Data Processing Agreement
Definitions
Purpose of processing
Duration of processing
Nature of processing, types of personal data processed, and categories of data subjects
The processing of personal data carried out by the Processor on behalf of the Controller includes, among other things, the receipt, collection, recording, storage, retention, modification, use, disclosure by transmission, deletion or destruction of data, as well as other operations performed on personal data.
a) Categories of data subjects
Personal data may relate to several categories of data subjects, such as users of the services under the commercial agreement between the Parties or the Controller’s personnel.
b) Types of personal data processed
The personal data processed may relate to several categories of personal data, such as a person’s name, address, telephone number, email address, bank account number, personal identity number, salary information, and other data. The types of personal data processed are specified in Annex A.
International data transfers
The Processor shall, as a rule, process personal data within the EU or EEA, or in countries that ensure an adequate level of data protection as required by data protection legislation.
Certain Sub-processors and their parent companies may be located outside the EU/EEA. All locations and sub-processors are listed in Annex A to this Data Processing Agreement.
If personal data is transferred to countries outside the EU or EEA, subject to the Controller’s separate prior written consent, such transfer shall be carried out by applying (i) the European Commission’s standard contractual clauses for the transfer of personal data or equivalent clauses approved by the European Union that replace such clauses, or (ii) other appropriate transfer mechanisms defined in the General Data Protection Regulation, and in accordance with the Controller’s instructions.
Sub-processors
Security
Audit rights & security
Data subject rights
Personal data breaches
Entry into force and effects of termination
A. Data Subjects, Personal Data Processed, Purpose of Processing, Nature of Processing and Duration of Processing
A.1 Categories of Data Subjects
- Employees of the customer/partner
-
Contact persons of the customer/partner
A.2 Personal Data Processed
-
Name
-
Telephone number
-
Email address
-
City
-
Login credentials
-
Personal identity number
-
Age
-
Gender
-
Education and qualification data
-
Performance evaluations
-
Employment information
-
Salary data, salary basis and salary changes
-
Log data
-
IP address
-
Nationality
-
Primary country of employment
A.3 Special Categories of Data (Sensitive Personal Data)
In order for the Processor to process Special Categories of Personal Data on behalf of the Controller, the Controller must list in the table below the Sensitive Personal Data that the Processor processes.
The Controller is also obliged to notify the Processor and update the table below if the information changes during the validity of this annex to the agreement.
Sensitive Personal Data
The Processor processes the following Sensitive Personal Data on behalf of the Controller:
| Category | Yes | No |
|---|---|---|
|
Race or ethnic origin, political opinion, philosophical or religious belief |
x |
|
|
Health Data |
x |
|
|
Sexual behavior and orientation |
x |
|
|
Trade union membership |
x |
|
|
Genetic or biometric data |
x |
|
|
Criminal convictions, suspicions, or charges |
x |
|
|
Children’s personal data |
x |
A.4 Purpose of Processing
The purpose of the Processor’s processing of Personal Data on behalf of the Controller is the following:
To provide services in accordance with the Agreement.
A.5 Nature of Processing
The Processor’s processing of Personal Data on behalf of the Controller mainly relates to:
Receiving, storing, recording, reporting, transferring, anonymizing, and deleting data.
A.6 Duration of Processing
The Processor processes Personal Data on behalf of the Controller for the following period:
As long as the Agreement is valid and applicable to the processing of Personal Data.
Current Sub-processors
The following sub-processors of the Processor have access to the Controller’s Personal Data (07.04.2026).
| Name | Location / Country | Legal transfer mechanism if the sub-processor has access to Personal Data outside the EU or EEA | Role in providing the service |
|---|---|---|---|
|
Google Cloud Platform |
EU |
Standard Contractual Clauses (if outside EU/EEA) |
Cloud infrastructure, storage, and computing services |
|
Mixpanel |
EU |
N/A (no transfers outside EU/EEA) |
Analytics tool |
|
Auth0 |
EU |
N/A (no transfers outside EU/EEA) or SCCs if applicable |
User authentication tool |
|
Crisp |
EU |
N/A (no transfers outside EU/EEA) |
Inapp chat tool |
|
Lettermint |
EU |
N/A (no transfers outside EU/EEA) |
Transactional email traffic |
|
Kombo |
EU |
N/A (no transfers outside EU/EEA) |
Integration platform for HRIS and ATS integrations. |