Legal

Data Processing Addendum

Effective August 17, 2026

This addendum gives business, vendor, and privacy-review readers a clear view of how data-processing obligations are handled around Ladder Breakers.

1. Purpose and relationship to other policies

This Data Processing Addendum describes the data-protection commitments that apply when Ladder Breakers or an authorized service provider processes personal data in connection with the service.

It works together with our Privacy Policy, Terms of Service, Subprocessors page, and any written agreement that expressly incorporates this addendum.

For individual consumer users, the Privacy Policy explains how your data is collected and used. This addendum is primarily intended for business, institutional, vendor, service-provider, or enterprise arrangements where data-processing terms are needed.

2. Roles

For data submitted by individual users to run their own job search, Ladder Breakers generally determines the purposes and means of processing and acts as a controller, business, or similar role under applicable privacy law.

For business or institutional arrangements where a customer determines the purposes and means of processing personal data and Ladder Breakers processes that data only to provide contracted services, Ladder Breakers may act as a processor, service provider, contractor, or similar role to the extent required by the applicable agreement and law.

Third-party providers that process personal data for Ladder Breakers act as processors, sub-processors, service providers, or independent controllers depending on the service, their role, and their own terms.

3. Categories of personal data

Personal data may include account information, email address, name, resume and career history, job preferences, application answers, generated resumes and cover letters, saved jobs, application status, employer or ATS submission data, support messages, billing metadata, device and log data, security events, and usage analytics.

When a user chooses to provide it for an application, personal data may also include work authorization, sponsorship needs, demographic self-identification, disability or veteran self-identification, salary expectations, location preferences, and other employer-requested application fields.

4. Processing instructions and limits

Ladder Breakers and its service providers process personal data only as needed to provide, secure, support, measure, improve, bill for, and protect the service; comply with law; prevent abuse; resolve disputes; and perform other purposes described in the Privacy Policy or an applicable agreement.

Service providers must not sell personal data, use it for cross-context behavioral advertising, or use customer content to train third-party foundation models unless the user or contracting customer has expressly authorized that use.

If a provider believes an instruction violates applicable law, it should notify Ladder Breakers where legally permitted.

5. Confidentiality and access controls

Personnel with access to personal data must be subject to confidentiality obligations. Access should be limited to people and systems with a legitimate need to provide, secure, support, or maintain the service.

Ladder Breakers may use administrative, technical, and organizational controls such as authentication, authorization, logging, encryption in transit, least-privilege access, monitoring, and vendor review appropriate to the nature of the data and service.

6. Sub-processors

Ladder Breakers may use service providers for hosting, storage, AI processing, authentication, email, payments, analytics, diagnostics, security, support, and employer-platform workflows. Current provider categories are listed on the Subprocessors page.

Sub-processors should be bound by contractual obligations designed to protect personal data and limit processing to the relevant service purpose.

We may add, replace, or remove providers as the service changes. Where a separate written agreement requires notice or objection rights, that agreement controls.

7. Security incidents

If Ladder Breakers becomes aware of a confirmed security incident affecting personal data in systems we control, we will take reasonable steps to investigate, mitigate, and notify affected users, customers, regulators, or other parties when required by law or an applicable agreement.

Notification is not an admission of fault or liability. No internet service can guarantee absolute security.

8. Assistance with privacy rights

Ladder Breakers will reasonably assist with requests to access, correct, delete, export, restrict, or object to processing of personal data where required by law and where we can verify the requester or receive a valid instruction from the relevant controller.

We may reject or limit requests that are unverifiable, excessive, abusive, legally restricted, technically infeasible, or inconsistent with fraud prevention, security, accounting, dispute-resolution, or legal retention requirements.

9. International transfers

Personal data may be processed in the United States and other countries where Ladder Breakers, its infrastructure, or service providers operate.

Where required, we use appropriate legal transfer mechanisms such as Standard Contractual Clauses, data-transfer addenda, adequacy decisions, contractual commitments, or other lawful safeguards.

10. Retention and deletion

Personal data is retained while needed to provide the service and for legitimate business, security, legal, billing, accounting, audit, fraud-prevention, support, and dispute-resolution purposes.

When data is deleted, residual copies may remain in backups or logs for a limited period before aging out according to normal retention cycles, unless longer retention is legally required.

Applications already submitted to employers or ATS platforms are controlled by those third parties and are subject to their own retention and deletion practices.

11. Audits and information requests

Where a signed agreement gives a customer audit or compliance-information rights, Ladder Breakers may satisfy those rights through reasonable documentation, security summaries, vendor information, questionnaires, certifications, or other evidence appropriate to the size and risk of the relationship.

Audits must be reasonable, pre-scheduled, limited to relevant controls, and conducted in a way that protects security, confidentiality, other users, and service availability.

12. Liability and conflicts

This addendum does not expand Ladder Breakers liability beyond the limits in the Terms of Service or any signed agreement, except where applicable law does not allow such limits.

If a signed agreement conflicts with this public addendum, the signed agreement controls for that customer. If this addendum conflicts with mandatory privacy law, the mandatory law controls only to the extent of the conflict.

13. Contact

Data-processing questions can be sent to support@ladderbreakers.ai.