← Home

Data Processing Agreement

Last updated: April 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and CV Tally ("Processor") and governs the processing of personal data as required by Article 28 GDPR.

1. Definitions

"Personal Data" means any information in the CVs submitted by the Controller that relates to an identifiable individual.

"Processing" means any operation performed on Personal Data as described herein.

2. Processing details

Subject matterAI-assisted CV screening and analysis
DurationFor the period of the order, maximum 48 hours
NatureStorage, AI analysis, PDF generation, transmission via secure link
PurposeTo generate candidate rankings, fit assessments, and interview questions at the Controller's request
Data typesCV contents: names, contact details, employment history, education, skills, and any other data contained in uploaded documents
Data subjectsJob candidates whose CVs are submitted by the Controller

3. Processor obligations

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller (the submission of CVs constitutes such instruction)
  • Ensure persons authorised to process Personal Data are bound by confidentiality
  • Implement appropriate technical and organisational security measures (encryption at rest and in transit, access controls, automatic deletion)
  • Assist the Controller in responding to data subject rights requests
  • Delete all Personal Data within 48 hours of processing completion, or immediately upon the Controller's request via the "Delete now" function
  • Provide all information necessary to demonstrate compliance with this DPA
  • Notify the Controller within 72 hours of becoming aware of a personal data breach

4. Sub-processing

The Controller authorises the Processor to engage the sub-processors listed in the Privacy Policy (Cloudflare, Anthropic, Resend). The Processor shall ensure sub-processors are bound by equivalent data protection obligations. The Processor will inform the Controller of any intended changes to sub-processors.

5. Controller obligations

The Controller warrants that it has a lawful basis to process and transfer the Personal Data contained in the uploaded CVs, and that it has complied with applicable obligations regarding notice to data subjects.

6. International transfers

Processing occurs within the EU where possible. Transfers to Anthropic (USA) are covered by Anthropic's Standard Contractual Clauses. The Controller accepts these transfer mechanisms by submitting CVs for processing.

7. Audit

The Processor shall make available all information necessary to demonstrate compliance with this DPA and allow audits conducted by the Controller or a mandated auditor, upon reasonable notice.

Contact

DPA enquiries: privacy@cvtally.com