Legal

Data Processing
Agreement.

How Crimson Talent processes personal data on behalf of our customers — the roles, safeguards and commitments that govern it. This is a plain-language summary of our standard DPA.

Last updated April 2026
This page summarizes our standard DPA. A countersigned copy — incorporating the EU Standard Contractual Clauses and UK Addendum — is available on request from trust@crimsontalent.com, usually within one business day. Where a signed DPA exists, its terms control over this summary.

This Data Processing Agreement ("DPA") forms part of the agreement between Crimson Talent LLC ("Crimson," "we") and the customer ("Customer," "you") for the provision of our recruiting services and Talent Analytics platform (the "Services"). It applies whenever we process personal data on your behalf and reflects the requirements of the GDPR, UK GDPR and CCPA/CPRA.

1. Roles of the parties

For personal data you provide or that we process to deliver the Services on your instructions — for example, candidate records you upload or data generated within your platform workspace — you act as the controller and Crimson acts as the processor. Crimson processes such personal data only on your documented instructions, including as set out in the agreement and this DPA. Where Crimson determines the purposes and means of processing (for example, our own recruiting activities or billing), Crimson acts as an independent controller and its Privacy Policy governs.

2. Scope & purpose of processing

Crimson processes personal data solely to provide, maintain, secure and support the Services, and to comply with your reasonable, lawful instructions. We will not sell personal data, will not retain, use or disclose it for any purpose other than performing the Services, and will not combine it with data from other sources except as needed to deliver the Services. These commitments satisfy the "service provider" obligations under the CCPA/CPRA.

3. Duration

This DPA takes effect when incorporated into the agreement and remains in force for as long as Crimson processes personal data on your behalf. Provisions that by their nature should survive termination — including confidentiality, deletion and audit obligations — continue to apply after the Services end.

4. Nature of the data & categories of data subjects

The personal data processed depends on how you use the Services but typically includes candidate and employee identifiers, contact details, professional and employment history, education, compensation information, and communications. Categories of data subjects typically include your job candidates, employees, contractors and business contacts. You are responsible for ensuring you have a lawful basis to provide this data to us.

5. Sub-processing

You grant Crimson general authorization to engage sub-processors to support the Services. We maintain a current list of sub-processors — including their purpose, the data they process and their location — on our subprocessors page. Each sub-processor is bound by written terms offering data-protection obligations no less protective than those in this DPA, and Crimson remains liable for their performance. We will give advance notice of new sub-processors and a reasonable opportunity to object on legitimate data-protection grounds.

6. Security measures

Crimson maintains technical and organizational measures appropriate to the risk, described in detail on our Security overview. These include encryption of data at rest with AES-256 and in transit with TLS 1.3, role-based access control (RBAC) with least-privilege enforcement, multi-factor authentication, network segmentation, continuous logging, and monitoring by a 24/7 Security Operations Center. Our controls are independently validated under SOC 2 Type II and ISO/IEC 27001.

7. International data transfers

Crimson hosts and processes customer data in the United States. Where personal data originating in the EEA, UK or Switzerland is transferred to us, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) as incorporated into our signed DPA, together with supplementary measures where appropriate. A transfer-impact assessment is available to customers on request.

8. Data-subject rights

Taking into account the nature of the processing, Crimson will assist you — by appropriate technical and organizational measures and insofar as possible — in responding to requests from data subjects exercising their rights under the GDPR and CCPA/CPRA, including access, correction, deletion, restriction, portability and objection. If a data subject contacts Crimson directly regarding data we process on your behalf, we will promptly refer them to you unless otherwise legally required.

9. Personal-data breach notification

Crimson will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal-data breach affecting your data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. We will cooperate reasonably with your own breach-response and regulatory-notification obligations.

10. Return & deletion of data

On termination of the Services, and at your choice, Crimson will return or delete all personal data processed on your behalf, and delete existing copies, unless retention is required by applicable law. We honor deletion requests within the timeframes specified in the agreement and will confirm completion in writing on request. Backup copies are purged on our standard rolling schedule.

11. Audit rights

Crimson will make available to you the information reasonably necessary to demonstrate compliance with this DPA, including our current SOC 2 Type II report and ISO certificates available through our Trust Center. Where those are insufficient to meet a regulatory requirement, you may conduct an audit — directly or via an independent auditor bound by confidentiality — on reasonable prior notice, no more than once per year absent a regulator's requirement or a suspected breach, subject to reasonable scope and cost arrangements.

12. Liability & order of precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the agreement. In the event of a conflict between this DPA and the agreement in respect of the processing of personal data, this DPA prevails; in the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail. All other terms of the agreement remain in full force.

Questions or want a signed copy? Contact our trust team at trust@crimsontalent.com. For how we handle data as a controller, see our Privacy Policy; for our security program, see the Security overview.