Data Processing Agreement
This Data Processing Agreement outlines how HubNest HRM processes personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Data Controller
The organization or entity that subscribes to HubNest HRM services and determines the purposes and means of processing employee personal data.
Data Processor
HubNest HRM (operated by SRJ Global Tech), which processes personal data on behalf of the Controller in accordance with this agreement.
Definitions
- 1.1
"Controller" means the entity that determines the purposes and means of the processing of Personal Data.
- 1.2
"Processor" means the entity that processes Personal Data on behalf of the Controller.
- 1.3
"Personal Data" means any information relating to an identified or identifiable natural person.
- 1.4
"Processing" means any operation performed on Personal Data, whether or not by automated means.
- 1.5
"Data Subject" means the identified or identifiable natural person to whom the Personal Data relates.
- 1.6
"Sub-processor" means any third party appointed by the Processor to process Personal Data on behalf of the Controller.
Scope of Processing
- 2.1
HubNest HRM processes Personal Data solely for the purpose of providing the HR management services as described in the main service agreement.
- 2.2
The categories of data processed include: employee names, contact information, employment records, attendance data, payroll information, and performance metrics.
- 2.3
Processing activities include collection, storage, organization, retrieval, consultation, use, disclosure by transmission, and erasure of Personal Data.
- 2.4
The duration of processing shall be for the term of the service agreement unless otherwise required by applicable law.
Data Subject Rights
- 3.1
We assist the Controller in fulfilling its obligations to respond to Data Subject requests, including the right of access, rectification, erasure, restriction, portability, and objection.
- 3.2
Upon receiving a request from a Data Subject, HubNest will promptly notify the Controller and provide reasonable assistance in responding to such requests.
- 3.3
HubNest provides built-in tools for Controllers to manage Data Subject access requests efficiently through the platform's admin dashboard.
- 3.4
All Data Subject requests are logged and tracked to ensure timely compliance within the legally mandated timeframes.
Security Measures
- 4.1
Encryption of Personal Data in transit (TLS 1.3) and at rest (AES-256) across all systems and databases.
- 4.2
Strict access controls with role-based permissions, multi-factor authentication, and principle of least privilege enforcement.
- 4.3
Regular security audits, penetration testing, and vulnerability assessments conducted by independent third-party firms.
- 4.4
Comprehensive incident response plan with documented procedures for detection, containment, eradication, and recovery.
- 4.5
Employee security awareness training programs conducted quarterly for all personnel with access to Personal Data.
Sub-processors
- 5.1
HubNest maintains a list of approved sub-processors, which is available upon request and updated regularly.
- 5.2
Prior written consent from the Controller is required before engaging any new sub-processor for the processing of Personal Data.
- 5.3
All sub-processors are bound by data protection obligations no less protective than those set forth in this Agreement.
- 5.4
HubNest remains fully liable for the acts and omissions of its sub-processors in relation to the processing of Personal Data.
Data Transfers
- 6.1
Personal Data may be transferred to countries outside the European Economic Area (EEA) only when adequate safeguards are in place.
- 6.2
Transfers are conducted under Standard Contractual Clauses (SCCs) approved by the European Commission, or other approved transfer mechanisms.
- 6.3
HubNest ensures that any country receiving Personal Data provides an adequate level of data protection as determined by applicable regulations.
- 6.4
Data residency options are available for Controllers who require Personal Data to remain within specific geographic regions.
Breach Notification
- 7.1
In the event of a Personal Data breach, HubNest will notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach.
- 7.2
Notification will include: the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken to address the breach.
- 7.3
HubNest will cooperate fully with the Controller and supervisory authorities in investigating and remediating any breach.
- 7.4
A detailed post-incident report will be provided within 30 days of breach resolution, including root cause analysis and preventive measures.
Termination
- 8.1
Upon termination of the service agreement, HubNest will, at the Controller's choice, return or securely delete all Personal Data within 90 days.
- 8.2
A certification of deletion will be provided upon request, confirming that all Personal Data has been permanently and irreversibly destroyed.
- 8.3
Obligations regarding confidentiality and data protection shall survive the termination of this Agreement.
- 8.4
HubNest may retain Personal Data where required by applicable law, provided that such retention is limited to the minimum extent necessary.
Questions About This Agreement?
If you have any questions regarding this Data Processing Agreement or need to request a signed copy, please contact our Data Protection Officer.