Legal · Employers
Data Processing Agreement
The contractual terms governing how Simonara processes personal data on behalf of employer customers. Applicable to every paid workspace — countersigned copies available on request. Version 2026-02-15.
Request a counter-signed DPA1.Parties & scope
This Data Processing Agreement ("DPA") is entered into between the employer customer identified in the applicable order form ("Controller") and Simonara Talent Solutions, LLC ("Processor") and forms part of the underlying Simonara Terms of Service.
It governs Processor's processing of Personal Data on behalf of the Controller in the course of providing the Simonara Talent Solutions platform.
2.Processing purpose
Processor will process Personal Data solely to:
- Operate the Simonara platform for the Controller (posting jobs, receiving applications, AI matching, background verification workflows, communications).
- Deliver features Controller has purchased or activated.
- Provide customer support at Controller's request.
- Comply with the DPA, the Terms of Service, and applicable law.
No secondary use for advertising, training third-party AI, or data brokering.
3.Categories of data & data subjects
Data subjects: Controller's employees + hiring team, and candidates who apply to Controller's roles.
Data types: contact identifiers (name, email, phone), professional history (resume, employment, references), authentication credentials, technical identifiers (IP, device ID), communications between Controller and candidates, and — with explicit candidate consent — background verification results.
4.Security measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control; production access limited to on-call engineers.
- Secrets isolated in a KMS-backed vault; no plaintext keys in code or environment dumps.
- Continuous vulnerability scanning and patch cadence < 30 days for high-severity CVEs.
- Audit logs retained for 12 months.
- Annual third-party penetration test.
5.Subprocessors
Processor may engage third-party subprocessors to deliver the platform. The current list is published at /subprocessors.
Processor will notify Controller at least 30 days before adding a new subprocessor that processes Personal Data. Controller may object in writing during the notice window; if the objection cannot be resolved, Controller may terminate the affected service without penalty.
6.International transfers
Where Personal Data is transferred out of the EEA/UK, transfers are covered by the EU Standard Contractual Clauses (2021/914) and, for UK transfers, the UK IDTA — incorporated into this DPA by reference.
7.Breach notification
Processor will notify Controller without undue delay and no later than 72 hours after becoming aware of a Personal Data Breach affecting Controller data, including scope, categories affected, and remediation steps.
Breach notifications are sent from security@simonaratalent.us.
8.Data subject rights assistance
Processor will assist Controller in responding to data subject requests (access, correction, deletion, portability, objection, restriction) within statutory timelines. Standard requests are handled within 30 days at no additional cost.
9.Return & deletion on termination
Within 30 days of the termination or expiry of the underlying Terms of Service, Processor will either return all Personal Data to Controller in a machine-readable format or securely delete it, at Controller's election. Deletion certification available on request. Backups purged on their normal rotation (max 90 days).
10.Audits
Once per calendar year, Controller (or an independent auditor on Controller's behalf, bound by confidentiality) may request a summary of Processor's security posture including the most recent penetration-test attestation. On-site audits available on 30-day notice and subject to reasonable scope + fee.
11.Liability
The liability of each party arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the underlying Terms of Service, save for liability that cannot be limited under applicable law.
12.Governing law
This DPA is governed by the laws of the State of Delaware, USA, except to the extent that mandatory data-protection laws apply.
Want this countersigned? Email privacy@simonaratalent.us and we'll return a signed copy on your paper or ours within two business days.
