Data Processing Agreement
Last updated: December 20, 2024
Request a Signed DPA
For Enterprise customers requiring a countersigned Data Processing Agreement
GDPR Compliant
EU Data Protection
CCPA Compliant
California Privacy
SOC 2 Type II
Type II Ready
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between TalentCafe ("Data Processor", "we", "us") and the Customer ("Data Controller", "you") for the use of TalentCafe's coaching platform services.
This DPA reflects our commitment to protect personal data in accordance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
2. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person.
"Processing" means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.
"Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
"Sub-processor" means any third party engaged by TalentCafe to process Personal Data on behalf of the Customer.
"Security Incident" means any unauthorized access, acquisition, use, or disclosure of Personal Data.
3. Scope of Processing
TalentCafe processes Personal Data solely for the purpose of providing the coaching platform services as described in the Terms of Service. The categories of Personal Data processed include:
• Identity Data: Names, email addresses, profile information
• Session Data: Coaching session recordings, notes, and transcripts
• Communication Data: Messages between coaches and clients
• Usage Data: Platform interaction logs and analytics
• Payment Data: Billing information (processed via Stripe)
The duration of processing continues for the term of the agreement plus any legally required retention period.
4. Processor Obligations
TalentCafe agrees to:
4.1 Process Personal Data only on documented instructions from the Customer, unless required by applicable law.
4.2 Ensure personnel are bound by confidentiality obligations and receive appropriate training on data protection.
4.3 Implement appropriate technical and organizational measures to ensure security of Personal Data, including:
- AES-256 encryption at rest and TLS 1.3 in transit
- Multi-factor authentication
- Role-based access controls
- Regular security audits and penetration testing
- SOC 2 Type II Ready (technical audits completed)
4.4 Notify the Customer of any Security Incident without undue delay and no later than 72 hours after becoming aware.
4.5 Assist the Customer in responding to Data Subject requests and regulatory inquiries.
4.6 Delete or return Personal Data upon termination of the agreement, unless retention is required by law.
5. Sub-processors
TalentCafe engages the following sub-processors:
• Supabase - Database & Authentication (United States)
• Stripe - Payment Processing (United States)
• Google Cloud Platform - Infrastructure (Global)
• Stream - Video Conferencing (United States)
• Resend - Email Delivery (United States)
The Customer authorizes TalentCafe to engage additional sub-processors, provided that:
- TalentCafe maintains an up-to-date list of sub-processors
- TalentCafe notifies the Customer of new sub-processors at least 30 days in advance
- Each sub-processor is bound by data protection obligations no less protective than this DPA
6. International Data Transfers
When Personal Data is transferred outside the European Economic Area (EEA), TalentCafe ensures appropriate safeguards are in place, including:
• Standard Contractual Clauses (SCCs) approved by the European Commission
• Supplementary measures as recommended by the EDPB, including encryption and access controls
• Data residency options for Enterprise customers requiring data to remain within specific regions
For transfers to the United States, TalentCafe relies on SCCs with supplementary measures.
7. Data Subject Rights
TalentCafe assists the Customer in fulfilling Data Subject requests, including:
• Right of Access: Data Subjects may request a copy of their Personal Data
• Right to Rectification: Data Subjects may request correction of inaccurate data
• Right to Erasure: Data Subjects may request deletion of their data
• Right to Data Portability: Data Subjects may request their data in a machine-readable format
• Right to Object: Data Subjects may object to processing based on legitimate interests
• Right to Restrict Processing: Data Subjects may request limitation of processing
Requests are processed within 30 days.
8. Audits and Compliance
TalentCafe provides the Customer with:
• SOC 2 Type II audit reports (upon request and under NDA)
• Security questionnaire responses using standard formats (SIG, CAIQ)
• Penetration testing summaries conducted by independent third parties
• On-site audit rights for Enterprise customers (with reasonable notice)
TalentCafe is GDPR and CCPA compliant, SOC 2 Type II Ready, and is pursuing ISO 27001 certification.
9. Term and Termination
This DPA remains in effect for the duration of the Terms of Service.
Upon termination:
- TalentCafe will delete all Personal Data within 30 days, unless retention is required by law
- Customer may request a copy of their data in a standard format before deletion
- TalentCafe will provide written confirmation of deletion upon request
Provisions regarding confidentiality, liability, and audit rights survive termination.