1. Parties
This Data Processing Addendum ("DPA") is incorporated by reference into, and forms part of, the Agreement entered into by and between Seed Software Technologies (Pty) Ltd ("Seed") and the Customer. The Customer agrees to the terms of this DPA by signing the Agreement or accessing or using the Service. No separate signature is required for this DPA to take effect. This Data Processing Addendum serves as Attachment 2 to the Seed Founding Partner Agreement (South Africa).
1.1 Seed Software Technologies (Pty) Ltd, Registration number 2026/631444/07, 24 Viognier Avenue, Aan de Wijnlanden, Stellenbosch, Western Cape, 7600 ("Seed"); and
1.2 This Data Processing Addendum applies to any Customer that enters into an Agreement with or accesses the Service provided by Seed Software Technologies (Pty) Ltd ("Seed").
2. Scope and roles
2.1 This Data Processing Addendum ("DPA") is incorporated by reference into the agreement between Seed Software Technologies (Pty) Ltd ("Seed") and the customer ("the Customer") under which the Customer accesses the Seed platform ("the Agreement"). The Customer agrees to this DPA by executing the Agreement or accessing the Service, and no additional signature is required.
2.2 In respect of Customer Personal Data, the Customer is the responsible party under POPIA and, where applicable, the controller under the EU GDPR or UK GDPR. Seed is the operator and, where applicable, the processor.
2.3 Seed processes Customer Personal Data only to provide, secure and support the Service, and only on the Customer's documented instructions.
2.4 Each party is independently responsible for its own compliance with Data Protection Law in the capacity in which it acts.
2.5 Where the Customer is itself acting as a processor for one of its own clients, this DPA applies as between the Customer and Seed on a sub-processing basis, and the Customer warrants that it has authority to appoint Seed.
3. Definitions
3.1 "Customer Personal Data" means personal information or personal data within the Customer Data, including Candidate Data, contained in or processed through the Service.
3.2 "Data Protection Law" means the Protection of Personal Information Act 4 of 2013 and its Regulations, the EU General Data Protection Regulation 2016/679, the UK General Data Protection Regulation and the Data Protection Act 2018, and any other law applicable to a party's processing under the Agreement.
3.3 "Data Subject" means the individual to whom Customer Personal Data relates, including a candidate.
3.4 "Security Compromise" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data, being a security compromise under section 22 of POPIA and a personal data breach under the GDPR.
3.5 "Sub-processor" means a third party engaged by Seed to process Customer Personal Data.
3.6 "SCCs" means the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914.
3.7 "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the Information Commissioner under section 119A of the Data Protection Act 2018.
3.8 Terms not defined here have the meaning given in the Agreement or in Data Protection Law.
4. Processing instructions
4.1 Seed will process Customer Personal Data only:
4.1.1 to provide, maintain, secure and support the Service in accordance with the Agreement;
4.1.2 on the Customer's further documented instructions, including instructions given through the configuration and use of the Service; and
4.1.3 where required by a law to which Seed is subject, in which case Seed will inform the Customer of that requirement before processing, unless the law prohibits it.
4.2 The Customer instructs Seed to process Customer Personal Data as described in Annex 1. The Customer's use of the Service constitutes a documented instruction.
4.3 Seed will inform the Customer if, in its opinion, an instruction infringes Data Protection Law. Seed may suspend performance of that instruction until it is withdrawn, amended or confirmed.
4.4 Seed will not sell Customer Personal Data, will not process it for its own purposes, and will not use it to train models that serve any other customer.
4.5 Seed may create aggregated and de-identified data derived from use of the Service, provided it cannot reasonably be used to identify the Customer, its Users, its clients or any Data Subject, and may use that data to operate and improve the Service.
4.6 The Customer warrants that it has a lawful basis for the processing it instructs, has issued the notices Data Protection Law requires, and has obtained any consent that is required.
5. Personnel and confidentiality
5.1 Seed will ensure that every person it authorises to process Customer Personal Data:
5.1.1 is subject to a written confidentiality obligation that survives the end of their engagement;
5.1.2 has received training appropriate to their role on data protection and information security; and
5.1.3 accesses Customer Personal Data only on a least-privilege, need-to-know basis.
5.2 Seed will maintain a record of individuals with access to production systems and will review that record at least every 6 months.
5.3 Seed will revoke access within 1 business day of a person ceasing to need it.
6. Security measures
6.1 Seed will implement and maintain the technical and organisational measures set out in Annex 2, being measures appropriate to the risk in terms of section 19 of POPIA and Article 32 of the GDPR.
6.2 Seed may update those measures, provided it does not materially reduce the overall level of protection.
6.3 Seed will maintain logical separation between customers so that one customer's data is not accessible to another.
6.4 Seed will regularly test, assess and evaluate the effectiveness of its measures.
7. Sub-processors
7.1 The Customer gives Seed general written authorisation to engage Sub-processors, subject to this clause.
7.2 The list of authorised Sub-processors is maintained in Annex 3 of this Addendum or provided directly to Customer via email or in-app notification upon request.
7.3 Seed will give the Customer at least 30 days' notice before adding or replacing a Sub-processor, by email to the Customer's nominated contact and by publishing the change at that page. The Customer may subscribe to notifications at that page.
7.4 The Customer may object to a new Sub-processor on reasonable data protection grounds within 30 days of notice. The parties will discuss the objection in good faith. If Seed cannot offer a reasonable alternative within 30 days, the Customer may terminate the affected part of the Service on written notice, with a pro-rata refund of prepaid fees for the unused period.
7.5 Seed will impose on each Sub-processor written obligations that are no less protective than those in this DPA, and remains fully liable to the Customer for the acts and omissions of its Sub-processors.
8. Data subject requests
8.1 Where Seed receives a request from a Data Subject relating to Customer Personal Data, Seed will not respond to it substantively, and will refer the Data Subject to the Customer and notify the Customer within 3 business days.
8.2 Seed will provide the Customer with the functionality within the Service to access, correct, export and delete Customer Personal Data, so that the Customer can respond to requests itself.
8.3 Where the Customer cannot respond using that functionality, Seed will provide reasonable assistance. Assistance that is more than trivial may be charged at Seed's then-current professional rates, on prior written notice of the estimated cost.
9. Assistance to the Customer
9.1 Taking into account the nature of the processing and the information available to it, Seed will assist the Customer with:
9.1.1 its obligation to keep Customer Personal Data secure;
9.1.2 notification of a Security Compromise to a regulator and to Data Subjects;
9.1.3 data protection impact assessments and prior consultation with a regulator; and
9.1.4 responding to enquiries from the Information Regulator or a supervisory authority.
9.2 Seed will make available the information reasonably necessary to demonstrate compliance with this DPA, including its Security Overview and, where it holds them, its current certifications and penetration test summaries.
10. Security compromises
10.1 Seed will notify the Customer of a Security Compromise affecting Customer Personal Data without undue delay and in any event within 72 hours of becoming aware of it.
10.2 The notification will include, so far as known at the time:
10.2.1 the nature of the compromise, including the categories and approximate number of Data Subjects and records affected;
10.2.2 the likely consequences;
10.2.3 the measures taken or proposed to address it and to mitigate its effects; and
10.2.4 the contact point for further information.
10.3 Where the full information is not available at the time of notification, Seed will provide it in phases without undue further delay, and will provide a written incident report within 10 business days of the incident being contained.
10.4 Seed will not notify the Information Regulator, a supervisory authority or any Data Subject about a Security Compromise affecting Customer Personal Data on the Customer's behalf unless the Customer instructs it to in writing, or unless Seed is independently required by law to do so, in which case it will inform the Customer first where lawful.
10.5 Seed will take reasonable steps to contain a Security Compromise, preserve evidence, and restore the availability of Customer Personal Data.
10.6 Notification under this clause is not an admission of fault or liability by Seed.
11. Return and deletion
11.1 During the term and for 30 days after termination or expiry, the Customer may export Customer Personal Data from the Service in CSV and JSON format.
11.2 On the Customer's written request within that window, Seed will provide a complete export within 5 business days at no charge.
11.3 After that window, Seed will delete or irreversibly de-identify Customer Personal Data from production systems within a further 30 days, and from backups within 90 days.
11.4 Seed may retain Customer Personal Data where a law to which it is subject requires retention, in which case it will retain only what is required, for only as long as required, and will continue to protect it under this DPA.
11.5 Seed will certify deletion in writing on request.
12. Audits and information
12.1 Seed will make available to the Customer the information necessary to demonstrate compliance with this DPA and with Article 28 of the GDPR.
12.2 The Customer may audit Seed's compliance:
12.2.1 once in any 12 month period, on at least 30 days' written notice;
12.2.2 more often where required by a regulator, or following a Security Compromise affecting the Customer's data;
12.2.3 during business hours, without unreasonable disruption to Seed's operations; and
12.2.4 subject to the auditor signing reasonable confidentiality undertakings and not being a competitor of Seed.
12.3 Seed may satisfy an audit request by providing its current security documentation, completed security questionnaire, and any third-party audit report or penetration test summary it holds, where these reasonably address the Customer's questions.
12.4 The Customer bears its own audit costs. Seed bears its own costs for the first audit in any 12 month period, and may charge its reasonable costs for any further audit.
12.5 An audit may not include access to another customer's data, to Seed's source code, or to systems where access would breach Seed's obligations to third parties.
13. Transborder flows under POPIA
13.1 The Customer acknowledges that the Service is hosted in the European Union, and that Seed's personnel access it from South Africa, and instructs Seed to process Customer Personal Data on that basis.
13.2 Where Customer Personal Data is transferred out of the Republic of South Africa, the transfer is made in reliance on section 72(1)(a) of POPIA, on the basis that the recipient is subject to binding corporate rules or a binding agreement, being this DPA and the equivalent terms Seed imposes on its Sub-processors, that provide an adequate level of protection upholding principles for reasonable processing substantially similar to POPIA, and that include provisions substantially similar to section 72 on onward transfers.
13.3 Seed will not transfer Customer Personal Data to a country or recipient not covered by clause 13.2 or Annex 3 without first notifying the Customer in accordance with clause 7.3.
14. International transfers under the GDPR and UK GDPR
14.1 This clause applies where the Customer is established in the European Economic Area or the United Kingdom, or where the EU GDPR or UK GDPR otherwise applies to the Customer's processing.
14.2 Customer Personal Data is hosted within the European Economic Area. Access by Seed's personnel in South Africa is a transfer to a third country that is not the subject of an adequacy decision.
14.3 For transfers subject to the EU GDPR, the SCCs are incorporated into this DPA and apply as set out in Annex 4, with the Customer as data exporter and Seed as data importer.
14.4 For transfers subject to the UK GDPR, the UK Addendum is incorporated as set out in Annex 5.
14.5 Where the Customer acts as a processor for its own client, Module Three of the SCCs applies. Where the Customer acts as a controller, Module Two applies.
14.6 Seed has carried out a transfer impact assessment covering access to Customer Personal Data from South Africa and will make a summary available to the Customer on request.
14.7 Seed will notify the Customer if it receives a legally binding request from a public authority for Customer Personal Data, unless prohibited by law, will challenge a request it considers unlawful or excessive, and will disclose only the minimum required.
14.8 If a transfer mechanism in this clause is invalidated, the parties will in good faith agree to an alternative mechanism without undue delay. Pending agreement, Seed will suspend the affected transfer if the Customer requires it in writing.
15. Liability and precedence
15.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, save where Data Protection Law does not permit that limitation.
15.2 Nothing in this DPA limits a Data Subject's rights under Data Protection Law or under the SCCs.
15.3 Where there is a conflict, this DPA prevails over the rest of the Agreement in respect of the processing of Customer Personal Data. Where there is a conflict between this DPA and the SCCs, the SCCs prevail.
15.4 This DPA continues for as long as Seed processes Customer Personal Data.
Annex 1: Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Seed recruitment CRM platform |
| Duration | The term of the Agreement, plus the retention periods in clause 10 |
| Nature and purpose | Hosting, storage, organisation, retrieval, structuring, automated screening and scoring, generation of outreach drafts, publication of job advertisements to the Customer's public job board, reporting, backup, and support |
| Categories of Data Subject | Candidates and applicants; the Customer's client contacts; the Customer's own Users; referees where the Customer records them |
| Categories of personal data | Name, contact details, address, date of birth where supplied, nationality and right to work information where supplied, curriculum vitae and its contents, employment history, education and qualifications, skills, salary expectations and current remuneration, notice period, interview notes and feedback, screening and scoring outputs, correspondence, placement and commission records, and identifiers created by the Service |
| Special personal data | Not required by the Service. May be present where the Customer chooses to record it, for example equity or demographic information collected for employment equity reporting, or accommodation requirements. The Customer is responsible for its lawful basis and for limiting what it records. |
| Frequency of transfer | Continuous, for the duration of the Agreement |
| Data exporter | The Customer, as identified in the Agreement |
| Data importer | Seed Software Technologies (Pty) Ltd, 24 Viognier Avenue, Aan de Wijnlanden, Stellenbosch, Western Cape, 7600, South Africa, contact info@seedtalent.co.za |
| Competent supervisory authority | Determined under Clause 13 of the SCCs by the Customer's place of establishment or its EU representative |
Annex 2: Technical and organisational measures
| Area | Measure |
|---|---|
| Encryption in transit | TLS 1.2 or higher on all connections to the Service |
| Encryption at rest | Database and object storage encrypted at rest by the hosting provider |
| Tenant isolation | Row-level security enforced at the database layer so a User can access only their own organisation's records |
| Access control | Role-based access within the Service; least-privilege access to production; multi-factor authentication required for all Seed personnel with production access |
| Authentication | Password policy, credential hashing, session expiry, and multi-factor authentication available to customers |
| Logging | Application and access logs retained for 12 months; audit trail of record changes available to Customer administrators |
| Backups | Automated backups at least daily, retained at least 30 days, with restore testing at least twice a year |
| Change management | Version control, peer review of changes to production code, and staged deployment |
| Vulnerability management | Dependency scanning, and remediation of critical vulnerabilities within 14 days of a fix being available |
| Penetration testing | Annual third-party test, with a summary available to customers under confidentiality |
| Personnel | Written confidentiality undertakings, background checks where lawful and proportionate, and role-appropriate security training |
| Sub-processor management | Written data processing terms with every Sub-processor, and periodic review |
| Physical security | Delegated to the hosting provider's certified data centres; Seed operates no data centre of its own |
| Business continuity | Documented incident response and recovery procedures, with a recovery point objective of 24 hours and a recovery time objective of 8 hours |
Annex 3: Approved sub-processors
The current list is reproduced in the Sub-processor List document or provided upon request. It forms part of this DPA.
Annex 4: Standard Contractual Clauses, module and options
Where clause 13.3 applies, the SCCs apply as follows.
| Item | Selection |
|---|---|
| Module | Module Two, controller to processor, where the Customer is a controller. Module Three, processor to processor, where the Customer is a processor for its own client. |
| Clause 7, docking clause | Included |
| Clause 9, sub-processors | Option 2, general written authorisation, with a notice period of 30 days |
| Clause 11, redress | The optional independent dispute resolution paragraph is not included |
| Clause 17, governing law | South Africa |
| Clause 18, forum | South Africa |
| Annex I.A, parties | As set out in Annex 1 above |
| Annex I.B, description of transfer | As set out in Annex 1 above |
| Annex I.C, supervisory authority | As set out in Annex 1 above |
| Annex II, technical and organisational measures | As set out in Annex 2 above |
| Annex III, sub-processors | As set out in Annex 3 above |
Annex 5: UK International Data Transfer Addendum
Where clause 14.4 applies, the UK Addendum applies as follows.
| Table | Entry |
|---|---|
| Table 1, parties | As set out in Annex 1 above. Start date is the effective date of the Agreement. |
| Table 2, selected SCCs | The SCCs as incorporated by Annex 4, including their modules, options and annexes |
| Table 3, appendix information | Annex 1, Annex 2 and Annex 3 above |
| Table 4, ending the Addendum | Either party may end the Addendum as set out in section 19 of the Addendum |
