TalentSync™ Data Processing Addendum (DPA)

This Data Processing Addendum ("DPA") forms part of the TalentSync™ Enterprise Terms of Service (the "Agreement").


1. DEFINITIONS

1.1 "Agreement" has the meaning set forth in Section 1.1 of the Enterprise Terms of Service.

1.2 "Client" means the Data Controller as defined in the Agreement.

1.3 "TriStarr" means the Data Processor.

1.4 "Candidate Data" has the meaning set forth in Section 1.4 of the Agreement.

1.5 "Applicable Data Protection Laws" means U.S. federal and state privacy laws applicable to the processing of personal data.

 

2. ROLES OF THE PARTIES

2.1 Client is the Data Controller.

2.2 TriStarr acts solely as a Data Processor processing Candidate Data on documented instructions from Client pursuant to Section 4 of the Agreement.

 

3. PROCESSOR OBLIGATIONS

3.1 Processing Instructions. TriStarr shall process Candidate Data only on documented instructions from Client.

3.2 Confidentiality. TriStarr shall ensure personnel are bound by confidentiality obligations consistent with Section 5 of the Agreement.

3.3 Security Measures. TriStarr shall implement commercially reasonable technical and organizational safeguards.

3.4 Breach Notification. TriStarr shall notify Client without undue delay and, where feasible, within seventy-two (72) hours of confirmation of a personal data breach.

 

4. SUBPROCESSORS

4.1 Client authorizes TriStarr to engage subprocessors subject to confidentiality and data protection obligations materially consistent with this DPA.

 

5. DATA RETURN AND DELETION

5.1 Upon termination of the Agreement pursuant to Section 7 thereof, TriStarr shall return or delete Candidate Data within thirty (30) days unless retention is required by Applicable Data Protection Laws.

 

6. AUDIT RIGHTS

6.1 Upon reasonable written request, TriStarr shall provide information reasonably necessary to demonstrate compliance with this DPA.