Data Processing Agreement
This DPA forms part of the Terms of Service and applies where HRGuru processes Candidate Data on the Client's behalf. It reflects GDPR Art. 28, Moldova Law 133/2011 (and 195/2024 from 23 Aug 2026), and Ukraine Law 2297-VI. Must be executed before any B2B client uploads candidate CVs or receives applications through HRGuru.
| Field | Value |
|---|---|
| Controller | [CLIENT COMPANY NAME, ADDRESS, REGISTRATION] |
| Processor | Viktor Razhev, Moldova |
| Subject matter | Processing candidate personal data via the HRGuru platform |
| Processing nature | AI analysis, structured storage, access management, deletion |
| Purpose | Recruitment support — candidate evaluation and pipeline management |
| Duration | Service term + retention period (see §10) |
| Data subjects | Candidates applying to, or sourced for, the Controller's vacancies |
| Governing law | EU GDPR · Moldova Law 195/2024 · Ukraine Law 2297-VI · SCCs where applicable |
| Effective date | [DATE] — same as or prior to first data upload |
1. Definitions
- Personal data, processing, controller, processor, data subject, personal data breach, supervisory authority — have the meanings in GDPR Art. 4 and the equivalent provisions of Moldovan and Ukrainian Data Protection Law.
- Data Protection Law — the GDPR, Moldova Law No. 133/2011 (and Law No. 195/2024 from 23 August 2026), and Ukraine Law No. 2297-VI, each as applicable.
- Candidate Data — personal data of candidates/applicants processed by the Processor on the Controller's behalf.
- Sub-processor — any third party engaged by the Processor to process Candidate Data.
- SCCs — the European Commission Standard Contractual Clauses and, for Moldova, the CNPDCP-approved standard contractual clauses.
2. Roles and scope
The Controller determines the purposes and means of processing Candidate Data. The Processor processes Candidate Data only to provide the Services and only on the Controller's documented instructions, which comprise the Agreement, this DPA and the Controller's configuration of the Services. The Processor will inform the Controller if, in its opinion, an instruction infringes Data Protection Law.
For the AI system, HRGuru is the provider and the Controller is the deployer (EU AI Act Art. 25–26); a Client-branded application form embedded on the Client's website does not transfer provider status to the Client (Art. 25(1)(a) applies to the AI system, not to intake forms).
3. Processor obligations (GDPR Art. 28(3))
- Process Candidate Data only on the Controller's documented instructions, including for transfers, unless required by law (in which case it informs the Controller unless legally prohibited).
- Ensure persons authorised to process are bound by confidentiality.
- Implement the technical and organisational measures in Annex 2 (Art. 32).
- Respect the conditions for engaging Sub-processors (§4).
- Assist the Controller, by appropriate measures, to respond to data-subject requests (§5).
- Assist the Controller with security, breach notification, DPIAs and prior consultation (§§6–7).
- At the Controller's choice, delete or return Candidate Data at the end of the Services (§10).
- Make available information necessary to demonstrate compliance and allow for audits (§9).
4. Sub-processors
The Controller gives general written authorisation for the Processor to engage the Sub-processors listed in Annex 3. The Processor imposes data-protection obligations on each Sub-processor no less protective than this DPA and remains fully liable for their performance.
Change mechanism (GDPR Art. 28(2) / Moldova Law). The Processor will give the Controller advance notice of any intended addition or replacement of a Sub-processor (via the list at hrguru.work/subprocessors and email to registered contacts). The Controller may object on reasonable data-protection grounds within 30 days; if the parties cannot resolve the objection, the Controller may terminate the affected Services.
5. Data-subject rights assistance
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, to fulfil the Controller's obligation to respond to requests to exercise data-subject rights. If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay and does not respond directly except to confirm receipt.
6. Personal data breach
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting Candidate Data, and provides information reasonably available to help the Controller meet its breach-notification obligations (including notifying the supervisory authority within 72 hours where required).
For processing subject to the law of the Republic of Moldova, breach notification follows Law No. 195/2024 and the requirements of the National Center for Personal Data Protection (CNPDCP) from its entry into force on 23 August 2026.
7. DPIA and prior consultation
The Processor provides reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority, taking into account the information available to it.
8. Bias-audit cooperation (US / NYC LL 144)
Where the Controller uses the Services as an AEDT subject to NYC Local Law 144, the Processor will provide reasonable information and cooperation to support the Controller's annual independent bias audit and candidate-notice obligations.
9. Audit
The Processor makes available information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, by the Controller or a mandated auditor, subject to reasonable confidentiality, security and notice conditions. The Processor may satisfy audit requests by providing third-party certifications or reports where available.
HRGuru likewise cooperates with the CNPDCP where the law of the Republic of Moldova applies.
10. Retention, return and deletion
Retention reconciliation. During the Service term, Candidate Data is retained per the Controller's configured retention period (default 365 days, configurable 30–730 days). On termination or expiry, the Processor deletes or returns Candidate Data, at the Controller's choice, and deletes existing copies within 30 days, unless retention is required by law.
11. International transfers
The Processor hosts Candidate Data in the EU (Frankfurt). Any transfer outside the EEA/Moldova/Ukraine relies on an adequacy decision or appropriate safeguards, including the SCCs. The relevant SCCs are incorporated by reference and prevail in case of conflict regarding transfers.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement.
13. Term
This DPA takes effect on the Effective Date and continues until the Processor has ceased all processing of Candidate Data and complied with §10.
Annex 1 — Details of processing
| Item | Detail |
|---|---|
| Subject matter | AI-assisted recruiting and CV-screening services |
| Duration | Service term plus the retention period |
| Nature and purpose | Hosting, storage, AI scoring/explanation, pipeline management |
| Types of personal data | Identification and contact data, CV content, work history, education, skills, interview notes, application metadata |
| Categories of data subjects | Job candidates and applicants of the Controller (applied or sourced) |
| Special categories | Not intended; Controller must not upload unless lawful and necessary |
Annex 2 — Technical and organisational security measures (Art. 32)
- EU data residency (Frankfurt); encryption in transit (TLS) and at rest where supported.
- Role-based access control; least-privilege; access limited to staff with a business need.
- Salted password hashing; SSO (Google, Microsoft) and MFA for privileged accounts.
- Row-level security and tenant separation isolating each customer's data.
- Append-only audit logging of access to and export of personal data.
- Vulnerability management, monitoring and error tracking with no personal data in logs.
- Documented incident-response and breach-notification procedures.
- Personnel vetting and confidentiality obligations; data processing agreements with Sub-processors.
Annex 3 — Approved sub-processors
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Supabase | Hosting, database, auth | EU (Frankfurt) | EU residency |
| OpenAI | AI CV scoring (API only) | USA | SCCs; no training on submitted content |
| Vercel | Application hosting | USA/EU | EU primary; SCCs |
| Resend | Transactional email | USA | SCCs; no CVs |
| Upstash Redis | Queue (transient) | EU West | EU region |
| Sentry | Error monitoring | USA/EU | Anonymised; no CVs |
| [Payment processor] | Subscription billing | [●] | [●] |
The current list is maintained at hrguru.work/subprocessors.
Signatures
Controller: Name / title / date / signature Processor — Viktor Razhev: Name / title / date / signature
Legal review required: complete all [bracketed] items, confirm the Sub-processor list against the live stack, and have counsel review before signature — especially for a regulated client such as a bank.