Data Processing Agreement (DPA)
Last updated: October 4, 2026For our enterprise customers, AuditCV.io provides an executed Data Processing Agreement (DPA) governing the obligations between the data controller (your company) and the data processor (AuditCV.io). Below is an overview and standard clauses; contact our sales team to request an executed copy.
View Full Text
1. Parties & Roles
Under this DPA, your organization acts as the "Data Controller", and AuditCV.io acts as the "Data Processor" processing reference verification data on your behalf.
2. Scope & Duration of Processing
Processing is strictly confined to the duration of the service contract and the purpose of conducting reference checks: candidate and referee full names, contact coordinates, and evaluation responses.
3. Sub-processors
Hosting, database, and transactional email infrastructure providers utilized to deliver the service are listed in the DPA annex. Customers are notified prior to engaging new sub-processors.
4. Security Measures
Data is encrypted in transit using TLS/HTTPS, access is governed by strict authorization, and data breaches will be reported to the customer without undue delay.
5. Audit Rights
Enterprise customers possess the right to inspect our data processing compliance or request relevant security audit certifications subject to reasonable notice.
6. Term & Termination
Upon termination of the service agreement, all processed data is returned or permanently destroyed in accordance with customer instructions, with written confirmation provided upon request.
7. Activity History (Audit Trail)
Under the activity history (audit trail) architecture, the customer acts as the data controller and AuditCV acts as the data processor. Logs are maintained for information security, accountability, internal auditing, abuse prevention, and evidencing GDPR and KVKK consent and erasure compliance.
Scope of records: user first name, last name, and role; operation type, summary, and record name; prior and updated values (including email and phone numbers as entered); deletion reason; IP address, coarse device/browser telemetry, and country; read logs for reports, PDFs, candidate/request listings, and history; login and explicit logout events (session timeout expiration is not recorded), failed login attempts (email tracked solely as a login event tag), and unauthorized access attempts.
General audit logs are retained for up to 12 months, and read logs are retained for 6 months, after which they are automatically purged. In-app feedback messages are retained for 24 months.
Company administrators may inspect records belonging to their own organization; granular diffs of prior/updated values, read logs, and IP/device metadata are allocated to paid plans (Pro and Enterprise tiers are upcoming, with the Free plan currently active). Support impersonation sessions display duration and reason to the company; platform system events are restricted to platform administrators.
Upon statutory erasure requests, personal data of candidates and referees is redacted from historical logs (retaining only name initials); personal data should not be entered into free-text reason fields.
8. Contact Us
To request an executed DPA tailored to your organization, please reach out to our enterprise sales team via the contact form.