Legal

Data Processing Agreement

Last updated: January 1, 2025

This Data Processing Agreement ("DPA") forms part of the agreement between PennyRecruiters ("Processor") and the client ("Controller") for the provision of services. This DPA sets out the terms governing the processing of personal data by the Processor on behalf of the Controller and reflects the requirements of applicable data protection laws, including the General Data Protection Regulation (GDPR) (EU Regulation 2016/679). This DPA takes precedence over any conflicting terms in the underlying service agreement.

1. Definitions

For the purposes of this DPA, the following terms shall have the meanings set forth below:

2. Scope and Purpose

This DPA applies to all personal data processed by PennyRecruiters on behalf of the Controller in connection with the services provided under the underlying service agreement. The Processor shall process personal data only in accordance with the Controller's documented instructions, unless required to do otherwise by applicable law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

3. Data Processing Terms

The specific details of the data processing activities are as follows:

4. Security Measures

The Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk presented by the processing, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. The Processor's security measures include, but are not limited to:

5. Sub-processing

The Controller provides general authorization to the Processor to engage sub-processors for the provision of services. The Processor shall maintain an up-to-date list of authorized sub-processors and shall notify the Controller of any intended changes concerning the addition or replacement of sub-processors at least 30 days prior to the change. The Controller may object to the engagement of a new sub-processor within 15 days of receipt of such notice on reasonable grounds relating to data protection. If the Controller objects and the objection is not resolved, either party may terminate the affected services. The Processor's current sub-processors include:

The Processor shall enter into written agreements with all sub-processors that impose data protection obligations no less protective than those set forth in this DPA. The Processor remains fully liable to the Controller for the performance of its sub-processors' obligations.

6. Data Subject Rights

The Processor shall provide reasonable assistance to the Controller in fulfilling its obligations to respond to data subjects' requests to exercise their rights under applicable data protection laws. The Processor shall:

7. Breach Notification

The Processor shall implement and maintain procedures for detecting, investigating, and reporting personal data breaches. In the event of a personal data breach affecting Controller data, the Processor shall:

8. Compliance, Audits, and Records

The Processor shall maintain a written record of all categories of processing activities conducted on behalf of the Controller, as required by GDPR Article 30. The Processor shall:

9. International Transfers

Personal data may be transferred to and processed in countries where the Processor or its sub-processors maintain facilities, including the United States, Pakistan, and other jurisdictions. The Processor shall ensure that any international transfer of personal data from the European Economic Area (EEA), Switzerland, or the United Kingdom to a country that has not been deemed adequate by the European Commission is governed by appropriate safeguards, including:

Upon the Controller's request, the Processor shall provide copies of the applicable safeguards and evidence that they provide an adequate level of data protection.

10. Termination and Data Return

Upon termination or expiration of the underlying service agreement, or upon the Controller's written request at any time, the Processor shall, at the Controller's option:

The Processor may retain personal data to the extent required by applicable law, provided that the Processor continues to protect such data in accordance with this DPA and processes it only for the purpose of legal compliance.

11. Limitation of Liability

The liability of each party under this DPA shall be subject to the limitations of liability set forth in the underlying service agreement. However, neither party's liability for: (a) breach of its obligations under GDPR Articles 28 (Processor), 32 (Security), or 33/34 (Breach Notification); (b) its indemnification obligations; or (c) its breach of confidentiality shall be limited or excluded to the extent such limitation or exclusion is prohibited by law. In all cases, liability under this DPA shall be subject to the cap set forth in the underlying service agreement.

12. Governing Law and Jurisdiction

This DPA shall be governed by and construed in accordance with the laws of the State of Georgia, USA, without regard to its conflict of law principles. Any disputes arising from this DPA that cannot be resolved through negotiation shall be resolved in accordance with the dispute resolution provisions of the underlying service agreement. This DPA does not override the mandatory data protection laws of the EEA member states where the Controller is established.

13. Contact

For questions about this DPA or to submit a data subject request or breach notification, please contact:

Email: info@pennyrecruiters.com

Secondary Email: info@pennyrecruiters.com

Phone: +1 (770) 710-4500

Address: 100 Peachtree Street NW, Suite 1500, Atlanta, GA 30303, USA