Data Processing Addendum
NovaHR by TradeNovaTech
This Data Processing Addendum ("DPA") describes the general responsibilities relating to Customer Data processed in connection with NovaHR, a cloud-based human resources and workforce management platform operated by TradeNovaTech ("TradeNovaTech", "NovaHR", "we", "us" or "our").
1. Parties and Scope
This DPA applies to the processing of Customer Data in connection with the customer's use of NovaHR where the applicable service arrangement requires such processing terms.
The customer remains responsible for determining the purposes for which its workforce and related information is submitted to NovaHR, subject to the customer's applicable legal and contractual obligations.
2. Customer Data
Customer Data may include information submitted to or generated through NovaHR for workforce-management purposes, including employee, attendance, leave, organizational, account and related operational information.
Customers should only submit information that they are authorized to provide and process through the service.
3. Processing Purposes
Customer Data may be processed as necessary to provide, operate, secure, support and maintain NovaHR and the functionality requested by the customer, including workforce-management and related administrative functions.
4. Customer Instructions and Responsibilities
The customer is responsible for providing appropriate instructions regarding Customer Data and for determining whether its use of NovaHR is appropriate for its intended workforce and business purposes.
- Maintain lawful authority for information submitted to NovaHR.
- Provide accurate and appropriate instructions where required.
- Manage user access and permissions responsibly.
- Use the service in accordance with applicable law and NovaHR terms.
- Respond appropriately to requests concerning the customer's workforce data.
5. Confidentiality
Customer Data should be treated as confidential within the scope of the applicable service relationship and handled using appropriate safeguards consistent with the operation and security of NovaHR.
6. Security Measures
Appropriate technical and organizational measures are applied to support the security of the service and Customer Data, taking into account the nature of the service and the risks associated with unauthorized access, disclosure, alteration or loss.
Security measures may include access controls, authentication controls, application protections, operational safeguards and other measures applicable to the NovaHR environment.
7. Security Incidents and Breach Handling
Where a security incident affecting Customer Data is identified, appropriate investigation, containment, mitigation and remediation steps may be undertaken as appropriate to the circumstances.
Relevant customer communication may be provided where required by the applicable service arrangement or law and where appropriate to the circumstances.
8. Assistance with Data-Principal Requests
Where Customer Data is subject to requests from individuals or other data principals, NovaHR may provide reasonable assistance within the functionality and technical scope of the service, subject to the customer's responsibilities and the applicable agreement.
9. Subprocessors
This draft does not state a specific current list of subprocessors because a confirmed NovaHR subprocessor list has not been established in the current project documentation.
Where third-party service providers are used in connection with operating or supporting NovaHR, their role and applicable processing arrangements should be documented before final publication of this DPA where required.
10. International Processing
This draft does not state a specific hosting region or international transfer arrangement because those details have not been confirmed in the current NovaHR project documentation.
Any applicable international processing or transfer arrangement should be documented and reviewed as appropriate before final publication.
11. Retention and Deletion
Customer Data should be retained only for the period and purposes applicable to the service relationship, subject to legal, security, operational and contractual requirements.
The specific retention period for Customer Data and any deletion or archival process should be determined and documented according to the applicable NovaHR service terms and operational policy.
12. Legal Requests
NovaHR may process or disclose information where required by applicable law, lawful governmental or regulatory requests, court orders, or other legally binding obligations, subject to applicable requirements.
13. Audit and Compliance Assistance
Where reasonably appropriate and consistent with the applicable agreement, NovaHR may provide information relevant to evaluating the security and processing practices applicable to the service.
Any audit or compliance assistance remains subject to reasonable security, confidentiality, operational and contractual limitations.
14. Termination and Data Handling
Customer Data handling following termination, cancellation or expiry of the applicable service should follow the applicable NovaHR agreement, operational procedures and legal requirements.
Specific deletion timelines are not stated in this draft because a confirmed NovaHR retention and deletion period has not yet been established.
15. Governing and Conflict Provisions
This DPA supplements the applicable NovaHR service agreement. Where provisions conflict, the applicable contractual documents should be interpreted according to their stated order of precedence.
The applicable governing-law framework for the NovaHR service is based generally on India, subject to the final terms of the governing agreement.
16. Contact
NovaHR by TradeNovaTech
support@tradenovatech.com
info@tradenovatech.com