Data Processing Agreement
Last updated: 20 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms & Conditionsbetween you (the "Customer") and SD IT Support Ltd("Processor", "we") and applies where we process personal data on your behalf in providing the Resume Vetting service. It reflects Article 28 of the UK GDPR.
1. Roles of the parties
The Customer is the controller of candidate personal data submitted to the Service. We are the processor, acting only on the Customer's documented instructions. The Customer is responsible for having a lawful basis and appropriate authority for that processing.
2. Definitions
"UK GDPR", "personal data", "processing", "data subject", "controller", "processor", and "personal data breach" have the meanings given in the UK GDPR and the Data Protection Act 2018.
3. Subject matter and details of processing (Annex 1)
- Subject matter: AI-assisted screening of candidate CVs against a job description.
- Duration: for the term of the Customer's use of the Service; candidate data is processed transiently per request and not retained.
- Nature and purpose: transient analysis of CV and job-description text to generate screening assessments, candidate ranking, AI-generated summaries, and skills/suitability assessments.
- Types of personal data: the personal data contained in CVs submitted by the Customer (e.g. name, contact details, employment history, education, and any other content the Customer chooses to include).
- Categories of data subjects: the Customer's job applicants and candidates.
The Customer must not submit special category data unless it has a valid Article 9 condition; we ask that CVs be limited to information relevant to the role.
4. Our obligations as processor
We will:
- process personal data only on the Customer's documented instructions (including those given through normal use of the Service), unless required by law;
- ensure personnel authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational security measures (Annex 2);
- engage subprocessors only as set out in section 6;
- taking into account the nature of processing, assist the Customer with data subject requests and with its obligations on security, breach notification, and data protection impact assessments; and
- at the Customer's choice, delete or return personal data after the end of the services (section 8).
5. Security measures (Annex 2)
- encryption of data in transit (HTTPS/TLS);
- secure authentication and password hashing;
- database access controls and row-level security so accounts access only their own data;
- secrets held only in server-side environment variables, never exposed to the browser;
- no CV files or extracted text persisted to storage or written to logs; and
- data minimisation by design — candidate data is processed in memory and discarded after each request.
6. Subprocessors (Annex 3)
The Customer authorises us to engage the following subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| OpenAI | AI analysis of job description and CV text submitted for screening (transient; not used to train models under our API configuration). | United States |
| Supabase | Authentication and database for accounts, billing records, and saved job descriptions. No CV files or candidate results are stored. | European Union / United Kingdom (region-dependent) |
| Vercel | Application hosting and privacy-friendly, cookieless usage analytics. | United States / global edge network |
| Stripe | Payment processing for one-time credit purchases. We never receive your full card details. | United States / United Kingdom |
We will impose data protection obligations on each subprocessor no less protective than those in this DPA, and will give the Customer reasonable notice of any intended change of subprocessor so the Customer may object.
7. International transfers
Where a subprocessor processes personal data outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, or an adequacy decision where one applies.
8. Data subject requests
Because candidate data is not retained after processing, we hold no candidate records to retrieve. We will nonetheless provide reasonable assistance to enable the Customer to respond to data subject requests it receives.
9. Personal data breach
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and provide information reasonably required to meet the Customer's breach-notification obligations.
10. Deletion and return
Candidate CV files, extracted text, and results are not retained, so there is nothing to return or delete at the end of a screening. For stored data we hold as processor (such as saved job descriptions), the Customer may request deletion, and we will delete it on termination unless retention is required by law.
11. Audit
We will make available information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, subject to reasonable confidentiality and security conditions.
12. Liability and governing law
Liability under this DPA is subject to the limitations in the Terms & Conditions. This DPA is governed by the laws of England and Wales.
13. Contact
Data protection queries: privacy@sd-support.com (SD IT Support Ltd).