AuditCV
Back to Home
🤝 DATA PROCESSING AGREEMENT

Data Processing Agreement (DPA)

Last updated: October 4, 2026
Legal NoticeThis English translation is provided for informational purposes only. The original Turkish version is legally binding.

For our enterprise customers, AuditCV.io provides an executed Data Processing Agreement (DPA) governing the obligations between the data controller (your company) and the data processor (AuditCV.io). Below is an overview and standard clauses; contact our sales team to request an executed copy.

AuditCV.io acts as a data processor under enterprise customer contracts; your organization acts as the data controller.
Scope of processed data is contractually restricted: candidate and referee contact information and evaluation responses.
Sub-processors (hosting and transactional email infrastructure providers) are explicitly listed in the agreement and bound by equivalent data protection terms.
Upon contract termination, all processed data is returned or permanently deleted per your instructions.
Processor obligations under GDPR Article 28 and KVKK (technical security, breach notification, audit rights) are fully incorporated.

Looking for an executed DPA? As part of our Enterprise plans, you can request a company-tailored, executed DPA directly from our sales team.

View Full Text
1. Parties & Roles

Under this DPA, your organization acts as the "Data Controller", and AuditCV.io acts as the "Data Processor" processing reference verification data on your behalf.

2. Scope & Duration of Processing

Processing is strictly confined to the duration of the service contract and the purpose of conducting reference checks: candidate and referee full names, contact coordinates, and evaluation responses.

3. Sub-processors

Hosting, database, and transactional email infrastructure providers utilized to deliver the service are listed in the DPA annex. Customers are notified prior to engaging new sub-processors.

4. Security Measures

Data is encrypted in transit using TLS/HTTPS, access is governed by strict authorization, and data breaches will be reported to the customer without undue delay.

5. Audit Rights

Enterprise customers possess the right to inspect our data processing compliance or request relevant security audit certifications subject to reasonable notice.

6. Term & Termination

Upon termination of the service agreement, all processed data is returned or permanently destroyed in accordance with customer instructions, with written confirmation provided upon request.

7. Activity History (Audit Trail)

Under the activity history (audit trail) architecture, the customer acts as the data controller and AuditCV acts as the data processor. Logs are maintained for information security, accountability, internal auditing, abuse prevention, and evidencing GDPR and KVKK consent and erasure compliance.

Scope of records: user first name, last name, and role; operation type, summary, and record name; prior and updated values (including email and phone numbers as entered); deletion reason; IP address, coarse device/browser telemetry, and country; read logs for reports, PDFs, candidate/request listings, and history; login and explicit logout events (session timeout expiration is not recorded), failed login attempts (email tracked solely as a login event tag), and unauthorized access attempts.

General audit logs are retained for up to 12 months, and read logs are retained for 6 months, after which they are automatically purged. In-app feedback messages are retained for 24 months.

Company administrators may inspect records belonging to their own organization; granular diffs of prior/updated values, read logs, and IP/device metadata are allocated to paid plans (Pro and Enterprise tiers are upcoming, with the Free plan currently active). Support impersonation sessions display duration and reason to the company; platform system events are restricted to platform administrators.

Upon statutory erasure requests, personal data of candidates and referees is redacted from historical logs (retaining only name initials); personal data should not be entered into free-text reason fields.

8. Contact Us

To request an executed DPA tailored to your organization, please reach out to our enterprise sales team via the contact form.