Compliance
Data Processing Addendum (DPA)
Last updated: August 24, 2026. Contractual terms governing the processing of personal and candidate data under global data protection regulations.
1. Scope and Application
This Data Processing Addendum (“DPA”) supplements the Parikshafy Terms of Service between Parikshafy Technologies Private Limited (“Processor”) and the Customer (“Controller”).
This DPA applies to the processing of personal data relating to candidates, employees, and authorized recruiters in connection with the assessment services provided by Parikshafy.
2. Processing Details
- Subject Matter: The provision of technical hiring assessments, automated coding evaluation, online proctoring, and talent analytics.
- Duration: The term of the Customer's active subscription plus any post-termination data retention period agreed upon.
- Nature and Purpose: Storing, transmitting, and evaluating candidate technical assessment attempts and integrity telemetry.
- Categories of Data: Names, contact emails, educational background, code submissions, integrity signals, webcam snapshots, and screen captures.
- Categories of Data Subjects: Job applicants, student candidates, employees, and customer hiring personnel.
3. Obligations of the Processor
- Processing on Instructions: Processor shall process personal data solely on documented instructions from Controller, including with respect to international transfers.
- Confidentiality: Processor ensures that all personnel authorized to process personal data are committed to confidentiality obligations.
- Security of Processing: Processor implements robust technical and organizational measures (encryption in transit/at rest, strict multi-tenant isolation, role-based access control, vulnerability scanning).
- Sub-Processors: Processor shall maintain an updated list of authorized sub-processors and notify Controller of material changes.
- Data Subject Rights Assistance: Processor provides Controller with functionality to export candidate data and execute erasure requests.
4. Security Incident Management
In the event of a confirmed personal data breach affecting Customer data, Processor shall notify Controller without undue delay (within 48 hours of becoming aware) and provide necessary information to assist Controller in meeting regulatory breach notification requirements.
5. Deletion or Return of Data
Upon termination of services or upon Controller's request, Processor shall securely delete or return all personal data within 30 days, unless applicable statutory law requires retention of such data.
6. Execution & Inquiries
Enterprise customers requiring a countersigned DPA with custom Standard Contractual Clauses (SCCs) may request execution by emailing:
Parikshafy Technologies Private Limited Legal & Compliance
Email: sales@parikshafy.com