This Data Processing Agreement ("DPA") forms part of the agreement between DimeRepublic ("Processor") and the client ("Controller") for the provision of services. This DPA sets out the terms governing the processing of personal data by the Processor on behalf of the Controller and reflects the requirements of applicable data protection laws, including the General Data Protection Regulation (GDPR) (EU Regulation 2016/679). This DPA takes precedence over any conflicting terms in the underlying service agreement.
1. Definitions
For the purposes of this DPA, the following terms shall have the meanings set forth below:
- "Controller" means the entity that determines the purposes and means of the processing of personal data, as defined in GDPR Article 4(7).
- "Processor" means the entity that processes personal data on behalf of the Controller, as defined in GDPR Article 4(8).
- "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject"), as defined in GDPR Article 4(1).
- "Processing" means any operation or set of operations performed on personal data, as defined in GDPR Article 4(2).
- "Data Subject" means an identified or identifiable natural person whose personal data is processed.
- "Sub-processor" means any processor engaged by the Processor to assist in processing personal data on behalf of the Controller.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
- "Supervisory Authority" means an independent public authority established by an EU member state pursuant to GDPR Article 51.
- "Applicable Data Protection Law" means all laws and regulations applicable to the processing of personal data under this DPA, including GDPR and any national implementing legislation.
2. Scope and Purpose
This DPA applies to all personal data processed by DimeRepublic on behalf of the Controller in connection with the services provided under the underlying service agreement. The Processor shall process personal data only in accordance with the Controller's documented instructions, unless required to do otherwise by applicable law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
3. Data Processing Terms
The specific details of the data processing activities are as follows:
- Nature and Purpose of Processing: The Processor processes personal data for the purpose of providing talent acquisition, staffing solutions, payroll management, performance monitoring, communication, and related administrative services as specified in the underlying service agreement.
- Categories of Data Subjects: The personal data processed under this DPA concerns the following categories of data subjects: (a) the Controller's employees, contractors, and representatives; (b) candidates and applicants for positions sourced through the Processor's services; (c) the Controller's customers, clients, and end users (where applicable); and (d) any other individuals whose data is provided to the Processor by or on behalf of the Controller.
- Types of Personal Data: The Processor may process the following categories of personal data: names, email addresses, phone numbers, postal addresses, job titles, employment history, educational background, professional qualifications, performance evaluations, compensation and benefits information, tax and financial information, identification documents (such as passports and national ID numbers), IP addresses, and any other data provided by the Controller as necessary for the services.
- Sensitive Data: The Processor does not intentionally process special categories of data (as defined in GDPR Article 9) or criminal conviction data (as defined in Article 10). If the Controller provides such data, it must explicitly notify the Processor and specify the applicable conditions for processing.
- Duration of Processing: Personal data shall be processed for the duration of the underlying service agreement and retained thereafter in accordance with the Controller's documented retention and deletion instructions, or as required by applicable law.
4. Security Measures
The Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk presented by the processing, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. The Processor's security measures include, but are not limited to:
- Encryption: Encryption of personal data at rest using AES-256 encryption and in transit using TLS 1.2 or higher protocols. All data transmitted between systems is protected by industry-standard encryption.
- Access Controls: Strict role-based access controls implementing the principle of least privilege. Multi-factor authentication (MFA) is required for all administrative access to systems processing personal data. Access is reviewed and audited on a quarterly basis.
- Network Security: Firewalls, intrusion detection and prevention systems (IDPS), and network segmentation to protect against unauthorized network access. Regular vulnerability scans and penetration tests are conducted by independent third-party security firms.
- Data Backup and Recovery: Automated daily backups of all personal data with encrypted storage. Backup restoration is tested quarterly to ensure data availability and integrity. Disaster recovery and business continuity plans are documented and tested annually.
- Employee Training: All employees and contractors with access to personal data receive mandatory data protection and information security training upon hire and annually thereafter. Training covers data handling procedures, breach reporting, and confidentiality obligations.
- Physical Security: Data center facilities and office premises are protected by biometric access controls, 24/7 video surveillance, and security personnel. Access is granted only to authorized personnel.
- Incident Response: A documented incident response plan is in place to detect, contain, investigate, and remediate security incidents. The plan is reviewed and updated at least annually.
- Logging and Monitoring: Comprehensive logging of all access to and processing of personal data, with automated monitoring and alerting for suspicious activities. Logs are retained for a minimum of 12 months.
5. Sub-processing
The Controller provides general authorization to the Processor to engage sub-processors for the provision of services. The Processor shall maintain an up-to-date list of authorized sub-processors and shall notify the Controller of any intended changes concerning the addition or replacement of sub-processors at least 30 days prior to the change. The Controller may object to the engagement of a new sub-processor within 15 days of receipt of such notice on reasonable grounds relating to data protection. If the Controller objects and the objection is not resolved, either party may terminate the affected services. The Processor's current sub-processors include:
- Amazon Web Services (AWS) – Cloud infrastructure and data hosting (eu-west-1 region).
- Google Cloud Platform (GCP) – Cloud infrastructure and data storage.
- HubSpot – CRM, marketing automation, and contact management.
- Slack Technologies – Internal communication and collaboration.
- Zoom Video Communications – Video conferencing and meeting recording.
- Stripe – Payment processing and billing.
- PayPal – Payment processing.
- SendGrid (Twilio) – Email delivery and notification services.
- Deel – Payroll management and contractor compliance.
The Processor shall enter into written agreements with all sub-processors that impose data protection obligations no less protective than those set forth in this DPA. The Processor remains fully liable to the Controller for the performance of its sub-processors' obligations.
6. Data Subject Rights
The Processor shall provide reasonable assistance to the Controller in fulfilling its obligations to respond to data subjects' requests to exercise their rights under applicable data protection laws. The Processor shall:
- Promptly notify the Controller (within 3 business days) if it receives a request from a data subject to exercise any of the following rights: right of access, rectification, erasure, restriction of processing, data portability, objection to processing, or any other rights under applicable law.
- Not respond to any data subject request on behalf of the Controller without the Controller's prior written authorization, except to acknowledge receipt or inform the data subject that the request has been forwarded to the Controller.
- Provide the Controller with the tools, information, and assistance necessary to enable the Controller to respond to data subject requests within the timeframes required by applicable data protection laws (typically 30 days, extendable by up to 60 days for complex requests).
- Implement technical and organizational measures to facilitate the Controller's compliance with data subject requests, including the ability to access, rectify, restrict, export, and delete personal data.
7. Breach Notification
The Processor shall implement and maintain procedures for detecting, investigating, and reporting personal data breaches. In the event of a personal data breach affecting Controller data, the Processor shall:
- Notify the Controller without undue delay and in any event within 48 hours of becoming aware of the breach. The notification shall include, to the extent available: (a) a description of the nature of the breach; (b) the categories and approximate number of data subjects and personal data records affected; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address the breach.
- Provide periodic updates to the Controller as the investigation progresses and additional information becomes available.
- Cooperate fully with the Controller in investigating the breach, mitigating its effects, and preparing notifications to affected data subjects and supervisory authorities.
- Not make any public statements or notifications regarding the breach without the Controller's prior written consent, unless required by applicable law.
- Maintain a documented record of all personal data breaches, including the facts surrounding the breach, its effects, and the remedial actions taken.
8. Compliance, Audits, and Records
The Processor shall maintain a written record of all categories of processing activities conducted on behalf of the Controller, as required by GDPR Article 30. The Processor shall:
- Maintain records documenting compliance with this DPA, including processing inventories, security measures, and sub-processor agreements.
- Upon the Controller's reasonable request and no more than once per calendar year (unless a breach or regulatory investigation necessitates more frequent audits), make available information necessary to demonstrate compliance with this DPA.
- Allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller. Any such audit shall be conducted with reasonable notice (at least 30 days), during normal business hours, and at the Controller's expense, unless the audit reveals material non-compliance by the Processor, in which case the Processor shall bear the cost.
- Provide access to relevant systems, facilities, personnel, and documentation as reasonably necessary for the audit, subject to confidentiality and security requirements.
9. International Transfers
Personal data may be transferred to and processed in countries where the Processor or its sub-processors maintain facilities, including the United States, Pakistan, and other jurisdictions. The Processor shall ensure that any international transfer of personal data from the European Economic Area (EEA), Switzerland, or the United Kingdom to a country that has not been deemed adequate by the European Commission is governed by appropriate safeguards, including:
- Standard Contractual Clauses (SCCs): The Processor shall enter into the European Commission's Standard Contractual Clauses (Module 2 for Controller-to-Processor and Module 3 for Processor-to-Processor transfers, as applicable) with any party that receives personal data from the EEA in a non-adequate country.
- Data Processing Agreements: Comprehensive data processing agreements incorporating SCC requirements shall be executed with all sub-processors.
- Transfer Impact Assessments: The Processor shall conduct transfer impact assessments (TIAs) for all restricted transfers and implement supplementary measures where necessary to ensure an essentially equivalent level of protection.
Upon the Controller's request, the Processor shall provide copies of the applicable safeguards and evidence that they provide an adequate level of data protection.
10. Termination and Data Return
Upon termination or expiration of the underlying service agreement, or upon the Controller's written request at any time, the Processor shall, at the Controller's option:
- Return: Provide the Controller with a complete copy of all personal data in a structured, commonly used, and machine-readable format (such as CSV or JSON) within 30 calendar days of the request.
- Delete: Securely delete or destroy all copies of personal data processed on behalf of the Controller, including from backup systems, within 90 calendar days of the request or termination date, except to the extent retention is required by applicable law.
- Certification: Upon completion of the deletion process, the Processor shall provide the Controller with a written certification that all personal data has been deleted from its systems and the systems of its sub-processors.
The Processor may retain personal data to the extent required by applicable law, provided that the Processor continues to protect such data in accordance with this DPA and processes it only for the purpose of legal compliance.
11. Limitation of Liability
The liability of each party under this DPA shall be subject to the limitations of liability set forth in the underlying service agreement. However, neither party's liability for: (a) breach of its obligations under GDPR Articles 28 (Processor), 32 (Security), or 33/34 (Breach Notification); (b) its indemnification obligations; or (c) its breach of confidentiality shall be limited or excluded to the extent such limitation or exclusion is prohibited by law. In all cases, liability under this DPA shall be subject to the cap set forth in the underlying service agreement.
12. Governing Law and Jurisdiction
This DPA shall be governed by and construed in accordance with the laws of the State of Georgia, USA, without regard to its conflict of law principles. Any disputes arising from this DPA that cannot be resolved through negotiation shall be resolved in accordance with the dispute resolution provisions of the underlying service agreement. This DPA does not override the mandatory data protection laws of the EEA member states where the Controller is established.
13. Contact
For questions about this DPA or to submit a data subject request or breach notification, please contact: