Application and priority
This Data Processing Addendum (“DPA”) forms part of an accepted agreement between GERMANN INC, a California corporation doing business as LIVEWORK (“LIVEWORK”), and the client identified in the applicable Search Order (“Client”). It applies to personal information Client provides, or directs LIVEWORK to collect, solely for processing on Client’s behalf (“Client Data”). The DPA takes effect with the accepted agreement and controls any conflicting provision concerning that processing.
For Client Data, Client determines the processing purposes and acts as the business or controller, and LIVEWORK acts as a service provider, contractor, or processor, as applicable under relevant privacy law. A contractual label does not override the parties’ actual activities. Information LIVEWORK independently sources and controls for its own recruiting services falls outside this processor relationship and is governed by the Privacy Policy and applicable Engagement Terms.
Processing details and instructions
The subject matter is Client’s applicant and search administration. The duration is the engagement plus the permitted return, deletion, and retention period. Processing consists of collecting on instruction, storing, organizing, retrieving, searching, formatting, transmitting to authorized recipients, and deleting Client Data to administer the agreed recruiting workflow. It includes applicant records, pipeline status, resume preparation, interview coordination, and client service communications.
Individuals include Client’s applicants, candidate references, and authorized business contacts. Information may include contact details, resumes, professional and educational history, skills, availability, compensation expectations, interview notes, feedback, and relevant communications. Sensitive information is excluded unless specifically necessary, lawful, and documented in the Search Order with additional safeguards.
The agreement, completed processing schedules, authorized portal actions, and lawful written directions constitute Client’s instructions. LIVEWORK will process Client Data only on those instructions, except where applicable law requires otherwise. If legally permitted, LIVEWORK will notify Client before legally compelled processing. LIVEWORK will promptly inform Client of an instruction it reasonably believes unlawful and may suspend the affected activity pending resolution.
Restricted use and required protections
LIVEWORK will not sell Client Data or share it for cross-context behavioral advertising. It will not retain, use, or disclose Client Data for a commercial purpose other than the specifically described services or outside the direct business relationship, except as applicable law permits. It will not combine Client Data with information from other clients or its independent recruiting database except as expressly permitted by applicable law and consistent with documented instructions.
LIVEWORK will comply with applicable privacy obligations, provide the protection required by the CCPA where applicable, and notify Client promptly if it determines it can no longer meet its obligations. LIVEWORK certifies that it understands and will comply with these restrictions. Client may take reasonable and appropriate steps to stop and remediate unauthorized use.
Client Data will not be used to train or improve a general-purpose or third-party AI model, create a cross-client talent pool, or support independent advertising. Any AI-assisted processing must be limited to the documented services through an authorized subprocessor, with appropriate retention and model-training restrictions. LIVEWORK will preserve required segregation between client accounts.
Personnel and safeguards
LIVEWORK will limit access to personnel with a business need who are bound by confidentiality obligations and receive appropriate privacy and security guidance. It will maintain safeguards proportionate to the nature of Client Data and the processing risk.
Minimum contractual safeguards include encryption in transit over public networks and encryption at rest for stored Client Data; role-based access and prompt revocation; multi-factor authentication for privileged administrative access where supported; logical segregation of client records; restricted document access; relevant access and security logging; vulnerability and patch management; incident response procedures; and secure deletion. LIVEWORK will maintain appropriate backup and recovery measures and periodically review the effectiveness of safeguards. These are contractual requirements to be implemented before Client Data is processed.
Subprocessors and processing locations
Client gives general authorization for subprocessors identified in a completed Schedule A supplied before processing begins. The schedule must identify each legal entity, its service, data involved, and processing locations. A reference to an unnamed category of AI provider does not authorize disclosure to that provider. No location or data-residency commitment is implied beyond the completed schedule and agreement.
LIVEWORK will give at least 15 days’ advance written notice before a new or replacement subprocessor handles Client Data. Client may object within that period on reasonable, documented privacy or security grounds. The parties will seek a reasonable alternative; LIVEWORK will not disclose the affected data to the proposed provider while the objection remains unresolved. If no solution is available, Client may terminate the affected processing or services without a termination penalty and receive a refund of prepaid fees for unperformed affected services. Earned fees remain payable.
LIVEWORK will impose written confidentiality, security, purpose-limitation, and other applicable obligations on subprocessors that are no less protective in substance for the delegated processing. LIVEWORK remains responsible for their performance of those obligations. Transfers subject to international transfer restrictions require a lawful mechanism and any additional agreement before transfer; this DPA alone is not a substitute for that mechanism.
Security incidents
A “Security Incident” is a breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Client Data. Unsuccessful attempts that do not compromise Client Data are excluded.
LIVEWORK will notify Client without undue delay and no later than 72 hours after becoming aware of a Security Incident involving Client Data, or sooner if applicable law requires. Notice will not be delayed until a complete investigation or final confirmation of scope. Initial notice may be supplemented as information becomes available.
Notice will describe the known nature of the incident, affected information and individuals where reasonably ascertainable, likely consequences, containment and remediation measures, and a response contact. LIVEWORK will take reasonable steps to contain and remediate the incident, preserve relevant evidence, and cooperate with Client. Each party is responsible for legally required notifications within its control. LIVEWORK will not notify individuals on Client’s behalf without instructions unless legally required. Notice is not an admission of liability.
Individual requests and regulatory assistance
LIVEWORK will notify Client of requests relating to Client Data without undue delay and ordinarily within five business days, or sooner if needed to meet a known deadline. It will not resolve a request on Client’s behalf without instructions except as required by law. It will provide reasonable assistance with access, correction, deletion, portability, opt-outs, and other applicable rights.
Taking account of the processing and available information, LIVEWORK will reasonably assist Client with privacy impact and risk assessments, regulatory inquiries, legally required assessments of automated processing, and security obligations relating to the services. Client remains responsible for decisions and obligations assigned to it by law; LIVEWORK remains responsible for its own.
Verification, audits, and remediation
LIVEWORK will make available information reasonably necessary to demonstrate compliance, including relevant policies, security summaries, and available independent assessments. Client may conduct reasonable reviews and, where needed, inspections or audits through a qualified independent reviewer bound by confidentiality.
Routine audits ordinarily occur no more than once annually on reasonable notice during business hours, with reasonable protections for security, other clients’ information, and privileged material. Those scheduling limits do not apply when additional review is reasonably needed because of an incident, suspected material noncompliance, a regulator’s request, or a legal requirement. LIVEWORK will cooperate with reasonable remediation and will not use confidentiality restrictions to prevent required verification.
Return, deletion, and legally retained copies
Upon Client’s written request or termination, LIVEWORK will, at Client’s choice, return Client Data in a reasonably usable standard format and delete it, or delete it without return, within 30 days unless another lawful period is agreed. The return process will use an appropriate secure method.
Copies required by law may be retained only for that purpose, subject to this DPA, with access restricted. LIVEWORK will identify the legal basis and expected retention period where reasonably possible. Backup copies will remain protected, be unavailable for ordinary processing, and be deleted on the documented backup cycle specified in Schedule A. If restored for disaster recovery, deletion instructions will be reapplied. LIVEWORK will confirm completion in writing on request.
Client obligations, liability, and contact
Client will provide lawful, specific instructions; appropriate notices and permissions; only information needed for the services; accurate authorized-user details; and any known preservation requirements. Client will not require LIVEWORK to process information unlawfully or use results for unlawful discrimination.
Liability is governed by the Engagement Terms, including their separate treatment of confidentiality, privacy, and security breaches and their exceptions for liability that cannot lawfully be limited. The DPA does not limit an individual’s statutory rights or a regulator’s powers. Its obligations continue for as long as LIVEWORK retains Client Data.
Privacy and incident contact: privacy@livework.inc. Legal notices: legal@livework.inc. Client’s privacy and incident contacts must be listed in the Search Order or Schedule A. Mail: GERMANN INC dba LIVEWORK, 26632 Towne Centre Dr. #300, Suite 3, Foothill Ranch, CA 92610.
Schedule A · processing configuration
Schedule A is completed for each engagement and attached to the Search Order before any Client Data is processed. It records the authorized subprocessor register together with the configuration fields listed below. LIVEWORK’s standing register is: Supabase (database, storage, authentication); Resend (transactional email); Microsoft (business email and documents); and GitHub (public site hosting, only to the extent it processes Client Data). An AI document-processing provider is named specifically in Schedule A and is authorized only for the documented services, with retention and model-training restrictions in place. A reference to an unnamed category of provider authorizes nothing.
For each authorized provider, record: legal entity; service; categories of Client Data; processing and support-access countries; contractual restrictions; and activation date. Hosting public web pages does not itself justify placing resumes or applicant data in a public repository.
Configuration fields completed per engagement: authorized provider register; Client privacy contact; Client incident contact; permitted processing locations; active-data retention instructions; backup deletion cycle; secure export method; and any approved sensitive data with its safeguards. No unspecified provider and no unapproved sensitive-data use is authorized by this schedule.
