Review copy. Publication details are being completed. This copy is not available for contractual acceptance.
Version 2026-09-14.1 · Permanent link to this version · U.S. legal documents
Version history
- Version 2026-09-14.2 — Prepared 2026-09-14 · Draft — not published
- Version 2026-09-14.1 — Prepared 2026-09-14 · Draft — not published
- Version 2026-09-13.1 — Prepared 2026-09-13 · Draft — not published
1. When this agreement applies
This agreement applies when Evidize LLC processes personal information on your organization’s behalf and the parties include it in their customer agreement. The parties must identify the services and processing it covers. The legal requirements below apply only where the relevant U.S. privacy law covers that processing.
Your organization determines the purposes of its hiring process. Evidize must follow the agreed lawful instructions for processing on your behalf. Any processing for Evidize’s own purposes is addressed separately in the applicable Privacy Notice.
2. Describe the agreed processing
The agreement must identify the parties and the specific purposes for which information is provided. For example, the purpose may be analyzing a résumé against a job’s stated requirements. A reference to the whole agreement does not adequately describe a purpose under California’s Consumer Privacy Act, or CCPA.
Where an applicable state law requires a controller–processor agreement, it must also state the processing instructions, nature of the work, types of personal data, duration, and each party’s rights and duties. These details may be in the customer agreement or an attached schedule.
3. Limits on using the information
For processing covered by the CCPA’s service-provider or contractor rules, Evidize must not sell or share the information; retain, use or disclose it outside the specified purposes or direct business relationship; or combine it with other sources, except as the CCPA and its regulations permit. Evidize must comply with the applicable CCPA provisions and provide the same level of privacy protection the law requires of the business. Your organization provides the information only for the limited, specified purposes in the agreement.
AI training and service improvement are subject to those same limits. The CCPA permits certain internal service improvement, security and other uses. This agreement does not create a blanket ban on legally permitted improvement or authorize reuse that the law prohibits. Required notices, choices and permissions still apply.
4. Help with privacy requests and required assessments
For covered processing, Evidize must provide the assistance required by applicable law so your organization can respond to people’s privacy requests. Your organization must inform Evidize of requests that require its action and provide the information needed to carry them out.
Where the CCPA requires your organization to complete a cybersecurity audit or risk assessment, Evidize must cooperate and supply the relevant information in its possession, custody or control. Evidize must also provide assistance required by applicable automated-decision rules. These duties do not require an audit or assessment where the law does not. Assistance can use the existing support and secure data-handling process; this agreement does not promise to administer the employer’s notices, appeals, audits or legal assessments. If Evidize independently acts as a covered business, employer agent, developer or reporting company, its own duties remain separate.
5. Security and other providers
Evidize must provide the security and confidentiality required by the applicable law. For covered CCPA processing, your organization has the right to take reasonable and appropriate steps to check compliance and, on notice, stop and remedy unauthorized use. Evidize must notify your organization if it determines it can no longer meet its CCPA obligations.
Where a controller–processor law requires it, people processing the data must be bound by confidentiality, and Evidize must provide necessary compliance information and allow reasonable assessments as that law provides. This does not require a separate independent audit in every case.
Evidize must give subcontractors the written terms and protections required by the applicable law, including any required notice or opportunity to object. Your organization is responsible for the corresponding duties for suppliers it appoints. See the Supplier Requirements.
6. Return or deletion
Where the applicable controller–processor law requires it, Evidize must delete or return the personal data at your organization’s direction when services end, unless the law requires retention. Applicable deletion requests, recordkeeping duties and legal holds also govern when information may be removed. Retained information remains subject to the applicable protections and use limits.
If Evidize acts as a CCPA contractor for the covered processing, it certifies, by entering into this agreement, that it understands the contractual restrictions and will comply with them.