Perfs.

Data processing addendum (DPA)

*This is the document a customer's legal team will ask for. Publish it at a stable URL and reference it from your Terms. Most customers will accept a published DPA as-is; some will want it signed, which you can do by countersigning a copy.*

Last updated: [DATE]

This Data Processing Addendum ("DPA") forms part of the agreement between Tahr Inc., doing business as Perfs ("Processor", "we") and the customer entity that has accepted the Perfs Terms of Service ("Controller", "you"), and governs our processing of personal data on your behalf.

1. Roles

You are the controller of the personal data you submit to or generate within Perfs. We are your processor. Each party will comply with the data protection laws applicable to it.

2. Scope and purpose of processing

Subject matter: provision of the Perfs performance-review service.

Duration: for as long as your account is active, plus the retention periods in section 8.

Nature and purpose: hosting, storing, transmitting, displaying, backing up, and securing review data so that you can run performance review cycles.

Categories of data subjects: your employees, contractors, and other personnel that you add to a Perfs roster.

Categories of personal data: names, work email addresses, job titles, levels and tracks, reporting relationships, ratings and scores, and written feedback.

Special categories: none are required by the service. You should not submit special category data (health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation) into free-text feedback fields.

3. Our obligations

We will:

embodied in your use of the service and the Terms of Service, unless required otherwise by law — in which case we'll tell you first unless legally prohibited;

requests, and in meeting your obligations around security, breach notification, and data protection impact assessments;

section 8.

4. Subprocessors

You give us general authorization to engage subprocessors. Our current subprocessors are:

SubprocessorPurposeLocation
SupabaseDatabase hosting and authenticationWest US (North California)
VercelApplication hosting and content deliveryUnited States
StripePayment processing (billing data only)United States
ResendTransactional email deliveryUnited States

We'll give you at least 30 days' notice before adding or replacing a subprocessor that processes your personal data. If you reasonably object on data protection grounds, you may terminate your use of the affected service and we'll refund any prepaid fees for cycles not yet opened. We remain liable for our subprocessors' performance of their obligations.

5. Security measures

We maintain the following measures, described more fully on our security page:

incident response

reaches our systems

We may update these measures over time, provided the level of protection is not reduced.

6. Personal data breach

We'll notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your personal data. The notice will describe what we know about the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. We'll cooperate with you in investigating and mitigating it.

7. Data subject requests

If we receive a request from one of your data subjects to exercise rights of access, correction, deletion, restriction, objection, or portability, we'll redirect them to you and will not respond substantively ourselves except to confirm the referral. We'll assist you in responding, including by providing export or deletion functionality within the service.

8. Deletion and return

On termination, or on your instruction at any time (including the in-product deletion control), we'll permanently delete your personal data from production within 30 days, except where retention is required by law (anonymized transaction records and the deletion event itself, per the privacy policy). Data in backups is deleted as those backups age out, within 7 days of production deletion. Before deletion you may export your data in a standard machine-readable format at no charge.

9. International transfers

Where you transfer personal data subject to the GDPR or UK GDPR to us in the United States, the parties agree that the European Commission's Standard Contractual Clauses (Module Two, controller to processor), and the UK International Data Transfer Addendum where applicable, are incorporated into this DPA by reference. For the purposes of those clauses: you are the data exporter, we are the data importer, the governing law is the law of Ireland unless otherwise required, and Annexes I, II and III are populated by sections 2, 4 and 5 of this DPA.

10. Audit

We'll respond to reasonable written questions about our processing and security, including security questionnaires, no more than once per year unless required by a supervisory authority or following a breach. Where we hold third-party attestations for our infrastructure providers, we'll point you to them.

11. California

Where the CCPA/CPRA applies, we act as a "service provider". We do not sell or share personal information, we won't retain, use, or disclose it for any purpose other than performing the service, and we won't combine it with personal information received from other sources except as permitted by the CCPA.

12. Precedence and term

This DPA supplements the Terms of Service. In the event of a conflict regarding the processing of personal data, this DPA controls. It remains in effect for as long as we process personal data on your behalf.

13. Contact

Tahr Inc. dba Perfs, [BUSINESS ADDRESS] — privacy@runperfs.com