Data Processing Agreement
TalentLeap AI Limited
Last updated: 18 August 2026
This Data Processing Agreement (“DPA”) applies where TalentLeap AI Limited (“TalentLeap”, the “Processor”) processes personal data on behalf of a client (the “Controller”) in the course of providing its recruitment services. It forms part of, and is subject to, the services agreement between the parties (the “Agreement”). Where there is any conflict on the subject of data protection, this DPA takes precedence.
1. Definitions
Terms such as “personal data”, “processing”, “data subject”, “controller”, “processor” and “personal data breach” have the meanings given to them in the UK GDPR. “Data protection law” means the UK GDPR, the Data Protection Act 2018, and any other law that applies to the processing of personal data under this DPA. “Subprocessor” means any processor engaged by TalentLeap to process personal data under this DPA.
2. Roles of the parties
The Controller determines the purposes and means of the processing. TalentLeap processes personal data only as a processor on behalf of the Controller for the purposes of providing the services. The details of the processing are set out in Annex 1.
3. TalentLeap’s obligations
TalentLeap will:
- process personal data only on the documented instructions of the Controller, including as set out in the Agreement and this DPA, unless required to do otherwise by law, in which case it will inform the Controller first unless the law prohibits this;
- make sure that people authorised to process the personal data are bound by an obligation of confidentiality;
- put in place the technical and organisational security measures described in Annex 2;
- respect the conditions in clause 5 for engaging a subprocessor;
- taking into account the nature of the processing, assist the Controller by appropriate measures to respond to requests from data subjects exercising their rights;
- assist the Controller in meeting its obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the information available to TalentLeap;
- at the choice of the Controller, delete or return all personal data at the end of the services and delete existing copies, unless the law requires the data to be kept;
- make available to the Controller the information necessary to demonstrate compliance with this clause, and allow for and contribute to audits conducted by the Controller or an auditor it appoints, on reasonable notice.
4. Personal data breach
TalentLeap will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s personal data, and will provide the Controller with the information it reasonably needs to meet its own obligations to report the breach.
5. Subprocessors
The Controller gives TalentLeap general authorisation to engage subprocessors to support the services. The current subprocessors are listed in Annex 3. TalentLeap will inform the Controller of any intended change to its subprocessors and give the Controller the opportunity to object. TalentLeap will impose on each subprocessor data protection obligations that are equivalent to those in this DPA, and remains responsible to the Controller for the performance of each subprocessor.
6. International transfers
TalentLeap will not transfer personal data outside the United Kingdom without making sure that an appropriate safeguard is in place, such as an adequacy decision or the International Data Transfer Agreement, so that the personal data continues to receive an equivalent level of protection.
7. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
8. Term
This DPA takes effect on the same date as the Agreement and continues for as long as TalentLeap processes personal data on behalf of the Controller.
9. Governing law
This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute.
Annex 1: Details of the processing
Subject matter. The provision of recruitment services by TalentLeap to the Controller.
Duration. For the term of the Agreement and any period afterwards during which TalentLeap is required to retain the personal data.
Nature and purpose. Sourcing, screening, referencing, shortlisting and placing candidates, arranging interviews and placements, and managing the associated administration on behalf of the Controller.
Types of personal data. Names and contact details, work history and qualifications, references, right to work and identity information, salary and rate information, interview and assessment notes, and where relevant tax and payment details.
Categories of data subjects. Candidates and workers introduced or placed by TalentLeap, and the Controller’s own staff involved in the hiring process.
Annex 2: Security measures
TalentLeap applies appropriate technical and organisational measures, including access controls on systems that hold personal data, encryption of data in transit and at rest where appropriate, restricted and role based access, secure authentication, confidentiality obligations on staff and contractors, regular review of access, and processes for detecting, reporting and responding to personal data breaches.
Annex 3: Subprocessors
The Controller authorises the following categories of subprocessor:
- cloud hosting and database providers;
- email and communications providers;
- screening and referencing providers, where used;
- other service providers engaged to support the recruitment services.
A current list of named subprocessors is available from TalentLeap on request at privacy@talentleap.ai.
