Crucible — Data Processing Agreement

Last updated: 14 September 2026 · Version 0.1 (Beta)

This is the document to have a lawyer review before onboarding outside agencies. It defines Crucible's obligations when it processes personal data on a Customer's behalf.

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer ("Controller", "you") and Bear Tech LLC ("Crucible", "Processor", "we"). It applies where Crucible processes Personal Data contained in Customer Data on the Controller's behalf. If there is a conflict between this DPA and the Terms on the subject of data protection, this DPA governs. It is accepted by the Account Owner on behalf of the agency.

1. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given under applicable data protection law, including the California Consumer Privacy Act as amended ("CCPA/CPRA") and Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA"). "Subprocessor" means a third party engaged by Crucible to process Personal Data.

2. Roles

The Controller determines the purposes and means of Processing Customer Data; Crucible processes it only as a Processor (a "service provider" under CCPA/CPRA) on the Controller's documented instructions. The Terms, this DPA, and the Controller's use of the Service constitute those instructions.

3. Scope of Processing

  • Subject matter: provision of the Crucible recruiting system-of-record service.
  • Duration: for the term of the Terms and the deletion/return period in Section 10.
  • Nature and purpose: hosting, storage, structuring, de-duplication, matching, document generation, reporting, and support, to provide the Service.
  • Categories of Data Subjects: the Controller's candidates and business contacts, and the Controller's own users.
  • Types of Personal Data: identity and contact details, professional and employment history, skills, availability, compensation notes, recruiter notes and screen transcripts, and activity records, as the Controller chooses to submit.

4. Crucible's obligations

Crucible will:

  1. Process Personal Data only on the Controller's documented instructions, including as to transfers, unless required by law (in which case we will notify the Controller unless legally prohibited).
  2. Not sell or share Personal Data, and not retain, use, or disclose it for any purpose other than providing the Service or as permitted by CCPA/CPRA for service providers. We certify we understand and will comply with these restrictions.
  3. Ensure personnel authorized to process Personal Data are bound by confidentiality.
  4. Implement and maintain the security measures in Section 5.
  5. Assist the Controller, taking into account the nature of Processing, in responding to Data Subject requests and in meeting the Controller's security, breach notification, and (where applicable) impact-assessment obligations.
  6. Make available information reasonably necessary to demonstrate compliance with this DPA and, subject to Section 8, allow for audits.

5. Security measures

Crucible maintains technical and organizational measures appropriate to the risk, including: per-firm logical isolation enforced by database row-level security; encryption of sensitive data in transit and at rest; per-person encryption keys enabling crypto-shred erasure; least-privilege database roles that keep the service's normal query path off the owner/superuser role; access controls and authentication; audit logging via an append-only, provenanced fact log; and regular review of these measures. Crucible may update measures provided protection is not materially reduced.

6. Subprocessors

  • The Controller provides general authorization for Crucible to engage the Subprocessors listed at /subprocessors to process Personal Data to provide the Service.
  • Crucible imposes data-protection obligations on each Subprocessor substantially equivalent to those in this DPA and remains responsible for their performance.
  • Crucible will give notice (by updating the Subprocessors page and, where the Controller subscribes to notifications, by email) before adding or replacing a Subprocessor. The Controller may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Controller may terminate the affected Service.

7. Data Subject requests and breach

  • If Crucible receives a request from a Data Subject relating to Customer Data, it will not respond directly (except to acknowledge and redirect) and will promptly notify the Controller and provide the tools to respond, including deletion and export.
  • Crucible will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data, with the information reasonably available to assist the Controller's own notification obligations.

8. Audits

On reasonable prior written request, no more than once per year (unless required by a regulator or following a Breach), and subject to confidentiality, Crucible will make available information necessary to demonstrate compliance and will respond to a reasonable security questionnaire. On-site audits, if any, will be at the Controller's expense, scheduled to avoid disruption, and limited to Crucible's own systems.

9. International transfers

Personal Data is hosted in the United States. Where the Controller transfers Personal Data of Canadian individuals to the Service, the Controller is responsible for its own PIPEDA notice and accountability obligations, and Crucible will provide comparable protection as required by PIPEDA. This DPA does not authorize Processing of EU, UK, or EEA Personal Data during the beta.

10. Return and deletion

On termination or the Controller's request, Crucible will delete or return Customer Data containing Personal Data within a reasonable period, and delete existing copies except (a) copies that must be retained by law, and (b) data preserved in immutable, de-identified audit logs. Where erasure of a specific Data Subject is requested, Crucible uses crypto-shredding so that the underlying Personal Data is rendered unrecoverable while the de-identified historical record remains.

11. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms.

12. Effect

This DPA takes effect on the Controller's acceptance of the Terms and remains in effect while Crucible processes Customer Data. Bear Tech LLC · 1112 S 17th St, Philadelphia, PA 19146 · privacy@crucible-crm.com.