Data Processing Addendum
Last updated: August 5, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Cobalt Glacier LLC (doing business as RecruitFractional) and the customer that agreed to those Terms. It applies where we process personal data on the customer's behalf, for example candidate records, pipeline notes, and search briefs inside the customer's workspace.
1. Parties and scope
The parties are the customer, being the company or recruiting firm holding the account, and Cobalt Glacier LLC, a North Carolina limited liability company. This DPA applies to personal data protected by applicable data protection law, including the EU and UK GDPR, the Swiss FADP, and US state privacy laws such as the CCPA and CPRA, that we process on the customer's behalf in providing the platform.
2. Roles of the parties
- For workspace content the customer controls, including candidate records the customer or its recruiters upload, pipeline notes, search briefs, and messages the customer sends, the customer is the controller (or business) and RecruitFractional is the processor (or service provider).
- For our own account, billing, security, product analytics, and marketplace operations data, RecruitFractional is an independent controller and our Privacy Policy applies.
- Where an executive publishes a profile to the marketplace, the executive and RecruitFractional determine that publication, not the customer.
- As a service provider under the CCPA, we do not sell or share personal data, do not retain, use, or disclose it for any purpose other than providing the service and the permitted business purposes, and do not combine it with data from other sources except as permitted by law.
3. Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the RecruitFractional marketplace and workspace software. |
| Duration | The term of the customer's subscription, plus the retention periods stated in the Privacy Policy. |
| Nature and purpose | Hosting, storage, retrieval, display, transmission, matching, notification, invoicing, support, and deletion. |
| Categories of data subjects | Customer personnel and workspace members, fractional executives, and candidates submitted by the customer or its recruiters. |
| Categories of personal data | Names, business contact details, professional and employment history, skills, seniority, availability, rate expectations, links, photos and optional video, message content, notes, engagement and placement records. |
| Special categories | None requested or required. The customer must not upload special category data, government identifiers, or payment card data into workspace fields. |
| Frequency | Continuous for the duration of the subscription. |
4. Processing instructions
We process personal data only to provide and support the platform, in accordance with the Terms, this DPA, and the customer's documented instructions given through the platform's features. We will notify the customer if an instruction appears to breach applicable law, and we may stop processing that instruction. The customer is responsible for the lawfulness of the data it uploads, for having a valid basis and, where required, candidate consent, and for providing the notices its own data subjects require.
5. Personnel and confidentiality
- Access to customer personal data is limited to personnel who need it to deliver, support, secure, or bill the service.
- Those personnel are bound by written confidentiality obligations that survive the end of their engagement.
- Administrative access is role-restricted and audit-logged.
6. Security measures
We maintain technical and organizational measures appropriate to the risk, including:
- Encryption of data in transit using TLS and encryption at rest by our hosting and database providers.
- Row-level database authorization so each account reaches only its own records, with least-privilege grants per role.
- Private storage buckets for uploaded photos, video, and documents, served through access-checked requests.
- Authenticated server functions with server-side authorization checks rather than client-side trust.
- Payment isolation: card data is handled entirely by Stripe and never reaches our systems.
- Logging, error reporting, and administrative audit trails.
- Periodic dependency and configuration scanning, and prompt remediation of identified issues.
- Backups managed by our database provider, with restoration procedures.
We may update these measures as the platform evolves, provided the level of protection is not materially reduced. We make no certification claim, including SOC 2, ISO 27001, HIPAA, or PCI Level 1 service-provider status, and the customer should not represent otherwise.
7. Subprocessors
The customer authorizes our use of the subprocessors listed on our subprocessor page, reproduced here in summary:
| Subprocessor | Purpose |
|---|---|
| Lovable (application hosting and edge delivery) | Hosts and serves the RecruitFractional web application. |
| Supabase (database, authentication, file storage) | Stores account, profile, workspace, messaging, and uploaded media data, and manages sign-in. |
| Stripe | Processes subscription payments and placement fee invoices. |
| Resend (transactional email delivery) | Delivers account, notification, billing, and invoice email. |
| Google Gemini via the Lovable AI Gateway | Powers AI matching and shortlist scoring. |
| Google Search Console | Search performance reporting for public marketing pages. |
- We impose data protection obligations on each subprocessor that are no less protective than this DPA, and we remain responsible for their performance.
- We will give at least 30 days' notice before adding or replacing a subprocessor that processes customer personal data, by updating the subprocessor page and, on request, by email notification.
- The customer may object on reasonable data protection grounds within that notice period. If we cannot offer a reasonable alternative, the customer may terminate the affected subscription and receive a pro-rata refund of prepaid, unused fees.
- To receive subprocessor change notices by email, write to privacy@recruitfractional.com.
8. Data subject requests and assistance
- The platform gives the customer tools to access, correct, export, and delete workspace records itself.
- If a data subject contacts us directly about customer-controlled data, we will not respond substantively other than to direct them to the customer, and we will forward the request without undue delay.
- We will provide reasonable assistance with data protection impact assessments and consultations with supervisory authorities, at the customer's cost where the effort is substantial.
9. Incident notification
We will notify the customer without undue delay, and in any event within seventy-two (72) hours of becoming aware, of a personal data breach affecting customer personal data. The notice will describe the nature of the breach, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed. We will cooperate reasonably with the customer's own notification obligations. Our notice is not an admission of fault.
10. Audits and information rights
On written request, no more than once in any twelve-month period unless required by a supervisory authority, we will provide the information reasonably necessary to demonstrate compliance with this DPA, including a written description of our security measures and answers to a reasonable security questionnaire. On-site audits and penetration testing against our production environment are not permitted, because that environment is shared multi-tenant infrastructure.
11. International transfers
Customer personal data is processed in the United States. Where the customer transfers personal data subject to EU, UK, or Swiss law to us, the European Commission's Standard Contractual Clauses (Module Two, controller to processor) are incorporated into this DPA by reference, with Cobalt Glacier LLC as data importer and the customer as data exporter, the governing law and forum being Ireland where the SCCs require an EU member state, the UK International Data Transfer Addendum applying to UK transfers, and the annexes populated by sections 3, 6, and 7 of this DPA. Onward transfers to subprocessors are made under equivalent terms.
12. Return and deletion
- The customer may export or delete workspace records at any time during the subscription.
- On termination, we delete or anonymize customer personal data within 90 days, except records we must retain for tax, accounting, dispute, anti-abuse, or legal purposes as described in the Privacy Policy, and except for short-lived backup copies that expire on their normal cycle.
- Retained records remain protected by this DPA for as long as we hold them.
- On written request we will confirm deletion.
13. Precedence and acceptance
If there is a conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service, in each case only as to the processing of personal data. Everything else in the Terms continues to apply. This DPA takes effect automatically when a customer accepts the Terms, so no signature is required. If your procurement process requires a countersigned copy, email legal@recruitfractional.com with your entity details.
This document is written in plain language and is not legal advice. Have your own counsel review it against your obligations before you rely on it.