DRAFT — PENDING LEGAL REVIEW. This document is a first-pass working draft prepared for internal review only. It has not been reviewed or approved by qualified legal counsel, has not been executed by any party, and must not be sent to a customer, relied upon, or represented as effective until counsel has reviewed it in full. Bracketed text in [ALL CAPS] marks a placeholder that must be filled in (or deliberately confirmed as not applicable) before this document is used. See "Notes for Legal Review" at the end of this document for a list of open questions and known gaps identified during drafting.
Data Processing Agreement
coffee-on.me
Version 0.1 — Drafted 2026-09-09
Parties
This Data Processing Agreement ("DPA") is entered into between:
-
the Company, operating the coffee-on.me platform at the domain
coffee-on.me, a company registered in [JURISDICTION OF INCORPORATION] with company number [COMPANY REGISTRATION NUMBER], whose registered office is at [REGISTERED ADDRESS] ("Company", "we", "us"); and -
[CUSTOMER LEGAL NAME], the entity identified as the customer in the applicable order, sign-up flow, or Master Subscription Agreement with the Company ("Controller", "Customer", "you"),
each a "Party" and together the "Parties."
Background
A. The Controller has agreed to receive, or is receiving, access to the coffee-on.me software-as-a-service platform (the "Services") under a Terms of Service, Master Subscription Agreement, or other written agreement between the Parties governing the Controller's use of the Services (the "Agreement").
B. In the course of providing the Services, the Company processes personal data on behalf of the Controller, including personal data about the Controller's prospective and existing candidates, the Controller's clients, and the Controller's own authorized users.
C. The Parties are entering into this DPA to set out their respective obligations with respect to that processing, in order to comply with the UK GDPR, the EU GDPR (to the extent applicable), and the Data Protection Act 2018.
D. This DPA is incorporated into, and forms part of, the Agreement. In the event of a conflict between this DPA and the Agreement in respect of the processing of personal data, this DPA prevails.
1. Definitions and Interpretation
1.1 In this DPA, the following terms have the meanings set out below. Capitalized terms not defined in this DPA have the meanings given to them in the Agreement.
- "Applicable Data Protection Laws" means, to the extent applicable to the processing of personal data under the Agreement: (a) the UK General Data Protection Regulation as it forms part of UK law by virtue of the Data Protection Act 2018 ("UK GDPR"); (b) the Data Protection Act 2018; (c) the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"); and (d) any implementing, derivative, or successor legislation in the United Kingdom or European Economic Area, in each case as amended, extended, or re-enacted from time to time.
- "Controller," "Processor," "Data Subject," "Personal Data," "Processing" (and "process"), "Personal Data Breach," and "Special Categories of Personal Data" have the meanings given in the UK GDPR / EU GDPR, and "processing" is construed accordingly.
- "Account Contact Information" means the name, business email address, and billing contact details of individuals the Controller designates to administer its account, used solely for account provisioning, invoicing, service communications, and security notices. The Company processes Account Contact Information as an independent controller.
- "Controller Personal Data" means all Personal Data processed by the Company via the Services in connection with the Agreement, other than Account Contact Information — including, without limitation, Personal Data about Candidates, Clients, and the Controller's own Authorized Users, as further described in Annex 1.
- "Authorized User" means an individual authorized by the Controller to access the Services on the Controller's behalf, including as a recruiter or workspace member.
- "Candidate" means an individual whose Personal Data is processed within the Services in connection with a recruitment or hiring process facilitated by the Controller.
- "Client" means an individual point of contact at an organization that is a client or prospective client of the Controller, whose Personal Data is processed within the Services.
- "Sub-processor" means any processor engaged by the Company to process Controller Personal Data in the provision of the Services, as listed in Annex 2.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission in Commission Implementing Decision (EU) 2021/914, as amended, together with, where the transfer is subject to UK GDPR, the UK's International Data Transfer Addendum to those clauses issued by the Information Commissioner's Office (the "UK Addendum"), or the UK's stand-alone International Data Transfer Agreement ("IDTA"), as applicable.
- "Data Subject Request" means a request made by, or on behalf of, a Data Subject to exercise a right under Applicable Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection).
1.2 The words "include," "includes," and "including" are to be construed without limitation.
2. Roles of the Parties
2.1 As between the Parties, and in respect of Controller Personal Data, the Controller is the Controller and the Company is the Processor. The Controller is the Controller of Personal Data relating to its Candidates and Clients; the Company processes such Personal Data solely to provide the Services to the Controller.
2.2 In respect of Account Contact Information, the Company is an independent Controller for the limited purposes described in Section 1.1. This DPA does not apply to that processing, which is governed by the Company's privacy notice.
2.3 The Company will not process Controller Personal Data for any purpose other than to provide, maintain, secure, and support the Services in accordance with the Controller's documented instructions, and as required by law.
3. Scope, Subject Matter, and Duration of Processing
3.1 The subject matter, duration, nature and purpose of the processing, and the categories of Data Subjects and Personal Data, are set out in Annex 1 (Details of Processing).
3.2 The Company will process Controller Personal Data for the duration of the Agreement, and thereafter only to the extent, and for so long as, necessary to comply with Section 10 (Deletion or Return of Data on Termination) or a legal retention obligation.
4. Controller's Instructions
4.1 The Company will process Controller Personal Data only on the Controller's documented instructions, which are constituted by: (a) the Agreement; (b) this DPA; (c) the Controller's configuration and use of the Services (including in-product actions such as uploading a document, initiating a chat, requesting a call, or recording a consent); and (d) further written instructions given by the Controller from time to time, provided such instructions are consistent with the Agreement.
4.2 If the Company reasonably believes an instruction from the Controller infringes Applicable Data Protection Laws, the Company will promptly inform the Controller, and may suspend performance of that instruction pending resolution.
4.3 The Company will promptly inform the Controller if, in its opinion, it is required by law (other than Applicable Data Protection Laws) to process Controller Personal Data other than in accordance with the Controller's instructions, unless that law prohibits such notice on important grounds of public interest.
5. Confidentiality of Processing Personnel
5.1 The Company will ensure that any individual it authorizes to process Controller Personal Data (including employees, contractors, and Sub-processor personnel) is subject to a binding written obligation of confidentiality (whether contractual or statutory), and processes Controller Personal Data only to the extent necessary for their role.
6. Security of Processing
6.1 The Company will implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as required by Article 32 of the UK GDPR / EU GDPR.
6.2 The measures currently implemented as part of the architecture of the Services are described in Annex 3 (Technical and Organizational Measures). These include, among others: deferred, verification-gated creation of third-party identity records (so that no record identifying a prospective Data Subject is created until that person has completed a one-time-passcode challenge); encryption of pending contact details prior to verification; private-by-default object storage with short-lived, single-purpose signed URLs for any disclosure of stored media; database-level, role-based access controls; and a structured, evidenced consent ledger for the specific processing purposes described in Annex 4.
6.3 The Company may update the measures described in Annex 3 from time to time, provided that any update does not materially decrease the overall level of security of the Services.
7. Sub-processors
7.1 The Controller provides a general authorization for the Company to engage the Sub-processors listed in Annex 2 as of the date of this DPA.
7.2 Before engaging any new Sub-processor to process Controller Personal Data, the Company will give the Controller at least [30] days' prior notice (by email to the Controller's designated account contact, or by posting to [SUB-PROCESSOR NOTICE LOCATION / URL — TO BE ESTABLISHED]), identifying the new Sub-processor and the processing it will perform.
7.3 If the Controller has reasonable grounds relating to data protection to object to the new Sub-processor, it may notify the Company in writing within [14] days of that notice, and the Parties will discuss the objection in good faith. If the Parties cannot reach a resolution, the Controller may, as its sole remedy, terminate the portion of the Services that cannot reasonably be provided without the new Sub-processor, by written notice to the Company.
7.4 Where the Company engages a Sub-processor, it will do so under a written contract imposing data protection obligations materially no less protective of Controller Personal Data than those set out in this DPA, and the Company remains liable to the Controller for the Sub-processor's performance of those obligations.
7.5 Where a Sub-processor processes Controller Personal Data outside the United Kingdom or European Economic Area, the transfer mechanism described in Section 9 applies.
8. Assistance with Data Subject Requests and Data Subjects' Rights
8.1 The Company will, taking into account the nature of the processing, provide reasonable assistance to the Controller (by appropriate technical and organizational measures) to fulfil the Controller's obligation to respond to Data Subject Requests under Applicable Data Protection Laws.
8.2 If the Company receives a Data Subject Request directly from a Candidate, Client, or other Data Subject that relates to Controller Personal Data, the Company will, without undue delay, inform the Controller of the request, and will not itself respond to the request other than to confirm receipt and (where applicable) to direct the individual to the relevant self-service mechanism described in Annex 4, unless required to do so by law or unless the Controller instructs otherwise.
8.3 The Services include self-service export and erasure mechanisms operated on the Controller's instructions (a Candidate/Client relationship track and a separate canonical-person track, as described in Annex 4). The Controller acknowledges the operation, and the known limitations, of those mechanisms as described in Annex 4, including that chat message content is redacted rather than deleted on erasure, and that provider-side deletion of AI session data (Section 8.4) is not currently implemented identically across both tracks.
8.4 Where the Company's provision of the Services involves a third-party AI provider retaining a persistent, provider-side copy of a conversation (as described in Annex 2 in respect of Anthropic), the Company will use the erasure mechanisms available to it under its contract with that provider to request deletion of the corresponding provider-side record, to the extent that functionality is implemented for the relevant processing activity, as further described in Annex 4.
9. International Data Transfers
9.1 The Controller acknowledges that the provision of the Services necessarily involves the storage and processing of Controller Personal Data outside the region in which it was originally collected. In particular, and without limitation: (a) the Company's primary application database is hosted in the United Kingdom (AWS region eu-west-2, London); (b) the Company's object storage for uploaded documents, media, and audio is hosted in Australia (a separate cloud project in the ap-southeast-2 region, Sydney); and (c) certain Sub-processors listed in Annex 2 may process Controller Personal Data in other locations, including outside the United Kingdom and European Economic Area, as further described in Annex 2.
9.2 Where the Company (or a Sub-processor) transfers Controller Personal Data to a country or territory that has not been the subject of an adequacy decision or adequacy regulations under Article 45 of the UK GDPR or EU GDPR (which, as of the date of this DPA, includes Australia), that transfer will be made subject to the Standard Contractual Clauses (or such other transfer mechanism recognized under Applicable Data Protection Laws as providing an adequate level of protection), which are hereby incorporated into this DPA by reference and will apply in addition to, and do not replace, the terms of this DPA. Where the Standard Contractual Clauses apply, the Parties agree that: the "data exporter" is the Controller, the "data importer" is the Company (or, for onward transfers, the relevant Sub-processor), Module Two (Controller to Processor) applies to the transfer from the Controller to the Company, and Module Three (Processor to Sub-processor) applies to onward transfers from the Company to a Sub-processor, in each case completed with the details in Annex 1 and Annex 2 of this DPA.
9.3 The Company will require each Sub-processor that processes Controller Personal Data outside the United Kingdom or European Economic Area to be bound by an equivalent transfer mechanism.
9.4 The Company has not confirmed the specific processing locations used by every Sub-processor listed in Annex 2 as of the date of this DPA. The Controller should request each Sub-processor's current data processing addendum and sub-processor list directly, or through the Company, for confirmed processing locations before relying on this Section 9 for a specific regulatory filing.
10. Deletion or Return of Data on Termination
10.1 On termination or expiry of the Agreement, and subject to Section 10.2, the Company will, at the Controller's election made in writing within [30] days of termination: (a) make available to the Controller a copy of the Controller Personal Data then held by the Company, using the export mechanisms described in Annex 4 or an equivalent format; and/or (b) delete the Controller Personal Data, using the mechanisms and subject to the known limitations described in Annex 4.
10.2 If the Controller does not elect an option under Section 10.1 within the period specified, the Company may delete the Controller Personal Data in accordance with its standard retention and deletion practices described in Annex 1.
10.3 This Section 10 does not require the Company to delete Controller Personal Data to the extent the Company is required to retain it by applicable law, or to the extent it is contained in encrypted backups that are not readily searchable and are subject to the Company's standard backup-rotation schedule, provided such retained data is not further processed except as necessary for that retention purpose and is protected in accordance with Section 6.
11. Personal Data Breach Notification
11.1 The Company will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Controller Personal Data.
11.2 That notification will describe, to the extent then known: (a) the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and Personal Data records affected; (b) the likely consequences of the Personal Data Breach; and (c) the measures taken or proposed to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects. Where not all such information is available within 72 hours, the Company will provide it in phases without further undue delay as it becomes available.
11.3 The Company will cooperate with the Controller and take such reasonable steps as are directed by the Controller to assist in the investigation, mitigation, and remediation of a Personal Data Breach affecting Controller Personal Data.
11.4 The Company will not, without the Controller's prior written consent, notify any Data Subject or regulator of a Personal Data Breach affecting Controller Personal Data on the Controller's behalf, except to the extent the Company is itself independently required to do so by law.
12. Audits and Compliance
12.1 The Company will make available to the Controller, on reasonable written request and no more than once in any 12-month period (except following a Personal Data Breach, or where required by a supervisory authority), information reasonably necessary to demonstrate compliance with this DPA, which may take the form of a written questionnaire response, a summary of the measures described in Annex 3, or, where available, a relevant third-party audit or certification report.
12.2 If the information provided under Section 12.1 is not reasonably sufficient to demonstrate compliance, the Controller (or an independent third-party auditor bound by confidentiality obligations and reasonably acceptable to the Company) may conduct an audit of the Company's processing of Controller Personal Data, including inspection of relevant facilities, systems, and records, subject to: (a) at least [30] days' prior written notice; (b) reasonable scope, timing, and duration to minimize disruption to the Company's business; (c) execution during the Company's normal business hours; and (d) the Controller bearing its own costs and a reasonable proportion of the Company's costs for audits beyond the first in any 12-month period.
12.3 Nothing in this Section 12 requires the Company to disclose information that would breach its obligations of confidentiality to another customer or third party, compromise the security of its systems or those of other customers, or disclose Personal Data of individuals other than the Controller's own Data Subjects.
13. Sensitive and Special Category Data
13.1 The Company does not design the Services to require the submission of Special Categories of Personal Data. The Controller acknowledges that documents it or its Authorized Users upload to the Services (including CVs, job descriptions, and LinkedIn profile snapshots) are free-text content that may incidentally contain Special Categories of Personal Data (for example, health information, trade union membership, or information revealing racial or ethnic origin) if included by the individual who authored or is described in that document, and that such content may be processed by the Company's document-extraction and AI features described in Annex 1 in the same manner as other document content.
13.2 The Controller is solely responsible for determining whether it has a lawful basis under Applicable Data Protection Laws to process any Special Category of Personal Data that it or its Authorized Users choose to submit to the Services, and for minimizing the collection of such data where it is not necessary for the Controller's recruitment purpose.
14. Controller's Obligations and Warranties
14.1 The Controller warrants that: (a) it has, and will maintain, a valid lawful basis under Applicable Data Protection Laws for all Controller Personal Data it submits to, or generates within, the Services, and for the instructions it gives to the Company; (b) its instructions to the Company (including its configuration of consent, matching, and notification features) comply with Applicable Data Protection Laws; and (c) where required by Applicable Data Protection Laws, it has provided adequate notice to, and (where required) obtained valid consent from, its Candidates, Clients, and Authorized Users for the processing described in Annex 1, including the specific consent purposes described in Annex 4.
14.2 The Controller acknowledges the candidate-network matching feature described in Annex 1 and Annex 4, under which a Candidate's canonical profile may, subject to the consent and eligibility gates described in Annex 4, be surfaced to a different Controller's workspace for the purpose of a recruitment introduction. The Controller is responsible for ensuring its use (or non-use) of this feature, and any onward disclosure it makes as a result of it, is consistent with the lawful basis and notices it has given to the relevant Data Subject.
15. Liability
15.1 Each Party's liability arising out of or in connection with this DPA, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of liability set out in the Agreement, save to the extent such limitations are not permitted by Applicable Data Protection Laws.
15.2 Nothing in this DPA limits or excludes either Party's liability for matters that cannot lawfully be limited or excluded, including liability arising from a Party's own infringement of Chapter V of the UK GDPR / EU GDPR (international transfers), to the extent applicable.
16. Term and Termination
16.1 This DPA takes effect on the effective date of the Agreement and remains in effect for as long as the Company processes Controller Personal Data on the Controller's behalf.
16.2 Termination of the Agreement automatically terminates this DPA, without prejudice to Sections 10 (Deletion or Return of Data on Termination), 11 (Breach Notification, to the extent a Breach relates to processing during the term), 12 (Audits, in respect of the period during which the Company held Controller Personal Data), and 15 (Liability), which survive termination.
17. General
17.1 Order of precedence. If there is a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails. If there is a conflict between this DPA and the Standard Contractual Clauses incorporated under Section 9, the Standard Contractual Clauses prevail.
17.2 Notices. Notices under this DPA must be given in writing to the contacts and addresses specified in the Agreement, or to [PRIVACY CONTACT EMAIL] in the case of notices to the Company under Sections 7, 8, or 11.
17.3 Governing law. This DPA is governed by the laws of [GOVERNING LAW / JURISDICTION], consistent with the governing law of the Agreement.
17.4 Severability. If any provision of this DPA is held unenforceable, the remaining provisions remain in full force and effect, and the Parties will negotiate in good faith a replacement provision that most closely reflects the original intent.
17.5 No third-party rights. Except as expressly provided in the Standard Contractual Clauses incorporated under Section 9, this DPA does not confer any right or benefit on any person who is not a Party.
17.6 Counterparts. This DPA may be executed in counterparts, including electronically, each of which is an original and all of which together constitute one instrument.
Signatures
For and on behalf of the Company
Name: ______________________________
Title: ______________________________
Signature: ______________________________
Date: ______________________________
For and on behalf of [CUSTOMER LEGAL NAME]
Name: ______________________________
Title: ______________________________
Signature: ______________________________
Date: ______________________________
Annex 1 — Details of Processing
Subject matter. The Company's provision of the coffee-on.me software-as-a-service platform to the Controller for founder-led recruitment and hiring workflows.
Duration. For the term of the Agreement, and thereafter as described in Section 10.
Nature and purpose of processing. The Company processes Controller Personal Data to:
- operate the Controller's workspace, including recruiter and workspace-member profiles, call-routing preferences, quiet-hours settings, and notification preferences;
- create and maintain records of the Controller's Candidates and Clients, including contact details, LinkedIn references, preferences, and free-text notes and profile snapshots;
- receive, store, and process documents uploaded by the Controller or its Authorized Users, including CVs, job descriptions, and LinkedIn profile snapshots, and to extract structured information from those documents (headline, employer, title, location, skills, experience, and education for CVs; title, employer, location, compensation, and requirements for job descriptions) using an AI document-extraction feature;
- accumulate structured facts about a Candidate over time, sourced from uploaded documents, call transcripts (where enabled), chat messages, or manual entry by an Authorized User;
- operate AI-assisted conversational features for the Controller's Authorized Users and, where a Candidate or Client engages with a share link, for that Candidate or Client, including retention of the full text of chat messages;
- where an Authorized User pastes a URL into a chat conversation (for example, a Candidate's public LinkedIn profile) and it cannot be retrieved by a standard server-side request, retrieve and summarize the text of that public web page using a headless-browser rendering service, and, if that page is protected by a bot-detection challenge, a second-tier automated challenge-solving service;
- send notifications by email and SMS to Authorized Users, Candidates, and Clients (for example, pre-alerts, callback requests, and conversation summaries);
- where voice calling is enabled for the Controller's workspace (a feature disabled by default), bridge telephone calls between an Authorized User and a Candidate or Client, generate a real-time transcript of the call, and record and retain the call audio, each subject to the consent mechanics described in Annex 4;
- record, evidence, and enforce the Data Subject consent and preference choices described in Annex 4, including whether a Candidate's or Client's profile may be shared with a different workspace for matching purposes;
- verify the identity of a prospective Candidate or Client connecting through a share link via a one-time-passcode challenge before any record identifying that person is created;
- provide the Controller (and, separately, a canonical Candidate/Client identity) with self-service data export and erasure functionality, as described in Annex 4;
- maintain security, audit, and operational logs (including webhook event payloads received from communications providers) necessary to operate, secure, and troubleshoot the Services; and
- otherwise provide, maintain, secure, and support the Services as instructed by the Controller under the Agreement.
Categories of Data Subjects.
- Candidates (individuals under consideration for a role facilitated by the Controller).
- Clients (individual contacts at the Controller's client or prospective client organizations).
- The Controller's Authorized Users (its recruiters and workspace members).
- Other individuals incidentally identified within content submitted to the Services (for example, a referee, colleague, or other person named in a CV, job description, or chat message).
Categories of Personal Data.
- Identity and contact data: display name, email address, phone number (E.164 format), LinkedIn URL.
- Verification data: before verification, a one-way lookup hash of the pending contact identifier plus a separately-held encrypted (reversible) form of it — no plaintext value is stored while the identifier is unverified; once the one-time code is confirmed, a hash of the verified identifier together with its normalized plaintext form, and phone/identity verification timestamps.
- Professional and profile data: CV content and full-text extractions, structured fields extracted from CVs and job descriptions (headline, employer, title, location, skills, experience, education, compensation, requirements), accumulated candidate profile facts, job-description content, LinkedIn profile snapshots.
- Communications content: full text of chat messages across recruiter, prospect, candidate, and client conversation surfaces; where voice calling is enabled, call audio recordings and per-segment call transcripts (speaker and text).
- Preference and consent data: consent purpose, decision, evidence, and policy version for each of the four tracked consent purposes described in Annex 4; communication and outreach-cadence preferences; call-routing and quiet-hours settings; introduction/profile-sharing permissions.
- Workspace and organizational data: workspace name, timezone, and default country/region settings; company name for Client records.
- Technical and log data: webhook event payloads received from communications providers; rate-limiting, session, and verification-challenge records.
- Recruiter avatar images: a profile photograph, where an Authorized User chooses to upload one, held in a publicly accessible storage location because it is composited into public share-link preview images.
Special Categories of Personal Data. Not intentionally collected as a designated field; may be incidentally present within free-text document or communications content submitted by the Controller or a Data Subject, as described in Section 13.
Annex 2 — Approved Sub-processors
The Company uses the following Sub-processors to provide the Services as of the date of this DPA. Processing locations marked "not confirmed" are not pinned down by the Company's own infrastructure configuration and should be confirmed against the relevant vendor's current data processing terms before this Annex is relied upon for a transfer-impact assessment.
| Sub-processor | Function | Controller Personal Data involved | Processing location |
|---|---|---|---|
| Anthropic, PBC | Provides the AI models and managed conversational-agent infrastructure underlying the Services' chat features, document-data extraction, call-transcript summarization (where voice calling is enabled), and image/vision-based text extraction. Chat conversations are run through a provider-hosted, persistent session that retains a server-side copy of the transcript. | Full chat transcript content; CV/job-description text submitted for extraction; call transcript text and call briefs (where voice calling is enabled); uploaded images/photos and rendered document pages submitted for vision-based extraction. | Not confirmed in this DPA; confirm against Anthropic's current data processing addendum. |
| Supabase (database project) | Hosts the Company's primary application database (all structured records described in Annex 1, other than binary files). | All categories of Personal Data described in Annex 1, in structured (database row) form. | United Kingdom (eu-west-2). |
| Supabase (storage project) | Hosts binary file storage for the Services, in a project separate from the database project above. | Uploaded CVs, job descriptions, LinkedIn snapshots, call audio recordings, share-link media, and recruiter avatar images. | Australia (ap-southeast-2). |
| Twilio SendGrid | Sends transactional email notifications on the Controller's behalf (for example, recruiter pre-alerts, callback requests, and conversation summaries). | Recipient email address, recipient/Authorized User display name, a truncated text summary of the relevant conversation or role, and a link to the private conversation thread. | Not confirmed in this DPA; confirm against SendGrid's current data processing addendum. |
| Telnyx | Sends transactional SMS notifications, and, where voice calling is enabled for the Controller's workspace, bridges telephone calls, provides real-time call transcription, and provides call-audio recording retrieval. Telnyx in turn uses its own integration with Deepgram, Inc. to perform the underlying speech-to-text transcription; the Company has no direct relationship with Deepgram. | SMS: recipient phone number, recipient name, role title, a truncated text summary, and a thread link. Voice (if enabled): call audio, call metadata, and real-time transcript content. | Not confirmed in this DPA; confirm against Telnyx's (and, indirectly, Deepgram's) current data processing terms. |
| Vercel Inc. | Hosts the Services' application and API infrastructure, and executes the Services' scheduled background jobs (for example, retention/erasure sweeps and notification triggers). | All categories of Personal Data described in Annex 1, to the extent processed by the application at runtime. | Not confirmed in this DPA; the Company's serving region is a Vercel project-level setting not fixed by application configuration. Confirm against Vercel's current data processing addendum. |
| Google Cloud Platform — "link-renderer" service | Renders a single web page using headless browser automation, at the request of an Authorized User's chat agent, when a URL cannot be retrieved by a standard server-side request (for example, a Candidate's public LinkedIn profile page), and returns the extracted page text/title. | The URL itself, and the resulting public web page content. Does not receive any of the Company's stored Controller Personal Data. | Google Cloud project sharp-sandbox-496115-h8; specific region not confirmed in this DPA. |
| Google Cloud Platform — "link-solver" service | Performs the same function as link-renderer above, but only when link-renderer reports that the target page is protected by an active bot-detection or CAPTCHA-style challenge, using automated challenge-solving techniques to render the page. | Same as link-renderer above. | Google Cloud project sharp-sandbox-496115-h8; specific region not confirmed in this DPA. |
The Company will update this Annex (and give notice under Section 7) as its Sub-processor list changes.
Annex 3 — Technical and Organizational Security Measures
The following measures are, to the best of the Company's knowledge as of the date of this DPA, implemented in the architecture of the Services. This Annex describes the measures currently observed in the system; it does not constitute a certification against any named security standard, as the Company has not represented that it holds one.
-
Verification-gated identity creation. When a prospective Candidate or Client connects to the Services through a share link, no database record identifying that individual (including their email, phone number, or name) is created until they complete a one-time-passcode challenge. Before verification, the destination contact detail is held only in encrypted form, tied to the specific verification challenge.
-
Consent ledger. Consent decisions are recorded in a dedicated, append-only consent table capturing the purpose, decision, supporting evidence, and the version of the relevant policy in force at the time of the decision, for each of the four tracked consent purposes described in Annex 4.
-
Private-by-default object storage. Uploaded documents (CVs, job descriptions, LinkedIn snapshots) and call audio recordings are stored in private storage buckets, accessible only via short-lived, single-purpose signed URLs (minted per request with a five-minute validity window) rather than persistent public links. One storage bucket — for recruiter profile photographs — is intentionally public, because such images have no per-record owner to restrict access to and are composited into public share-link preview images.
-
Segregated storage infrastructure. Binary file storage is hosted in a separate cloud project from the primary application database, accessed only through a dedicated storage client in the Company's codebase, to reduce the risk of storage operations being misdirected to the wrong project.
-
Database access controls. Access to structured records in the primary application database is governed by row-level, role-based database access-control policies.
-
Consent-gated, multi-condition data sharing. Cross-workspace candidate-matching introductions require multiple independent eligibility conditions to be simultaneously satisfied, including verified evidence of the Data Subject's introduction permission and valid channel consent, before a match is presented.
-
Scheduled retention and cleanup jobs. Automated jobs run on a fixed schedule to delete data classes with a defined retention period (for example, temporary call audio, expired verification challenges, and expired sessions), as described in Annex 4.
-
Self-service data subject rights tooling. The Services include dedicated export and erasure endpoints (described in Annex 4), gated by an explicit confirmation step, that programmatically remove or redact the relevant records and associated stored files.
-
Feature-level risk gating. Voice call bridging, recording, and transcription are disabled by default at the platform level and must be explicitly enabled for a given workspace before any call audio or transcript is generated for that workspace.
The Company may supplement or replace these measures over time, consistent with Section 6.3.
Annex 4 — Consent Mechanics and Data Subject Rights Tooling
This Annex describes, for the Controller's and its legal advisers' information, the specific mechanisms the Services provide to support the Controller's consent-management and data-subject-rights obligations. These mechanisms are tools the Controller uses in operating the Services; they do not themselves establish the Controller's lawful basis, which remains the Controller's responsibility under Section 14.
A. Tracked consent purposes. The Services record Data Subject consent decisions against four defined purposes, each independently versioned:
- Follow-up contact — a Candidate's or Client's consent to be re-contacted about future roles; enforced before any automated follow-up trigger or re-contact for matching purposes.
- Profile sharing — a Candidate's consent to share their profile with a specific Client for a specific role; required before a client-facing pitch referencing that Candidate is generated.
- Call transcription — required from both the Authorized User and the call recipient before any call is bridged; the recipient's consent is captured at the moment of the call request, and a call cannot be created in the Services without a corresponding recorded consent decision.
- Audio training — a separate, optional, opt-in consent for a call recording to be retained as a training-corpus copy beyond the standard temporary retention window described below.
B. Cross-workspace matching gate. A Candidate's canonical profile may be surfaced to a different Controller's workspace for a recruitment introduction only where multiple independent conditions are all satisfied, including verified evidence of the Candidate's introduction permission and valid channel consent. The Controller should treat this feature as a potential onward disclosure of Candidate Personal Data outside the Controller's own workspace and account for it in its own notices to Candidates, as described in Section 14.2.
C. Data retention defaults.
| Data category | Current default retention | Notes |
|---|---|---|
| Temporary call audio (standard retention class) | 7 days by default (configurable between 1 and 30 days) | Swept by a daily automated job; the Controller should confirm the value currently configured for its environment. |
| Call recording retained under the "audio training" consent | No automatic expiry | Removed only on an explicit erasure request. |
| CVs, job descriptions, and LinkedIn snapshots | No automatic expiry | Removed only on an explicit erasure request. |
| Chat message content | Indefinite; not automatically deleted | On an erasure request, message content is overwritten with a fixed redaction placeholder rather than the row being deleted; the message's timestamp, role, and position in the conversation are retained. |
| Communications provider webhook event payloads | Indefinite; no automatic expiry mechanism currently implemented | — |
| Signed media-access URLs | Five minutes | Not a storage retention period; governs how long a given link to stored media remains usable. |
| Session, verification-challenge, invite, and rate-limiting records | Defined short-lived expiry (same day to approximately one day) | Swept by daily automated jobs. |
D. Export and erasure tooling. Two parallel, self-service tracks exist:
- Candidate/Client relationship track: an export function returns the relationship record, associated role/pitch history, accumulated profile facts, consent history, full chat messages, and call summaries. An erasure function (gated by an explicit confirmation phrase) deletes call-audio files and associated extractions, deletes any training-corpus copy, deletes accumulated profile facts, overwrites the relationship record's identifying fields, redacts chat message content as described above, revokes active sessions, and — for this track only — additionally requests deletion of the corresponding persistent AI-provider-side conversation session.
- Canonical person (share-link identity) track: a separate export and erasure function operates over a Candidate's or Client's cross-workspace identity, where one exists. Erasure under this track deletes matching/opportunity records, blanks and revokes artifacts, removes associated stored media, redacts chat content in the same manner as the relationship track, and deletes identity, preference, and session records. As of the date of this DPA, this track does not include the additional step of requesting deletion of the corresponding AI-provider-side session that the relationship track performs; this is a known asymmetry between the two tracks (see Notes for Legal Review).