Skip to content
ENROUKRU
1. Definitions2. Roles and scope3. Processor obligations (GDPR Art. 28(3))4. Sub-processors5. Data-subject rights assistance6. Personal data breach7. DPIA and prior consultation8. Bias-audit cooperation (US / NYC LL 144)9. Audit10. Retention, return and deletion11. International transfers12. Liability13. TermAnnex 1 — Details of processingAnnex 2 — Technical and organisational security measures (Art. 32)Annex 3 — Approved sub-processorsSignatures
Effective [●] 2026 · Applies to: EU/EEA · Moldova · Ukraine · USA

Data Processing Agreement

This DPA forms part of the Terms of Service and applies where HRGuru processes Candidate Data on the Client's behalf. It reflects GDPR Art. 28, Moldova Law 133/2011 (and 195/2024 from 23 Aug 2026), and Ukraine Law 2297-VI. Must be executed before any B2B client uploads candidate CVs or receives applications through HRGuru.

FieldValue
Controller[CLIENT COMPANY NAME, ADDRESS, REGISTRATION]
ProcessorViktor Razhev, Moldova
Subject matterProcessing candidate personal data via the HRGuru platform
Processing natureAI analysis, structured storage, access management, deletion
PurposeRecruitment support — candidate evaluation and pipeline management
DurationService term + retention period (see §10)
Data subjectsCandidates applying to, or sourced for, the Controller's vacancies
Governing lawEU GDPR · Moldova Law 195/2024 · Ukraine Law 2297-VI · SCCs where applicable
Effective date[DATE] — same as or prior to first data upload

1. Definitions

  • Personal data, processing, controller, processor, data subject, personal data breach, supervisory authority — have the meanings in GDPR Art. 4 and the equivalent provisions of Moldovan and Ukrainian Data Protection Law.
  • Data Protection Law — the GDPR, Moldova Law No. 133/2011 (and Law No. 195/2024 from 23 August 2026), and Ukraine Law No. 2297-VI, each as applicable.
  • Candidate Data — personal data of candidates/applicants processed by the Processor on the Controller's behalf.
  • Sub-processor — any third party engaged by the Processor to process Candidate Data.
  • SCCs — the European Commission Standard Contractual Clauses and, for Moldova, the CNPDCP-approved standard contractual clauses.

2. Roles and scope

The Controller determines the purposes and means of processing Candidate Data. The Processor processes Candidate Data only to provide the Services and only on the Controller's documented instructions, which comprise the Agreement, this DPA and the Controller's configuration of the Services. The Processor will inform the Controller if, in its opinion, an instruction infringes Data Protection Law.

For the AI system, HRGuru is the provider and the Controller is the deployer (EU AI Act Art. 25–26); a Client-branded application form embedded on the Client's website does not transfer provider status to the Client (Art. 25(1)(a) applies to the AI system, not to intake forms).

3. Processor obligations (GDPR Art. 28(3))

  • Process Candidate Data only on the Controller's documented instructions, including for transfers, unless required by law (in which case it informs the Controller unless legally prohibited).
  • Ensure persons authorised to process are bound by confidentiality.
  • Implement the technical and organisational measures in Annex 2 (Art. 32).
  • Respect the conditions for engaging Sub-processors (§4).
  • Assist the Controller, by appropriate measures, to respond to data-subject requests (§5).
  • Assist the Controller with security, breach notification, DPIAs and prior consultation (§§6–7).
  • At the Controller's choice, delete or return Candidate Data at the end of the Services (§10).
  • Make available information necessary to demonstrate compliance and allow for audits (§9).

4. Sub-processors

The Controller gives general written authorisation for the Processor to engage the Sub-processors listed in Annex 3. The Processor imposes data-protection obligations on each Sub-processor no less protective than this DPA and remains fully liable for their performance.

Change mechanism (GDPR Art. 28(2) / Moldova Law). The Processor will give the Controller advance notice of any intended addition or replacement of a Sub-processor (via the list at hrguru.work/subprocessors and email to registered contacts). The Controller may object on reasonable data-protection grounds within 30 days; if the parties cannot resolve the objection, the Controller may terminate the affected Services.

5. Data-subject rights assistance

Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, to fulfil the Controller's obligation to respond to requests to exercise data-subject rights. If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay and does not respond directly except to confirm receipt.

6. Personal data breach

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting Candidate Data, and provides information reasonably available to help the Controller meet its breach-notification obligations (including notifying the supervisory authority within 72 hours where required).

For processing subject to the law of the Republic of Moldova, breach notification follows Law No. 195/2024 and the requirements of the National Center for Personal Data Protection (CNPDCP) from its entry into force on 23 August 2026.

7. DPIA and prior consultation

The Processor provides reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority, taking into account the information available to it.

8. Bias-audit cooperation (US / NYC LL 144)

Where the Controller uses the Services as an AEDT subject to NYC Local Law 144, the Processor will provide reasonable information and cooperation to support the Controller's annual independent bias audit and candidate-notice obligations.

9. Audit

The Processor makes available information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, by the Controller or a mandated auditor, subject to reasonable confidentiality, security and notice conditions. The Processor may satisfy audit requests by providing third-party certifications or reports where available.

HRGuru likewise cooperates with the CNPDCP where the law of the Republic of Moldova applies.

10. Retention, return and deletion

Retention reconciliation. During the Service term, Candidate Data is retained per the Controller's configured retention period (default 365 days, configurable 30–730 days). On termination or expiry, the Processor deletes or returns Candidate Data, at the Controller's choice, and deletes existing copies within 30 days, unless retention is required by law.

11. International transfers

The Processor hosts Candidate Data in the EU (Frankfurt). Any transfer outside the EEA/Moldova/Ukraine relies on an adequacy decision or appropriate safeguards, including the SCCs. The relevant SCCs are incorporated by reference and prevail in case of conflict regarding transfers.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement.

13. Term

This DPA takes effect on the Effective Date and continues until the Processor has ceased all processing of Candidate Data and complied with §10.

Annex 1 — Details of processing

ItemDetail
Subject matterAI-assisted recruiting and CV-screening services
DurationService term plus the retention period
Nature and purposeHosting, storage, AI scoring/explanation, pipeline management
Types of personal dataIdentification and contact data, CV content, work history, education, skills, interview notes, application metadata
Categories of data subjectsJob candidates and applicants of the Controller (applied or sourced)
Special categoriesNot intended; Controller must not upload unless lawful and necessary

Annex 2 — Technical and organisational security measures (Art. 32)

  • EU data residency (Frankfurt); encryption in transit (TLS) and at rest where supported.
  • Role-based access control; least-privilege; access limited to staff with a business need.
  • Salted password hashing; SSO (Google, Microsoft) and MFA for privileged accounts.
  • Row-level security and tenant separation isolating each customer's data.
  • Append-only audit logging of access to and export of personal data.
  • Vulnerability management, monitoring and error tracking with no personal data in logs.
  • Documented incident-response and breach-notification procedures.
  • Personnel vetting and confidentiality obligations; data processing agreements with Sub-processors.

Annex 3 — Approved sub-processors

Sub-processorPurposeLocationSafeguard
SupabaseHosting, database, authEU (Frankfurt)EU residency
OpenAIAI CV scoring (API only)USASCCs; no training on submitted content
VercelApplication hostingUSA/EUEU primary; SCCs
ResendTransactional emailUSASCCs; no CVs
Upstash RedisQueue (transient)EU WestEU region
SentryError monitoringUSA/EUAnonymised; no CVs
[Payment processor]Subscription billing[●][●]

The current list is maintained at hrguru.work/subprocessors.

Signatures

Controller: Name / title / date / signature Processor — Viktor Razhev: Name / title / date / signature

Legal review required: complete all [bracketed] items, confirm the Sub-processor list against the live stack, and have counsel review before signature — especially for a regulated client such as a bank.

Last updated: [●] 2026 · Version 3.2 · For questions: privacy@hrguru.work

To execute a signed DPA, create an account or contact sales@hrguru.work.

⬇ Download DPA as PDF
HR
HRGuru
For CompaniesNewsPricing
Sign inStart free
HR
HRGuru

AI-powered hiring for IT teams.

Product

  • Features
  • Pricing
  • For Companies

Company

  • About
  • Recruiting News
  • Contact

Legal

  • Legal

© 2026 HRGuru. All rights reserved.

Built with ♥ in Moldova