in case of a Personal Data breach.
- •Audits must be conducted during normal business hours with reasonable notice
- •Customer may request ResumeAI's most recent third-party audit reports
- •ResumeAI shall provide reasonable cooperation and access to relevant information
- •Audit costs shall be borne by Customer, except where material non-compliance is found
Return and Deletion of Data
Upon termination of the Services, ResumeAI shall delete or return all Personal Data to Customer.
- •Deletion shall occur within 30 days of termination, unless storage is required by law
- •Customer may export their data at any time during the subscription term
- •Backup data shall be deleted in accordance with ResumeAI's data retention policies
- •Confirmation of deletion shall be provided to Customer upon request
DPA Execution
This DPA is pre-signed on behalf of ResumeAI. To complete this DPA, Customer must complete the information below and send the completed and signed DPA to ResumeAI by email to legal@resumeai.com.
On behalf of ResumeAI:
Name: Sarah Chen
Title: CEO
Signature: [Electronic Signature]
Date: January 15, 2024
On behalf of Customer:
Name: ___________________
Title: ___________________
Signature: ___________________
Date: ___________________
Questions About This DPA?
For questions about this Data Processing Agreement or to request a signed copy, please contact our legal team.
⚖️Contact Legal Team