ClearBGV

Legal

Data processing addendum

The terms on which ClearBGV processes personal data on behalf of a client, forming part of the agreement between us.

Last updated: 01-04-2026

1. Scope and roles

This addendum forms part of the agreement between the client ("Data Fiduciary") and ClearBGV operating as ClearBGV ("Data Processor").

The client determines the purpose and means of processing. ClearBGV processes personal data only on the client’s documented instructions, except where required by law — in which case we notify the client unless prohibited from doing so.

2. Subject matter of processing

ItemDetail
Subject matterBackground verification of candidates and employees
DurationFor the term of the agreement, plus the agreed retention period
Nature and purposeCollection, verification, storage, reporting and deletion
Categories of data subjectCandidates and employees of the client
Categories of personal dataIdentity, contact, employment, education, address, and where instructed, criminal and court records

3. Processor obligations

  • Process personal data only on documented instructions from the client
  • Ensure personnel with access are bound by confidentiality and trained on data protection
  • Implement appropriate technical and organisational security measures (Annex A)
  • Assist the client in responding to data principal rights requests
  • Assist the client with breach notification and any impact assessments
  • Delete or return personal data at the end of the engagement, as instructed
  • Make available the information needed to demonstrate compliance, and allow audits

4. Sub-processors

The client provides general authorisation for ClearBGV to engage sub-processors for hosting, communications and international verification. We impose data protection obligations on each sub-processor no less protective than those in this addendum, and remain fully liable for their performance.

We maintain a current list of sub-processors and will give the client at least 30 days’ notice before adding or replacing one. The client may object on reasonable data protection grounds.

5. Security measures (Annex A)

  • Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access control with least-privilege provisioning and periodic review
  • Immutable audit logging of access to case data
  • Network segregation and hardened production environments
  • Background verification and confidentiality undertakings for all personnel
  • Documented backup, restoration and business continuity procedures
  • Annual penetration testing and continuous vulnerability management

6. Personal data breach

ClearBGV will notify the client without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the client’s data. The notification will describe the nature of the breach, the categories and approximate volume affected, the likely consequences, and the measures taken.

7. Data principal rights

Where a candidate contacts ClearBGV directly to exercise a right, we will refer them to the client unless the client has instructed otherwise, and will assist the client in responding within the statutory timeline.

8. International transfers

Where processing occurs outside India, ClearBGV ensures an appropriate transfer mechanism is in place and that the recipient is bound by obligations equivalent to those in this addendum.

9. Return and deletion

On termination, ClearBGV will, at the client’s election, return or securely delete all personal data within 5 years, except where retention is required by law. Certification of deletion is available on request.

10. Audit

The client may audit ClearBGV’s compliance with this addendum once per year on reasonable notice, or more frequently following a breach. Audits may be satisfied by providing a current independent audit report where one is available.

11. Contact

Email — bgv_request@clearbgv.com

Post — ClearBGV, Pegasus Tower, Block-A, Sector 68, Noida, Uttar Pradesh - 201309