This Data Processing Addendum ("DPA") forms part of the Master Services Agreement or Terms of Service ("Agreement") between Anderise LLC ("Anderise") and the Client.
Where there is a conflict between this DPA and our Terms of Service, this DPA governs with respect to the processing of personal data. Capitalised terms not defined here have the meaning given in our Terms.
01Definitions
- Personal Data: Any information relating to an identified or identifiable natural person processed under the Services.
- Controller: The entity that determines the purposes and means of processing Personal Data — typically the Client.
- Processor: The entity that processes Personal Data on behalf of the Controller — Anderise.
- Sub-processor: Any third party engaged by Anderise to process Personal Data.
- Data Protection Laws: All applicable laws on data protection and privacy, including the GDPR, UK GDPR, and the CCPA/CPRA, as applicable.
02Roles and Scope of Processing
The parties acknowledge that, with respect to the processing of Personal Data, the Client is the Controller and Anderise is the Processor. Anderise will process Personal Data only:
- To provide and support the Services as described in the agreement;
- In accordance with the Client's documented lawful instructions; and
- As required by applicable law, in which case Anderise will inform the Client of that legal requirement before processing, unless prohibited from doing so.
The subject matter, duration, nature, and purpose of processing, the types of Personal Data, and the categories of data subjects are set out in Annex A below.
03Anderise's Obligations
As Processor, Anderise will:
- Confidentiality: Ensure that personnel authorised to process Personal Data are bound by appropriate confidentiality obligations.
- Security: Implement appropriate technical and organisational measures to protect Personal Data, as described in our Security practices and Section 6 below.
- Assistance:Assist the Client, taking into account the nature of processing, in responding to data subject requests and in meeting the Client's obligations regarding security, breach notification, and impact assessments.
- Deletion or return:At the Client's choice, delete or return all Personal Data at the end of the Services, unless retention is required by law.
04Sub-processing
The Client provides general authorisation for Anderise to engage Sub-processors to support the Services. Anderise will:
- Impose data protection obligations on each Sub-processor that are no less protective than those in this DPA;
- Remain liable to the Client for the performance of each Sub-processor's obligations; and
- Make available a current list of Sub-processors and notify the Client of intended changes, giving the Client the opportunity to object on reasonable grounds.
Current Sub-processors include providers of cloud hosting, payment processing, applicant tracking, and communications, listed at legal@anderise.com upon request.
05International Data Transfers
Anderise connects LATAM talent with companies in the United States and globally, which may involve transfers of Personal Data across borders. Where Personal Data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, the parties agree that the applicable Standard Contractual Clauses (or equivalent valid transfer mechanism) are incorporated into this DPA by reference and will apply to such transfers.
06Security Measures
Anderise maintains a security program that includes, at minimum:
- Encryption of Personal Data in transit and at rest;
- Role-based access controls and the principle of least privilege;
- Regular logging, monitoring, and vulnerability management;
- Personnel security training and background checks where lawful; and
- A documented incident response process.
07Personal Data Breach
Anderise will notify the Client without undue delay after becoming aware of a Personal Data breach affecting the Client's Personal Data, and will provide information reasonably available to assist the Client in meeting its own notification obligations under Data Protection Laws.
08Audits
Anderise will make available to the Client information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Client or an auditor mandated by the Client, subject to reasonable notice, confidentiality, and limits on frequency.
09Annex A — Details of Processing
- Subject matter: Provision of remote staff augmentation and talent matching services.
- Duration: The term of the agreement plus any legally required retention period.
- Nature and purpose: Collection, storage, organisation, and transfer of Personal Data to match professionals with Client roles and administer the engagement.
- Types of Personal Data: Names, contact details, professional history, CV/resume data, and billing information.
- Categories of data subjects: Client representatives, candidates, and engaged professionals (talent).
10Contact Us
To request a signed copy of this DPA or our current Sub-processor list, please contact us:
Anderise LLC — Data Protection
Email: privacy@anderise.com
Entity: Anderise LLC, registered in the State of Wyoming, USA.