SprintHR Data Processing Addendum
Provider: Gleent, Inc.
Product: SprintHR
Effective Date: October 1, 2026
Version: 1.0
This SprintHR Data Processing Addendum (the “DPA”) forms part of the SprintHR Customer Agreement, an Order, or another written agreement between Gleent, Inc. (“Gleent”) and the customer using SprintHR (“Customer”) that incorporates this DPA (collectively, the “Agreement”).
This DPA applies where Gleent processes Personal Data on behalf of Customer in connection with SprintHR and Customer acts as a Personal Information Controller and Gleent acts as a Personal Information Processor under Republic Act No. 10173, the Data Privacy Act of 2012 (“Philippine DPA”), its Implementing Rules and Regulations (“IRR”), applicable issuances of the National Privacy Commission (“NPC”), or equivalent roles under other applicable data protection laws.
1. Definitions
For this DPA:
- “Customer Personal Data” means Personal Data contained in Customer Data that Gleent processes on behalf of Customer in providing SprintHR.
- “Data Subject” means an individual whose Personal Data is processed.
- “Personal Data” includes personal information, sensitive personal information, and privileged information as defined by applicable Philippine data protection law.
- “Personal Information Controller” or “PIC” has the meaning given under applicable Philippine data protection law and generally refers to the party that controls or determines the purpose and extent of processing Personal Data.
- “Personal Information Processor” or “PIP” has the meaning given under applicable Philippine data protection law and generally refers to a party that processes Personal Data on behalf of a PIC.
- “Personal Data Breach” means a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data, or another event treated as a personal data breach under applicable law.
- “Processing” or “process” means any operation performed on Personal Data, including collection, recording, organization, storage, updating, modification, retrieval, consultation, use, transmission, disclosure, consolidation, blocking, erasure, or destruction.
- “Subprocessor” means a third party engaged by Gleent to process Customer Personal Data on Gleent's behalf in connection with the Services.
- “Services” means SprintHR and the related services covered by the Agreement.
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
2. Roles and Scope
2.1 Customer as PIC
For Customer Personal Data processed through SprintHR on Customer's behalf, Customer generally acts as the PIC and determines the lawful purpose, scope, and means of the relevant processing.
Customer is responsible for:
- establishing an appropriate lawful basis for its processing of Personal Data;
- providing required privacy notices and obtaining consent where consent is legally required;
- determining what Personal Data is submitted to SprintHR;
- configuring access, roles, permissions, workflows, retention settings, and other Customer-controlled features appropriately;
- ensuring its instructions to Gleent comply with applicable law; and
- responding to Data Subjects and regulators as required by law, with Gleent's assistance where applicable under this DPA.
2.2 Gleent as PIP
Gleent will process Customer Personal Data on behalf of Customer only as necessary to provide, secure, support, maintain, and improve the operation and reliability of the Services in accordance with Customer's documented instructions, the Agreement, this DPA, applicable Orders, and Customer's lawful use and configuration of SprintHR.
For clarity, this DPA does not govern Personal Data for which Gleent independently determines the purpose and means of processing and therefore acts as a PIC. Such processing is addressed by the SprintHR Privacy Policy and applicable law.
3. Details of Processing
The subject matter, duration, nature and purpose of processing, types of Personal Data, categories of Data Subjects, and geographic aspects of processing are described in Annex 1.
Customer acknowledges that its use and configuration of particular SprintHR modules determines which categories of Customer Personal Data are actually processed.
4. Documented Instructions
Gleent will process Customer Personal Data only on Customer's documented instructions, including instructions contained in:
- the Agreement and this DPA;
- an applicable Order or statement of work;
- Customer's configuration and authorized use of SprintHR;
- Customer's use of APIs, integrations, workflows, and administrative controls; and
- other written instructions accepted by Gleent.
Gleent may process Customer Personal Data where required by applicable law. Where legally permitted, Gleent will inform Customer of that legal requirement before the processing or disclosure.
If Gleent reasonably believes a Customer instruction violates the Philippine DPA, its IRR, an applicable NPC issuance, or another applicable data protection law, Gleent will inform Customer without undue delay and may suspend the affected processing to the extent reasonably necessary while the parties address the issue.
5. Confidentiality and Personnel
Gleent will ensure that personnel authorized to process Customer Personal Data:
- are subject to appropriate confidentiality obligations;
- receive access only where reasonably necessary for their duties;
- are informed of relevant privacy and security responsibilities; and
- process Customer Personal Data only in accordance with authorized instructions and applicable policies.
Gleent will take reasonable steps to limit access to Customer Personal Data based on role, responsibility, and legitimate business need.
6. Security Measures
Gleent will implement reasonable and appropriate organizational, physical, and technical measures designed to preserve the confidentiality, integrity, and availability of Customer Personal Data and protect it against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, or other unlawful processing.
Measures may include, as appropriate to the Services and risks involved:
- identity and access controls;
- role-based permissions and least-privilege access;
- authentication and account-security controls;
- encryption or other appropriate safeguards for data in transit and at rest;
- logging, monitoring, and audit trails;
- vulnerability and security-management practices;
- backup and disaster-recovery procedures;
- personnel confidentiality and access restrictions;
- incident-response procedures; and
- appropriate safeguards for development, deployment, and change-management activities.
Additional information regarding applicable measures may be described in Annex 2 or SprintHR Security / Trust documentation.
7. Subprocessors
7.1 General Authorization
Customer provides Gleent with general written authorization to engage Subprocessors that are reasonably necessary to provide the Services, subject to this Section and the then-current SprintHR Subprocessor List.
7.2 Subprocessor Obligations
Before permitting a Subprocessor to process Customer Personal Data, Gleent will impose data-protection obligations appropriate to the processing and designed to provide a level of protection materially consistent with Gleent's obligations under this DPA, taking into account the nature of the services provided by that Subprocessor.
Gleent remains responsible for the performance of its Subprocessors to the extent required by the Agreement and applicable law.
7.3 Changes to Subprocessors
Gleent may add or replace Subprocessors as the Services evolve. Where reasonably practicable and required by the Agreement or applicable law, Gleent will provide notice of material new Subprocessors through the Subprocessor List, the Services, email, or another reasonable method.
If Customer has a reasonable data-protection objection to a new Subprocessor, Customer may notify Gleent promptly with the grounds for its objection. The parties will work in good faith to identify a commercially reasonable solution. If no reasonable solution is available, the parties may address the affected Service in accordance with the Agreement.
8. International and Cross-Border Processing
Customer authorizes Gleent and its authorized Subprocessors to process Customer Personal Data in the Philippines and in other countries identified through the SprintHR Subprocessor List or otherwise disclosed in connection with the Services, subject to this DPA and applicable law.
Gleent will take reasonable steps to ensure that cross-border processing of Customer Personal Data is subject to appropriate contractual, organizational, technical, and legal safeguards consistent with applicable Philippine data protection requirements.
Where Customer instructs Gleent to enable an integration or processing activity involving a transfer to a third party selected or controlled by Customer, that transfer will be treated as part of Customer's documented instructions, subject to the Agreement and applicable law.
9. Data Subject Requests
Taking into account the nature of the processing, Gleent will provide reasonable assistance to Customer through appropriate technical and organizational measures, where practicable, to help Customer respond to valid requests by Data Subjects exercising rights available under applicable law.
If Gleent receives a request directly from a Data Subject relating primarily to Customer Personal Data for which Customer is the PIC, Gleent may:
- direct the Data Subject to Customer;
- notify or forward the request to Customer where appropriate; and
- provide reasonable assistance to Customer in responding.
Unless required by applicable law, Gleent will not independently fulfill a request to access, correct, delete, block, port, or otherwise act on Customer-controlled employment, applicant, payroll, attendance, performance, or similar records without Customer's instruction.
10. Personal Data Breaches and Security Incidents
Gleent will maintain procedures to identify, contain, investigate, mitigate, document, and respond to Personal Data Breaches affecting Customer Personal Data.
Upon becoming aware of a Personal Data Breach affecting Customer Personal Data, Gleent will notify Customer without undue delay and provide information reasonably available to Gleent that Customer may need to assess the incident and comply with applicable notification or reporting obligations.
Such information may include, as available:
- the nature of the incident;
- categories of affected Personal Data and Data Subjects;
- approximate scope of affected records or individuals, where known;
- likely or reasonably foreseeable consequences;
- containment, mitigation, and remediation measures taken or proposed; and
- a contact point for follow-up information.
Gleent may provide information in phases where complete details are not immediately available and will provide reasonable updates as the investigation progresses.
Each party remains responsible for its own regulatory and Data Subject notification obligations under applicable law. Where Customer is the PIC, Gleent will provide reasonable assistance to Customer in determining and fulfilling applicable breach-notification obligations.
Notification of an incident under this Section is not an admission of fault or liability by Gleent.
11. Assistance with Compliance
Taking into account the nature of the processing and the information available to Gleent, Gleent will provide reasonable assistance to Customer in supporting Customer's compliance with applicable data protection obligations relating to the Services, which may include:
- security of processing;
- Personal Data Breach assessment and response;
- Data Subject rights;
- privacy impact assessments where relevant to Customer's use of SprintHR;
- consultations with the NPC or another competent authority where legally required; and
- information reasonably necessary for Customer to understand the processing performed through the Services.
Customer remains responsible for determining whether its particular use of SprintHR requires a privacy impact assessment, additional notice, consent, registration, human review, or other safeguards.
12. AI-Assisted Processing and Automated Features
Where Customer enables SprintHR artificial-intelligence-assisted, automated classification, recommendation, analysis, or similar features that process Customer Personal Data, such processing forms part of Customer's documented instructions under this DPA.
Where Gleent uses a third-party AI provider to process Customer Personal Data on Gleent's behalf, that provider will be treated as a Subprocessor where applicable and will be subject to Section 7 and the SprintHR Subprocessor List.
Customer is responsible for determining the lawful basis, appropriate use, transparency, human review, and other safeguards required for employment-related automated processing or profiling configured or initiated by Customer.
Gleent will provide information reasonably available to it regarding relevant SprintHR processing features to support Customer's compliance obligations. Additional product-specific obligations may be stated in the SprintHR AI Terms.
13. Return, Export, Retention, and Deletion
During the applicable subscription term, Customer may access or export Customer Personal Data using functionality made available by SprintHR, subject to the applicable plan and technical limitations.
Following termination or expiration of the Services, and subject to Customer's instructions, the Agreement, applicable retention periods, documented backup procedures, and applicable law, Gleent will delete or return Customer Personal Data in accordance with the applicable SprintHR data-return and deletion process.
Where Customer requests deletion of Customer Personal Data and Gleent is legally permitted to comply, Gleent will delete the applicable data from active systems within the applicable operational deletion process.
Residual copies may remain temporarily in backups, disaster-recovery systems, logs, archives, or other systems where immediate deletion is not technically feasible, provided that such retained copies remain protected under this DPA and are deleted, overwritten, or rendered inaccessible according to applicable retention cycles unless continued storage is required by law.
Gleent may retain information that has been appropriately aggregated or de-identified so that it no longer constitutes Personal Data, subject to applicable law.
14. Audit and Demonstration of Compliance
Gleent will make available to Customer information reasonably necessary to demonstrate Gleent's compliance with its obligations as a PIP under this DPA and applicable law.
Upon reasonable written request, Gleent may satisfy this obligation through available security or compliance documentation, questionnaires, certifications, independent assessment reports, audit summaries, or similar materials where appropriate.
Where such materials are not reasonably sufficient and an audit is required by applicable law or reasonably necessary to verify compliance with this DPA, Customer may request an audit subject to the following conditions:
- reasonable advance written notice;
- reasonable scope, timing, duration, and frequency;
- protection of Gleent's confidential information, systems, security information, and information relating to other customers;
- use of an independent auditor bound by appropriate confidentiality obligations where appropriate; and
- measures designed to avoid unreasonable disruption to Gleent's operations.
The parties will cooperate in good faith regarding reasonable audit arrangements. Customer will bear its audit costs unless otherwise required by applicable law or agreed in writing.
15. Customer Responsibilities
Customer represents and warrants that its instructions and use of SprintHR comply with applicable data protection law.
Without limiting the Agreement, Customer is responsible for:
- ensuring that Customer has the right and lawful basis to provide Customer Personal Data to Gleent for processing;
- providing legally required notices to employees, applicants, contractors, dependents, beneficiaries, and other relevant Data Subjects;
- obtaining consent where consent is specifically required by law;
- limiting Customer Personal Data to what is appropriate and necessary for Customer's purposes;
- properly managing Authorized Users, roles, permissions, credentials, and integrations under Customer's control;
- determining appropriate retention periods for Customer-controlled HR records; and
- ensuring that Customer does not instruct Gleent to process Personal Data in a manner prohibited by applicable law.
16. Regulatory Cooperation
Each party will reasonably cooperate with the other where necessary to respond to a lawful inquiry, investigation, compliance check, or request from the NPC or another competent data-protection authority concerning processing covered by this DPA.
Nothing in this DPA requires either party to disclose information in violation of law, legal privilege, confidentiality obligations owed to another person, or reasonable security restrictions.
17. Records and Accountability
Gleent will maintain records and documentation regarding its processing of Customer Personal Data as required by applicable law and will make relevant information available to Customer as reasonably necessary to demonstrate compliance with this DPA.
Customer remains responsible for its own records, registrations, policies, notices, lawful bases, and accountability obligations as PIC.
18. Relationship with the Agreement
This DPA forms part of the Agreement.
If there is a conflict between this DPA and the Agreement regarding the processing or protection of Customer Personal Data, this DPA controls for that subject matter unless a mutually signed agreement expressly states otherwise.
If an applicable Order contains specifically negotiated data-protection terms that expressly override a provision of this DPA, those terms control only to the extent of that express conflict.
Except as modified by this DPA, the Agreement remains in full force and effect.
Liability arising under this DPA is subject to the liability provisions of the Agreement unless applicable law prohibits the relevant limitation or the parties expressly agree otherwise in writing.
19. Changes to this DPA
Gleent may update this DPA to reflect changes in applicable law, NPC requirements, the Services, security practices, subprocessors, or processing activities.
For material changes that affect Customer's rights or obligations, Gleent will provide reasonable notice before the changes take effect where required by applicable law or the Agreement.
Gleent will maintain the effective date or version of the then-current DPA and may retain prior versions for reference.
20. Contact and Data Protection Officer
Questions or notices concerning this DPA or Gleent's processing of Customer Personal Data may be directed to:
Gleent, Inc.
Unit 18, 2nd Floor, Sundrel Bldg.
Brgy. Sala, City of Cabuyao
Laguna, Philippines
Data Protection Officer / Privacy Email: [email protected]
Formal contractual or legal notices that are required under the Agreement may also be sent through the legal-notice channel specified in the Customer Agreement.
Annex 1 — Details of Processing
A. Subject Matter
Processing of Customer Personal Data as necessary to provide, operate, secure, support, maintain, and administer SprintHR and the modules, integrations, APIs, workflows, and AI-assisted features enabled or used by Customer.
B. Duration
Processing occurs for the duration of Customer's use of the Services and for any additional period reasonably necessary to complete Customer-directed return or deletion, comply with documented backup and retention procedures, resolve disputes, meet contractual obligations, or satisfy applicable legal requirements.
C. Nature and Purpose of Processing
Depending on Customer's use of SprintHR, processing may include:
- collection, recording, organization, structuring, and storage;
- retrieval, consultation, display, and use;
- updating, correction, consolidation, and synchronization;
- calculation and processing of attendance, payroll, leave, benefits, and related HR information;
- recruitment, applicant tracking, performance, workflow, task, and organizational processing;
- generation of reports, records, documents, notifications, and audit trails;
- authentication, authorization, logging, security, fraud prevention, troubleshooting, backup, and disaster recovery;
- processing through Customer-enabled integrations and APIs;
- AI-assisted summarization, drafting, classification, search, retrieval, recommendation, analysis, or other enabled decision-support functions; and
- deletion, return, export, blocking, or other processing performed according to Customer's instructions and applicable law.
D. Categories of Data Subjects
Depending on Customer's use of the Services, Data Subjects may include:
- Customer employees and workers;
- applicants and candidates;
- contractors and consultants;
- former employees or workers;
- interns and trainees;
- dependents, beneficiaries, emergency contacts, and related individuals;
- Customer administrators, managers, HR personnel, payroll personnel, recruiters, and other Authorized Users; and
- other individuals whose Personal Data Customer lawfully submits to or processes through SprintHR.
E. Categories of Personal Data
Depending on the modules and features used, Customer Personal Data may include:
- names, contact details, addresses, dates of birth, and profile information;
- employee, applicant, contractor, or personnel identifiers;
- job title, department, work location, reporting relationships, and employment status;
- attendance, schedules, time records, leave, absences, and overtime;
- compensation, payroll, allowances, commissions, bonuses, deductions, and benefits;
- tax, statutory, government-issued identification, and compliance information;
- bank or payment details used for payroll, reimbursements, or related functions;
- employment contracts, memoranda, notices, certificates, permits, and other documents;
- resumes, education and employment history, skills, qualifications, references, interview notes, and assessments;
- performance records, goals, evaluations, training, disciplinary or related employment records where lawfully used by Customer;
- dependent, beneficiary, emergency-contact, or related information;
- account, authentication, role, permission, device, IP address, usage, activity, and audit-log information associated with Customer's environment;
- prompts, instructions, retrieved context, files, metadata, and generated outputs associated with enabled AI-assisted features; and
- other Personal Data that Customer or its Authorized Users lawfully submit to or generate through the Services.
Some Customer Personal Data may constitute sensitive personal information or privileged information under applicable law.
F. Geographic Location of Processing
Customer Personal Data may be processed in the Philippines and in other countries where Gleent's authorized Subprocessors provide infrastructure or services. The then-current SprintHR Subprocessor List identifies relevant Subprocessors and may describe applicable processing locations or regions.
Customer may contact [email protected] for additional information reasonably available regarding processing locations applicable to the Services.
Annex 2 — Summary of Security Measures
Gleent's security measures are designed to be appropriate to the nature, scope, context, and risks of the processing and may evolve as technologies, threats, and the Services change.
Measures may include, as applicable:
1. Access and Identity Management
- unique user and administrative accounts;
- role-based access controls;
- least-privilege access principles;
- authentication controls appropriate to the relevant system;
- procedures for granting, reviewing, modifying, and revoking access; and
- restrictions on personnel access to production and Customer environments.
2. Data Protection
- encryption or equivalent safeguards for supported data in transit and at rest;
- logical tenant or access separation appropriate to SprintHR's architecture;
- controlled handling of secrets, credentials, and access tokens;
- backup and recovery safeguards; and
- secure deletion or lifecycle controls appropriate to the storage system.
3. Monitoring and Security Operations
- security and application logging;
- monitoring of relevant systems and events;
- vulnerability identification and remediation practices;
- incident detection and response procedures; and
- preservation of relevant records during security investigations where appropriate.
4. Organizational Measures
- personnel confidentiality obligations;
- privacy and security responsibilities for personnel with relevant access;
- documented security and incident-response procedures;
- appropriate vendor and Subprocessor review; and
- review and improvement of safeguards as reasonably necessary.
5. Resilience and Recovery
- backup procedures appropriate to relevant systems;
- disaster-recovery and service-restoration measures;
- operational monitoring; and
- reasonable measures intended to support availability and integrity of the Services.
This Annex describes categories of safeguards and is not intended to disclose confidential security architecture or create a representation that any particular control eliminates all risk.
