Skip to main content
FIRSTSHIFT — home

Legal

Data Processing Agreement

The data processing terms between First Shift and its customers — roles, sub-processors, security and breach notification.

Last updated: 23 September 2026

Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Use between Arbeo, which provides First Shift and operates the Arbeo hiring platform ("we", "Processor"), and the customer that has accepted those Terms ("Customer", "Controller"). It applies whenever we process Personal Data on the Customer's behalf in providing the Service.

If this DPA conflicts with the Terms of Use about processing Personal Data, this DPA prevails.

1. Definitions

  • "Privacy Laws" means the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the California Consumer Privacy Act as amended (CCPA), and any other US federal or state data-protection law that applies to the Customer's use of the Service.
  • "Personal Data" (or "Candidate Data") means information about an identified or reasonably identifiable individual that the Customer collects through, uploads to or generates in the Service, mainly about job candidates.
  • "Processing" means any operation performed on Personal Data, such as collecting, storing, using, disclosing or deleting it.
  • "Data Subject" means the individual the Personal Data is about.
  • "Sub-processor" means a third party we engage to process Personal Data.
  • Terms not defined here have the meaning given in the Terms of Use.

2. Roles of the parties

For Personal Data, the Customer is the controller (under the CCPA, the "business") and we are the processor (under the CCPA, the "service provider"). The Customer decides the purposes and means of processing; we process only to provide the Service and on the Customer's instructions.

Separately, we are the controller of the Customer's own account information, such as staff names, logins, billing and usage. Our Privacy Policy governs that, not this DPA.

3. Customer instructions

  • We process Personal Data only on the Customer's documented instructions. The Terms of Use, this DPA, and the Customer's settings and use of the Service (for example, which jobs have AI screening on, and its retention period) together make up those instructions.
  • We will tell the Customer if we think an instruction breaches Privacy Laws, without any obligation to give legal advice.
  • CCPA commitments. We will not sell or share Personal Data; retain, use or disclose it outside our direct business relationship with the Customer or for any purpose other than providing the Service; or combine it with personal information from other sources, except as the CCPA permits. We will tell the Customer if we can no longer meet our CCPA obligations.

4. Customer obligations

The Customer warrants that:

  • it has a lawful basis to collect the Personal Data it puts into the Service and to have us process it;
  • it has given candidates any notices, and obtained any consents, required by Privacy Laws and by employment and AI-in-hiring laws, beyond the notices the Service shows by default;
  • it will not use the Service to collect medical information before a conditional offer, protected health information, or data about protected characteristics; and
  • its instructions to us comply with Privacy Laws.

5. Our obligations

We will:

  • process Personal Data only as set out in clause 3;
  • make sure everyone authorised to process Personal Data is bound by confidentiality;
  • implement and maintain the security measures in Annex B;
  • not use Personal Data to train AI models, and use AI providers only under API terms that exclude training;
  • help the Customer respond to Data Subject requests (clause 7) and meet its own breach-notification and compliance obligations (clause 9), as far as we reasonably can given the nature of the processing; and
  • delete or return Personal Data at the end of the Service in line with clause 12.

6. Sub-processors

  • The Customer gives general authorisation for us to engage the Sub-processors listed in Annex C.
  • We will impose data-protection obligations on each Sub-processor that are at least as protective in substance as this DPA, and we remain responsible for their performance.
  • We will give the Customer notice, by updating Annex C and the Privacy Policy, or by email, before adding or replacing a Sub-processor. If the Customer reasonably objects on data-protection grounds, we will discuss it in good faith. If we can't resolve the concern, the Customer may stop using the affected feature or terminate.

7. Data Subject requests

If a Data Subject contacts us about Personal Data, for example to access, correct or delete it, we will not respond directly except to direct them to the Customer. We will forward the request to the Customer without undue delay and give reasonable help so the Customer can respond. The candidate portal also lets a signed-in candidate download their data and ask for their applications to be deleted. We email the Customer's account owner when a candidate asks for deletion. Deletion happens after a 30-day grace period, during which the candidate can cancel the request; after that it is permanent. The Customer is responsible for telling us within the grace period if the law requires it to keep any of those records.

8. Security

We will maintain technical and organisational measures appropriate to the risk, described in Annex B, to protect Personal Data against misuse, loss, and unauthorised access, change or disclosure.

9. Personal data breach

If we confirm a breach affecting the Customer's Personal Data, we will notify the Customer without undue delay and within 48 hours of confirming it. We will give the information we have to help the Customer meet its obligations under the Notifiable Data Breaches scheme, US state breach-notification laws and other applicable law. This includes the nature of the breach, the data and Data Subjects affected (where known), and the steps taken in response. We will keep the Customer updated as we learn more.

10. Connected AI tools

If the Customer enables our AI connector (the Model Context Protocol, or "MCP", server) and connects an AI client, such as an AI assistant it uses, Personal Data is disclosed to that AI client at the Customer's direction. The connector is read-only. The AI client and its provider act under the Customer's own agreement with them, are not our Sub-processors, and are outside this DPA. The Customer is responsible for choosing that provider and for its terms. The Customer can revoke the connection at any time.

11. International transfers

Personal Data is hosted in the United States (see Annex C). We are an Australian company, and our authorised staff may access Personal Data from Australia to support and run the Service. We will take reasonable steps, including under APP 8, to make sure anyone who handles Personal Data protects it consistently with the APPs, this DPA and applicable US state law. The Service is not offered in the EU, the EEA or the UK. If another law requires a specific transfer mechanism, the parties will put one in place.

12. Records and audit

We will give the Customer the information reasonably needed to show we comply with this DPA. On reasonable written notice, no more than once in any 12 months (unless a regulator requires it or after a breach), and subject to confidentiality, we will answer a reasonable written audit questionnaire. Where a Sub-processor provides an independent audit report or certification, we may share it to help satisfy this clause. We do not currently hold our own SOC 2 or similar certification.

13. Retention, return and deletion

  • During the Service, Personal Data is kept for the retention period the Customer sets (1 to 10 years; the default is 4 years from the application date), then deleted automatically, including stored files.
  • When the Service ends, the Customer can export its data. We then delete or de-identify Personal Data within a reasonable period, unless the law requires us to keep it. Backups age out on a rolling schedule.

14. Liability

Each party's liability under this DPA is subject to the limits and exclusions in the Terms of Use.

15. Term and governing law

This DPA takes effect when the Customer accepts the Terms of Use and continues for as long as we process Personal Data for the Customer. It is governed by the laws of New South Wales, Australia.

Annex A: Details of processing

  • Subject matter: providing the First Shift hiring software (applicant tracking) to the Customer.
  • Duration: for the term of the Service, plus the Customer's retention period and any retention the law requires.
  • Nature and purpose: publishing jobs and careers pages; receiving applications through forms, the AI intake chat and forwarded Indeed emails; parsing résumés; producing advisory AI summaries, match scores and flags; recruiter search and assistant features; interview scheduling; and sending candidate emails on the Customer's behalf.
  • Types of Personal Data: contact details; work history; résumé and cover-letter files; screening answers, including credential facts (state registry number, background-check date, CPR/first-aid expiry, driver's licence, insured vehicle, work-authorization answer, availability); intake-chat transcripts; AI-generated summaries, scores and flags; the Customer's notes and status changes; and TB test dates, recorded by the Customer only after a conditional offer.
  • Special categories: none intended. The Service does not collect or infer protected characteristics, and the Customer must not upload protected health information.
  • Categories of Data Subjects: job candidates and applicants to the Customer, and any referees or other people named in their applications.

Annex B: Security measures

  • Encryption of Personal Data in transit (TLS) and at rest.
  • Candidate documents stored in a private storage bucket and served only through short-lived signed links.
  • Tenant isolation: each Customer's data is scoped to its own account in every query.
  • Authentication for all staff access, role-based permissions within each Customer account, and least-privilege access for our personnel.
  • Rate limiting, upload file-type and size checks, and security headers.
  • Hosting with reputable providers (Annex C) that hold their own security certifications.
  • Automated deletion at the end of the retention period, including stored files.
  • Card data handled by Stripe; we do not store full card numbers.

Annex C: Approved Sub-processors

Sub-processor Purpose Region
Google Cloud (Cloud Run, Cloud Storage, Gemini API) Application hosting, document storage, AI features United States
OpenAI (API) AI features (intake chat, recruiter assistant) United States
Neon Database hosting (Postgres) United States
Resend Sending email, and receiving forwarded application emails United States
Stripe Subscription billing for the Customer (no candidate data) United States
PostHog Product analytics about Customer staff only (no candidate data) United States

This list mirrors §7 of the Privacy Policy, and we keep the two in sync. We will give notice before any change, as set out in clause 6.