Data Processing Agreement

    GDPR Article 28

    Version 1.0 — Last updated: April 2, 2026

    This Data Processing Agreement ("DPA") is entered into between the Customer (the data controller, as identified in the Platform account) and Argon Servizi di Impresa srl, operating as tenperzent.com (the data processor).

    By accepting the Terms of Service, you also accept this DPA.

    1. Definitions

    • "Agreement" means the Terms of Service, Privacy Policy, and this Data Processing Agreement collectively.
    • "Controller" means the Customer, who determines the purposes and means of processing Personal Data through the Platform.
    • "Data Subject" means the identified or identifiable natural person to whom the Personal Data relates, including but not limited to job candidates whose CVs are uploaded to the Platform.
    • "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.
    • "Personal Data" means any information relating to a Data Subject that is processed through the Platform.
    • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
    • "Platform" means the tenperzent.com AI-powered recruitment screening platform.
    • "Processor" means Argon Servizi di Impresa srl, who processes Personal Data on behalf of the Controller.
    • "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
    • "Supervisory Authority" means the Italian Data Protection Authority (Garante per la protezione dei dati personali) or any other competent supervisory authority.

    2. Scope and Purpose of Processing

    This DPA applies to the processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the Platform services.

    The Processor processes Personal Data solely for the following purposes:

    • AI-powered screening and scoring of candidate CVs against job descriptions
    • Storing and managing candidate data within the Controller's account
    • Generating AI insights, rankings, and recruitment recommendations
    • Managing recruitment pipelines and candidate status workflows
    • Providing data export and reporting functionality

    The nature of processing includes automated analysis, storage, retrieval, organisation, and erasure of Personal Data.

    3. Categories of Personal Data and Data Subjects

    3.1 Data Subjects

    • Job candidates whose CVs/résumés are uploaded to the Platform
    • Recruiters and hiring managers who use the Platform (Controller's employees/agents)

    3.2 Categories of Personal Data

    CategoryExamples
    Identity dataName, age, photograph, location
    Contact dataEmail address, phone number, LinkedIn profile
    Professional dataWork experience, current role, seniority level, skills, education, key achievements
    CV contentFull text of uploaded CVs/résumés
    Assessment dataAI scores, insights, fit/risk tags, match breakdowns
    Account dataRecruiter name, email, authentication credentials

    Special categories of data: The Controller must not upload CVs or data containing special categories of personal data (Article 9 GDPR) unless the Controller has obtained explicit consent from the Data Subject or another valid legal basis.

    4. Obligations of the Processor

    4.1 Lawful Processing

    The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by EU or Member State law.

    4.2 Confidentiality

    The Processor shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

    4.3 Security Measures (Article 32 GDPR)

    The Processor implements the following technical and organisational measures:

    • Encryption of data in transit (TLS 1.2+) and at rest
    • Row-Level Security (RLS) policies ensuring strict data isolation between users
    • Authentication via secure token-based sessions with email verification
    • Audit logging of all data access and status changes
    • Automated data backup and disaster recovery procedures
    • Access control: role-based permissions with principle of least privilege
    • Regular security scanning and vulnerability assessments
    • Secure file storage with per-user folder isolation and ownership validation

    4.4 Sub-processors

    The Controller provides general authorisation for the Processor to engage Sub-processors, subject to the following conditions:

    1. The Processor shall maintain an up-to-date list of Sub-processors (see Annex B below)
    2. The Processor shall inform the Controller of any intended changes to Sub-processors, providing at least 30 days' notice
    3. The Controller may object to the appointment of a new Sub-processor within 14 days of notification
    4. The Processor shall impose equivalent data protection obligations on all Sub-processors via written contract

    4.5 Data Subject Rights

    The Processor shall assist the Controller in responding to requests from Data Subjects exercising their rights under GDPR Articles 15–22, including:

    • Right of access (Article 15)
    • Right to rectification (Article 16)
    • Right to erasure (Article 17)
    • Right to restriction of processing (Article 18)
    • Right to data portability (Article 20)
    • Right to object (Article 21)

    The Platform provides the Controller with tools to delete candidate data, export data, and manage their account, which support these obligations.

    4.6 Personal Data Breach Notification

    The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach. The notification shall include:

    1. A description of the nature of the breach, including categories and approximate number of Data Subjects affected
    2. The name and contact details of the Processor's contact point
    3. A description of the likely consequences of the breach
    4. A description of the measures taken or proposed to address the breach

    4.7 Data Protection Impact Assessment

    The Processor shall assist the Controller with data protection impact assessments (Article 35) and prior consultations with supervisory authorities (Article 36) where required.

    5. Obligations of the Controller

    The Controller warrants and undertakes that:

    1. It has a valid legal basis for processing candidate Personal Data (e.g., legitimate interest in recruitment, or consent)
    2. It has provided appropriate privacy notices to Data Subjects whose data is uploaded to the Platform
    3. It shall not upload special categories of data without a valid legal basis and, where required, explicit consent
    4. It is responsible for the accuracy of Personal Data provided to the Processor
    5. It shall comply with all applicable data protection laws in its use of the Platform

    6. International Data Transfers

    The Processor may transfer Personal Data outside the European Economic Area (EEA) only where appropriate safeguards are in place, including:

    • EU Standard Contractual Clauses (SCCs) as approved by the European Commission
    • An adequacy decision by the European Commission (Article 45 GDPR)
    • Binding Corporate Rules approved by a competent Supervisory Authority

    Details of current transfers and applicable safeguards are set out in Annex B (Sub-processors).

    7. Duration, Termination, and Data Return

    7.1 Duration

    This DPA shall remain in effect for the duration of the Controller's use of the Platform and for as long as the Processor retains Personal Data on behalf of the Controller.

    7.2 Data Return and Deletion

    Upon termination of the Controller's account or upon the Controller's written request:

    1. The Processor shall make all Personal Data available for export by the Controller
    2. Upon confirmation or after a reasonable retention period (not exceeding 30 days), the Processor shall permanently delete all Personal Data, unless EU or Member State law requires continued storage
    3. The Controller may initiate immediate account deletion via the Platform's settings, which triggers permanent removal of all associated data (job analyses, candidates, CVs, notes, and scores)
    4. Billing transaction records are retained for accounting and legal compliance purposes only and do not contain candidate Personal Data

    8. Audit Rights

    The Controller has the right to conduct audits, including inspections, to verify the Processor's compliance with this DPA. The Processor shall:

    1. Make available all information necessary to demonstrate compliance with Article 28 GDPR
    2. Allow for and contribute to audits conducted by the Controller or an independent auditor mandated by the Controller
    3. Immediately inform the Controller if, in the Processor's opinion, an instruction from the Controller infringes GDPR or other data protection provisions

    Audits shall be conducted with reasonable prior notice (at least 30 days) and during normal business hours, unless an urgent audit is required following a data breach.

    9. Liability

    Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, except that neither party excludes or limits its liability for:

    • Fraud or fraudulent misrepresentation
    • Any liability that cannot be excluded or limited by applicable law
    • Fines imposed by a Supervisory Authority to the extent attributable to the responsible party's breach

    10. Governing Law and Jurisdiction

    This DPA shall be governed by and construed in accordance with the laws of Italy. Any disputes shall be submitted to the exclusive jurisdiction of the courts of Italy, without prejudice to the right of Data Subjects to lodge a complaint with a Supervisory Authority.

    11. Amendments

    The Processor may update this DPA from time to time to reflect changes in applicable law or the Platform's processing activities. Material changes shall be communicated to the Controller with at least 30 days' notice. Continued use of the Platform after such notice constitutes acceptance of the updated DPA.

    Annex A — Description of Processing

    ElementDetails
    Subject matterAI-powered recruitment screening and candidate management
    DurationFor the term of the Controller's Platform account
    Nature of processingAutomated analysis, scoring, storage, organisation, retrieval, and erasure
    PurposeEnabling the Controller to screen, score, and manage job candidates
    Data subjectsJob candidates, recruiters, and hiring managers
    Categories of dataIdentity, contact, professional, CV content, assessment, and account data
    Special categoriesNone (unless uploaded by the Controller with valid legal basis)

    Annex B — Authorised Sub-processors

    The following Sub-processors are authorised as of the date of this DPA:

    Sub-processorPurposeLocationSafeguard
    Supabase Inc.Database hosting, authentication, file storage, serverless functionsUS / EUSCCs / DPF
    Google Cloud (Gemini AI)AI model inference for CV screening and scoringUS / EUSCCs / DPF
    OpenAI Inc.AI model inference for CV screening and scoringUSSCCs / DPF
    Stripe Inc.Payment processing and billingUSSCCs / DPF
    Cloudflare Inc.CDN, DDoS protection, email routingGlobalSCCs / DPF
    Lovable (GPT Engineer AB)Platform hosting, deployment, email infrastructureEU (Sweden)Adequacy / SCCs

    Annex C — Technical and Organisational Measures

    The Processor implements the following measures pursuant to Article 32 GDPR:

    Access Control

    • Token-based authentication with secure session management
    • Email verification required before account activation
    • Role-based access control (admin/user) with separate roles table
    • Row-Level Security (RLS) on all database tables ensuring user data isolation
    • Service-role-only access for system operations (email, billing, credits)

    Data Protection

    • TLS 1.2+ encryption for all data in transit
    • AES-256 encryption for data at rest
    • Per-user folder isolation for uploaded CV files with ownership validation
    • Private storage buckets (no public access to CVs or candidate photos)
    • Immutable audit logs (insert-only, no update/delete)

    Availability and Resilience

    • Automated database backups with point-in-time recovery
    • Multi-region infrastructure with failover capabilities
    • DDoS protection via CDN provider

    Data Minimisation and Retention

    • Data collected is limited to what is necessary for the recruitment screening purpose
    • Account deletion permanently removes all associated personal data
    • Consent records maintained with version tracking for compliance auditing

    Breach Detection and Response

    • Continuous security scanning and vulnerability assessments
    • Activity logging for all significant user actions
    • Email suppression system to prevent sending to bounced/complained addresses

    Acceptance

    This DPA is automatically accepted by the Controller upon creation of a Platform account and acceptance of the Terms of Service, Privacy Policy, and Cookie Policy through the consent gate.

    Processor: Argon Servizi di Impresa srl, operating as tenperzent.com

    Date: April 2, 2026

    Contact: tenperzent.com@gmail.com