Version 1.0. Effective date: 1 March 2026. Governed by EU GDPR.
1. Definitions
- Personal Data
- Any information relating to an identified or identifiable natural person contained in resume or CV files submitted to CVault, including name, contact details, employment history, and education.
- Processing
- Any operation performed on Personal Data, including collection, storage, parsing, structuring, retrieval, and deletion.
- Sub-processor
- Any third party engaged by CVault to assist in Processing on behalf of the Controller.
- Data Subject
- The individual whose personal data is contained in a submitted resume or CV file.
2. Scope and nature of processing
CVault processes Personal Data solely to provide resume parsing, candidate scoring, and candidate intelligence services described in the CVault documentation.
- Processing follows documented instructions from the Controller.
- Processing is limited to contracted services.
- Retention is bounded: Workspace candidate records are retained while the customer keeps them for search, scoring, comparison, reporting, and auditability. Customers can delete candidate records at any time. Uploaded source files are used for text extraction and are not retained as workspace candidate records by default.
CVault will not sell, share, or use Personal Data to train models on behalf of third parties.
3. Controller obligations
- The Controller must have a lawful basis for submitting candidate Personal Data.
- The Controller must inform Data Subjects when resumes may be processed by a third-party parsing service.
- The Controller should avoid submitting special-category data beyond what candidates voluntarily include.
- The Controller must submit deletion requests promptly after receiving a verified Data Subject erasure request.
4. Data subject rights
CVault assists the Controller with access, erasure, rectification, and portability requests under GDPR Chapter III.
Erasure requests are handled according to the active deletion process. Verified candidate erasure requests are handled within 5 business days.
Requests should be sent to [email protected].
5. Security measures
- Encryption at rest for stored Personal Data.
- TLS protection for data in transit.
- Access controls scoped to authorized personnel and workspace boundaries.
- API authentication through signed keys or JWT tokens where applicable.
- Retention controls and deletion jobs for records with explicit expiry metadata.
6. International transfers
Where data is transferred outside the EEA, CVault uses appropriate safeguards such as Standard Contractual Clauses where required.
7. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Structured data storage and authentication | EEA |
| DigitalOcean | API server infrastructure and file processing | EEA |
| Paddle | Payment processing for billing data only | UK / EEA |
8. Audits and compliance
CVault will provide information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, subject to reasonable notice and confidentiality obligations.
9. Term and termination
This DPA remains in effect for the duration of the service agreement. Upon termination, CVault will delete remaining Personal Data within 30 days unless a longer retention period is required by law.
10. Request a signed copy
To receive a countersigned DPA, email [email protected] with subject line DPA Request and your company name.
