Data Processing Addendum
HIREQUARTERS
Effective Date: 1st June 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between HIREQUARTERS and the Client and governs the processing of Personal Data.
1. Purpose and Scope
1.1 Purpose
This DPA establishes the obligations of the Parties where HIREQUARTERS processes Personal Data on behalf of the Client.
1.2 Applicable Services
This DPA applies to all Services under which HIREQUARTERS processes Personal Data in connection with a Statement of Work.
1.3 Relationship to Terms
This DPA supplements the HIREQUARTERS Master Terms of Service.
2. Definitions
2.1 Personal Data
Any information relating to an identified or identifiable natural person.
2.2 Data Subject
An individual whose Personal Data is processed.
2.3 Controller
The entity determining the purposes and means of processing Personal Data.
2.4 Processor
An entity processing Personal Data on behalf of the Controller.
2.5 Personal Data Breach
A breach of security leading to accidental or unlawful destruction, loss, alteration, or disclosure of Personal Data.
3. Roles of the Parties
3.1 Controller
The Client acts as the Data Controller.
3.2 Processor
HIREQUARTERS acts as a Data Processor processing Personal Data on behalf of the Client.
3.3 Processing Instructions
HIREQUARTERS shall process Personal Data only on documented instructions from the Client.
4. Nature and Purpose of Processing
4.1 Processing Activities
Processing may include:
- Accessing analytics platforms
- Reviewing marketing data
- Managing content or SEO datasets
- Handling business contact information
4.2 Types of Personal Data
Personal Data may include:
- Names
- Email addresses
- Business contact information
- Website interaction data
- Technical metadata
4.3 Categories of Data Subjects
Data Subjects may include:
- Website users
- Business contacts
- Customers of the Client
- Employees of the Client
5. Processor Obligations
5.1 Processing Limitations
HIREQUARTERS shall process Personal Data solely to provide the Services.
5.2 Confidentiality
All personnel processing Personal Data are subject to confidentiality obligations.
5.3 Security Measures
HIREQUARTERS shall implement appropriate technical and organizational security measures.
6. Security of Processing
Security measures may include:
6.1 Access Controls
Limiting access to Personal Data to authorized personnel.
6.2 Infrastructure Security
Use of secure infrastructure and platforms.
6.3 Data Minimization
Processing only the data necessary for service delivery.
6.4 Internal Policies
Implementation of internal security procedures and training.
7. Subprocessors
7.1 Authorisation
The Client authorizes HIREQUARTERS to engage Subprocessors as necessary to deliver the Services.
7.2 Subprocessor Obligations
HIREQUARTERS shall ensure that Subprocessors are bound by appropriate data protection obligations.
7.3 Liability
HIREQUARTERS remains responsible for the acts and omissions of its Subprocessors.
8. Assistance to the Controller
8.1 Data Subject Requests
HIREQUARTERS shall assist the Client in responding to requests relating to:
- Access
- Rectification
- Erasure
- Data portability
8.2 Regulatory Compliance
HIREQUARTERS shall assist the Client in fulfilling its obligations regarding data protection compliance where reasonably required.
9. Personal Data Breach
9.1 Notification
HIREQUARTERS shall notify the Client without undue delay upon becoming aware of a Personal Data Breach.
9.2 Cooperation
HIREQUARTERS shall cooperate with the Client in investigating and mitigating the breach.
10. International Data Transfers
10.1 Cross-Border Transfers
Personal Data may be transferred to jurisdictions outside the Client’s country where necessary for service delivery.
10.2 Transfer Safeguards
Such transfers shall be conducted in accordance with applicable data protection laws.
11. Data Retention and Deletion
11.1 Retention
Personal Data shall be retained only for the duration necessary to provide the Services.
11.2 Return or Deletion
Upon termination of Services, HIREQUARTERS shall, at the Client’s instruction:
- Return Personal Data, or
- Securely delete such data
unless retention is required by law.
12. Audit Rights
12.1 Audit Requests
The Client may request reasonable information demonstrating compliance with this DPA.
12.2 Limitations
Audits must:
- Occur with reasonable notice
- Not disrupt operations
- Be conducted no more than once annually unless required by law.
13. Liability
Liability arising under this DPA shall be subject to the limitations of liability set forth in the Master Terms of Service.
14. Governing Law
This DPA shall be governed by the laws of the Republic of Serbia.
Disputes shall be resolved in accordance with the dispute resolution provisions in the Master Terms of Service.
