1. Purpose and Scope

1.1 Purpose

This DPA establishes the obligations of the Parties where HIREQUARTERS processes Personal Data on behalf of the Client.

1.2 Applicable Services

This DPA applies to all Services under which HIREQUARTERS processes Personal Data in connection with a Statement of Work.

1.3 Relationship to Terms

This DPA supplements the HIREQUARTERS Master Terms of Service.

2. Definitions

2.1 Personal Data

Any information relating to an identified or identifiable natural person.

2.2 Data Subject

An individual whose Personal Data is processed.

2.3 Controller

The entity determining the purposes and means of processing Personal Data.

2.4 Processor

An entity processing Personal Data on behalf of the Controller.

2.5 Personal Data Breach

A breach of security leading to accidental or unlawful destruction, loss, alteration, or disclosure of Personal Data.

3. Roles of the Parties

3.1 Controller

The Client acts as the Data Controller.

3.2 Processor

HIREQUARTERS acts as a Data Processor processing Personal Data on behalf of the Client.

3.3 Processing Instructions

HIREQUARTERS shall process Personal Data only on documented instructions from the Client.

4. Nature and Purpose of Processing

4.1 Processing Activities

Processing may include:

  • Accessing analytics platforms
  • Reviewing marketing data
  • Managing content or SEO datasets
  • Handling business contact information

4.2 Types of Personal Data

Personal Data may include:

  • Names
  • Email addresses
  • Business contact information
  • Website interaction data
  • Technical metadata

4.3 Categories of Data Subjects

Data Subjects may include:

  • Website users
  • Business contacts
  • Customers of the Client
  • Employees of the Client

5. Processor Obligations

5.1 Processing Limitations

HIREQUARTERS shall process Personal Data solely to provide the Services.

5.2 Confidentiality

All personnel processing Personal Data are subject to confidentiality obligations.

5.3 Security Measures

HIREQUARTERS shall implement appropriate technical and organizational security measures.

6. Security of Processing

Security measures may include:

6.1 Access Controls

Limiting access to Personal Data to authorized personnel.

6.2 Infrastructure Security

Use of secure infrastructure and platforms.

6.3 Data Minimization

Processing only the data necessary for service delivery.

6.4 Internal Policies

Implementation of internal security procedures and training.

7. Subprocessors

7.1 Authorisation

The Client authorizes HIREQUARTERS to engage Subprocessors as necessary to deliver the Services.

7.2 Subprocessor Obligations

HIREQUARTERS shall ensure that Subprocessors are bound by appropriate data protection obligations.

7.3 Liability

HIREQUARTERS remains responsible for the acts and omissions of its Subprocessors.

8. Assistance to the Controller

8.1 Data Subject Requests

HIREQUARTERS shall assist the Client in responding to requests relating to:

  • Access
  • Rectification
  • Erasure
  • Data portability

8.2 Regulatory Compliance

HIREQUARTERS shall assist the Client in fulfilling its obligations regarding data protection compliance where reasonably required.

9. Personal Data Breach

9.1 Notification

HIREQUARTERS shall notify the Client without undue delay upon becoming aware of a Personal Data Breach.

9.2 Cooperation

HIREQUARTERS shall cooperate with the Client in investigating and mitigating the breach.

10. International Data Transfers

10.1 Cross-Border Transfers

Personal Data may be transferred to jurisdictions outside the Client’s country where necessary for service delivery.

10.2 Transfer Safeguards

Such transfers shall be conducted in accordance with applicable data protection laws.

11. Data Retention and Deletion

11.1 Retention

Personal Data shall be retained only for the duration necessary to provide the Services.

11.2 Return or Deletion

Upon termination of Services, HIREQUARTERS shall, at the Client’s instruction:

  • Return Personal Data, or
  • Securely delete such data

unless retention is required by law.

12. Audit Rights

12.1 Audit Requests

The Client may request reasonable information demonstrating compliance with this DPA.

12.2 Limitations

Audits must:

  • Occur with reasonable notice
  • Not disrupt operations
  • Be conducted no more than once annually unless required by law.

13. Liability

Liability arising under this DPA shall be subject to the limitations of liability set forth in the Master Terms of Service.

14. Governing Law

This DPA shall be governed by the laws of the Republic of Serbia.

Disputes shall be resolved in accordance with the dispute resolution provisions in the Master Terms of Service.