Data Processing Addendum
Aptimal, Inc.
Last updated: 07/23/2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Aptimal, Inc. ("Aptimal," "Service Provider") and the customer agreeing to those Terms ("Customer," "Business"), and applies where Aptimal processes Personal Information on Customer's behalf.
Scope note. This DPA is drafted for processing in the United States. Aptimal does not currently offer the Services in the EEA, UK, or Switzerland, and this DPA does not incorporate the EU Standard Contractual Clauses. Customers requiring GDPR terms should contact us before using the Services for candidates located in those regions.
In the event of a conflict between this DPA and the Terms, this DPA controls with respect to Personal Information.
1. Definitions
- "Privacy Laws" means U.S. federal and state laws applicable to the processing of Personal Information under this DPA, including the California Consumer Privacy Act as amended by the California Privacy Rights Act and its implementing regulations ("CCPA"), and comparable comprehensive privacy laws in other states.
- "Personal Information" means personal information, personal data, or personally identifiable information within Customer Data that Aptimal processes on Customer's behalf.
- "Business," "Service Provider," "Consumer," "Sell," "Share," "Process," "Sensitive Personal Information" have the meanings given in the CCPA.
- "Subprocessor" means a third party engaged by Aptimal to process Personal Information.
- "Security Incident" means a breach of security leading to unauthorized access to, or acquisition, disclosure, loss, alteration, or destruction of, Personal Information in Aptimal's possession.
- "Services" has the meaning given in the Terms.
2. Roles of the Parties
2.1 Customer is the Business and Aptimal is the Service Provider with respect to Personal Information processed through the Services, including candidate Personal Information.
2.2 Aptimal acts as an independent business for account, billing, support, and website data as described in the Privacy Policy. This DPA does not apply to that processing.
2.3 Customer is responsible for the lawfulness of the Personal Information it provides and the instructions it gives, including providing required notices to Consumers and complying with laws governing automated decision-making technology and automated employment decision tools.
2.4 Employment context. Customer acknowledges that most state privacy laws exclude job applicants from the definition of Consumer, but that California does not. Customer is responsible for determining which Privacy Laws apply to its candidate population.
3. Processing of Personal Information
3.1 Limited purpose. Aptimal will process Personal Information only for the business purpose of providing the Services under the Terms, and only on Customer's documented instructions.
3.2 Service Provider restrictions. Aptimal will not:
(a) sell or share Personal Information;
(b) retain, use, or disclose Personal Information for any purpose other than the business purposes specified in the Terms, or outside the direct business relationship with Customer;
(c) retain, use, or disclose Personal Information for a commercial purpose other than providing the Services;
(d) combine Personal Information received from Customer with personal information received from or on behalf of another person, or collected from its own interactions with a Consumer, except as permitted under the CCPA to perform a business purpose;
(e) use Personal Information to train, fine-tune, or otherwise improve any foundation model or general-purpose AI model; or
(f) use Personal Information to build or enrich a profile of any individual for its own purposes.
3.3 Certification. Aptimal certifies that it understands the restrictions in Section 3.2 and will comply with them.
3.4 Notice of inability to comply. Aptimal will notify Customer promptly if it determines it can no longer meet its obligations under Privacy Laws.
3.5 Customer remediation right. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information, including requesting a written summary of Aptimal's processing activities.
3.6 Deidentified data. Where Aptimal uses deidentified data, it will take reasonable measures to prevent reidentification, publicly commit to maintaining the data in deidentified form, and contractually obligate recipients to do the same.
3.7 Confidentiality. Aptimal will ensure personnel authorized to process Personal Information are bound by confidentiality obligations and have received appropriate training.
4. Subprocessors
4.1 Authorization. Customer authorizes Aptimal to engage Subprocessors. The current list is maintained at /legal/subprocessors.
4.2 Notice of changes. Aptimal will notify Customer at least 30 days in advance of adding or replacing a Subprocessor, by email to the address on the account and by updating the subprocessor page.
4.3 Objection. Customer may object on reasonable data protection grounds within 30 days. The parties will discuss in good faith. If Aptimal cannot provide a commercially reasonable alternative, Customer may terminate the affected Services and receive a pro-rata refund of prepaid, unused fees.
4.4 Flow-down and liability. Aptimal will bind each Subprocessor by written contract to obligations no less protective than those in this DPA, including the Service Provider restrictions in Section 3.2, and remains liable to Customer for each Subprocessor's performance.
5. Security
5.1 Aptimal will implement and maintain reasonable security procedures and practices appropriate to the nature of the Personal Information, designed to protect it from unauthorized access, destruction, use, modification, or disclosure. Current measures are described in Annex II.
5.2 Aptimal may update its security measures provided the level of protection is not materially reduced.
6. Security Incidents
6.1 Aptimal will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Personal Information.
6.2 Notification will describe, to the extent known: the nature of the incident, categories and approximate number of individuals and records affected, likely consequences, measures taken or proposed, and a contact point. Information unavailable at the time will follow without undue delay.
6.3 Aptimal will take reasonable steps to contain, investigate, and mitigate, and will cooperate with Customer's investigation and any notification obligations under state breach notification statutes.
6.4 Aptimal will not notify affected individuals or regulators on Customer's behalf unless required by law or requested in writing by Customer.
6.5 Notification is not an acknowledgment of fault or liability.
7. Assistance to Customer
7.1 Consumer requests. If Aptimal receives a request from a Consumer relating to Customer's Personal Information, it will not respond substantively but will forward it to Customer without undue delay. The Services provide functionality enabling Customer to access, correct, export, and delete candidate data directly. Where a request cannot be fulfilled through self-service, Aptimal will provide reasonable assistance.
7.2 Risk assessments. Aptimal will provide reasonable assistance with risk assessments Customer is required to conduct, including under the CCPA regulations governing automated decision-making technology, by supplying available information about the Services' processing operations, security measures, and the general logic and intended effects of the scoring features.
7.3 Automated decision-making disclosures. On reasonable request, Aptimal will provide information reasonably available to it to support Customer's obligations to give pre-use notices and access explanations regarding automated decision-making technology.
Aptimal may charge a reasonable fee, on prior notice, for assistance that is excessive or beyond the functionality of the Services.
8. Audits
8.1 Aptimal will make available information reasonably necessary to demonstrate compliance with this DPA, including third-party audit reports and security documentation where available.
8.2 Where that documentation is insufficient, Customer may audit, including on-site inspection, subject to: (a) 30 days' prior written notice; (b) no more than once per 12-month period, except following a Security Incident or where required by a regulator; (c) conduct during business hours without disrupting operations; (d) confidentiality undertakings; and (e) Customer bearing its own and Aptimal's reasonable costs.
8.3 Auditors must not be competitors of Aptimal, and audits must not require disclosure of other customers' data or information that would compromise security.
9. Deletion and Return
9.1 Following termination, Customer may export Personal Information for 30 days.
9.2 After that period, Aptimal will delete or deidentify Personal Information, including from Subprocessor systems, except where retention is required by law. Customer is responsible for exporting any records it must retain under EEOC recordkeeping rules, California Civil Rights Department ADS recordkeeping requirements, or Colorado SB 26-189's three-year retention requirement.
9.3 Backup copies delete on Aptimal's standard cycle, not exceeding 90 days, and remain subject to this DPA until deleted.
9.4 Aptimal will certify deletion in writing on request.
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, except where Privacy Laws prohibit such limitation. Nothing in this DPA limits any Consumer's rights under Privacy Laws.
11. General
11.1 This DPA takes effect with the Terms and continues until Aptimal ceases processing Personal Information on Customer's behalf.
11.2 If any provision is invalid, the remainder continues in effect.
11.3 This DPA is governed by the law stated in the Terms, except where Privacy Laws require otherwise.
11.4 Aptimal may update this DPA to reflect changes in law or the Services, provided updates do not materially reduce protections. Material changes will be notified at least 30 days in advance.
ANNEX I — Details of Processing
Business (Customer): The entity identified in the Terms or applicable order form.
Service Provider:
Aptimal, Inc. — Email: support@aptimal.ai — Registered Agent: Legalinc Corporate Services Inc., 131 Continental Dr Suite 305, Newark, DE 19713, US
Categories of individuals
- Job candidates and applicants who apply to Customer's postings or complete Customer's assessments
- Customer's authorized users (recruiters, hiring managers, administrators)
Categories of Personal Information
- Identifiers: name, email, telephone, location
- Professional and education information: resume/CV contents, employment history, education, skills, certifications, attachments
- Assessment data: free-text responses to scenario-based and role-specific questions
- Generated data: AI summaries, Qualification Scores, Assessment Scores, suggested interview questions
- Pipeline data: application status, stage history, recruiter notes, tags, rejection status, cross-posting application history
- Scheduling data: appointment times, meeting links
- Background check data: where ordered by Customer, results returned by the consumer reporting agency
- User account data: names, work emails, roles, authentication data
- Internet activity: IP address, device and browser information, log data
Sensitive Personal Information
Not solicited by the Services. Customer is prohibited from configuring the Services to elicit it. Any such information appearing incidentally in a free-text response or uploaded document is processed only as an inseparable part of that document. Where Sensitive Personal Information is nonetheless processed, Customer warrants it has a lawful basis and has given required notices.
Nature and purpose of processing
Hosting, storage, retrieval, organization, analysis, and transmission of Personal Information to provide applicant tracking, AI-assisted resume analysis and scoring, AI-assisted assessment delivery and scoring, generation of suggested interview questions, transactional email delivery, scheduling, background check ordering, candidate search, and integration with Customer's systems.
Duration
For the term of the subscription, per Customer's configured retention settings, plus a 30-day export window and up to 90 days in backups following termination.
ANNEX II — Security Measures
Access control
- Role-based access control with least-privilege provisioning
- Multi-factor authentication for administrative and production access
- Unique named accounts; no shared production credentials
- Periodic access reviews; prompt revocation on role change or departure
Encryption
- TLS 1.2 or higher in transit
- Encryption at rest for databases, object storage, and backups
- Secrets held in a managed secrets service, not in source code
Tenant isolation
- Logical segregation of Customer Data with row-level security enforcement
- Application-layer authorization checks on all data access paths
Infrastructure
- Managed cloud infrastructure with provider-maintained physical security
- Restricted production access; no direct public database exposure
- Web application firewall and rate limiting
Application security
- Secure development lifecycle with peer code review
- Automated dependency and vulnerability scanning
- Separate development, staging, and production environments; no production Personal Information in non-production environments
Logging and monitoring
- Audit logging of authentication events and administrative actions
- Centralized log aggregation with alerting on anomalous activity
Resilience
- Automated encrypted backups with defined retention
- Documented, periodically tested restoration procedures
Personnel
- Background screening where lawful and appropriate
- Confidentiality obligations in all personnel agreements
- Security and privacy training at onboarding and periodically
Incident response
- Documented plan with severity levels and escalation paths
- Post-incident review for material incidents
Vendor management
- Security and privacy review before engaging any Subprocessor
- Written data protection terms with each Subprocessor
AI-specific
- Contractual prohibition on model training with all AI Subprocessors
- Zero- or minimal-retention configuration with AI Subprocessors where available
- No Personal Information used in prompt engineering, evaluation datasets, or fine-tuning
[Delete any control you have not actually implemented before publishing. A shorter honest list is better than an aspirational one — this annex gets diffed against reality in security questionnaires.]
ANNEX III — Subprocessors
The current list, including entity name, processing activity, data categories, and location, is maintained at /legal/subprocessors and incorporated by reference.
Contact
Aptimal Inc.
Email us: support@aptimal.ai
Registered Agent: Legalinc Corporate Services Inc.
131 Continental Dr Suite 305 Newark, DE, 19713 US