Data Processing Agreement
Effective date: 9 August 2026
Entity: Axys Platforms LLC, doing business as Axys Analysis (“Axys Analysis”, “Processor”)
Contact: privacy@axysanalysis.com
Section 1 — Definitions
“Controller” means the customer entity that has signed up to use the Axys Analysis platform and determines the purposes and means of processing personal data, including where that Controller has authorised an Authorised Agency (defined below) to access the platform on its behalf.
“Processor” means Axys Platforms LLC, which processes personal data on behalf of the Controller.
“Personal Data” means any information relating to an identified or identifiable natural person processed through the Axys Analysis platform.
“Services” means the cognitive screening and candidate assessment platform provided by Axys Platforms LLC.
“Sub-processor” means any third party engaged by the Processor to process Personal Data in connection with the Services.
“Authorised Agency” means a staffing or recruiting agency that a Controller has authorised to access and use the Services on the Controller's behalf, per Terms of Service Section 5A.
Section 2 — Scope and role
2.1
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Controller and Axys Platforms LLC and governs the processing of Personal Data by Axys Platforms LLC on behalf of the Controller.
2.2
The Controller is the data controller for all candidate Personal Data collected through the platform, including data accessed by an Authorised Agency on the Controller's behalf. Axys Platforms LLC acts solely as a data processor for such data, processing it only on the documented instructions of the Controller.
2.3
This DPA applies to all Personal Data processed through the platform, including candidate names, email addresses, assessment responses, and behavioural signals captured during assessments.
Section 2A — Agency access
2A.1
Where a Controller authorises an Authorised Agency to access the Services, the Controller is solely responsible for that authorisation and for any terms governing the relationship between the Controller and the Authorised Agency.
2A.2
Axys Platforms LLC's obligations under this DPA run to the Controller. Access by an Authorised Agency does not create a separate processing relationship between Axys Platforms LLC and the Authorised Agency.
2A.3
The Controller acknowledges that, depending on account configuration, an Authorised Agency's personnel may be able to access Personal Data across multiple Controller accounts linked to that agency.
Section 3 — Processor obligations
Axys Platforms LLC agrees to:
3.1
Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to third countries.
3.2
Ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations.
3.3
Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption in transit and at rest, access controls, and rate limiting.
3.4
Not engage any Sub-processor without informing the Controller. The current list of Sub-processors is maintained at /legal/sub-processors. Controllers will be notified at least 30 days before any new Sub-processor is engaged.
3.5
Assist the Controller in responding to requests from data subjects exercising their rights under applicable data protection law.
3.6
Assist the Controller in ensuring compliance with obligations relating to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
3.7
At the choice of the Controller, delete or return all Personal Data on termination of the Services, and delete existing copies unless applicable law requires their retention.
3.8
Make available to the Controller all information necessary to demonstrate compliance with the obligations in this DPA.
Section 4 — Controller obligations
The Controller agrees to:
4.1
Ensure it has a lawful basis for processing candidate Personal Data and for instructing Axys Platforms LLC to process it on its behalf.
4.2
Obtain all necessary consents and provide all required notices to candidates before administering assessments through the platform.
4.3
Ensure candidates are informed that an automated assessment tool is used and how their data will be processed.
4.4
Not instruct Axys Platforms LLC to process Personal Data in a manner that would violate applicable law.
4.5
Where the Controller authorises an Authorised Agency, ensure that authorisation itself complies with applicable law, including any notice to candidates required as a result.
Section 5 — Data retention and deletion
5.1
Candidates who do not complete their assessment are deleted immediately upon closure of the associated job.
5.2
Candidates who complete their assessment are retained, with full detail available to the Controller, for as long as the associated job remains open, and for 30 days after the job closes, after which their record is redacted per Section 5.4 below.
5.3
If a job never closes, candidate Personal Data (including for candidates who did not complete their assessment) is retained for a maximum of 12 months from the date of the assessment, after which Section 5.4 applies automatically.
5.4
Redaction at the applicable deadline consists of: replacement of identifying fields (name, email) with a non-identifying value; removal of detailed open-ended answer text and AI-generated rubric rationale; removal of free-text hiring-manager notes; removal of any linked applicant-tracking-system identifiers. Composite scores, dimension-level scores, and the job association are retained after redaction to support the Controller's ability to review past hiring rounds.
5.5
Declined candidates' data is deleted after 60 days, or immediately upon job closure, whichever is earlier.
5.6
On termination of the Controller's account, Personal Data will be deleted within 30 days unless the Controller requests earlier deletion or applicable law requires longer retention.
5.7 — Backups
Personal Data deleted from the live system per this Section may persist for up to 30 additional days in encrypted, rolling off-site backups maintained for disaster recovery purposes, until that backup is rotated out of retention.
Section 6 — Security incidents
6.1
Axys Platforms LLC will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting the Controller's data.
6.2
Notification will include: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
6.3
The Controller is responsible for notifying supervisory authorities and affected data subjects where required by applicable law.
Section 7 — Sub-processors
7.1
The Controller provides general authorisation for Axys Platforms LLC to engage Sub-processors for the delivery of the Services.
7.2
The current list of Sub-processors is available at /legal/sub-processors.
7.3
Axys Platforms LLC will inform the Controller of any intended changes to Sub-processors at least 30 days in advance. The Controller may object to a new Sub-processor by contacting privacy@axysanalysis.com within 14 days of notification.
7.4
Axys Platforms LLC ensures that Sub-processors are bound by data protection obligations equivalent to those in this DPA.
Section 8 — International transfers
8.1
All Sub-processors used by Axys Platforms LLC are based in the United States.
8.2
Where Personal Data originating from the European Economic Area or United Kingdom is transferred to the United States, such transfers require appropriate safeguards under applicable law. As of this version, Standard Contractual Clauses for such transfers have not yet been implemented — see Section 8.3.
8.3
Controllers with EEA or UK candidate data must contact privacy@axysanalysis.com to discuss appropriate transfer mechanisms before using the platform for such candidates.
Section 9 — Term and termination
This DPA is effective for the duration of the Controller's subscription to the Services and terminates automatically upon termination of the Terms of Service.
Section 10 — Governing law
This DPA is governed by the laws of the State of Indiana.
Section 11 — Contact
Axys Platforms LLC (d/b/a Axys Analysis)
5534 Saint Joe Road
Fort Wayne, IN 46835
EIN: 42-3381322
Sub-processor list: /legal/sub-processors