Recruiter Marketplace

Data Processing Addendum

This Data Processing Addendum (the "DPA”) forms an integral part of the Recruiter Marketplace Terms and Conditions available at Marketplace Terms & Conditions (the “Marketplace Terms”), including any order, contract, or agreement concluded based on the Marketplace Terms, executed separately by Mamba Technologies s.r.o., ID No. 214 01 896, with its registered seat at Mánesova 812/6, Vinohrady, 120 00 Praha 2 (“Finlay”), and the Party defined as Recruiter in the Marketplace Terms (the “Recruiter”)(collectively, the "Agreement").

WHEREAS

(A) In delivering or using the Services under the Agreement, the Recruiter may process data, including Personal Data controlled by Finlay, or its respective customers, contacts, or partners.

(B) The parties seek to implement data processing provisions in compliance with the Data Protection Legislation. Further, as part of its privacy notices and its contractual arrangements, Finlay has provided certain assurances to its customers, contacts, partners, and end-users to ensure the appropriate protection of all data, including Personal Data, when Finlay engages third parties. Finlay’s engagement of the Recruiter is conditioned upon the Recruiter’s agreement to the terms and conditions of this DPA.

1. DEFINITIONS
2. RECRUITER'S OBLIGATIONS
3. AUDIT RIGHTS
4. FINLAY'S OBLIGATIONS
5. COOPERATION
6.  SECURITY INCIDENTS
7. SUB-PROCESSING
8. DATA TRANSFERS
9. LIMITATION OF LIABILITY
10. USE OF ARTIFICIAL INTELLIGENCE (AI)
11. FINAL PROVISIONS

Annex A
Description of the Processing Activities / Transfer

Annex A(1) List of Parties: 
Data Exporter
Data exporter
Name: Finlay, as identified in the DPA
Name: Recruiter, as identified in the DPA
Address: As identified in the DPA
Address: As identified in the DPA
Contact details: email: info@finlay.ai
Contact details: email provided by the Recruiter
Activities relevant to the transfer: See Annex A(2) below
Activities relevant to the transfer: See Annex A(2) below 
Role: Controller or Processor (as applicable)
Role: Processor or Sub-processor (as applicable)
Annex A(3): Competent supervisory authority With respect to EU Data the competent supervisory authority is The Office of the Information Commissioner of Czech Republic (the "Supervisory Authority").  
Annex A(2)  Description of Transfer: 
Description
Description
Categories of data subjects:
●  Job Candidates
Categories of Personal Data:







●  Job Candidates: Identification and contact data (name, address, title, contact details, username); employment details (employer, job title, geographic location, area of responsibility, qualifications, references); identification documents (e.g., passport, driver's license) where required by law; salary expectations, job preferences, and availability
‌Sensitive data:




The Recruiter does not require any special categories of personal data to provide the Services and does not intentionally collect or process such data in connection with the provision of the Services.
Frequency:
Continuous 
Nature and subject matter of processing:


















The Personal Data may be subject to the following processing activities:

 storage (hosting) and other processing necessary to provide, maintain and improve the Services provided to Finlay under the Agreement,

● support provided to Finlay on a case by case basis,

disclosures in accordance with the Agreement and the DPA, as compelled by law, and

collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Duration of the processing:
Processing Term.
Purpose(s) of the data transfer and further processing: 






(i) Processing to provide, maintain, support, and improve the Services provided to Finlay in accordance with the Agreement;

(ii) Processing to comply with other instructions provided by Finlay (e.g., via email) where such instructions are consistent with the Agreement (including this DPA).
Retention period (or, if not possible to determine, the criteria used to determine that period): Processing Term.
Processing Term.
Annex A(3): Competent supervisory authority With respect to EU Data the competent supervisory authority is The Office for Personal Data Protection of the Czech Republic (the "Supervisory Authority").

Annex B
Technical and Organisational Measures

The Recruiter has implemented the following technical and organisational measures that ensure an appropriate level of security taking into account the nature, scope, context, and purposes of the processing, and the risks for the rights and freedoms of natural persons: 

1. Access Control Measures
● Controls to specify authorized individuals permitted to access personal data
● Logging and monitoring of access attempts
2. Data Encryption & Pseudonymization
● Encryption of personal data in transit
● Implementation of a password policy
3. Network & System Security
● Firewalls, intrusion detection, and prevention systems (IDS/IPS)
● Regular vulnerability scanning and patch management
● Secure software development lifecycle (SDLC) practices
4. Operational Security & Incident Response
● Security monitoring and threat detection
● Defined incident response plan with breach notification procedures
● Regular security awareness training for employees
● Confidentiality obligation for employees
5. Data Resilience & Backup
● Regular automated backups with encrypted storage
● Disaster recovery and business continuity planning
● Periodic data integrity checks
6. Audit & Compliance
● Regular internal security audits
● Compliance with industry standards (e.g., ISO 27001, SOC 2)

Annex C
Approved Sub-processors

The list of approved sub-processors of the Recruiter:
Country
Identification of sub-processon
Services
Ireland
Google Ireland Limited, with the registered office at Gordon House, Barrow Street, Dublin 4, Ireland
Analytics, Hosting, Search and Storage
New Zeland, Global
Soul Machines Ltd.,L1, 106 Customs Street West, Auckland, 1010, New Zealand
AI, Interviews
Israel, Global
Bright Data Ltd., 4 Hamahshev St., Netanya 4250714, Israel
Web data collection & Proxy services
France, Global
Unipile SAS, 168 Rue de la Rotonde, 42153 Riorges, France
Messaging & Communication API's
Ireland, USA
Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg
Hosting