1.Introduction
This Data Processing Addendum ("DPA") forms part of and supplements the Terms of Service, Master Services Agreement ("MSA"), Order Form, or other written agreement (collectively, the "Agreement") between INGENIOUSPOLYMATH (OPC) PRIVATE LIMITED, operating the NewSkill platform ("Processor", "Company", "we", "our", or "us"), and the customer identified in the applicable Agreement ("Customer" or "Controller").
This DPA governs the processing of Personal Data by the Company on behalf of the Customer in connection with the NewSkill platform and related Services. Where there is any conflict between this DPA and the Agreement regarding processing of Personal Data, this DPA shall prevail to the extent of that conflict.
2.Purpose
The purpose of this DPA is to define the parties' responsibilities regarding Personal Data, meet applicable data protection requirements, describe the safeguards applied by NewSkill, establish Processor obligations, and support Customers in complying with applicable privacy laws, including:
- Digital Personal Data Protection Act, 2023 (India), where applicable
- General Data Protection Regulation (EU) 2016/679 ("GDPR"), where applicable
- UK GDPR, where applicable
- Other applicable data protection legislation governing the processing of Personal Data
3.Definitions
- Controller — the entity that determines the purposes and means of processing. For most NewSkill deployments, the Customer acts as the Controller.
- Processor — INGENIOUSPOLYMATH (OPC) PRIVATE LIMITED, acting through NewSkill, which processes Personal Data on behalf of the Customer.
- Personal Data — any information relating to an identified or identifiable natural person.
- Processing — any operation performed on Personal Data (collection, recording, storage, retrieval, use, disclosure, transmission, deletion, destruction, etc.).
- Data Subject — the individual to whom Personal Data relates (candidates, recruiters, hiring managers, employees, administrators, end users).
- Customer Data — all information submitted to or processed through the Services by or on behalf of the Customer.
- Subprocessor — a third party engaged by the Processor to process Personal Data on behalf of the Customer.
- Security Incident — an actual or reasonably suspected unauthorized access to, acquisition of, disclosure of, alteration of, or destruction of Personal Data processed by the Processor.
4.Scope of Processing
This DPA applies whenever the Processor processes Personal Data on behalf of the Customer while providing the Services — including online assessments, candidate evaluations, recruiter dashboards, AI-powered hiring assistance, recruitment workflow automation, skills testing, interview support, reporting, analytics, APIs, integrations, and customer support — regardless of whether the Services are accessed through the website, web applications, APIs, integrations, mobile applications, or other interfaces.
5.Roles of the Parties
Unless otherwise agreed in writing, the Customer acts as the Controller and INGENIOUSPOLYMATH (OPC) PRIVATE LIMITED acts as the Processor. The Customer determines why Personal Data is processed, which individuals' data is processed, which categories are collected, and how long Personal Data should be retained subject to technical and legal limitations. The Processor processes Personal Data solely on behalf of the Customer and in accordance with documented instructions. Nothing in this DPA transfers ownership of Customer Data to the Processor.
6.Categories of Personal Data & Data Subjects
Candidate Information
Full name, email, phone, resume/CV, education, employment history, skills, certifications, assessment responses, coding submissions, portfolio links, interview notes, AI-generated summaries, assessment scores, recruiter comments.
Customer User Information
Name, business email, job title, department, organization, login history, authentication records, workspace permissions.
Technical Information
IP address, browser type, device identifiers, operating system, session identifiers, activity logs, error reports, audit logs.
Billing Information
Billing contact, organization details, GST information, subscription information, invoice information. Payment card information is generally processed by third-party payment processors.
Data Subjects
Candidates, recruiters, hiring managers, customer employees, organization administrators, contractors, temporary staff, interview panel members, customer representatives, customer support contacts.
7.Nature & Purpose of Processing
The Processor may collect, record, store, organize, analyze, transmit, back up, retrieve, delete, and securely dispose of Personal Data. Processing is limited to activities necessary for providing the Services.
Purposes include delivering the Services, hosting Customer Data, operating the assessment platform, providing recruiter dashboards, generating reports, delivering AI-powered hiring assistance, supporting integrations, authenticating users, providing customer support, monitoring platform performance, maintaining security, detecting fraud, performing backup and disaster recovery, and meeting legal obligations. The Processor shall not process Personal Data for its own independent commercial purposes except where expressly permitted.
8.Processing Instructions
The Processor shall process Personal Data only in accordance with this DPA, the Agreement, documented instructions provided by the Customer, and where required by applicable law. If applicable law requires the Processor to process Personal Data beyond the Customer's instructions, the Processor shall notify the Customer unless prohibited by law. Where the Processor believes an instruction violates applicable law, it may suspend the affected Processing until the matter is resolved.
9.Customer & Processor Responsibilities
The Customer represents and warrants that:
- It has all necessary rights and permissions to provide Personal Data to the Processor
- It has a lawful basis for Processing
- It has provided required privacy notices to Data Subjects
- It complies with applicable employment, privacy, and data protection laws
- Personal Data submitted is accurate to the extent reasonably possible
The Processor shall:
- Process Personal Data only as permitted by the Agreement and this DPA
- Implement appropriate technical and organizational security measures
- Maintain confidentiality obligations for personnel with access
- Assist the Customer in fulfilling applicable legal obligations
- Notify the Customer of Personal Data Breaches
- Engage Subprocessors only in accordance with this DPA
- Delete or return Personal Data upon termination where applicable
10.Technical & Organizational Security Measures
Access Controls
- Role-based access control (RBAC)
- Least privilege access
- Multi-factor authentication (MFA) for privileged accounts
- Administrative approval processes
- Periodic access reviews
Network Security
- TLS encryption for data in transit
- Firewalls
- Network segmentation where appropriate
- DDoS mitigation
- Secure API authentication
- Continuous monitoring
Data Protection
- Encryption at rest where appropriate
- Secure password hashing
- Backup encryption where supported
- Secure deletion procedures
- Data integrity monitoring
Application Security
- Secure software development practices
- Dependency management
- Security testing
- Vulnerability remediation
- Patch management
- Logging and monitoring
Operational Security
- Employee security awareness training
- Internal access approval processes
- Incident response procedures
- Change management
- Business continuity planning
- Disaster recovery procedures
The Processor may update these measures from time to time provided that the overall level of security is not materially reduced.
11.Subprocessors
The Customer acknowledges that the Processor may engage third-party subprocessors, including cloud infrastructure providers, database providers, email delivery providers, authentication providers, monitoring and analytics providers, customer support platforms, AI infrastructure providers, payment providers, and CDNs.
The Processor shall ensure each Subprocessor is bound by contractual obligations that provide an appropriate level of protection for Personal Data and remains responsible for their performance to the extent required by law and the Agreement. A current list of approved Subprocessors is available upon request or through our Trust Center. Where required by law or contract, Customers will be provided with reasonable notice of material Subprocessor changes.
12.International Data Transfers
The Services may involve processing or storage of Personal Data in jurisdictions outside the country in which the Customer or Data Subjects are located. Where international transfers occur, the Processor shall implement appropriate contractual, organizational, and technical safeguards, encryption, and internationally recognized transfer mechanisms where applicable. The Processor will not knowingly transfer Personal Data in violation of applicable data protection laws.
13.Assistance with Data Subject Requests & Compliance
Where the Processor receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Customer, the Processor shall promptly notify the Customer where legally permitted, not respond directly unless authorized or legally required, and reasonably assist the Customer in responding.
The Processor shall provide reasonable assistance for privacy impact assessments (DPIAs), regulatory enquiries, security documentation, compliance questionnaires, and customer audits (subject to audit terms). Reasonable fees may apply for assistance requiring substantial additional work.
14.Personal Data Breach Notification
If the Processor becomes aware of a confirmed Personal Data Breach affecting Customer Personal Data, the Processor shall notify the Customer without undue delay, provide available information regarding the nature of the incident, describe categories of affected Personal Data where reasonably known, describe mitigation measures, and cooperate with reasonable investigations. The Processor's obligation is limited to information reasonably available at the time of notification.
15.Audit Rights
Where required by applicable law or the Agreement, the Processor shall make available information reasonably necessary to demonstrate compliance with this DPA through security documentation, compliance reports, questionnaires, certifications where available, or other mutually agreed mechanisms. On-site audits shall be conducted only where reasonably necessary, subject to reasonable advance notice, during normal business hours, without disruption, and subject to appropriate confidentiality obligations. Independent third-party audit reports or certifications may satisfy audit requirements where available.
16.Government Requests for Personal Data
If the Processor receives a legally binding request from a governmental authority seeking access to Customer Personal Data, the Processor shall, where legally permitted, notify the Customer promptly, limit disclosure to what is legally required, challenge unlawful or overly broad requests where appropriate, and maintain appropriate records of such disclosures.
17.Return, Deletion & Retention of Personal Data
Upon termination or expiration of the Agreement, and subject to applicable law, the Customer may request that the Processor return Customer Personal Data, provide an export in a commonly used electronic format where technically feasible, or securely delete Customer Personal Data.
Unless otherwise agreed or required by law, the Processor shall securely delete or anonymize Customer Personal Data following completion of the applicable retention period. Limited information may be retained to comply with legal obligations, resolve disputes, enforce contractual rights, maintain backup integrity for a limited period, prevent fraud, or protect the security of the Services.
18.Privacy by Design and by Default
- Role-based permissions
- Configurable access controls
- Secure default settings
- Audit logging
- Encryption
- Secure software development practices
- Regular security improvements
19.Liability
The liability of each party under this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement, unless otherwise prohibited by applicable law. Nothing in this DPA shall exclude or limit liability where such exclusion or limitation is not permitted by law.
20.Term & Termination
This DPA becomes effective on the earlier of the effective date of the Agreement, the Customer's first use of the Services involving Personal Data, or the execution of a separate DPA. It remains in effect for as long as the Processor processes Personal Data on behalf of the Customer. Termination of the Agreement automatically terminates this DPA, except for provisions intended by their nature to survive, including confidentiality, liability, audit rights, and data deletion obligations.
21.Changes to this DPA
We may update this DPA from time to time to reflect changes in applicable law, regulatory guidance, security improvements, operational changes, new Services or features, or industry best practices. Where material changes affect Customer rights or obligations, reasonable notice will be provided in accordance with the Agreement.
22.Governing Law, Precedence & Severability
Unless otherwise agreed in writing, this DPA shall be governed by the laws specified in the Agreement. Where none are specified, it shall be governed by the laws of the Republic of India.
In the event of any inconsistency: (1) this DPA shall prevail with respect to the processing of Personal Data; (2) the Agreement shall govern all other matters; (3) any executed Order Form or Master Services Agreement shall apply where expressly stated. If any provision of this DPA is determined to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
23.Annex I — Details of Processing
Data Processor
INGENIOUSPOLYMATH (OPC) PRIVATE LIMITED, brand: NewSkill. Primary Services: AI Hiring Platform, Candidate Assessment Platform, Recruitment Automation, Skills Testing, Interview Assistance, Hiring Analytics.
Data Controller
The Customer identified in the applicable Agreement.
Duration of Processing
For the duration of the Agreement and any applicable retention period required to fulfill contractual obligations, comply with legal requirements, maintain backup integrity, or securely delete or anonymize Customer Personal Data.
24.Annex II — Technical & Organizational Security Measures
Access Management
- Role-based access control
- Least privilege
- Administrative approval workflows
- Multi-factor authentication for privileged accounts
Infrastructure Security
- TLS encryption
- Encryption at rest where appropriate
- Firewalls
- Secure cloud infrastructure
- Continuous monitoring
- Network protection
Application Security
- Secure software development lifecycle
- Code review practices
- Dependency management
- Security testing
- Patch management
- Vulnerability remediation
Operational Controls
- Security awareness training
- Confidentiality obligations
- Change management
- Backup procedures
- Disaster recovery planning
- Incident response procedures
Monitoring
- Audit logging
- Security logging
- Infrastructure monitoring
- Performance monitoring
- Access logging
25.Annex III — Approved Subprocessors
The Processor may engage trusted third-party providers to support delivery of the Services. Categories commonly used include:
| Category | Purpose |
|---|---|
| Cloud Infrastructure Provider | Application hosting and infrastructure |
| Database Provider | Data storage and database services |
| Email Delivery Provider | Transactional emails and notifications |
| Authentication Provider | User authentication and identity services |
| Payment Processor | Subscription billing and payment processing |
| AI Service Provider | AI-powered features and language model processing |
| Content Delivery Network (CDN) | Performance and content delivery |
| Monitoring & Logging Provider | Application monitoring and diagnostics |
| Analytics Provider | Product analytics and performance measurement |
| Customer Support Platform | Customer support ticketing and communications |
Customers should refer to the most recent Subprocessor List maintained by the Processor for current information.
26.Contact
For DPA enquiries, please contact:
INGENIOUSPOLYMATH (OPC) PRIVATE LIMITED — Brand: NewSkill
Enterprise / DPA: enterprise@newskill.in
Privacy enquiries: privacy@newskill.in
