Wooble

Data Processing Agreement

This agreement governs how Wooble processes candidate personal data on behalf of companies using the hiring platform, including obligations under GDPR and India's DPDP Act 2023.

Effective date: June 15, 2026

1. Introduction and scope

This Data Processing Agreement ("DPA") forms part of the agreement between Wooble ("Processor") and the company using the Wooble portal ("Controller"). It governs the processing of personal data that Wooble carries out on the Controller's instructions in connection with the Services.

This DPA applies wherever the Controller uses Wooble to conduct hiring activities involving candidate personal data — including challenge creation, submission collection, review, shortlisting, and related workflows.

To the extent applicable, this DPA is intended to satisfy the requirements of Article 28 of the EU General Data Protection Regulation (GDPR), equivalent provisions under the UK GDPR, and the obligations of a Data Processor under India's Digital Personal Data Protection Act, 2023 (DPDP Act).

2. Roles and responsibilities

The Controller determines the purposes and means of processing candidate personal data. When you (the company) use Wooble to run challenges, collect submissions, and evaluate candidates, you act as the Controller.

Wooble acts as the Processor, processing candidate personal data only on the documented instructions of the Controller and for the purpose of providing the Services.

The Controller is solely responsible for: (a) the legal basis on which it processes candidate personal data; (b) providing required notices to data subjects (candidates) before their data is collected; (c) obtaining any consents required by applicable law; and (d) ensuring that use of the Services complies with applicable employment, anti-discrimination, and privacy laws.

3. Nature, purpose, and duration of processing

Wooble processes candidate personal data for the purpose of operating the hiring workflows you configure on the platform, including hosting and delivering challenges, receiving and storing submissions, facilitating review and scoring, maintaining shortlists, and generating activity reports.

The categories of personal data processed may include: name, email address, contact details, government identification (if voluntarily provided), professional experience, portfolio links, submitted work product (code, documents, designs, recordings), review notes, scores, and any other information candidates submit in response to your challenges.

Wooble processes this data for as long as you maintain an active account and for such period thereafter as is required for legal compliance, security audit trails, and legitimate dispute resolution, after which it is deleted or anonymized in accordance with our data retention practices.

4. Processor obligations

Wooble will:

  • Process candidate personal data only on the Controller's documented instructions, including the purposes set out in these Terms and any lawful further instructions you provide through the platform.
  • Ensure that persons authorized to process personal data are bound by appropriate confidentiality obligations.
  • Implement and maintain technical and organizational security measures appropriate to the risk, including access controls, encryption in transit, hashed credentials, and least-privilege service account policies.
  • Not engage a sub-processor without prior authorization in the form of the general authorization granted by the Controller's acceptance of this DPA. A list of current sub-processors is available on request at privacy@wooble.org.
  • Assist the Controller, where technically feasible and at the Controller's reasonable cost, in responding to data subject requests to exercise rights under applicable law (access, rectification, erasure, restriction, portability, objection).
  • Notify the Controller without undue delay upon becoming aware of a personal data breach affecting candidate data processed under this DPA.
  • Make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and assist with audits or inspections upon reasonable notice.
  • Upon termination of the Services, delete or return candidate personal data at the Controller's election, and delete existing copies unless retention is required by applicable law.

5. Controller obligations

The Controller agrees to:

  • Use the Services only for lawful hiring purposes and in compliance with applicable employment, anti-discrimination, and data protection laws.
  • Provide candidates with a clear, accessible privacy notice before collecting their personal data through Wooble challenges, describing the categories of data collected, the purpose of collection, and how candidates can exercise their rights.
  • Establish and document a valid legal basis (e.g., consent, legitimate interests, or performance of a contract) for processing candidate personal data before running any challenge.
  • Ensure that challenge briefs, role descriptions, and evaluation criteria do not unlawfully discriminate against candidates on protected characteristics.
  • Not instruct Wooble to process personal data in a manner that would violate applicable law or Wooble's acceptable use policies.
  • Promptly inform Wooble of any instructions that the Controller believes may cause Wooble to violate applicable law.

6. Sub-processors

Wooble uses third-party service providers (sub-processors) to deliver the Services, including infrastructure hosting, file storage, email delivery, and security monitoring. By accepting this DPA you grant general authorization for Wooble to engage sub-processors subject to the safeguards below.

Wooble will: (a) impose data protection obligations on sub-processors no less protective than those in this DPA; (b) remain liable to the Controller for sub-processor compliance; and (c) notify the Controller of material changes to the sub-processor list at least 30 days in advance, giving the Controller the opportunity to object.

Current infrastructure sub-processors include cloud hosting providers operating in India and other regions. A current list is available on request at privacy@wooble.org.

7. International transfers

Where candidate personal data is transferred outside India or the European Economic Area, Wooble will apply appropriate safeguards consistent with applicable law, including standard contractual clauses, adequacy decisions, or equivalent mechanisms.

The Controller acknowledges that candidates may be located in various jurisdictions and should ensure that its challenge configurations and privacy notices reflect any applicable cross-border transfer obligations.

8. India — DPDP Act 2023

To the extent the Controller processes personal data of Indian residents (Data Principals) through the Services, this section applies in addition to the other provisions of this DPA.

The Controller is the Data Fiduciary as defined under the DPDP Act. Wooble is a Data Processor acting on the Controller's instructions.

The Controller is responsible for: (a) obtaining free, specific, informed, unconditional, and unambiguous consent from Data Principals before collecting their personal data through Wooble challenges, or establishing another valid legal ground; (b) providing a notice in plain language describing the data being collected, the purpose, and Data Principal rights before or at the time of collection; (c) honoring Data Principal rights including the right to access, correct, erase, and withdraw consent.

Wooble will assist the Controller in fulfilling Data Principal rights requests to the extent technically feasible, and will promptly notify the Controller of any such requests received directly by Wooble.

Wooble maintains records of processing activities in accordance with the DPDP Act and applicable rules.

9. European Union and UK — GDPR

To the extent the Controller processes personal data of individuals in the European Economic Area or United Kingdom, this section applies.

The Controller is the data controller; Wooble is the data processor within the meaning of the GDPR and UK GDPR. This DPA constitutes the written contract required by Article 28 GDPR.

The Controller is responsible for identifying the appropriate legal basis under Article 6 (and Article 9 where special category data is involved) and for providing the information notices required by Articles 13 and 14 of the GDPR to data subjects.

Wooble will not process personal data subject to the GDPR except on the Controller's documented instructions, and will not transfer such data to a third country without appropriate safeguards in place.

Wooble will assist the Controller in meeting its obligations regarding data subject rights under Chapter III of the GDPR, data security obligations under Article 32, breach notification obligations under Articles 33–34, and data protection impact assessments under Article 35.

10. Security measures

Wooble maintains a security program that includes: encrypted data transport (TLS); hashed and salted credential storage; role-based access controls; audit logging of privileged access; vulnerability management; and regular review of security practices.

The specific technical and organizational measures in place as of the effective date of this DPA are available on request at privacy@wooble.org. Wooble may update security measures over time, provided the level of protection is not materially reduced.

11. Personal data breach notification

Wooble will notify the Controller without undue delay — and in any event within 72 hours of becoming aware — of a personal data breach that affects candidate personal data processed under this DPA, to the extent the breach poses a risk to the rights and freedoms of data subjects.

Notification will be sent to the email address associated with the Controller's account. The notification will include, to the extent then known: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.

12. Term and termination

This DPA remains in effect for as long as Wooble processes candidate personal data on behalf of the Controller.

Upon termination of the Services or written request from the Controller, Wooble will delete or return all candidate personal data it holds on the Controller's behalf within 30 days, except to the extent retention is required by applicable law or for legitimate security or audit purposes, in which case Wooble will continue to apply the protections in this DPA.

13. Contact and governing terms

For questions about this DPA, data subject rights requests, breach notifications, or sub-processor inquiries, contact Wooble at privacy@wooble.org.

This DPA is governed by the same law and jurisdiction as the Terms of Service (laws of India, courts in Bhubaneswar, Odisha), except where mandatory provisions of GDPR or other applicable laws require otherwise.

See the talent your résumé pile is hiding.

Book a 30 minute demo. We'll scope your first challenge and show you what hiring on proof of work looks like.