Data processing addendum (DPA)
*This is the document a customer's legal team will ask for. Publish it at a stable URL and reference it from your Terms. Most customers will accept a published DPA as-is; some will want it signed, which you can do by countersigning a copy.*
Last updated: [DATE]
This Data Processing Addendum ("DPA") forms part of the agreement between Tahr Inc., doing business as Perfs ("Processor", "we") and the customer entity that has accepted the Perfs Terms of Service ("Controller", "you"), and governs our processing of personal data on your behalf.
1. Roles
You are the controller of the personal data you submit to or generate within Perfs. We are your processor. Each party will comply with the data protection laws applicable to it.
2. Scope and purpose of processing
Subject matter: provision of the Perfs performance-review service.
Duration: for as long as your account is active, plus the retention periods in section 8.
Nature and purpose: hosting, storing, transmitting, displaying, backing up, and securing review data so that you can run performance review cycles.
Categories of data subjects: your employees, contractors, and other personnel that you add to a Perfs roster.
Categories of personal data: names, work email addresses, job titles, levels and tracks, reporting relationships, ratings and scores, and written feedback.
Special categories: none are required by the service. You should not submit special category data (health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation) into free-text feedback fields.
3. Our obligations
We will:
- process personal data only on your documented instructions, including the instructions
embodied in your use of the service and the Terms of Service, unless required otherwise by law — in which case we'll tell you first unless legally prohibited;
- ensure that anyone authorized to process the data is bound by confidentiality;
- implement the technical and organizational measures described in section 5;
- assist you, taking into account the nature of processing, in responding to data subject
requests, and in meeting your obligations around security, breach notification, and data protection impact assessments;
- make available the information reasonably necessary to demonstrate compliance with this DPA;
- at your choice, delete or return personal data at the end of the service, as set out in
section 8.
4. Subprocessors
You give us general authorization to engage subprocessors. Our current subprocessors are:
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting and authentication | West US (North California) |
| Vercel | Application hosting and content delivery | United States |
| Stripe | Payment processing (billing data only) | United States |
| Resend | Transactional email delivery | United States |
We'll give you at least 30 days' notice before adding or replacing a subprocessor that processes your personal data. If you reasonably object on data protection grounds, you may terminate your use of the affected service and we'll refund any prepaid fees for cycles not yet opened. We remain liable for our subprocessors' performance of their obligations.
5. Security measures
We maintain the following measures, described more fully on our security page:
- Tenant isolation enforced at the database layer using Postgres row-level security
- Passwordless authentication via single-use, expiring email links
- Encryption of data in transit (TLS) and at rest
- Administrative access to production restricted to named personnel, used only for support and
incident response
- Daily backups with a 7-day rolling retention
- Payment data handled entirely by a PCI DSS Level 1 certified processor; card data never
reaches our systems
We may update these measures over time, provided the level of protection is not reduced.
6. Personal data breach
We'll notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your personal data. The notice will describe what we know about the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. We'll cooperate with you in investigating and mitigating it.
7. Data subject requests
If we receive a request from one of your data subjects to exercise rights of access, correction, deletion, restriction, objection, or portability, we'll redirect them to you and will not respond substantively ourselves except to confirm the referral. We'll assist you in responding, including by providing export or deletion functionality within the service.
8. Deletion and return
On termination, or on your instruction at any time (including the in-product deletion control), we'll permanently delete your personal data from production within 30 days, except where retention is required by law (anonymized transaction records and the deletion event itself, per the privacy policy). Data in backups is deleted as those backups age out, within 7 days of production deletion. Before deletion you may export your data in a standard machine-readable format at no charge.
9. International transfers
Where you transfer personal data subject to the GDPR or UK GDPR to us in the United States, the parties agree that the European Commission's Standard Contractual Clauses (Module Two, controller to processor), and the UK International Data Transfer Addendum where applicable, are incorporated into this DPA by reference. For the purposes of those clauses: you are the data exporter, we are the data importer, the governing law is the law of Ireland unless otherwise required, and Annexes I, II and III are populated by sections 2, 4 and 5 of this DPA.
10. Audit
We'll respond to reasonable written questions about our processing and security, including security questionnaires, no more than once per year unless required by a supervisory authority or following a breach. Where we hold third-party attestations for our infrastructure providers, we'll point you to them.
11. California
Where the CCPA/CPRA applies, we act as a "service provider". We do not sell or share personal information, we won't retain, use, or disclose it for any purpose other than performing the service, and we won't combine it with personal information received from other sources except as permitted by the CCPA.
12. Precedence and term
This DPA supplements the Terms of Service. In the event of a conflict regarding the processing of personal data, this DPA controls. It remains in effect for as long as we process personal data on your behalf.
13. Contact
Tahr Inc. dba Perfs, [BUSINESS ADDRESS] — privacy@runperfs.com