Peepel Data Processing Agreement (DPA)
This Data Processing Agreement (DPA) describes how Peepel, acting as processor, processes personal data on behalf of customers (controllers) under article 28 of the GDPR.
Subject and duration
Peepel processes personal data of the customer's employees solely to deliver the agentic HR platform: onboarding, leave automation, contracts, payroll automation, surveys and performance reviews. The DPA runs for as long as the main agreement between the customer and Peepel is in force.
Security measures
- ISO 27001 certified processes.
- Encryption in transit (TLS) and at rest.
- Least-privilege access control and audit logging.
- Data hosted in the European Union.
Sub-processors, data breaches and customer rights
Peepel uses an approved list of sub-processors (including cloud hosting). Data breaches are notified to the customer within 72 hours. The customer can request audits at any time and have data returned or deleted. Contact: privacy@peepel.io.