Data Processing Addendum

Effective date: July 28, 2026

This Data Processing Addendum ("DPA") supplements the Terms of Servicebetween you ("Customer") and DataSpark Tech LLC ("HRGrove") and applies whenever HRGrove processes personal information on Customer's behalf through the Service, most importantly the employee and candidate data Customer submits. It's incorporated into the Terms by reference and automatically applies to every workspace; no separate signature is required, though we're happy to countersign a copy for customers who need one for their own records. Email info@hrgrove.com.

1. Roles of the parties

For personal information Customer submits about its employees, contractors, and candidates ("Customer Personal Data"), Customer is the controller(or "business," under the CCPA/CPRA) and HRGrove is the processor(or "service provider"). Customer determines the purposes and means of processing Customer Personal Data; HRGrove processes it only on Customer's documented instructions, as set out in this DPA and the Terms, and as necessary to provide the Service.

2. Scope & nature of processing

Subject matter:HRGrove's provision of the HR management Service to Customer. Duration: for the term of the Terms, plus the post-termination retention window described in our Privacy Policy. Nature & purpose: storage, display, transmission, and AI-assisted generation of documents, solely to operate the features Customer uses. Categories of data subjects: Customer's employees, contractors, and job candidates. Categories of data: the information described in our Privacy Policy, Section 2: contact and role information, compensation, employment records, onboarding and time-off data, documents and e-signatures, resumes/applications, and (where Customer chooses to collect it) Social Security Numbers or similar tax IDs, which receive additional field-level encryption as described there.

3. Customer's instructions

HRGrove will process Customer Personal Data only to provide, secure, and support the Service, consistent with the Terms and Customer's use of the Service's features and settings, which constitute Customer's documented processing instructions. If HRGrove believes an instruction violates applicable data protection law, it will notify Customer (unless prohibited from doing so by law).

4. Subprocessors

Customer authorizes HRGrove to engage the subprocessors listed in our Privacy Policy, Section 5 (currently: Supabase, Vercel, Stripe, Anthropic, Resend, Google (analytics on our public marketing site only) and Cloudflare (bot protection on our public forms), and, only where Customer opts in, Slack and Microsoft Teams), each bound by written terms requiring a standard of data protection no less protective than this DPA. HRGrove remains responsible for its subprocessors' performance. We'll post updates to this list on our Privacy Policy; where required by law, we'll provide advance notice of a new subprocessor so Customer can object on reasonable data-protection grounds.

5. Security measures

HRGrove maintains the technical and organizational measures described in our Privacy Policy, Section 7, including encryption in transit and at rest, additional field-level encryption for Social Security Numbers, row-level tenant isolation, hashed credentials, role-based access control, optional two-factor authentication, and audit logging.

6. Personnel

HRGrove limits access to Customer Personal Data to personnel and contractors who need it to provide the Service, and requires them to be bound by confidentiality obligations at least as protective as Section 10 of the Terms.

7. Assistance with data subject requests

Where HRGrove receives a request from one of Customer's employees or candidates to exercise a data protection right (access, correction, deletion, etc.), HRGrove will promptly redirect the request to Customer, who is best positioned to respond as the controller. HRGrove will provide reasonable assistance to Customer in responding to such requests through the Service's existing functionality (export, edit, and delete tools) and, where those tools aren't sufficient, reasonable additional assistance at Customer's request.

8. Security incident notification

If HRGrove becomes aware of a security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, HRGrove will notify Customer without undue delay after becoming aware, and provide information reasonably available to HRGrove to help Customer meet its own notification obligations under applicable law.

9. Return & deletion of data

On termination of the Terms, HRGrove will make Customer Personal Data available for export and, following the retention window described in our Privacy Policy, Section 9, delete or anonymize it, except where retention is required by applicable law.

10. International transfers

The Service and our subprocessors currently store and process data in the United States. HRGrove doesn't currently offer the Service outside the United States; if that changes, we'll update this DPA and our Privacy Policy with the applicable transfer mechanism.

Customer represents that Customer Personal Data submitted to the Service relates to individuals located in the United States. If Customer nonetheless submits Customer Personal Data about an individual located outside the United States, including in the European Economic Area, United Kingdom, or Switzerland, Customer is solely responsible for identifying and implementing any transfer mechanism or additional safeguard required under the law applicable to that individual (such as the GDPR); HRGrove has not implemented, and doesn't represent that it has implemented, such a mechanism.

11. Audits

On reasonable request, no more than once per year (unless required following a security incident or by a regulator), HRGrove will make available information reasonably necessary to demonstrate compliance with this DPA, such as summaries of relevant security certifications or practices. Customer must give reasonable advance notice and conduct any review in a way that doesn't unreasonably disrupt HRGrove's operations or other customers' data.

12. Relationship to the Terms

This DPA is part of the Terms of Service. In the event of a conflict between this DPA and the Terms regarding the processing of personal information, this DPA controls. Capitalized terms not defined here have the meaning given in the Terms.

13. Contact

Questions about this DPA, or requests for a countersigned copy: info@hrgrove.com