Data Processing Addendum

Last updated 2026-10-09

This Addendum forms part of the Terms between Ashwani Bhat, trading as TheTalentDesk (Processor, "we", "us"), and the customer who accepts those Terms (Controller, "you"). It applies whenever we process personal data on your behalf. Where it conflicts with the Terms on the subject of personal data, this Addendum wins.

It is written to Article 28(3) of the UK and EU GDPR and is intended also to satisfy the obligations of a Data Processor under India's Digital Personal Data Protection Act 2023. "Personal data", "processing", "controller", "processor" and "supervisory authority" carry the meanings given in applicable data protection law.

1. What is being processed, and why

Subject matter. Our provision of the TheTalentDesk applicant tracking and review service to you.

Duration. For as long as you have a workspace, and thereafter only as clause 8 allows.

Nature and purpose. Hosting, storing, organising and displaying the records you create so that you can open roles, track applicants through stages, record interview feedback, and run 30, 60 and 90 day reviews. It includes publishing the job listings you choose to make public, on pages, in sitemaps and in feeds that contain nothing about any candidate, and receiving the applications made through those pages. We process for no other purpose.

Categories of data subject. Your candidates and applicants, including people who apply through a public job page you publish; the members of your own team you invite into a workspace.

Types of personal data. Name, email address, telephone number, links to professional profiles, employment history, education, skills, location, the content of any resume you upload, and the notes, scores and decisions your team records about a person. For an application made through a public job page it also includes what the applicant enters in the form (name, email address, an optional telephone number and a resume file), a record that they agreed to the notice shown beside it and when, and the link they arrived from. We do not require special category data and ask you not to put it in.

2. Our instructions come from you

We process personal data only on your documented instructions, including on transfers, unless we are required to do otherwise by law to which we are subject — in which case we will tell you before processing, unless that law forbids us from telling you. Your use of the service, and this Addendum, are your instructions.

We will tell you if, in our opinion, an instruction infringes applicable data protection law. We do not sell personal data, and we do not use it to train machine learning models — ours or anyone else's.

You are responsible for having a lawful basis to upload a candidate's information and for telling that candidate what you are doing, as their controller.

If you publish a job page, applicants are shown a notice and a consent box worded by us, which names your company and links to our privacy policy. You remain responsible for having a lawful basis for the processing and for any further information you owe applicants as their controller.

3. Confidentiality

Access is limited to those who need it to run or support the service. Ashwani Bhat is at present the only person with administrative access to production systems and is bound by this Addendum directly. Any person we later authorise will be under a written confidentiality obligation before they are given access.

4. Security

We implement appropriate technical and organisational measures under Article 32, set out in Annex 2. We may change them, but not in a way that materially reduces the protection of your data.

5. Sub-processors

You give general authorisation for the sub-processors in Annex 3. We impose data protection obligations on each of them no less protective than those in this Addendum, and we remain fully liable to you for what they do.

We will give you at least 30 days' notice before adding or replacing one. If you reasonably object on data protection grounds within that period, tell us and we will try to resolve it; if we cannot, you may terminate the affected part of the service and we will refund any amount you have paid for a period you can no longer use.

The AI provider is not our sub-processor. Resume parsing is off until you switch it on, and you switch it on by connecting your own account at Anthropic or OpenAI with your own API key. The contract for that processing is between you and them; we transmit the resume text to the provider you nominated, on your instruction, and we store your key encrypted. Leave the feature off and no resume ever leaves our infrastructure.

6. International transfers

Our sub-processors operate globally, so personal data may be processed outside the country where you or your candidates are. Where data protection law restricts such a transfer, it takes place under an approved mechanism.

For transfers out of the European Economic Area, the Standard Contractual Clauses approved by the European Commission in Decision 2021/914 are incorporated into this Addendum by reference, Module Two (controller to processor), with you as data exporter and us as data importer. For transfers out of the United Kingdom, the UK International Data Transfer Addendum to those clauses applies on the same basis. Annex 1 and Annex 2 supply the information those clauses require, and the courts in India are specified for the purpose of any clause requiring a choice of forum, to the extent that choice is permitted.

7. Helping you meet your own obligations

Data subject requests. The service lets you find, correct and delete a candidate's record yourself, which answers most requests without involving us. If a request reaches us directly we will not respond to it on your behalf — we will pass it to you without undue delay, because it is yours to answer. Where you need help we cannot give through the product, we will give it.

Personal data breach. We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data, with what we know of its nature, the categories and approximate number of records, the likely consequences, and what we are doing about it. Where we cannot provide all of it at once we will provide it in phases. That deadline mirrors your own under Article 33 so that you are not left waiting on us to start your clock.

Assessments. We will give you the information you reasonably need for a data protection impact assessment or a prior consultation with a supervisory authority, taking into account the nature of the processing and what is available to us.

8. Return and deletion

On your instruction, and on termination, we delete the personal data in your workspace from active systems within 30 days. Restricted backup copies expire within 730 days of their creation, and security audit records expire within 730 days of the recorded event. These are maximum periods, not a requirement to retain every record for that long. We will confirm completion of the active-system deletion. Backups are used only for recovery, and deletion instructions must be reapplied before restored data returns to ordinary use.

Applications received through a job page that have not yet become candidate records are deleted with the workspace, resume files included. Once an application has become a candidate record, the copy in the holding area is deleted and the candidate record is the only copy, so deleting that candidate deletes the applicant's details.

Before deletion you may ask for a copy of your workspace and we will provide one in a structured, commonly used, machine-readable format. There is no self-service export in the product today — this is done by request, which is why it is stated as an obligation here rather than left to a button.

Ending a paid term is not an instruction to delete: a workspace becomes read-only and active records stay until you ask for them to go. The two-year maximum for backups and security records does not automatically delete active candidate records.

9. Audit

We will make available the information reasonably necessary to demonstrate compliance with this Addendum and, on reasonable notice and no more than once a year, allow and contribute to an audit by you or an auditor you mandate. Our sub-processors' own certifications and reports may be used to answer what they cover. An audit must not compromise the confidentiality or security of another customer's data.

10. Liability and governing law

The limitations of liability in the Terms apply to this Addendum, except where applicable data protection law does not permit them. This Addendum is governed by the law of India and subject to the courts in India, save that clause 6 is governed as the Standard Contractual Clauses require where they apply.


Annex 1. The parties and the processing

Data exporter / Controller: the customer accepting the Terms. Contact: the administrator email on the workspace.

Data importer / Processor: Ashwani Bhat, trading as TheTalentDesk, India. Contact: ashwani@thetalentdesk.io.

Processing: as described in clause 1. Frequency: continuous for the duration of the workspace.

Annex 2. Technical and organisational measures

These are the measures actually in place, not an aspiration:

  • In transit. All traffic to the site, the app and every sub-processor API is over TLS. Strict-Transport-Security is set.
  • At rest. Candidate records and uploaded resumes are held in Cloudflare D1 and R2, which encrypt at rest. Any AI provider API key you connect is additionally encrypted by us at the application layer before it is stored; the service refuses to store one at all if that encryption is not configured.
  • Separation. Each workspace is a separate tenant. Every read and write is scoped to the caller's workspace; there is no unscoped read path in the data layer.
  • Access control. Sign-in is by invitation only — being on a company domain grants nothing. Single sign-on via Microsoft, or an individual password with a lockout after repeated failures. Roles are scoped, so a reviewer sees only the candidates they are granted.
  • Public job pages. The pages, sitemaps and feeds read a separate copy that holds only the fields of a job you chose to publish, never the workspace record that holds candidates. Draft and confidential roles are not in that copy at all.
  • Applications from job pages. The form is rate limited per IP address and per job, and the address is kept only as a one-way hash that expires within an hour. It has a hidden field that catches automated submissions, accepts only PDF or Word .docx files up to 4 MB, and checks the file's content rather than trusting its name. An application waits in a holding area that is deleted as soon as its candidate record exists.
  • Accountability. A workspace-scoped audit log records administrative actions, including access-grant changes and connecting or rejecting an AI key, with the actor and the time.
  • Application hardening. Content Security Policy, X-Frame-Options DENY, X-Content-Type-Options nosniff and a strict Referrer-Policy. Signed, expiring tokens for anything reachable from an email link.
  • Supplier assurance. Infrastructure is operated by the providers in Annex 3, whose own certifications and controls apply to the layers they run.
  • Resilience. Managed services with the provider's own durability and backup guarantees. We state honestly that there is no independently audited certification — ISO 27001 or SOC 2 — held by us, and none is claimed anywhere.

Annex 3. Authorised sub-processors

  • Vercel — application and site hosting. Request data, including IP addresses and logs.
  • Cloudflare — D1 database and R2 object storage. Workspaces, accounts, candidates, feedback and uploaded resumes.
  • Upstash — the waitlist on the marketing site, before any workspace exists.
  • Resend — email sent from the marketing site.
  • Our SMTP provider — email sent from the app: welcome and access notices.
  • Dodo Payments — checkout, subscriptions and invoicing, as merchant of record. Billing details only; we never receive card numbers.

Anthropic and OpenAI are deliberately absent: see clause 5. They act for you under your own account, not for us.

Search engines and job sites that read your public listings are not sub-processors: a listing contains nothing about any candidate.

11. Signing this

Accepting the Terms accepts this Addendum, and no signature is needed for it to bind us. If your procurement process requires a countersigned copy, or your own paper instead, write to ashwani@thetalentdesk.io and you will get one.

← Back to TheTalentDesk