Data processing addendum
Draft revised October 3, 2026. Effective date to be set on publication.
Shops own their hiring data. This addendum sets out how RPM Talent processes applicant and employee information on a shop's behalf, the security measures we keep and the companies we rely on.
1Scope and roles
This addendum is part of the terms of service between RPM Talent and Customer. It applies to personal information RPM Talent processes on Customer's behalf (“Customer Personal Data”).
Customer is the controller and the “business.” RPM Talent is the processor and the “service provider” under the California Consumer Privacy Act as amended (CCPA) and acts the same way under other US state privacy laws.
2Details of processing
| Item | Description |
|---|---|
| Subject matter | Providing the RPM Talent hiring and onboarding service. |
| Duration | The term of the agreement plus the 30-day export period, then deletion. |
| Nature and purpose | Collecting applications, screening, assessments, scheduling, messaging, offer preparation, coordinating background checks and e-signature, onboarding, payroll handoff and post-hire check-ins. |
| Data subjects | Job applicants, candidates, new hires and employees of Customer; Customer's users. |
| Categories of data | Contact details, resume, experience and certifications, screening answers, assessment responses and scores, interview records and scorecards, messages, offer terms, background check status, onboarding answers (emergency contact, uniform sizes, tool inventory, typed acknowledgments), check-in answers, user account and audit data. |
| Excluded by design | Social Security numbers, dates of birth, driver's license numbers, tax forms, bank and direct deposit details, identity documents, signed documents and criminal record details. These are handled by Checkr, the payroll provider or Dropbox Sign, not stored by RPM Talent. |
3RPM Talent's obligations
- Process Customer Personal Data only on Customer's documented instructions, which are these terms, Customer's configuration of the service and Customer's actions in it.
- Not sell or share Customer Personal Data, and not retain, use or disclose it outside the direct business relationship or for any purpose other than providing the service.
- Not combine it with personal information from other customers or other sources, except as the CCPA permits for service providers.
- Ensure everyone with access is bound by confidentiality and has access only as needed.
- Notify Customer if we believe an instruction violates law, or if we can no longer meet our obligations under applicable privacy law.
- Give Customer the right to take reasonable steps to stop and remediate unauthorized use.
4Security measures
RPM Talent maintains these technical and organizational measures and may improve them over time without reducing overall protection:
| Area | Measure |
|---|---|
| Encryption in transit | TLS 1.2 or higher on all connections, with HTTP Strict Transport Security. |
| Encryption at rest | AES-256 for the database, backups and file storage. Integration credentials are additionally encrypted with AES-256-GCM using a key held outside the database. |
| Tenant isolation | Every query against customer data is automatically scoped to the customer's tenant ID at the data-access layer. Stored files are prefixed by tenant and access is checked on each request. |
| Access control | Role-based permissions (admin, hiring manager, read only); hashed passwords; sign-in rate limiting; 30-minute idle sign-out; session revocation. |
| Audit logging | Sign-ins, failed sign-ins, candidate and file views, exports, deletions, API requests and setting changes, with user, time and IP address. |
| Application security | Same-origin checks on state-changing requests, a strict content security policy, request rate limiting, signature verification on incoming webhooks, and bot protection on public forms. |
| Data minimization | Sensitive identifiers are routed to the provider that needs them instead of being stored. |
| Personnel | Production access limited to named staff, with confidentiality obligations and multi-factor authentication. [Operations to confirm] |
| Resilience | Automated daily backups with point-in-time recovery, retained for [35 days; confirm with database provider]. |
5Sub-processors
Customer authorizes RPM Talent to use the sub-processors below. Each is bound by written terms that protect Customer Personal Data at least as well as this addendum. We will give account admins at least 30 days' notice by email before adding or replacing a sub-processor. Customer may object on reasonable data protection grounds; if we can't resolve the objection, Customer may terminate the affected service and receive a refund of prepaid fees for it.
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Vercel Inc. | Application hosting and content delivery | All service data in transit; application logs | United States |
| Managed PostgreSQL provider | Primary database | All stored customer data (encrypted at rest) | United States |
| Cloudflare, Inc. (R2) | Resume file storage | Resume files uploaded by applicants | United States |
| Twilio Inc. | SMS delivery | Mobile number, message content | United States |
| Twilio SendGrid | Email delivery | Email address, name, message content | United States |
| JobCannon | Assessment item delivery and scoring | Assessment responses and an internal reference ID; no name or contact details | United States |
| Stripe, Inc. | Subscription billing | Customer billing contact and payment card (held by Stripe) | United States |
| Zippopotam.us | ZIP code to coordinates for commute-distance screening | Five-digit ZIP code only | United States |
[Name the managed PostgreSQL provider and confirm hosting regions before publishing.]
6Services Customer connects
The services below are turned on by Customer, usually under Customer's own account with that provider. Data flows to them at Customer's direction and is then governed by Customer's agreement with the provider. RPM Talent sends each only what its step requires.
| Service | Purpose | Data exchanged |
|---|---|---|
| Indeed | Job posting and Indeed Apply intake | Job posts out; applicant name, contact details, resume and answers in |
| ZipRecruiter | Job posting and applicant intake | Job posts out; applicant name, contact details, resume and answers in |
| Calendly | Interview self-scheduling | Candidate name, email, phone; interview time |
| Dropbox Sign | Offer letter e-signature and storage of signed documents | Candidate name and email, offer letter text |
| Checkr, Inc. | Background checks (Checkr acts as a consumer reporting agency) | Candidate name, email, phone, package. SSN, date of birth and license are entered by the candidate directly with Checkr |
| ADP, Inc. | Payroll employee creation | New hire name, contact details, title, location, start date, pay rate, manager |
| Intuit Inc. (QuickBooks Payroll) | Payroll employee creation | New hire name, contact details, title, location, start date, pay rate, manager |
7Data subject requests
RPM Talent gives Customer self-service tools to respond to requests from applicants and employees:
- Access and portability: export all Customer Data, or an individual's records, from Settings, Security & data.
- Deletion: permanently delete a candidate, including applications, messages, notes and resume file, from the candidate's page.
- Correction: edit candidate details in the app.
If we receive a request directly, we will forward it to Customer within 5 business days and will not respond on the merits unless Customer instructs us to.
8Security incidents
RPM Talent will notify Customer without undue delay, and no later than 72 hours after confirming a security incident affecting Customer Personal Data. The notice will describe what happened, the data and people likely affected, what we are doing about it and a contact for more information. We will cooperate with Customer's reasonable requests, including information Customer needs to notify individuals or regulators.
9Return and deletion
Customer can export Customer Data at any time. After the agreement ends, Customer has 30 days to export it, after which RPM Talent permanently deletes Customer Personal Data, including resume files, and certifies deletion on request. Backups are not altered but expire on their normal schedule and are not restored except for disaster recovery.
10Audits and assistance
On request, no more than once a year, RPM Talent will answer a reasonable security questionnaire and provide available third-party security reports. We will provide reasonable help with data protection assessments. If a regulator requires it, or after a security incident, Customer may conduct an audit on 30 days' notice, during business hours, at its own cost and under confidentiality.
11Location of processing
Customer Personal Data is stored and processed in the United States. RPM Talent does not transfer it outside the United States without Customer's prior written consent. Contact privacy@rpmtalent.app with questions about this addendum.