# Data Processing Agreement

**Between:**

- **Data Controller** ("Customer"): [Customer Legal Name]
- **Data Processor** ("Corvalon"): Corvalon, Inc.

**Effective Date:** [Date]

---

## 1. Definitions

- **Personal Data**: Any information relating to an identified or identifiable natural person processed by Corvalon on behalf of the Customer through the Corvalon HRM Platform.
- **Processing**: Any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, combination, erasure, or destruction.
- **Data Subject**: An identified or identifiable natural person whose Personal Data is processed.
- **Sub-processor**: A third party engaged by Corvalon to process Personal Data on behalf of the Customer.
- **Supervisory Authority**: An independent public authority established by an EU Member State pursuant to the GDPR, or equivalent regulatory body under applicable privacy law.

---

## 2. Purpose and Scope of Processing

### 2.1 Purpose

Corvalon processes Personal Data solely to provide the Corvalon HRM Platform services as described in the Master Services Agreement ("MSA"), including:

- Human resource management (employee records, organizational data)
- Payroll processing and tax compliance
- Benefits administration and enrollment
- Time and attendance tracking
- Talent acquisition and onboarding
- Performance management and learning
- Compliance reporting and analytics
- AI-powered features (with explicit tenant opt-in)

### 2.2 Nature of Processing

Automated and manual processing operations including: collection, storage, retrieval, encryption, pseudonymization, aggregation, analysis, transmission, erasure, and destruction.

### 2.3 Duration

Processing continues for the duration of the MSA plus the data retention period specified in Section 5, after which all Personal Data is deleted or returned per Section 10.

---

## 3. Categories of Data Subjects

- Employees (current and former)
- Job applicants and candidates
- Contractors and contingent workers
- Dependents and beneficiaries (benefits administration)
- Emergency contacts

---

## 4. Categories of Personal Data

| Category | Examples | Sensitivity |
|----------|----------|-------------|
| Identity | Name, date of birth, employee ID, photo | Standard |
| Contact | Email, phone, address | Standard |
| Employment | Title, department, hire date, status, manager | Standard |
| Financial | Bank account numbers, salary, tax withholdings | Sensitive (encrypted) |
| Government IDs | SSN, EIN, passport number, driver's license | Sensitive (encrypted) |
| Benefits | Plan enrollments, dependents, beneficiaries | Standard |
| Health | FMLA records, workers' comp claims, ADA accommodations | Special category |
| Performance | Reviews, goals, PIPs, calibration scores | Standard |
| Time | Timesheets, PTO balances, schedules | Standard |
| Recruiting | Resumes, interview notes, offer details, EEO data | Standard/Special category |

---

## 5. Data Retention

Corvalon retains Personal Data according to the following schedule, unless the Customer specifies a different retention period:

| Data Category | Retention Period | Basis |
|---------------|-----------------|-------|
| Active employee records | Duration of employment + 7 years | Legal/regulatory requirements |
| Terminated employee records | 7 years post-termination | Tax, benefits, and legal compliance |
| Applicant data (not hired) | 2 years post-application | EEO/OFCCP compliance |
| Payroll records | 7 years | IRS requirements |
| Benefits records | 7 years post-plan termination | ERISA requirements |
| Audit logs | 7 years | SOC 2 / regulatory compliance |
| Temporary processing data | 90 days | Operational necessity |

Customers may configure shorter retention periods within the platform. Data subject to legal holds is retained until the hold is released regardless of retention schedule.

---

## 6. Sub-processors

### 6.1 Authorization

The Customer provides general authorization for Corvalon to engage sub-processors listed in the current Sub-Processor List, available at [trust center URL] and updated with 30 days' prior notice.

### 6.2 Obligations

Corvalon imposes data protection obligations on each sub-processor that are no less protective than those in this DPA. Corvalon remains fully liable for the acts and omissions of its sub-processors.

### 6.3 Objection

If the Customer objects to a new sub-processor within 30 days of notification, Corvalon will work in good faith to provide an alternative. If no alternative is feasible, either party may terminate the affected services.

---

## 7. Security Measures

Corvalon implements the following technical and organizational measures:

### 7.1 Encryption

- **At rest:** AES-256 database encryption, Vault Transit field-level encryption for sensitive data (SSN, bank accounts, EIN, MFA secrets) with per-tenant key derivation
- **In transit:** TLS 1.2+ on all connections, HTTPS-only API and webhooks

### 7.2 Access Control

- 15-role RBAC with field-level security
- MFA enforcement for privileged roles (TOTP and WebAuthn)
- Argon2id password hashing with account lockout
- JWT tokens with 15-minute expiry

### 7.3 Tenant Isolation

- Schema-per-tenant database architecture (~303 tables per tenant)
- PostgreSQL Row-Level Security as defense-in-depth
- Per-tenant encryption key derivation

### 7.4 Monitoring

- Append-only audit trail (7-year retention)
- Bi-temporal versioning on all mutable data
- OpenTelemetry distributed tracing
- Continuous vulnerability scanning (DAST, SAST, dependency audit)

### 7.5 Personnel

- Background checks for personnel with data access
- Annual security awareness training
- Least-privilege access to production systems

---

## 8. Data Subject Rights

Corvalon provides the Customer with tools to fulfill data subject requests:

- **Access:** Data export in machine-readable format (JSON, CSV)
- **Rectification:** Self-service profile editing and administrative correction
- **Erasure:** Automated right-to-be-forgotten processing with legal hold checks
- **Portability:** Structured data export
- **Restriction:** Processing suspension capability
- **Objection:** Opt-out of automated decision-making and AI features

Corvalon will promptly notify the Customer of any data subject request received directly and will not respond independently unless legally required.

---

## 9. Breach Notification

### 9.1 Notification Timeline

Corvalon will notify the Customer of a confirmed Personal Data breach without undue delay and no later than 48 hours after becoming aware of the breach.

### 9.2 Notification Content

Notification will include:

- Nature of the breach (categories and approximate number of data subjects affected)
- Contact details of Corvalon's data protection point of contact
- Likely consequences of the breach
- Measures taken or proposed to address and mitigate the breach

### 9.3 Cooperation

Corvalon will cooperate with the Customer to fulfill any regulatory notification obligations, including providing information required for the Customer's notification to supervisory authorities and affected data subjects.

---

## 10. Data Return and Deletion

Upon termination of the MSA:

1. **Data export:** Customer may export all Personal Data in machine-readable format within 30 days of termination
2. **Deletion:** Corvalon will delete all Personal Data within 90 days of termination (or export, whichever is later), except where retention is required by law
3. **Certification:** Corvalon will provide written certification of deletion upon request
4. **Backup purge:** Personal Data in backups will be deleted as backup copies expire per the retention schedule (maximum 30 days)

---

## 11. Cross-Border Data Transfers

### 11.1 Data Location

Customer data is processed and stored in Corvalon's AWS US East (N. Virginia) region; production backup copies are replicated to US West (Oregon). Additional regions, including EU residency, are on the roadmap and not yet available.

### 11.2 Transfer Mechanisms

For transfers of Personal Data outside the European Economic Area, Corvalon relies on:

- **Standard Contractual Clauses (SCCs):** EU Commission-approved Module 2 (Controller to Processor) clauses, incorporated by reference
- **Supplementary measures:** Encryption in transit and at rest, access controls, contractual commitments

### 11.3 Government Access

Corvalon will promptly notify the Customer of any government request for access to Personal Data, unless legally prohibited. Corvalon will challenge any request that is overly broad or legally deficient.

---

## 12. Audit Rights

### 12.1 Audit Information

Corvalon will make available to the Customer all information necessary to demonstrate compliance with this DPA, including security documentation, audit-readiness controls mappings, and, once completed, SOC 2 reports and penetration test summaries.

### 12.2 On-Site Audits

The Customer may conduct or commission an audit of Corvalon's data processing activities, subject to reasonable advance notice (30 days), scope limitation, and confidentiality obligations. Audits are limited to once per year unless a breach has occurred.

### 12.3 SOC 2 Reports

Corvalon has not yet undergone a SOC 2 examination; a Type I examination is planned on the launch roadmap, with Type II to follow after an observation period. Once issued, SOC 2 reports will be available under NDA and may satisfy audit requirements. Until then, Corvalon's SOC 2 controls mapping (audit-readiness documentation) is available on request.

---

## 13. Liability

Corvalon's liability under this DPA is subject to the limitations set forth in the MSA. Nothing in this DPA limits liability for intentional breaches of data protection obligations.

---

## 14. Term and Termination

This DPA is effective as of the Effective Date and continues for the duration of the MSA. Upon termination of the MSA, Sections 5, 9, 10, and 12 survive.

---

## Signatures

| | Data Controller (Customer) | Data Processor (Corvalon) |
|---|---|---|
| **Name** | _________________________ | _________________________ |
| **Title** | _________________________ | _________________________ |
| **Date** | _________________________ | _________________________ |
| **Signature** | _________________________ | _________________________ |
