This Data Processing Addendum ("DPA") forms part of the applicable agreement between Bash AI Inc., a Delaware corporation with its principal business office at 7688 Saint Patrick Way, Dublin, California 94568 ("Bash"), and the Customer for use of the Services. This DPA applies only to Bash's processing of Customer Personal Data on behalf of the Customer.
1. Definitions
Capitalized terms not defined in this DPA have the meanings given in the agreement, the Privacy Policy, or applicable Data Protection Laws. For purposes of this DPA:
Applicable Data Protection Laws means all data protection, privacy, biometric, recording, electronic communications, consumer privacy, AI-in-hiring, and security laws applicable to Bash's processing of Customer Personal Data under the agreement, including, where applicable, the CCPA/CPRA, other U.S. state privacy laws, the EU GDPR, UK GDPR, Swiss data protection law, Brazil's LGPD, Canada's privacy laws, Singapore's PDPA, India's Digital Personal Data Protection Act, and similar laws.
Customer Personal Data means personal information or personal data contained in Customer Data, including Candidate Data, that Bash processes on behalf of the Customer through the Services. Customer Personal Data excludes Usage Data, Staff User account administration data processed by Bash for its own business purposes, website visitor data, business contact data, and information Bash processes as an independent business or controller.
Customer Instructions means the agreement, this DPA, the Customer's configuration and use of the Services, written instructions submitted through authorized support or administrative channels, and any lawful instructions agreed by the parties in writing.
Sub-processor means a third party engaged by Bash to process Customer Personal Data to provide, secure, support, or improve the Services, including hosting, storage, AI model, transcription, identity-verification, communications, analytics, security, support, and code-execution providers.
2. Parties, roles, and scope
For Customer Personal Data processed in connection with the Customer's hiring process, the Customer determines the purposes and means of processing and acts as the business, controller, or equivalent role. Bash acts as the service provider, processor, or equivalent role and will process Customer Personal Data only as permitted by this DPA and the Customer Instructions. The Customer remains responsible for candidate notices, lawful basis, consents, employment-law compliance, accessibility accommodations, anti-discrimination obligations, recording notices, biometric notices and consents, AI-in-hiring notices and audits, human review, appeal rights, and all decisions made using the Services. Bash is not responsible for the Customer's hiring decisions or for the Customer's failure to configure or use the Services lawfully.
3. Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of Bash's hiring-intelligence Platform and related implementation, support, and professional services. |
| Duration | The term of the agreement, plus any limited retention, export, backup, legal-hold, audit, security, dispute-resolution, or deletion period permitted by this DPA, the agreement, or applicable law. |
| Nature and purpose | Hosting, storage, transmission, retrieval, structuring, parsing, transcription, AI-assisted analysis, reporting, assessment administration, integrity monitoring, identity verification, customer support, troubleshooting, security monitoring, deletion, and other processing necessary to provide the Services configured by the Customer. |
| Data subjects | Candidates, Verified Candidates, Staff Users included in hiring records, Third-Party Participants, interview or meeting participants, assessment collaborators, report recipients, and other individuals whose personal information is submitted to or processed through the Services by or for the Customer. |
| Categories of personal information | Identifiers; professional and employment information; resumes and application materials; recruiter notes; interview evaluations; recordings and transcripts; assessment work product; Advocacy conversations; AI-generated summaries, scores, reports, evidence packs, and integrity indicators; session logs; device, browser, and security signals; and, where enabled by the Customer and consented to as required, biometric verification data and location or device-intelligence signals. |
| Sensitive processing | Only where enabled by the Customer or required to provide the configured Services: biometric verification selfie and verification result, precise or city-level location signals, recording and transcript data, and other sensitive personal information disclosed in the Privacy Policy. Bash does not store raw government ID images, date of birth, gender, or nationality from identity documents. |
4. Bash's processing obligations and certifications
Bash will process Customer Personal Data only to provide, secure, support, maintain, troubleshoot, improve, and protect the Services as configured by the Customer, and only in accordance with Customer Instructions. Bash will promptly inform the Customer if, in Bash's reasonable opinion, an instruction violates applicable law, unless prohibited by law from doing so.
- not sell Customer Personal Data or share it for cross-context behavioral advertising;
- not retain, use, or disclose Customer Personal Data for any purpose other than the specific business purposes described in this DPA, the agreement, the Customer Instructions, or as otherwise permitted by applicable law;
- not retain, use, or disclose Customer Personal Data outside the direct business relationship between Bash and the Customer, except as permitted by applicable law;
- not combine Customer Personal Data with personal information received from another customer or source, except to detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, provide the Services, maintain or improve service integrity, or as otherwise permitted by applicable law;
- not use Customer Personal Data or Candidate Data to train generalized AI models shared across customers unless the Customer expressly agrees in writing and the use is permitted by applicable law;
- require personnel authorized to process Customer Personal Data to be bound by confidentiality obligations and to access Customer Personal Data only as needed for their role;
- provide the same level of privacy protection required by applicable Data Protection Laws for Bash's role as service provider, processor, or equivalent role;
- notify the Customer if Bash determines it can no longer meet its obligations under applicable Data Protection Laws and allow the Customer to take reasonable and appropriate steps to stop and remediate unauthorized processing; and
- reasonably assist the Customer with privacy-rights requests, security obligations, breach response, DPIAs, transfer assessments, regulatory inquiries, and other compliance obligations, taking into account the nature of the processing and information available to Bash.
5. Customer responsibilities
The Customer is solely responsible for determining whether and how to use the Services in its hiring process. The Customer will provide all required notices, obtain all required consents or authorizations, establish a lawful basis for processing, respond to candidate and employee requests where it is the controller or business, configure retention and access settings appropriately, avoid submitting unnecessary sensitive or protected-category information, and ensure that any use of AI outputs, assessment monitoring, recordings, identity verification, geolocation, device checks, or biometric processing complies with applicable law. The Customer will not instruct Bash to process Customer Personal Data in a manner that violates applicable law.
6. Security and incident notice
Bash will maintain reasonable technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including measures appropriate to the nature, scope, context, and purpose of processing. These measures may include encryption in transit, access controls, role-based permissions, secure authentication practices, tenant separation, time-limited access links, logging and monitoring, safeguards for assessment and verification workflows, secure development practices, vendor review, and incident-response procedures. Bash may update its security measures from time to time, provided it does not materially reduce the overall level of protection for Customer Personal Data. Bash will notify the Customer without undue delay and, where feasible, within 72 hours after confirming a security incident affecting Customer Personal Data, unless legally prohibited. Bash will provide information reasonably available to assist the Customer with investigation, mitigation, and legally required notifications. The Customer controls notices to candidates, employees, regulators, and other third parties, unless applicable law requires Bash to notify directly.
7. Sub-processors
The Customer grants Bash general authorization to engage Sub-processors necessary to provide, secure, support, maintain, and improve the Services. Bash will maintain a current list of Sub-processors and will require each Sub-processor that processes Customer Personal Data to be bound by written obligations that are materially protective and no less protective, in substance, than the obligations imposed on Bash under this DPA. Bash remains responsible for each Sub-processor's processing of Customer Personal Data to the extent required by applicable law. Bash will provide advance notice of any new or replacement Sub-processor through a reasonable method, such as a public sub-processor page, email notice, or in-product notice. The Customer may object on reasonable data-protection grounds within 30 days after notice. If the parties cannot resolve the objection, the Customer's sole remedy is to stop using the affected Service or terminate the impacted Order Form, subject to the agreement.
8. Privacy-rights requests and cooperation
Taking into account the nature of the processing and information available to Bash, Bash will reasonably assist the Customer in responding to verifiable privacy-rights requests relating to Customer Personal Data, including access, correction, deletion, portability, restriction, objection, opt-out, appeal, and consent-withdrawal requests where applicable. If Bash receives a request directly from an individual relating to Customer Personal Data, Bash may respond directly where legally required or may refer the requester to the Customer. Bash may require reasonable verification before acting on any request and will not disclose Customer Personal Data to a requester unless authorized by the Customer or required by law.
9. Retention, deletion, and return
Bash will retain Customer Personal Data only for as long as reasonably necessary to provide and secure the Services, support the Customer's hiring process, comply with law, resolve disputes, enforce agreements, maintain audit and security records, and exercise or defend legal claims. Upon termination or expiration of the applicable agreement, Bash will delete or de-identify Customer Personal Data in accordance with its then-current retention procedures and the Customer Instructions, unless retention is required or permitted by law. Bash may retain limited backup, audit-log, security, financial, legal, and consent records for the applicable retention period, provided such information remains protected and is not used for any unrelated purpose.
10. Audits and verification
Upon the Customer's reasonable written request, Bash will provide information reasonably necessary to demonstrate Bash's compliance with this DPA, ordinarily through Bash's then-current standard security and privacy documentation, relevant certifications, independent audit reports, penetration-test executive summaries, Sub-processor information, or completed standard security questionnaires, in each case to the extent available and subject to confidentiality obligations and reasonable redaction. Such materials will be deemed sufficient to satisfy the Customer's audit and verification rights unless applicable Data Protection Laws expressly require further verification and the materials provided are reasonably insufficient for that purpose. Any further audit must be requested by the Customer at least 30 days in advance through written notice specifying the legal basis, proposed scope, requested documents, auditor details, and proposed dates. Any such audit must be limited to the processing of Customer Personal Data under this DPA, be conducted no more than once in any 12-month period unless required by applicable law or following a confirmed Security Incident materially affecting the Customer's Personal Data, occur during Bash's normal business hours, and be performed by an independent, reputable, non-competing auditor bound by written confidentiality obligations. No audit may include penetration testing, vulnerability scanning, source-code review, access to production systems, disruption of Bash's operations, or access to information relating to other customers, Bash's trade secrets, legally privileged material, or information whose disclosure could reasonably create a security risk. Bash may determine the reasonable manner, timing, scope, and location of the audit and may require the parties and the auditor to enter into additional confidentiality and security terms. The Customer will bear all costs of any audit and Bash may charge reasonable fees for assistance beyond its standard compliance materials, unless prohibited by applicable law. Nothing in this Section requires Bash to disclose information where disclosure would violate applicable law, contractual confidentiality obligations, or the rights of another person.
11. International transfers
Bash is headquartered in the United States and may process Customer Personal Data in the United States and other countries where Bash or its Sub-processors operate. Where Customer Personal Data subject to the EU GDPR, UK GDPR, Swiss data protection law, or similar cross-border transfer restrictions is transferred to a country that does not provide an adequate level of protection, the parties will use an appropriate transfer mechanism, which may include the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, the Swiss addendum or adaptations, supplementary safeguards, transfer impact assessments, or another lawful mechanism. For transfers from the EEA where the Customer is the controller and Bash is the processor, Module Two of the EU Standard Contractual Clauses will apply to the extent required. For approved onward transfers to Sub-processors, Bash will ensure appropriate onward-transfer safeguards consistent with applicable law.
12. AI, assessment monitoring, biometric verification, and recordings
Bash provides AI-assisted evidence, summaries, interview intelligence, assessment reports, integrity indicators, and workflow tools to support the Customer's human reviewers. Bash does not intend the Services to automatically reject, select, rank out, or disqualify a Candidate without human review. The Customer is responsible for deciding whether AI, assessment monitoring, recording, transcription, biometric verification, geolocation, device checks, or similar features are lawful for the relevant role, jurisdiction, and hiring context. Where required, the Customer must provide notices, obtain express written consent, offer reasonable accommodations, maintain human review, conduct impact assessments or bias audits, preserve required records, and provide contestability or appeal rights. Bash will not use biometric information for automated hiring decisions, surveillance, sale, lease, trade, or unrelated purposes.
13. Confidentiality and compelled disclosure
Bash will protect Customer Personal Data as confidential information and will not disclose it except as permitted by the agreement, this DPA, Customer Instructions, or applicable law. If Bash is legally required to disclose Customer Personal Data, Bash will, unless legally prohibited, provide reasonable notice to the Customer and reasonably cooperate with efforts to limit or challenge the disclosure.
14. Order of precedence, liability, and survival
If this DPA conflicts with the agreement, this DPA controls only the processing of Customer Personal Data. All liability, disclaimers, exclusions, and limitations in the agreement apply to this DPA unless prohibited by applicable law. The obligations that by their nature should survive termination, including confidentiality, security, deletion, audit cooperation, transfer safeguards, and restrictions on use and disclosure of Customer Personal Data, will survive for as long as Bash processes or retains Customer Personal Data.