Terms governing the processing of personal data on the Commitment platform.
Last updated: July 4, 2026
This Data Processing Agreement ("DPA") forms part of the Commitment Terms of Service and governs the processing of personal data on the platform in accordance with the General Data Protection Regulation (GDPR) (EU 2016/679).
Data Controller: The company that registers on the platform and determines the purposes and means of processing staff personal data (e.g., the lending company that adds staff to its bench).
Data Processor: Commitment, acting on behalf of the Data Controller to host, manage, and facilitate the platform's functionality — including staff listings, messaging, contracts, timesheets, and invoice records.
Joint Controllers: In the context of a staff engagement, both the lending and borrowing companies may act as joint controllers for the personal data exchanged through contracts and timesheets.
Commitment processes personal data on behalf of companies using the platform for the following purposes:
Commitment does not process any payment data, as all monetary transfers occur directly between companies outside the platform.
Commitment assists Data Controllers in fulfilling their obligations regarding data subject rights (access, rectification, erasure, restriction, portability, and objection). Where a data subject makes a request directly to Commitment, the request will be forwarded to the relevant Data Controller.
Commitment implements appropriate technical and organizational security measures, including:
Commitment uses the following categories of sub-processors:
All sub-processors are bound by data processing agreements with GDPR-compliant terms. Data Controllers will be notified of any changes to sub-processors.
Personal data is stored and processed within the European Union. Where a sub-processor processes data outside the EU, appropriate safeguards (Standard Contractual Clauses) are in place.
Personal data is retained for the duration of the Data Controller's use of the platform and for a period thereafter as required by law. Upon account closure, data is deleted or anonymized within 90 days, subject to legal retention obligations (e.g., tax records for 7 years under Greek law).
Data Controllers may request information about data processing practices. On-site audits are available upon reasonable request, subject to confidentiality agreements.
Questions about data processing? Contact commitment.contact@gmail.com