1. Application, parties and electronic execution
This Data Processing Addendum (DPA) forms part of the agreement (Agreement) between the customer identified in an order form, account or other signed agreement (Customer) and VRS LLC, Amman, Hashemite Kingdom of Jordan (VRS), when VRS processes personal data on Customer’s behalf to provide VRS Recruit or another contracted service.
This DPA becomes binding when Customer signs or accepts an Agreement that references VRS’s online terms or DPA, clicks to accept it through an authorized account, or both parties sign it. Customer’s account and Agreement supply Customer’s legal name, address, contact and signature details. A person accepting for Customer represents that they have authority to do so.
Scope boundary. This DPA governs VRS’s processor activities. The Privacy Policy governs data for which VRS acts as controller, such as VRS account administration, security, billing, website inquiries, our own talent network, and certain agency recruitment activities.
2. Definitions
Applicable Data Protection Law means privacy and data-protection law that applies to the processing, including Jordan’s Personal Data Protection Law No. 24 of 2023 and its regulations and instructions, and, where applicable, the EU General Data Protection Regulation 2016/679 (GDPR).
Customer Personal Data means personal data contained in Customer Data that VRS processes as processor for Customer. Data Subject, Controller, Processor, Processing, Personal Data Breach, and Subprocessor have the meanings in Applicable Data Protection Law. Restricted Transfer means a transfer requiring an adequacy or contractual safeguard under Applicable Data Protection Law.
3. Roles, subject matter and compliance
- Customer is the Controller, or a Processor lawfully appointing VRS as its Subprocessor. VRS is the Processor or Subprocessor for Customer Personal Data.
- Each party will comply with the obligations that apply to its role. Customer is responsible for the lawfulness of its instructions, data collection, notices, consent, recruitment criteria, automated-decision safeguards, retention choices and Data Subject communications.
- VRS will process Customer Personal Data only for the subject matter, nature, purposes, duration, Data Subjects and categories in Annex A and the Agreement.
- If VRS is required by law to process data outside Customer’s instructions, VRS will notify Customer before processing unless law prohibits notice.
- VRS will promptly inform Customer if, in VRS’s reasonable opinion, an instruction violates Applicable Data Protection Law. VRS may suspend the affected processing until the parties resolve the issue.
4. Documented instructions and purpose limitation
The Agreement, Customer’s authorized use and configuration of the Services, support requests, and other written directions accepted by VRS are Customer’s documented instructions. VRS will not exceed the specified purpose or duration. VRS will not sell Customer Personal Data, use it for third-party advertising, or disclose it except under the Agreement, Customer’s instruction, or applicable law.
Customer authorizes VRS to make the transfers and disclosures reasonably necessary to provide enabled features through the Subprocessors in Annex C. Additional instructions that require a material product change or unusual assistance may be subject to feasibility, a written change order and reasonable fees.
5. Confidentiality and authorized personnel
VRS will limit access to personnel and contractors who need Customer Personal Data for their assigned duties. VRS will ensure they are bound by confidentiality, receive appropriate data-protection and security direction, and process data only within their authorization. These duties survive the end of their access and the Agreement.
6. Security, technical and organizational measures
- VRS will maintain the measures in Annex B, taking into account the state of the art, implementation cost, processing scope and risk.
- VRS may update measures as technology and risk change, provided the overall protection is not materially reduced.
- Customer is responsible for using available account safeguards, managing authorized users, configuring roles and retention, securing its own endpoints, and avoiding unnecessary sensitive data.
- VRS will maintain appropriate continuity, backup, access-control, incident-response and restoration procedures and will periodically assess the effectiveness of relevant controls.
- VRS does not represent that it holds ISO 27001, SOC 2 or another certification unless VRS separately provides current written evidence.
7. Subprocessors
- Customer gives general written authorization for the Subprocessors in Annex C, subject to this section.
- VRS will impose written data-protection obligations on each Subprocessor that are no less protective for the delegated processing than the relevant obligations in this DPA. VRS remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law.
- VRS will post an updated schedule and give subscribed Customers at least 30 days’ notice before a new Subprocessor begins materially processing Customer Personal Data, unless an urgent security or continuity need makes shorter notice necessary.
- Customer may object within 15 days of notice on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, Customer may stop the affected feature or terminate only the affected Service and receive a pro-rata refund of prepaid fees for its unused period.
- Customer may subscribe to change notices by emailing hamzah@vrsjo.com from its contract-contact address.
8. Data Subject, regulatory and impact-assessment assistance
Taking into account the nature of processing and information available to VRS, VRS will reasonably assist Customer with:
- secure access, correction, completion, restriction, objection, portability, deletion or concealment requests;
- consent withdrawal and objections to unnecessary, excessive, discriminatory, unfair or unlawful profiling;
- providing meaningful information and human-review routes for qualifying automated decisions;
- security inquiries, regulator consultations and legally required records;
- data-protection impact assessments, including the annual or transfer-related assessments required under Jordanian law; and
- Customer’s breach assessment and required notifications.
VRS will not respond substantively to a request about Customer Personal Data except on Customer’s instruction or as required by law. VRS will forward the request where it can identify the relevant Customer. Customer is responsible for verifying the requester and deciding the response.
9. Personal Data Breaches and government demands
- VRS will notify Customer immediately and without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
- As information becomes available, notice will describe the nature of the incident, affected data and people, likely consequences, mitigation, and a VRS contact. VRS may provide information in phases and will take reasonable steps to contain, investigate, remediate and prevent recurrence.
- Notification is not an admission of fault. Customer controls notices to Data Subjects and authorities unless law assigns the duty directly to VRS.
- VRS will notify Customer of a legally binding government demand for Customer Personal Data where permitted, review its validity, disclose only the required minimum, and reasonably support Customer’s protective efforts.
The parties acknowledge that Jordanian law may require a Controller to notify affected people within 24 hours and the Personal Data Protection Unit within 72 hours after discovering a serious breach. Customer must preserve enough response time when directing VRS and its own processors.
10. Compliance evidence and audits
- VRS will make available information reasonably necessary to demonstrate compliance, such as security summaries, architecture evidence, policy extracts, penetration or vulnerability-review summaries when available, and Subprocessor information.
- Customer may conduct one reasonable audit per 12-month period through document review or a qualified independent auditor, on at least 30 days’ notice, during business hours, subject to confidentiality and without accessing another customer’s data.
- Additional or on-site audits are permitted when required by a regulator, following a material incident, or where supplied evidence is reasonably insufficient. Customer will bear its audit cost unless the audit identifies VRS’s material breach.
- Audits must not compromise security, service availability, privilege or another party’s rights. VRS may satisfy overlapping requests with a recent independent report or pooled response.
11. Return, deletion and retention
During the Agreement, VRS will provide supported export, correction, anonymization and deletion controls and reasonable assistance. On Customer’s written instruction or at termination, VRS will return, delete, conceal or anonymize Customer Personal Data as required by Applicable Data Protection Law and the Agreement, unless law requires continued retention.
Deletion proceeds across supported active records, processor systems and rolling backup cycles. Some records may be anonymized to preserve referential, financial or audit integrity. Security, audit, legal-hold and commercial records may be retained for their applicable period. Residual backups remain protected from ordinary use and will be overwritten or deleted under the applicable cycle. VRS will provide a deletion confirmation on reasonable written request when the process is complete.
12. International and Restricted Transfers
- VRS will not transfer Customer Personal Data outside Jordan unless the Controller has a lawful transfer basis and the recipient provides the protection required by Articles 14 and 15 of Jordan’s Personal Data Protection Law or an applicable exception is documented.
- Customer authorizes processing in the locations in Annex C and will document any required Jordan transfer assessment or consent. VRS will provide information reasonably needed for that assessment.
- For an EEA Restricted Transfer to VRS in a country without an adequacy decision, the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 (SCCs) are incorporated by reference. Module 2 applies when Customer is Controller; Module 3 applies when Customer is Processor. Annex D completes the selections and appendices.
- The parties will complete a transfer impact assessment and implement supplementary measures reasonably required by law. VRS will promptly inform Customer if it can no longer comply with the transfer safeguard.
- For UK or Swiss transfers, the parties will execute or incorporate the regulator-approved addendum or adaptation applicable at the time. Contact hamzah@vrsjo.com before the Restricted Transfer.
The official SCC text is available on EUR-Lex. Nothing in the Agreement modifies the SCCs or limits Data Subject rights under them.
13. Term, liability and order of precedence
This DPA lasts while VRS processes Customer Personal Data. The Agreement’s liability terms apply between the parties to the extent permitted by law, but do not limit rights or liability that cannot lawfully be limited and do not override the SCCs. If this DPA conflicts with the Agreement on processing, this DPA controls. If it conflicts with the SCCs for a Restricted Transfer, the SCCs control.
Changes required by law may take effect on notice. Other material changes apply under the Agreement. Invalid terms are limited to the minimum extent needed while preserving the remaining DPA.
Annex A — Processing details
| Subject matter | Providing, securing, supporting and maintaining VRS Recruit and the contracted recruitment, communication, meeting, document, workflow, integration and related services. |
|---|---|
| Duration | The Agreement term plus the period needed to complete return, deletion, anonymization, backup expiry, legal retention and dispute handling. |
| Nature and purpose | Collection, recording, organization, structuring, storage, retrieval, consultation, parsing, comparison, scoring, ranking, grading, summarization, communication, disclosure to authorized recipients, restriction, export, deletion and anonymization, solely to deliver Customer-configured recruitment operations and support. |
| Frequency | Continuous or event-driven while authorized users, candidates, communications, integrations and automated jobs use the Services. |
| Data Subjects | Candidates, applicants, prospects, referees, employees, contractors, customer users, recruiters, interviewers, hiring managers, client contacts, signers, meeting participants and people communicating through enabled channels. |
| Personal-data categories | Identity and contact; CV, employment, education, skills and languages; applications and screening; recruitment stages, notes, scores and decisions; assessments and integrity events; interview media, transcripts and summaries; email, SMS, WhatsApp, call and meeting content or metadata; connected account data; signatures; account, authentication, device, IP, audit and support data; billing-contact and usage data. |
| Sensitive data | Not required by default. Customer may submit or collect sensitive data only where strictly necessary and lawful. This can include accessibility or accommodation information, financial or signature information, background information, or sensitive content voluntarily included in files or communications. Customer must provide explicit instructions and safeguards. |
| Controller obligations | Lawful basis and consent; Article 9 or equivalent notice; accuracy; minimization; retention; rights responses; DPIA; transfer assessment; human-review safeguards; lawful employment and non-discrimination practices. |
Annex B — Current technical and organizational measures
Network and transport
HTTPS/TLS for public traffic; Cloudflare edge protection and bot controls; private Cloud SQL networking with encrypted-only database connections; signed edge-to-origin host authority for product-bound services.
Encryption and secrets
Provider-managed encryption at rest for managed database and object storage; secrets stored outside source code in managed secret services; credential rotation and restricted runtime binding.
Access control
Verified accounts, secure production cookies, magic links and optional OTP, TOTP and passkeys; workspace membership, role, capability and object-scope checks; separated VRS, Syndeo and internal-admin runtime boundaries.
Tenant and product boundaries
Trusted host resolution, workspace-edition checks, workspace-scoped application authorization, and isolated product service identities. VRS does not claim a separate physical database for every customer.
Input and file controls
Boundary validation, file extension, MIME and magic-byte checks, size limits on supported upload paths, anti-automation controls on public application flows, and rate limiting on covered endpoints.
Logging and monitoring
Audit records for significant operations and access decisions; infrastructure and application logs; error monitoring configured not to collect default PII; security and incident investigation procedures.
Availability and recovery
Managed regional compute and database services, health checks, point-in-time database recovery, rolling object backups, deployment rollback procedures, and restoration testing appropriate to the service.
Retention and disposal
Category-specific retention jobs, candidate anonymization, supported object deletion, customer-configurable policies for covered categories, protected backup cycles, and legal-hold exceptions.
People and vendors
Need-to-know access, confidentiality duties, role restriction, security and privacy direction, vendor due diligence, written processor obligations, and incident and rights-request coordination.
Review
Risk-based control review, vulnerability assessment, DPIAs for sensitive or international processing, and updates following material architecture, vendor or risk changes.
These measures describe the current control framework, not a certification or guarantee. VRS will provide additional non-public implementation detail under confidentiality where reasonably required for a Customer assessment.
Annex C — Current Subprocessor and provider schedule
“Optional” means the provider receives Customer Personal Data only when Customer or an authorized user enables or uses the associated feature. Locations are high-level because provider networks and customer-selected regions may change; the current provider contract and transfer assessment control.
| Provider | Purpose | Use | Processing location |
|---|---|---|---|
| Google Cloud Platform | Application compute, managed PostgreSQL database, cache, logs, secrets, backups and supporting infrastructure. | Core | Primary application/database region: Germany; provider resilience and support locations under contract. |
| Cloudflare | CDN, DNS, edge Workers, web application protection, Turnstile, Pages hosting and R2 object storage. | Core | Global edge network; storage and support locations under account configuration and provider terms. |
| Brevo | Transactional VRS Recruit application email and delivery of VRSJO website business and candidate inquiries, including submitted attachments, to authorized VRS recipients. | Core and VRS controller operations | EEA and other contracted provider and delivery-network locations. |
| Sentry | Error and performance monitoring with default PII collection disabled. | Core | Configured German ingestion region; limited provider support locations. |
| DeepSeek | Candidate comparison and scoring and other configured AI generation. | Feature-specific | People’s Republic of China and locations stated by the provider. |
| Mistral AI | CV parsing and structured extraction. | Feature-specific | EEA and other provider processing locations under contract. |
| Groq | Recruiter copilot or agent execution and optional speech generation. | Feature-specific | United States and provider support locations. |
| Daily | Video meetings, call media, recordings and transcription workflows. | Optional | Customer-selected or provider-assigned regions; United States/global operations. |
| Twilio | Voice, SMS and WhatsApp communications and delivery events. | Optional | Global network, including United States and selected regional processing. |
| Cal.com | Scheduling and booking synchronization. | Optional | United States and provider infrastructure locations. |
| Google APIs / Google Workspace | Customer-authorized sign-in, Gmail, Calendar, Drive and Sheets features. | Optional | Global Google infrastructure under the connected account and Google terms. |
| Composio | Customer-enabled connection and action layer for Gmail, Outlook, Google Calendar, Slack, HubSpot, Zendesk and other selected tools. | Optional | United States/global provider and connected-app locations. |
Annex D — EU SCC selections and appendices
For an applicable EEA Restricted Transfer, the parties complete the SCCs as follows:
- Module: Module 2 (Controller to Processor) or Module 3 (Processor to Processor), according to Customer’s role.
- Clause 7: the docking clause applies.
- Clause 9: Option 2, general written authorization, with the 30-day notice period in Section 7.
- Clause 11: the optional independent dispute-resolution language does not apply.
- Clause 17: Option 1; the SCCs are governed by the law of Ireland.
- Clause 18: the courts of Ireland have jurisdiction for SCC disputes.
- Annex I.A: the Data Exporter is Customer, with the name, address, contact and activities in the Agreement; the Data Importer is VRS LLC, Amman, Jordan, hamzah@vrsjo.com, providing the activities in Annex A.
- Annex I.B: Annex A of this DPA describes the transfer, including categories, frequency, purpose and duration.
- Annex I.C: the competent supervisory authority is determined under SCC Clause 13; where a fallback is required and lawful, the Irish Data Protection Commission applies.
- Annex II: Annex B of this DPA.
- Annex III: Annex C of this DPA for Module 3 and any other case requiring the list.
The Agreement’s electronic acceptance records are the parties’ signatures for the incorporated SCCs to the extent electronic execution is legally valid. Either party will provide a countersigned copy or complete additional exporter details on reasonable request.
VRS contact for this DPA: VRS LLC, Amman, Hashemite Kingdom of Jordan · hamzah@vrsjo.com