Review copy. Publication details are being completed. This copy is not available for contractual acceptance.
Version 2026-09-14.2 · Permanent link to this version · U.S. legal documents
Version history
- Version 2026-09-14.2 — Prepared 2026-09-14 · Draft — not published
- Version 2026-09-14.1 — Prepared 2026-09-14 · Draft — not published
- Version 2026-09-13.1 — Prepared 2026-09-13 · Draft — not published
1. Who this agreement covers
This U.S. Customer Data Agreement is between Evidize LLC ("Evidize") and the customer identified in the accepted Customer Terms, order or service agreement that expressly incorporates this version ("Customer"). It governs personal information Evidize processes on Customer's behalf ("Customer Data"). It takes effect on the date that incorporation becomes binding. Affirmative acceptance of Customer Terms incorporating this version also accepts this agreement. Creating a workspace without valid acceptance, viewing this draft or receiving an informational email does not enter into it.
Customer chooses its hiring purposes and lawful instructions. Evidize will process Customer Data for the services and purposes in section 2, the selected service settings, and other lawful written instructions accepted within that scope. Neither party may instruct the other to break the law. Evidize will raise a suspected unlawful instruction with Customer and suspend the affected processing where necessary to comply with its own duties.
The terms "business," "controller," "service provider," "contractor" and "processor" have their meanings under the law governing the activity. This agreement does not determine a role by its label. Separate processing for Evidize's own purposes is addressed in its Privacy Notice; Evidize cannot move Customer Data into that category merely by changing a notice.
2. The agreed processing
The subject is the delivery of Evidize's selected U.S. private-employer and staffing services. The people concerned are applicants, interview participants, Customer's hiring users and contacts, and people whose information they lawfully supply for those services. Customer provides information only for the specific purposes below. A row authorizes only the functions selected in the order or service settings; it does not enable an unavailable product.
| Selected function and purpose | Information and processing |
|---|---|
| Applications and job analysis | Receive, store and organize names, contact details, résumés, work and education history, skills, application answers, professional links and job criteria. Extract text, compare the supplied evidence with the stated job criteria, and produce qualification findings, summaries, scores, rankings and recommendations for Customer's hiring use. |
| Interview setup and access | Process participant and recruiter details, calendar information, meeting links, interview times, session identifiers and access status to arrange the selected interview and authenticate access. Process selected information supplied through an enabled Microsoft 365 integration for that function. |
| Disclosed interview security checks | Process the permitted device, application, network, clipboard-event and display signals described in the session notice, together with check times and outcomes, to detect disallowed tools, administer temporary access holds and supply authorized review evidence. The notice and approved collector configuration limit the fields collected; this clause does not authorize arbitrary device content collection. |
| Customer records, requests and assistance | Store authorized notes, scorecards, outputs, corrections, employer-supplied location facts, candidate declarations, notice and permission receipts, and relevant support messages. Provide authorized access, exports, corrections, retention and deletion, and maintain necessary evidence of service actions. Handle accommodation information and voluntary demographic information only for the separately selected, lawful assistance or reporting purpose; do not use it as an undisclosed ranking input. |
| Service operation and troubleshooting | Process access logs, error information, delivery status and the minimum relevant Customer Data needed to operate, secure, diagnose, repair and check the quality of the services supplied to Customer, subject to section 3. Authorized suppliers may host, transmit or process only the data needed for their assigned function. |
Processing lasts for the selected service and any permitted completion, recordkeeping or preservation period under section 7. Customer's written retention instructions identify the record category, retention period or determining event, and any legal hold. Evidize's own legally required records are treated separately. A hiring employer's retention period does not automatically apply to every technical record Evidize holds.
This schedule does not authorize new recording, biometric extraction, credit or criminal screening, general candidate profiling across customers, or a consumer companion service. A separate feature, new purpose or supplier use requires its own lawful scope and any required notice, agreement or permission. The supported U.S. hiring market is not a promise that all storage, processing or supplier access occurs in the U.S.
3. Limits on use, evaluation and training
Evidize will restrict Customer Data to the agreed services and lawful instructions. It will not use identifiable Customer Data to train a general model or build profiles for other customers under this agreement. Such use requires a separate, specific written agreement and a defensible legal basis, with all required disclosures and choices; Customer's agreement alone cannot override a person's legal rights.
Within the selected service, Evidize may inspect relevant inputs and outputs to investigate an error, validate a correction or evaluate whether that service works as described. It will limit access and the information used to that task, use less identifying information where practicable, and apply the same retention and supplier restrictions. This permission does not authorize unrelated model training, sale, targeted advertising or enriching another customer's candidate records. Separate use of deidentified or aggregated information is allowed only if the information meets the applicable legal standard, is handled subject to required safeguards and is not reidentified contrary to law or the agreement.
Where California's CCPA applies to the service-provider or contractor processing, Evidize will not sell or share Customer Data; use, retain or disclose it for a commercial or other purpose outside the limited purposes specified here; use it outside the direct business relationship; or combine it with information from other customers, its own interactions or other sources, except as expressly permitted by the CCPA and its regulations. Evidize will comply with the applicable CCPA obligations and give that information the level of protection the CCPA requires. A permitted internal improvement or security use must still satisfy those restrictions. By entering into this agreement as a CCPA contractor, Evidize certifies that it understands and will comply with them.
4. Confidentiality, security and incidents
Evidize will require people authorized to process Customer Data to keep it confidential and limit their access to their assigned work. It will maintain reasonable administrative, technical and physical safeguards appropriate to the information and processing, including authorized access, separation of customer data, secure transfer, and protection against unauthorized use, disclosure, alteration or destruction. These are contractual obligations, not a statement that an independent certification or audit has been completed.
Evidize will notify Customer of a security breach involving Customer Data as required by the applicable law and within its applicable deadline, and provide the available information and assistance needed for Customer's corresponding duties. It will investigate, contain and remedy the incident as required. Customer remains responsible for notices it must send; this agreement does not assign their administration to Evidize. Each party will keep the other's designated security contact current.
5. Requests and required assistance
Customer will send Evidize the requests and lawful instructions requiring Evidize's action, together with enough information to identify the affected records and the applicable deadline. Evidize will provide the technical and organizational assistance required by the applicable provider law, considering the processing and information available to it. This includes applicable access, correction, deletion and other data-rights assistance. For a request received directly, Evidize will follow Customer's lawful instructions or explain the provider relationship and direct the person to the appropriate Customer contact, as the applicable law permits. Evidize will separately handle duties arising from its own covered processing or reports.
Where applicable law requires it, Evidize will supply information and cooperation for Customer's data protection assessments, cybersecurity audits and automated-decision obligations. For covered CCPA audits and risk assessments, this includes relevant information in Evidize's possession, custody or control without misrepresenting relevant facts. Confidential handling can protect legitimate secrets without withholding assistance the law requires.
Assistance uses existing support and secure information-sharing methods. Customer remains responsible for its job criteria, hiring decisions, required employer notices, lawful accommodations, audits and appeals. Evidize does not verify completion of those duties or operate an employer audit or appeal program under this agreement. Evidize remains responsible for duties attached to its own actual activities.
6. Suppliers and checking compliance
Evidize will engage a supplier that processes Customer Data on its behalf under a written agreement imposing the applicable processing restrictions and protections on that supplier. Where applicable law requires prior notice, an opportunity to object or authorization for a new supplier, Evidize will provide that process before the relevant processing begins. An independent recipient cannot be treated as a subprocessor merely by naming it one. Its separate use requires its own assessment, applicable third-party contract terms, disclosure and any required choice or permission; this agreement does not authorize that use by default. See the Supplier Data Requirements.
Where the applicable provider law requires it, Evidize will make available the information needed to demonstrate compliance and allow and cooperate with reasonable assessments. Where that law permits an independent assessor's report as an alternative, Evidize may use that route and supply the required report. Customer and its assessor must protect confidential information and other customers' data; these safeguards will not remove a statutory inspection or information right.
For CCPA-covered processing, Customer may take reasonable and appropriate steps to check that Evidize's use complies with Customer's CCPA obligations. Evidize will notify Customer if it determines it cannot meet its CCPA obligations. On notice, Customer may take reasonable and appropriate steps to stop and remedy unauthorized use, and Evidize will cooperate. An automatic annual independent audit is not imposed by this agreement.
These law-specific rights apply to the processing covered by that law. Iowa requires compliance information but does not add Virginia's reasonable-assessment clause; Utah's processor provision is narrower still. This agreement does not represent the broadest state's obligations as every state's legal minimum.
7. Retention, return and deletion
Evidize will follow the applicable law and Customer's agreed lawful retention and deletion instructions. It will not retain Customer Data simply because it might be useful later. Where the applicable provider law requires return or deletion at the end of services, Evidize will, at Customer's direction, return or delete the covered data unless law requires retention. Where no such rule applies, the order's agreed completion arrangements govern, subject to applicable privacy and security limits.
Any retained information must have a documented purpose and legal or contractual basis. Evidize will restrict it to that purpose, maintain its protections and delete it when the basis ends. A scoped legal hold preserves only the relevant records. It does not authorize indefinite retention of every applicant or device record.
Evidize will issue required instructions to its suppliers and track completion or a lawful limitation. Backup deletion may follow a documented, legally permitted replacement cycle; a backup exception is not an unlimited exemption. Restricted backup copies must not be used for ordinary processing, and restored data must have applicable deletion instructions reapplied. Exact supplier and backup schedules must be confirmed in the service arrangements before this draft is adopted; this page does not claim immediate erasure from every system.
8. Agreement records, changes and contacts
The signup agreement record or incorporating order must identify Customer's legal name, the service and selected processing, effective date and authorized representative. The service arrangements must also record the operational contacts and agreed retention or completion instructions. Evidize's business mailing address and monitored privacy email are TBC. These details and supplier terms remain to be verified; this version is a draft and has not been adopted for a customer by posting it.
For the processing it covers, this agreement controls conflicting general service terms, unless a separately agreed term gives greater protection or mandatory law requires otherwise. It does not waive protected individual rights, transfer responsibility imposed by law, replace reporting-company certifications where needed, or cancel earlier binding duties. A new version applies through a valid amendment or incorporation; informational email updates alone do not add processing permission or retroactively replace an accepted agreement.
Sources for the conditional contract duties: California Civil Code 1798.100; CCPA regulations 7050–7051; Iowa 715D.5; Utah 13-61-301; Virginia 59.1-579. The state guide describes other applicable U.S. requirements; it does not expand the selected services.