VRS Recruit Data Processing Addendum

VRS LLC. Effective: 21 July 2026.

This Addendum forms part of the agreement between VRS LLC (“we”, “us”, the processor) and the organization that controls a VRS Recruitworkspace (“you”, the controller). It applies whenever we process personal data on your behalf. Where it conflicts with the terms of service, this Addendum governs for that processing.

1. Roles

You are the controller of the personal data in your workspace and decide what is processed there, who may access it, and how long it is needed. We are the processor and act on your documented instructions. Using the product as documented, and configuring it through its settings, constitute your instructions. We are an independent controller only for our own account administration, billing, security, and service-improvement records.

2. Subject matter, duration, nature and purpose

We process personal data to provide, secure, maintain and support VRS Recruit for the duration of your subscription, plus the retention periods in section 7. The processing consists of hosting, storage, transmission, retrieval, organisation, analysis and deletion of workspace content, and the specific operations you trigger through product features.

3. Types of personal data and categories of data subjects

Data subjects: candidates and applicants, your employees and contractors, and client contacts.

Types of personal data: identification and contact details, CV and application content, work and education history, interview notes, assessments, communications, and hiring decisions. You control what is uploaded, so this list describes expected use rather than a technical limit.

The product is not designed for special categories of personal data. If you choose to place such data in your workspace, you are responsible for having a lawful basis for it.

4. Our obligations

5. Security

We apply measures appropriate to the risk, including: encryption of data in transit; tenant-scoped access controls so a workspace can only reach its own records; role-aware authorisation on sensitive operations; audit logging of access and changes; least-privilege administrative access; encrypted backups; and separation of production credentials from application code and configuration.

We will notify you without undue delay after becoming aware of a personal data breach affecting your workspace, and provide the information you reasonably need to meet your own notification duties.

6. Sub-processors

You give general authorisation for us to engage sub-processors. Our current sub-processors, their purpose and their processing locations are published at /subprocessors. We impose data protection obligations on each sub-processor that are no less protective than this Addendum, and we remain responsible for their performance.

We will update that page before a new sub-processor begins processing workspace data. You may object on reasonable data protection grounds by writing to privacy@vrsjo.com; if we cannot offer a reasonable alternative, you may terminate the affected part of the service.

7. Retention, return and deletion

On termination, or on your written request, we will delete personal data we process on your behalf, except where law requires us to keep it. Our standard periods are:

Deleted data can persist in encrypted backups until the backup cycle above completes. A legal hold suspends erasure for the records it covers.

8. Audits

On request we will provide the information reasonably necessary to demonstrate compliance with this Addendum. You may audit no more than once in any twelve-month period, on at least thirty days’ written notice, during business hours, without unreasonable disruption, and subject to confidentiality. We may satisfy an audit request with an existing report or documentation where that reasonably answers it. Additional audits may be conducted where required by a supervisory authority or following a breach affecting your workspace.

9. International transfers

Our hosting, error monitoring and product analytics are processed in the European Union. Some sub-processors listed at /subprocessorsoperate from, or route through, countries outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on the transfer safeguards in our agreement with that provider, such as the European Commission’s standard contractual clauses, and we limit the data transferred to what the feature requires.

10. Contact and changes

Send data protection questions, sub-processor objections, and data subject requests you need our help with to privacy@vrsjo.com. We will update this Addendum where the law or our processing changes, and the effective date above will change with it.