Data Processing Addendum (DPA)
The GDPR-aligned data processing terms available for execution by enterprise customers.
This Data Processing Addendum ("DPA") sets out the terms on which Kempian processes personal data for an enterprise customer using the Platform. It's for legal, procurement, and security reviewers evaluating or executing a data processing relationship with Kempian.
*This document is part of Kempian's Trust Center documentation. It is reviewed periodically and does not constitute legal advice. Draft v0.2 — pending final legal review before publication.*
This DPA forms part of, and is incorporated by reference into, the agreement between Kempian and any enterprise customer that processes personal data through the Platform (the "Agreement"), to the extent Kempian processes personal data on that customer's behalf as a processor. To request execution of this DPA, or ask about its terms, contact trust@kempian.com.
Data Processing Addendum — Template
This DPA is between Adept AI Inc., a Delaware corporation, principal place of business at registered address placeholder ("Processor," "Kempian"), and the customer entity named in the Agreement or the applicable order form ("Controller," "Customer"), each a "Party" and together the "Parties." It takes effect on effective date (the "Effective Date").
1. Definitions
1.1 "Controller" means the entity that decides the purposes and means of Processing Personal Data. Here, that's Customer, except where Section 2.4 says Kempian acts as Controller in its own right.
1.2 "Processor" means the entity that Processes Personal Data on the Controller's behalf. Here, that's Kempian, for the Personal Data Annex 1 describes.
1.3 "Data Subject" means an identified or identifiable natural person whose Personal Data this DPA covers. This includes candidates, Customer's authorized users (recruiters and employer/organisation administrators), and anyone else whose Personal Data reaches the Platform through Customer's use of it.
1.4 "Personal Data" means any information relating to an identified or identifiable natural person that Kempian Processes on Customer's behalf under the Agreement, as Annex 1 further describes.
1.5 "Processing" (and "Process") means any operation performed on Personal Data, whether automated or not — including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure, combination, restriction, erasure, or destruction.
1.6 "Sub-processor" means any third party Kempian engages to Process Personal Data on Kempian's behalf for the Platform, as the Subprocessor List identifies.
1.7 "Data Protection Laws" means all data protection and privacy laws that apply to Processing Personal Data under this DPA — including, as applicable, the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, India's Digital Personal Data Protection Act 2023 and its Rules ("DPDP Act"), and applicable US state privacy laws.
1.8 "Standard Contractual Clauses" or "SCCs" means the European Commission's standard contractual clauses for transferring personal data to third countries (Commission Implementing Decision (EU) 2021/914) and, for UK transfers, the UK International Data Transfer Addendum to the SCCs.
1.9 "Personal Data Breach" means a security breach that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data this DPA covers.
Terms the GDPR defines, and this DPA doesn't otherwise define — such as "special categories of personal data" — carry the meaning the GDPR gives them.
2. Subject Matter, Duration, Nature and Purpose of Processing
2.1 Subject matter. This DPA governs Kempian's Processing of Personal Data on Customer's behalf while providing the Platform under the Agreement.
2.2 Duration. Kempian will Process Personal Data for as long as the Agreement lasts, and after that only as far as Section 3.7 (deletion or return of data) or applicable law requires.
2.3 Nature and purpose of Processing. Kempian Processes Personal Data to provide the Platform's core functionality to Customer. This includes importing and storing candidate records from Customer's applicant tracking system where applicable; running the AI Features (Candidate Matching, Resume Parsing, the Job Creation Assistant, and the Chat Assistant) to support Customer's recruiting workflow; letting Customer's authorized users search, message, and manage candidates; generating platform-derived data such as AI match scores, rationale text, and audit/consent records (the candidate's Privacy Timeline); and providing account, billing, and support functions.
2.4 Controller/processor roles. For candidate data Customer imports from its own systems, or that Kempian otherwise processes on Customer's documented instructions, Kempian acts as Processor and Customer acts as Controller. For certain data Kempian processes while operating the Platform as a multi-tenant service more generally — for example, self-registered candidate accounts not tied to a specific employer instruction, or Kempian's own account and billing records — Kempian may act as an independent Controller, as the Privacy Policy describes. This DPA doesn't apply to Processing where Kempian acts as an independent Controller.
2.5 Types of Personal Data. As applicable to Customer's use of the Platform: candidate name and contact details; resume/CV content; employment history; education; skills; certifications and professional licences (occupational-qualification data, not special-category health data under GDPR Article 9, unless the specific content collected reveals health information in substance); location; salary expectations; availability and notice period; engagement/response signals; and, for Customer's authorized users, account and contact details, organisation affiliation, role/permissions, and usage/activity data. The Privacy Policy fully describes these data categories.
2.6 Categories of Data Subjects. Candidates — whether imported via Customer's ATS, self-registered, AI-discovered, or connected, consistent with Kempian's Four-State Model as the Candidate Privacy & Visibility Notice describes — and Customer's authorized users (recruiters and employer/organisation administrators).
3. Processor Obligations
3.1 Processing on documented instructions. Kempian will Process Personal Data only on Customer's documented instructions, including for international transfers, unless applicable law requires otherwise. If the law requires otherwise, Kempian will tell Customer about that legal requirement before Processing, unless the law prohibits this notice on important public-interest grounds. The Agreement, this DPA, and Customer's use of the Platform's ordinary functionality together constitute Customer's documented instructions.
3.2 Confidentiality. Kempian will make sure people authorized to Process Personal Data have committed to confidentiality, or are under an appropriate statutory confidentiality obligation.
3.3 Security measures. Kempian will implement appropriate technical and organisational measures to secure Personal Data at a level appropriate to the risk, consistent with GDPR Article 32. This takes into account the state of the art, implementation cost, and the nature, scope, context, and purposes of Processing. These measures include encryption of data in transit and at rest, access controls, tenant isolation safeguards, and an incident response process. The Security Overview has further detail, including specific implementation detail such as hosting provider, region, and infrastructure configuration.
3.4 Sub-processor authorization and flow-down. Kempian may engage Sub-processors to Process Personal Data as Section 4 describes. Where Kempian engages a Sub-processor, Kempian will impose data protection obligations on that Sub-processor that are substantially no less protective than this DPA's, through a written agreement. Kempian stays liable to Customer for the Sub-processor's performance of its data protection obligations.
3.5 Assistance with data subject rights. Taking into account the nature of the Processing, Kempian will give Customer reasonable assistance — through appropriate technical and organisational measures — to help Customer respond to Data Subjects who exercise their rights under applicable Data Protection Laws (access, rectification, erasure, restriction, portability, and objection). If a Data Subject sends such a request directly to Kempian in connection with Customer's use of the Platform, Kempian will direct the Data Subject to Customer, or notify Customer of the request, without undue delay.
3.6 Assistance with data protection impact assessments. Taking into account the nature of Processing and the information available to Kempian, Kempian will give Customer reasonable assistance with Customer's obligations to carry out data protection impact assessments and, where required, consult with supervisory authorities beforehand — to the extent these obligations relate to Kempian's Processing of Personal Data under this DPA.
3.7 Deletion or return of data. When the Agreement ends or expires, and subject to any retention obligations the Privacy Policy describes or applicable law requires (including AI-audit traceability retention under Section 11 of the Privacy Policy), Kempian will, at Customer's choice, delete or return all Personal Data it Processed on Customer's behalf, and will delete existing copies unless applicable law requires their continued storage.
3.8 Audit rights. Kempian will make available to Customer all information reasonably necessary to show compliance with this DPA, and will allow and contribute to audits — including inspections — that Customer or an auditor Customer mandates conducts. This is subject to reasonable advance notice, confidentiality protections, and a limit of once per year absent a Personal Data Breach or a specific regulatory requirement. Kempian may satisfy an audit request, in whole or in part, by providing a summary of relevant third-party audit reports, security certifications, or the additional detail the AI Governance Statement, Security Overview, and Subprocessor List describe, where these reasonably address the scope of Customer's request.
4. Sub-processor Authorization
4.1 Customer gives Kempian general authorization to engage Sub-processors to Process Personal Data for the Platform, subject to the obligations in Section 3.4.
4.2 The Subprocessor List sets out the current list of Sub-processors, their purpose, the data categories they Process, and their location. It's incorporated into this DPA by reference, and Kempian updates it from time to time.
4.3 Kempian will notify Customer before adding or replacing a Sub-processor, through the Platform or by other reasonable means, consistent with the change-notification commitment the Subprocessor List describes. Customer may object to a new Sub-processor on reasonable data-protection grounds by contacting trust@kempian.com; the Parties will work in good faith to address the objection, as the Subprocessor List describes.
5. International Data Transfers
5.1 Kempian operates across the EU/UK, the United States, and India, so Personal Data this DPA covers may move between these regions, including to the Sub-processors the Subprocessor List identifies, consistent with Section 10 of the Privacy Policy.
5.2 When Kempian transfers Personal Data originating in the EEA, the UK, or Switzerland (as data exporter or on Customer's behalf) to a country without an adequate level of data protection, the Parties agree that the Standard Contractual Clauses are incorporated into this DPA by reference and apply to that transfer, together with the UK International Data Transfer Addendum where the transfer originates from the UK. The appropriate SCC module — controller-to-processor or processor-to-processor, as applicable — applies based on the Parties' respective roles under Section 2.4.
5.3 For Personal Data relating to India-located Data Subjects, cross-border transfer is subject to the DPDP Act's conditions, consistent with Section 7 of the Privacy Policy.
6. Personal Data Breach Notification
6.1 Kempian will notify Customer without undue delay, and in any case within 72 hours of becoming aware, of a Personal Data Breach affecting Personal Data this DPA covers, consistent with the notification standard under GDPR Article 33.
6.2 To the extent reasonably available at the time, Kempian's notification will describe the nature of the Personal Data Breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach and limit its effects. Kempian will share further information as it becomes available, and will cooperate with Customer's own notification obligations under applicable Data Protection Laws.
6.3 Enterprise customers with specific incident-notification requirements under their own contracts may raise them through their Kempian account contact or trust@kempian.com, so we can reflect them in an executed version of this DPA.
7. Liability
7.1 Each Party's liability arising out of or connected to this DPA, including liability for breach of this DPA, is subject to the limitations and exclusions of liability the Terms and Conditions or the applicable Agreement between the Parties sets out. These apply in the aggregate to the Agreement and this DPA, unless the Agreement states otherwise.
7.2 Nothing in this DPA limits either Party's liability to a Data Subject or a supervisory authority under applicable Data Protection Laws, to the extent the law doesn't allow that liability to be limited.
8. Term and Termination
8.1 This DPA takes effect on the Effective Date and stays in effect for as long as Kempian Processes Personal Data on Customer's behalf under the Agreement, regardless of the Agreement's own stated duration.
8.2 When the Agreement terminates or expires, this DPA automatically terminates too, without affecting Kempian's obligations under Section 3.7 (deletion or return of data) and any provision of this DPA that by its nature is meant to survive termination.
8.3 Either Party may propose amendments to this DPA to reflect changes in applicable Data Protection Laws or regulatory guidance. Amendments need both Parties' agreement, except where an amendment is needed to keep this DPA consistent with a change in law — in that case, Kempian may update this DPA and will notify Customer of the update.
IN WITNESS WHEREOF, the Parties have caused this DPA to be executed by their duly authorized representatives as of the Effective Date.
| Adept AI Inc. | Customer legal entity name |
| Signature: _______________________ | Signature: _______________________ |
| Name: Name | Name: Name |
| Title: Title | Title: Title |
| Date: Date | Date: Date |
Annex 1 — Description of Processing
See Section 2 above for subject matter, duration, nature and purpose of Processing, types of Personal Data, and categories of Data Subjects. The Parties may add Customer-specific detail — systems integrated, data volumes, and any Customer-specific instructions — by mutual agreement in an executed version of this DPA.
Annex 2 — Technical and Organisational Measures
See Section 3.3 above and the Security Overview for current detail on Kempian's technical and organisational security measures.
Annex 3 — Sub-processors
See the Subprocessor List, incorporated by reference.
Related Documents
Read this Data Processing Addendum together with: the Terms and Conditions, the Privacy Policy, the AI Governance Statement, the Subprocessor List, the Security Overview, and the Candidate Privacy & Visibility Notice.
Contact
- DPA execution requests and enterprise procurement inquiries: trust@kempian.com
- General privacy questions: privacy@kempian.com
- Security vulnerability reports: security@kempian.com
Kempian — Data Processing Addendum — v0.3 (Draft) — July 2026