Pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679
The Recruiter / Client Employer
The natural or legal person — in-house recruiter, HR manager, or agency/third-party recruiter — who subscribes to the AITACS Talent Service and enters Candidate data into it.
The Controller determines the purposes and means of processing Candidate personal data.
Artem Chukov / AITACS Talent
Sole proprietor, registered in the State of Israel (עוסק פטור 345086623).
The Processor processes personal data solely on behalf of and under the documented instructions of the Controller.
This Data Processing Agreement ("DPA") forms part of and supplements the Terms of Service between the Controller and the Processor (together, the "Parties").
2.1. The Processor shall process personal data on behalf of the Controller solely for the purpose of providing the AITACS Talent Service, including data storage, calendar/interview scheduling, and AI-assisted candidate screening.
2.2. The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law to which the Processor is subject (Art. 28(3)(a) GDPR).
2.3. This DPA applies for the duration of the Controller's active subscription to the Service and for the data retention period described in Section 11.
In accordance with Article 28(3) of the GDPR, the Processor shall:
5.1. The Controller shall ensure that there is a lawful basis for all processing of personal data that it instructs the Processor to carry out, including obtaining consent from Candidates pursuant to Article 6(1)(a) of the GDPR.
5.2. The Controller shall provide Candidates with an informed consent form prior to entering their data into the Platform. A template is provided at Informed Consent Template.
5.3. The Controller shall comply with applicable anti-discrimination and employment law, including not attempting to reintroduce protected characteristics into free-text fields as a substitute for the fields the Platform intentionally omits.
5.4. The Controller shall comply with the minimum security requirements set forth in the User Security Requirements document.
5.5. The Controller shall notify the Processor without undue delay if it becomes aware of any data breach involving data processed through the Platform.
6.1. The Controller provides general written authorization for the Processor to engage the subprocessors listed in the Subprocessor List as of the effective date of this DPA.
6.2. The Processor shall notify the Controller at least 14 days in advance of any intended addition or replacement of subprocessors, providing the Controller with the opportunity to object.
6.3. If the Controller objects to a new subprocessor on reasonable data protection grounds and the Processor cannot accommodate the objection, the Controller may terminate the affected service component without penalty.
6.4. The Processor shall impose the same data protection obligations as set out in this DPA on each subprocessor by way of a contract (Art. 28(4) GDPR). The Processor remains fully liable for the performance of each subprocessor's obligations.
6.5. Current subprocessors and their data protection status:
| Subprocessor | Country | Function | Data Received | Safeguard |
|---|---|---|---|---|
| OpenAI, LLC | USA | Chat assistant, candidate analysis, and résumé/document-import extraction | Pseudonym + de-identified professional data for screening/analysis; full document content for import extraction (see Privacy Policy §3) | OpenAI Data Processing Addendum (incorporates EU SCCs); zero-retention policy; data not used for model training |
| Hetzner Online GmbH | Germany / Finland | MySQL database and application hosting | All Platform data (encrypted in transit) | Hetzner Online GmbH DPA (incorporates EU SCCs); TLS 1.2+; server access controls |
| Google Firebase | USA | Recruiter authentication | Email, UID | Google Cloud Data Processing Terms (incorporates EU SCCs) |
| Google LLC — Calendar API | USA | OAuth calendar synchronisation — interview scheduling | Interview date, time, and event title configured by the Recruiter | Google Cloud Data Processing Terms (incorporates EU SCCs); Limited Use requirements apply |
| Zapier, Inc. | USA | Webhook relay for interview-scheduling metadata from the Recruiter's own Zoom account | Meeting ID/topic, host/participant email, scheduled time, recording URL (if any) | Shared webhook secret over TLS; Zapier's own DPA governs its processing as an independent controller/processor of the automation it runs for the Recruiter |
As described in the Terms of Service, Section 3, no payment processor is technically connected to AITACS Talent at the time of writing. Once one is integrated (e.g. PayPal and/or Paddle.com Market Limited), it will be added to this table and to the Subprocessor List at least 14 days before going live, per Section 6.2 above.
A live video/audio interview widget ("Transcription Module") exists in the Platform's coach product and has not yet been adapted or activated for AITACS Talent; its subprocessor, if and when enabled here, will be added to this table before activation.
7.1. The Processor may transfer personal data to subprocessors located outside the EU/EEA (currently: United States) only where appropriate safeguards are in place in accordance with Chapter V of the GDPR.
7.2. The primary safeguard mechanism is Standard Contractual Clauses (SCCs) (Commission Implementing Decision (EU) 2021/914), incorporated via each subprocessor's own Data Processing Agreement, as listed in Section 6.5 above.
7.3. For data transmitted to OpenAI for the chat assistant and candidate-analysis features specifically: this data is de-identified as described in the Privacy Policy §3.1 before transmission. This does not apply to the résumé/document-import feature, which necessarily transmits identifying data extracted from the uploaded document (Privacy Policy §3.2) — the safeguard there is the subprocessor's zero/short retention terms, not de-identification.
9.1. The Processor shall notify the Controller of any confirmed or suspected personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach, in accordance with Article 33 of the GDPR.
9.2. The notification shall include:
a) A description of the nature of the breach, including the categories and approximate number of data subjects and records concerned;
b) The name and contact details of the Processor's contact point;
c) A description of the likely consequences of the breach;
d) A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
9.3. The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of each breach.
10.1. Where the Controller is required to carry out a Data Protection Impact Assessment (DPIA) under Article 35 of the GDPR, the Processor shall provide reasonable assistance, taking into account the nature of processing and the information available to the Processor.
10.2. Given that the Platform uses automated means (AI screening) to assist decisions materially affecting Candidates, and that recruitment AI is classified as high-risk under the EU AI Act (Annex III), the Controller is advised to conduct a DPIA before commencing use of the Platform in jurisdictions where this is required.
11.1. This DPA shall remain in effect for the duration of the Controller's subscription to the Service and for as long as the Processor processes personal data on behalf of the Controller.
11.2. Upon termination of the Service, the Processor shall, at the Controller's choice: (a) return all personal data to the Controller in a structured, machine-readable format (JSON export); or (b) delete all personal data and certify such deletion in writing.
11.3. Following termination, Candidate data is retained for 12 months by default to allow export, consistent with the Terms of Service §8, unless a shorter or longer period is required by applicable employment or data-protection law, after which the Processor shall permanently delete all personal data if the Controller has made no election. This 12-month post-termination period is separate from, and does not change, the ongoing per-Candidate retention the Controller configures during active use of the Service (see Privacy Policy §10).
11.4. The obligations of this DPA that by their nature should survive termination (including confidentiality, data deletion, and cooperation with audits relating to the processing period) shall survive termination.
12.1. Each Party shall be liable for damage caused by processing that infringes the GDPR in accordance with Article 82 of the GDPR.
12.2. The Processor shall be liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to lawful instructions of the Controller (Art. 82(2) GDPR).
12.3. The Processor's aggregate liability under this DPA shall not exceed the amounts set forth in the Terms of Service.
13.1. This DPA is governed by the laws of the State of Israel, in accordance with Terms of Service §9, without prejudice to the mandatory data-protection law described in §9.1 of that document (GDPR for EU/EEA data subjects, Israeli Privacy Law for the Processor's own processing, and Ukrainian data-protection law for data subjects in Ukraine) — each applying in parallel where relevant, not as alternatives to one another.
13.2. Any disputes arising from this DPA shall be resolved in accordance with the dispute resolution mechanism set forth in the Terms of Service §9.
14.1.1. A formal Data Protection Officer (DPO) pursuant to Article 37 GDPR has not been designated. The Processor is a sole proprietor whose core activities do not constitute large-scale systematic processing of special categories of personal data within the meaning of Article 37(1)(c) GDPR — indeed, the Platform's Candidate schema is designed to exclude special-category data entirely. The designation obligation under Art. 37(1)(b) is likewise not applicable.
14.1.2. All functions typically performed by a DPO — monitoring compliance, advising on processing activities, and acting as contact point for supervisory authorities and data subjects — are carried out directly by the Processor (Artem Chukov). The Processor's data protection contact is set out in §14.3 below.
14.2.1. Art. 13 GDPR (direct collection). When personal data is collected directly from Recruiters, the required information under Art. 13 GDPR — identity and contact details of the Processor, purposes and legal basis of processing, categories of recipients, retention periods, data subject rights, right to withdraw consent, and the right to lodge a complaint with a supervisory authority — is provided in the Privacy Policy.
14.2.2. Art. 14 GDPR (indirect collection — Candidates). Personal data of Candidates is not collected directly by the Processor from the data subjects — it is entered into the Service by the Controller (the Recruiter). The Art. 14 GDPR information obligation for Candidates is therefore the responsibility of the Controller. The Processor provides the Informed Consent Template as a practical instrument to assist Controllers in meeting their Art. 14 obligations toward Candidates.
14.2.3. Data subjects (Candidates) may exercise their rights under GDPR Articles 15–22 by contacting the Controller (their recruiter). The Controller shall involve the Processor where technically necessary, in accordance with DPA §4, obligation 5.
For DPA-related inquiries, data subject right requests, breach reports, or supervisory authority matters:
Artem Chukov — Data Processor / Data Protection Contact
Email: talent@aitacscrm.app
Web: aitacscrm.app/talent
Terms of Service · Privacy Policy · Informed Consent Template · Cookie Policy · Data Processing Agreement (DPA) · Recruitment Data Sharing Agreement · Subprocessor List · Security Requirements · Incident Response Policy · Security Overview · Refund Policy · Copyright Policy · Contact Us