Skip to content
Penroll
← Legal

Data Processing Agreement

Version: v1.0 · 2026-05-14

Download PDF

This Data Processing Agreement (“DPA”) governs how Penroll processes personal data on behalf of Customers in the course of providing the Penroll service. It forms part of the Terms of Service. If anything in this DPA conflicts with the Terms of Service, this DPA wins for the subject of personal-data processing.

1. Roles

For data the Customer or its candidates submit to Penroll — recruiter accounts, candidate CVs, screening answers, offer letters, and any other content created in the dashboard — the Customer acts as the data Controller and Penroll acts as the Processor. Penroll processes the data only on documented instructions from the Customer, which instructions are reflected in the configuration of the Customer’s workspace.

2. Scope and duration

Processing under this DPA continues for as long as the Customer uses Penroll. Upon termination, candidate data is retained for the period set out in the Privacy Policy (normally 24 months for unsuccessful candidates, or 4 years where the candidate explicitly opts in to future-role consideration) and then deleted from production storage. Backups expire on a 30-day rolling window.

3. Categories of data

4. Sub-processors

Penroll engages the sub-processors listed at /legal/sub-processors. We inform Customers by email at least 30 days before adding a new sub-processor. Customers may object in writing on reasonable grounds during the notice period; we will work in good faith to find an acceptable alternative.

5. Security measures

6. International transfers

Personal data is stored on EU-resident infrastructure. Where a sub-processor operates outside the EU (e.g. AI model providers located in the US), the transfer is governed by the European Commission’s Standard Contractual Clauses (SCCs) and additional technical safeguards (prompt redaction, data minimisation).

7. Breach notification

Penroll will notify affected Customers without undue delay — and in any event within 72 hours — of becoming aware of a personal data breach. The notification will include the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and the measures we have taken or propose to take.

8. Data subject rights

Penroll provides tools in the dashboard for Customers to fulfil their obligations under GDPR Articles 15–22 (access, erasure, rectification, portability, objection). Where a Customer cannot self-serve a request, Penroll will assist within 30 days of a written request to privacy@penroll.app.

9. Audits

The Customer may audit Penroll’s compliance with this DPA once per calendar year on 30 days’ written notice. Audits may take the form of an on-site visit, a written questionnaire, or review of a third-party audit report where available. Penroll bears its own costs; reasonable costs of an auditor engaged by the Customer are borne by the Customer.

10. Signing

This DPA enters into force when both parties accept the Penroll Terms of Service. Where a wet-ink signature is required for procurement purposes, request a signed copy at privacy@penroll.app.

This DPA is a template document. For complex deployments — healthcare, regulated industries, public-sector procurement — please get in touch to negotiate a bespoke agreement.

Data Processing Agreement — Penroll