This Data Processing Agreement (“DPA”) governs how Penroll processes personal data on behalf of Customers in the course of providing the Penroll service. It forms part of the Terms of Service. If anything in this DPA conflicts with the Terms of Service, this DPA wins for the subject of personal-data processing.
1. Roles
For data the Customer or its candidates submit to Penroll — recruiter accounts, candidate CVs, screening answers, offer letters, and any other content created in the dashboard — the Customer acts as the data Controller and Penroll acts as the Processor. Penroll processes the data only on documented instructions from the Customer, which instructions are reflected in the configuration of the Customer’s workspace.
2. Scope and duration
Processing under this DPA continues for as long as the Customer uses Penroll. Upon termination, candidate data is retained for the period set out in the Privacy Policy (normally 24 months for unsuccessful candidates, or 4 years where the candidate explicitly opts in to future-role consideration) and then deleted from production storage. Backups expire on a 30-day rolling window.
3. Categories of data
- Recruiter accounts: name, email, role, billing arrangement, package purchase records, audit logs.
- Candidate applications: applicant name, email, CV file, parsed CV text, screening answers, AI ranking output, interview details, offer letters, and the candidate’s consent record.
- Operational telemetry: error logs, rate-limit counters, audit-trail entries. No candidate data in plain text.
4. Sub-processors
Penroll engages the sub-processors listed at /legal/sub-processors. We inform Customers by email at least 30 days before adding a new sub-processor. Customers may object in writing on reasonable grounds during the notice period; we will work in good faith to find an acceptable alternative.
5. Security measures
- EU-resident production database (Supabase EU region).
- Row-level security enforced at the database layer so a compromised application credential cannot read another tenant’s data.
- TLS 1.2+ for all data in transit; AES-256 at rest.
- Per-user AI rate limits on every model-calling endpoint.
- Cloudflare in front of the application stack for DDoS mitigation, WAF, and bot management.
- Production access restricted to named operators; access is revoked within 24 hours of an operator leaving.
6. International transfers
Personal data is stored on EU-resident infrastructure. Where a sub-processor operates outside the EU (e.g. AI model providers located in the US), the transfer is governed by the European Commission’s Standard Contractual Clauses (SCCs) and additional technical safeguards (prompt redaction, data minimisation).
7. Breach notification
Penroll will notify affected Customers without undue delay — and in any event within 72 hours — of becoming aware of a personal data breach. The notification will include the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and the measures we have taken or propose to take.
8. Data subject rights
Penroll provides tools in the dashboard for Customers to fulfil their obligations under GDPR Articles 15–22 (access, erasure, rectification, portability, objection). Where a Customer cannot self-serve a request, Penroll will assist within 30 days of a written request to privacy@penroll.app.
9. Audits
The Customer may audit Penroll’s compliance with this DPA once per calendar year on 30 days’ written notice. Audits may take the form of an on-site visit, a written questionnaire, or review of a third-party audit report where available. Penroll bears its own costs; reasonable costs of an auditor engaged by the Customer are borne by the Customer.
10. Signing
This DPA enters into force when both parties accept the Penroll Terms of Service. Where a wet-ink signature is required for procurement purposes, request a signed copy at privacy@penroll.app.
This DPA is a template document. For complex deployments — healthcare, regulated industries, public-sector procurement — please get in touch to negotiate a bespoke agreement.