CG Recruit Data Processing Addendum
Effective date: [EFFECTIVE DATE]
This Data Processing Addendum ("DPA") forms part of the CG Recruit Terms of Service between MYCG AI TECH LLC, a Kentucky limited liability company ("Processor", "we") and the customer ("Customer", "Controller"). If this DPA conflicts with the Terms on data protection, this DPA wins.
1. Roles
- Customer is the controller (or "business" under the CCPA) of personal data about candidates, references, vendor contacts and its own users that it puts into, or collects through, CG Recruit ("Customer Personal Data").
- MYCG AI TECH LLC is the processor (or "service provider" / "processor" under US state privacy laws) and processes Customer Personal Data only on Customer's documented instructions.
- The Terms, Customer's configuration of the service and actions taken by Customer's users in the app are Customer's instructions.
2. Details of processing
| Item | Description |
|---|---|
| Subject matter | Providing CG Recruit, a recruiting workflow tool for IT staffing firms |
| Duration | The term of the Terms plus the deletion period in section 10 |
| Nature and purpose | Hosting, parsing resumes and requirement emails with AI, matching, drafting and sending email and text messages, running written screenings, recording RTR confirmations and references, reading work authorization documents, preparing submissions, audit logging, support |
| Data subjects | Job candidates, references, vendor and client contacts, Customer's users |
| Categories of data | Identity and contact details; resume and employment history; skills and education; messages; screening answers; screening integrity telemetry (paste events, pasted character counts, tab switches, keystroke counts, time per answer); work authorization fields extracted from documents (document type, category, name, validity dates, employer); RTR records (typed name, timestamp, IP address, user agent); reference answers; rates and pay type |
| Sensitive data | Immigration or work authorization status. Customer must not upload other sensitive data (for example health data, Social Security numbers, passport numbers beyond what the document read requires) unless needed and lawful. |
| Location | United States |
3. Processor obligations
We will:
- Process Customer Personal Data only on Customer's instructions, and tell Customer if we think an instruction breaks the law.
- Not sell or share Customer Personal Data, not use it for our own purposes (including training AI models), and not combine it with other data except as allowed by law to provide the service.
- Ensure everyone with access is bound by confidentiality.
- Apply the security measures in section 6.
- Help Customer respond to data subject requests (section 7) and with security assessments where reasonably required.
- Notify Customer of a personal data breach without undue delay, and in any case within [72] hours of becoming aware, with the information Customer reasonably needs.
- Delete or return data at the end of the service (section 10).
- Make available information reasonably needed to show compliance with this DPA (section 9).
4. Customer obligations
Customer will:
- Have a lawful basis, give required notices, and obtain any consents needed for the processing, including consent before text messages and consent to screening telemetry.
- Make sure its instructions comply with law, including TCPA, CAN-SPAM, EEO and anti-discrimination laws, state privacy laws and, where it uses the service for background screening, the FCRA.
- Have a human review AI output before making decisions about any person.
- Verify work authorization through lawful channels. The service is not an I-9 or E-Verify tool.
5. Sub-processors
Customer authorizes the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting and serverless compute | United States |
| Supabase Inc. | Database, authentication and file storage | United States |
| Anthropic PBC | AI processing (Claude) of resumes, requirements, messages, screening answers and documents | United States |
| Resend (Plus Five Five, Inc.) | Sending and receiving email | United States |
| Stripe, Inc. | Subscription billing for Customer (not candidate data) | United States |
| Twilio Inc. | Sending and receiving text messages | United States |
- We impose data protection terms on each sub-processor that are at least as protective as this DPA, and we stay responsible for them.
- We will give at least [30] days notice of a new or replacement sub-processor at [SUBPROCESSOR PAGE] or by email. Customer may object on reasonable data protection grounds. If we cannot address the objection, Customer may end the affected service and receive a pro rata refund of prepaid fees.
6. Security measures
- Encryption in transit (TLS) and at rest (provider managed).
- Logical separation of each customer's data, enforced by database row level security and composite keys.
- Role-based access within each customer workspace; least privilege access for our staff; service credentials kept server side.
- Work authorization files are read in memory and discarded. Only extracted fields are stored.
- Public candidate links (screening, RTR, reference) use long random tokens and are served only through server code.
- Audit logging of user actions; suppression lists for opt outs and bounces.
- Backups with limited retention; incident response procedures.
- [COUNSEL / OPS: attach a fuller technical and organizational measures annex once SOC 2 or equivalent work begins.]
7. Data subject requests
If we receive a request from a data subject about Customer Personal Data, we will pass it to Customer and not respond ourselves except to confirm it was routed, unless the law requires otherwise. The app lets Customer find, export, correct and delete a candidate's data. We will give further reasonable help on request.
8. Opt outs
Opt out requests received by text (STOP) or email unsubscribe are recorded on Customer's suppression list and honored automatically. Customer must not work around them.
9. Audits
On written request no more than once a year, we will answer a reasonable security questionnaire and share available third party reports of our sub-processors. On-site audits require reasonable notice, are at Customer's cost, and are limited to what is needed where the questionnaire is not enough or a regulator requires it.
10. Deletion and return
Customer can export its data at any time during the subscription and for 30 days after it ends. After that we delete Customer Personal Data within [30] days, and backups roll off within [35] days, unless the law requires us to keep it.
11. International transfers
Customer Personal Data is stored and processed in the United States. If Customer is subject to laws that restrict transfers to the United States, Customer must tell us before uploading such data so the parties can agree on a transfer mechanism. [COUNSEL: add EU SCCs / UK addendum if non-US customers are accepted.]
12. Liability
Each party's liability under this DPA is subject to the limits in the Terms, unless the law does not allow it.
13. Contact
Privacy: [PRIVACY EMAIL]. MYCG AI TECH LLC, [ADDRESS].
Signed for Customer: [NAME, TITLE, DATE]
Signed for MYCG AI TECH LLC: [NAME, TITLE, DATE]
terms of service · privacy policy · data processing addendum · sms terms · acceptable use
