Skip to content

Draft for legal review · Not effective

Business Data Processing Terms

These proposed terms are a framework for business customers that submit personal data about applicants, talent, clients, staff or audiences to TCW.

Draft status and when these terms apply

This candidate document is provided for legal and operational review. It is not effective, does not replace any existing agreement, and must not be used to collect consent until TCW records final approval and a publication date.

These terms apply only when an approved TCW order or business agreement incorporates them and TCW processes personal data on the documented instructions of a business customer. They do not convert processing for TCW's own account, billing, security, fraud, legal or service-improvement purposes into customer-controlled processing. The parties must complete any required processing details before covered data is uploaded.

Roles and customer instructions

For customer-controlled applicant, talent, client, campaign or workspace data, the customer is the controller or business and TCW is the processor or service provider to the extent applicable law assigns those roles. The customer instructs TCW to process the data only to provide, secure and support the contracted service, follow documented feature settings, and comply with law. TCW will notify the customer if an instruction appears unlawful unless prohibited from doing so.

The customer is independently responsible for a lawful basis, notices, consents, source and accuracy of submitted data; user and administrator permissions; retention choices; responses owed to individuals; and limits on employment, biometric, health, children's, precise-location or other sensitive data. TCW does not authorize uploading sensitive data to a general field or message merely because the field accepts text or files.

Confidentiality, security and access

TCW will limit access to personnel and providers who need it for contracted duties and are bound by confidentiality. TCW will maintain risk-appropriate organizational and technical safeguards, including authentication, authorization, encryption in transit, protected service credentials, logging, vulnerability management, backups, incident handling and deletion controls. A final agreement must attach or link to the verified security measures actually in production rather than promise an unimplemented control.

Subprocessors and international transfers

TCW may use disclosed subprocessors for hosting, database, authentication, storage, communications, monitoring, payments and fulfillment. Before effectiveness, TCW must publish a current subprocessor register with service purpose and processing location, establish equivalent data-protection duties, and provide the notice and objection process required by the governing agreement. TCW remains responsible for subprocessor performance to the extent required by law and contract.

Restricted international transfers require an applicable adequacy decision, approved contractual clauses or another lawful mechanism plus supplementary measures where needed. These candidate terms do not claim that EU, UK, Swiss or another transfer addendum has been executed. A signed transfer attachment must identify the parties, modules, data, purposes, recipients and safeguards before the relevant transfer begins.

Security incidents

After confirming a personal-data breach affecting covered customer data, TCW will notify the customer without undue delay and provide available information reasonably needed for the customer's duties, including nature, affected data, likely consequences and mitigation. Notice is not an admission of fault. The customer remains responsible for its own regulatory or individual notices unless law assigns that duty to TCW.

Return, deletion and retention

At the end of covered service, TCW will make a reasonable export available and delete or return customer-controlled personal data according to the verified retention schedule, unless law requires preservation. Backup deletion follows documented rotation. TCW may retain segregated account, billing, security, fraud, dispute and legal records for its own lawful purposes under the Privacy Notice.

Evidence, audits and conflicts

TCW will provide information reasonably necessary to demonstrate these obligations through current certifications, summaries, questionnaires or a proportionate audit arrangement that protects other customers and system security. Customer audits require reasonable notice, confidentiality, defined scope and reimbursement of exceptional cost unless a confirmed breach makes that allocation unlawful or unfair.

The approved order, these terms, a signed international-transfer attachment and mandatory law control in that order for covered processing. The master Terms govern other service issues. These candidate terms are not effective until the parties and processing details are complete and TCW records formal approval.