Back to overview

Data Processing Agreement (DPA)

Last updated: 7 July 2026

Available in English only

This document is currently available in English only. The English version is the authoritative version.

pursuant to Article 28(3) GDPR

This Data Processing Agreement (the "DPA") supplements and forms part of the agreement between the parties consisting of the Order Form and the Terms of Service (the "Main Agreement") and sets out the parties' obligations under applicable data protection law in relation to the products contracted under the Main Agreement: LeadFlow, GrowthEngine and/or PlacementEngine.

between

Growthlynk Management FZCO, Dubai Digital Park, Dubai, United Arab Emirates, trading as "Hiring Intelligence" (the "Processor" or "HI")

and

the customer identified in the Order Form / Annex I (the "Controller" or "Customer")

(each a "Party", together the "Parties").

This DPA is concluded by acceptance of the Main Agreement; no separate signature is required (Art. 28(9) GDPR — electronic form).

1. Subject Matter, Roles and Scope

1.1 The Processor processes personal data on behalf of the Controller solely to the extent that, in providing the contracted products under the Main Agreement, it processes data on the Controller's behalf. The processing activities per product are described in Annex II. This DPA applies to each product only insofar as that product is contracted under the Main Agreement.

1.2 Delimitation / Processor acting as independent controller. The Processor's own generation, sourcing and enrichment of leads and profiles — including the use of its own sources and third-party enrichment providers — is carried out by the Processor as an independent controller within the meaning of the GDPR, on its own legal basis, and is not subject to this DPA. The handover of a finished lead or profile to the Controller occurs on a controller-to-controller basis and does not constitute processing on the Controller's behalf. Processing under this DPA is confined to the activities described in Annex II.

1.3 Determination of purposes and means. For all processing under this DPA, the Controller determines the purposes and essential means of processing; the Processor provides the technical infrastructure and executes the processing on the Controller's documented instructions. The Processor has no own interest in the personal data processed on the Controller's behalf.

1.4 Eligibility criteria. Any relevance or eligibility criteria agreed jointly with the Controller (including any job-eligibility filter applied across LeadFlow and GrowthEngine) constitute a specification of the Controller's instructions solely for the processing described in Annex II. Insofar as such criteria also influence the Processor's own independent sourcing activity (clause 1.2), they are mere product configuration of that independent activity — not instructions. They do not constitute joint processing of, or joint decision-making over, individual data subjects.

1.5 The Controller is responsible for the lawfulness of the processing under this DPA and warrants that it has a valid legal basis for the processing it instructs, including for any outreach it conducts.

2. Instructions

2.1 The Processor processes personal data only on the Controller's documented instructions, unless required to process by applicable law; in that case it informs the Controller before processing, unless the law prohibits this.

2.2 The processing described in Annex II constitutes the Controller's documented instructions. Further instructions are given in writing or text form and shall be documented.

2.3 The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions.

3. Confidentiality

The Processor grants access to personal data only to persons who need it to perform the Main Agreement, and ensures that such persons are bound by confidentiality or an appropriate statutory duty of confidentiality.

4. Security of Processing

The Processor implements the technical and organisational measures (TOMs) required under Article 32 GDPR, as set out in Annex III. Measures may be updated to reflect the state of the art, provided the level of protection is not reduced.

5. Sub-processors

5.1 The Controller grants the Processor general authorisation to engage the sub-processors listed in Annex IV. The current list is also published at hiring-intelligence.io/legal/subprocessors.

5.2 The Processor informs the Controller at least four (4) weeks in advance of any intended change to that list (addition or replacement) in text form, giving the Controller the opportunity to object on reasonable data protection grounds.

5.3 The Processor imposes on each sub-processor, by contract, substantially the same data protection obligations as set out in this DPA, and remains fully liable to the Controller for the sub-processor's compliance.

6. Assistance to the Controller

6.1 Taking into account the nature of the processing, the Processor reasonably assists the Controller in responding to data subjects exercising their rights (Articles 12–23 GDPR).

6.2 The Processor further assists the Controller in complying with Articles 32 to 36 GDPR (security, personal data breach notification, data protection impact assessment), to the extent necessary and proportionate.

6.3 Where the Processor becomes aware of a personal data breach relating to data processed under this DPA, it notifies the Controller without undue delay.

7. Data Subject Requests and Opt-out

7.1 Where a data subject addresses a request directly to the Processor concerning data processed on the Controller's behalf, the Processor forwards it to the Controller without undue delay and does not respond itself unless instructed to do so.

7.2 Where a request — in particular an objection, opt-out or erasure request — concerns data that the Processor generated or enriched as an independent controller under clause 1.2, the Controller shall forward any such request it receives to the Processor without undue delay, so that the Processor can suppress the data subject in its systems.

8. Deletion and Return

8.1 Where the Processor processes Controller system data only transiently (in particular the LeadFlow deduplication match), it does not store such data persistently beyond the minimal match-result data described in Annex II.A; transiently processed data is discarded immediately after the operation.

8.2 On termination of the processing, the Processor, at the Controller's choice, deletes or returns all personal data processed on the Controller's behalf and certifies deletion in text form, unless a statutory retention obligation applies. If the Controller does not communicate a choice within thirty (30) days of the termination date, the Processor deletes. Data held within a Customer workspace (GrowthEngine), including reply data stored in the Processor's database, is deleted upon termination or on the Controller's instruction. The delivery log (the record of which data records were provided to the Controller) is maintained by the Processor as its own controller-side accountability record (clause 1.2; Art. 19 GDPR notification duty, billing and defence of legal claims) and is not subject to this clause 8.2.

9. Records and Audits

On request, the Processor makes available the information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits — including inspections — conducted by the Controller or an auditor mandated by it, at reasonable intervals and with reasonable prior notice.

10. International Data Transfers (Third Country)

10.1 The Processor is established in the United Arab Emirates. To the extent that the processing involves a transfer of personal data to a third country without an adequacy decision, the Parties enter into the EU Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), as completed in the SCC Schedule attached to this DPA and incorporated by reference. The SCC Schedule forms an integral part of this DPA.

10.2 The Processor implements supplementary measures, in particular EU-hosted infrastructure where possible (primary database hosted in the EU) and encryption as set out in Annex III. Any onward transfer by a sub-processor takes place only on the basis of an appropriate transfer mechanism under Chapter V GDPR.

10.3 The Processor has appointed an EU representative pursuant to Article 27 GDPR, as identified in Annex I.

11. Liability, Precedence and Final Provisions

11.1 Liability is governed by the Main Agreement; mandatory requirements of the GDPR remain unaffected.

11.2 In the event of a conflict, this DPA and the incorporated Standard Contractual Clauses prevail on data protection matters. The law governing the data protection provisions and the SCCs shall be the law of an EU Member State as specified in the SCC Schedule, notwithstanding the language of this DPA or the governing law of the Main Agreement.

11.3 Should individual provisions be invalid, the validity of the remaining provisions is unaffected. Amendments require text form.


Annex I — List of Parties

Controller — as identified in the Order Form:

FieldEntry
Company / Nameper Order Form
Addressper Order Form
Contact / person authorised to give instructionsper Order Form
Data protection officer (if appointed)per Order Form
Contracted product(s)per Order Form: LeadFlow / GrowthEngine / PlacementEngine

Processor:

FieldEntry
Company / NameGrowthlynk Management FZCO (Hiring Intelligence)
AddressDubai Digital Park, Dubai, United Arab Emirates
Contact / recipient of instructionsPhilipp Käming, [email protected]
EU representative (Art. 27 GDPR)Euverify Ltd (Ireland), company no. 781168, Unit 3D, North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland — [email protected] (appointed 2 July 2026)

Annex II — Description of the Processing (per product)

Only the sections for contracted products apply. The Processor's own sourcing and enrichment (clause 1.2) is excluded from all sections below.

II.A LeadFlow — lead delivery and deduplication

Data subjectsContacts/leads stored in the Controller's target system against which matching occurs, and the leads delivered by the Processor.
Categories of dataIdentity data (name), contact data (e.g. email, phone), professional data, and a status/deduplication attribute.
Special categoriesNone.
Nature of processingTransient, ephemeral matching of individual records for deduplication and deliverability-status determination; delivery of leads into the Controller's CRM/target system (via webhook, spreadsheet or CRM integration). No persistent storage of the Controller's system data; retained per record are only a minimal match result (status flag and timestamp) and — for ambiguous matches — a minimal reference to the candidate records concerned (name, CRM link, status label) until the match is manually resolved, at the latest 30 days after flagging.
PurposeDeduplication, determination of deliverability, and data delivery.
DurationTerm of the Main Agreement; retrieved system data discarded immediately after each match.

II.B GrowthEngine — email outreach on the Controller's behalf

Data subjectsRecipients of the Controller's outreach campaigns; persons who reply.
Categories of dataRecipient contact data (name, email), email content and replies, engagement, delivery and tracking data; business phone numbers researched for recipients who reply with interest (qualified replies).
Special categoriesNot intended. Replies are unstructured and may contain data voluntarily provided by respondents, potentially including special categories; access is restricted accordingly.
Nature of processingSending email campaigns in the Controller's name and on its behalf, using the Controller's own sending domains and sender identity, within an isolated workspace assigned to the Controller in the Processor's email-sending entity; reply handling and automated reply classification, and — for qualified replies — business-contact (phone) research (in each case via the sub-processors listed in Annex IV); storage of campaign, reply and engagement data in the Processor's EU-hosted database for the duration of the service; delivery and open/click tracking; optional sync of qualified replies into the Controller's CRM or spreadsheet.
PurposeExecution of the Controller's outreach campaigns on its documented instructions.
DurationTerm of the Main Agreement.

Controller responsibilities (GrowthEngine): the Controller determines the recipients and campaign and is responsible for the legal basis of the outreach (including applicable unfair-competition/anti-spam rules such as § 7 UWG and the GDPR) and for any consent required for tracking under ePrivacy rules. The Processor provides the infrastructure and executes on instructions.

II.C PlacementEngine — candidate–job matching

This section applies only insofar as the processed data constitutes personal data. Where the Processor sources candidate data on its own account, that sourcing is the Processor's independent-controller activity (clause 1.2) and is out of scope; only the matching/processing on the Controller's behalf is covered here.

Data subjectsCandidates whose profiles are matched to job opportunities.
Categories of dataCandidate profile data: identity/contact data where present, qualifications, career/experience data, availability/status.
Special categoriesNot intended. Candidate data (e.g. CV content) may reveal or approach special categories; strict purpose limitation and access restriction apply given the heightened sensitivity of candidate data.
Nature of processingProcessing of candidate data provided by or on behalf of the Controller for the purpose of matching candidates to job opportunities and facilitating outreach on the Controller's behalf.
PurposeRecruiter-to-job matching / placement facilitation on the Controller's documented instructions.
DurationTerm of the Main Agreement.

Annex III — Technical and Organisational Measures (TOMs)

Confidentiality & Access Control

  • Access to production systems on a need-to-know basis; individual accounts, no shared logins; multi-factor authentication on all administrative accounts (database, hosting, task infrastructure, email-sending entity).
  • Centralised credential management via a password manager (1Password); credentials are never stored in code or documents; revocation on offboarding.

Multi-tenant Isolation (GrowthEngine)

  • Each Customer is confined to its own assigned, isolated workspace in the email-sending entity; entity-level access by the Processor is need-to-know only.
  • No cross-workspace merging of data or suppression lists between Customers.
  • Customer-specific suppression is maintained per workspace; the Processor's own sourcing-level suppression is maintained separately, with no bleed between Customers.

Integrity & Confidentiality of Data

  • Encryption in transit (TLS 1.2+) for all connections; encryption at rest for the primary database (managed PostgreSQL, EU region).
  • LeadFlow deduplication: the Controller's system data is processed transiently in memory and discarded after the match; only a minimal per-record match result is persisted (plus, for ambiguous matches, a minimal candidate reference for manual resolution — deleted upon resolution, at the latest 30 days after flagging); payload/response logging for the matching step is disabled in the task infrastructure — task logs contain only counters, record IDs and status values.
  • Access to the Controller's CRM occurs exclusively via Controller-provided API credentials, scoped to the integration.

Candidate Data (PlacementEngine)

  • Strict purpose limitation to matching; access restricted to personnel involved in matching; no use beyond the agreed purpose.

Availability & Accountability

  • Operation on established cloud infrastructure with the providers' contractually assured security measures; primary database EU-hosted (AWS eu-west-1 via Supabase); task execution on US compute (AWS us-east-1 via API Hero Ltd) is transient, with no persistent storage on the task infrastructure, and covered by SCCs.
  • Logging of security-relevant access; regular review of access rights and effectiveness of measures.

Annex IV — Sub-processors

Only services that technically process personal data on the Controller's behalf. Current version also published at hiring-intelligence.io/legal/subprocessors.

CompanyLocation / RegionService (products)
Supabase Inc.USA (parent); database hosted in the EU (AWS eu-west-1, Ireland)Primary database: GrowthEngine workspace data incl. reply data; LeadFlow match-result flags incl. minimal ambiguous-match references; PlacementEngine matching data
API Hero Ltd (trading as Trigger.dev), UK — company no. 14441978Cloud hosted on AWS us-east-1 (USA); SCCs with sub-processorsExecution of processing tasks (LeadFlow matching and delivery; GrowthEngine send/reply pipeline; PlacementEngine matching) — transient; persistent data remains in the EU-hosted database
Vercel Inc.USA (parent); compute pinned to EU region (Dublin, dub1) — both client portal and operations dashboardApplication hosting for dashboards and client portal
EmailBison, 3080 Yonge Street, Suite 6060, Toronto, Ontario M4N 3N1, CanadaCanadaEmail-sending infrastructure, isolated per-Customer workspace (GrowthEngine)
OpenAI, L.L.C.USA — API terms: no training on API data; retention limited to abuse monitoring (max. 30 days); no zero-data-retention addendum (standard API tier)Automated reply classification and reply-content extraction (GrowthEngine reply handling)
Perplexity AI, Inc.USA — API terms: no training on API dataAI-assisted business-contact research (phone numbers) for qualified replies (GrowthEngine reply handling)
Hackeez Consulting SAS (trading as BetterContact), Lyon, France — RCS Lyon 882 799 372France (EU); engages its own vetted data providers under its DPALicensed contact-data enrichment (phone numbers) for qualified replies (GrowthEngine reply handling)

Not sub-processors:

  • The enrichment providers and data sources used in the Processor's own sourcing/enrichment are engaged in the Processor's independent-controller activity (clause 1.2) and are, in that role, not part of the processing on the Controller's behalf. Where the same provider is additionally used within a Service on the Controller's behalf (e.g. BetterContact and Perplexity for reply phone research in GrowthEngine), it is listed above as a sub-processor for that Service.
  • Tools owned and controlled by the Controller (e.g. the Controller's own CRM instance such as Close, or the Controller-owned Google Sheets used for spreadsheet delivery and reply sync) are the Controller's own recipients/processors, even where the Processor pushes data into them on instruction.

SCC Schedule

The completed Standard Contractual Clauses (Module Two) are set out in the separate SCC Schedule document, which forms part of this DPA.


Signatures (required only where a Party requests wet-ink or qualified electronic signature; otherwise concluded per the Main Agreement)

Controller (Customer)Processor (Hiring Intelligence)
Place, date, signaturePlace, date, signature

SCC Schedule to the Data Processing Agreement

Standard Contractual Clauses — Module Two (Controller to Processor)
Commission Implementing Decision (EU) 2021/914 of 4 June 2021

For execution, the full official text of the SCCs (Module Two) is attached to / incorporated into the DPA together with the selections and Annexes below. Official text: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj

1. Incorporation and Module Selection

The Parties agree to be bound by the Standard Contractual Clauses (EU) 2021/914, Module Two (transfer controller to processor), with the data exporter being the Customer (Controller) and the data importer being Growthlynk Management FZCO (Processor). The SCCs prevail over the DPA and the Main Agreement in case of conflict (Clause 5 SCCs).

2. Selections and Options

ClauseSelection
Clause 7 (Docking clause)Included.
Clause 9(a) (Use of sub-processors)Option 2 — general written authorisation. List: Annex III of this Schedule (= Annex IV DPA). Notice period for changes: 4 weeks (aligned with clause 5.2 DPA).
Clause 11(a) (Redress — independent dispute resolution body)Optional wording not included.
Clause 13 / Annex I.C (Supervisory authority)The supervisory authority of the EU Member State in which the data exporter is established (for exporters subject to Art. 3(2) GDPR: the authority of the Member State of their EU representative).
Clause 17 (Governing law)Option 1: law of an EU Member State allowing third-party beneficiary rights — the law of Germany.
Clause 18(b) (Forum)Courts of Germany.

Annex I

A. List of Parties

Data exporter:

FieldEntry
Name / address / contactThe Customer, as identified in the Order Form
Activities relevant to the transferUse of the contracted products (LeadFlow / GrowthEngine / PlacementEngine) as Controller
RoleController

Data importer:

FieldEntry
NameGrowthlynk Management FZCO (trading as Hiring Intelligence)
AddressDubai Digital Park, Dubai, United Arab Emirates
ContactPhilipp Käming, [email protected]
Activities relevant to the transferProvision of the contracted products on the Controller's documented instructions
RoleProcessor

B. Description of Transfer

FieldEntry
Categories of data subjectsPer Annex II DPA for the contracted product(s): contacts/leads in the Controller's target system; recipients of and respondents to the Controller's outreach campaigns; candidates.
Categories of personal dataPer Annex II DPA: identity and business contact data, professional data, deduplication/status attributes, email content and replies, engagement/delivery/tracking data, candidate profile data.
Sensitive dataNot intended. Unstructured replies and candidate documents may incidentally contain such data; access restriction and purpose limitation per Annex II TOMs apply.
Frequency of the transferContinuous, for the duration of the Main Agreement.
Nature of the processingSee Annex II DPA (matching/deduplication, delivery, outreach execution, reply handling, candidate–job matching).
Purpose(s)Provision of the contracted products on documented instructions.
Retention periodTerm of the Main Agreement; deletion per clause 8 DPA. Transient matching data: immediate discard.
Transfers to sub-processorsPer Annex III of this Schedule; same subject matter and duration.

C. Competent Supervisory Authority

The authority determined per Clause 13 (see Selections table above); to be named per Customer in the Order Form where required.

Annex II — Technical and Organisational Measures

The technical and organisational measures set out in Annex III of the DPA apply and are incorporated here by reference. Supplementary measures for the third-country transfer: EU-hosted primary database (AWS eu-west-1), TLS-encrypted transport, at-rest encryption, need-to-know access with MFA, minimal persistence for LeadFlow matching (transient in-memory processing, payload logging disabled), per-Customer workspace isolation for GrowthEngine.

Annex III — List of Sub-processors

The sub-processor list in Annex IV of the DPA applies (also published at hiring-intelligence.io/legal/subprocessors). Authorisation model: general written authorisation with 4-week advance notice of changes.


Transfer Impact Assessment: documented separately (internal document "TIA — UAE"), available to the exporter on request per Clause 14(c) SCCs.