Data Processing Agreement (DPA)

Data & Security

Gappeo is committed to protecting your data with enterprise-grade security. Our Data Processing Agreement outlines exactly how we collect, process, and secure your information.

GDPR CompliantCCPA CompliantDPDP Act 2023ISO 27001 ReadySOC 2 Ready48-hr Breach Notification

Overview

This Data Processing Agreement ("DPA") forms part of the Master Subscription Agreement or Terms of Service between Uprise Labs Pvt. Ltd. ("Gappeo" or "Processor") and the entity purchasing or using the Services ("Customer" or "Controller").

Gappeo is committed to processing your data securely, transparently, and in full compliance with applicable data protection laws including GDPR, CCPA, and the Digital Personal Data Protection Act, 2023 (India).

1. Key Definitions

AffiliateAny entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity.
Authorized Sub-processorA third-party data processor engaged by Gappeo who has or potentially will have access to or process Personal Data from the Controller.
ControllerThe entity which determines the purposes and means of the Processing of Personal Data.
Data Protection LawsAll applicable laws and regulations including the EU GDPR (2016/679), the California Consumer Privacy Act (CCPA), the Digital Personal Data Protection Act, 2023 (India), and any other applicable data protection legislation.
Data SubjectThe identified or identifiable natural person to whom Personal Data relates (e.g., job candidates, applicants).
Personal DataAny information relating to a Data Subject that is processed by Gappeo on behalf of the Customer in the course of providing the Services.
ProcessingAny operation or set of operations performed on Personal Data, such as collection, recording, organization, storage, retrieval, use, disclosure, or deletion.
ServicesThe AI-powered hiring platform services, including AI telephonic screening, AI video interviews, and candidate assessments provided by Gappeo.

2. Scope & Roles

This DPA applies where Gappeo processes Personal Data on behalf of the Customer as a Processor to provide the Services described in the Agreement.

The Customer acts as a Data Controller and Gappeo acts as a Data Processor.

3. Processing of Personal Data

  • Instructions: Gappeo shall process Personal Data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by applicable law.
  • Purpose: The subject matter, duration, nature, and purpose of the processing are described in Annex I.
  • AI & Biometric Data: The Customer acknowledges that the Services utilize Artificial Intelligence to analyze candidate voice (Telephonic Screening) and visual/tonal data (Video Interviews). The Customer is responsible for ensuring it has a valid legal basis (such as explicit consent) for the collection and processing of such data, including biometric information where applicable.

4. Gappeo's Obligations

  • Confidentiality: Gappeo shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Security: Gappeo shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as outlined in Annex II.
  • Data Subject Rights: Gappeo shall assist the Customer by appropriate technical and organizational measures for the fulfillment of the Customer's obligation to respond to requests for exercising Data Subject rights.
  • Impact Assessments: Gappeo shall provide reasonable assistance for any data protection impact assessments and prior consultations with supervising authorities, specifically regarding the use of AI-driven automated decision-making.

5. Sub-processors

The Customer provides a general authorization for Gappeo to engage Sub-processors to process Personal Data for the purpose of providing, securing, and supporting the Services. Gappeo shall maintain a list of its Authorized Sub-processors and shall inform the Customer of any intended changes.

The Customer may object to a new Sub-processor on reasonable grounds relating to data protection by providing written notice to Gappeo within ten (10) business days of receiving notice of the change.

Gappeo shall impose data protection terms on any Sub-processor it appoints that require the Sub-processor to protect Personal Data to the same standard required of Gappeo under this DPA.

6. Personal Data Breach Notification

Gappeo shall notify the Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach involving Personal Data processed under this DPA.

Such notification shall include: a description of the nature of the breach; the likely consequences; and the measures taken or proposed to address the breach.

Gappeo shall provide reasonable further information and cooperation to support the Customer's obligations to notify supervisory authorities, regulators, and/or affected Data Subjects under applicable Data Protection Laws.

Unless required by applicable law, Gappeo's notification of a Personal Data Breach shall not be construed as an admission of fault or liability.

7. International Data Transfers

Gappeo may process Personal Data in India or any other country where Gappeo or its Sub-processors maintain facilities.

Where required by applicable Data Protection Laws, Gappeo shall ensure that international transfers are implemented with appropriate safeguards and transfer mechanisms, including: Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA; the UK International Data Transfer Agreement (IDTA) for transfers from the UK; and the Swiss Federal Data Protection Act recognized transfer mechanisms.

Where the Customer is subject to the Digital Personal Data Protection Act, 2023 (India) and cross-border transfer restrictions apply, the parties shall ensure transfers occur only in accordance with applicable Indian law.

8. Audits & Compliance

Gappeo shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer, no more than once per year.

9. Data Deletion & Return

Upon termination of the Agreement, Gappeo shall, at the choice of the Customer, delete or return all Personal Data to the Customer and delete existing copies unless applicable law requires storage of the Personal Data.

10. Liability

Each party's liability taken together in the aggregate arising out of or related to this DPA shall be subject to the exclusions and limitations of liability set forth in the Agreement.

11. Governing Law

This DPA shall be governed by the laws of India. The courts at Bangalore, Karnataka, India shall have exclusive jurisdiction over any dispute arising out of or in connection with this DPA.

Annex I: Details of Processing

Subject MatterThe provision of AI-powered recruitment and assessment services.
DurationThe term of the Agreement plus the period until deletion of all data by Gappeo in accordance with the DPA.
Nature & PurposeAutomated screening and telephonic interviewing; AI video analysis (tone, expression, and soft skills); Technical and behavioral assessments; Shortlisting and reporting for recruitment purposes.
Data SubjectsJob applicants and candidates; Customer's employees (users of the platform).
Types of Personal DataIdentification data (Name, email, phone, address); Professional data (Resumes, work history, skill sets, education); Audio/Visual data (Recordings of telephonic and video interviews); AI Insights (Personality analysis, live scoring, and assessment results).

Annex II: Technical & Organizational Security Measures

Access Control

Restricted access to Personal Data based on the principle of least privilege, including role-based access controls and periodic access reviews.

Encryption

Encryption of Personal Data at rest and in transit (SSL/TLS or equivalent industry-standard cryptography).

Integrity

Regular backups and disaster recovery protocols, including monitoring for unauthorized changes and restoration testing.

Resilience

Use of Tier-1 cloud infrastructure providers (e.g., AWS/Azure/GCP) with industry-standard certifications (ISO 27001, SOC 2 or equivalent).

Logging & Monitoring

Security logging for key systems and administrative actions, with alerting for suspicious activity.

Vulnerability Management

Regular patching and vulnerability scanning; security testing processes appropriate to the nature of the Services.

Incident Response

Documented incident response procedures and escalation paths for security events and Personal Data Breaches.

Business Continuity

Measures to maintain availability and recoverability appropriate to the risk (e.g., redundancy, backups, and disaster recovery planning).

Personnel Security

Background checks where permitted by law; security awareness training; confidentiality obligations for personnel with access to Personal Data.

Data Minimization

Logical controls supporting retention and deletion consistent with Customer instructions and the Agreement.

AI Ethics

Regular auditing and evaluation of AI models to minimize algorithmic bias and improve data quality and accuracy; governance controls around model changes.

Physical Security

Security measures implemented at data centers by infrastructure providers, including controlled access and environmental safeguards.

Questions about data & security?

Reach out to our team for any DPA inquiries, security documentation, or compliance questions.

info@gappeo.ai →