AITACS Talent — Recruiting Calendar & CRM Suite  ·  Terms · Privacy · Informed Consent
AITACS Talent — Legal Documentation

Data Processing Agreement

Pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679

Effective Date: 2026-07-13  ·  Last Updated: 2026-07-13  ·  Version: 0.1-draft  ·  Provider: Artem Chukov, Israel

GDPR Article 28 Israeli Privacy Law

1. Parties

Data Controller

The Recruiter / Client Employer

The natural or legal person — in-house recruiter, HR manager, or agency/third-party recruiter — who subscribes to the AITACS Talent Service and enters Candidate data into it.

The Controller determines the purposes and means of processing Candidate personal data.

Data Processor

Artem Chukov / AITACS Talent

Sole proprietor, registered in the State of Israel (עוסק פטור 345086623).

The Processor processes personal data solely on behalf of and under the documented instructions of the Controller.

This Data Processing Agreement ("DPA") forms part of and supplements the Terms of Service between the Controller and the Processor (together, the "Parties").

2. Scope and Purpose of Processing

2.1. The Processor shall process personal data on behalf of the Controller solely for the purpose of providing the AITACS Talent Service, including data storage, calendar/interview scheduling, and AI-assisted candidate screening.

2.2. The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law to which the Processor is subject (Art. 28(3)(a) GDPR).

2.3. This DPA applies for the duration of the Controller's active subscription to the Service and for the data retention period described in Section 11.

3. Details of Processing (Annex I)

Annex I — Description of Processing

Subject matter: Provision of a recruiting calendar and candidate CRM, with AI-assisted screening, for recruiters and HR professionals.
Duration: For the term of the Controller's subscription plus the retention period described in Section 11.
Nature of processing: Collection, storage, retrieval, scheduling, pseudonymization, AI-assisted analysis, erasure.
Purpose: Enabling the Controller to manage Candidate records, schedule interviews, take interview notes, and obtain AI-generated screening assistance.
Categories of data subjects: Candidates sourced or considered by the Controller for a Vacancy.
Categories of personal data: Contact data (name, phone, email, résumé), professional data (skills, salary expectations, notice period, pipeline stage), interview scheduling data, and — where consented — video/audio interview recordings. See Privacy Policy §1 for the full data category list.
Special categories (Art. 9): None by design. The Candidate data schema does not include date of birth, gender, race, ethnicity, religion, marital status, or health information as an anti-discrimination safeguard (see Privacy Policy §1, §3). If a Controller nonetheless uploads a document containing such data (e.g. within a résumé's free text), that data is not a designed field of the Platform and processing it remains the Controller's sole responsibility.

4. Obligations of the Processor

In accordance with Article 28(3) of the GDPR, the Processor shall:

Process personal data only on documented instructions from the Controller, unless required by applicable law. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR).
Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (Art. 32 GDPR), including: encryption of data in transit (TLS 1.2+), de-identification before AI transmission for the screening and analysis features (see Privacy Policy §3), Firebase-based authentication with UID isolation, regular database backups, and server access controls.
Not engage another processor (subprocessor) without prior specific or general written authorization of the Controller. In the case of general written authorization, the Processor shall inform the Controller of any intended changes concerning the addition or replacement of subprocessors, giving the Controller the opportunity to object (Art. 28(2) GDPR). Current subprocessors are listed in the Subprocessor List.
Assist the Controller in fulfilling data subject rights requests (access, rectification, erasure, portability, restriction, objection) by implementing appropriate technical and organizational measures (Art. 28(3)(e) GDPR). Response time: within 15 business days of receiving the Controller's request.
Assist the Controller in ensuring compliance with Articles 32–36 of the GDPR (security, breach notification, DPIA, prior consultation), taking into account the nature of processing and the information available to the Processor.
Notify the Controller without undue delay — and in any event within 72 hours — after becoming aware of a personal data breach (Art. 33 GDPR). The notification shall include: the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
At the choice of the Controller, delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies unless Union or Member State law requires storage (Art. 28(3)(g) GDPR). The Processor shall provide data export in JSON format upon request.
Make available to the Controller all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller (Art. 28(3)(h) GDPR). Audits shall be conducted with reasonable advance notice (minimum 14 days) and during normal business hours.

5. Obligations of the Controller

5.1. The Controller shall ensure that there is a lawful basis for all processing of personal data that it instructs the Processor to carry out, including obtaining consent from Candidates pursuant to Article 6(1)(a) of the GDPR.

5.2. The Controller shall provide Candidates with an informed consent form prior to entering their data into the Platform. A template is provided at Informed Consent Template.

5.3. The Controller shall comply with applicable anti-discrimination and employment law, including not attempting to reintroduce protected characteristics into free-text fields as a substitute for the fields the Platform intentionally omits.

5.4. The Controller shall comply with the minimum security requirements set forth in the User Security Requirements document.

5.5. The Controller shall notify the Processor without undue delay if it becomes aware of any data breach involving data processed through the Platform.

6. Subprocessors

6.1. The Controller provides general written authorization for the Processor to engage the subprocessors listed in the Subprocessor List as of the effective date of this DPA.

6.2. The Processor shall notify the Controller at least 14 days in advance of any intended addition or replacement of subprocessors, providing the Controller with the opportunity to object.

6.3. If the Controller objects to a new subprocessor on reasonable data protection grounds and the Processor cannot accommodate the objection, the Controller may terminate the affected service component without penalty.

6.4. The Processor shall impose the same data protection obligations as set out in this DPA on each subprocessor by way of a contract (Art. 28(4) GDPR). The Processor remains fully liable for the performance of each subprocessor's obligations.

6.5. Current subprocessors and their data protection status:

SubprocessorCountryFunctionData ReceivedSafeguard
OpenAI, LLC USA Chat assistant, candidate analysis, and résumé/document-import extraction Pseudonym + de-identified professional data for screening/analysis; full document content for import extraction (see Privacy Policy §3) OpenAI Data Processing Addendum (incorporates EU SCCs); zero-retention policy; data not used for model training
Hetzner Online GmbH Germany / Finland MySQL database and application hosting All Platform data (encrypted in transit) Hetzner Online GmbH DPA (incorporates EU SCCs); TLS 1.2+; server access controls
Google Firebase USA Recruiter authentication Email, UID Google Cloud Data Processing Terms (incorporates EU SCCs)
Google LLC — Calendar API USA OAuth calendar synchronisation — interview scheduling Interview date, time, and event title configured by the Recruiter Google Cloud Data Processing Terms (incorporates EU SCCs); Limited Use requirements apply
Zapier, Inc. USA Webhook relay for interview-scheduling metadata from the Recruiter's own Zoom account Meeting ID/topic, host/participant email, scheduled time, recording URL (if any) Shared webhook secret over TLS; Zapier's own DPA governs its processing as an independent controller/processor of the automation it runs for the Recruiter
Payment Processor — Not Yet a Subprocessor

As described in the Terms of Service, Section 3, no payment processor is technically connected to AITACS Talent at the time of writing. Once one is integrated (e.g. PayPal and/or Paddle.com Market Limited), it will be added to this table and to the Subprocessor List at least 14 days before going live, per Section 6.2 above.

A live video/audio interview widget ("Transcription Module") exists in the Platform's coach product and has not yet been adapted or activated for AITACS Talent; its subprocessor, if and when enabled here, will be added to this table before activation.

7. International Data Transfers

7.1. The Processor may transfer personal data to subprocessors located outside the EU/EEA (currently: United States) only where appropriate safeguards are in place in accordance with Chapter V of the GDPR.

7.2. The primary safeguard mechanism is Standard Contractual Clauses (SCCs) (Commission Implementing Decision (EU) 2021/914), incorporated via each subprocessor's own Data Processing Agreement, as listed in Section 6.5 above.

7.3. For data transmitted to OpenAI for the chat assistant and candidate-analysis features specifically: this data is de-identified as described in the Privacy Policy §3.1 before transmission. This does not apply to the résumé/document-import feature, which necessarily transmits identifying data extracted from the uploaded document (Privacy Policy §3.2) — the safeguard there is the subprocessor's zero/short retention terms, not de-identification.

8. Technical and Organizational Measures (Annex II)

Annex II — Security Measures

Encryption in transit: TLS 1.2+ for all communications between Recruiter, server, and third-party APIs.
Encryption at rest: Server-side encryption per hosting provider standards; AES-256 recommended for local device storage.
De-identification: Automatic stripping of name, phone, email, and résumé link before AI screening/analysis calls; regex-based scrubbing of contact-like patterns in free-text notes; auto-generated pseudonym. Does not apply to the résumé/document-import feature (see Section 7.3).
Authentication: Firebase Authentication with unique UID per user. 2FA recommended.
Access control: Data isolation by Firebase UID. No cross-account data access. Server API requires valid authentication token.
Backup: Regular encrypted database backups. Backup deletion follows primary data deletion.
Breach detection: Server log monitoring. Anomalous access alerting. See Incident Response Policy.
Personnel: Sole proprietor operation. No third-party personnel have access to production data.

9. Data Breach Notification

9.1. The Processor shall notify the Controller of any confirmed or suspected personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach, in accordance with Article 33 of the GDPR.

9.2. The notification shall include:

a) A description of the nature of the breach, including the categories and approximate number of data subjects and records concerned;

b) The name and contact details of the Processor's contact point;

c) A description of the likely consequences of the breach;

d) A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.

9.3. The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of each breach.

10. Data Protection Impact Assessment

10.1. Where the Controller is required to carry out a Data Protection Impact Assessment (DPIA) under Article 35 of the GDPR, the Processor shall provide reasonable assistance, taking into account the nature of processing and the information available to the Processor.

10.2. Given that the Platform uses automated means (AI screening) to assist decisions materially affecting Candidates, and that recruitment AI is classified as high-risk under the EU AI Act (Annex III), the Controller is advised to conduct a DPIA before commencing use of the Platform in jurisdictions where this is required.

11. Term and Termination

11.1. This DPA shall remain in effect for the duration of the Controller's subscription to the Service and for as long as the Processor processes personal data on behalf of the Controller.

11.2. Upon termination of the Service, the Processor shall, at the Controller's choice: (a) return all personal data to the Controller in a structured, machine-readable format (JSON export); or (b) delete all personal data and certify such deletion in writing.

11.3. Following termination, Candidate data is retained for 12 months by default to allow export, consistent with the Terms of Service §8, unless a shorter or longer period is required by applicable employment or data-protection law, after which the Processor shall permanently delete all personal data if the Controller has made no election. This 12-month post-termination period is separate from, and does not change, the ongoing per-Candidate retention the Controller configures during active use of the Service (see Privacy Policy §10).

11.4. The obligations of this DPA that by their nature should survive termination (including confidentiality, data deletion, and cooperation with audits relating to the processing period) shall survive termination.

12. Liability

12.1. Each Party shall be liable for damage caused by processing that infringes the GDPR in accordance with Article 82 of the GDPR.

12.2. The Processor shall be liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to lawful instructions of the Controller (Art. 82(2) GDPR).

12.3. The Processor's aggregate liability under this DPA shall not exceed the amounts set forth in the Terms of Service.

13. Governing Law

13.1. This DPA is governed by the laws of the State of Israel, in accordance with Terms of Service §9, without prejudice to the mandatory data-protection law described in §9.1 of that document (GDPR for EU/EEA data subjects, Israeli Privacy Law for the Processor's own processing, and Ukrainian data-protection law for data subjects in Ukraine) — each applying in parallel where relevant, not as alternatives to one another.

13.2. Any disputes arising from this DPA shall be resolved in accordance with the dispute resolution mechanism set forth in the Terms of Service §9.

14. Data Protection Officer; Art. 13/14 GDPR; Contact

14.1 Data Protection Officer

14.1.1. A formal Data Protection Officer (DPO) pursuant to Article 37 GDPR has not been designated. The Processor is a sole proprietor whose core activities do not constitute large-scale systematic processing of special categories of personal data within the meaning of Article 37(1)(c) GDPR — indeed, the Platform's Candidate schema is designed to exclude special-category data entirely. The designation obligation under Art. 37(1)(b) is likewise not applicable.

14.1.2. All functions typically performed by a DPO — monitoring compliance, advising on processing activities, and acting as contact point for supervisory authorities and data subjects — are carried out directly by the Processor (Artem Chukov). The Processor's data protection contact is set out in §14.3 below.

14.2 Information Under GDPR Art. 13 and Art. 14

14.2.1. Art. 13 GDPR (direct collection). When personal data is collected directly from Recruiters, the required information under Art. 13 GDPR — identity and contact details of the Processor, purposes and legal basis of processing, categories of recipients, retention periods, data subject rights, right to withdraw consent, and the right to lodge a complaint with a supervisory authority — is provided in the Privacy Policy.

14.2.2. Art. 14 GDPR (indirect collection — Candidates). Personal data of Candidates is not collected directly by the Processor from the data subjects — it is entered into the Service by the Controller (the Recruiter). The Art. 14 GDPR information obligation for Candidates is therefore the responsibility of the Controller. The Processor provides the Informed Consent Template as a practical instrument to assist Controllers in meeting their Art. 14 obligations toward Candidates.

14.2.3. Data subjects (Candidates) may exercise their rights under GDPR Articles 15–22 by contacting the Controller (their recruiter). The Controller shall involve the Processor where technically necessary, in accordance with DPA §4, obligation 5.

14.3 Contact

For DPA-related inquiries, data subject right requests, breach reports, or supervisory authority matters:

Artem Chukov — Data Processor / Data Protection Contact
Email: talent@aitacscrm.app
Web: aitacscrm.app/talent

Related Compliance Documents

Terms of Service · Privacy Policy · Informed Consent Template · Cookie Policy · Data Processing Agreement (DPA) · Recruitment Data Sharing Agreement · Subprocessor List · Security Requirements · Incident Response Policy · Security Overview · Refund Policy · Copyright Policy · Contact Us