Processing
What the processor agreement commits us to, clause by clause
A data processing addendum is the document that says what a vendor may do with your candidate data, and this walks through each commitment it makes in ordinary language.
The Surhires data processing addendum sets out how Soor LLC processes candidate data on your instructions: scope and purpose, confidentiality, security measures, sub-processing and change notice, assistance with data-subject requests, breach notification, audit rights, international transfers and deletion or return on exit. The executed addendum is the binding text, not this summary.
By Surhires Editorial · Published · Reviewed
This explains the addendum; the executed addendum governs
The data processing addendum is a real contractual document that attaches to the customer agreement. This page is a walkthrough of what it commits Soor LLC to, written so a procurement reviewer can see the shape before the legal review starts. The executed addendum and the current published version are what bind. Where this page reads differently, the document wins.
Nothing here is legal advice, and this page cannot tell you whether the addendum satisfies your obligations. That depends on where your candidates sit, which regime applies, what your own client contracts flow down and what your data protection officer has already decided. Those are questions for your counsel with the executed text in front of them.
One thing is worth stating before the detail: an addendum is not a certification. Signing one does not make either party compliant with anything. It allocates responsibility between two parties and records what each will do. That is genuinely useful, and it is not the same as a stamp.
Scope and instructions define what may be done at all
The addendum records what is being processed, for whom, and why: candidate and client personal data held in your tenant, processed to provide the recruitment software and applicant tracking service you have subscribed to, for the duration of the agreement. That framing is the boundary. Processing outside it needs a new instruction rather than a broad interpretation of an old one.
Your instructions are the ones expressed in the agreement, in the addendum, and through your ordinary use of the product. Configuring a retention window is an instruction. Running an export is an instruction. Asking support to correct a botched import is an instruction. What is excluded is Soor LLC deciding, on its own account, to do something new with candidate data.
Where an instruction appears to conflict with applicable law, the addendum requires that to be raised rather than silently followed or silently ignored. That clause looks like boilerplate and is not: it is the mechanism that stops a processor quietly doing something questionable because a customer asked.
- Processing limited to providing the subscribed service for the agreement term
- Instructions come from the agreement, the addendum and your configuration
- New purposes require a new instruction rather than a broad reading
- Conflicts between an instruction and applicable law are raised, not absorbed
- No processing on Soor LLC's own account against tenant candidate data
Confidentiality binds people, not just the company
The company undertaking confidentiality is the easy part. The clause that matters commits Soor LLC to ensuring that individuals authorised to process your data are themselves bound by confidentiality obligations, whether by employment terms or by contract for contractors, and that authorisation is limited to people who need it to do their work.
In practice that means access is granted through named roles rather than shared credentials, is scoped to a purpose, and is logged. It also means access is removed when a role changes, which is the control most often missing in small vendors: joiners are handled carefully and leavers are handled eventually.
None of this is exotic, and it is exactly what a security questionnaire asks about. The reason to state it in the addendum rather than only in a policy is that a policy can be rewritten unilaterally and a contractual commitment cannot.
Security measures are described, not just promised
The addendum commits to technical and organisational measures appropriate to the risk, and then names them rather than leaving the phrase to do all the work: encryption in transit and at rest, tenancy separation enforced in the data layer, role-based access control, logged administrative and support access, backup with tested restoration, and change management on production systems.
It also commits to keeping those measures at least at the level described for the term, which is the clause that stops a vendor quietly degrading its controls. Improvements are allowed; silent reductions are not.
Alongside the contractual commitment sits the readiness programme. SOC 2 readiness is under way with continuous control monitoring, and a Type I report is the first deliverable. No Type II report is claimed until one has been issued, and the report date will be published when there is one. A readiness programme is not a certification and is not written as if it were.
Sub-processing carries notice and an objection route
Running recruitment software requires other vendors: hosting, model providers, messaging and telephony, email delivery, analytics and support tooling. The addendum permits those sub-processors, requires that each is bound by data protection terms no less protective than the addendum itself, and keeps Soor LLC responsible to you for their performance.
Additions are not silent. A register of current sub-processors is published by category and by named entity, subscribing to change notice is available, and a notice period runs before a new sub-processor begins processing customer data. During that period you can object, on reasonable data protection grounds, and the escalation route if the objection cannot be resolved ends at termination without penalty for the affected service.
That last part is the test of whether a notice clause means anything. A notice you cannot act on is an announcement. The objection route is what turns it into a control, and it is the part worth reading closely in any vendor's addendum, not only this one.
- Published register by category and named entity, with change notification
- A stated notice period before a new sub-processor begins processing
- Objection on reasonable data protection grounds during the notice period
- Flow-down terms no less protective than the addendum itself
- Soor LLC remains responsible to you for sub-processor performance
Assistance with data-subject requests is designed to be self-service
The addendum commits to assisting you with data-subject requests, and the product is built so that most of that assistance is not needed. Subject access export, correction, restriction and erasure run from the record, by your own staff, without a support ticket in the path. A statutory deadline should not depend on a vendor's queue.
Where a request genuinely needs vendor involvement, because it concerns backups, logs or something outside the ordinary product surface, the addendum commits to reasonable assistance taking into account the nature of the processing and the information available. That is a real commitment with a real limit, and the limit is stated rather than hidden.
Requests that arrive at Soor LLC from a candidate are forwarded to the tenant contact rather than answered. A processor answering a controller's data subject directly would be acting outside instructions, however helpful it might feel in the moment.
Breach notification is measured from awareness
The addendum commits to notifying you without undue delay after becoming aware of a personal data breach affecting your data, and to providing the information you need to make your own notification decision: what happened, when, which categories of data and roughly how many records, what has been done, and what is recommended.
The direction of that obligation matters. As controller, you decide whether a supervisory authority or a candidate has to be told, and within what deadline. The processor's job is to get you the facts quickly enough that the decision is yours to make rather than one taken by default while you wait.
Notification is not an admission of liability, and the addendum says so, because a clause that makes disclosure expensive produces slower disclosure. The incentive should point towards telling you early with partial information and updating, not towards a polished account that arrives late.
Audit rights are real, and proportionate
You are entitled to information demonstrating compliance with the addendum. In the ordinary case that is satisfied by documentation: the security overview, the sub-processor register, the completed security questionnaire and, once issued, the SOC 2 report. Most audit obligations in this market are met with paper, and there is no point pretending otherwise.
Where documentation genuinely does not answer a question, the addendum provides for an audit on reasonable notice, during business hours, no more than once a year absent an incident or a regulator's requirement, subject to confidentiality and to not disrupting other customers. Enterprise agreements can vary that, and buyers with a regulatory audit obligation should raise it during procurement.
The constraints are not evasions. A multi-tenant platform cannot open its production environment to unscheduled inspection by any of its customers without creating a security problem for all of the others. Naming the limits is more useful than a broad promise that would have to be renegotiated the first time anyone tried to use it.
Transfers and deletion close the loop
Primary processing is in the United States, on AWS us-east-1. For customers in the UK and the EU that is an international transfer and needs a mechanism: the addendum incorporates the European Commission standard contractual clauses and the UK international data transfer addendum as applicable, together with a transfer impact assessment and the supplementary measures described in the security section.
Those mechanisms are the ones available to a US processor. What they are not is a guarantee about how any regulator or court will view a given transfer in future, and a vendor that tells you otherwise is selling certainty it does not have. The assessment is a document you should read with your own counsel rather than file unread.
On termination, and at your election, candidate data is returned or deleted. Export is self-service throughout the term, the tenant remains retrievable for the window stated in the agreement, and deletion then runs across primary storage and rolls through backups on the ordinary backup cycle rather than instantly, which is a real limitation and is stated as one.
What you get
Defined processing scope
Candidate and client data, processed to provide the subscribed service, for the term of the agreement.
Instruction boundary
New purposes need a new instruction; nothing is processed on Soor LLC's own account.
Unlawful-instruction clause
An instruction that appears to conflict with applicable law is raised rather than silently followed.
Personnel confidentiality
Individuals authorised to process your data are bound by confidentiality obligations, not only the company.
Named measures
Encryption, tenancy separation, role-based access, logged support access, tested restoration and change management.
No silent downgrade
Security measures are held at or above the described level for the term of the agreement.
Published sub-processor register
Categories and named entities, with a subscription route for change notification.
Notice and objection
A stated notice period before a new sub-processor starts, with an objection route on data protection grounds.
Flow-down terms
Sub-processors are bound by terms no less protective, and Soor LLC stays responsible to you.
Self-service subject access
Export, correction, restriction and erasure run from the record without a support ticket in the path.
Request forwarding
Candidate requests reaching Soor LLC are routed to your tenant contact rather than answered directly.
Breach notice on awareness
Notification without undue delay, with the facts you need to make your own notification decision.
Documentation-first audit
Security overview, questionnaire, register and, when issued, the SOC 2 report, with on-site audit provided for.
Transfer mechanisms
Standard contractual clauses and the UK addendum as applicable, with a transfer impact assessment.
Return or delete on exit
Your election on termination, with backup rollout described honestly rather than promised as instant.
Questions recruiters ask
Do we have to sign a separate DPA?
The addendum attaches to the customer agreement rather than being negotiated from scratch each time, which is how most buyers prefer it. Enterprise customers with their own required paper can raise that during procurement. Either way, the executed document is what governs; this page is a walkthrough written for a reviewer deciding whether the shape is workable.
How much notice do we get before a new sub-processor is added?
A notice period runs before a new sub-processor begins processing customer data, and the current period is stated in the published addendum and on the sub-processor page rather than here, so that one number stays authoritative. During the period you can object on reasonable data protection grounds, and unresolved objections escalate to termination for the affected service.
Can we audit your production environment?
The addendum provides for audit on reasonable notice, in business hours, ordinarily once a year absent an incident or a regulator's requirement, subject to confidentiality and to not disrupting other customers. In most cases documentation answers the question faster. A multi-tenant platform cannot open production to unscheduled inspection without creating a problem for every other tenant.
Is Surhires SOC 2 certified?
No. A readiness programme is under way with continuous control monitoring, and a Type I report is the first deliverable. No Type II report is claimed until one has been issued, and the report date will be published when there is one. Anyone describing a readiness programme as a certification is describing something that has not happened.
What mechanism covers transfers out of the UK or the EU?
The addendum incorporates the European Commission standard contractual clauses and the UK international data transfer addendum as applicable, with a transfer impact assessment and the supplementary technical measures described in the security section. Those are the mechanisms available to a US processor. They are not a guarantee about how a regulator will view a transfer in future.
When exactly is our data deleted after we leave?
Export is self-service during the term. After termination the tenant remains retrievable for the window stated in your agreement, then deletion runs across primary storage. Backups roll off on the ordinary backup cycle rather than being edited individually, so there is a short tail. That is a genuine limitation and it is stated rather than glossed.
Keep reading
- Two sets of people, two different roles, one privacy position
- The subprocessor register, and why recruitment needs one
- Holding candidate data lawfully under UK and EU GDPR
- The terms you are agreeing to, written out in ordinary language
- The compliance matrix, walked posture by posture
- The engineering answer to how your candidate data is protected
- Where responsibility sits for every regime that touches recruitment
See it against your own reqs
Bring one live role and three resumes. In twenty minutes you will see the match scores, the shortlist and the placement invoice that comes out the other end.