Skip to main content

Legal · BETIHUT-LEGAL-DPA

Data Processing Addendum

Entity
XCITERR LTD. · AUTOMAIZE SOLUTIONS LTD
Reg. No.
206478710 · HE 480609
Effective
23 July 2026
Status
Version 1.4 · Effective template

This Data Processing Addendum (the "DPA") forms part of the Employer Terms of Service between the Customer, XCITERR LTD. and AUTOMAIZE SOLUTIONS LTD. It governs only processing performed by Xciterr or Automaize as a processor or sub-processor on documented instructions; independent-controller processing is governed by the Privacy Notice and applicable law.

This DPA is concluded in accordance with Article 28 GDPR. In the event of conflict between this DPA and the Employer Terms of Service in respect of data protection, this DPA prevails.

1.Definitions

  1. 1.1Terms such as "controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given to them in the GDPR.
  2. 1.2"Applicable Data Protection Law" means the GDPR and the national data-protection laws applicable in Cyprus, Bulgaria and each territory in which the documented processing occurs.
  3. 1.3"Processor" means Xciterr or Automaize only to the extent that the relevant company processes personal data on a Controller's documented instructions. "Sub-processor" includes Automaize when engaged by Xciterr and each infrastructure provider engaged in the documented processing chain.

2.Roles and scope of processing

  1. 2.1For a Customer-controlled workflow, the Customer determines the purposes and essential means and the applicable order identifies Xciterr as processor and Automaize as processor or sub-processor. Xciterr and Automaize process that data only on the documented instructions applicable to their role.
  2. 2.2This DPA does not apply where Xciterr acts as an independent controller for agency-led recruitment or where Automaize acts as an independent controller for platform accounts, security, consent and AI-accountability evidence, moderation, fraud prevention, technology compliance or service administration.
  3. 2.3The subject matter, duration, nature and purpose of the processing, the categories of data subjects and personal data, are described in Annex 1 (Details of Processing). This includes candidate profile data, CVs, application records, interview recordings, transcripts, automated scorecards, matching evidence, consent records and audit logs processed for recruitment workflows.
  4. 2.4Processing lasts for the term of the Customer's Service and the documented return/deletion period, subject to legal holds and mandatory retention. Data subjects include candidates, prospective candidates and authorised Customer users; data may include identity/contact, professional profile, CV, application, interview audio/transcript, assessment, communications, consent and technical-security data. Special-category data is neither requested nor intended and must not be submitted unless the parties document a lawful Article 9 condition and instructions.

3.Obligations of each Processor

Each company, while acting as a Processor, shall:

  1. 3.1process personal data only on the documented instructions of the Controller, including with regard to international transfers, unless required to do otherwise by law;
  2. 3.2ensure that persons authorised to process personal data are bound by an appropriate duty of confidentiality;
  3. 3.3implement the technical and organisational measures described in clause 5 and Annex 2;
  4. 3.4respect the conditions in clause 6 for engaging sub-processors;
  5. 3.5assist the Controller, taking into account the nature of the processing, in fulfilling its obligations to respond to data-subject requests and to ensure security, breach notification and data-protection impact assessments; and
  6. 3.6at the Controller's choice, delete or return all personal data at the end of the provision of the services, save to the extent retention is required by law.

4.Confidentiality

  1. 4.1Each Processor shall treat all personal data as confidential and shall not disclose it except as permitted under this DPA or as required by law.

5.Security

  1. 5.1Each Processor shall implement appropriate technical and organisational measures proportionate to its role. Automaize's platform measures are described in Annex 2 and the Information Security Statement; Xciterr remains responsible for recruitment-access, personnel and operational controls.

6.Sub-processors

  1. 6.1The Controller grants Xciterr general authorisation to engage Automaize for the technology processing described in the applicable order and grants the applicable Processor general authorisation to engage the infrastructure providers listed in the Sub-processor Notice.
  2. 6.2The appointing Processor shall impose data-protection obligations on each sub-processor that are no less protective than those in this DPA and remains responsible for that sub-processor as required by Article 28 GDPR.
  3. 6.3Xciterr and Automaize shall maintain an up-to-date processing chain and give the Controller prior notice of an intended material change, allowing the Controller to object on reasonable data-protection grounds.

7.Data-subject requests

  1. 7.1The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in responding to requests by data subjects to exercise their rights, and shall promptly forward to the Controller any such request it receives directly.

8.Personal data breach

  1. 8.1The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and shall provide the information reasonably required to enable the Controller to meet its own notification obligations.
  2. 8.2The Processor maintains an internal breach-notification procedure aligned to Articles 33 and 34 GDPR, including severity triage, evidence preservation, controller notice, supervisory-authority assessment, data-subject communication assessment and breach-register completion.

9.International transfers

  1. 9.1The Processor shall not transfer personal data outside the EEA except on the Controller's instructions and subject to appropriate safeguards under Chapter V GDPR, including the Standard Contractual Clauses where applicable.

10.Audit

  1. 10.1The Processor shall make available information necessary to demonstrate Article 28 compliance and shall allow reasonable audits. Audits normally begin with current independent reports and written evidence; an on-site audit may follow where that evidence is insufficient or a material incident reasonably requires it, subject to confidentiality, security, reasonable notice and allocation of exceptional costs.

11.Liability and governing law

  1. 11.1The liability of each party under this DPA is subject to the limitations of liability agreed in the Employer Terms of Service.
  2. 11.2This DPA follows the governing-law allocation in the applicable executed Employer Terms or order, without displacing mandatory GDPR rights or supervisory-authority powers.

12.Annexes

  1. 12.1Annex 1 - Details of Processing: recruitment workflow hosting, CV parsing, screening, structured voice interview, assessment, matching, candidate sharing, employer pipeline management, support and billing administration for candidates, employer users and invited representatives.
  2. 12.2Annex 2 - Security Measures: encryption in transit and at rest, row-level security, least-privilege and audited access, signed URL expiry controls, provider kill-switches, network and application security, monitoring, backup/resilience controls, incident response and regular review of measures.
  3. 12.3Annex 3 - Processing chain: Xciterr may engage Automaize as technology processor; Automaize may engage Google Cloud / Gemini, Supabase, WorkOS, Vercel, Railway, Stripe, Cal.com, Resend, Meta, Cloudflare and Sentry as published and maintained in the Sub-processor Notice. WorkOS remains disabled until its stated approval gates are complete.
  4. 12.4Annex 4 - Compliance Assistance: assistance with data-subject requests, DPIAs, prior-consultation assessment, breach notifications, audit evidence and deletion/return of personal data at service termination.