Data Processing Addendum
Effective date: August 23, 2026 · Version 1.0
This Data Processing Addendum (“DPA”) forms part of the Customer Terms of Service at correlia.ai/legal/terms (the “Terms”) between the customer identified in the Order Form or account registration (“Customer”) and Correlia Inc. (“Correlia”). It governs Correlia’s processing of Customer Personal Data in providing the Services and prevails over the Terms on data-protection matters. The Customer accepts this DPA by accepting the Terms, signing an Order Form that references them, or using the Services, and does so on behalf of any affiliate using the Services under its account.
1. Definitions
Capitalised terms not defined here have the meanings given in the Terms.
1.1 “AI Hiring Laws” means laws regulating artificial intelligence or automated decision-making in recruitment or employment, including the Illinois Artificial Intelligence Video Interview Act, the Illinois Human Rights Act, New York City Local Law 144, California’s automated-decision rules, Colorado Senate Bill 26-189, Maryland’s facial-recognition waiver law and the EU AI Act (Regulation (EU) 2024/1689).
1.2 “Applicable Data Protection Law” means all laws applying to the processing of Personal Data under this DPA, including the GDPR (Regulation (EU) 2016/679); the UK GDPR and the Data Protection Act 2018; the Swiss Federal Act on Data Protection (the “FADP”); the California Consumer Privacy Act, as amended, and its regulations (the “CCPA”) and other US state privacy laws where they apply; Brazil’s LGPD; Canada’s PIPEDA; and any other applicable privacy law, as amended.
1.3 “Candidate” means an individual whose Personal Data the Customer imports into the Services or who is invited to interview or evaluated through the Services.
1.4 “Customer Personal Data” means Personal Data that Correlia processes on the Customer’s behalf in providing the Services, including data about Candidates and about Authorised Users held in the Customer’s workspace.
1.5 “Personal Data” means information relating to an identified or identifiable natural person, including “personal information” under the CCPA. Other terms such as “processing”, “controller”, “processor”, “business”, “service provider”, “sell” and “share” have the meanings given in Applicable Data Protection Law.
1.6 “Restricted Transfer” means a transfer of Customer Personal Data from the EEA, the United Kingdom or Switzerland that would be unlawful without a transfer mechanism under the GDPR, the UK GDPR or the FADP.
1.7 “SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
1.8 “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data held by Correlia or a Sub-processor, excluding unsuccessful attempts.
1.9 “Sub-processor” means a third party engaged by Correlia to process Customer Personal Data on Correlia’s behalf.
1.10 “UK Addendum” means the UK Information Commissioner’s International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, in force from 21 March 2022.
1.11 “Optional Training Consent” has the meaning given in Section 5.
2. Roles and scope
2.1 Customer as controller. For Customer Personal Data processed to deliver the Services (resume intake, invitations, interviews conducted by Corra, scoring, integrity reports, storage and Integrations), the Customer is the controller or business and Correlia is the processor or service provider.
2.2 Correlia’s limited independent purposes. Correlia acts as an independent controller only for these limited purposes: (a) operating, securing and protecting the platform, including preventing abuse and fraud directed at the platform and keeping security logs; (b) complying with law and responding to legal requests; (c) service analytics and product improvement using de-identified or aggregated data that identifies no Candidate, Authorised User or Customer; (d) training and improving Correlia’s own AI models using interview recordings, only with the Candidate’s Optional Training Consent and only where the Customer has not disabled that option; and (e) communicating directly with Candidates about their data-protection rights. These purposes, and Correlia’s role as controller of Authorised Users’ account data, are described in the Privacy Policy (correlia.ai/legal/privacy) and Candidate Privacy Notice (correlia.ai/legal/candidate-privacy-notice).
2.3 Article 28(10). If Correlia determines the purposes and means of processing Customer Personal Data in breach of this DPA, it is treated as a controller of that processing under Article 28(10) GDPR. Processing under Section 2.2 is not such a breach.
3. Customer instructions and obligations
3.1 Documented instructions. The Customer’s complete instructions are the Terms, this DPA, any Order Form, the Customer’s configuration of the Services (including retention and interview settings, the Optional Training Consent setting and enabled Integrations) and any further written instructions the parties agree.
3.2 Lawfulness and notices. The Customer is responsible for: (a) a lawful basis for the processing of Customer Personal Data and for the interview, scoring and integrity-report features it uses; (b) giving Candidates and Authorised Users the notices Applicable Data Protection Law requires, including the Candidate Privacy Notice, the Candidate Interview Terms (correlia.ai/legal/candidate-terms) and the AI Transparency Statement (correlia.ai/legal/ai-transparency); (c) any consents Applicable Data Protection Law or AI Hiring Laws require; and (d) any data protection impact assessment or prior consultation its use of the Services requires, with Correlia’s assistance under Section 10.
3.3 AI Hiring Laws. The Customer is the employer or hiring decision-maker and is responsible for the duties AI Hiring Laws place on employers and deployers, including notices, consents, bias audits, opt-out and appeal rights, record-keeping and an alternative process on request. The Customer will ensure meaningful human review of AI outputs before any hiring decision, will not reject a Candidate solely on the basis of an AI score or integrity report, and will not remove or obscure the disclosures the Services present to Candidates, including that Corra is an AI interviewer with a computer-generated face and voice.
3.4 Retention. The Customer configures how long recordings, transcripts, AI outputs and integrity signals are retained; the default is 12 months after the interview. The Customer may delete Customer Personal Data earlier at any time.
3.5 Candidate data confidentiality. The “Candidate Data Confidentiality and Use Restrictions” section of the Terms allows the Customer and its Authorised Users to access recordings, transcripts, scores, summaries and integrity reports only inside the Services (or through Correlia-provided Integrations and exports) and only to evaluate the Candidate for the relevant Vacancy; prohibits downloading, copying, screen-recording or redistributing them, sharing them outside the hiring decision, or using them to train AI models or to re-identify or profile Candidates; and requires notice to Correlia of any unauthorised access or disclosure.
4. Correlia’s obligations
4.1 Instructions. Correlia will process Customer Personal Data only on the Customer’s documented instructions, unless law applicable to Correlia requires otherwise, in which case Correlia will inform the Customer before processing unless the law prohibits this.
4.2 Infringing instructions. Correlia will promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
4.3 Confidentiality. Personnel processing Customer Personal Data are bound by written or statutory confidentiality obligations and access data only as needed for their role.
4.4 No sale, sharing or third-party training. Correlia will not sell or share Customer Personal Data, use it for cross-context behavioural advertising, or use it to train third parties’ general-purpose AI models. Third-party AI providers are contractually prohibited from training on Correlia data.
4.5 CCPA service provider. Where the CCPA applies, Correlia is a service provider for the business purpose of providing the Services. Correlia certifies that it will not sell or share Customer Personal Data; will not retain, use or disclose it outside that business purpose or the direct business relationship between the parties, except as the CCPA permits; will not combine it with Personal Data from other sources except as the CCPA regulations permit; and will notify the Customer promptly if it can no longer meet its CCPA obligations. Annex 4 applies.
5. Optional Training Consent
5.1 Mechanism. Before an interview begins, the Services show each Candidate a separate, optional checkbox, unchecked by default, asking whether Correlia may use the interview recording (video, audio and transcript) to train and improve Correlia’s own AI models (the “Optional Training Consent”). The choice has no effect on the interview or application, and the Candidate may withdraw at any time at ntitov@correlia.ai.
5.2 Customer control. The Customer may disable the Optional Training Consent for its Candidates at any time through the “Allow Optional Training Consent for my candidates” setting in the Services (enabled by default) or by written notice to ntitov@correlia.ai. Disabling removes the checkbox from later interviews; consents already given remain valid unless withdrawn.
5.3 Correlia’s role. Where a Candidate gives the Optional Training Consent, Correlia processes the recording for that purpose as an independent controller. Correlia is responsible for the validity and records of the consent and for honouring withdrawals, and relies on it as explicit consent under Article 9(2)(a) GDPR and as a written release under the Illinois Biometric Information Privacy Act. Sections 3, 6, 11 and 13 do not apply to the training copy, which Correlia keeps separately.
5.4 Limits. Correlia will not use those recordings to produce outputs that depict the Candidate or reproduce the Candidate’s face, voice or likeness, and will not create face templates, voiceprints or other identifiers that uniquely identify the Candidate.
5.5 Withdrawal. On withdrawal, Correlia removes the recording from its training datasets within 30 days and no longer uses it for training; models already trained are not retrained. A Candidate’s request to delete their interview is treated as a withdrawal.
6. Sub-processors
6.1 General authorisation. The Customer authorises Correlia to engage Sub-processors for the purposes in Annex 1. The current Sub-processors are listed on the Sub-processor List at correlia.ai/legal/sub-processors, incorporated as Annex 3. Integrations the Customer connects receive data only on the Customer’s instruction and are not Sub-processors.
6.2 Notice. Correlia will give at least 30 days’ written notice before a new or replacement Sub-processor processes Customer Personal Data, by email to the Customer’s administrator or designated privacy contact and to subscribers to Sub-processor List notifications.
6.3 Objection. The Customer may object within 10 business days after the notice on reasonable data-protection grounds. If the parties cannot resolve the objection in good faith within 30 days, the Customer may terminate the affected Services on written notice and receive a refund of prepaid fees for the period after termination.
6.4 Flow-down. Correlia will bind each Sub-processor by written contract to obligations no less protective than this DPA, including the terms required by Article 28(4) GDPR and a transfer mechanism for any Restricted Transfer.
6.5 Liability. Correlia remains liable for its Sub-processors’ acts and omissions as for its own.
7. Security
7.1 Measures. Correlia will implement and maintain appropriate technical and organisational measures, described in Annex 2, including at least: TLS encryption in transit and AES-256 encryption at rest; multi-factor authentication for Correlia personnel with production access, and available to Authorised Users; least-privilege access controls; logging and monitoring; encrypted backups; vulnerability management; secure development; personnel training; vendor assessments; and business continuity planning. Correlia may update Annex 2 without materially reducing protection.
7.2 Customer responsibilities. The Customer is responsible for its own systems and Integrations, its Authorised Users’ credentials, secure configuration of the Services and data it exports.
8. Security Incidents
8.1 Notification. Correlia will notify the Customer without undue delay, and in any event within 48 hours, after confirming a Security Incident affecting Customer Personal Data.
8.2 Contents. The notice will describe, to the extent known, the nature of the incident, the categories and approximate number of affected data subjects and records, the likely consequences, the measures taken or proposed, and a contact point.
8.3 Cooperation. Correlia will take reasonable steps to contain and remediate the incident and will reasonably assist the Customer with its own notification obligations. The Customer decides whether and how to notify regulators and data subjects.
8.4 No admission. A notification is not an acknowledgement of fault or liability.
9. Data subject and consumer requests
9.1 Forwarding. If Correlia receives a request from a Candidate or other data subject to exercise rights in relation to Customer Personal Data, Correlia will forward it to the Customer within 5 business days and will not respond substantively unless the Customer instructs otherwise or law requires.
9.2 Tools and assistance. The Services let the Customer access, export, correct and delete Candidate data. Taking into account the nature of the processing, Correlia will give further reasonable assistance so that the Customer can respond within statutory time limits.
9.3 Illinois deletion cascade. Where a Candidate requests deletion of a video interview under the Illinois Artificial Intelligence Video Interview Act, the Customer will forward or confirm the request to Correlia without delay, and Correlia will delete the recording and all copies in its control, and instruct any Sub-processor holding a copy to delete it, within 30 days after the Candidate’s request. If the Customer does not respond to a forwarded request within 10 business days, it authorises Correlia to complete the deletion.
9.4 Automated decision-making. Corra’s outputs are decision support for the Customer’s human reviewers. The Customer handles individuals’ rights in relation to automated decisions, with the support described in Section 10.
9.5 Correlia as controller. Correlia may respond directly to requests relating to processing for which it is a controller under Section 2.2, including withdrawals of the Optional Training Consent.
10. Assistance
10.1 Impact assessments. Correlia will provide the information reasonably required for the Customer’s data protection impact assessments and prior consultations, including Annexes 1 and 2, the AI Transparency Statement and a summary of Correlia’s transfer impact assessment.
10.2 AI documentation. Correlia will provide instructions for use, descriptions of the characteristics Corra evaluates and the data used, human-oversight guidance and log retention supporting the Customer’s deployer duties under Article 26 of the EU AI Act; developer documentation under Colorado Senate Bill 26-189; and the data-retention policy text required by New York City Local Law 144. Correlia will cooperate reasonably with independent bias audits the Customer commissions.
10.3 Records. Correlia keeps the records required by Article 30(2) GDPR, will provide relevant extracts on request, and will cooperate with supervisory authorities.
11. Audits
11.1 Information. Correlia will make available all information necessary to demonstrate compliance with this DPA and Article 28 GDPR. Annually on request, Correlia will provide its current security documentation, summaries of independent audit reports or certifications it holds (a SOC 2 Type II audit is planned) and penetration-test summaries.
11.2 Remote audit. If that information is insufficient, the Customer may conduct a remote audit through written questions and document review.
11.3 On-site audit. The Customer, or an independent auditor bound by confidentiality, may audit Correlia’s premises and systems once in each 12-month period, on at least 30 days’ written notice, during business hours, for an agreed scope, without unreasonable disruption or risk to other customers’ data, and at the Customer’s cost. On-site audits do not extend to Sub-processor facilities; Correlia provides their audit reports instead. Findings are Confidential Information, and Correlia will remedy material non-compliance.
11.4 Regulator audits. Correlia will cooperate with inspections by a competent supervisory authority or regulator, and the SCCs’ audit provisions apply to Restricted Transfers.
12. International transfers
12.1 Data location. Customer Personal Data is hosted in the United States on Amazon Web Services and Correlia and its Sub-processors process it in the United States.
12.2 EEA transfers. For Restricted Transfers from the EEA, the SCCs are incorporated by reference with the Customer as data exporter and Correlia as data importer: Module Two where the Customer is a controller, and Module Three where the Customer acts as a processor for its own clients. The SCCs are completed as follows: Clause 7 (docking) applies; Clause 9(a): Option 2 (general authorisation) with 30 days’ notice; Clause 11(a): the optional language is not used; Clause 13: the competent supervisory authority is determined under Annex 1, Part C; Clause 17: Option 1, the laws of Ireland; Clause 18(b): the courts of Ireland; Annexes I, II and III: Annexes 1, 2 and 3 of this DPA. Onward transfers to Sub-processors use Module Three or another mechanism permitted by Clause 8.8.
12.3 UK transfers. For Restricted Transfers from the United Kingdom, the UK Addendum is incorporated by reference and amends the SCCs as set out in its Part 2. Table 1 is completed with the parties’ details in the Order Form and Annex 1, Table 2 with the SCCs, modules and options in Section 12.2, Table 3 with Annexes 1, 2 and 3 of this DPA, and Table 4 so that either party may end the UK Addendum under its Section 19.
12.4 Swiss transfers. For Restricted Transfers from Switzerland, the SCCs apply with these adaptations: references to the GDPR are read as references to the FADP; the competent supervisory authority under Clause 13 and Annex 1, Part C, is the Swiss Federal Data Protection and Information Commissioner (FDPIC); and “Member State” is not read so as to prevent data subjects in Switzerland from bringing claims in Switzerland under Clause 18(c).
12.5 Data Privacy Framework and fallback. Correlia is not currently certified under the EU-US Data Privacy Framework, its UK Extension or the Swiss-US Data Privacy Framework and intends to self-certify once it is eligible. If Correlia later self-certifies, the parties may rely on the Data Privacy Framework in addition to the SCCs and the UK Addendum, which remain in place. If any mechanism relied on is invalidated or ceases to be available, the remaining mechanism continues to apply, and the parties will cooperate in good faith to adopt an alternative without delay.
12.6 Transfer impact assessment. Correlia has assessed the laws and practices of the United States applying to this processing and will provide a summary on request. Correlia applies the supplementary measures in Annex 2 and the procedure in Section 12.7.
12.7 Government access requests. If Correlia receives a legally binding request from a public authority for Customer Personal Data, it will: (a) promptly notify the Customer unless legally prohibited; (b) review the legality of the request and challenge it where there are reasonable grounds to consider it unlawful; (c) disclose only the minimum data required; (d) not give any public authority voluntary, direct or bulk access; and (e) document such requests and share available information with the Customer where legally permitted.
13. Return and deletion
13.1 During the term. The Customer may export Customer Personal Data at any time through the Services’ export features, subject to the use restrictions in the Terms.
13.2 After termination. For 30 days after termination or expiry of the Terms, Correlia will keep the Customer’s export features available. Correlia will then delete Customer Personal Data within 30 days and instruct Sub-processors to do the same. Backup copies are deleted or overwritten within 90 days after termination or expiry. On written request, Correlia will confirm deletion in writing.
13.3 Retention required by law. Correlia may retain Customer Personal Data to the extent and for as long as law applicable to Correlia requires. As a controller, Correlia also retains Candidate consent records, held separately from recordings, for 5 years after the interview, and training copies under Section 5.
14. Liability
14.1 The total combined liability of Correlia and its affiliates, and of the Customer and its affiliates, arising out of this DPA, the SCCs and the UK Addendum is subject to the limitations and exclusions of liability in the Terms and counts towards the aggregate liability limit in the Terms. This Section does not limit either party’s liability to data subjects under Clause 12 of the SCCs or any liability that cannot be limited by law.
15. Term, precedence, changes and governing law
15.1 Term. This DPA takes effect when the Customer accepts the Terms and continues until Correlia has deleted or returned all Customer Personal Data under Section 13.
15.2 Precedence. This DPA prevails over the Terms on data-protection matters. For a Restricted Transfer, the SCCs and the UK Addendum prevail over this DPA.
15.3 Changes. Correlia may update this DPA to reflect changes in Applicable Data Protection Law, transfer mechanisms or the Services, giving at least 30 days’ notice of material changes. If a change materially reduces the protection of Customer Personal Data, the Customer may object in writing within that period and, if the objection is not resolved in good faith, terminate the affected Services on written notice.
15.4 Governing law and notices. This DPA is governed by the law and courts set out in the Terms (the laws of the State of Delaware and the state and federal courts located in Delaware), except that the SCCs and the UK Addendum are governed by the law and courts specified in Sections 12.2 to 12.4. Notices to Correlia under this DPA go to ntitov@correlia.ai.
Annex 1 — Description of Processing
This Annex also serves as Annex I to the SCCs and as the Appendix Information for the UK Addendum.
A. Parties
Data exporter: the Customer (details in the Order Form or account registration); role: controller, or processor where Module Three applies.
Data importer: Correlia Inc., 630 Chapel St., New Haven, CT 06510, USA, ntitov@correlia.ai; role: processor. EU and UK representatives: Correlia will publish the details of its EU and UK representatives once they are appointed.
B. Description of processing
Subject matter: the Correlia platform, through which the Customer manages Vacancies, invites Candidates and has Corra conduct recorded video interviews and produce transcripts, evaluations, scores, summaries and integrity reports.
Duration: the term of the Terms plus the export and deletion periods in Section 13.
Nature and purpose: collection, storage, transcription, analysis, evaluation, disclosure on the Customer’s instruction (including to Integrations) and deletion, to support the Customer’s recruitment and selection of Candidates and to host, support and secure the Services.
Data subjects: Candidates; the Customer’s Authorised Users to the extent their data is held in the Customer’s workspace; and, incidentally, other individuals mentioned in resumes or answers.
Categories of Personal Data:
- Identity and contact data: name, email, phone, links such as LinkedIn profiles, and a photo if included in the resume.
- Resume and profile data: work history, education, skills, languages, location, salary expectations and anything else the Candidate or Customer includes, including data imported from the Customer’s ATS (Ashby, Greenhouse), job boards (hh.ru), public professional profiles (LinkedIn import or search) or spreadsheets.
- Interview recording: video and audio of the Candidate for the whole interview, and screen and code input in the live-coding widget.
- Transcript of the Candidate’s answers and Corra’s questions.
- AI-generated outputs: scores, per-question evaluations, summaries, requirements-match results and the integrity report.
- Integrity signals: browser window focus and visibility events, copy and paste events and counts, answer timing, text-pattern features of answers, video presence events (whether a person is present on camera, whether more than one person appears, camera interruptions), approximate location (country) derived from IP address, device and browser type, IP address, and interview language or locale; a temporary face template used for the same-person check and deleted automatically when the interview ends.
- Technical and usage data: log data, timestamps, IP address, device identifiers and cookies.
- Communications: invitation emails, messages sent through job-board or ATS Integrations, and support correspondence.
- Hiring-process data recorded by the Customer: pipeline stage, decisions, rejection reasons, comments and offer dates.
Special categories: the integrity check creates a temporary biometric face template during each interview, used solely to confirm that the same person remains on camera and deleted automatically when the interview ends; it is processed on the basis of the Candidate’s explicit pre-interview consent. No other special categories are intended. The Customer must not configure interviews, job requirements or questions to elicit special categories of data; a Candidate may nevertheless volunteer such information in a resume or answer, and it is then processed only as part of the recording or transcript and is not used for scoring. Correlia creates no voiceprints and does not identify Candidates against external databases, and the Customer must not use the Services to identify Candidates by those means.
Frequency: continuous for the duration of the Services.
Retention: recordings, transcripts, AI outputs and integrity signals for the period the Customer configures, by default 12 months after the interview, or until earlier deletion by the Customer; all Customer Personal Data is deleted after termination under Section 13.
Transfers to Sub-processors: the Sub-processors in Annex 3 process the categories above in the United States for the purposes shown on the Sub-processor List.
C. Competent supervisory authority
Under the GDPR: the authority of the EU or EEA member state in which the Customer is established or, if the Customer is not established in the EEA, in which its Article 27 representative is established or the data subjects are predominantly located. Under the UK GDPR: the Information Commissioner. Under the FADP: the FDPIC.
Annex 2 — Technical and Organisational Measures
This Annex also serves as Annex II to the SCCs.
- Security programme and governance. Written security policies approved by management and reviewed annually; a named security owner; a documented risk assessment process. Independent assurance: a SOC 2 Type II audit is planned.
- Access control and authentication. Role-based, least-privilege access; unique accounts; multi-factor authentication for all production, code-repository and administrative access; periodic access reviews; prompt removal on departure.
- Encryption. TLS 1.2 or higher in transit; AES-256 at rest for databases, object storage (including recordings) and backups; managed keys with restricted access and rotation.
- Tenant isolation. Each Customer’s data logically separated through workspace-scoped identifiers enforced in the application and data layers; production and non-production environments separated.
- Network and infrastructure security. Private networks with restricted ingress; firewalls and security groups; cloud-platform denial-of-service protection.
- Logging and monitoring. Centralised logging of authentication events, administrative actions and access to Customer Personal Data; alerting on suspicious activity; tamper-protected logs retained for 12 months.
- Vulnerability management and testing. Automated dependency and container scanning; patching of critical vulnerabilities on a defined timeline; independent penetration testing at least annually once the programme is in place.
- Secure development. Code review for all changes; separation of duties for deployment; secrets management; security and privacy review of features that process Candidate data; testing before release.
- AI and model safeguards. Third-party AI providers used only under terms prohibiting training on Correlia data; model changes reviewed for accuracy and bias impact before release.
- Backups, continuity and incident response. Encrypted daily backups stored separately within the hosting region; restoration procedures tested periodically; a documented business continuity and disaster recovery plan; a documented incident response plan with an on-call rotation and post-incident reviews.
- Personnel security and training. Written confidentiality obligations for all personnel; security and privacy training at onboarding and annually; managed staff devices.
- Vendor and Sub-processor management. Security and privacy assessment before engagement; written contracts with data-protection terms; periodic review of audit reports and certifications.
- Physical security and data handling. Production infrastructure hosted in Amazon Web Services data centres with physical access controls and independent certifications, including SOC 2 and ISO 27001; Customer-configurable retention with automated deletion; consent records held separately from recordings.
Annex 3 — Sub-processors
The Sub-processor List at correlia.ai/legal/sub-processors is incorporated by reference as Annex III to the SCCs and states each Sub-processor’s name, purpose and location. Avatar rendering and voice synthesis for Corra, and the large language models used for interview dialogue, evaluation and summaries, run on Correlia’s own and open-source models on Correlia’s infrastructure and involve no Sub-processor.
Annex 4 — CCPA Service Provider Terms
These terms apply where the CCPA applies to Customer Personal Data and supplement Section 4.5. “Business Purpose” means providing the Services under Annex 1 and the other purposes the CCPA permits a service provider, consistently with Section 2.2.
- Correlia is a service provider to the Customer, which is the business, and receives Customer Personal Data only for the Business Purpose.
- Correlia will not sell or share Customer Personal Data.
- Correlia will not retain, use or disclose Customer Personal Data for any purpose, including any commercial purpose, other than the Business Purpose, or outside the direct business relationship with the Customer.
- Correlia will not combine Customer Personal Data with personal information from another source, except as the CCPA regulations permit.
- Correlia will comply with the CCPA and provide the same level of privacy protection it requires of businesses.
- The Customer may take reasonable and appropriate steps to ensure Correlia’s compliance and to stop and remediate unauthorised use.
- Correlia will notify the Customer within 5 business days if it can no longer meet its CCPA obligations.
- Correlia will engage sub-contractors only under written contracts imposing the same obligations and will not attempt to re-identify de-identified data.
- Correlia certifies that it understands these restrictions and will comply with them.