Data Processing Agreement
Talendoo
Data Processing Agreement
This Data Processing Agreement (“DPA”) is entered into between:
True Cloud ERP (Pty) Ltd a company incorporated in the Republic of South Africa, with its registered address at 1st Floor, Gateway West, 22 Magwa Crescent, Midrand, South Africa (“Company,” “Processor,” or “Operator”); and
True Cloud ERP (Pty) Ltd, the Employer or Recruiter identified in the applicable order form, Account registration, or signature block (“Customer,” “Controller,” or “Responsible Party”),
each a “Party” and together the “Parties.”
Background
A. The Company operates the Talendoo recruitment platform (the “Platform”) and provides related services to the Customer pursuant to the Platform General Terms & Conditions and the applicable Employer Terms & Conditions or Recruiter Terms & Conditions (together, the “Principal Agreement”).
B. While providing the Platform and Services, the Company processes Personal Information on behalf of, and on the documented instructions of, the Customer, including the Personal Information of Candidates and the Customer’s own personnel who use the Platform.
C. This DPA sets out the Parties’ respective obligations in relation to that processing, to comply with the Protection of Personal Information Act 4 of 2013 (“POPIA”), the EU General Data Protection Regulation 2016/679, and the UK GDPR and Data Protection Act 2018 (together, “Data Protection Law”).
D. This DPA is incorporated into, and forms part of, the Principal Agreement. In the event of any conflict between this DPA and the Principal Agreement on a matter of data processing, this DPA prevails. This DPA is the negotiated contractual instrument between the Company and a specific Customer, and is distinct from, and does not replace, the Company’s published POPIA/GDPR Data Processing Notice, which remains the general, public-facing compliance explanation addressed to Candidates and other users generally, including where they are not a party to this DPA.
1. Definitions
1.1 Unless otherwise defined in this DPA, capitalized terms have the meaning given in the Principal Agreement or, for data-protection-specific terms (such as “processing,” “controller/responsible party,” “processor/operator,” “data subject,” “personal data breach,” and “special categories of personal data”), the meaning given under Data Protection Law.
1.2 “Approved Sub processor” means a subprocess or listed in the Sub processor List (as defined below) or otherwise approved in accordance with clause 8.
1.3 “Sub processor List” means the Company’s published list of sub processors engaged in connection with the Platform, as updated from time to time and made available at https://app.talendoo.io/terms-of-service?doc=subprocessors or on request.
1.4 “EU Transfer SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission under Commission Implementing Decision (EU) 2021/914, as amended or replaced from time to time, and, where relevant, the equivalent UK International Data Transfer Agreement or Addendum issued under the UK GDPR.
2. Roles of the Parties
2.1 As between the Parties, and in respect of the Personal Information described in Schedule A, the Customer is the Controller/Responsible Party and the Company is the Processor/Operator, save that the Company remains an independent Controller/Responsible Party in its own right for the limited purposes described in clause 2 of the POPIA/GDPR Data Processing Notice (including Account administration, billing, Platform-wide security, and Platform-wide analytics), which fall outside the scope of this DPA.
2.2 Where the Customer is a Recruiter processing Candidate Personal Information on the instructions of an Employer client, the Recruiter may itself be a Processor/Operator in respect of that Employer, without prejudice to the Recruiter’s status as Controller/Responsible Party toward the Candidate directly, as described in the Recruiter Terms & Conditions and the POPIA/GDPR Data Processing Notice. This DPA governs only the processing relationship between the Company and the Customer and does not itself constitute the data-processing arrangement (if any) required between a Recruiter and its Employer clients, which remains the Recruiter’s own responsibility to put in place.
3. Subject Matter and Duration of Processing
3.1 The subject matter of the processing is the provision of the Platform and Services by the Company to the Customer under the Principal Agreement.
3.2 Processing will continue for the duration of the Principal Agreement, and thereafter only to the extent, and for so long as necessary for the Company to comply with clause 13 (Return and Deletion) or a legal retention obligation.
3.3 Full details of the subject matter, nature, purpose, categories of data subjects, and categories of personal data are set out in Schedule A.
4. Documented Instructions
4.1 The Company shall process Personal Information only on the Customer’s documented instructions, including with regard to transfers of Personal Information to a third country, unless required to do otherwise by South African, European Union, member state, or other applicable law to which the Company is subject, in which case the Company shall, unless prohibited from doing so, inform the Customer of that legal requirement before processing.
4.2 The Principal Agreement, this DPA, and the Customer’s use of the ordinary, documented functionality of the Platform (for example, posting a role, downloading a Candidate profile, or messaging a Candidate through the Platform) together constitute the Customer’s documented instructions for the purposes of this clause. Any additional or different instruction must be agreed in writing and may be treated by the Company as a change request subject to additional fees and timelines where it requires material changes to the Platform.
4.3 The Company shall immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
5. Confidentiality
5.1 The Company shall ensure that any person authorized to process Personal Information under this DPA (including its employees, agents, and contractors) is subject to a binding written or statutory obligation of confidentiality and has received appropriate training on their data protection obligations.
5.2 Confidentiality obligations under this clause survive termination of this DPA and the Principal Agreement.
6. Security of Processing
6.1 The Company shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of data subjects, including, as appropriate:
(a) pseudonymization and encryption of Personal Information;
(b) the ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
(c) the ability to restore the availability of and access to Personal Information in a timely manner in the event of a physical or technical incident;
(d) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures;
(e) role-based access controls limiting access to Personal Information to personnel who require it to perform their duties; and
(f) logging and monitoring of access to Personal Information held on the Platform, and secure software development and vulnerability-management practices, each to the extent implemented as confirmed in Schedule B.
6.2 Schedule B reflects only the security measures the Company has confirmed it implements. The Company shall not represent a measure in Schedule B as in place unless it is genuinely operating and shall promptly notify the Customer in writing if a measure listed in Schedule B is materially reduced, discontinued, or found not to have been operating as described. The Company may update Schedule B if it does not materially decrease the overall level of security during the term of the Principal Agreement, other than as permitted by this clause 6.2.
7. Personnel
7.1 The Company shall ensure that its personnel engaged in the processing of Personal Information are informed of the confidential nature of the Personal Information, have undergone appropriate training on their responsibilities, and are bound by confidentiality obligations as described in clause 5.
8. Sub processors
8.1 The Customer authorizes the Company to engage the Approved Sub processors listed in the Sub processor List as at the date of this DPA for the processing activities described there.
8.2 The Company shall not engage a new subprocess or to process Personal Information under this DPA without providing the Customer with at least thirty (30) days’ prior written notice (which may be given by email or by updating the published Sub processor List and notifying registered Customer administrators), giving the Customer the opportunity to object.
8.3 If the Customer reasonably objects to a new subprocess or on legitimate data-protection grounds within the notice period, the Parties will discuss the objection in good faith. If the Parties cannot resolve the objection within a further thirty (30) days, the Customer may, as its sole and exclusive remedy, terminate the affected Service on written notice to the Company, without penalty, to the extent it cannot reasonably continue to use that Service without the new subprocess or.
8.4 The Company shall impose data protection terms on any subprocess, or it engages that are substantially no less protective of Personal Information than those set out in this DPA and shall remain fully liable to the Customer for the performance of that sub processor’s obligations, to the extent required by Data Protection Law.
9. Assistance with Data Subject Rights
9.1 Considering the nature of the processing, the Company shall provide reasonable assistance to the Customer, by appropriate technical and organizational measures, to enable the Customer to respond to requests from data subjects seeking to exercise their rights under Data Protection Law (including access, correction, deletion, objection, restriction, and portability requests).
9.2 If the Company receives a request directly from a data subject relating to processing carried out on the Customer’s behalf, the Company will, unless legally prohibited from doing so, promptly inform the data subject that the request has been forwarded to the relevant Employer or Recruiter, and forward the request to the Customer without undue delay, without itself responding to the request other than to make that referral.
10. Assistance with Data Protection Impact Assessments and Regulator Consultations
10.1 The Company shall provide the Customer with reasonable assistance, taking into account the nature of processing and the information available to the Company, with any data protection impact assessment or prior consultation with a supervisory authority that the Customer is required to carry out under Data Protection Law in relation to processing carried out by the Company on the Customer’s behalf.
11. Personal Data Breach Cooperation
11.1 The Company shall notify the Customer without undue delay, and in any event within twenty-four (24) hours, after becoming aware of a personal data breach affecting Personal Information processed on the Customer’s behalf under this DPA.
11.2 Notification under clause 11.1 will, to the extent the information is available, describe: (a) the nature of the breach, including, where possible, the categories and approximate number of data subjects and personal data records concerned; (b) the likely consequences of the breach; (c) the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects; and (d) a contact point for further information. Where full information is not available within 24 hours, the Company will provide it in phases without undue further delay and will provide reasonable ongoing updates until the incident is resolved.
11.3 The Company shall take reasonable steps to contain and remediate the breach, preserve relevant evidence and logs, and cooperate with the Customer’s own investigation and, where applicable, its regulatory notifications, but shall not make any public statement identifying the Customer or the breach as concerning the Customer without the Customer’s prior consent unless required by law.
11.4 Notification of, or response to, a personal data breach shall not be construed as an acknowledgement of fault or liability by the Company.
12. Audit and Inspection Rights
12.1 The Company shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections conducted by the Customer or an auditor mandated by the Customer, subject to clause 12.2.
12.2 Audit rights under this clause may be satisfied, at the Company’s reasonable election, by the Company providing: (a) a current third-party security certification or audit report (for example, an ISO 27001 certificate or SOC 2 report, where held); (b) a completed security questionnaire; or (c) a summary of relevant policies and the Schedule B security measures, in each case before requiring an on-site or system-level audit. Any on-site or system-level audit shall be conducted no more than once per year (save where required following a personal data breach or by a supervisory authority), on reasonable notice of at least 30 days, during business hours, subject to reasonable confidentiality obligations, and at the Customer’s cost, without unreasonably disrupting the Company’s business or compromising the confidentiality or security of other customers’ data.
13. Return and Deletion of Personal Information
13.1 On termination or expiry of the Principal Agreement, or earlier on the Customer’s written request, the Company shall, at the Customer’s election, return or delete all Personal Information processed on the Customer’s behalf under this DPA, and delete existing copies, within ninety (90) days, unless applicable law requires continued storage of the Personal Information, in which case the Company shall isolate and protect that Personal Information from further processing except to the extent required by that law.
13.2 The Company may retain Personal Information in encrypted backups for a limited period thirty (30) days consistent with its standard backup-rotation schedule, provided such backups are not used for any purpose other than disaster recovery and are deleted in the ordinary course in accordance with that schedule
14. Government and Third-Party Access Requests
14.1 If the Company receives a legally binding request from a public authority (including a law-enforcement or national-security authority) for disclosure of Personal Information processed under this DPA, the Company shall, unless legally prohibited from doing so (for example, by a confidential legal-process order): (a) notify the Customer promptly and before disclosure, where feasible; (b) assess the validity of the request and challenge it where there are reasonable grounds to consider it unlawful, excessive, or not legally binding; and (c) disclose the minimum amount of Personal Information necessary to comply with a valid, binding request.
14.2 Where the Company is prohibited by law from notifying the Customer of a request, it shall use reasonable efforts to obtain a waiver of that prohibition to allow it to make as much information available to the Customer as soon as possible, and shall document such requests and make general, aggregated information about government access requests available to the Customer on reasonable request, to the extent legally permitted.
15. International Transfers
15.1 The Company shall not transfer Personal Information processed under this DPA outside the country in which it was collected, or from South Africa or the European Union/United Kingdom to a third country, except in accordance with Data Protection Law, including by relying on an adequacy decision, the EU Transfer SCCs, or another lawful transfer mechanism, as further described in Schedule D.
15.2 Distinction between Article 28 processor terms and Chapter V transfer clauses. The Parties acknowledge that the European Commission has adopted two distinct sets of standard contractual clauses: (a) controller-to-processor clauses addressing the requirements of GDPR Article 28, adopted under Commission Implementing Decision (EU) 2021/915, the substance of which is addressed directly by the body of this DPA rather than by incorporating that instrument separately; and (b) the EU Transfer SCCs, addressing international transfers under GDPR Chapter V, adopted under Commission Implementing Decision (EU) 2021/914, which include four modules (controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller). Where a transfer of Personal Information under this DPA requires the EU Transfer SCCs or the equivalent UK mechanism, the Parties shall execute the appropriate module as a signed addendum to this DPA (the “Transfer Addendum”), with its annexes completed to specify: the identities of the exporting and importing parties; the module selected; the categories of data subjects and personal data transferred; the frequency of transfer; the purpose of processing; the retention period; the competent supervisory authority; the technical and organizational measures applied; any sub processors involved in the transfer; and the governing law and choice of forum for the Transfer Addendum. A general statement of incorporation by reference, without a signed Transfer Addendum in this form, is not sufficient to satisfy this clause 15.2 for a transfer that requires it.
15.3 Where POPIA section 72 applies to a transfer, the Parties shall rely on the mechanisms described in clause 5 of the POPIA/GDPR Data Processing Notice and record the relevant transfer route in Schedule D.
16. Liability
16.1 Each Party’s liability arising out of or in connection with this DPA, whether in contract, delict/tort, or otherwise, is subject to the limitations and exclusions of liability set out in clause 10 of the Platform General Terms & Conditions, which apply to this DPA as though set out in full, save that nothing in this DPA or the Principal Agreement limits Party’s liability for infringements of Data Protection Law to the extent such liability cannot lawfully be limited.
16.2 Each Party shall be liable for, and shall indemnify the other Party against, fines, penalties, or damages awarded against the other Party by a supervisory authority or court to the extent caused by the indemnifying Party’s breach of this DPA or Data Protection Law.
17. Term and Termination
17.1 This DPA takes effect on the date the Customer accepts the Principal Agreement (or, for Customers with an existing Account, the effective date of this DPA’s publication) and continues for as long as the Company processes Personal Information on the Customer’s behalf under the Principal Agreement, notwithstanding the expiry or termination of the Principal Agreement for any reason.
18. Acceptance, Records, and Odoo Implementation Requirements
18.1 The Customer accepts this DPA either by accepting the applicable Employer Terms & Conditions or Recruiter Terms & Conditions (of which this DPA form’s part) during Platform registration, or, for Customers who require it, by separately countersigning this DPA as a standalone signed contract; a separately signed DPA is available on request and is recommended for larger, enterprise Customers.
18.2 Where accepted through Platform registration, the Company’s registration flow must: (a) present a link to this DPA (and confirm that it forms part of the Principal Agreement) at the point of Employer or Recruiter registration; (b) record the specific version of this DPA accepted, together with a timestamp and the identity of both the individual user and the Customer entity on whose behalf they are acting; (c) capture a confirmation from that individual that they are authorized to bind the Customer to this DPA; (d) retain this acceptance record, and, where lawfully collected, associated device/IP information, as evidence of acceptance; (e) make a downloadable copy of the accepted version available to the Customer on request; and (f) require the Customer to re-accept this DPA following a material change, in the same manner as described in clause 18.3 of the Platform General Terms & Conditions.
19. General
19.1 This DPA is governed by, and any dispute arising out of it resolved in accordance with clause 16 and clause 17 of the Platform General Terms & Conditions (governing law and dispute resolution).
19.2 Notices under this DPA shall be given in accordance with clause 15 of the Platform General Terms & Conditions, save that data-protection-specific notices to the Company should be directed to the privacy officer’s email.
19.3 In the event of any conflict between the body of this DPA and its Schedules, the body of this DPA prevails unless the Schedule expressly states that it overrides a specific clause.
Schedule A - Details of Processing
A.1 Subject matter: Provision of the Talendoo recruitment platform and related Services to the Customer.
A.2 Duration: For the term of the Principal Agreement, and thereafter as described in clause 13 of this DPA.
A.3 Nature and purpose of processing: Hosting, storage, transmission, organization, retrieval, and display of Candidate and Customer-personnel Personal Information for the purpose of enabling the Customer to advertise roles, search for and evaluate Candidates, manage applications, and communicate with Candidates and, where applicable, Recruiters, through the Platform.
A.4 Categories of data subjects:
(a) Candidates who apply to, or are shortlisted, contacted, or represented in connection with, roles associated with the Customer;
(b) the Customer’s own employees, contractors, and authorized users of the Platform;
(c) where the Customer is a Recruiter, the Recruiter’s Employer clients’ contact personnel, to the extent their Personal Information is processed in connection with a mandate; and
(d) referees nominated by a Candidate, to the extent their contact details and responses are processed in connection with a specific recruitment process.
A.5 Categories of personal data: Name, contact details, CV/résumé content, employment and education history, qualifications, skills, salary expectations, references and referee contact details, work-authorization status, application status and history, messages exchanged through the Platform, interview recordings/transcripts and assessment results (where used), and account/login data; billing contact details for the Customer’s own personnel; and, where applicable and separately consented to, special categories of personal data as described in A.6.
A.6 Special categories of personal data (if any): Health information disclosed for reasonable accommodation purposes; criminal-record information disclosed for lawful background-vetting purposes; and, only where voluntarily provided by a Candidate for equal-opportunity monitoring purposes, information revealing race, ethnicity, or disability status. Processing of any special category of personal data is subject to the Candidate’s explicit consent or another applicable statutory exemption, as described in the POPIA/GDPR Data Processing Notice.
Schedule B - Technical and Organizational Security Measures
This Schedule must reflect only measures the Company has confirmed are genuinely and currently implemented for the Platform. Before this Schedule is relied upon contractually, the Company must confirm each item below against its actual Odoo hosting environment and internal practices (including, for example: whether multi-factor authentication is enforced for all production administrators; whether database data is encrypted at rest and not only in transit; how long access logs are retained and who reviews them; how frequently backups are tested by restoration; whether the Platform’s hosting provider – Odoo Online, Odoo.sh, or another provider – actually provides the control claimed; whether vulnerability scanning is actually performed and at what frequency; and whether a documented incident-response test is actually conducted, and how often). Any measure not yet in place must be removed from this Schedule, or clearly marked as planned with a target date, rather than stated as a current, contractually binding control.
(a) Encryption of Personal Information in transit using industry-standard protocols – TLS 1.2 minimum, TLS 1.3 preferred, with all HTTP requests redirected to HTTPS;
(b) Encryption of Personal Information at rest – enabled at the database layer (Amazon RDS storage encryption using AWS KMS), the document-storage layer (Amazon S3 server-side encryption, AES-256), and the caching layer (Amazon ElastiCache for Redis, with encryption in transit and at rest and authentication enabled);
(c) Access controls and the principle of least privilege for personnel and system access to Personal Information – implemented through private network segmentation, security-group isolation, document storage that is not publicly accessible and is served only through time-limited signed URLs, and database network access restricted to internal networks only;
(d) Multi-factor authentication is enforced for all administrative access to production systems;
(e) Logging and monitoring of access to systems processing Personal Information – application logging to Amazon CloudWatch retained for 30 days, and administrative audit logging via AWS CloudTrail with log-file validation;
(f) Vulnerability scanning and patch management – container images are scanned on push to the registry, and automated dependency scanning is enabled across source repositories;
(g) Secure software development practices – changes are developed on feature branches and merged by pull request, subject to review before merge;
(h) Documented incident-response procedures – In the event of a security incident or personal data breach, the incident is identified and immediately escalated to the responsible team members. The team takes appropriate steps to contain the incident and prevent further unauthorized access or data exposure, preserves relevant logs and evidence, investigates the cause and scope of the incident, and implements the necessary remediation measures. Where Customer Personal Data is affected, the Customer is notified without undue delay and no later than 24 hours after becoming aware of the breach, in accordance with Clause 11 of this DPA. The team also provides the necessary information and assistance to support further investigation and resolution of the incident.
(i) Backups and restoration testing – automated daily database backups, encrypted at rest and retained for seven days, with restoration from backup periodically tested;
(j) Physical and environmental security at hosting facilities – delegated to Amazon Web Services (eu-north-1, Stockholm, Sweden), which maintains ISO 27001 and SOC 2 certification; reports available via AWS Artifact;
(k) Data-minimization and pseudonymization measures where consistent with the purpose of processing – Personal Information is retained only for the periods published in clause 7 of the Privacy Policy;
(l) Confidentiality undertakings and data-protection/security training for personnel with access to Personal Information – personnel with access to production systems or Personal Information are subject to contractual confidentiality obligations and are provided with internal guidance on data protection, secure handling of Personal Information, access control, credential security, and incident reporting.
(m) Business-continuity and disaster-recovery plan – production infrastructure is hosted on Amazon Web Services and designed to allow service restoration following infrastructure or application failures. Automated encrypted database backups are performed daily and retained for seven days, with backup restoration periodically tested. Recovery procedures include restoration of application services, databases, and supporting infrastructure from maintained infrastructure configurations and backups.
(n) Vendor/subprocessor due-diligence and periodic reassessment in accordance with clause 8 of this DPA – subprocessors are reviewed before engagement with regard to the nature of Personal Information processed, security and data-protection practices, hosting and processing locations, contractual data-protection commitments, and relevant security certifications where available. The approved Subprocessor List is maintained and reviewed when new subprocessors are introduced or existing subprocessors materially change their services.
Schedule C - Approved Sub processors
The Approved Sub processors engaged by the Company at the effective date of this DPA are set out in the Company’s published Sub processor List at https://app.talendoo.io/terms-of-service?doc=subprocessors, which is incorporated into this DPA by reference and updated from time to time in accordance with clause 8. At minimum, the Sub processor List identifies, for each of the following categories (where used): (a) the Odoo hosting provider (Odoo Online, Odoo.sh, or self-hosted infrastructure provider); (b) cloud infrastructure/storage provider; (c) email delivery provider; (d) SMS or WhatsApp messaging provider; (e) payment gateway; (f) analytics provider; (g) CAPTCHA/bot-detection provider; (h) customer-support ticketing system; (i) identity-verification provider; (j) background-check provider; (k) document storage provider; (l) video-interview or meeting-hosting provider; and (m) AI/CV-parsing or other AI provider.
Schedule D - International Transfer Mechanisms and Routes
D.1 General mechanisms. Transfers of Personal Information outside the country of original collection are made under the mechanisms described in clause 6 of the Privacy Policy and clause 5 of the POPIA/GDPR Data Processing Notice, including, as applicable to the transfer in question: an applicable adequacy decision; the EU Transfer SCCs (executed as a Transfer Addendum in accordance with clause 15.2); the UK International Data Transfer Agreement/Addendum; or, in respect of transfers governed by POPIA section 72, another lawful transfer mechanism recognized under that section.
D.2 Specific transfer routes. The table below records the Company’s actual transfer routes and must be completed and kept current; it is illustrative only until populated.
| Data origin | Recipient | Destination country | Purpose | Safeguard |
|---|---|---|---|---|
| South Africa | [Odoo hosting / cloud infrastructure provider] | South Africa | Platform hosting and database infrastructure | [e.g., POPIA section 72 arrangement – confirm actual basis] |
| European Union | [COMPANY LEGAL NAME] | South Africa | Provision of recruitment services to an EU-based Customer or Candidate | EU Transfer SCCs (Transfer Addendum per clause 15.2) |
| United Kingdom | [COMPANY LEGAL NAME] | South Africa | Provision of recruitment services to a UK-based Customer or Candidate | UK International Data Transfer Agreement/Addendum |
Acceptance
Acceptance. By accepting the Employer Terms & Conditions or Recruiter Terms & Conditions in accordance with clause 18 of this DPA, or by countersigning this DPA where presented as a separate signed contract for enterprise Customers, the Customer agrees to be bound by this DPA.
True Cloud ERP (Pty) Ltd Signature: _______________________ Name: _______________________ Title: _______________________ Date: _______________________
_______________________ Signature: _______________________ Name: _______________________ Title: _______________________ Date: _______________________
Data Processing Agreement
Talendoo
Data Processing Agreement
This Data Processing Agreement (“DPA”) is entered into between:
True Cloud ERP (Pty) Ltd a company incorporated in the Republic of South Africa, with its registered address at 1st Floor, Gateway West, 22 Magwa Crescent, Midrand, South Africa (“Company,” “Processor,” or “Operator”); and
True Cloud ERP (Pty) Ltd, the Employer or Recruiter identified in the applicable order form, Account registration, or signature block (“Customer,” “Controller,” or “Responsible Party”),
each a “Party” and together the “Parties.”
Background
A. The Company operates the Talendoo recruitment platform (the “Platform”) and provides related services to the Customer pursuant to the Platform General Terms & Conditions and the applicable Employer Terms & Conditions or Recruiter Terms & Conditions (together, the “Principal Agreement”).
B. While providing the Platform and Services, the Company processes Personal Information on behalf of, and on the documented instructions of, the Customer, including the Personal Information of Candidates and the Customer’s own personnel who use the Platform.
C. This DPA sets out the Parties’ respective obligations in relation to that processing, to comply with the Protection of Personal Information Act 4 of 2013 (“POPIA”), the EU General Data Protection Regulation 2016/679, and the UK GDPR and Data Protection Act 2018 (together, “Data Protection Law”).
D. This DPA is incorporated into, and forms part of, the Principal Agreement. In the event of any conflict between this DPA and the Principal Agreement on a matter of data processing, this DPA prevails. This DPA is the negotiated contractual instrument between the Company and a specific Customer, and is distinct from, and does not replace, the Company’s published POPIA/GDPR Data Processing Notice, which remains the general, public-facing compliance explanation addressed to Candidates and other users generally, including where they are not a party to this DPA.
1. Definitions
1.1 Unless otherwise defined in this DPA, capitalized terms have the meaning given in the Principal Agreement or, for data-protection-specific terms (such as “processing,” “controller/responsible party,” “processor/operator,” “data subject,” “personal data breach,” and “special categories of personal data”), the meaning given under Data Protection Law.
1.2 “Approved Sub processor” means a subprocess or listed in the Sub processor List (as defined below) or otherwise approved in accordance with clause 8.
1.3 “Sub processor List” means the Company’s published list of sub processors engaged in connection with the Platform, as updated from time to time and made available at https://app.talendoo.io/terms-of-service?doc=subprocessors or on request.
1.4 “EU Transfer SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission under Commission Implementing Decision (EU) 2021/914, as amended or replaced from time to time, and, where relevant, the equivalent UK International Data Transfer Agreement or Addendum issued under the UK GDPR.
2. Roles of the Parties
2.1 As between the Parties, and in respect of the Personal Information described in Schedule A, the Customer is the Controller/Responsible Party and the Company is the Processor/Operator, save that the Company remains an independent Controller/Responsible Party in its own right for the limited purposes described in clause 2 of the POPIA/GDPR Data Processing Notice (including Account administration, billing, Platform-wide security, and Platform-wide analytics), which fall outside the scope of this DPA.
2.2 Where the Customer is a Recruiter processing Candidate Personal Information on the instructions of an Employer client, the Recruiter may itself be a Processor/Operator in respect of that Employer, without prejudice to the Recruiter’s status as Controller/Responsible Party toward the Candidate directly, as described in the Recruiter Terms & Conditions and the POPIA/GDPR Data Processing Notice. This DPA governs only the processing relationship between the Company and the Customer and does not itself constitute the data-processing arrangement (if any) required between a Recruiter and its Employer clients, which remains the Recruiter’s own responsibility to put in place.
3. Subject Matter and Duration of Processing
3.1 The subject matter of the processing is the provision of the Platform and Services by the Company to the Customer under the Principal Agreement.
3.2 Processing will continue for the duration of the Principal Agreement, and thereafter only to the extent, and for so long as necessary for the Company to comply with clause 13 (Return and Deletion) or a legal retention obligation.
3.3 Full details of the subject matter, nature, purpose, categories of data subjects, and categories of personal data are set out in Schedule A.
4. Documented Instructions
4.1 The Company shall process Personal Information only on the Customer’s documented instructions, including with regard to transfers of Personal Information to a third country, unless required to do otherwise by South African, European Union, member state, or other applicable law to which the Company is subject, in which case the Company shall, unless prohibited from doing so, inform the Customer of that legal requirement before processing.
4.2 The Principal Agreement, this DPA, and the Customer’s use of the ordinary, documented functionality of the Platform (for example, posting a role, downloading a Candidate profile, or messaging a Candidate through the Platform) together constitute the Customer’s documented instructions for the purposes of this clause. Any additional or different instruction must be agreed in writing and may be treated by the Company as a change request subject to additional fees and timelines where it requires material changes to the Platform.
4.3 The Company shall immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
5. Confidentiality
5.1 The Company shall ensure that any person authorized to process Personal Information under this DPA (including its employees, agents, and contractors) is subject to a binding written or statutory obligation of confidentiality and has received appropriate training on their data protection obligations.
5.2 Confidentiality obligations under this clause survive termination of this DPA and the Principal Agreement.
6. Security of Processing
6.1 The Company shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of data subjects, including, as appropriate:
(a) pseudonymization and encryption of Personal Information;
(b) the ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
(c) the ability to restore the availability of and access to Personal Information in a timely manner in the event of a physical or technical incident;
(d) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures;
(e) role-based access controls limiting access to Personal Information to personnel who require it to perform their duties; and
(f) logging and monitoring of access to Personal Information held on the Platform, and secure software development and vulnerability-management practices, each to the extent implemented as confirmed in Schedule B.
6.2 Schedule B reflects only the security measures the Company has confirmed it implements. The Company shall not represent a measure in Schedule B as in place unless it is genuinely operating and shall promptly notify the Customer in writing if a measure listed in Schedule B is materially reduced, discontinued, or found not to have been operating as described. The Company may update Schedule B if it does not materially decrease the overall level of security during the term of the Principal Agreement, other than as permitted by this clause 6.2.
7. Personnel
7.1 The Company shall ensure that its personnel engaged in the processing of Personal Information are informed of the confidential nature of the Personal Information, have undergone appropriate training on their responsibilities, and are bound by confidentiality obligations as described in clause 5.
8. Sub processors
8.1 The Customer authorizes the Company to engage the Approved Sub processors listed in the Sub processor List as at the date of this DPA for the processing activities described there.
8.2 The Company shall not engage a new subprocess or to process Personal Information under this DPA without providing the Customer with at least thirty (30) days’ prior written notice (which may be given by email or by updating the published Sub processor List and notifying registered Customer administrators), giving the Customer the opportunity to object.
8.3 If the Customer reasonably objects to a new subprocess or on legitimate data-protection grounds within the notice period, the Parties will discuss the objection in good faith. If the Parties cannot resolve the objection within a further thirty (30) days, the Customer may, as its sole and exclusive remedy, terminate the affected Service on written notice to the Company, without penalty, to the extent it cannot reasonably continue to use that Service without the new subprocess or.
8.4 The Company shall impose data protection terms on any subprocess, or it engages that are substantially no less protective of Personal Information than those set out in this DPA and shall remain fully liable to the Customer for the performance of that sub processor’s obligations, to the extent required by Data Protection Law.
9. Assistance with Data Subject Rights
9.1 Considering the nature of the processing, the Company shall provide reasonable assistance to the Customer, by appropriate technical and organizational measures, to enable the Customer to respond to requests from data subjects seeking to exercise their rights under Data Protection Law (including access, correction, deletion, objection, restriction, and portability requests).
9.2 If the Company receives a request directly from a data subject relating to processing carried out on the Customer’s behalf, the Company will, unless legally prohibited from doing so, promptly inform the data subject that the request has been forwarded to the relevant Employer or Recruiter, and forward the request to the Customer without undue delay, without itself responding to the request other than to make that referral.
10. Assistance with Data Protection Impact Assessments and Regulator Consultations
10.1 The Company shall provide the Customer with reasonable assistance, taking into account the nature of processing and the information available to the Company, with any data protection impact assessment or prior consultation with a supervisory authority that the Customer is required to carry out under Data Protection Law in relation to processing carried out by the Company on the Customer’s behalf.
11. Personal Data Breach Cooperation
11.1 The Company shall notify the Customer without undue delay, and in any event within twenty-four (24) hours, after becoming aware of a personal data breach affecting Personal Information processed on the Customer’s behalf under this DPA.
11.2 Notification under clause 11.1 will, to the extent the information is available, describe: (a) the nature of the breach, including, where possible, the categories and approximate number of data subjects and personal data records concerned; (b) the likely consequences of the breach; (c) the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects; and (d) a contact point for further information. Where full information is not available within 24 hours, the Company will provide it in phases without undue further delay and will provide reasonable ongoing updates until the incident is resolved.
11.3 The Company shall take reasonable steps to contain and remediate the breach, preserve relevant evidence and logs, and cooperate with the Customer’s own investigation and, where applicable, its regulatory notifications, but shall not make any public statement identifying the Customer or the breach as concerning the Customer without the Customer’s prior consent unless required by law.
11.4 Notification of, or response to, a personal data breach shall not be construed as an acknowledgement of fault or liability by the Company.
12. Audit and Inspection Rights
12.1 The Company shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections conducted by the Customer or an auditor mandated by the Customer, subject to clause 12.2.
12.2 Audit rights under this clause may be satisfied, at the Company’s reasonable election, by the Company providing: (a) a current third-party security certification or audit report (for example, an ISO 27001 certificate or SOC 2 report, where held); (b) a completed security questionnaire; or (c) a summary of relevant policies and the Schedule B security measures, in each case before requiring an on-site or system-level audit. Any on-site or system-level audit shall be conducted no more than once per year (save where required following a personal data breach or by a supervisory authority), on reasonable notice of at least 30 days, during business hours, subject to reasonable confidentiality obligations, and at the Customer’s cost, without unreasonably disrupting the Company’s business or compromising the confidentiality or security of other customers’ data.
13. Return and Deletion of Personal Information
13.1 On termination or expiry of the Principal Agreement, or earlier on the Customer’s written request, the Company shall, at the Customer’s election, return or delete all Personal Information processed on the Customer’s behalf under this DPA, and delete existing copies, within ninety (90) days, unless applicable law requires continued storage of the Personal Information, in which case the Company shall isolate and protect that Personal Information from further processing except to the extent required by that law.
13.2 The Company may retain Personal Information in encrypted backups for a limited period thirty (30) days consistent with its standard backup-rotation schedule, provided such backups are not used for any purpose other than disaster recovery and are deleted in the ordinary course in accordance with that schedule
14. Government and Third-Party Access Requests
14.1 If the Company receives a legally binding request from a public authority (including a law-enforcement or national-security authority) for disclosure of Personal Information processed under this DPA, the Company shall, unless legally prohibited from doing so (for example, by a confidential legal-process order): (a) notify the Customer promptly and before disclosure, where feasible; (b) assess the validity of the request and challenge it where there are reasonable grounds to consider it unlawful, excessive, or not legally binding; and (c) disclose the minimum amount of Personal Information necessary to comply with a valid, binding request.
14.2 Where the Company is prohibited by law from notifying the Customer of a request, it shall use reasonable efforts to obtain a waiver of that prohibition to allow it to make as much information available to the Customer as soon as possible, and shall document such requests and make general, aggregated information about government access requests available to the Customer on reasonable request, to the extent legally permitted.
15. International Transfers
15.1 The Company shall not transfer Personal Information processed under this DPA outside the country in which it was collected, or from South Africa or the European Union/United Kingdom to a third country, except in accordance with Data Protection Law, including by relying on an adequacy decision, the EU Transfer SCCs, or another lawful transfer mechanism, as further described in Schedule D.
15.2 Distinction between Article 28 processor terms and Chapter V transfer clauses. The Parties acknowledge that the European Commission has adopted two distinct sets of standard contractual clauses: (a) controller-to-processor clauses addressing the requirements of GDPR Article 28, adopted under Commission Implementing Decision (EU) 2021/915, the substance of which is addressed directly by the body of this DPA rather than by incorporating that instrument separately; and (b) the EU Transfer SCCs, addressing international transfers under GDPR Chapter V, adopted under Commission Implementing Decision (EU) 2021/914, which include four modules (controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller). Where a transfer of Personal Information under this DPA requires the EU Transfer SCCs or the equivalent UK mechanism, the Parties shall execute the appropriate module as a signed addendum to this DPA (the “Transfer Addendum”), with its annexes completed to specify: the identities of the exporting and importing parties; the module selected; the categories of data subjects and personal data transferred; the frequency of transfer; the purpose of processing; the retention period; the competent supervisory authority; the technical and organizational measures applied; any sub processors involved in the transfer; and the governing law and choice of forum for the Transfer Addendum. A general statement of incorporation by reference, without a signed Transfer Addendum in this form, is not sufficient to satisfy this clause 15.2 for a transfer that requires it.
15.3 Where POPIA section 72 applies to a transfer, the Parties shall rely on the mechanisms described in clause 5 of the POPIA/GDPR Data Processing Notice and record the relevant transfer route in Schedule D.
16. Liability
16.1 Each Party’s liability arising out of or in connection with this DPA, whether in contract, delict/tort, or otherwise, is subject to the limitations and exclusions of liability set out in clause 10 of the Platform General Terms & Conditions, which apply to this DPA as though set out in full, save that nothing in this DPA or the Principal Agreement limits Party’s liability for infringements of Data Protection Law to the extent such liability cannot lawfully be limited.
16.2 Each Party shall be liable for, and shall indemnify the other Party against, fines, penalties, or damages awarded against the other Party by a supervisory authority or court to the extent caused by the indemnifying Party’s breach of this DPA or Data Protection Law.
17. Term and Termination
17.1 This DPA takes effect on the date the Customer accepts the Principal Agreement (or, for Customers with an existing Account, the effective date of this DPA’s publication) and continues for as long as the Company processes Personal Information on the Customer’s behalf under the Principal Agreement, notwithstanding the expiry or termination of the Principal Agreement for any reason.
18. Acceptance, Records, and Odoo Implementation Requirements
18.1 The Customer accepts this DPA either by accepting the applicable Employer Terms & Conditions or Recruiter Terms & Conditions (of which this DPA form’s part) during Platform registration, or, for Customers who require it, by separately countersigning this DPA as a standalone signed contract; a separately signed DPA is available on request and is recommended for larger, enterprise Customers.
18.2 Where accepted through Platform registration, the Company’s registration flow must: (a) present a link to this DPA (and confirm that it forms part of the Principal Agreement) at the point of Employer or Recruiter registration; (b) record the specific version of this DPA accepted, together with a timestamp and the identity of both the individual user and the Customer entity on whose behalf they are acting; (c) capture a confirmation from that individual that they are authorized to bind the Customer to this DPA; (d) retain this acceptance record, and, where lawfully collected, associated device/IP information, as evidence of acceptance; (e) make a downloadable copy of the accepted version available to the Customer on request; and (f) require the Customer to re-accept this DPA following a material change, in the same manner as described in clause 18.3 of the Platform General Terms & Conditions.
19. General
19.1 This DPA is governed by, and any dispute arising out of it resolved in accordance with clause 16 and clause 17 of the Platform General Terms & Conditions (governing law and dispute resolution).
19.2 Notices under this DPA shall be given in accordance with clause 15 of the Platform General Terms & Conditions, save that data-protection-specific notices to the Company should be directed to the privacy officer’s email.
19.3 In the event of any conflict between the body of this DPA and its Schedules, the body of this DPA prevails unless the Schedule expressly states that it overrides a specific clause.
Schedule A - Details of Processing
A.1 Subject matter: Provision of the Talendoo recruitment platform and related Services to the Customer.
A.2 Duration: For the term of the Principal Agreement, and thereafter as described in clause 13 of this DPA.
A.3 Nature and purpose of processing: Hosting, storage, transmission, organization, retrieval, and display of Candidate and Customer-personnel Personal Information for the purpose of enabling the Customer to advertise roles, search for and evaluate Candidates, manage applications, and communicate with Candidates and, where applicable, Recruiters, through the Platform.
A.4 Categories of data subjects:
(a) Candidates who apply to, or are shortlisted, contacted, or represented in connection with, roles associated with the Customer;
(b) the Customer’s own employees, contractors, and authorized users of the Platform;
(c) where the Customer is a Recruiter, the Recruiter’s Employer clients’ contact personnel, to the extent their Personal Information is processed in connection with a mandate; and
(d) referees nominated by a Candidate, to the extent their contact details and responses are processed in connection with a specific recruitment process.
A.5 Categories of personal data: Name, contact details, CV/résumé content, employment and education history, qualifications, skills, salary expectations, references and referee contact details, work-authorization status, application status and history, messages exchanged through the Platform, interview recordings/transcripts and assessment results (where used), and account/login data; billing contact details for the Customer’s own personnel; and, where applicable and separately consented to, special categories of personal data as described in A.6.
A.6 Special categories of personal data (if any): Health information disclosed for reasonable accommodation purposes; criminal-record information disclosed for lawful background-vetting purposes; and, only where voluntarily provided by a Candidate for equal-opportunity monitoring purposes, information revealing race, ethnicity, or disability status. Processing of any special category of personal data is subject to the Candidate’s explicit consent or another applicable statutory exemption, as described in the POPIA/GDPR Data Processing Notice.
Schedule B - Technical and Organizational Security Measures
This Schedule must reflect only measures the Company has confirmed are genuinely and currently implemented for the Platform. Before this Schedule is relied upon contractually, the Company must confirm each item below against its actual Odoo hosting environment and internal practices (including, for example: whether multi-factor authentication is enforced for all production administrators; whether database data is encrypted at rest and not only in transit; how long access logs are retained and who reviews them; how frequently backups are tested by restoration; whether the Platform’s hosting provider – Odoo Online, Odoo.sh, or another provider – actually provides the control claimed; whether vulnerability scanning is actually performed and at what frequency; and whether a documented incident-response test is actually conducted, and how often). Any measure not yet in place must be removed from this Schedule, or clearly marked as planned with a target date, rather than stated as a current, contractually binding control.
(a) Encryption of Personal Information in transit using industry-standard protocols – TLS 1.2 minimum, TLS 1.3 preferred, with all HTTP requests redirected to HTTPS;
(b) Encryption of Personal Information at rest – enabled at the database layer (Amazon RDS storage encryption using AWS KMS), the document-storage layer (Amazon S3 server-side encryption, AES-256), and the caching layer (Amazon ElastiCache for Redis, with encryption in transit and at rest and authentication enabled);
(c) Access controls and the principle of least privilege for personnel and system access to Personal Information – implemented through private network segmentation, security-group isolation, document storage that is not publicly accessible and is served only through time-limited signed URLs, and database network access restricted to internal networks only;
(d) Multi-factor authentication is enforced for all administrative access to production systems;
(e) Logging and monitoring of access to systems processing Personal Information – application logging to Amazon CloudWatch retained for 30 days, and administrative audit logging via AWS CloudTrail with log-file validation;
(f) Vulnerability scanning and patch management – container images are scanned on push to the registry, and automated dependency scanning is enabled across source repositories;
(g) Secure software development practices – changes are developed on feature branches and merged by pull request, subject to review before merge;
(h) Documented incident-response procedures – In the event of a security incident or personal data breach, the incident is identified and immediately escalated to the responsible team members. The team takes appropriate steps to contain the incident and prevent further unauthorized access or data exposure, preserves relevant logs and evidence, investigates the cause and scope of the incident, and implements the necessary remediation measures. Where Customer Personal Data is affected, the Customer is notified without undue delay and no later than 24 hours after becoming aware of the breach, in accordance with Clause 11 of this DPA. The team also provides the necessary information and assistance to support further investigation and resolution of the incident.
(i) Backups and restoration testing – automated daily database backups, encrypted at rest and retained for seven days, with restoration from backup periodically tested;
(j) Physical and environmental security at hosting facilities – delegated to Amazon Web Services (eu-north-1, Stockholm, Sweden), which maintains ISO 27001 and SOC 2 certification; reports available via AWS Artifact;
(k) Data-minimization and pseudonymization measures where consistent with the purpose of processing – Personal Information is retained only for the periods published in clause 7 of the Privacy Policy;
(l) Confidentiality undertakings and data-protection/security training for personnel with access to Personal Information – personnel with access to production systems or Personal Information are subject to contractual confidentiality obligations and are provided with internal guidance on data protection, secure handling of Personal Information, access control, credential security, and incident reporting.
(m) Business-continuity and disaster-recovery plan – production infrastructure is hosted on Amazon Web Services and designed to allow service restoration following infrastructure or application failures. Automated encrypted database backups are performed daily and retained for seven days, with backup restoration periodically tested. Recovery procedures include restoration of application services, databases, and supporting infrastructure from maintained infrastructure configurations and backups.
(n) Vendor/subprocessor due-diligence and periodic reassessment in accordance with clause 8 of this DPA – subprocessors are reviewed before engagement with regard to the nature of Personal Information processed, security and data-protection practices, hosting and processing locations, contractual data-protection commitments, and relevant security certifications where available. The approved Subprocessor List is maintained and reviewed when new subprocessors are introduced or existing subprocessors materially change their services.
Schedule C - Approved Sub processors
The Approved Sub processors engaged by the Company at the effective date of this DPA are set out in the Company’s published Sub processor List at https://app.talendoo.io/terms-of-service?doc=subprocessors, which is incorporated into this DPA by reference and updated from time to time in accordance with clause 8. At minimum, the Sub processor List identifies, for each of the following categories (where used): (a) the Odoo hosting provider (Odoo Online, Odoo.sh, or self-hosted infrastructure provider); (b) cloud infrastructure/storage provider; (c) email delivery provider; (d) SMS or WhatsApp messaging provider; (e) payment gateway; (f) analytics provider; (g) CAPTCHA/bot-detection provider; (h) customer-support ticketing system; (i) identity-verification provider; (j) background-check provider; (k) document storage provider; (l) video-interview or meeting-hosting provider; and (m) AI/CV-parsing or other AI provider.
Schedule D - International Transfer Mechanisms and Routes
D.1 General mechanisms. Transfers of Personal Information outside the country of original collection are made under the mechanisms described in clause 6 of the Privacy Policy and clause 5 of the POPIA/GDPR Data Processing Notice, including, as applicable to the transfer in question: an applicable adequacy decision; the EU Transfer SCCs (executed as a Transfer Addendum in accordance with clause 15.2); the UK International Data Transfer Agreement/Addendum; or, in respect of transfers governed by POPIA section 72, another lawful transfer mechanism recognized under that section.
D.2 Specific transfer routes. The table below records the Company’s actual transfer routes and must be completed and kept current; it is illustrative only until populated.
| Data origin | Recipient | Destination country | Purpose | Safeguard |
|---|---|---|---|---|
| South Africa | [Odoo hosting / cloud infrastructure provider] | South Africa | Platform hosting and database infrastructure | [e.g., POPIA section 72 arrangement – confirm actual basis] |
| European Union | [COMPANY LEGAL NAME] | South Africa | Provision of recruitment services to an EU-based Customer or Candidate | EU Transfer SCCs (Transfer Addendum per clause 15.2) |
| United Kingdom | [COMPANY LEGAL NAME] | South Africa | Provision of recruitment services to a UK-based Customer or Candidate | UK International Data Transfer Agreement/Addendum |
Acceptance
Acceptance. By accepting the Employer Terms & Conditions or Recruiter Terms & Conditions in accordance with clause 18 of this DPA, or by countersigning this DPA where presented as a separate signed contract for enterprise Customers, the Customer agrees to be bound by this DPA.
True Cloud ERP (Pty) Ltd Signature: _______________________ Name: _______________________ Title: _______________________ Date: _______________________
_______________________ Signature: _______________________ Name: _______________________ Title: _______________________ Date: _______________________