Data Processing Agreement (DPA)
Last updated: 7 July 2026
This document is currently available in English only. The English version is the authoritative version.
pursuant to Article 28(3) GDPR
This Data Processing Agreement (the "DPA") supplements and forms part of the agreement between the parties consisting of the Order Form and the Terms of Service (the "Main Agreement") and sets out the parties' obligations under applicable data protection law in relation to the products contracted under the Main Agreement: LeadFlow, GrowthEngine and/or PlacementEngine.
between
Growthlynk Management FZCO, Dubai Digital Park, Dubai, United Arab Emirates, trading as "Hiring Intelligence" (the "Processor" or "HI")
and
the customer identified in the Order Form / Annex I (the "Controller" or "Customer")
(each a "Party", together the "Parties").
This DPA is concluded by acceptance of the Main Agreement; no separate signature is required (Art. 28(9) GDPR — electronic form).
1. Subject Matter, Roles and Scope
1.1 The Processor processes personal data on behalf of the Controller solely to the extent that, in providing the contracted products under the Main Agreement, it processes data on the Controller's behalf. The processing activities per product are described in Annex II. This DPA applies to each product only insofar as that product is contracted under the Main Agreement.
1.2 Delimitation / Processor acting as independent controller. The Processor's own generation, sourcing and enrichment of leads and profiles — including the use of its own sources and third-party enrichment providers — is carried out by the Processor as an independent controller within the meaning of the GDPR, on its own legal basis, and is not subject to this DPA. The handover of a finished lead or profile to the Controller occurs on a controller-to-controller basis and does not constitute processing on the Controller's behalf. Processing under this DPA is confined to the activities described in Annex II.
1.3 Determination of purposes and means. For all processing under this DPA, the Controller determines the purposes and essential means of processing; the Processor provides the technical infrastructure and executes the processing on the Controller's documented instructions. The Processor has no own interest in the personal data processed on the Controller's behalf.
1.4 Eligibility criteria. Any relevance or eligibility criteria agreed jointly with the Controller (including any job-eligibility filter applied across LeadFlow and GrowthEngine) constitute a specification of the Controller's instructions solely for the processing described in Annex II. Insofar as such criteria also influence the Processor's own independent sourcing activity (clause 1.2), they are mere product configuration of that independent activity — not instructions. They do not constitute joint processing of, or joint decision-making over, individual data subjects.
1.5 The Controller is responsible for the lawfulness of the processing under this DPA and warrants that it has a valid legal basis for the processing it instructs, including for any outreach it conducts.
2. Instructions
2.1 The Processor processes personal data only on the Controller's documented instructions, unless required to process by applicable law; in that case it informs the Controller before processing, unless the law prohibits this.
2.2 The processing described in Annex II constitutes the Controller's documented instructions. Further instructions are given in writing or text form and shall be documented.
2.3 The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
3. Confidentiality
The Processor grants access to personal data only to persons who need it to perform the Main Agreement, and ensures that such persons are bound by confidentiality or an appropriate statutory duty of confidentiality.
4. Security of Processing
The Processor implements the technical and organisational measures (TOMs) required under Article 32 GDPR, as set out in Annex III. Measures may be updated to reflect the state of the art, provided the level of protection is not reduced.
5. Sub-processors
5.1 The Controller grants the Processor general authorisation to engage the sub-processors listed in Annex IV. The current list is also published at hiring-intelligence.io/legal/subprocessors.
5.2 The Processor informs the Controller at least four (4) weeks in advance of any intended change to that list (addition or replacement) in text form, giving the Controller the opportunity to object on reasonable data protection grounds.
5.3 The Processor imposes on each sub-processor, by contract, substantially the same data protection obligations as set out in this DPA, and remains fully liable to the Controller for the sub-processor's compliance.
6. Assistance to the Controller
6.1 Taking into account the nature of the processing, the Processor reasonably assists the Controller in responding to data subjects exercising their rights (Articles 12–23 GDPR).
6.2 The Processor further assists the Controller in complying with Articles 32 to 36 GDPR (security, personal data breach notification, data protection impact assessment), to the extent necessary and proportionate.
6.3 Where the Processor becomes aware of a personal data breach relating to data processed under this DPA, it notifies the Controller without undue delay.
7. Data Subject Requests and Opt-out
7.1 Where a data subject addresses a request directly to the Processor concerning data processed on the Controller's behalf, the Processor forwards it to the Controller without undue delay and does not respond itself unless instructed to do so.
7.2 Where a request — in particular an objection, opt-out or erasure request — concerns data that the Processor generated or enriched as an independent controller under clause 1.2, the Controller shall forward any such request it receives to the Processor without undue delay, so that the Processor can suppress the data subject in its systems.
8. Deletion and Return
8.1 Where the Processor processes Controller system data only transiently (in particular the LeadFlow deduplication match), it does not store such data persistently beyond the minimal match-result data described in Annex II.A; transiently processed data is discarded immediately after the operation.
8.2 On termination of the processing, the Processor, at the Controller's choice, deletes or returns all personal data processed on the Controller's behalf and certifies deletion in text form, unless a statutory retention obligation applies. If the Controller does not communicate a choice within thirty (30) days of the termination date, the Processor deletes. Data held within a Customer workspace (GrowthEngine), including reply data stored in the Processor's database, is deleted upon termination or on the Controller's instruction. The delivery log (the record of which data records were provided to the Controller) is maintained by the Processor as its own controller-side accountability record (clause 1.2; Art. 19 GDPR notification duty, billing and defence of legal claims) and is not subject to this clause 8.2.
9. Records and Audits
On request, the Processor makes available the information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits — including inspections — conducted by the Controller or an auditor mandated by it, at reasonable intervals and with reasonable prior notice.
10. International Data Transfers (Third Country)
10.1 The Processor is established in the United Arab Emirates. To the extent that the processing involves a transfer of personal data to a third country without an adequacy decision, the Parties enter into the EU Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), as completed in the SCC Schedule attached to this DPA and incorporated by reference. The SCC Schedule forms an integral part of this DPA.
10.2 The Processor implements supplementary measures, in particular EU-hosted infrastructure where possible (primary database hosted in the EU) and encryption as set out in Annex III. Any onward transfer by a sub-processor takes place only on the basis of an appropriate transfer mechanism under Chapter V GDPR.
10.3 The Processor has appointed an EU representative pursuant to Article 27 GDPR, as identified in Annex I.
11. Liability, Precedence and Final Provisions
11.1 Liability is governed by the Main Agreement; mandatory requirements of the GDPR remain unaffected.
11.2 In the event of a conflict, this DPA and the incorporated Standard Contractual Clauses prevail on data protection matters. The law governing the data protection provisions and the SCCs shall be the law of an EU Member State as specified in the SCC Schedule, notwithstanding the language of this DPA or the governing law of the Main Agreement.
11.3 Should individual provisions be invalid, the validity of the remaining provisions is unaffected. Amendments require text form.
Annex I — List of Parties
Controller — as identified in the Order Form:
| Field | Entry |
|---|---|
| Company / Name | per Order Form |
| Address | per Order Form |
| Contact / person authorised to give instructions | per Order Form |
| Data protection officer (if appointed) | per Order Form |
| Contracted product(s) | per Order Form: LeadFlow / GrowthEngine / PlacementEngine |
Processor:
| Field | Entry |
|---|---|
| Company / Name | Growthlynk Management FZCO (Hiring Intelligence) |
| Address | Dubai Digital Park, Dubai, United Arab Emirates |
| Contact / recipient of instructions | Philipp Käming, [email protected] |
| EU representative (Art. 27 GDPR) | Euverify Ltd (Ireland), company no. 781168, Unit 3D, North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland — [email protected] (appointed 2 July 2026) |
Annex II — Description of the Processing (per product)
Only the sections for contracted products apply. The Processor's own sourcing and enrichment (clause 1.2) is excluded from all sections below.
II.A LeadFlow — lead delivery and deduplication
| Data subjects | Contacts/leads stored in the Controller's target system against which matching occurs, and the leads delivered by the Processor. |
| Categories of data | Identity data (name), contact data (e.g. email, phone), professional data, and a status/deduplication attribute. |
| Special categories | None. |
| Nature of processing | Transient, ephemeral matching of individual records for deduplication and deliverability-status determination; delivery of leads into the Controller's CRM/target system (via webhook, spreadsheet or CRM integration). No persistent storage of the Controller's system data; retained per record are only a minimal match result (status flag and timestamp) and — for ambiguous matches — a minimal reference to the candidate records concerned (name, CRM link, status label) until the match is manually resolved, at the latest 30 days after flagging. |
| Purpose | Deduplication, determination of deliverability, and data delivery. |
| Duration | Term of the Main Agreement; retrieved system data discarded immediately after each match. |
II.B GrowthEngine — email outreach on the Controller's behalf
| Data subjects | Recipients of the Controller's outreach campaigns; persons who reply. |
| Categories of data | Recipient contact data (name, email), email content and replies, engagement, delivery and tracking data; business phone numbers researched for recipients who reply with interest (qualified replies). |
| Special categories | Not intended. Replies are unstructured and may contain data voluntarily provided by respondents, potentially including special categories; access is restricted accordingly. |
| Nature of processing | Sending email campaigns in the Controller's name and on its behalf, using the Controller's own sending domains and sender identity, within an isolated workspace assigned to the Controller in the Processor's email-sending entity; reply handling and automated reply classification, and — for qualified replies — business-contact (phone) research (in each case via the sub-processors listed in Annex IV); storage of campaign, reply and engagement data in the Processor's EU-hosted database for the duration of the service; delivery and open/click tracking; optional sync of qualified replies into the Controller's CRM or spreadsheet. |
| Purpose | Execution of the Controller's outreach campaigns on its documented instructions. |
| Duration | Term of the Main Agreement. |
Controller responsibilities (GrowthEngine): the Controller determines the recipients and campaign and is responsible for the legal basis of the outreach (including applicable unfair-competition/anti-spam rules such as § 7 UWG and the GDPR) and for any consent required for tracking under ePrivacy rules. The Processor provides the infrastructure and executes on instructions.
II.C PlacementEngine — candidate–job matching
This section applies only insofar as the processed data constitutes personal data. Where the Processor sources candidate data on its own account, that sourcing is the Processor's independent-controller activity (clause 1.2) and is out of scope; only the matching/processing on the Controller's behalf is covered here.
| Data subjects | Candidates whose profiles are matched to job opportunities. |
| Categories of data | Candidate profile data: identity/contact data where present, qualifications, career/experience data, availability/status. |
| Special categories | Not intended. Candidate data (e.g. CV content) may reveal or approach special categories; strict purpose limitation and access restriction apply given the heightened sensitivity of candidate data. |
| Nature of processing | Processing of candidate data provided by or on behalf of the Controller for the purpose of matching candidates to job opportunities and facilitating outreach on the Controller's behalf. |
| Purpose | Recruiter-to-job matching / placement facilitation on the Controller's documented instructions. |
| Duration | Term of the Main Agreement. |
Annex III — Technical and Organisational Measures (TOMs)
Confidentiality & Access Control
- Access to production systems on a need-to-know basis; individual accounts, no shared logins; multi-factor authentication on all administrative accounts (database, hosting, task infrastructure, email-sending entity).
- Centralised credential management via a password manager (1Password); credentials are never stored in code or documents; revocation on offboarding.
Multi-tenant Isolation (GrowthEngine)
- Each Customer is confined to its own assigned, isolated workspace in the email-sending entity; entity-level access by the Processor is need-to-know only.
- No cross-workspace merging of data or suppression lists between Customers.
- Customer-specific suppression is maintained per workspace; the Processor's own sourcing-level suppression is maintained separately, with no bleed between Customers.
Integrity & Confidentiality of Data
- Encryption in transit (TLS 1.2+) for all connections; encryption at rest for the primary database (managed PostgreSQL, EU region).
- LeadFlow deduplication: the Controller's system data is processed transiently in memory and discarded after the match; only a minimal per-record match result is persisted (plus, for ambiguous matches, a minimal candidate reference for manual resolution — deleted upon resolution, at the latest 30 days after flagging); payload/response logging for the matching step is disabled in the task infrastructure — task logs contain only counters, record IDs and status values.
- Access to the Controller's CRM occurs exclusively via Controller-provided API credentials, scoped to the integration.
Candidate Data (PlacementEngine)
- Strict purpose limitation to matching; access restricted to personnel involved in matching; no use beyond the agreed purpose.
Availability & Accountability
- Operation on established cloud infrastructure with the providers' contractually assured security measures; primary database EU-hosted (AWS eu-west-1 via Supabase); task execution on US compute (AWS us-east-1 via API Hero Ltd) is transient, with no persistent storage on the task infrastructure, and covered by SCCs.
- Logging of security-relevant access; regular review of access rights and effectiveness of measures.
Annex IV — Sub-processors
Only services that technically process personal data on the Controller's behalf. Current version also published at hiring-intelligence.io/legal/subprocessors.
| Company | Location / Region | Service (products) |
|---|---|---|
| Supabase Inc. | USA (parent); database hosted in the EU (AWS eu-west-1, Ireland) | Primary database: GrowthEngine workspace data incl. reply data; LeadFlow match-result flags incl. minimal ambiguous-match references; PlacementEngine matching data |
| API Hero Ltd (trading as Trigger.dev), UK — company no. 14441978 | Cloud hosted on AWS us-east-1 (USA); SCCs with sub-processors | Execution of processing tasks (LeadFlow matching and delivery; GrowthEngine send/reply pipeline; PlacementEngine matching) — transient; persistent data remains in the EU-hosted database |
| Vercel Inc. | USA (parent); compute pinned to EU region (Dublin, dub1) — both client portal and operations dashboard | Application hosting for dashboards and client portal |
| EmailBison, 3080 Yonge Street, Suite 6060, Toronto, Ontario M4N 3N1, Canada | Canada | Email-sending infrastructure, isolated per-Customer workspace (GrowthEngine) |
| OpenAI, L.L.C. | USA — API terms: no training on API data; retention limited to abuse monitoring (max. 30 days); no zero-data-retention addendum (standard API tier) | Automated reply classification and reply-content extraction (GrowthEngine reply handling) |
| Perplexity AI, Inc. | USA — API terms: no training on API data | AI-assisted business-contact research (phone numbers) for qualified replies (GrowthEngine reply handling) |
| Hackeez Consulting SAS (trading as BetterContact), Lyon, France — RCS Lyon 882 799 372 | France (EU); engages its own vetted data providers under its DPA | Licensed contact-data enrichment (phone numbers) for qualified replies (GrowthEngine reply handling) |
Not sub-processors:
- The enrichment providers and data sources used in the Processor's own sourcing/enrichment are engaged in the Processor's independent-controller activity (clause 1.2) and are, in that role, not part of the processing on the Controller's behalf. Where the same provider is additionally used within a Service on the Controller's behalf (e.g. BetterContact and Perplexity for reply phone research in GrowthEngine), it is listed above as a sub-processor for that Service.
- Tools owned and controlled by the Controller (e.g. the Controller's own CRM instance such as Close, or the Controller-owned Google Sheets used for spreadsheet delivery and reply sync) are the Controller's own recipients/processors, even where the Processor pushes data into them on instruction.
SCC Schedule
The completed Standard Contractual Clauses (Module Two) are set out in the separate SCC Schedule document, which forms part of this DPA.
Signatures (required only where a Party requests wet-ink or qualified electronic signature; otherwise concluded per the Main Agreement)
| Controller (Customer) | Processor (Hiring Intelligence) |
|---|---|
| Place, date, signature | Place, date, signature |
SCC Schedule to the Data Processing Agreement
Standard Contractual Clauses — Module Two (Controller to Processor)
Commission Implementing Decision (EU) 2021/914 of 4 June 2021
For execution, the full official text of the SCCs (Module Two) is attached to / incorporated into the DPA together with the selections and Annexes below. Official text: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
1. Incorporation and Module Selection
The Parties agree to be bound by the Standard Contractual Clauses (EU) 2021/914, Module Two (transfer controller to processor), with the data exporter being the Customer (Controller) and the data importer being Growthlynk Management FZCO (Processor). The SCCs prevail over the DPA and the Main Agreement in case of conflict (Clause 5 SCCs).
2. Selections and Options
| Clause | Selection |
|---|---|
| Clause 7 (Docking clause) | Included. |
| Clause 9(a) (Use of sub-processors) | Option 2 — general written authorisation. List: Annex III of this Schedule (= Annex IV DPA). Notice period for changes: 4 weeks (aligned with clause 5.2 DPA). |
| Clause 11(a) (Redress — independent dispute resolution body) | Optional wording not included. |
| Clause 13 / Annex I.C (Supervisory authority) | The supervisory authority of the EU Member State in which the data exporter is established (for exporters subject to Art. 3(2) GDPR: the authority of the Member State of their EU representative). |
| Clause 17 (Governing law) | Option 1: law of an EU Member State allowing third-party beneficiary rights — the law of Germany. |
| Clause 18(b) (Forum) | Courts of Germany. |
Annex I
A. List of Parties
Data exporter:
| Field | Entry |
|---|---|
| Name / address / contact | The Customer, as identified in the Order Form |
| Activities relevant to the transfer | Use of the contracted products (LeadFlow / GrowthEngine / PlacementEngine) as Controller |
| Role | Controller |
Data importer:
| Field | Entry |
|---|---|
| Name | Growthlynk Management FZCO (trading as Hiring Intelligence) |
| Address | Dubai Digital Park, Dubai, United Arab Emirates |
| Contact | Philipp Käming, [email protected] |
| Activities relevant to the transfer | Provision of the contracted products on the Controller's documented instructions |
| Role | Processor |
B. Description of Transfer
| Field | Entry |
|---|---|
| Categories of data subjects | Per Annex II DPA for the contracted product(s): contacts/leads in the Controller's target system; recipients of and respondents to the Controller's outreach campaigns; candidates. |
| Categories of personal data | Per Annex II DPA: identity and business contact data, professional data, deduplication/status attributes, email content and replies, engagement/delivery/tracking data, candidate profile data. |
| Sensitive data | Not intended. Unstructured replies and candidate documents may incidentally contain such data; access restriction and purpose limitation per Annex II TOMs apply. |
| Frequency of the transfer | Continuous, for the duration of the Main Agreement. |
| Nature of the processing | See Annex II DPA (matching/deduplication, delivery, outreach execution, reply handling, candidate–job matching). |
| Purpose(s) | Provision of the contracted products on documented instructions. |
| Retention period | Term of the Main Agreement; deletion per clause 8 DPA. Transient matching data: immediate discard. |
| Transfers to sub-processors | Per Annex III of this Schedule; same subject matter and duration. |
C. Competent Supervisory Authority
The authority determined per Clause 13 (see Selections table above); to be named per Customer in the Order Form where required.
Annex II — Technical and Organisational Measures
The technical and organisational measures set out in Annex III of the DPA apply and are incorporated here by reference. Supplementary measures for the third-country transfer: EU-hosted primary database (AWS eu-west-1), TLS-encrypted transport, at-rest encryption, need-to-know access with MFA, minimal persistence for LeadFlow matching (transient in-memory processing, payload logging disabled), per-Customer workspace isolation for GrowthEngine.
Annex III — List of Sub-processors
The sub-processor list in Annex IV of the DPA applies (also published at hiring-intelligence.io/legal/subprocessors). Authorisation model: general written authorisation with 4-week advance notice of changes.
Transfer Impact Assessment: documented separately (internal document "TIA — UAE"), available to the exporter on request per Clause 14(c) SCCs.