LEGAL
Data Processing Addendum
Last Updated: July 27th, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between BPilot LLC, a Delaware limited liability company (“Humavera”, “we”, “our”, or “Processor”), and the customer (“Customer”, “you”, or “Controller”) governing the use of the Humavera platform.
This DPA applies whenever Humavera processes Personal Data on behalf of the Customer.
01 Purpose
The purpose of this DPA is to define the responsibilities of both parties regarding the processing of Personal Data in accordance with applicable data protection laws, including, where applicable:
- EU General Data Protection Regulation (GDPR)
- UK GDPR
- Other applicable privacy regulations
02 Roles of the Parties
For Personal Data processed through Humavera:
- The Customer acts as the Data Controller.
- Humavera acts as the Data Processor.
The Customer determines:
- what Personal Data is collected,
- why it is collected,
- how it should be used.
Humavera processes Personal Data solely to provide the Services and only in accordance with the Customer’s documented instructions.
03 Categories of Personal Data
Depending on the modules enabled, Personal Data may include:
- Employee information
- Candidate information
- User account details
- Contact information
- Job titles
- Department information
- Organizational structure
- Payroll-related information
- Attendance records
- Performance reviews
- Skills and competency assessments
- Learning records
- Uploaded documents
- System activity logs
The Customer remains responsible for ensuring that the Personal Data uploaded to Humavera is lawful and appropriate.
04 Categories of Data Subjects
Data subjects may include:
- Employees
- Job Applicants
- Contractors
- Consultants
- Temporary Workers
- HR Personnel
- Managers
- System Administrators
- Learning Participants
05 Processing Activities
Humavera may process Personal Data for purposes including:
- User authentication
- Account administration
- HR management
- Recruitment
- Learning Management
- Payroll processing
- Skills management
- Workflow approvals
- Reporting and analytics
- AI-powered features requested by the Customer
- Technical support
- Security monitoring
- Backup and disaster recovery
06 Customer Responsibilities
The Customer agrees to:
- process Personal Data lawfully;
- obtain all required employee notices and consents where required;
- configure Humavera appropriately;
- manage user permissions responsibly;
- maintain secure credentials;
- respond to Data Subject requests.
The Customer is solely responsible for the accuracy and legality of the Personal Data submitted to Humavera.
07 Humavera Responsibilities
Humavera will:
- process Personal Data only on documented instructions from the Customer;
- maintain appropriate technical and organizational security measures;
- ensure personnel are bound by confidentiality obligations;
- assist the Customer with applicable privacy obligations where reasonably requested;
- notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Data, unless prohibited by law.
08 Security Measures
Humavera maintains appropriate security measures designed to protect Customer Data, including, where applicable:
- Encryption in transit (TLS)
- Encryption at rest
- Role-Based Access Control (RBAC)
- Multi-Factor Authentication (where enabled)
- Secure password hashing
- Audit logging
- Continuous monitoring
- Vulnerability management
- Secure software development practices
- Backup and disaster recovery procedures
- Least privilege access controls
Security measures are periodically reviewed and may evolve as industry best practices develop.
09 Confidentiality
Humavera personnel and authorized subcontractors are subject to confidentiality obligations and may access Customer Data only when necessary to provide the Services.
10 Subprocessors
Humavera may engage trusted third-party subprocessors to deliver parts of the Services, including cloud hosting, infrastructure, email delivery, authentication, monitoring, and customer support.
Humavera remains responsible for the performance of its subprocessors and requires them to maintain appropriate data protection obligations.
A current list of subprocessors is available upon request or through our Trust Center.
11 International Data Transfers
Where Customer Data is transferred internationally, Humavera will implement appropriate safeguards as required by applicable data protection laws, which may include:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions
- Other legally recognized transfer mechanisms
12 Data Subject Rights
Humavera will reasonably assist Customers in responding to requests relating to:
- Access
- Rectification
- Erasure
- Restriction
- Portability
- Objection
- Other applicable privacy rights
Where legally permitted, Humavera may refer such requests directly to the Customer.
13 AI Processing
Certain Humavera features use Artificial Intelligence to assist Customers with HR, recruitment, learning, reporting, skills intelligence, and workflow automation.
Unless explicitly stated for a specific feature:
- Customer Data is processed solely for providing the requested functionality.
- Customer Data is not used to train public foundation AI models.
- AI-generated outputs should be reviewed by authorized users before making employment or business decisions.
Customers remain responsible for decisions made using AI-generated recommendations.
14 Data Retention
Customer Data is retained only for the duration necessary to provide the Services or as required by applicable law.
Customers may delete their data at any time using available administrative functions or by submitting a support request.
15 Data Return and Deletion
Upon termination of the Services, and subject to contractual terms:
- Customers may request an export of their Customer Data.
- Humavera will delete Customer Data after the applicable retention period unless legal obligations require continued retention.
Backup copies may remain temporarily until overwritten through normal backup cycles.
16 Personal Data Breach
If Humavera becomes aware of a confirmed Personal Data Breach affecting Customer Data, Humavera will:
- investigate the incident;
- take reasonable steps to mitigate its impact;
- notify affected Customers without undue delay where required by law;
- provide available information necessary to assist Customers with their legal obligations.
17 Audits
Upon reasonable written request, Humavera may provide available compliance documentation, certifications, or security reports to demonstrate compliance with this DPA.
Where necessary, the parties may agree upon additional audit procedures, subject to reasonable confidentiality and security safeguards.
18 Liability
This DPA is subject to the liability limitations contained in the primary agreement governing the use of Humavera.
19 Governing Law
This DPA shall be governed by the governing law specified in the applicable Humavera Terms of Service or Master Subscription Agreement unless otherwise agreed in writing.
Contact
Questions regarding this Data Processing Addendum may be directed to:
Privacy Team
BPilot LLC
Delaware, USA
Email: privacy@humavera.com