Back to Home
c
ommitment

Data Processing Agreement

Terms governing the processing of personal data on the Commitment platform.

Last updated: July 4, 2026

This Data Processing Agreement ("DPA") forms part of the Commitment Terms of Service and governs the processing of personal data on the platform in accordance with the General Data Protection Regulation (GDPR) (EU 2016/679).

1. Roles and Responsibilities

Data Controller: The company that registers on the platform and determines the purposes and means of processing staff personal data (e.g., the lending company that adds staff to its bench).

Data Processor: Commitment, acting on behalf of the Data Controller to host, manage, and facilitate the platform's functionality — including staff listings, messaging, contracts, timesheets, and invoice records.

Joint Controllers: In the context of a staff engagement, both the lending and borrowing companies may act as joint controllers for the personal data exchanged through contracts and timesheets.

2. Scope of Processing

Commitment processes personal data on behalf of companies using the platform for the following purposes:

  • Storing and displaying staff profiles (full name, photo, title, skills, and rate) in the marketplace.
  • Facilitating messaging, formal offers, and digital contract signing.
  • Managing monthly timesheets, approvals, and immutable snapshots.
  • Generating reference invoice records from approved timesheets.
  • Enforcing non-poaching and platform policies.
  • Providing notifications and customer support.

Commitment does not process any payment data, as all monetary transfers occur directly between companies outside the platform.

3. Data Subject Rights

Commitment assists Data Controllers in fulfilling their obligations regarding data subject rights (access, rectification, erasure, restriction, portability, and objection). Where a data subject makes a request directly to Commitment, the request will be forwarded to the relevant Data Controller.

4. Security Measures

Commitment implements appropriate technical and organizational security measures, including:

  • Encryption of data in transit (TLS) and at rest (AES-256).
  • Role-based access controls and multi-factor authentication.
  • Regular security assessments and vulnerability scanning.
  • EU-based data hosting with certified providers.
  • Incident response and breach notification procedures.

5. Sub-Processors

Commitment uses the following categories of sub-processors:

  • Cloud hosting: EU-based infrastructure providers.
  • Email delivery: Transactional email services for notifications.
  • Analytics: Platform usage analytics (anonymous).

All sub-processors are bound by data processing agreements with GDPR-compliant terms. Data Controllers will be notified of any changes to sub-processors.

6. International Data Transfers

Personal data is stored and processed within the European Union. Where a sub-processor processes data outside the EU, appropriate safeguards (Standard Contractual Clauses) are in place.

7. Data Retention and Deletion

Personal data is retained for the duration of the Data Controller's use of the platform and for a period thereafter as required by law. Upon account closure, data is deleted or anonymized within 90 days, subject to legal retention obligations (e.g., tax records for 7 years under Greek law).

8. Audit Rights

Data Controllers may request information about data processing practices. On-site audits are available upon reasonable request, subject to confidentiality agreements.

Questions about data processing? Contact commitment.contact@gmail.com