Data Processing Agreement
Last updated: January 1, 2026
This Data Processing Agreement (“DPA”) between Search O Pal (the “Processor”) and users of the platform (the “Controller”) governs the handling of personal data processed through the CV Shortlister platform, effective January 1, 2026.
1. Definitions
This agreement defines core GDPR terms including Controller, Processor, and Data Subject. A “Security Incident” is defined as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
2. Scope
This DPA covers the processing of CVs, candidate contact information, employment history, and job descriptions to provide AI-powered CV screening and candidate matching services.
3. Controller Duties
The Controller must ensure a lawful basis for processing, provide data subject notices, maintain data accuracy, and implement protective measures before transmitting data to the platform.
4. Processor Responsibilities
The Processor will process data only per the Controller's instructions, maintain confidentiality, implement appropriate security measures, obtain prior approval for sub-processors, and assist with data subject rights requests.
5. Sub-Processors
General authorization is granted for sub-processors providing cloud hosting, AI/ML services, analytics, and support platforms. Changes to sub-processors require 14 days' notice, with a 30-day termination option available to the Controller.
6. International Transfers
The Processor ensures appropriate transfer mechanisms, such as Standard Contractual Clauses, and conducts data transfer impact assessments where required.
7. Incident Response
Security incidents are notified to the Controller without undue delay, and in any event within 48 hours, including a description of the incident, the affected parties count, likely consequences, and remediation measures taken.
8. Data Subject Rights
The Processor assists the Controller by forwarding data subject requests promptly and providing technical features to support timely responses.
9. Deletion
Upon termination of services, data deletion is completed within 30 days of the request, with written certification of deletion provided to the Controller.
10. Audits
The Processor permits annual audits and inspections with 30 days' notice, or may satisfy audit requirements through recognized third-party reports such as SOC 2 Type II.
11. Security Measures
Security measures include TLS 1.3 encryption in transit, AES-256 encryption at rest, multi-factor authentication, regular staff training, and documented incident response procedures.