Draft notice. This consolidated Data Processing Agreement is a draft published for transparency and is undergoing professional legal review. Until that review is complete, the operative data-processing terms between Scovai and each Tenant remain Section 6 of the Recruiter Terms of Service. This draft restates those commitments in the standard structure of Article 28(3) GDPR; it does not add new obligations and does not remove existing ones.
This Data Processing Agreement ("DPA") forms part of the agreement between OmniSage LLC, operating the Scovai platform ("Scovai", "Processor", "we", "us"), and the organisation using the Scovai platform for recruitment and talent management purposes ("Tenant", "Controller", "you"). It governs the processing of personal data of Candidates carried out by Scovai on the Tenant's behalf, as required by Article 28 of Regulation (EU) 2016/679 ("GDPR"). Capitalised terms not defined here have the meaning given in the Recruiter Terms of Service ("Terms").
1. Parties and Roles
- The Tenant is the Data Controller: you determine the purposes and means of processing Candidate personal data for your recruitment and talent management activities, including which candidates to assess, what data to collect, and what legal basis applies.
- OmniSage LLC is the Data Processor: we process Candidate personal data only on your behalf and on your documented instructions, for the purpose of providing the Scovai platform as described in the Terms.
For data relating to our own website visitors, direct applicants to our talent pool, and account holders, Scovai acts as an independent data controller; that processing is governed by our Privacy Policy and is outside the scope of this DPA.
2. Subject Matter, Duration, Nature and Purpose of Processing
- Subject matter: the provision of the Scovai platform: position creation and publishing, CV parsing and semantic matching, candidate screening and shortlisting, technical, psychometric and cognitive assessments, AI-conducted and live interviews, analytics, and talent pipeline management.
- Duration: the term of the Tenant's subscription, plus the post-termination retention window described in Section 10 of this DPA.
- Nature: collection, recording, organisation, structuring, storage, analysis (including AI-assisted parsing, scoring, matching, assessment and interview evaluation), retrieval, disclosure to the Controller and its authorised users, restriction, and erasure.
- Purpose: solely the provision of the Service as described in the Terms. We will not process Candidate personal data for any other purpose without the Controller's prior written consent.
3. Categories of Data Subjects and Personal Data
Data subjects: Candidates, meaning individuals whose data is processed through the platform for the Tenant's recruitment purposes, whether sourced directly, via applications, or through the CV Bank.
Categories of personal data:
- Identification and contact data: name, email address, phone number, location
- CV and career data: work experience, education, skills, certifications, languages, extracted through AI-assisted CV parsing
- Assessment data: technical assessment responses, psychometric assessment results, cognitive assessment results
- Interview data: interview transcripts, responses, recordings where the Controller enables them, and generated evaluation reports
- Scoring data: AI-generated scores across multiple dimensions, with explainability rationales
- Embedding data: vector representations of CV content used for semantic matching (not human-readable)
- Platform activity data: application status, consent records, and audit trail entries relating to the Candidate
Special categories of data (Article 9 GDPR) are processed only where the Controller chooses to collect them through its own configuration of the platform. The Controller is responsible for ensuring a lawful basis for any such collection.
4. Processor Obligations
Scovai will:
- process Candidate personal data only on the Controller's documented instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law; in that case, we will inform the Controller of that legal requirement before processing, unless the law prohibits it;
- ensure that persons authorised to process Candidate personal data are bound by confidentiality obligations;
- not use Candidate personal data for marketing purposes, not sell or license it to third parties, and not use individual Candidate data to train or fine-tune AI models;
- assist the Controller as described in Sections 8 and 9 of this DPA;
- delete or return personal data at the end of the provision of services as described in Section 10;
- make available the information necessary to demonstrate compliance as described in Section 11;
- inform the Controller immediately if, in our opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
5. Security Measures (Article 32 GDPR)
Scovai implements appropriate technical and organisational measures to protect Candidate personal data, including:
- TLS encryption (TLS 1.2/1.3) for all data in transit
- AES-256-CBC encryption of API keys and sensitive credentials at rest
- Argon2 password hashing
- JWT-based authentication with access and refresh tokens
- Role-based access control (RBAC) with logical isolation of each Tenant's data
- Comprehensive audit logging of platform actions, accessible to the Controller through the platform audit trail
- Pseudonymised vector embeddings for semantic matching that are not human-readable and cannot be reversed to reconstruct the original CV text
- Regular security assessments
Candidate personal data is stored on our own servers within the European Economic Area (see Section 7). Details of our data-protection-by-design measures are described in our GDPR Policy.
6. Sub-Processing
The Controller grants Scovai a general authorisation to engage the sub-processors listed below. Scovai imposes on each sub-processor data-protection obligations materially equivalent to those in this DPA, and remains liable to the Controller for the performance of each sub-processor's obligations.
| Sub-processor | Purpose | Safeguards |
|---|---|---|
| Anthropic (Claude API) | CV parsing, candidate-position scoring, assessment and interview analysis, identity-document verification | Data-processing agreement; routed through a centrally configured, audited gateway; API data is not used to train provider models |
| OpenAI (API) | Speech-to-text and text-to-speech for voice interviews, text embeddings | Data-processing agreement; routed through the same centrally configured, audited gateway; API data is not used to train provider models |
| Infrastructure providers | Application hosting and database storage | Located within the European Economic Area |
| Stripe | Billing and subscription management | Processes the Tenant's payment data, not Candidate personal data |
| Email delivery (SMTP) | Transactional email notifications | Processes email addresses and notification content necessary for delivery |
AI Agent execution. Where the Service includes AI agents engaged through the Scovai marketplace, agent execution is performed by OmniSage LLC itself as an internal service function, not by a separate legal person or Marketplace Vendor; it therefore does not add a sub-processor. It remains subject to this DPA and to the processing-location, security, and transfer safeguards stated here. Any future delegation to a separate legal person or external provider will be treated as a new sub-processor, notified in advance, and governed by Article 28 GDPR and, where applicable, Chapter V GDPR.
Changes to sub-processors. We will notify the Controller in advance before engaging a new sub-processor that handles Candidate personal data, giving the Controller the opportunity to object within 15 days of the notice. If an objection cannot be resolved, the Controller may suspend or terminate the affected part of the Service in accordance with the Terms. The current sub-processor list is available on request at privacy@scovai.com.
7. International Data Transfers
Candidate personal data is stored on our own servers within the European Economic Area. Where a sub-processor processes personal data outside the EEA, the transfer relies on Standard Contractual Clauses and equivalent safeguards under Chapter V GDPR. Material changes to transfer mechanisms are notified in advance.
8. Assistance with Data Subject Rights
Taking into account the nature of the processing, Scovai assists the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to data subject requests under Articles 12 to 23 GDPR:
- Access and rectification: Candidates can view and edit their profile data directly; the Controller can export Candidate data via the compliance module.
- Erasure and restriction: data deletion requests and per-candidate processing restrictions can be initiated through the compliance module, with full audit logging.
- Portability: data can be exported in structured JSON format via the compliance module or API.
- Automated decision-making: human review requests can be submitted for any AI-generated assessment or score, and every AI-generated score includes an explainability rationale to support Article 22 safeguards.
If a Candidate contacts Scovai directly with a data subject request concerning processing carried out on the Controller's behalf, we will forward the request to the Controller without undue delay and execute the Controller's resulting instructions.
9. Personal Data Breach Notification
In the event of a personal data breach affecting Candidate personal data, Scovai will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach, providing the information necessary for the Controller to fulfil its own notification obligations under Articles 33 and 34 GDPR, including the nature of the breach, the categories of data affected, the likely consequences, and the measures taken or proposed to address it. Breaches are documented in an internal breach register.
10. Return and Deletion of Personal Data
Upon termination of the Tenant's subscription, workspace data is retained for 90 days to allow the Controller to export it. After this period, Candidate personal data processed on the Controller's behalf is deleted or anonymised, except where retention is required by law. Interview recordings and transcripts are purged automatically once they exceed their configured retention window. Written confirmation of deletion is available on request.
11. Audit and Demonstration of Compliance
Scovai makes available to the Controller the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, on a documentation-first basis: technical documentation, relevant logs, and access to technical contacts. In addition, the Controller may conduct audits or inspections under Article 28(3)(h) GDPR, provided that they:
- are requested in writing at least 15 days in advance;
- take place during normal business hours;
- do not exceed one audit per calendar year, unless required following a personal data breach or by a supervisory authority;
- are conducted by auditors bound by confidentiality obligations;
- do not include destructive testing, load testing, or security scanning without prior written approval.
12. Liability
The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Recruiter Terms of Service. Nothing in this DPA limits any liability that cannot be limited under applicable law, or affects the rights that data subjects hold directly under the GDPR.
13. Final Provisions
- Precedence: in the event of a conflict between this DPA and the Terms with respect to the processing of Candidate personal data, this DPA prevails.
- Third parties: this DPA does not create third-party beneficiary rights; Candidates retain the rights granted to them directly by the GDPR.
- Governing law: this DPA is governed by the law applicable to the Terms; where the Controller is established in the European Union, the mandatory provisions of EU law, including the GDPR, apply.
- Contact: privacy@scovai.com for any question about this DPA or our data-processing commitments.