Legal
Data Processing Addendum
Last updated: May 1, 2026
This addendum covers how C2C Central processes personal data on a firm's behalf — the controller and processor roles, the subprocessors we use, the security we apply, and how we handle data subject rights, breaches, and international transfers.
1.Roles of the parties
This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer") and C2C Central and applies where C2C Central processes personal data on the Customer's behalf.
For platform data — candidate records, submissions, application activity, and compliance documents — the Customer is the controller and C2C Central is the processor. C2C Central processes personal data only on documented instructions from the Customer, as set out in the agreement and this DPA.
2.Scope and purpose of processing
C2C Central processes personal data solely to provide the Service: bench management, submissions, recruiter performance, the application tracker, immigration and compliance tracking, and hotlist broadcast.
The categories of data subjects include the Customer's bench consultants, candidates, recruiters, managers, and other personnel. The categories of personal data include identifiers, contact details, work-authorization and visa status, resumes, and activity records.
3.Subprocessors
The Customer authorizes C2C Central to engage subprocessors to deliver the Service. Current subprocessors support cloud infrastructure and storage, authentication, payment processing, and email delivery.
C2C Central imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains responsible for their performance. We will give the Customer reasonable notice of any new subprocessor and an opportunity to object on reasonable grounds.
4.Security measures
C2C Central maintains technical and organizational measures appropriate to the risk, including encryption of data in transit and at rest, absolute firm-level data isolation, role-based access control for Owners, Managers, and Recruiters, audit logging of recruiter actions, and hardened cloud infrastructure.
Access to personal data is limited to personnel who need it to operate the Service and who are bound by confidentiality obligations.
5.Data subject rights
Where C2C Central receives a request from a data subject relating to Customer data, we will, to the extent legally permitted, direct the request to the Customer rather than respond directly.
C2C Central will provide reasonable assistance to enable the Customer to respond to data subject requests to access, correct, delete, port, or restrict the processing of personal data, taking into account the nature of the processing.
6.Personal data breach notification
C2C Central will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer data.
The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address it. C2C Central will reasonably cooperate with the Customer's own breach-response obligations.
7.International data transfers
C2C Central primarily stores Customer data in United States-based cloud regions. Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the transfer is governed by appropriate safeguards such as the applicable Standard Contractual Clauses, which are incorporated into this DPA by reference.
8.Deletion and return of data
On termination of the Service, C2C Central will, at the Customer's choice, return or delete Customer personal data within a reasonable period, except where retention is required by law. Backup copies are deleted in line with our standard retention schedule.
9.Audits
C2C Central will make available information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality and scheduling terms.
10.Requesting and contact
Firms that require an executed DPA can request one by emailing hello@c2ccentral.com. This page describes the substance of the addendum; the signed version controls in case of any conflict.