Skip to main content
HACKTALENTSBack to site

Data Processing Agreement

Auftragsverarbeitungsvertrag pursuant to Art. 28 GDPR

Version 1.0 · Effective 7 August 2026


§ 1 Parties, Scope and Precedence

1.1 This Data Processing Agreement ("DPA") is concluded between:

Hack-Nation UG (haftungsbeschränkt), Tal 44, 80331 München, Germany, operating the HackTalents platform at hacktalents.ai (the "Processor")

and the business customer using that platform under the General Terms and Conditions at hacktalents.ai/terms (the "Controller").

1.2 This DPA applies exclusively to the processing of personal data contained in documents and text the Controller uploads, pastes or links to the Platform in order to describe a role and search against it — in particular job descriptions and comparable recruitment documents — together with material derived from that content ("Customer Content").

1.3 This DPA does not apply to any other processing carried out by the Processor. In particular, the Processor acts as an independent controller, and not as a processor, in respect of:

(a) the candidate index and all candidate profile data; (b) Interest Checks, Introductions and records of the Controller's interactions with the Platform, which the Processor retains for its own purposes including the establishment and enforcement of its claims under § 6 of the General Terms and Conditions; (c) the Controller's account, authentication, billing and usage data; (d) communications sent by the Processor to candidates.

1.4 This DPA forms part of the contract between the parties. Where this DPA conflicts with the General Terms and Conditions, this DPA prevails in respect of the processing described in § 1.2.

1.5 Terms used in this DPA have the meaning given to them in the GDPR.


§ 2 Subject Matter and Details of the Processing

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.


§ 3 Instructions

3.1 The Processor processes Customer Content only on the documented instructions of the Controller, including in relation to transfers to a third country, unless required to do otherwise by Union or Member State law to which the Processor is subject. In that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.

3.2 The Controller's instructions are constituted by this DPA, the General Terms and Conditions, and the Controller's use of the documented functions of the Platform. Instructions going beyond those functions must be given in text form and may require a separate agreement on remuneration and feasibility.

3.3 The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions. The Processor may suspend execution of that instruction until the Controller confirms or amends it.

3.4 The Controller is responsible for the lawfulness of the processing it instructs and warrants that it is entitled to transfer the Customer Content to the Processor for the purposes described in Annex 1.


§ 4 Restrictions on Customer Content

4.1 The Controller shall not upload or otherwise submit:

(a) personal data beyond what is necessary to describe a role; (b) candidate CVs or applicant data; (c) special categories of personal data within the meaning of Art. 9 GDPR; (d) personal data relating to persons under 18 years of age; (e) personal data relating to criminal convictions or offences (Art. 10 GDPR).

4.2 The Processor's service is not designed for the categories of data listed in § 4.1 and the technical and organisational measures in Annex 2 are not calibrated to them. Where the Controller submits such data contrary to § 4.1, it does so on its own responsibility.


§ 5 Confidentiality

5.1 The Processor ensures that persons authorised to process Customer Content have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.2 That obligation survives the end of the relevant person's engagement with the Processor.

5.3 Access to Customer Content is limited to those persons who require it in order to perform the contract.


§ 6 Security of Processing

6.1 The Processor implements the technical and organisational measures set out in Annex 2 in accordance with Art. 32 GDPR.

6.2 The measures in Annex 2 are subject to technical progress and development. The Processor may implement alternative measures provided the level of protection is not reduced. Material changes are documented and communicated to the Controller on request.

6.3 The Controller has satisfied itself that the measures in Annex 2 are appropriate to the risk presented by the Customer Content it submits, taking into account § 4.1.


§ 7 Sub-processors

7.1 The Controller grants the Processor general written authorisation to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex 3.

7.2 The Processor informs the Controller of any intended addition or replacement of a sub-processor at least thirty (30) days in advance, in text form or by updating Annex 3 and notifying the Controller.

7.3 The Controller may object to a change on reasonable grounds relating to data protection within fourteen (14) days of being informed. Where the parties cannot resolve the objection, the Controller may terminate the contract in respect of the affected services with effect from the date the change takes effect, without liability on either side.

7.4 The Processor imposes on each sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, and in particular the obligations in Art. 28(3) GDPR.

7.5 The Processor remains fully liable to the Controller for the performance of each sub-processor's obligations.


§ 8 Assistance with Data Subject Rights

8.1 Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests for exercising data subject rights under Chapter III GDPR.

8.2 Where a data subject contacts the Processor directly in respect of Customer Content, the Processor forwards the request to the Controller without undue delay and does not respond to it substantively, unless legally required to do so.

8.3 The Processor may charge a reasonable fee for assistance that goes materially beyond providing information available through the Platform's standard functions.


§ 9 Assistance with Security, Breach Notification and Impact Assessments

9.1 The Processor assists the Controller in ensuring compliance with the obligations under Arts. 32 to 36 GDPR, taking into account the nature of the processing and the information available to it.

9.2 The Processor notifies the Controller without undue delay, and in any event within twenty-four (24) hours, after becoming aware of a personal data breach affecting Customer Content. The notification includes, as far as known:

(a) a description of the nature of the breach, including the categories and approximate number of data subjects and records concerned; (b) the name and contact details of the Processor's contact point; (c) the likely consequences; (d) the measures taken or proposed to address the breach and mitigate its effects.

Where the information cannot be provided at once, it is provided in phases without further undue delay.

9.3 The Processor documents personal data breaches affecting Customer Content and makes that documentation available to the Controller on request.

9.4 The Processor takes no steps to notify a supervisory authority or a data subject on the Controller's behalf unless expressly instructed to do so.

9.5 Contact point. The Processor's contact point for security incidents and for all matters under this DPA is:

Kai Nestor Wiederhold · k-wiederhold@web.de

The Processor keeps this contact point monitored and will notify the Controller in text form if it changes.


§ 10 Deletion and Return

10.1 On termination of the contract the Processor, at the Controller's choice, deletes or returns all Customer Content and deletes existing copies, unless Union or Member State law requires continued storage.

10.2 The Controller shall communicate its choice in text form within thirty (30) days of termination. In the absence of a choice within that period, the Processor deletes the Customer Content.

10.3 Deletion from the Processor's active production systems takes place within thirty (30) days of the Controller's choice or of the expiry of the period in § 10.2.

10.4 Backups. Customer Content contained in encrypted backups is not deleted individually. It is overwritten in accordance with the applicable backup retention cycle and is not restored to production except in the course of a disaster-recovery event. During that period the content remains subject to the measures in Annex 2 and to the confidentiality obligation in § 5.

10.5 Vendor logs. Customer Content transmitted to a sub-processor may persist in that sub-processor's operational or abuse-monitoring logs for the period stated in Annex 3. The Processor cannot delete such copies individually.

10.6 The Processor confirms deletion to the Controller in text form on request.

10.7 During the term of the contract the Controller may request deletion of individual Customer Content at any time in text form. The Processor gives effect to the request within thirty (30) days, subject to §§ 10.4 and 10.5.


§ 11 Verification and Audit

11.1 The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR.

11.2 The Processor's obligation under § 11.1 is discharged in the first instance by providing:

(a) this DPA together with Annexes 1 to 3; (b) a completed written security questionnaire, once per calendar year on request; (c) any assurance reports of its sub-processors that it is contractually permitted to pass on.

11.3 Where the information provided under § 11.2 is not sufficient to demonstrate compliance, or following a substantiated personal data breach, the Controller may conduct or mandate an inspection. The Controller shall give at least thirty (30) (in urgent cases fourteen (14)) days' notice in text form, conduct the inspection during normal business hours, cause the minimum necessary disruption, and bear its own costs. An inspection may take place no more than once per calendar year unless a substantiated incident gives cause for more.

11.4 An auditor mandated by the Controller shall not be a competitor of the Processor and shall be bound to confidentiality.

11.5 The Processor may withhold information whose disclosure would breach a legal obligation, a duty of confidentiality owed to a third party, or the security of other customers' data. Certifications or audit reports of the Processor's sub-processors are not certifications of the Processor.


§ 12 International Transfers

12.1 The Processor processes Customer Content within the European Economic Area except where transfer to a third country is necessary for the provision of the service. The processing location of each sub-processor is stated in Annex 3.

12.2 Where Customer Content is transferred to a third country, the transfer is based on:

(a) an adequacy decision of the European Commission under Art. 45 GDPR; or (b) the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, module two or module three as applicable, supplemented by a transfer impact assessment.

12.3 The Controller authorises the Processor to conclude the Standard Contractual Clauses with sub-processors on its behalf, in its name, for transfers required to provide the service.

12.4 The Processor informs the Controller without undue delay if it receives a legally binding request from a public authority for disclosure of Customer Content, unless prohibited from doing so.


§ 13 Liability

13.1 The parties' liability under this DPA is governed by § 13 of the General Terms and Conditions.

13.2 Art. 82 GDPR remains unaffected.


§ 14 Term, Amendments, Governing Law

14.1 This DPA takes effect with the contract between the parties and ends when that contract ends, save for the obligations in §§ 5, 10 and 11, which survive for as long as the Processor holds Customer Content.

14.2 Amendments to this DPA require text form. § 17 of the General Terms and Conditions applies accordingly.

14.3 This DPA is governed by the law of the Federal Republic of Germany. § 18 of the General Terms and Conditions applies to the place of jurisdiction.

14.4 Should individual provisions of this DPA be invalid, the validity of the remainder is unaffected.


Annex 1 — Details of the Processing

Subject matter Hosting and analysis of role descriptions and comparable recruitment documents supplied by the Controller, in order to derive search criteria and search the Processor's candidate index.

Duration The term of the contract, plus the deletion periods in § 10.

Nature of the processing Collection; transient handling of uploaded files; extraction of text where the format is supported; storage of extracted text; analysis by a large language model to normalise the role and derive filters, preferences and semantic search queries; embedding of derived queries; searching the candidate index; storage of the resulting interaction records; return and deletion.

Purpose To convert the Controller's role requirements into search criteria and to use those criteria to search the candidate index.

Types of personal data

  • Free-text content of the submitted document or text
  • Company and role information
  • Employment requirements and criteria
  • Names, contact details, job titles or reporting lines of individuals named in the submitted content
  • Criteria, filters and semantic queries derived from the above

Categories of data subjects

  • The Controller's personnel, in particular hiring managers and contact persons named in submitted content
  • Any other individual named in submitted content

Special categories of personal data Not required for the service and prohibited under § 4.1.

Format handling Uploaded PDF, DOC and DOCX files are accepted but their contents are not currently extracted; the file bytes are discarded after the request and no copy is retained. Text content is processed from pasted text, uploaded plain-text files, or a public job-page URL supplied by the Controller. Text is truncated at 20,000 characters. Uploaded filenames are not retained.


Annex 2 — Technical and Organisational Measures (Art. 32 GDPR)

The measures below are those implemented by the Processor at the date of this DPA. Measures marked (vendor) are commitments made by the relevant sub-processor rather than by the Processor.

Confidentiality — access control

  • Row-level security is enforced on the database tables holding Customer Content.
  • Direct table privileges are revoked from browser-facing and service roles; all access is routed through constrained server-side functions.
  • Application operations are scoped to the authenticated user's account membership, so a user cannot reach another account's Customer Content.
  • Access to Customer Content by the Processor's personnel is limited to those who require it to perform the contract, and those persons are bound to confidentiality.

Confidentiality — transmission and storage control

  • All application interfaces and all calls to sub-processors use HTTPS.
  • API responses carrying Customer Content are marked private, no-store.
  • Raw uploaded files are not written to disk or object storage and are discarded after the request.
  • Uploaded filenames are sanitised and replaced.
  • Encryption at rest using AES-256 and in transit using TLS 1.2 or higher for the primary database and its backups (vendor).
  • Encryption at rest using AES-256 or equivalent, TLS 1.2 or higher in transit, and cloud-provider key management for the vector search service (vendor).

Integrity

  • Interaction and search-lineage records are append-only, preventing undetected alteration of the record of what was processed.
  • Referential integrity constraints prevent orphaned or partially removed records.

Availability and resilience

  • Daily physical backups of the primary database (vendor).
  • Managed, redundant infrastructure operated by the sub-processors named in Annex 3 (vendor).

Data minimisation

  • Text input is truncated at 20,000 characters and retrieved job-page content at 1.5 MB.
  • Only derived semantic queries, not the full submitted content, are transmitted to the embedding and vector-search providers.
  • No analytics, advertising or third-party tracking technologies are present in the application.
  • Application error logging records the error type only, and does not capture request bodies or Customer Content.

Server-side request forgery protection

  • Job-page retrieval enforces HTTPS, DNS and IP address checks, a redirect limit and a size limit.

Sub-processor governance

  • Written data protection terms with each sub-processor, as recorded in Annex 3.
  • Sub-processor changes notified in accordance with § 7.

Annex 3 — Sub-processors

Sub-processorLegal entity and addressProcessing of Customer ContentProcessing locationTransfer basis
SupabaseSupabase Pte. Ltd., 65 Chulia Street, #38-02/03, OCBC Centre, Singapore 049513Stores the extracted brief, the language-model interaction record, derived filters, semantic queries and clarification answersPrimary database: AWS eu-west-1, IrelandStandard Contractual Clauses
OpenAIOpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, IrelandReceives the extracted or pasted brief; normalises the role and derives filters and semantic queriesGlobal endpoint; processing may occur outside the EEAStandard Contractual Clauses
Voyage AI (a MongoDB company)Voyage AI Innovations, Inc. / MongoDB, Inc., 1633 Broadway, 38th Floor, New York, NY 10019, USAReceives derived semantic queries for embedding, and derived queries with candidate evidence for rerankingUnited StatesEU–US Data Privacy Framework, supplemented by the Standard Contractual Clauses
WeaviateWeaviate B.V., Prinsengracht 769A, 1017 JZ Amsterdam, NetherlandsReceives derived query text and a transient query vector; returns matching candidate recordsWeaviate Cloud, AWS eu-central-1, FrankfurtWithin the EEA
VercelVercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USAProcesses the request and the brief in function memory during the requestEU function regionStandard Contractual Clauses

Retention in sub-processor logs (§ 10.5)

  • OpenAI: Customer Content is not used to train models. It may be retained in abuse-monitoring logs for up to 30 days.
  • Voyage AI: the Processor has opted out of the use of submitted content for service improvement, and zero-day retention applies.
  • Supabase, Weaviate, Vercel: operational and security log retention is governed by the respective vendor's terms.

No persisted vector

Customer Content is not stored as a vector in the Processor's vector database. Semantic query vectors are generated for an individual search and transmitted as transient query inputs. There is accordingly no stored Customer Content vector requiring deletion under § 10.


Hack-Nation UG (haftungsbeschränkt) · Tal 44, 80331 München, Germany Amtsgericht München, HRB 304261 · VAT ID DE456131673

Version 1.0 · Effective 7 August 2026

  • Imprint
  • Privacy
  • Cookies
  • Terms
  • DPA
© 2026 HackTalents