This Data Processing Agreement ("DPA") is entered into between the Customer (the data controller, as identified in the Platform account) and Argon Servizi di Impresa srl, operating as tenperzent.com (the data processor).
By accepting the Terms of Service, you also accept this DPA.
1. Definitions
- "Agreement" means the Terms of Service, Privacy Policy, and this Data Processing Agreement collectively.
- "Controller" means the Customer, who determines the purposes and means of processing Personal Data through the Platform.
- "Data Subject" means the identified or identifiable natural person to whom the Personal Data relates, including but not limited to job candidates whose CVs are uploaded to the Platform.
- "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.
- "Personal Data" means any information relating to a Data Subject that is processed through the Platform.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
- "Platform" means the tenperzent.com AI-powered recruitment screening platform.
- "Processor" means Argon Servizi di Impresa srl, who processes Personal Data on behalf of the Controller.
- "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Supervisory Authority" means the Italian Data Protection Authority (Garante per la protezione dei dati personali) or any other competent supervisory authority.
2. Scope and Purpose of Processing
This DPA applies to the processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the Platform services.
The Processor processes Personal Data solely for the following purposes:
- AI-powered screening and scoring of candidate CVs against job descriptions
- Storing and managing candidate data within the Controller's account
- Generating AI insights, rankings, and recruitment recommendations
- Managing recruitment pipelines and candidate status workflows
- Providing data export and reporting functionality
The nature of processing includes automated analysis, storage, retrieval, organisation, and erasure of Personal Data.
3. Categories of Personal Data and Data Subjects
3.1 Data Subjects
- Job candidates whose CVs/résumés are uploaded to the Platform
- Recruiters and hiring managers who use the Platform (Controller's employees/agents)
3.2 Categories of Personal Data
| Category | Examples |
|---|
| Identity data | Name, age, photograph, location |
| Contact data | Email address, phone number, LinkedIn profile |
| Professional data | Work experience, current role, seniority level, skills, education, key achievements |
| CV content | Full text of uploaded CVs/résumés |
| Assessment data | AI scores, insights, fit/risk tags, match breakdowns |
| Account data | Recruiter name, email, authentication credentials |
Special categories of data: The Controller must not upload CVs or data containing special categories of personal data (Article 9 GDPR) unless the Controller has obtained explicit consent from the Data Subject or another valid legal basis.
4. Obligations of the Processor
4.1 Lawful Processing
The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by EU or Member State law.
4.2 Confidentiality
The Processor shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.3 Security Measures (Article 32 GDPR)
The Processor implements the following technical and organisational measures:
- Encryption of data in transit (TLS 1.2+) and at rest
- Row-Level Security (RLS) policies ensuring strict data isolation between users
- Authentication via secure token-based sessions with email verification
- Audit logging of all data access and status changes
- Automated data backup and disaster recovery procedures
- Access control: role-based permissions with principle of least privilege
- Regular security scanning and vulnerability assessments
- Secure file storage with per-user folder isolation and ownership validation
4.4 Sub-processors
The Controller provides general authorisation for the Processor to engage Sub-processors, subject to the following conditions:
- The Processor shall maintain an up-to-date list of Sub-processors (see Annex B below)
- The Processor shall inform the Controller of any intended changes to Sub-processors, providing at least 30 days' notice
- The Controller may object to the appointment of a new Sub-processor within 14 days of notification
- The Processor shall impose equivalent data protection obligations on all Sub-processors via written contract
4.5 Data Subject Rights
The Processor shall assist the Controller in responding to requests from Data Subjects exercising their rights under GDPR Articles 15–22, including:
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
The Platform provides the Controller with tools to delete candidate data, export data, and manage their account, which support these obligations.
4.6 Personal Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach. The notification shall include:
- A description of the nature of the breach, including categories and approximate number of Data Subjects affected
- The name and contact details of the Processor's contact point
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach
4.7 Data Protection Impact Assessment
The Processor shall assist the Controller with data protection impact assessments (Article 35) and prior consultations with supervisory authorities (Article 36) where required.
5. Obligations of the Controller
The Controller warrants and undertakes that:
- It has a valid legal basis for processing candidate Personal Data (e.g., legitimate interest in recruitment, or consent)
- It has provided appropriate privacy notices to Data Subjects whose data is uploaded to the Platform
- It shall not upload special categories of data without a valid legal basis and, where required, explicit consent
- It is responsible for the accuracy of Personal Data provided to the Processor
- It shall comply with all applicable data protection laws in its use of the Platform
6. International Data Transfers
The Processor may transfer Personal Data outside the European Economic Area (EEA) only where appropriate safeguards are in place, including:
- EU Standard Contractual Clauses (SCCs) as approved by the European Commission
- An adequacy decision by the European Commission (Article 45 GDPR)
- Binding Corporate Rules approved by a competent Supervisory Authority
Details of current transfers and applicable safeguards are set out in Annex B (Sub-processors).
7. Duration, Termination, and Data Return
7.1 Duration
This DPA shall remain in effect for the duration of the Controller's use of the Platform and for as long as the Processor retains Personal Data on behalf of the Controller.
7.2 Data Return and Deletion
Upon termination of the Controller's account or upon the Controller's written request:
- The Processor shall make all Personal Data available for export by the Controller
- Upon confirmation or after a reasonable retention period (not exceeding 30 days), the Processor shall permanently delete all Personal Data, unless EU or Member State law requires continued storage
- The Controller may initiate immediate account deletion via the Platform's settings, which triggers permanent removal of all associated data (job analyses, candidates, CVs, notes, and scores)
- Billing transaction records are retained for accounting and legal compliance purposes only and do not contain candidate Personal Data
8. Audit Rights
The Controller has the right to conduct audits, including inspections, to verify the Processor's compliance with this DPA. The Processor shall:
- Make available all information necessary to demonstrate compliance with Article 28 GDPR
- Allow for and contribute to audits conducted by the Controller or an independent auditor mandated by the Controller
- Immediately inform the Controller if, in the Processor's opinion, an instruction from the Controller infringes GDPR or other data protection provisions
Audits shall be conducted with reasonable prior notice (at least 30 days) and during normal business hours, unless an urgent audit is required following a data breach.
9. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, except that neither party excludes or limits its liability for:
- Fraud or fraudulent misrepresentation
- Any liability that cannot be excluded or limited by applicable law
- Fines imposed by a Supervisory Authority to the extent attributable to the responsible party's breach
10. Governing Law and Jurisdiction
This DPA shall be governed by and construed in accordance with the laws of Italy. Any disputes shall be submitted to the exclusive jurisdiction of the courts of Italy, without prejudice to the right of Data Subjects to lodge a complaint with a Supervisory Authority.
11. Amendments
The Processor may update this DPA from time to time to reflect changes in applicable law or the Platform's processing activities. Material changes shall be communicated to the Controller with at least 30 days' notice. Continued use of the Platform after such notice constitutes acceptance of the updated DPA.
Annex A — Description of Processing
| Element | Details |
|---|
| Subject matter | AI-powered recruitment screening and candidate management |
| Duration | For the term of the Controller's Platform account |
| Nature of processing | Automated analysis, scoring, storage, organisation, retrieval, and erasure |
| Purpose | Enabling the Controller to screen, score, and manage job candidates |
| Data subjects | Job candidates, recruiters, and hiring managers |
| Categories of data | Identity, contact, professional, CV content, assessment, and account data |
| Special categories | None (unless uploaded by the Controller with valid legal basis) |
Annex B — Authorised Sub-processors
The following Sub-processors are authorised as of the date of this DPA:
| Sub-processor | Purpose | Location | Safeguard |
|---|
| Supabase Inc. | Database hosting, authentication, file storage, serverless functions | US / EU | SCCs / DPF |
| Google Cloud (Gemini AI) | AI model inference for CV screening and scoring | US / EU | SCCs / DPF |
| OpenAI Inc. | AI model inference for CV screening and scoring | US | SCCs / DPF |
| Stripe Inc. | Payment processing and billing | US | SCCs / DPF |
| Cloudflare Inc. | CDN, DDoS protection, email routing | Global | SCCs / DPF |
| Lovable (GPT Engineer AB) | Platform hosting, deployment, email infrastructure | EU (Sweden) | Adequacy / SCCs |
Annex C — Technical and Organisational Measures
The Processor implements the following measures pursuant to Article 32 GDPR:
Access Control
- Token-based authentication with secure session management
- Email verification required before account activation
- Role-based access control (admin/user) with separate roles table
- Row-Level Security (RLS) on all database tables ensuring user data isolation
- Service-role-only access for system operations (email, billing, credits)
Data Protection
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption for data at rest
- Per-user folder isolation for uploaded CV files with ownership validation
- Private storage buckets (no public access to CVs or candidate photos)
- Immutable audit logs (insert-only, no update/delete)
Availability and Resilience
- Automated database backups with point-in-time recovery
- Multi-region infrastructure with failover capabilities
- DDoS protection via CDN provider
Data Minimisation and Retention
- Data collected is limited to what is necessary for the recruitment screening purpose
- Account deletion permanently removes all associated personal data
- Consent records maintained with version tracking for compliance auditing
Breach Detection and Response
- Continuous security scanning and vulnerability assessments
- Activity logging for all significant user actions
- Email suppression system to prevent sending to bounced/complained addresses
Acceptance
This DPA is automatically accepted by the Controller upon creation of a Platform account and acceptance of the Terms of Service, Privacy Policy, and Cookie Policy through the consent gate.
Processor: Argon Servizi di Impresa srl, operating as tenperzent.com
Date: April 2, 2026
Contact: tenperzent.com@gmail.com