1.Scope and parties
This Data Processing Addendum ("DPA") forms part of the Apex ATS Terms of Service between Caspian Solutions ("Processor" or "Caspian") and the customer that accepts the Terms ("Controller" or "Customer"). It applies whenever Caspian processes personal data on the Customer's behalf in connection with the Service, and it is intended to satisfy Article 28 of the GDPR and UK GDPR and the service provider requirements of the CCPA/CPRA. In case of conflict with the Terms, this DPA controls for matters of data protection.
2.Definitions
"Personal Data", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meanings given in the GDPR. "Customer Personal Data" means personal data in Customer Data, principally applicant data and data about the Customer's users. "Data Protection Laws" means all laws applicable to the processing of Customer Personal Data, including the GDPR, UK GDPR, CCPA/CPRA and other US state privacy laws. "Subprocessor" means a third party engaged by Caspian to process Customer Personal Data.
3.Roles and details of processing
Customer is the controller (or business) and Caspian is the processor (or service provider) of Customer Personal Data.
- Subject matter: provision of the Apex ATS applicant tracking and messaging service.
- Duration: the term of the Customer's subscription plus the retention period in the Terms.
- Nature and purpose: hosting, storage, parsing, scoring, display, transmission of messages, scheduling, reporting and export, as instructed through the Service.
- Categories of data subjects: job applicants and candidates; the Customer's users and hiring team.
- Categories of data: contact details, resume content and work history, education, skills, screening answers, cover letters, message content and metadata, interview details, notes and evaluations, consent and opt-out records, technical identifiers. Customers should not submit special category data through screening questions.
4.Processor obligations and instructions
Caspian will process Customer Personal Data only on the Customer's documented instructions, which consist of the Terms, this DPA, and the Customer's configuration and use of the Service, unless required to do otherwise by law, in which case Caspian will inform the Customer before processing unless the law prohibits it. Caspian will inform the Customer if it believes an instruction infringes Data Protection Laws.
Caspian will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality, will assist the Customer as described below, and will make available the information necessary to demonstrate compliance with this DPA.
Caspian does not sell or share Customer Personal Data, does not retain, use or disclose it for any purpose other than performing the Service, and does not combine it with personal data from other sources except as needed to provide the Service. Caspian certifies that it understands these restrictions.
5.Security measures
Caspian implements appropriate technical and organizational measures, including:
- Encryption of data in transit (TLS 1.2 or higher) and at rest.
- Logical tenant isolation enforced by database Row Level Security keyed to the Customer's organization.
- Role-based access control within the Service (Owner, Admin, Recruiter, Hiring manager).
- Private storage of resume files with short-lived signed URLs.
- Least-privilege access for Caspian staff, with access logged and reviewed.
- Webhook signature verification for inbound messaging events.
- Automated daily backups with point-in-time recovery, retained for 30 days.
- Vulnerability management, dependency updates and a responsible disclosure process.
Further details are published at ats.apexsales.ai/security and may be updated, provided the overall level of protection does not decrease.
6.Subprocessors
The Customer authorizes Caspian to engage the following Subprocessors:
- Supabase, Inc. (United States): managed Postgres database, authentication, file storage. Hosted on Amazon Web Services, US region.
- Cloudflare, Inc. (United States): application hosting, content delivery, DDoS protection and edge security.
- Twilio Inc. (United States): SMS transmission, when the Customer connects a Twilio account. Twilio is also engaged directly by the Customer under Twilio's terms.
- Resend (United States): transactional email delivery.
Caspian will notify the Customer by email at least 30 days before adding or replacing a Subprocessor. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected part of the Service and receive a refund of prepaid fees for the remainder of the term. Caspian imposes data protection obligations on Subprocessors that are no less protective than this DPA and remains liable for their performance.
7.International transfers
Customer Personal Data is stored and processed in the United States. Where transfers from the EEA, UK or Switzerland are subject to Data Protection Laws, the parties enter into the EU Standard Contractual Clauses (Module Two, controller to processor, and Module Three where applicable), which are incorporated by reference, together with the UK International Data Transfer Addendum. The Customer is the data exporter and Caspian the data importer. Caspian will provide a signed copy on request.
8.Assistance with data subject requests
The Service includes controls for the Customer to export, correct and delete applicant records and to record consent and opt-outs. If Caspian receives a request from a data subject relating to Customer Personal Data, it will not respond except to direct the person to the Customer, unless required by law, and will promptly notify the Customer. Caspian will provide reasonable assistance, taking into account the nature of the processing, to help the Customer respond to requests and to meet its obligations regarding security, breach notification, data protection impact assessments and consultation with supervisory authorities.
9.Personal data breach notification
Caspian will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, measures taken or proposed, and a contact point, and will be updated as information becomes available. Caspian will cooperate with the Customer's investigation and remediation.
10.Deletion and return
During the term the Customer can export Customer Personal Data at any time. On termination Caspian will keep Customer Personal Data available for export for 60 days, then delete it from production systems, with backups expiring within a further 30 days, unless retention is required by law. On written request Caspian will confirm deletion.
11.Audits
Caspian will make available information reasonably necessary to demonstrate compliance with this DPA, including its security documentation and any third-party assessment reports it obtains. No more than once per year, or after a breach, the Customer may conduct an audit, on 30 days' notice, during business hours, without disrupting the Service, subject to confidentiality, and at the Customer's expense. Caspian may require that the audit be performed by a mutually agreed independent auditor.
12.Liability and term
Each party's liability under this DPA is subject to the limitations in the Terms. This DPA lasts as long as Caspian processes Customer Personal Data. Caspian may update this DPA to reflect changes in law or the Service with notice, provided the protections are not reduced.
13.Contact
Privacy contact for the Processor: management@apexsales.ai. The Customer's privacy contact is the email address of the Workspace Owner unless otherwise notified.
Last updated: September 2026.
