VERSION: 1.0
EFFECTIVE FROM: april 1, 2025

Data Processing Addendum

1. INITIAL PROVISIONS
2. DEFINITIONS
3. PROVIDER'S OBLIGATIONS
4. AUDIT RIGHTS
5. CLIENT'S OBLIGATIONS
6. COOPERATION
7. SECURITY INCIDENTS
8. SUB-PROCESSING
9. DATA TRANSFERS
10. LIMITATION OF LIABILITY
11. FINAL PROVISIONS

Annex A
Description of the Processing Activities / Transfer

Annex A(1) List of Parties: 
Data Exporter
Data exporter
Name: Client, as identified in the Order
Name: Provider, as identified in the Agreement
Address: As identified in the Order
Address: As identified in the Agreement
Contact details: As identified in the Order
Contact details: As identified in the Agreement
Activities relevant to the transfer: See Annex A(2) below
Activities relevant to the transfer: See Annex A(2) below 
Role: Controller
Role: Processor
Annex A(3): Competent supervisory authority With respect to EU Data the competent supervisory authority is The Office of the Information Commissioner of Czech Republic (the "Supervisory Authority").  
Annex A(2)  Description of Transfer: 
Description
Description
Categories of data subjects:
●  Job Candidates
Categories of Personal Data:







●  Job Candidates: Identification and contact
data (name, address, title, contact details, username); employment details (employer, job title, geographic location, area of responsibility, qualifications, references); identification documents (e.g., passport, driver's license) where required by law; salary expectations, job preferences, and availability
‌Sensitive data:




The Provider does not require any special categories of personal data to provide the Services and does not intentionally collect or process such data in connection with the provision of the Services.
Frequency:
Continuous 
Nature and subject matter of processing:


















The Personal Data may be subject to the following processing activities:

●  
storage (hosting) and other processing necessary to provide, maintain and improve the Services provided to Client under the Agreement,

● support provided to the Client on a case by case basis,

disclosures in accordance with the Agreement and the DPA, as compelled by law, and

collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Duration of the processing:
Processing Term
Purpose(s) of the data transfer and further processing: 






(i) Processing to provide, maintain, support, and improve the Services provided to the Client in accordance with the Agreement; (ii) Processing to comply with other documented reasonable instructions provided by the Client (e.g., via email) where such instructions are consistent with the Agreement (including this DPA).
Retention period (or, if not possible to determine, the criteria used to determine that period): 
Processing Term.
Annex A(3): Competent supervisory authority With respect to EU Data the competent supervisory authority is The Office of the Information Commissioner of Czech Republic (the "Supervisory Authority").  

Annex B
Technical and Organisational Measures

The Provider has implemented the following technical and organisational measures that ensure an appropriate level of security taking into account the nature, scope, context, and purposes of the processing, and the risks for the rights and freedoms of natural persons: 

1. Access Control Measures
● Controls to specify authorized individuals permitted to access personal data
● Logging and monitoring of access attempts
2. Data Encryption & Pseudonymization
● Implementation of a password policy
● Encryption of personal data in transit
3. Network & System Security
● Firewalls, intrusion detection, and prevention systems (IDS/IPS)
● Regular vulnerability scanning and patch management
● Secure software development lifecycle (SDLC) practices
4. Operational Security & Incident Response
● Security monitoring and threat detection
● Regular security awareness training for employees
● Confidentiality obligation for employees
● Defined incident response plan with breach notification procedures
5. Data Resilience & Backup
● Regular automated backups with encrypted storage
● Disaster recovery and business continuity planning
● Periodic data integrity checks
6. Audit & Compliance
● Regular internal security audits
● Compliance with industry standards (e.g., ISO 27001, SOC 2)

Annex C
Approved Sub-processors

Country
Identification of sub-processon
Services
Ireland
Google Ireland Limited, with the registered office at Gordon House, Barrow Street, Dublin 4, Ireland
Analytics and Storage
Ireland
Amazon Web Services, Inc., with offices at 410 Terry Avenue North, Seattle, WA 98109-5210
Hosting