Data Processing Agreement
GDPR-compliant data processing terms for enterprise customers
Overview
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Hirebee HRMS (“Processor”) and the customer (“Controller”) who processes personal data using our services.
This DPA ensures compliance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, and other applicable privacy legislation. It establishes the obligations of each party regarding the processing of personal data.
This DPA applies automatically to all customers whose use of Hirebee involves the processing of personal data of individuals located in the European Economic Area (EEA), the United Kingdom, or Switzerland.
Definitions
Controller
The customer who determines the purposes and means of processing personal data.
Processor
Hirebee HRMS, which processes personal data on behalf of the Controller.
Personal Data
Any information relating to an identified or identifiable natural person ('data subject').
Sub-processor
A third party engaged by Hirebee to process personal data on behalf of the Controller.
Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
Processing
Any operation performed on personal data, including collection, recording, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.
Scope & Purpose
Categories of Data Processed
- Employee personal information (name, email, phone number, address)
- Employment data (job title, department, start date, salary information)
- Leave and attendance records
- Performance review data and feedback
- Recruitment and applicant data
- Training and development records
Data Subjects
- Current, former, and prospective employees of the Controller
- Job applicants and candidates
- Contractors and temporary workers
- Emergency contacts and dependents (limited data)
Processing Activities
- Storage and retrieval of employee records
- Processing payroll and benefits administration
- Managing leave requests and attendance tracking
- Facilitating recruitment workflows and applicant tracking
- Generating reports and analytics (aggregated/anonymized where possible)
Data Processing Principles
Hirebee shall process personal data in accordance with the following principles:
- Lawfulness: Process data only on documented instructions from the Controller
- Purpose limitation: Process data only for the specified purposes outlined in this DPA
- Data minimization: Ensure only necessary data is collected and processed
- Accuracy: Maintain data accuracy and provide tools for the Controller to rectify data
- Storage limitation: Retain data only for as long as necessary to fulfill processing purposes
- Confidentiality: Ensure all personnel authorized to process data are bound by confidentiality obligations
Security Measures
Technical Safeguards
- End-to-end encryption for data in transit (TLS 1.2+) and at rest (AES-256)
- Multi-factor authentication and role-based access controls
- Regular security monitoring, vulnerability scanning, and penetration testing
- Secure data centers with SOC 2 Type II compliance
- Automated backups with encrypted off-site storage
Organizational Measures
- Employee privacy training and confidentiality agreements
- Regular privacy impact assessments (DPIAs)
- Third-party vendor management and due diligence
- Designated Data Protection Officer (DPO)
Incident Response
In the event of a personal data breach, Hirebee will notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach. The notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
Sub-processors
Hirebee engages certain third-party sub-processors to assist in providing our services. We maintain a list of current sub-processors and will update the Controller prior to any changes.
Notification & Objection
- Hirebee will notify the Controller at least 30 days before engaging a new sub-processor
- The Controller may object to the engagement of a new sub-processor within 14 days of notification
- If a reasonable objection is raised, Hirebee will make reasonable efforts to provide an alternative or allow the Controller to terminate the affected services
Due Diligence
All sub-processors are subject to the same data protection obligations as set out in this DPA. Hirebee conducts regular audits of sub-processors to ensure ongoing compliance with security and privacy requirements.
Data Subject Rights
Hirebee will assist the Controller in fulfilling data subject requests under GDPR, including:
- Right of access — provide copies of personal data being processed
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure — delete personal data (“right to be forgotten”)
- Right to restrict processing — limit how data is processed
- Right to data portability — export data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — withdraw previously given consent at any time
Hirebee will respond to data subject requests within 30 days and will promptly notify the Controller of any direct requests received from data subjects.
International Transfers
Data may be transferred to and processed in countries outside the EEA. Hirebee ensures adequate protection through the following mechanisms:
- Standard Contractual Clauses (SCCs): We use the European Commission's approved SCCs (2021/914) for transfers to countries without an adequacy decision
- Adequacy decisions: Where available, we rely on European Commission adequacy decisions recognizing equivalent data protection standards
- Supplementary measures: We implement additional technical and organizational safeguards where required by transfer impact assessments
- UK Addendum: For transfers from the UK, we apply the International Data Transfer Addendum to the EU SCCs as approved by the UK ICO
Get the Full DPA
Enterprise customers can request the complete Data Processing Agreement including detailed annexes and technical specifications. For questions about data processing practices, contact our legal team.
Contact Us