This Data Processing Agreement ("DPA") is incorporated into, and forms part of, the Terms of Service between Silicon Prairie Technologies, LLC ("Processor," "Company") and the customer entity agreeing to the Terms of Service ("Controller," "Customer"). This DPA applies to the extent Company processes Candidate personal data on Customer's behalf in connection with the Service, as described in the Terms of Service and Privacy Policy.
1. Definitions
- "Personal Data" means information relating to an identified or identifiable individual that Company processes on Customer's behalf as part of the Service, principally Candidate information Customer submits.
- "Processing" has the meaning commonly given under applicable data protection law, and includes any operation performed on Personal Data, such as collection, storage, use, and deletion.
- "Sub-processor" means a third party engaged by Company to process Personal Data in connection with providing the Service.
- "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data processed by Company.
2. Roles of the Parties
As between the parties, Customer is the Controller of Candidate Personal Data submitted to the Service, and Company is the Processor, acting only on Customer's documented instructions as set out in the Terms of Service, this DPA, and Customer's configuration and use of the Service.
3. Subject Matter, Duration, and Nature of Processing
Company processes Personal Data for the duration of Customer's subscription to the Service, for the purpose of providing recruiting screening functionality, including candidate record management, AI-assisted interview question generation, and screening session tracking. The categories of data subjects are principally Candidates whose information Customer submits to the Service. The categories of Personal Data typically include name, email address, phone number, resume content, employment history, and screening notes and ratings entered by Customer's personnel.
A subset of Personal Data, specifically resume content, is transmitted to Company's AI sub-processor (Anthropic) as described in Section 5, for the purpose of automated timeline-consistency review and skill extraction.
4. Processor Obligations
- Process Personal Data only on Customer's documented instructions, including as set out in the Terms of Service, unless otherwise required by law.
- Ensure personnel authorized to process Personal Data are subject to confidentiality obligations.
- Implement appropriate technical and organizational measures designed to protect Personal Data, as described in Section 6.
- Not engage a new Sub-processor without providing Customer notice and an opportunity to object, as described in Section 5.
- Provide reasonable assistance to Customer in responding to requests from data subjects, recognizing that such requests will typically be directed to Customer as the Controller in the first instance.
- Notify Customer of a Security Incident affecting Customer's Personal Data as described in Section 7.
- At Customer's request, and subject to the Service's standard data retention and deletion functionality, delete Personal Data upon termination of the subscription, except to the extent retention is required by law.
5. Sub-processors
Customer authorizes Company to engage the following Sub-processors in connection with the Service:
Sub-processor
Function
Nature of Processing
Supabase
Database, authentication, file storage
Hosts substantially all Candidate personal data processed through the Service, including candidate records and resume files.
Anthropic
AI content generation
Processes job description and role information to generate interview questions and answer guidance, and processes Candidate resume content, after an automated redaction step, to perform automated timeline-consistency review and skill extraction. Before transmission, the Service applies redaction intended to remove the Candidate's name and email address; phone number and street address, where present, are redacted on a best-effort basis and may not be removed in all cases. Redacted resume content may still include employment history, job titles, dates, and skills associated with the Candidate. Does not perform scoring, ranking, or evaluation of Candidates; output is limited to informational flags and extracted skill terms for Customer's own review.
Resend
Transactional email
Delivers account and notification email, which may reference Candidate names in limited contexts (such as assignment notifications).
Upstash
Rate limiting, background job processing
Processes job identifiers and infrastructure-level data in support of Service functionality.
Vercel
Application hosting
Hosts the application infrastructure through which the Service is delivered.
Stripe
Payment processing
Processes Customer billing information. Does not process Candidate personal data.
Sentry
Error tracking and monitoring
Processes technical error data (stack traces, request paths, internal record identifiers) for the purpose of identifying and resolving Service defects. Does not receive Candidate names, contact information, resume content, or other Personal Data content by design; a technical redaction process is applied to captured data before transmission.
Axiom
Log aggregation
Processes structured operational logs (request metadata, internal record identifiers, timestamps) for the purpose of Service operation and troubleshooting. Same redaction process as described for Sentry above applies.
Company will provide notice to Customer before engaging a new Sub-processor that will process Personal Data, and Customer may object on reasonable data protection grounds within a reasonable period following that notice.
6. Security Measures
Company implements technical and organizational measures designed to protect Personal Data, including tenant-level data isolation enforced at the database layer so that one customer's data is not accessible to another, encryption of data in transit, role-based access controls limiting internal access to Personal Data to personnel who require it to provide support, and a structured internal security review process applied prior to launch and on an ongoing basis. Company does not currently hold a formal third-party security certification such as SOC 2; Customer should confirm whether such certification is required for its own compliance purposes.
Where Company applies automated redaction to reduce Personal Data exposure — including redaction applied to Candidate resume content before it is sent to Company's AI sub-processor, and redaction applied to data sent to logging and monitoring systems — such redaction is a technical measure designed to reduce, not guarantee elimination of, incidental exposure. Certain categories, such as phone number and street address within resume content, are redacted on a best-effort basis and may not be removed in every instance.
7. Security Incident Notification
Company will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Customer's Personal Data, and will provide reasonably available information to help Customer understand the nature and scope of the incident.
8. International Data Transfers
The Service and its Sub-processors are intended to process Personal Data within the United States. As described in the Terms of Service, the Service is not directed at, and is not intended for, individuals or entities located in the European Union, the European Economic Area, or the United Kingdom, and this DPA does not address the transfer of Personal Data from those regions.
9. Audits and Compliance
Upon reasonable request, and no more than once per year absent a Security Incident, Company will make available information reasonably necessary to demonstrate compliance with this DPA, such as a summary of its security practices.
10. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations of liability set out in the Terms of Service.
11. Term
This DPA remains in effect for as long as Company processes Personal Data on Customer's behalf under the Terms of Service, and the obligations in Sections 4 through 7 survive termination to the extent Company continues to hold Personal Data.
12. Contact
Questions about this DPA may be directed to privacy@siliconprairietechnologies.com.