Skip to content
Chefotech HRMS

Data Processing Addendum

The processor terms that apply when we handle personal data on a customer's behalf.

Last updated · Chefotech Technologies Private Limited

Scope

This Addendum forms part of the Terms of Service between Chefotech Technologies Private Limited ("Processor") and the Customer ("Controller"). Where it conflicts with the Terms on the subject of personal data, this Addendum prevails.

It applies for as long as we process personal data on the Controller's behalf.

Subject matter and duration

Subject matter: provision of the Chefotech HRMS platform. Duration: the term of the subscription, plus the deletion period described below.

Nature and purpose: hosting, storing, computing and making available human resources data as directed by the Controller through their configuration and use of the platform.

Categories of data subject: the Controller's employees, contractors, and applicants where the Controller uses the platform for recruitment.

Categories of personal data: as listed in the Privacy Policy.

Our obligations

We will:

  • Process personal data only on the Controller's documented instructions, which include the Controller's use of the platform's configuration. If we believe an instruction breaches applicable law, we will tell the Controller.
  • Ensure that personnel with access are bound by confidentiality obligations.
  • Implement and maintain the technical and organisational measures described in the Security section below.
  • Not engage a new sub-processor without giving the Controller prior notice and an opportunity to object.
  • Assist the Controller, taking into account the nature of the processing, in responding to data subject requests, in carrying out impact assessments, and in consulting supervisory authorities.
  • Notify the Controller without undue delay after becoming aware of a personal data breach, with the information the Controller needs to meet their own obligations.
  • Delete or return personal data at the end of the engagement, as described below.
  • Make available the information reasonably necessary to demonstrate compliance, and allow for audits as described below.

Security measures

Without limiting the above, we maintain:

  • Encryption of personal data in transit (TLS) and at rest.
  • Tenant isolation enforced at the data access layer, so that a query without an authenticated tenant context fails rather than returning data.
  • Role-based access control with least-privilege defaults, and immediate revocation when access is removed.
  • An append-only audit trail of security-relevant events.
  • Individually authenticated, logged and time-limited access to production systems.
  • Regular backups, and testing that they can actually be restored.
  • Segregated development, staging and production environments; production personal data is not used for development or testing.

Sub-processors

The current sub-processor list is published and maintained on the Sub-processors page.

We give at least 30 days' notice before adding or replacing a sub-processor. If the Controller reasonably objects on data protection grounds, and we cannot offer a practical alternative, the Controller may terminate the affected part of the service without penalty.

We remain liable for our sub-processors' performance of these obligations.

International transfers

Where personal data is transferred out of its region of origin, we rely on an adequacy decision where one exists, or on Standard Contractual Clauses or the equivalent mechanism in the applicable regime, together with any supplementary measures the transfer requires.

Audit

On reasonable notice and no more than once a year — or more often if a supervisory authority requires it, or following a breach — we will respond to a reasonable security questionnaire and provide available third-party assessment reports.

Where that is genuinely insufficient for the Controller's compliance obligations, we will discuss an on-site audit, conducted so as not to disrupt other customers and subject to confidentiality.

Return and deletion

On termination the Controller has 30 days of read-only access to export data. We then delete personal data from live systems within 60 days, and it is cycled out of encrypted backups within a further 90 days as the backup rotation completes.

We will certify deletion in writing on request. Where law requires us to retain something, we will say so and retain only what is required, for only as long as required.