Amazon Web Services EMEA SARL
L-1855 Luxembourg
Email delivery service (Amazon SES) used to send product and transactional emails, including on behalf of the Company as part of the Services.
Data processing agreement (“DPA” or “Agreement”) between the Company and JOIN.
Preamble
JOIN has set itself the mission of connecting job seekers and companies worldwide. Companies can use the JOIN platform at https://join.com/ (hereinafter referred to as “Platform”) to advertise vacancies and manage applications received in one central location.
JOIN provides services to the Company in accordance with the service agreement concluded between the parties (“Services”). The Services notably include the possibility for the Company to publish job listings and manage related application procedures on the Platform using a web-based management tool. In the context of the Services, personal data controlled by the Company is processed by JOIN acting as the processor as defined by the current data protection laws.
Personal data may be processed by JOIN as the controller as defined by the current data protection laws. Please refer to JOIN’s privacy policy for more information.
This DPA serves to protect the parties against the improper use of the personal data processed for the Services, to ensure data protection by JOIN due to personal data that the Company has made known to them, and to comply with applicable legal requirements.
Unless otherwise expressly agreed, this DPA shall form part of every service agreement between the Company and JOIN. This DPA, including all appendices, also specifies the data protection obligations of the parties from the underlying service agreement as follows:
Section 01
Section 02
Section 03
The provisions of this DPA are an integral part of the service agreement between the parties and take precedence over the other contractual agreements of the parties regarding data protection, in particular other contracts that contain provisions that deviate from those of this DPA to the detriment of the Company. Clause 1.1. remains unaffected. The provisions of this DPA do not apply to the processing of personal data that JOIN, as the controller, provides to the Company or any other individual user. Each party’s liability arising out of or related to this DPA shall be subject to the limitations and exclusions of liability set out in the service agreement entered into between the parties.
Section 04
The parties hereby agree that the purpose of the data processing is the provision of the Services by JOIN according to the service agreement. The scope and nature of data collection, processing and/or use of personal data are determined by the provisions of the service agreement as well as the Services actually used by the Company.
Section 05
The data subjects affected by the handling of personal data within the framework of the service agreement include:
Section 06
The following types of data are particularly affected by order processing:
If this data is processed as part of other JOIN Services where JOIN acts as a controller, this does not take place within the scope of this DPA. Reference is made to JOIN’s privacy policy.
Section 07
Section 08
Data processing. JOIN is obliged to process personal data under this DPA solely in accordance with this agreement and/or the underlying service agreement and the instructions of the Company.
Rights of data subjects. JOIN will support the Company as far as possible in fulfilling the rights of data subjects, in particular with regard to correction, restriction of processing and deletion, notification and provision of information.
JOIN shall, on the Company’s instructions, rectify, delete or restrict the processing of the personal data processed on behalf of the Company. This obligation does not apply to personal data that JOIN processes as controller as part of the services it offers via the Platform.
If a data subject contacts JOIN directly to request correction, deletion or restriction of processing of his or her personal data, JOIN shall forward this request to the Company immediately upon receipt. The Company shall remain responsible for the execution of the requests.
Internal control obligations. JOIN shall implement the appropriate control measures, e.g. internal audits, data protection concept, etc., to ensure that the personal data processed under this DPA is processed in accordance with this agreement and the corresponding instructions.
Duty to inform. JOIN, as the processor, shall inform the Company if, according to its own assessment, an instruction violates legal regulations. JOIN shall then be entitled to suspend the execution of the corresponding instruction until it is amended by the Company. This does not hereby justify JOIN’s obligation to check or notify.
JOIN shall notify the Company of any personal data breach concerning data processed by JOIN (“Personal Data Breach”) no later than 48 hours after becoming aware of it. Such notice shall include, at a minimum:
If access to the personal data that the Company has transmitted to JOIN for data processing is endangered by measures taken by third parties (e.g. measures taken by an insolvency administrator, confiscation by tax authorities, etc.), JOIN is obliged to notify the Company of this.
JOIN shall only pass on information to a party requesting information after prior agreement with the Company, unless JOIN is obliged to provide information by government measures or court decisions.
Where a Personal Data Breach results from the compromise, loss, or unauthorised disclosure of the Company’s own credentials, systems, or personnel, JOIN acts strictly as data processor and its obligations are limited to notifying the Company in accordance with this DPA. JOIN shall have no obligation to make notifications on the Company’s behalf. JOIN may decide, alone or following a request from the Company, to notify data subjects of the existence of a breach in order for such data subjects to take necessary measures to mitigate risks and further unauthorised access to JOIN’s infrastructure.
Creation of a processing log. Upon request, JOIN shall support the Company in compiling a list of processing activities within the scope of the DPA and the data processing that is taking place and provide the necessary information in a suitable manner.
JOIN shall also maintain its own log of all categories of processing activities carried out on behalf of the Company in accordance with the provisions of the current data protection laws.
Reporting and cooperation obligations. JOIN shall support the Company upon request in:
Place of data processing. Unless otherwise agreed between the parties, the processing and use of the data by JOIN takes place in Switzerland, the European Union or in another treaty state of the Agreement on the European Economic Area. Any relocation of JOIN’s data processing activities to a third country is only permitted if the special requirements of Chapter V of the GDPR or Section 2 of the FADP are observed. The Company agrees that where JOIN engages a subprocessor in accordance with this agreement for carrying out specific processing activities (on behalf of the Company) in a third country and those processing activities involve transfer of personal data within the meaning of the GDPR or the FADP, as applicable, JOIN and the subprocessor may use standard contractual clauses adopted by the Commission on the basis of Article 46(2) GDPR in order to comply with the requirements of Chapter V of the GDPR, provided the conditions for the use of those clauses are met and provided that an internal assessment concluded that such transfer meets the level of data protection of the GDPR and the FADP.
Deletion of personal data after termination of the agreement. After the termination of the service agreement, JOIN is obliged to delete all personal data processed on behalf of the Company and certify to the Company that it has done so, and delete existing copies unless Union, Member State or Swiss law requires storage of the personal data. This obligation to delete does not apply to personal data that JOIN processes as controller as part of the services it offers via the Platform.
Section 09
Section 10
JOIN is entitled to commission subprocessors with data processing in accordance with the following provisions:
Section 11
Section 12
Section 13
Section 14
Tim Ruffner, CEO and Founder JOIN Solutions
15th September, 2026
Appendix 1
JOIN implements and maintains the following technical and organisational measures.
JOIN implements and maintains technical and organisational measures designed to protect personal data processed in connection with the Services against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful or unauthorised forms of processing.
These measures are implemented on a risk-based basis, taking into account the nature, scope, context and purposes of processing, as well as the risks to the rights and freedoms of natural persons.
JOIN reviews and updates its technical and organisational measures as appropriate in order to maintain a level of security appropriate to the risk and to reflect changes in legal requirements, the Services, and the state of the art. Such measures are intended to support JOIN’s information security management framework and applicable data protection obligations.
JOIN maintains an information security management framework including documented policies, assigned responsibilities, risk assessment and risk treatment processes, and periodic review of relevant security and privacy risks.
JOIN maintains documented procedures and controls relating to areas such as access management, incident response, secure development, vulnerability management, business continuity, supplier oversight, and data protection.
Personnel with responsibilities relevant to customer personal data are subject to confidentiality obligations and receive security and data protection training appropriate to their role.
JOIN applies role-appropriate onboarding, role change, and offboarding processes for personnel with potential access to systems or personal data processed as part of the Services.
Access is granted based on business need and the principle of least privilege, and personnel are required to comply with JOIN’s internal security and confidentiality requirements.
JOIN takes reasonable steps to ensure that authorised personnel understand their responsibilities relating to confidential information, data protection, and acceptable system use.
JOIN primarily relies on cloud-hosted systems and infrastructure for the processing and storage of customer personal data. Physical and environmental security for the underlying hosting infrastructure is managed by the relevant cloud infrastructure provider under its own security programme and contractual commitments.
JOIN applies proportionate physical security and device protection measures for office-based and remote-working environments relevant to its business operations.
This annex does not describe infrastructure-specific controls that are solely operated by third-party cloud providers unless such controls form part of the provider-managed environment supporting the Services.
Access to systems and customer personal data is restricted to authorised persons with a legitimate business need. JOIN uses access management processes designed to ensure that access rights are assigned, modified and revoked in a controlled manner.
JOIN uses unique user identities where appropriate, restricts privileged access to authorised personnel, and applies strong authentication controls, including multi-factor authentication for critical systems where technically supported and appropriate.
JOIN maintains processes for credential management, access reviews, role-based permissions, and timely revocation of access following role change or termination.
JOIN’s services are designed to logically separate customer data from the data of other customers and to ensure that users may access only the data and functions for which they are authorised.
JOIN maintains separation between production and non-production environments where appropriate for operational and security purposes.
Where personal data is processed in connection with testing, support, troubleshooting or maintenance activities, such processing is limited to what is necessary and subject to appropriate access restrictions and safeguards.
JOIN applies encryption in transit for personal data transmitted over public networks using industry-standard secure communication protocols.
JOIN applies encryption at rest for JOIN-controlled production systems used to persistently store customer personal data. Where customer personal data is processed or stored through third-party services, JOIN relies on the applicable security measures and contractual safeguards of the relevant provider.
Cryptographic keys, secrets, authentication credentials and related sensitive configuration data are managed through controlled processes designed to restrict unauthorised access and disclosure.
JOIN maintains development and change-management processes designed to reduce security risk throughout the design, development, testing, deployment and operation of the Services.
Changes to production systems are subject to appropriate review, testing and approval procedures proportionate to the nature and risk of the change. JOIN also maintains separation between development, test and production activities where appropriate.
Security considerations are incorporated into the software lifecycle, including vulnerability remediation, dependency management, defect handling, and the controlled release of changes.
JOIN maintains processes to identify, assess, prioritise and remediate vulnerabilities affecting systems within its control. Security updates and patches are applied based on risk, severity and operational requirements.
JOIN applies endpoint-security and device-management measures appropriate to company-managed endpoints used in connection with the Services.
Before engaging relevant suppliers or subprocessors that may process customer personal data, JOIN performs appropriate due diligence and requires contractual safeguards appropriate to the services provided and the applicable legal requirements. JOIN manages subprocessors in accordance with the applicable data processing agreement.
JOIN maintains logging and monitoring measures for relevant systems in order to support security monitoring, service operation, troubleshooting, incident investigation and response.
Access to such logs is restricted to authorised personnel, and retention periods are determined according to operational, security, legal and contractual requirements. JOIN maintains an incident management process covering the identification, assessment, escalation, containment, remediation and post-incident follow-up of security and operational incidents relevant to the Services.
In the event of a personal data breach, JOIN will notify the relevant customer in accordance with the DPA, and will provide reasonable cooperation and relevant available information to support investigation, mitigation and compliance with applicable notification obligations.
JOIN maintains measures designed to support the availability, resilience and recoverability of the Services, including backup, recovery, service monitoring and operational continuity measures appropriate to the Services and their underlying infrastructure.
Backup and recovery arrangements are periodically tested or otherwise validated in accordance with operational requirements, and JOIN maintains business continuity and recovery processes intended to support restoration following material operational or security incidents.
Upon termination of the relevant contractual relationship, JOIN deletes customer personal data in accordance with the applicable agreement and documented customer instructions, except where retention is required by applicable law. Deletion processes are designed to remove personal data from active systems and to manage residual data in backups in accordance with applicable retention and deletion processes.
Appendix 2
Email delivery service (Amazon SES) used to send product and transactional emails, including on behalf of the Company as part of the Services.
Product analytics platform used to analyse user and usage behaviour on the JOIN platform; processes personal data contained in event properties.
Web application firewall (WAF), CDN, and DDoS protection for JOIN services.
Calendar synchronisation and interview scheduling service; processes scheduling data including candidate name and email contained in interview event details, on behalf of the Company.
Messaging automation platform used to send product, lifecycle, and application-related emails, including emails containing candidate personal data sent in connection with a customer’s job.
Customer communication platform used to manage shared inboxes, customer support interactions, and email workflows.
Hosting and storage for the JOIN platform, including virtual machines (Compute Engine), managed databases (Cloud SQL), object storage (Cloud Storage), networking, and backups.
Email platform used to send product and transactional emails to users and on behalf of the Company.
Meeting-bot service used in the Interview Mode feature to record and transcribe interviews; processes candidate personal data contained in interview recordings and transcripts on behalf of the Company.
Internal applications used by JOIN staff to access and manage platform data, including candidate application data and recruiter/company data, for operational and support purposes.
Customer data platform used to collect and route product and usage event data, including candidate personal data processed on behalf of the Company, to other tools.
Error monitoring and performance tracking for the JOIN application. May process technical data in logs.
Questions on this agreement, our subprocessors, or a data-subject request? Reach our legal team at [email protected] or via join.com/contact.