Data Processing Agreement

Last updated: January 1, 2026

This Data Processing Agreement (“DPA”) between Search O Pal (the “Processor”) and users of the platform (the “Controller”) governs the handling of personal data processed through the CV Shortlister platform, effective January 1, 2026.

1. Definitions

This agreement defines core GDPR terms including Controller, Processor, and Data Subject. A “Security Incident” is defined as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.

2. Scope

This DPA covers the processing of CVs, candidate contact information, employment history, and job descriptions to provide AI-powered CV screening and candidate matching services.

3. Controller Duties

The Controller must ensure a lawful basis for processing, provide data subject notices, maintain data accuracy, and implement protective measures before transmitting data to the platform.

4. Processor Responsibilities

The Processor will process data only per the Controller's instructions, maintain confidentiality, implement appropriate security measures, obtain prior approval for sub-processors, and assist with data subject rights requests.

5. Sub-Processors

General authorization is granted for sub-processors providing cloud hosting, AI/ML services, analytics, and support platforms. Changes to sub-processors require 14 days' notice, with a 30-day termination option available to the Controller.

6. International Transfers

The Processor ensures appropriate transfer mechanisms, such as Standard Contractual Clauses, and conducts data transfer impact assessments where required.

7. Incident Response

Security incidents are notified to the Controller without undue delay, and in any event within 48 hours, including a description of the incident, the affected parties count, likely consequences, and remediation measures taken.

8. Data Subject Rights

The Processor assists the Controller by forwarding data subject requests promptly and providing technical features to support timely responses.

9. Deletion

Upon termination of services, data deletion is completed within 30 days of the request, with written certification of deletion provided to the Controller.

10. Audits

The Processor permits annual audits and inspections with 30 days' notice, or may satisfy audit requirements through recognized third-party reports such as SOC 2 Type II.

11. Security Measures

Security measures include TLS 1.3 encryption in transit, AES-256 encryption at rest, multi-factor authentication, regular staff training, and documented incident response procedures.