Recruitcha GTM

Data Processing Addendum

Exhibit A to the Terms of Service. Effective as of August 31, 2026.

This Data Processing Addendum (the “DPA”) is entered into by and between Recruitcha, Inc (“Provider”) and the Customer identified in the Terms of Service (the “Agreement”) and forms Exhibit A to the Agreement. This DPA is incorporated into the Agreement by reference. If there is a conflict between this DPA and the remainder of the Agreement with respect to the processing of Personal Data, this DPA controls.

This DPA applies to the extent Provider processes Customer Personal Data in the course of providing the Services. Processing that Provider performs as an independent controller (including sourcing, caching, and maintaining job-posting and business-contact information as described in the Privacy Policy) is governed by the Privacy Policy, not this DPA.

1. Definitions

Capitalized terms not defined in this DPA have the meaning given in the Agreement. In this DPA:

  • “Applicable Data Protection Law” means all Laws applicable to the processing of Personal Data under this DPA, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA (“CCPA”), and other U.S. state consumer privacy laws, in each case as applicable.
  • “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “processing”, and “Supervisory Authority” have the meanings given in the GDPR (or the analogous terms under other Applicable Data Protection Law, including “Business” and “Service Provider” / “Contractor” under the CCPA).
  • “Customer Personal Data” means Personal Data that Provider processes on behalf of Customer in providing the Services, including: (i) data submitted, uploaded, or imported by or on behalf of Customer; (ii) data retrieved from Third-Party Platforms that Customer connects; and (iii) business-contact and related records stored in Customer’s account (including enriched hiring-manager and prospect records once delivered into the Services for that Customer). Customer Personal Data does not include Provider Data.
  • “GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the GDPR as it forms part of the law of the United Kingdom.
  • “Provider Data” means job-posting information, professional-profile information, and business-contact information that Provider sources, caches, or maintains independently (including from data partners, publicly available sources, and Provider’s operational warehouses) in order to operate and provide the Services generally, as described in the Privacy Policy.
  • “Standard Contractual Clauses” or “SCCs” means the contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914.
  • “Sub-processor” means a Processor engaged by Provider to process Customer Personal Data.

2. Roles of the Parties

2.1. Customer as Controller; Provider as Processor

For Customer Personal Data, Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Provider is the Processor (or a sub-processor). Customer is solely responsible for determining the purposes of processing Customer Personal Data, including outreach, marketing, and recruiting uses, and for ensuring that it has a lawful basis and all required notices, consents, and rights under Applicable Data Protection Law.

2.2. Provider as Controller of Provider Data

Provider is an independent Controller of Provider Data, including operational caches of job postings and business contacts used to discover hiring signals and return enrichment results. When Provider delivers a copy of Provider Data into Customer’s account, that copy becomes Customer Personal Data and is thereafter processed under this DPA. Customer is the Controller of its subsequent use of that copy, including any outreach.

2.3. No Sensitive Personal Information

Customer will not instruct Provider to process Sensitive Personal Information (as defined in the Agreement). Provider has no obligation to monitor Customer Personal Data to determine whether it includes Sensitive Personal Information.

3. Provider Obligations

3.1. Instructions

Provider will process Customer Personal Data only: (a) to provide, maintain, and improve the Services; (b) in accordance with the Agreement, this DPA, and Customer’s documented instructions (including configuration of campaigns, exports, and connected Third-Party Platforms); and (c) as required by Laws, in which case Provider will notify Customer unless legally prohibited. The Agreement and Customer’s use of the Services constitute Customer’s documented instructions. Provider will notify Customer without undue delay if, in Provider’s opinion, an instruction infringes Applicable Data Protection Law.

3.2. Confidentiality

Provider will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations and process it only as required to perform their duties.

3.3. Security

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Provider will implement the technical and organizational measures described in Schedule B (the “Security Policy” referenced in Section 4 of the Agreement). Customer is responsible for securing its accounts, credentials, and any Customer Personal Data it exports from the Services.

3.4. Assistance

Taking into account the nature of the processing, Provider will provide reasonable assistance to Customer, at Customer’s expense if the assistance is not reasonably provided as part of the Services, in: (a) responding to Data Subject requests; (b) implementing appropriate security measures; (c) notifying Personal Data Breaches; and (d) conducting data-protection impact assessments and prior consultations with Supervisory Authorities, in each case solely to the extent required of a Processor under Applicable Data Protection Law and relating to Customer Personal Data.

3.5. Personal Data Breach

Provider will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will include information then reasonably available to Provider to help Customer meet its own notification obligations. Provider will take reasonable steps to contain, investigate, and remediate the incident. Provider’s notification is not an admission of fault or liability.

3.6. Return and Deletion

Upon termination or expiration of the Agreement, Provider will, at Customer’s election communicated within thirty (30) days, delete or return Customer Personal Data, except that Provider may retain copies: (a) as required by Laws; (b) in routine backup systems for a limited period, isolated from further processing; or (c) as Provider Data that Provider processes as an independent Controller under the Privacy Policy. As stated in Section 8.3 of the Agreement, Customer should export any Customer Data it wishes to retain before termination; Provider may delete stored Customer Personal Data any time after that thirty (30) day period.

3.7. Audits

Upon written request not more than once per twelve (12) month period (unless a Supervisory Authority or a confirmed Personal Data Breach reasonably requires more), Provider will make available information reasonably necessary to demonstrate compliance with this DPA, which may include responses to a security questionnaire and summaries of relevant policies. On-site audits are permitted only if required by Applicable Data Protection Law and not reasonably satisfied by the foregoing, on at least thirty (30) days’ notice, during normal business hours, without unreasonably disrupting operations, and at Customer’s expense. Audits are subject to confidentiality and may not include access to other customers’ data or to Provider Data processed as Controller.

4. Customer Obligations

Customer represents and warrants that:

  • It has provided all notices and obtained all consents, permissions, and lawful bases required for Provider to process Customer Personal Data as contemplated by the Agreement, including enrichment, storage, and export to Third-Party Platforms Customer enables.
  • Its instructions comply with Applicable Data Protection Law, including anti-spam, ePrivacy, CAN-SPAM, CASL, and similar Laws governing electronic marketing and outreach.
  • It will not use the Services to process Sensitive Personal Information or to collect Personal Data of children.
  • If it is a Processor for a third-party Controller, it is authorized to appoint Provider as a sub-processor and to enter into this DPA on that Controller’s behalf.

5. Sub-processors

Customer authorizes Provider to engage Sub-processors to process Customer Personal Data. Current material Sub-processors are listed in Schedule C. Provider will impose data-protection terms on each Sub-processor that are no less protective of Customer Personal Data than this DPA, and remains responsible for each Sub-processor’s performance of its obligations.

Provider will provide notice of a new category of Sub-processor by updating Schedule C or otherwise notifying Customer (including via the Services or email) at least fifteen (15) days before processing in that category begins, except where sooner engagement is reasonably required for security, legal, or operational reasons, in which case Provider will notify Customer as soon as practicable. Substitutions of a specific vendor within an authorized category do not require a public update. Upon written request, Provider will identify then-current Sub-processors to Customer subject to confidentiality. Customer may object to a new category on reasonable data-protection grounds within fifteen (15) days of notice. If the parties cannot resolve the objection, Customer may terminate the affected Services as its sole remedy.

Third-Party Platforms that Customer elects to connect or export to (for example, a Customer-owned email, professional-network, CRM, ATS, or similar account) process Customer Personal Data as Customer’s processors or independent controllers, not as Provider’s Sub-processors, except to the extent Provider itself operates or provisions that integration as part of the Services.

6. International Transfers

Provider is established in the United States and processes Customer Personal Data in the United States and in other countries where Provider or its Sub-processors operate. Where a transfer of Customer Personal Data from the EEA, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection requires a transfer mechanism, the following apply:

  • EEA transfers. The SCCs, Module Two (Controller to Processor), are incorporated by reference. If Customer is itself a Processor, Module Three (Processor to Processor) applies instead. For Module Two or Three: Clause 7 (docking) is omitted; Clause 9(a) option 2 (general written authorization) applies with the notice period in Section 5 of this DPA; Clause 11(a) (optional independent redress) is omitted; Clause 17 option 1 (governing law of an EU Member State) is the law of Ireland; Clause 18(b) courts are the courts of Ireland. Annex I is completed by Schedule A, Annex II by Schedule B, and Annex III by Schedule C. The data exporter is Customer; the data importer is Provider.
  • UK transfers. The International Data Transfer Addendum issued by the UK Information Commissioner’s Office (version B1.0, in force 21 March 2022) is incorporated by reference, completed using the information in the Schedules, with the SCCs as the referenced clauses.
  • Swiss transfers. The SCCs are adapted as required by the Swiss Federal Data Protection and Information Commissioner, including references to Switzerland and the FADP where applicable.

If a transfer mechanism is amended, replaced, or invalidated, the parties will cooperate in good faith to implement a valid successor mechanism.

7. CCPA and U.S. State Privacy Laws

To the extent the CCPA or another U.S. state consumer privacy law applies to Customer Personal Data, Provider will process that data as a Service Provider or Contractor (or the analogous role). Provider will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data except to provide the Services, for the business purposes specified in the Agreement, or as otherwise permitted by those laws; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer; or (d) combine Customer Personal Data with personal information received from or on behalf of another person, except as permitted for a Service Provider (including to detect security incidents, protect against fraud, or perform the Services). Provider will comply with applicable restrictions on Service Providers and will notify Customer if Provider determines it can no longer meet its obligations. Customer may take reasonable and appropriate steps to ensure Provider processes Customer Personal Data consistent with Customer’s obligations, including remediation as required by law.

This Section 7 does not restrict Provider’s independent Controller processing of Provider Data as described in the Privacy Policy.

8. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent prohibited by Applicable Data Protection Law. Provider’s processing of Provider Data as Controller is not subject to this DPA’s Processor obligations.

9. General

Provider may update this DPA as described in Section 16.7 of the Agreement, provided that updates may not materially reduce the level of protection of Customer Personal Data. This DPA survives termination of the Agreement until Provider has deleted or returned Customer Personal Data as required herein.

Schedule A — Details of Processing

A.1 Subject matter and duration

Processing of Customer Personal Data to provide the Services (hiring-signal discovery, company qualification, hiring-manager and prospect identification and enrichment, campaign storage, and export to Customer-authorized destinations) for the Subscription Term and the post-termination period in Section 3.6.

A.2 Nature and purpose

Collection, storage, organization, retrieval, enrichment (including queries to data partners), analysis, disclosure by transmission to Sub-processors and Customer-authorized destinations, and deletion.

A.3 Types of Customer Personal Data

  • Customer personnel: name, work email, title, company, authentication identifiers, billing information, and usage data.
  • Hiring managers, prospects, and similar business contacts in Customer’s campaigns: name, title, company, work email, phone number, professional-profile URL, location, photo, and related enrichment records.
  • Job-posting and company information associated with those contacts, and campaign, messaging, and export metadata.
  • Data Customer retrieves from connected Third-Party Platforms (for example, professional-network session data needed to operate a connected seat).

Provider does not intend to process special-category data. Phone numbers may be stored even though the Services do not send SMS.

A.4 Categories of Data Subjects

  • Customer’s Permitted Users and other Customer personnel.
  • Hiring managers, recruiters, executives, and other business contacts identified or enriched through the Services.
  • Individuals whose data Customer uploads or imports (for example, custom lists).

A.5 Frequency and retention

Continuous or batch processing for as long as Customer uses the Services. Campaign and lead records are retained for the Subscription Term and deleted in accordance with Section 3.6. Operational Provider Data caches are retained as described in the Privacy Policy.

Schedule B — Technical and Organizational Measures

Provider maintains the following measures, which may be updated as practices evolve, provided the overall level of protection is not materially reduced:

  • Access control. Access to Customer Personal Data is limited to personnel with a need to know. Unique user credentials and role-based access are used for production systems. Customer accounts are authenticated; Customers are responsible for user provisioning and password confidentiality.
  • Encryption in transit. Network connections to the Services use TLS. Data at rest is stored using encryption implemented by Provider’s hosting providers.
  • Infrastructure. Production databases and application hosting are provided by reputable cloud providers. Provider relies on those providers’ physical and environmental controls.
  • Least privilege and confidentiality. Personnel are subject to confidentiality obligations. Production access is restricted.
  • Application security. The Services are designed so that Customer workspaces are logically separated. Sensitive Personal Information is contractually prohibited.
  • Logging and monitoring. Provider uses application monitoring and error reporting to detect operational and security issues.
  • Backup and availability. Hosting providers perform routine backups. Provider uses commercially reasonable efforts to keep the Services available, as stated in the Agreement.
  • Vendor management. Sub-processors are engaged under written terms requiring appropriate protection of Customer Personal Data.
  • Incident response. Provider maintains processes to investigate, contain, and notify relevant incidents affecting Customer Personal Data as described in Section 3.5.

Schedule C — Sub-processors

Provider may use the following categories of Sub-processors. Specific vendors within a category may be replaced in accordance with Section 5 and are not listed publicly. Customer-authorized destinations that Customer connects with its own credentials are not Provider Sub-processors except as noted in Section 5.

  • Cloud infrastructure — database, authentication, application hosting, content delivery, background compute, and related backend infrastructure, including operational warehouses used to provide the Services.
  • Payments — payment processing and billing.
  • Enrichment and discovery — professional-profile and people-search, work-email and phone enrichment, data-collection workflows, and job-posting feeds used for hiring-signal discovery.
  • AI providers — large-language-model processing of prompts and related content to classify jobs, generate copy, and operate product features.
  • Outreach and connectivity — email delivery and professional-network connectivity or messaging when Provider provisions or transmits campaigns on Customer’s instructions.
  • Operations — application error monitoring and similar operational tooling.

Additional email, professional-network, CRM, ATS, and spreadsheet destinations process Customer Personal Data when Customer enables them. Those providers are Customer’s processors or independent controllers unless Provider operates the integration as part of the Services.

Contact

Data-protection inquiries: legal@recruitcha.com

Recruitcha, Inc
3637 Fillmore Street
San Francisco, CA 94123

© 2026 Recruitcha, Inc. All rights reserved.

Terms of ServicePrivacy PolicyDPA