Legal
Data processing addendum
The terms on which ClearBGV processes personal data on behalf of a client, forming part of the agreement between us.
Last updated: 01-04-2026
1. Scope and roles
This addendum forms part of the agreement between the client ("Data Fiduciary") and ClearBGV operating as ClearBGV ("Data Processor").
The client determines the purpose and means of processing. ClearBGV processes personal data only on the client’s documented instructions, except where required by law — in which case we notify the client unless prohibited from doing so.
2. Subject matter of processing
| Item | Detail |
|---|---|
| Subject matter | Background verification of candidates and employees |
| Duration | For the term of the agreement, plus the agreed retention period |
| Nature and purpose | Collection, verification, storage, reporting and deletion |
| Categories of data subject | Candidates and employees of the client |
| Categories of personal data | Identity, contact, employment, education, address, and where instructed, criminal and court records |
3. Processor obligations
- Process personal data only on documented instructions from the client
- Ensure personnel with access are bound by confidentiality and trained on data protection
- Implement appropriate technical and organisational security measures (Annex A)
- Assist the client in responding to data principal rights requests
- Assist the client with breach notification and any impact assessments
- Delete or return personal data at the end of the engagement, as instructed
- Make available the information needed to demonstrate compliance, and allow audits
4. Sub-processors
The client provides general authorisation for ClearBGV to engage sub-processors for hosting, communications and international verification. We impose data protection obligations on each sub-processor no less protective than those in this addendum, and remain fully liable for their performance.
We maintain a current list of sub-processors and will give the client at least 30 days’ notice before adding or replacing one. The client may object on reasonable data protection grounds.
5. Security measures (Annex A)
- Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access control with least-privilege provisioning and periodic review
- Immutable audit logging of access to case data
- Network segregation and hardened production environments
- Background verification and confidentiality undertakings for all personnel
- Documented backup, restoration and business continuity procedures
- Annual penetration testing and continuous vulnerability management
6. Personal data breach
ClearBGV will notify the client without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the client’s data. The notification will describe the nature of the breach, the categories and approximate volume affected, the likely consequences, and the measures taken.
7. Data principal rights
Where a candidate contacts ClearBGV directly to exercise a right, we will refer them to the client unless the client has instructed otherwise, and will assist the client in responding within the statutory timeline.
8. International transfers
Where processing occurs outside India, ClearBGV ensures an appropriate transfer mechanism is in place and that the recipient is bound by obligations equivalent to those in this addendum.
9. Return and deletion
On termination, ClearBGV will, at the client’s election, return or securely delete all personal data within 5 years, except where retention is required by law. Certification of deletion is available on request.
10. Audit
The client may audit ClearBGV’s compliance with this addendum once per year on reasonable notice, or more frequently following a breach. Audits may be satisfied by providing a current independent audit report where one is available.
11. Contact
Email — bgv_request@clearbgv.com
Post — ClearBGV, Pegasus Tower, Block-A, Sector 68, Noida, Uttar Pradesh - 201309