Parties and scope
This Data Processing Agreement ("DPA") is between Comitium and the organization using the Service to process recruitment data ("Customer"). It forms part of the Terms of Use and becomes binding when an authorized person accepts those Terms for Customer or Customer otherwise uses the Service to process personal data.
This DPA applies to personal data that Comitium processes for Customer through the Service ("Customer Personal Data"). "Applicable Data Protection Law" means the privacy and data-protection law that applies to that processing. Terms such as "controller", "processor", "personal data", "processing", and "personal data breach" have the meanings given by that law.
If this DPA conflicts with the Terms of Use concerning Customer Personal Data, this DPA controls.
Roles and instructions
Customer is the controller of Customer Personal Data or, where Customer processes it for another controller, a processor acting with that controller's authority. Comitium acts as Customer's processor or subprocessor accordingly.
Comitium will process Customer Personal Data only:
- to provide, secure, support, and maintain the Service;
- through features, settings, and integrations used by Customer's authorized users;
- on Customer's other documented instructions; or
- where law requires processing, after notifying Customer unless notice is prohibited.
The Terms of Use, this DPA, Customer's configuration and use of the Service, and authorized support requests are Customer's documented instructions, including instructions concerning transfers. Customer is responsible for the lawfulness, accuracy, and completeness of its instructions, recruiting process, privacy notices, collection and use of Customer Personal Data, and responses to data subjects. Where Customer acts as a processor, it confirms that the relevant controller has authorized its instructions and Comitium's processing.
If Comitium believes an instruction infringes Applicable Data Protection Law, it will promptly inform Customer and may suspend the affected processing until the matter is resolved.
Confidentiality and security
Comitium will ensure that people authorized to process Customer Personal Data are bound by confidentiality and access it only as needed for their work.
Comitium will maintain technical and organizational measures appropriate to the nature and risk of the processing. The current measures are summarized under Technical and organizational measures. Customer is responsible for the accounts, permissions, integrations, instructions, content, and end-user devices within its control.
Assistance and requests
Taking into account the nature of the processing and the information available to Comitium, Comitium will provide assistance reasonably required by Applicable Data Protection Law concerning:
- requests from people exercising data-protection rights;
- security and personal data breach obligations;
- data-protection impact assessments and prior consultation with a regulator where required; and
- information needed to demonstrate Customer's compliance.
If Comitium receives a request concerning Customer Personal Data, it will direct the requester to Customer or notify Customer, unless law prevents it. Comitium will not independently fulfill the request except on Customer's documented instruction or where law requires it. Customer may be charged reasonable costs for assistance that requires material work beyond the standard Service, except to the extent the request results from Comitium's breach of this DPA or charging is prohibited by law.
Requests can be sent to legal@comitium.co.
Personal data breaches
Comitium will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Comitium will provide available information that Customer reasonably needs to meet its notification obligations and may provide further information in phases. A notification is not an admission of fault or liability.
Subprocessors
Customer gives Comitium general written authorization to use the subprocessors managed under this section and identified under Current subprocessors. Comitium will require each subprocessor to protect Customer Personal Data under data-protection obligations equivalent in substance to those that apply to Comitium and will remain responsible for the subprocessor's performance to the extent required by Applicable Data Protection Law.
Comitium will give reasonable advance notice before adding or replacing a subprocessor that will process Customer Personal Data. Customer may object during the notice period on reasonable data-protection grounds by contacting legal@comitium.co. If the parties cannot resolve the objection, Customer's sole remedy is to stop using the affected feature or terminate the affected Service before the change takes effect.
Public blockchain and IPFS networks are decentralized public infrastructure, not subprocessors controlled by Comitium. Customer instructs Comitium to publish the public Organization, job, transaction, and commitment information submitted to those networks through the Service. Protected recruitment content is not intentionally published to them.
International transfers
Comitium may process Customer Personal Data in the European Economic Area and in other countries where authorized subprocessors operate. Where Applicable Data Protection Law requires a transfer safeguard, Comitium will use an applicable adequacy decision, the relevant standard contractual clauses, or another lawful mechanism. Customer authorizes those transfers and will provide information reasonably needed for their implementation.
Return and deletion
During use of the Service, Customer may request export or deletion of Customer Personal Data through legal@comitium.co. When the affected Service ends, Comitium will, at Customer's choice, return or delete Customer Personal Data unless law requires retention. If Customer chooses return, Comitium will delete controlled copies after completing the return. Residual backup copies will remain protected and be removed through the ordinary backup cycle.
Comitium will stop controlled hosting or pinning of public IPFS content when instructed, but cannot delete copies retained by independent network participants or alter immutable blockchain records. End-to-end encryption may require a Customer user with vault access to unlock protected content before it can be exported in readable form.
Compliance information and audits
Comitium will provide information reasonably necessary to demonstrate compliance with applicable processor obligations. Customer must first use available documentation and written responses. If those materials are insufficient, Customer may request a proportionate audit no more than once in any 12-month period, except after a material personal data breach affecting Customer Personal Data, where a regulator requires otherwise, or where Customer has reasonable documented evidence of material non-compliance.
Audits must use an independent auditor that is not a Comitium competitor, is bound by confidentiality, and has no access to other customers' data. They must begin with remote documentation review, be arranged on at least 30 days' notice unless a regulator requires otherwise, occur during normal business hours, and avoid unreasonable disruption or access to security-sensitive systems. Customer bears all audit costs and will reimburse Comitium's reasonable costs unless the audit establishes a material breach of this DPA by Comitium.
California personal information
This section applies only where the California Consumer Privacy Act, as amended ("CCPA"), applies to Customer Personal Data and Customer discloses that data to Comitium as a service provider or contractor.
Customer discloses this personal information, and Comitium processes it, only for the limited and specified business purposes described under Roles and instructions and Processing details. Comitium will not sell or share it, retain, use, or disclose it outside those purposes or the direct business relationship with Customer, or combine it with personal information from another source except where the CCPA permits. Comitium will provide the level of privacy protection required by the CCPA and certifies that it understands and will comply with these restrictions.
Comitium will notify Customer if it determines that it can no longer meet those obligations. Customer may take reasonable and appropriate steps to verify compliance and may require Comitium to stop and remediate unauthorized use. Comitium will impose applicable restrictions on subprocessors that handle the personal information.
AI-assisted processing
Comitium processes Customer Personal Data through an AI-assisted feature only when Customer enables the feature or otherwise instructs Comitium to use it. The AI Feature Terms govern Customer's use of those features. Comitium does not use Customer Personal Data to train general-purpose AI models.
Duration and changes
This DPA remains in effect while Comitium processes Customer Personal Data. Provisions that by their nature continue after processing ends will survive.
Comitium may update this DPA prospectively to reflect changes in law, the Service, or subprocessors, provided the update does not materially reduce the overall protection of Customer Personal Data. If a change materially affects Customer's rights or obligations, Comitium will provide reasonable advance notice through the Service, by email, or through another appropriate channel, unless the change is needed sooner to comply with law, address an urgent security or abuse risk, or respond to circumstances outside Comitium's reasonable control. The revised DPA will state its effective date.
The limitation of liability and other liability provisions in the Terms of Use apply to this DPA to the maximum extent permitted by law.
Processing details
Subject matter and purpose: providing a recruitment platform, including job publication, application intake, candidate and hiring workflow management, communications, scheduling, secure storage, support, and optional AI-assisted recruiting features.
Duration: while Customer uses the Service and for the limited period needed for deletion, protected backups, legal obligations, security, or dispute resolution.
Nature of processing: collecting, recording, organizing, structuring, encrypting, storing, retrieving, consulting, transmitting, matching, extracting, displaying, restricting, deleting, and otherwise processing personal data on Customer's documented instructions.
Data subjects: candidates, applicants, prospective candidates, referees, Customer personnel, interviewers, recruiters, hiring managers, and other people whose information Customer lawfully submits.
Personal data: identity and contact details; resumes and work history; application answers and attachments; candidate profiles; communications; interview and scheduling details; assessments, notes, feedback, and hiring-stage information; account, permission, audit, device, and security metadata; wallet addresses and related public transaction metadata.
The Service does not require Customer to collect special-category data. If Customer chooses to configure or submit it, Customer is responsible for establishing a lawful basis and applying appropriate safeguards.
Customer's rights and duties: Customer determines its lawful purposes and retention instructions, controls user access, provides required notices, and responds to data subjects. Customer may use the controls and request channels described in this DPA to exercise its controller or processor rights.
Technical and organizational measures
Comitium's current measures include:
- browser-side encryption and encrypted storage for designated private recruitment content;
- encrypted transport and protections for infrastructure and backups;
- Organization-scoped access controls, role permissions, and encrypted vault access for authorized users;
- purpose-bound, time-limited authorization controls for requested service operations;
- separation of public blockchain and IPFS information from protected recruitment content;
- minimized operational logs, security monitoring, dependency maintenance, and incident handling;
- restricted infrastructure access and confidentiality obligations; and
- backup and recovery procedures appropriate to the Service.
These measures may evolve as technology and risk change, provided the overall protection is not materially reduced.
Current subprocessors
- Cloudflare, Inc.: edge hosting, security, API runtime, object storage, queues, email routing, and AI infrastructure.
- Hetzner Online GmbH: database, application, and self-hosted scheduling infrastructure.
- Horkos, LLC d/b/a Privy: authentication and embedded-wallet infrastructure.
- Plus Five Five, Inc. d/b/a Resend: outbound email delivery and delivery status.
- Filebase, Inc.: distribution of public Organization and job information through IPFS.
- Alchemy Insights, Inc.: blockchain RPC access for public Base operations and metadata.
The public Base and IPFS networks are not controlled subprocessors.
Customer-authorized integrations, including Google Calendar and Google Meet, are used at Customer's direction and may also be governed by Customer's or the user's separate relationship with the provider.
Questions about this DPA or a subprocessor can be sent to legal@comitium.co.