Skip to main content

Data Processing Agreement for Parsing (DPA)

H
Written by HrFlow.ai Marketing

The HrFlow.ai Parsing API automatically extracts unstructured data from resumes and job offers - irrespective of their structure or format - and converts it into structured data.
This data can be: contact details (name, email, telephone, etc.), experiences (companies, job titles, starting date, end date, job description, etc.), academic backgrounds (diplomas, schools, universities, starting date, end date, description, etc.), skills (skills, know-how, languages, etc.), interests.

When using this service, data processing between the Client and the Provider (HrFlow.ai) is governed by the following Data Processing Agreement (DPA) to ensure full compliance with applicable Data Protection Legislation.


Schedule 1 : Processing, Personal Data, and Data Subjects

Scope

Parsing Resumes and Job offers using https://hrflow.ai/parsing/

Nature

collection, structuring, storage, adaptation, retrieval,

Purpose of processing

Optimizing the candidate and the recruiter experience within the Customer Platform candidate

Duration of the processing

Defined by the customer

Type of Personal Data

Full list data points: Name, Email, Phone, Address, and career path data: ​​https://developers.hrflow.ai/reference/the-profile-object. This list might be restricted depending on the Client subscription.

Categories of Data Subject

Applicant data and employee data of Controller


DEFINITIONS

  1. Controller, Processor, Data Subject, Personal Data, Personal Data Breach, processing and appropriate technical and organizational measures: as defined in the Data Protection Legislation.

  2. Data Protection Legislation: all applicable data protection and privacy legislation in force from time to time, as applicable to the parties, and all other legislation and regulatory requirements in force from time to time which applies to a party relating to the use of Personal Data (including, without limitation, the privacy of electronic communications);


DATA PROTECTION

  1. Both parties will comply with all applicable requirements of the Data Protection Legislation as they relate to Processors. This clause 1, is in addition to and does not relieve, remove or replace a party's obligations or rights under the Data Protection Legislation.

  2. The parties acknowledge that for the purposes of the Data Protection Legislation, the Client acts as the primary Processor (hereinafter referred to as “Initial Processor”) in relation to the Controller, and the Provider is the sub-Processor (hereinafter referred to as the “Sub-Processor”). Schedule 1 sets out the scope, nature, and purpose of the processing of the Controller's Personal Data by Sub-Processor, the duration of the processing, and the types of Personal Data and categories of Data Subject.

  3. Without prejudice to the generality of 1, the Initial Processor will ensure that its Controller customer has all necessary appropriate consents and notices in place to enable the lawful transfer of the Personal Data to the Sub-processor and/or lawful collection of the Personal Data by the Initial Processor and/or the Sub-Processor on behalf of the Controller for the duration and purposes of this agreement.

  4. Without prejudice to the generality of 1, the Sub-Processor shall, in relation to any Personal Data processed in connection with the performance by it of its obligations under this agreement:

    1. process that Personal Data only on the documented written instructions of the Initial Processor and/or the Controller which are set out in Schedule 1 unless the Sub-Processor is required by Domestic Law or EU Law to otherwise process that Personal Data. Where the Sub-Processor is relying on Domestic Law or EU Law as the basis for processing Personal Data, the Provider shall promptly notify the Initial Processor of this before performing the processing required by the Domestic Law or EU Law unless the Domestic Law or EU Law prohibits the Sub-Processor from so notifying the Initial Processor.

    2. ensure that it has in place appropriate technical and organizational measures, reviewed and approved by the Initial Processor to protect against unauthorized or unlawful processing of Personal Data and against accidental loss or destruction of, or damage to, Personal Data, appropriate to the harm that might result from the unauthorized or unlawful processing or accidental loss, destruction or damage and the nature of the data to be protected, having regard to the state of technological development and the cost of implementing any measures (those measures may include, where appropriate, pseudonymizing and encrypting Personal Data, ensuring confidentiality, integrity, availability, and resilience of its systems and services, ensuring that availability of and access to Personal Data can be restored in a timely manner after an incident, and regularly assessing and evaluating the effectiveness of the technical and organizational measures adopted by it);

    3. ensure that all of its personnel who have access to and/or process Personal Data are obliged to keep the Personal Data confidential; and

    4. not transfer any Personal Data outside the EEA unless and until the Sub-processor receives proof of the Controller's prior written consent to such transfer and the following conditions are fulfilled:

      1. the Sub-processor has provided appropriate safeguards in relation to the transfer;

      2. the Data Subjects have enforceable rights and effective legal remedies;

      3. the Sub-processor complies with its obligations under the Data Protection Legislation by providing an adequate level of protection to any Personal Data that is transferred; and

      4. the Sub-processor complies with reasonable instructions notified to it in advance by the Initial Processor, in accordance with the Controller's instructions with respect to the processing of the Personal Data;

    5. assist the Initial Processor, in responding to any request from a Data Subject and in ensuring compliance with the Controller's obligations under the Data Protection Legislation with respect to security, breach notifications, impact assessments, and consultations with supervisory authorities or regulators;

    6. notify the Initial Processor without undue delay on becoming aware of a Personal Data Breach;

    7. at the written direction of the Initial Processor delete or return Personal Data and copies thereof to the Initial Processor on termination of the agreement unless required by Domestic Law or EU Law to store the Personal Data; and

    8. maintain complete and accurate records and information to demonstrate its compliance with this clause and allow for audits by the Initial Processor and/or the Controller or the Initial Processor's and/or the Controller's designated auditor and immediately inform the Initial Processor if, in the opinion of the Sub-processor, an instruction infringes the Data Protection Legislation.

    9. The Sub-Processor does and will not use the Personal Data, in whole or in part, to train, fine-tune, evaluate or otherwise improve any machine learning or artificial intelligence model, whether its own or a third party's.

  5. In accordance with its agreement with the Controller and/or instructions, the Initial Processor does not consent to the Sub-processor appointing any third-party further processor of Personal Data under this agreement, except for its hosting provider located within the EEA.

  6. Either party may, at any time on not less than 30 (thirty) days’ notice, revise this clause by replacing it with any applicable processor-to-processor standard clauses or similar terms adopted under the Data Protection Legislation or forming part of an applicable certification scheme (which shall apply when replaced by attachment to this agreement).


For any related question, please contact our Data Protection Officer at dpo@hrflow.ai

Did this answer your question?