This Data Processing Addendum ("DPA") is entered into by and between the entity signing or agreeing to this document ("Customer" or "Data Controller") and Manatal ("Company" or "Data Processor"). This DPA supplements the Subscription Agreement or Manatal Terms and Conditions ("Agreement") between the parties.
1. Definitions
- "Applicable Data Protection Law" means any privacy and data protection law that is legally applicable to a Party’s Processing of Personal Data under the Agreement, including the EU/UK GDPR and the California Consumer Privacy Act (CCPA/CPRA), as amended.
- "Personal Data" means any information relating to an identified or identifiable natural person processed by Manatal on behalf of the Customer in connection with the Services.
- "Data Subject" means the individual to whom the Personal Data relates (e.g., job applicants, candidates, employees).
- "Security Incident" means any actual, confirmed unlawful destruction, loss, alteration, unauthorized disclosure of, or malicious access to Customer’s Personal Data.
2. Scope and Role of the Parties
- 2.1 Relationship: Customer acts as a Controller and Manatal acts as a Processor, except where Customer processes Personal Data on behalf of another Controller, in which case Customer acts as a Processor and Manatal acts as a Subprocessor.
- 2.2 Customer Instructions: Manatal will only Process Personal Data on behalf of and in accordance with the documented instructions of the Customer, including with respect to transfers of Personal Data, unless required to do so by applicable law. The Agreement and this DPA constitute the Customer’s complete instructions. Where applicable law requires Manatal to Process Personal Data other than on Customer's instructions, Manatal will inform Customer of that legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest.
- 2.3 Unlawful Instructions: Manatal will inform Customer without undue delay if, in Manatal’s reasonable opinion, an instruction infringes Applicable Data Protection Law.
3. Technical and Organizational Measures (Security)
- 3.1 Security Program: Manatal shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.
- 3.2 Confidentiality: Manatal ensures that all personnel authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- 3.3 Compliance Assistance: Taking into account the nature of the Processing and the information available to Manatal, Manatal will provide reasonable assistance to Customer with Customer's obligations concerning security of Processing, Personal Data Breach notifications, data protection impact assessments, and prior consultation with supervisory authorities, as required by Applicable Data Protection Law.
4. Subprocessors
- 4.1 Prior Authorization: Customer grants Manatal general written authorisation to engage the Subprocessors identified in Manatal’s then-current Subprocessor List available at Manatal Subprocessor List, which Customer acknowledges and authorises as of the effective date of the Agreement.
- 4.2 Notification of Changes: Manatal will keep the Subprocessor List up to date. Customer may enable notifications to receive written email notice of any intended addition or replacement of a Subprocessor. Customer may object to a new or replacement Subprocessor on reasonable data-protection-specific grounds by providing written notice within seven (7) days after receiving Manatal’s notice. If Customer does not object within that period, Customer shall be deemed to have authorised the new or replacement Subprocessor.
- 4.3 Downstream Flow-Down: Manatal will impose data protection obligations upon any Subprocessor it engages that are no less restrictive than those contractual obligations imposed on Manatal under this DPA, to the extent applicable to the Subprocessor's services.
5. Data Subject Rights & Cooperation
- 5.1 Assistance: Taking into account the nature of the processing, Manatal will provide reasonable assistance to the Customer, insofar as this is possible, to enable the Customer to respond to requests from Data Subjects exercising their rights (e.g., access, deletion, or portability requests).
- 5.2 Direct Requests: If a Data Subject contacts Manatal directly regarding Personal Data belonging to the Customer, Manatal will forward the request to the Customer without undue delay and will not respond directly unless legally required.
6. Incident Management and Notification
- 6.1 Notification: Manatal will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a confirmed Security Incident.
- 6.2 Details: The notification will contain sufficient information to allow the Customer to meet its obligations under Applicable Data Protection Law, including the nature of the breach, the categories of data affected, and the mitigation steps taken or planned.
7. Audit Rights
- 7.1 Documentation: Manatal will make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA.
- 7.2 Formal Audits: To the extent Customer requires an audit to verify compliance, Customer may request a third-party security certification or audit report (SOC 2 Type 2) held by Manatal. If further inspection is legally required, it shall be conducted during regular business hours, no more than once per year, at the Customer's expense, and subject to strict confidentiality agreements.
8. International Data Transfers
8.1 Transfers subject to the GDPR
To the extent that Personal Data subject to the GDPR is transferred to a recipient in a jurisdiction, territory, or specified sector that is not covered by an applicable adequacy decision of the European Commission, the Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914 (“EU SCCs”) are incorporated into this DPA and shall apply to the transfer.
Where Customer acts as a Controller and Manatal acts as a Processor, Module Two (Controller to Processor) shall apply. Where Customer acts as a Processor and Manatal acts as a Subprocessor, Module Three (Processor to Processor) shall apply.
For purposes of the EU SCCs:
- The Customer is the data exporter and Manatal is the data importer.
- By entering into the Agreement, including by electronically accepting Manatal's online Terms and Conditions or signing an offline Agreement that incorporates this DPA, each party agrees to be legally bound by this DPA and the EU SCCs. Such acceptance or signature constitutes execution of Annex I.A of the EU SCCs as of the effective date of the Agreement.
- Annex I.A to the EU SCCs shall be completed with: (i) the parties' identities and contact details set out in the Agreement, this DPA, or, for an online Customer, its account or subscription information; and (ii) the activities relevant to the transfer described in Exhibit A. The acceptance or signature described above supplies the signature and date for Annex I.A.
- Annex I.B to the EU SCCs shall be completed with the processing and transfer details set out in Exhibit A to this DPA.
- Annex I.C to the EU SCCs shall be completed with the competent supervisory authority determined in accordance with Clause 13 of the EU SCCs.
- Annex II to the EU SCCs shall be completed with the technical and organizational measures set out in Exhibit B to this DPA.
- The docking clause in Clause 7 of the EU SCCs shall apply, provided that no entity may accede to the EU SCCs without Manatal’s prior written agreement.
- For Clause 9(a) of the EU SCCs, Option 2 shall apply. The general authorisation, notification, objection and downstream requirements in Section 4 shall apply for purposes of Clause 9(a).
- The optional provision in Clause 11(a) of the EU SCCs shall not apply.
- For Clause 17 of the EU SCCs, Option 1 shall apply, and the EU SCCs shall be governed by the laws of Ireland.
- For Clause 18 of the EU SCCs, disputes arising from the EU SCCs shall be resolved by the courts of Ireland.
- If the EU SCCs conflict with this DPA or the Agreement, the EU SCCs shall prevail with respect to the relevant transfer.
8.2 Transfers Subject to UK Data Protection Law
Where a transfer is subject to UK Data Protection Law and is not otherwise lawfully permitted, the UK Addendum is incorporated into this DPA. Tables 1 to 3 shall be completed with the information and selections in the Agreement, this DPA, Section 8.1, Exhibit A, Exhibit B and, where applicable, Manatal’s Subprocessor List. Table 4 shall be completed by selecting “neither party.”
Acceptance or signature of the Manatal Terms and Conditions, an Agreement or this DPA constitutes execution of the UK Addendum. The UK Addendum shall prevail with respect to the relevant transfer in the event of conflict.
8.3 Transfers Subject to Swiss Data Protection Law
Where a transfer is subject to the Swiss Federal Act on Data Protection and is not covered by an applicable Swiss adequacy determination or another lawful transfer mechanism relied upon by Manatal, the EU SCCs are incorporated into and form part of this DPA as adapted below.
For the relevant Swiss transfer: (a) references in the EU SCCs to the GDPR shall be understood as references to the Swiss Federal Act on Data Protection; (b) references to the EU, Union, Member State and Member State law shall be understood as references to Switzerland and Swiss law, as applicable; (c) the term “Member State” shall not be interpreted to prevent data subjects in Switzerland from bringing proceedings in Switzerland; (d) the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner; and (e) the EU SCCs shall be governed by Swiss law and disputes shall be resolved by the competent courts of Switzerland.
Where a transfer is subject to both the EU GDPR and Swiss law, the EU SCCs shall apply separately under Sections 8.1 and 8.3 to the extent applicable.
8.4 Other Required Transfer Mechanisms
Where a transfer is subject to Applicable Data Protection Law other than the laws addressed above, is not covered by an applicable adequacy decision or another lawful transfer mechanism relied upon by Manatal, and requires an officially approved contractual transfer mechanism, that mechanism shall be incorporated by reference into and form part of this DPA, but only to the extent it may be validly incorporated by reference and is legally required for the relevant transfer.
Unless the mandatory terms require otherwise: (a) Customer is the data exporter and Manatal is the data importer; (b) the parties’ roles are those specified in Section 2.1; (c) the Agreement, Customer’s account or subscription information, Exhibit A and Exhibit B supply the required party, transfer, processing and security information; and (d) acceptance or signature of the Manatal Terms and Conditions, an Agreement or this DPA constitutes acceptance and execution of the applicable terms.
No country-specific mechanism shall apply to Processing that is not subject to the relevant law or impose obligations unrelated to the affected transfer. If the required mechanism cannot validly be incorporated by reference or must be reproduced, completed or executed in a specified language or form, the parties shall complete only the additional documentation legally required before the affected transfer occurs.
If an applicable mechanism ceases to be valid, the parties shall use commercially reasonable efforts to implement a valid replacement. Manatal may suspend the affected transfer until the replacement becomes effective.
9. Return and Deletion of Data
9.1 Termination: Upon termination or expiration of the Agreement, Manatal shall, at the choice and expense of the Customer, delete or return all Personal Data in its possession, custody, or control, unless applicable law requires the continued storage of the Personal Data.
Exhibit A: Details of Processing
| Detail |
Description |
| Categories of Data Subjects |
Job applicants, candidates, potential recruits, external consultants, recruitment agencies and employees or users authorized by the Customer to access the software. |
| Types of Personal Data |
Contact details (name, email, phone number), professional history (CVs, resumes, work experience, education), evaluation notes, interview feedback, social media profiles, and any other recruitment-related information. |
| Nature & Purpose of Processing |
Collecting, organizing, structuring, storing, hosting, and analyzing recruitment data to provide the Manatal recruitment software and Applicant Tracking System (ATS) functionalities as agreed under the Agreement. |
| Duration of Processing |
For the duration of the Agreement plus the period between the expiration of the Agreement and the final deletion of data as specified in Section 9. |
| Frequency of Transfer |
Continuous or recurring for the duration of the Agreement, as necessary for the provision of the Services. |
| Subject Matter of Processing |
Provision, operation, support, security, and maintenance of the Manatal recruitment software and Applicant Tracking System services under the Agreement. |
| Special Categories of Data |
Customer may submit special-category data where permitted by Applicable Data Protection Law. Where such data is submitted, the safeguards include access restrictions, confidentiality obligations, encryption in transit and at rest, and the other measures described in Exhibit B. |
| Retention and Deletion |
Personal Data is retained for the duration of the Agreement and thereafter only for the period reasonably necessary to return or delete the data in accordance with Section 9, including deletion through Manatal's ordinary backup lifecycle, unless applicable law requires longer retention. |
| Subprocessor Processing (Module Three) |
The subject matter, nature, and duration of Processing by Manatal and its Subprocessors correspond to the services, Processing operations, and duration described in this Exhibit A and the applicable Subprocessor services. |
Exhibit B: Technical & Organizational Security Measures
Manatal maintains a robust, enterprise-grade security posture designed to protect the confidentiality, integrity, and availability of Customer Data. The Company continually reviews and improves these measures, maintaining compliance with SOC 2 Type II standards.
1. Data Encryption & Privacy
Data in Transit: All communication between Customer users and Manatal production servers is mandatory over HTTPS, utilizing secure SSL/TLS 1.2 or higher encryption protocols.
Data at Rest: All core customer databases and files are fully encrypted at rest using industry-standard AES-256 encryption algorithms.
Credentials Security: User authentication credentials are safely transformed using advanced one-way cryptographic hashing algorithms; plain-text passwords are never stored anywhere within the system.
2. Infrastructure & Hosting Security
Top-Tier Cloud Infrastructure: All Services run exclusively in a secure multi-tier network environment hosted on Amazon Web Services (AWS) in the United States.
Data Center Compliance: Physical infrastructure centers are managed by AWS and maintain strict adherence to global standards, accredited under ISO 27001, SOC 1, SOC 2, SSAE 16, and ISAE 3402.
Resilience & Uptime: Built with modern disaster-recovery and failover infrastructure to ensurea contractual service uptime level of 99.9% or higher.
3. Business Continuity & Backup Lifecycle
Daily Snapshots: Manatal runs full, automated daily backups of all system databases to protect against catastrophic events.
Backup Integrity: Backups are securely encrypted, stored isolated from production environments, and rigorously tested to ensure immediate availability.
Retention Policy: All daily automated backups are permanently overwritten and naturally purged on a strict 7-day retention cycle.
4. Identity & Access Control
Internal Personnel Restrictions: Access to underlying systems and customer environments is strictly restricted to a limited pool of authorized key engineering staff on a "need-to-know" basis, governed by signed corporate confidentiality agreements.
Privileged System Access: Internal operational access to AWS, GitHub, and production backends strictly enforces complex password policies and mandatory Multi-Factor Authentication (MFA / 2FA).
Customer Role-Based Access Control (RBAC): The software platform provides customizable, multi-tier user role permissions, ensuring that Customer data is partitioned internally so users can only view records they are explicitly authorized to access.
5. Vulnerability Management & Engineering
Secure Development Practices: Engineering teams utilize strict secure coding practices heavily aligned with defending against the OWASP Top 10 web application security risks.
Continuous Detection: Deployment of automated vulnerability detection software and real-time security scanning to actively monitor environment changes.
Proactive Threat Mitigation: Continuous infrastructure monitoring with real-time automated threat alarms configured to immediately flag anomalies to on-call engineering response teams.
Responsible Disclosure: Maintenance of an active, monitored Vulnerability Disclosure Program allowing vetted security researchers to responsibly report zero-day bugs directly to security engineers via dedicated channels (vulnerability-report@manatal.com).