Data Processing Agreement
Version 1.0 — 2 August 2026
When you upload candidate data into Parthumanally, you are the controller of that data and we are your processor. Article 28 of the GDPR requires a written contract between us. This page is that contract.
1. How this becomes binding
This agreement takes effect when you create an account and accept it, together with the Privacy Policy, and it remains in force for as long as your organization has an account. The date of your acceptance is recorded against your user account.
It incorporates, in full and without modification, the standard contractual clauses between controllers and processors adopted by the European Commission in Implementing Decision (EU) 2021/915. Those clauses are the binding core of this agreement. Clauses 1 to 10 of that text apply between us, and the annexes below are the annexes those clauses require.
The Commission publishes that text in every official EU language, so you can read the binding part in your own language at the link above. The annexes below are in English only, because they describe our service and we would rather have one accurate version than four translations we cannot verify.
2. Options selected in the clauses
Clause 7.7, sub-processors: general written authorisation. You authorise the sub-processors listed in Annex IV. If we intend to add or replace one, we will tell you at least 30 days in advance, and you may object; if you object and we cannot offer an alternative, you may terminate without penalty.
Clause 9, personal data breaches: we notify you without undue delay and in any event within 48 hours of becoming aware of a breach affecting your data, with the information we have at that moment, followed by updates as we learn more.
Clause 5, docking: not used. This agreement is between your organization and us only.
Annex I — Parties
Controller
The organization that holds the account, as identified by the organization name and the administrator email address registered in the account. Contact point: that administrator.
Processor
Parthumanally, established in Portugal. Contact point for all data protection matters: info@parthumanally.com.
Neither party has appointed a data protection officer. Signature is replaced by your acceptance at registration, as described in section 1.
Annex II — Description of the processing
Categories of data subjects
Candidates whose applications or CVs you upload to, or receive through, your organization's account.
Categories of personal data
Identification and contact details (name, email address, telephone number where provided); CV content as you supply it (professional experience, education, languages, skills, and any other free text the candidate included); application data (the vacancy applied to, status in your pipeline, notes written by your team); and output generated by the service (screening score, written justification, per-criterion results, interview guides).
Sensitive data
The service does not ask for, and is not designed to process, special categories of personal data under Article 9. Such data may nevertheless appear incidentally in free text inside a CV you upload. You are instructed not to upload special categories deliberately, and not to define screening criteria that target them. Safeguards applied regardless: strict access separation between organizations, restricted personnel access, and the retention limits below.
Nature of the processing
Storage; extraction of text from uploaded documents; automated analysis of that text against criteria you define; generation of scores, written justifications, ranked shortlists and interview guides; making all of the above available to users you authorise; and deletion.
Purpose
Solely to provide you with the recruitment screening service you subscribed to. We do not process this data for our own purposes, we do not use it to train any model, and we do not disclose it to other customers.
Duration
For as long as your account exists, subject to automatic deletion: candidate records are deleted 12 months after that candidate's most recent application, or 3 months on the free plan. Audit records and AI usage records are kept for 24 months as evidence of compliance. On termination of the account, we delete your data, unless EU or Member State law requires us to keep it.
Annex III — Technical and organisational measures
Separation between customers
Isolation is enforced by the database itself through row-level security policies, and the application connects using a role that cannot bypass them. A query that omits the organization scope returns nothing rather than another customer's data.
Encryption and secrets
All traffic is served over HTTPS with certificates renewed automatically. Passwords are stored only as bcrypt hashes and API keys only as hashes; neither can be read back. Two-factor authentication secrets are encrypted with AES-256-GCM. Two-factor authentication is available to all users and mandatory for platform administrators.
Access control
Access within your organization is governed by roles you assign. Administrative access to the production server is limited to the operator of the service, over SSH with key authentication only. Administrative actions are recorded in an audit log.
Logging and traceability
Every AI run is recorded, so any screening result can be traced and explained after the fact. Administrative and security-relevant actions are recorded in an audit log retained for 24 months.
Data minimisation
A scheduled job deletes candidate records and logs once their retention period has expired, without requiring anyone to remember to do it.
Availability and restoration
The database is backed up daily and restoration is tested. We state plainly that, at the date of this version, those backups are stored on the same host as the database: they protect against accidental deletion and data corruption, but not against the total loss of the host. Moving backups to separate infrastructure is planned. We prefer to describe this accurately rather than claim a level of resilience we have not yet built.
Annex IV — Sub-processors
Only two sub-processors are involved in processing your candidate data, and neither of them receives CV content except as described.
Oracle Cloud (Oracle Corporation)
Hosting of the server and database, in region eu-madrid-1, Spain, European Union. Oracle provides the infrastructure; it does not access application data in the course of providing it.
Resend
Delivery of transactional email such as account verification, password resets and notifications. Resend processes the recipient's email address and the message content we generate. CV content is never included in those messages.
No AI sub-processor. The model that analyses CVs runs on our own server, on the same machine that hosts the application. CV content is not sent to any external AI provider, and it does not leave the European Union. Text extraction from uploaded documents also happens on that same machine.
If you sign in using Google, Google processes that authentication. That concerns your own users' sign-in, not candidate data, and Google is therefore not a sub-processor under this agreement.
3. International transfers
Candidate data is processed only within the European Union, and we do not transfer it to a third country. Should that ever need to change, we would notify you in advance under the sub-processor procedure in section 2 and put an appropriate transfer mechanism in place first.
4. Changes to this agreement
If we change this agreement in a way that affects your rights or our obligations, we will notify account administrators by email at least 30 days before it takes effect. Earlier versions remain available on request. Questions go to info@parthumanally.com.