Skip to content

Data Processing Addendum (DPA)

SkillFoundry offers a Data Processing Addendum that becomes part of your agreement and governs SkillFoundry's processing of personal data on your behalf. This page summarizes the DPA so counsel knows what to expect; the binding version is the signed document available from your account team or privacy@skillfoundry.dev.

This is a summary, not the contract

The wording below describes the structure and key terms of the standard DPA. Enterprise customers can negotiate specifics (retention periods, deletion SLAs, audit cadence). Request the executable DPA — do not rely on this summary as the operative text.

Structure of the DPA

Clause What it covers
1. Definitions Aligns terms with GDPR/UK GDPR and CCPA/CPRA (controller, processor, service provider, personal data, sub-processor, data subject).
2. Roles & scope Confirms the customer is controller and SkillFoundry is processor / service provider; processing only on documented instructions.
3. Subject matter & duration Processing lasts for the term of the main agreement plus wind-down.
4. Nature & purpose Operating the assessment platform: hosting, evaluation/scoring, behavioral analytics, support.
5. Categories of data & data subjects See tables below.
6. Sub-processors Authorization, list, and change-notice/objection rights.
7. International transfers Standard Contractual Clauses + UK Addendum; transfer impact assessment support.
8. Security measures Technical & organizational measures (Annex II).
9. Data-subject requests SkillFoundry assists the controller and forwards requests it receives directly.
10. Personal-data breach Notice without undue delay; cooperation on notifications.
11. Audits Reports/questionnaires on request; on-site audit rights subject to reasonable limits.
12. Deletion & return On termination, deletion or return of personal data, subject to legal-retention exceptions.
13. CCPA/CPRA service-provider terms No sale/share; use limited to the business purpose.

Categories of data subjects

  • Candidates taking assessments (the primary personal data at issue).
  • Hiring-team users (interviewers, admins) of the customer.
  • Prospective candidates invited but not yet assessed.

Categories of personal data

Category Examples Notes
Identity & contact Name, email Provided at invite/sign-up
Account & profile Role, organization membership, activity timestamps —
Assessment content Submitted code (diff), notes, chat with simulated stakeholders See Monitoring and data collection
Behavioral telemetry Activity metadata — file/test/edit/focus activity — never keystrokes, clipboard, screen, or camera Sanitized before upload
Evaluation outputs Scores, score breakdowns, behavioral results, flags —
Technical metadata IP address, user-agent (in audit/security logs) —
Consent records Consent type/status, policy version, timestamp —

Special-category / protected-class data: SkillFoundry does not collect race, ethnicity, sex, health, biometric, or similar sensitive attributes as part of assessment. Demographic data for a bias audit is held by the employer, not SkillFoundry — see Bias audits and adverse impact.

Annex I — processing details

  • Controller: the customer (hiring organization).
  • Processor: SkillFoundry.
  • Purpose: provision of the technical-assessment service.
  • Duration: term of the agreement + wind-down/deletion period.
  • Frequency: continuous, for the duration of the service.

Annex II — technical and organizational measures (TOMs)

The DPA's security annex references the controls documented in Certifications and attestations, including at minimum:

  • Encryption in transit (TLS/HSTS) and at rest, plus application-level encryption of stored secrets.
  • Role-based access control, SSO/SCIM, and organization data isolation.
  • Audit logging (7-year retention) and security monitoring with automated abuse response.
  • Input sanitization, CSRF protection, rate limiting, and security headers.
  • Integrity-verified, cross-region backups with defined RTO (4h) / RPO (1h) and DR testing.
  • Data minimization in telemetry, sanitization, anonymization/pseudonymization, and DPIA tooling.
  • Breach detection with 72-hour notification-deadline handling.

Annex III — sub-processors

The DPA incorporates the current sub-processor list (cloud hosting/storage, identity provider, payments, error monitoring, AI model providers) with each entity's purpose, data categories, and region, and the process for advance notice of changes. See Certifications and attestations.

International transfers

For transfers of EU/EEA, UK, or Swiss personal data outside those regions, the DPA relies on the EU Standard Contractual Clauses (2021/914) with the UK International Data Transfer Addendum and the Swiss addendum as applicable, supported by a transfer impact assessment. SkillFoundry can accommodate data residency preferences (e.g. EU-region hosting) for enterprise plans — raise this during contracting.

Deletion and return

On termination, and on the controller's instruction, SkillFoundry deletes or returns personal data, subject to the erasure mechanics and legal-retention exceptions described in Data retention and erasure. Contractual deletion SLAs can be set in the DPA.

Getting the DPA signed

  1. Request the DPA package (DPA + SCCs + sub-processor list) from privacy@skillfoundry.dev or your account team.
  2. Note any negotiated terms (residency, retention, deletion SLA, audit cadence).
  3. Execute alongside the main agreement; the DPA prevails over conflicting data-protection terms.