This Data Processing Addendum ("DPA") applies where StructSure, LLC ("Processor") processes Personal Data on behalf of a Customer ("Controller") in providing the Services. It supplements and is incorporated into the Terms of Service. If there is a conflict, this DPA controls for data‑protection matters.
For workforce data the Controller submits about its employees and candidates, the Customer is the Controller and StructSure is the Processor. StructSure processes such Personal Data only on the Controller's documented instructions (including as set out in the Terms, this DPA, and the Customer's use of the Services' features), unless legally required otherwise.
| Item | Detail |
|---|---|
| Subject matter | Provision of the StructSure Services (staffing intelligence) |
| Duration | The term of the subscription, plus deletion/return per §8 |
| Nature & purpose | Hosting, storing, organizing, displaying, and reporting on workforce data to help the Controller plan staffing |
| Categories of data subjects | The Controller's employees, candidates, and authorized users |
| Categories of Personal Data | Names, work contact details, job titles, site assignments; and for admins, pay and employment‑status fields; approximate work locations |
| Special categories | None intended. The Controller must not submit special‑category data. |
StructSure ensures that personnel authorized to process Personal Data are bound by confidentiality obligations and access it only as needed to provide the Services.
StructSure maintains appropriate technical and organizational measures, including encryption in transit and at rest, row‑level access controls scoping data to each Controller, role‑based permissions, an activity/audit log, and restricted administrative access. Detailed measures are in Annex II [attach/complete].
The Controller authorizes StructSure to engage the subprocessors listed in our Privacy Policy (currently: Supabase, Netlify, Stripe, Resend, and map/geocoding and CDN providers). StructSure imposes data‑protection terms on subprocessors no less protective than this DPA and remains responsible for their performance. StructSure will give the Controller [e.g., 30 days'] notice of a new or replacement subprocessor via [email / a subprocessors page], and the Controller may object on reasonable data‑protection grounds.
Taking into account the nature of the processing, StructSure will assist the Controller (including through the Services' self‑service features and, where needed, reasonable support) in responding to requests from data subjects to exercise their rights (access, correction, deletion, portability, objection).
StructSure will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller's data, and will provide information reasonably available to help the Controller meet its notification obligations.
On termination, StructSure will, at the Controller's choice, delete or return the Controller's Personal Data within [e.g., 30] days, and delete existing copies except where retention is legally required.
StructSure will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, subject to reasonable confidentiality and security limits. [Define scope/frequency.]
StructSure processes data in the United States. Where the Controller transfers data of individuals located outside the U.S., the parties will put in place an appropriate transfer mechanism (e.g., Standard Contractual Clauses). [Attach if applicable.]
Liability under this DPA is subject to the limitations in the Terms of Service. Except as amended here, the Terms remain in effect.