Version 2026-10
This Data Processing Agreement (“DPA”) shares its version with our Privacy Policy and our Sub-processors list. A new version of one is a new version of all three (Privacy Policy, section 2.1).
1. Parties and scope
This DPA is between Wipperoz Pty Ltd (ACN 623 500 603) (“Wipperoz”, the “Processor”) and the organisation that holds an Orbit account (the “Customer”, the “Controller”). It forms part of the Wipperoz Terms and Conditions that govern the Customer’s use of Orbit (the “Agreement”).
It applies to personal data that Wipperoz processes on the Customer’s behalf when providing Orbit (“Customer Personal Data”). It does not apply to personal data for which Wipperoz is itself a controller, such as a candidate’s own Wipperoz account, Virtual CVs and the applications they send, which are governed by the Privacy Policy.
The Customer agrees to the Terms and Conditions and the Privacy Policy when it signs up for Orbit. This DPA applies from when the Customer first uses Orbit, as part of the Agreement. The version that applies is the one published when the processing takes place.
This DPA is written to meet Article 28 of the EU and UK General Data Protection Regulation (“GDPR”), the Australian Privacy Act 1988 (Cth), and Brazil’s Lei Geral de Proteção de Dados (“LGPD”) (together, “Data Protection Law”). Terms such as controller, processor, personal data, data subject and personal data breach have the meaning given in the GDPR.
2. Subject matter and duration
- Subject matter — the processing of Customer Personal Data needed to provide Orbit to the Customer under the Agreement
- Duration — for as long as the Customer has an Orbit account, and then until Customer Personal Data is deleted under section 12
3. Nature and purpose of the processing
Wipperoz processes Customer Personal Data to:
- Host the Customer’s roles, careers pages and applications
- Receive applications and invitations, and show them to the Customer’s team
- Store the Customer’s notes, decisions, offers, hiring stages and application history
- Score each applicant’s fit for a role, assess it with AI when the Customer asks or has turned on role automations, and run the role automations the Customer turns on
- Import the CVs the Customer uploads, and email the people in them
- Run AI screening interviews the Customer asks for, and produce their findings
- Schedule interviews, including reading free/busy times from calendars the Customer’s users connect
- Send emails the Customer’s use of Orbit triggers, including telling candidates when they move stage, and, when a role automation rejects them, that the decision was made automatically (Privacy Policy, section 20.2)
- Apply the Customer’s retention setting, and delete or de-identify data when it ends
- Help the Customer answer requests from data subjects
- Keep Orbit secure, and provide support
The processing involves storage, retrieval, organisation, display, transmission, AI analysis, de-identification and deletion.
4. Categories of data subjects
- Applicants and candidates for the Customer’s roles, including people invited to apply
- People whose CVs the Customer imports into Orbit
- Candidates a recruitment agency presents to its clients through Orbit
- The Customer’s users: its team members, including former team members, and colleagues they invite
- People outside the Customer who take part in its interviews
- The Customer’s clients’ reviewers, where the Customer is a recruitment agency
5. Categories of personal data
- Identity and contact details: name, email address, phone number, location
- CVs the Customer imports: the person’s name, email address and CV file
- Hiring records the Customer creates: notes, decisions, offers (including the amount), hiring stage and history, and how often its team viewed a candidate
- AI fit assessments of applicants: a score, the reasons for it, and comments
- AI screening interviews: answers, transcripts and findings, including how each answer was typed (section 19 of the Privacy Policy)
- Interviews: times, formats, notes, and the names and email addresses of the people taking part
- Candidates the Customer keeps in its My candidates list
- Calendar free/busy times and the email address of a connected calendar
- Team members’ account details and their activity in Orbit
What a candidate sends when they apply — their application, CV, answers and the consent they gave — and their own Wipperoz account and Virtual CVs are held by Wipperoz as a controller, under the Privacy Policy (section 18.1). The Customer receives them as part of Orbit, and Wipperoz applies the Customer’s retention setting to the Customer’s copy.
The Customer should not ask applicants for special-category data (for example health, religion or ethnic origin) through Orbit unless the law allows it and the Customer has a lawful basis. Orbit does not ask for it.
6. The Customer’s instructions
Wipperoz processes Customer Personal Data only on the Customer’s documented instructions. The Agreement, this DPA, and the Customer’s use and configuration of Orbit are those instructions.
Wipperoz will tell the Customer if, in its opinion, an instruction breaches Data Protection Law, and may suspend that processing until the instruction is confirmed or changed. If the law requires Wipperoz to process Customer Personal Data otherwise, it will tell the Customer first, unless the law forbids it.
The Customer is responsible for having a lawful basis for the processing, for giving data subjects the information the law requires, and for the lawfulness of its instructions.
7. Wipperoz’s obligations
Wipperoz will:
- Process Customer Personal Data only for the purposes in section 3
- Not sell Customer Personal Data, not use it for its own purposes, and not combine it with data from other customers
- Not use Customer Personal Data to train AI models, and not allow its sub-processors to
- Ensure that everyone authorised to process Customer Personal Data is bound by confidentiality
- Give access to Customer Personal Data only to staff who need it to provide Orbit or support
8. Sub-processors
The Customer gives Wipperoz general authorisation to engage sub-processors. The current sub-processors, what each one does and where it processes data, are on the Sub-processors list.
- Wipperoz will tell the Customer at least 30 days before adding or replacing a sub-processor, by email to the account’s Admins and by publishing a new version of the Sub-processors list
- The Customer may object on reasonable data protection grounds within those 30 days. The parties will discuss the objection in good faith. If it cannot be resolved, the Customer may close its Orbit account and receive a refund of any prepaid, unused fees for Orbit
- Wipperoz will impose on each sub-processor, by written contract, data protection obligations no less protective than this DPA, and remains responsible to the Customer for each sub-processor’s performance
9. Security
Wipperoz maintains technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit (TLS), and encryption at rest with keys managed by AWS
- Access control: each Orbit request is authorised against the Customer’s account and the user’s role in it
- Logical separation of each customer’s data within Orbit
- Access for staff only where they need it
- Monitoring and alerting for errors and failures
- Point-in-time backups of our database, which let us restore data from any moment in the last 35 days
- Regular review of these measures
10. Help with data subject requests
Taking into account the nature of the processing, Wipperoz will help the Customer respond to requests from data subjects to exercise their rights:
- On the Customer’s request to privacy@wipperoz.com, Wipperoz will find, export, correct or erase one candidate’s data held by the Customer’s account. Orbit has no self-service tool for one candidate’s data; the Customer’s Admins can export the whole account’s data themselves (section 12)
- If Wipperoz receives a request about Customer Personal Data, it will pass it to the Customer without undue delay and will not answer it itself, except to tell the person that it has done so
- Wipperoz will also help the Customer with data protection impact assessments and consultations with regulators, where these relate to Orbit
11. Personal data breaches
Wipperoz will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the measures taken or proposed. Wipperoz will update the Customer as more becomes known, and will help the Customer meet its own notification obligations, including under Australia’s Notifiable Data Breaches scheme.
12. Deletion and return at the end
- During the account — the Customer’s Admins can export the account’s data at any time while the account is open, in Settings → Account → Data & privacy → Export the company’s data, and download the file from that screen for 7 days. The Customer can also ask for a copy by emailing privacy@wipperoz.com. Applications to a closed role are de-identified after the Customer’s retention setting: 12 months by default, adjustable by an Admin between 6 and 24 months. De-identification covers the application and its hiring records. It does not cover screening findings or interview records, which are kept until the account is closed (a candidate can remove their answers and quotes from findings), or the My candidates list, whose entries are kept until the Customer removes them, the candidate ends the Customer’s access, or the account is closed
- When the account is closed — only an Admin can close the account. Deletion starts straight away and cannot be undone: Wipperoz deletes the Customer’s roles, applications, hiring records, imports, screenings, interviews and team members. The Customer should export what it needs before it closes the account
- Exceptions — Wipperoz keeps a record of the deletion, which contains the team members’ email addresses, for 90 days; the record of credits and usage, and invoices and payment records, for as long as Australian record-keeping law requires; and Virtual CVs created from imported CVs, which belong to the people in them and are deleted after 90 days if not claimed (Privacy Policy, section 12.5). Copies in backups are overwritten within 35 days
13. Audits
Wipperoz will make available to the Customer the information reasonably needed to demonstrate compliance with this DPA, including written answers to a reasonable security questionnaire once a year.
Where that information is not enough, or a regulator requires it, the Customer may carry out an audit, itself or through an independent auditor bound by confidentiality, on at least 30 days’ notice, during business hours, at its own cost, and no more than once a year unless a breach has occurred. Wipperoz may rely on its sub-processors’ own certifications and audit reports for the parts of the service they provide.
14. International transfers
Wipperoz is based in Australia. Customer Personal Data is hosted by Amazon Web Services in the United States (us-east-1, Northern Virginia), and some sub-processors process it in other countries, as the Sub-processors list shows.
Where the GDPR or the UK GDPR applies to a transfer of Customer Personal Data to a country without an adequacy decision, the parties agree that the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), Module Two (controller to processor), together with the UK International Data Transfer Addendum, apply to that transfer and are incorporated into this DPA by reference. Where the LGPD applies, the standard contractual clauses approved by the ANPD apply in the same way.
Wipperoz will ensure that its sub-processors have equivalent transfer safeguards in place.
15. Liability and precedence
Each party’s liability under this DPA is subject to the limits in the Agreement, except where Data Protection Law does not allow it to be limited. If this DPA and the Agreement conflict about the processing of Customer Personal Data, this DPA prevails. If this DPA and the Standard Contractual Clauses conflict, the Standard Contractual Clauses prevail.
Questions about this DPA, objections to a sub-processor, and requests for audit information: privacy@wipperoz.com