Legal

Data Processing Addendum

Baseline processing terms for business customers. A signed DPA or agreement controls if it differs from this page.

Effective September 13, 2026

1. Scope and instructions

This DPA applies when Question Techs processes personal data for a customer through PulseHireX. The customer is controller or business; Question Techs is processor or service provider and processes data only on documented instructions, including the agreement and authorized service use.

2. People, security and incidents

Personnel with access are bound by confidentiality. We maintain measures appropriate to the service risk, including access controls, authentication safeguards, logging and incident handling. We notify the customer without undue delay after confirming a personal-data breach affecting customer data and provide available information needed for its obligations.

3. Subprocessors and transfers

The customer authorizes listed subprocessors subject to written data-protection obligations. We will maintain a current list and provide notice of material changes through the agreed channel. International transfers use a lawful mechanism where required.

4. Rights, assistance and audits

Taking account of the processing, we assist with data-subject requests, impact assessments and regulator consultations where reasonably required. We provide information reasonably necessary to demonstrate compliance; audit scope, confidentiality, timing and costs follow the signed agreement.

5. Return and deletion

At the customer's choice and subject to law, customer personal data is returned or deleted after termination according to the Data Deletion and Return Policy. Backup copies remain protected and age out under controlled schedules.