Data Processing Agreement (DPA)
DRAFT — review with a CA-DPO/lawyer before commercial use. This document is a template for the joint-processing arrangement between TrustGraph and a Customer Company; sign-off is required before commercial activation.
Effective date: 2 May 2026
This Data Processing Agreement ("DPA") supplements the Terms of Service between TrustGraph ("we", "us") and the Customer Company ("Customer", "you") that has signed up to post jobs on the platform.
1. Roles
For candidate personal data that we surface to you (the Customer) within your hiring queue:
- TrustGraph acts as a Data Fiduciary in respect of the candidate's relationship with the platform.
- The Customer acts as a co-Data Fiduciary in respect of the candidate's relationship with the Customer's hiring process — independently determining what to do with the data once received (interview, archive, reject, etc.).
The arrangement is one of co-Data Fiduciaries, not a Processor relationship. Each party is independently responsible for its own DPDP-Act compliance after the data crosses the platform boundary into the Customer's systems.
2. Categories of data shared with the Customer
| Category | Notes |
|---|---|
| Candidate name and headline | Visible by default |
| Candidate email | Visible only after the candidate accepts the intro |
| Candidate phone | Visible only after the candidate explicitly shares it |
| Resume (parsed skills + structured fields) | Visible to the Customer in the candidate card |
| Resume (full PDF) | Visible only after the candidate clicks "Share full resume" |
| Warmth path (chain of intermediate users) | Visible by default for transparency about why the candidate was surfaced |
The Customer must not request data the candidate has not consented to share, and must not use any visible data for purposes beyond evaluating the candidate for the specific posted role.
3. Customer obligations
The Customer agrees:
- To process candidate data only for the purpose of evaluating, interviewing, and (if applicable) hiring for the posted role.
- To not share candidate data with any third party (recruiting agency, parent company, etc.) without the candidate's explicit consent.
- To not retain rejected candidates' data beyond 6 months unless the candidate has affirmatively opted into a Customer talent pool.
- To respond to candidate Data Principal requests (access, correction, erasure) routed through the platform within 30 days.
- To maintain reasonable security including access controls, encryption-at-rest where appropriate, and incident response.
- To notify TrustGraph within 48 hours of becoming aware of any personal-data breach affecting candidate data received via the platform.
- To not attempt to re-identify anonymised data the platform has provided.
4. Sub-processors
The Customer may engage sub-processors (e.g., its own ATS) provided the sub-processor is bound by terms no less protective than this DPA. The Customer remains responsible to TrustGraph and to candidates for sub-processor compliance.
5. Cross-border transfers
If the Customer transfers candidate data outside India, the Customer is responsible for ensuring the transfer satisfies DPDP §16 (notified country list or candidate consent).
6. Audit
TrustGraph may, on reasonable notice, request written confirmation of the Customer's compliance with this DPA. On-site audit rights are reserved for cases where a documented breach has occurred.
7. Term and termination
This DPA runs for as long as the Customer holds an active account. On termination:
- Candidate data already integrated into the Customer's hiring records may be retained for the Customer's lawful purposes.
- The Customer must delete or anonymise candidate data not so integrated within 30 days of termination.
8. Indemnity
Each party indemnifies the other against losses arising from its own breach of this DPA, capped per the limitation in Terms of Service §9.
9. Governing law
This DPA is governed by Indian law and is subject to the exclusive jurisdiction of the courts at Bangalore.
10. Acknowledgement
Posting a job on the platform constitutes acceptance of this DPA by an authorised representative of the Customer.