Data Processing Agreement
Last updated: TODO_FILL
This agreement applies where TODO_FILL, registered at TODO_FILL (the "Processor"), processes personal data on behalf of a customer (the "Controller") in connection with the Evolyxis service. It forms part of, and is subject to, the Terms of Service.
1. Subject matter and duration
The Processor processes personal data solely to provide the Evolyxis service, for the duration of the subscription and for any agreed export or deletion period after it ends.
2. Nature and purpose of processing
Submitting screening questions and associated candidate information to a panel of independent AI models, recording each model's response, flagging divergence, routing held decisions to a human reviewer, and storing the resulting decision record for audit.
3. Categories of data and data subjects
- Data subjects: job applicants and candidates screened by the Controller, and the Controller's own users and reviewers.
- Personal data: identity and contact details, CV and application content, screening criteria and outcomes, reviewer identity and actions, and account and log data.
The Controller must not submit special category data unless it has separately agreed the basis for doing so in writing.
4. Processor obligations
- process personal data only on documented instructions from the Controller;
- ensure personnel with access are bound by confidentiality;
- implement appropriate technical and organisational security measures;
- assist the Controller with data subject requests, data protection impact assessments and regulator engagement, taking into account the nature of processing;
- notify the Controller without undue delay after becoming aware of a personal data breach;
- delete or return personal data at the end of the agreement, except where retention is required by law.
5. Sub-processors
The Controller authorises the use of sub-processors, including cloud hosting providers, Supabase for authentication and account storage, and the independent AI model providers that make up the panel. Each sub-processor is bound by written terms no less protective than this agreement. We maintain a current sub-processor list and will give notice of intended changes so the Controller can object.
6. International transfers
Where personal data is transferred outside the UK or EEA, the transfer is made under the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, together with any supplementary measures reasonably required.
7. Security
Measures include encryption in transit, access control and least-privilege access to production systems, logging of administrative actions, and segregation of customer data. The Processor holds no third-party security certification at this time and does not represent otherwise.
8. Audit
On reasonable written notice and no more than once a year, the Processor will make available the information necessary to demonstrate compliance with this agreement, and will co-operate with an audit conducted by the Controller or an independent auditor appointed by it, subject to confidentiality.
9. Retention and deletion
Decision records exist to be an audit trail and are retained for the period agreed in the order form. On termination, records are made available for export before deletion. We do not represent that data transmitted to third-party model providers is subject to zero retention; their retention behaviour is described on request.
10. Contact
To request the sub-processor list, a signed copy of this agreement, or to raise a data protection matter, write to our contact address.