This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller") and Openoffice Technologies, Inc. dba syrcleHR("Processor") for the provision of the Services. It applies when syrcleHR processes Personal Data on behalf of the Controller and is subject to applicable data protection laws, including the GDPR, UK GDPR, and the CCPA/CPRA as a "service provider".
1. Roles and scope
syrcleHR acts as a Processor (or service provider) for Personal Data that Controller submits to the Services in connection with its hiring activities. syrcleHR acts as an independent Controller for account administration, billing, security, and product analytics.
2. Processing details
- Subject matter: operation of the syrcleHR confidential hiring marketplace.
- Duration: the term of the agreement plus any retention period required by law.
- Nature and purpose: hosting, redaction, matching, communication, and audit logging to support hiring workflows.
- Categories of data subjects: educator candidates, district personnel, recruiting-firm personnel.
- Categories of Personal Data: identification data, contact details, professional credentials, employment history, communications, and usage metadata.
3. Processor obligations
- Process Personal Data only on documented instructions from Controller, including as set out in the agreement.
- Ensure that personnel authorized to process Personal Data are bound by confidentiality.
- Implement appropriate technical and organizational measures, including encryption in transit and at rest, role-based access controls, row-level security, and immutable audit logging for unlock events.
- Assist Controller, taking into account the nature of processing, in responding to data-subject requests and in meeting its obligations under Articles 32-36 GDPR (or equivalent).
- Notify Controller without undue delay after becoming aware of a Personal Data breach affecting Controller data.
4. Sub-processors
Controller authorizes syrcleHR to engage sub-processors to provide hosting, database, email, analytics, AI gateway, and payment services. A current list is available on request from legal@syrcleHR.com. syrcleHR remains responsible for sub-processor performance and will give Controller notice of new sub-processors with a reasonable opportunity to object.
5. International transfers
Where Personal Data originating in the EEA, UK, or Switzerland is transferred to a jurisdiction without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses and the UK Addendum by reference. syrcleHR will implement supplementary measures as reasonably necessary.
6. Data subject rights
syrcleHR will, taking into account the nature of the processing, provide reasonable assistance to enable Controller to respond to requests from data subjects to exercise their rights under applicable law.
7. Audits
On reasonable written request and no more than once per year (except following a Personal Data breach or as required by a regulator), syrcleHR will make available information necessary to demonstrate compliance with this DPA, including summary security documentation.
8. Deletion and return
On termination of the agreement, syrcleHR will, at Controller's choice, delete or return all Personal Data, subject to retention required by law or for legitimate dispute resolution. Audit logs for unlock events are retained as described in our Privacy Policy.
9. CCPA / CPRA
When processing Personal Information of California residents on Controller's behalf, syrcleHR acts as a "service provider" and will not (a) sell or share Personal Information, (b) retain, use, or disclose it for any purpose other than the business purposes specified in the agreement, or (c) combine it with Personal Information received from other sources except as permitted by the CCPA.
10. Contact
Requests under this DPA: legal@syrcleHR.com.

