Data Processing Addendum
This Data Processing Addendum ("DPA") supplements the Terms of Service and Privacy Policy and governs The People Pocket's processing of Customer Personal Data on Customer's behalf. It is effective as of the date Customer first accepts the Terms of Service or executes a written order form referencing it, whichever is earlier. A countersigned counterpart is available on request for customers that require one.
1. Roles of the parties
For workforce and situation data Customer submits to Tova, employee names, job details, conduct notes, conversation content, uploaded documents, Customer is the Controller and The People Pocket is the Processor. For account, billing, and product-telemetry data about Customer's authorized users, The People Pocket is an independent Controller under the Privacy Policy.
2. Subject matter, duration, and nature of processing
Subject matter: providing the The People Pocket service (AI HR guidance, situation records, document generation, reminders). Duration: the term of the subscription plus the retention windows in the Privacy Policy. Nature and purpose: storing, retrieving, analyzing, and generating text about workforce situations Customer chooses to describe. Data subjects: Customer's employees, applicants, contractors, and third parties named by Customer's users. Categories of data: identifiers, employment details, performance and conduct information, and any additional categories Customer elects to submit (which may include sensitive categories such as health, disability, or protected-class information, Customer controls what it submits).
3. Processor instructions
The People Pocket processes Customer Personal Data only on documented instructions from Customer, which include the Terms of Service, this DPA, in-product configuration, and Customer's use of the service. The People Pocket will inform Customer if, in its opinion, an instruction violates applicable data-protection law.
4. Confidentiality
Personnel authorized to process Customer Personal Data are bound by written confidentiality obligations or statutory duties of confidence and are granted access on a need-to-know basis.
5. Security measures
The People Pocket maintains technical and organizational measures appropriate to the risk, including: encryption in transit (TLS 1.2+) and at rest, role-based access controls, tenant isolation, least-privilege service credentials, audit logging of privileged actions, secrets management, and a documented vulnerability and patch-management process. A current summary is available on request.
6. Subprocessors
Customer authorizes The People Pocket to engage subprocessors to provide the service. Current subprocessors include hosting, backend platform, AI model providers, email delivery, and payment processing. A current subprocessor list is available on request. The People Pocket will provide notice of intended additions or replacements before they take effect and will remain responsible for its subprocessors' performance under this DPA.
7. Data-subject rights and cooperation
Taking into account the nature of the processing, The People Pocket will assist Customer through appropriate technical and organizational measures, including in-product export and deletion, to fulfill Customer's obligations to respond to data-subject requests. Requests received by The People Pocket directly will be redirected to Customer without responding on the merits.
8. Assistance with DPIAs and regulator engagement
The People Pocket will provide Customer with reasonable information necessary to demonstrate compliance with processor obligations and to support Customer's data-protection impact assessments and prior consultations with supervisory authorities, taking into account the information available to The People Pocket.
9. Personal-data breach notification
The People Pocket will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide information reasonably available to enable Customer to meet its notification obligations. Notifications are not an acknowledgment of fault or liability.
10. International transfers
Where processing involves the transfer of Customer Personal Data outside the jurisdiction of origin, The People Pocket relies on lawful transfer mechanisms, including, where applicable, the EU Standard Contractual Clauses and the UK Addendum, which are incorporated by reference and made available on request.
11. Return or deletion on termination
On termination or expiration of the subscription, The People Pocket will, at Customer's election, return or delete Customer Personal Data within the timelines in the Privacy Policy, except where retention is required by law or is contained in routine backups pending overwrite.
12. Audits
The People Pocket will make available to Customer information reasonably necessary to demonstrate compliance with this DPA. On reasonable prior written notice and no more than once per twelve months (or as required by a supervisory authority), The People Pocket will respond to a documentation-based audit questionnaire; on-site audits require a separate written agreement and are at Customer's expense.
13. Contact
Privacy and DPA inquiries: privacy@backpockethr.com. Security incidents: security@backpockethr.com. Legal: legal@backpockethr.com.