Data Processing Agreement
Last updated: February 2025
1. Scope & Purpose
This Data Processing Agreement ("DPA") forms part of and supplements the Enterprise Services Agreement and Terms of Service between DARWN Inc. ("DARWN") and the entity using DARWN's services ("Client"). This DPA sets forth the parties' rights and responsibilities with respect to the processing of personal data in connection with DARWN's services.
2. Definitions
- "Personal Data" — Any information relating to an identified or identifiable natural person, including candidate names, contact information, NPI numbers, employment history, and performance data.
- "Processing" — Any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.
- "Data Controller" — The party that determines the purposes and means of Processing Personal Data.
- "Data Processor" — The party that Processes Personal Data on behalf of the Data Controller.
- "Data Subject" — The identified or identifiable natural person to whom Personal Data relates.
- "Sub-Processor" — Any third party engaged by DARWN to Process Personal Data on behalf of the Client.
3. DARWN as Data Controller
With respect to data collected directly from platform users (healthcare workers, hospitals, recruiters, and medical students), DARWN acts as the Data Controller. In this capacity, DARWN:
- Collects user registration data, account information, and trading activity
- Processes professional data including credentials, employment history, and performance metrics
- Maintains anonymized candidate profiles for marketplace display
- Generates aggregated analytics and risk reports
DARWN's processing of this data is governed by our Privacy Policy.
4. Client as Data Controller
With respect to candidate data that the Client receives through DARWN's services (including full candidate profiles and risk reports), the Client acts as an independent Data Controller. The Client:
- Determines how candidate data is used within its organization
- Is responsible for compliance with applicable data protection laws in its use of the data
- Must maintain appropriate data security measures
- Is responsible for responding to data subject requests related to data in its possession
5. Data Processing Obligations
5.1 Confidentiality
Both parties shall ensure that persons authorized to process Personal Data are under appropriate obligations of confidentiality, whether contractual or statutory.
5.2 Security Measures
DARWN implements and maintains appropriate technical and organizational measures to protect Personal Data, including:
- Encryption of data in transit and at rest
- Access controls and authentication mechanisms
- Regular security assessments and vulnerability testing
- Employee training on data protection
- Incident response procedures
5.3 Sub-Processors
DARWN may engage Sub-Processors to assist in providing services. DARWN will:
- Impose contractual obligations on Sub-Processors at the same level of protection as this DPA
- Remain liable for the acts and omissions of its Sub-Processors
- Maintain a list of current Sub-Processors available upon request
6. Data Subject Rights
DARWN will assist the Client, to the extent reasonably practicable, in responding to Data Subject requests to exercise their rights, including:
- Right of Access: The right to obtain confirmation of whether their data is being processed and to access that data
- Right of Correction: The right to request correction of inaccurate or incomplete data
- Right of Deletion: The right to request deletion of their data, subject to legal retention requirements
- Right of Portability: The right to receive their data in a structured, commonly used format
Data subject requests should be directed to privacy@darwn.com.
7. Data Retention & Deletion
DARWN retains Personal Data only for as long as necessary to fulfill the purposes for which it was collected or as required by law. Upon termination of the Client's account or upon written request:
- DARWN will delete or return Client-specific data within 30 days
- Anonymized and aggregated data may be retained for analytics purposes
- Data required to be retained by law will be retained for the legally required period only
8. Security Measures
DARWN maintains the following security measures to protect Personal Data:
- TLS/SSL encryption for all data in transit
- AES-256 encryption for data at rest
- Role-based access controls with least-privilege principles
- Multi-factor authentication for administrative access
- Regular backups with tested recovery procedures
- SOC 2 Type II compliance (when available)
- Regular penetration testing and security audits
9. Breach Notification
In the event of a security breach involving Personal Data, DARWN will:
- Notify the affected Client within 72 hours of becoming aware of the breach
- Provide details of the breach including the nature, scope, and affected data
- Describe the measures taken or proposed to address the breach
- Cooperate with the Client's own breach notification obligations
Breach notifications will be sent to the Client's designated security contact or, if none is designated, to the primary account contact.
10. Cross-Border Transfers
DARWN processes all data within the United States. Our infrastructure is hosted on US-based cloud services. If any data processing occurs outside the US, DARWN will:
- Ensure appropriate safeguards are in place (Standard Contractual Clauses or equivalent)
- Notify the Client prior to any cross-border transfer
- Comply with applicable cross-border data transfer regulations
11. Contact
For data protection inquiries:
DARWN Data Protection
Email: privacy@darwn.com
Data Protection Officer: dpo@darwn.com