Review copy. Publication details are being completed. This copy is not available for contractual acceptance.
Version 2026-09-14.2 · Permanent link to this version · U.S. legal documents
Version history
- Version 2026-09-14.2 — Prepared 2026-09-14 · Draft — not published
- Version 2026-09-14.1 — Prepared 2026-09-14 · Draft — not published
- Version 2026-09-13.1 — Prepared 2026-09-13 · Draft — not published
1. When these terms bind a supplier
This Supplier Data Addendum is between Evidize LLC ("Evidize") and the supplier identified in a purchase order or service agreement that expressly incorporates this version ("Supplier"). It covers personal information Supplier processes for Evidize under that identified service ("Service Data"), including Customer Data entrusted to Evidize. It becomes binding only through the parties' valid agreement. This draft has not been accepted by Microsoft, Azure or any other supplier merely because it is published or linked.
The incorporating agreement must identify the actual supplier legal entity, account or order, covered products, effective date and authorized representatives. A verified existing supplier agreement and data addendum may supply the required protections instead; this text need not be imposed as a second agreement if the accepted terms already meet the applicable requirements.
Evidize appoints and manages its own suppliers. A hiring organization manages providers it appoints. An independent recipient's own-purpose processing needs its own legal classification, applicable contract terms, disclosure and any required choice or permission; this addendum cannot make that activity processing on Evidize's behalf by changing its name. This addendum governs the processor service identified in the order, not an independently controlled purpose that has not been covered by an appropriate separate arrangement.
2. The authorized service and instructions
Supplier will follow Evidize's lawful written instructions for the product and service identified in the incorporating order. The order must select the relevant row below, specify the actual product and assigned task, and identify any narrower data scope. Supplier receives only the information needed for that task. The supplier service does not include every Evidize function by default.
| Service to identify in the order | Permitted purpose and information, if selected |
|---|---|
| Hosting, database or storage | Host, store, retrieve and protect the assigned application records, uploaded files, service configuration, authorized outputs and logs, and perform the identified backup and restoration service. Identify the data stores and the supplier's permitted support access. |
| AI processing | Process the specifically supplied résumé text, application evidence, job criteria or permitted security evidence and return the requested extraction, analysis or summary for the applicable hiring or security function. Identify the model/service, deployment type, input and output storage, abuse-review access and any training or evaluation use. |
| Identity, calendar or email | Authenticate authorized users, exchange selected scheduling information, or deliver the identified operational messages. Process only the relevant identifiers, recipient details, selected calendar fields, message content and delivery records for the enabled service. |
| Network protection or support | Protect the identified website or service, validate authorized anti-abuse checks, or investigate a specified service issue using relevant connection, request, event and diagnostic information. Describe any content inspection; a label such as "metadata" does not remove personal-information obligations. |
The people concerned are applicants, interview participants, hiring users, customer contacts and website users, to the extent their information is needed for the selected service. The order must identify any sensitive information that actually reaches Supplier. Its schedule must also identify the processing duration or determining criteria, processing and support locations, relevant subcontractors, and the return, deletion and backup arrangements. These facts remain unverified in this draft; it makes no U.S.-only storage or fixed-deletion-period promise.
The service runs for the identified order and its lawful completion or preservation period. Supplier may not expand its purpose, collected fields, location commitments or onward use through an unrelated product term or unilateral privacy notice where this would conflict with the parties' binding agreement or applicable law.
3. Purpose, reuse and confidentiality
Supplier will process Service Data only to perform the specified services on Evidize's lawful instructions or as law permits consistently with its role and the agreement. Supplier will require authorized personnel to maintain confidentiality and limit access to what their work needs.
This addendum does not authorize using identifiable Service Data to train a general model, advertise to individuals, or build profiles for unrelated customers. Any proposed additional training or reuse must be specifically described and separately agreed before it begins, and must satisfy the applicable law, customer commitments and individual rights. A broad supplier improvement clause is not treated as that approval.
Supplier may use the minimum relevant data to diagnose an issue, validate a repair or check performance of the identified service if that activity falls within the agreed purpose and applicable legal limits. It must restrict access and retention to that task. Deidentified or aggregated use requires the applicable legal standard and safeguards; removing a name alone is not enough. Supplier must not reidentify such information contrary to law or the agreement.
For covered CCPA service-provider or contractor processing, Evidize discloses Service Data only for the limited purposes specified in section 2 and the incorporating order. Supplier will not sell or share that information; use, retain or disclose it for a commercial or other purpose outside those purposes; use it outside the direct business relationship; or combine it with information from other customers, its own interactions or other sources, except as expressly allowed by the CCPA and its regulations. Supplier will comply with the applicable CCPA duties and provide the level of privacy protection the CCPA requires. If Supplier is a CCPA contractor, its acceptance certifies that it understands and will comply with these restrictions.
4. Protection and incident handling
Supplier will maintain reasonable administrative, technical and physical safeguards appropriate to Service Data, the assigned service and applicable law. It will protect against unauthorized access, use, disclosure, alteration or destruction and maintain the access, transfer and storage safeguards agreed for that service.
Supplier will notify Evidize of a breach involving Service Data as required by the applicable law and within its required deadline, and provide the available information and cooperation required for Evidize's or its customer's corresponding duties. Supplier will investigate, contain and remedy the incident as required. The parties will identify current incident contacts in the order. No completed security audit, certification or tested control is represented by this draft.
5. Assistance and further suppliers
Evidize will provide Supplier with the applicable data-rights request or lawful instruction, information needed to locate the affected data, and the known response deadline. Supplier will carry out the assistance and technical steps required by the applicable provider law, taking account of the service and information available to it. This includes applicable access, correction, deletion, security and breach-response assistance. A supplier response does not automatically complete Evidize's corresponding request.
Where applicable law requires it, Supplier will provide necessary information and cooperation for data protection assessments, cybersecurity audits and automated-decision duties. For CCPA-covered processing this includes relevant information in Supplier's possession, custody or control, without misrepresenting relevant facts. This is assistance with the supplier service; it does not transfer an employer's hiring appeals, audits or notice administration to Supplier or Evidize.
Before allowing another processor or subcontractor to process Service Data, Supplier will bind it in writing to the restrictions and protections required by applicable law for that processing. Supplier will meet any legally required advance notice, objection or authorization procedure. Each processing tier must preserve the applicable purpose, confidentiality, security and request-assistance duties. Supplier remains responsible for the duties imposed on it by its role and applicable law.
6. Checking compliance and fixing problems
Where the applicable provider law requires it, Supplier will supply information necessary to demonstrate compliance and allow and cooperate with reasonable assessments. It may use an independent assessor's report as an alternative only where the governing law allows that route, and must provide the required report. Confidential handling and protection of other customers' information must not defeat a legally required information or assessment right.
For CCPA-covered processing, Evidize may take reasonable and appropriate steps to check that Supplier's processing meets the applicable obligations. Supplier will notify Evidize if it determines it cannot comply with its CCPA obligations. On notice, Evidize may take reasonable and appropriate steps to stop and remedy unauthorized use, and Supplier will cooperate, including supplying evidence of the remedy where required.
Law-specific requirements apply only where that law covers the processing. Iowa requires compliance information and specified supplier terms but does not impose Virginia's assessment provision. Utah's processor-contract requirements do not themselves impose Iowa's end-of-service return or deletion clause. Another applicable law or the accepted order may require those protections. This addendum does not create a universal annual audit requirement.
7. Completion, retention and deletion
Supplier will follow the lawful retention and deletion instructions applicable to its service. Where the governing provider law requires it, Supplier will, at Evidize's direction, return or delete Service Data when the services end unless law requires retention. Other completion arrangements follow the accepted order and applicable law.
For any retained data, Supplier will identify the category, basis and applicable end event, keep the information protected, and restrict its use to the permitted retention purpose. It will remove information when that basis ends and pass required deletion or correction instructions to its own processors. Any legally permitted backup delay must have a documented deletion or replacement cycle; restored copies must have applicable deletion instructions reapplied. Supplier will provide legally required completion information and explain any lawful limitation.
8. Information from a covered AI developer
If Supplier is a covered developer for the identified technology, it will supply the product, use, limitation, update and protected-information explanations required by the applicable developer law when due. This clause does not turn every host or model service into a covered hiring-technology developer. Evidize's separate developer duties remain its own.
For covered Colorado developer activity from January 1, 2027, this includes required product information, direct material-update notices and developer records kept for at least three years from creation. For qualifying Connecticut deployments on or after October 1, 2027, it includes the required information for deployer disclosures and applicable explanations of protected information withheld. The Colorado retention period does not become a Connecticut requirement. See Colorado's law, Connecticut's law and the shared provider-information format.
9. Contract record and status
The executed order must establish which terms control a conflict; mandatory legal protections cannot be removed through that priority clause. A new draft or website version does not replace an earlier accepted agreement. Any change requiring agreement or individual permission must use the appropriate process. Routine informational updates need no additional acceptance unless law or the binding agreement requires it.
Evidize's business mailing address and monitored privacy email are TBC. The supplier's legal identity, order, designated contacts, processing schedule and acceptance evidence must be completed in the actual contract record. An accepted Microsoft Customer Agreement for the inspected Azure account was verified, including its incorporated Data Protection Addendum and Product Terms. Evidize LLC’s exact contracting identity for that account, covered service orders and any separate Microsoft 365 or reseller arrangements still need confirmation. This does not mean Microsoft accepted this addendum or that other suppliers are covered.
Related documents: Customer Data Agreement and Privacy Notice. Contract sources: California 1798.100, CCPA regulations 7050–7051, Iowa 715D.5, Utah 13-61-301 and Virginia 59.1-579.