Data Processing Addendum

VERSION: 1.0
Last Updated: 1. April 2025

1. Initial provision

1.1 Agreement.
This Data Processing Addendum (the "DPA”) forms an integral part of the Terms of Service available at Terms of Service  and the Order executed separately by the Parties (collectively, the "Agreement").

1.2 Data Processing Agreement.
By entering into the Agreement with the Provider, the Client acknowledges that it has read and understood this DPA and agrees to be bound by it.

2. Definition

Other than the terms defined in the body of this DPA or in the Agreement, these terms have the following meaning:

"Data Breach" means a breach of security of the Services leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed by the Provider under this DPA.

"Data Protection Legislation" means, as applicable to a party and its Processing of Personal Data, the EU Data Protection Law and any other law applicable for the provision of the Services.

"EU Data Protection Laws" mean Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (the "GDPR") and the EU e-Privacy Directive (Directive 2002/58/EC). The terms "Controller", "Processor", "Process", "Processing", and "Data Subject" shall have the same meanings given to them under the GDPR.

"Personal Data" means any information that (i) is protected as "personal data", "personal information" or "personally identifiable information" under Data Protection Legislation; and (ii) is Processed by the Provider on behalf of the Client in the course of providing the Services, as more particularly described in Annex A of this DPA.

"Sub-processor" means any third party engaged by the Provider to assist in fulfilling its obligations with respect to providing the Services and that Processes Personal Data as a Processor.

"Standard Contractual Clauses" means the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 (the "EU SCCs").

3. Provider's obligations

3.1 Roles.
For the purposes of this DPA, the Client (or a third party on whose behalf the Client is authorized to instruct the Provider) is the Controller of the Personal Data, and the Provider shall Process Personal Data as a Processor (or Sub-processor, as applicable to the Client's use of the Services).

3.2 Permitted Purposes.
The Provider shall Process Personal Data for the purposes described in Annex A and in accordance with Client's documented lawful instructions ("Permitted Purposes"), except where otherwise required by the Data Protection Legislation. To the extent required by Data Protection Legislation, this Section 3.2 constitutes the certification from the Provider to the Processing instructions herein. The Provider is obliged at all times to Process Personal Data in compliance with Data Protection Legislation and fulfil all its obligations arising out of Data Protection Legislation.

3.3 Processing Instructions.
The Provider shall immediately inform the Client if it becomes aware that the Client's Processing instructions infringe Data Protection Legislation. If the Provider is unable to Process Personal Data in accordance with the Client's documented lawful instructions, the Provider is obliged to promptly notify the Client of its inability to comply.

3.4 Security Measures.
The Provider shall implement and maintain reasonable and appropriate technical and organizational measures designed to protect Personal Data from Data Breaches and preserve their security, integrity, and confidentiality. Such measures shall have regard to the state of the art, the costs of implementation and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons. 

3.5 Access and Confidentiality.
The Provider shall ensure that any person it authorizes to Process the Personal Data (including Provider's staff, agents and Sub-processors) ("Personnel") are under appropriate obligations of confidentiality (whether a contractual or statutory duty), have received proper training, and are informed about the confidential nature of the Personal Data, their obligations related to it, and have access to Personal Data only on a need-to-know basis. The Provider shall ensure that Personnel Process the Personal Data only as necessary for the Permitted Purposes.

3.6 Data Returns and Deletion.
Upon termination or expiration of the Agreement, the Provider must delete or return to the Client all Personal Data in its possession or control except for one copy for archival and compliance purposes.

4. Audit rights

4.1 Right to conduct audits.
The Client shall have the right to conduct an audit to verify Provider's compliance with its obligations laid down in Art. 28 GDPR (if applicable) and in this DPA. The Provider shall allow the Client to carry out the audit if (i) the Client requests to carry out the audit via a written notice at least 30 (thirty) days in advance; (ii) the Client will specify the agenda for such audit in such notice; (iii) the audit shall not take place more than once a year; (iv) all associated costs and expenses shall be borne by the Client or reimbursed to the Provider on demand; and (v) the audit shall last no longer than the equivalent of 1 working day (8 hours) of Provider's representative. On the request of the Client, the Provider will provide the Client with the estimated cost that it expects to incur during such audit according to the extent specified in the agenda provided by the Client.

4.2 Independent Auditor.
In case the Client requests the audit by an independent party – external licensed auditor, the Provider may object to an external licensed auditor appointed by the Client to conduct the audit if the auditor is, in Provider's reasonable opinion, not suitably qualified or independent, a competitor of the Provider, or otherwise manifestly unsuitable. Any such objection will require the Client to appoint another auditor. 

5. Client's obligations

5.1 Client's Processing of Personal Data.
The Client shall, in its use of the Services, Process Personal Data in accordance with Data Protection Legislation. The Client shall have the sole responsibility for the accuracy, quality, and legality of Personal Data and how the Client acquired Personal Data.

5.2 Client's Compliance.
The Client agrees that (i) it shall comply with its obligations as a Controller under Data Protection Legislation in respect of its Processing of Personal Data and any Processing instructions it issues to the Provider; (ii) it has provided notice and obtained (or shall obtain) all consents or any other necessary authorizations (as applicable) under Data Protection Legislation for the Provider to Process Personal Data for the Permitted Purposes; (iii) it shall be responsible for providing any notices required by Data Protection Legislation to the relevant data subjects with respect to sharing their Personal Data with the Provider; (iv) it has fulfilled (or shall fulfil) all registration or notification obligations to which the Client is subject under the Data Protection Legislation; and (v) it is responsible for its own Processing of Personal Data, including integrity, security, maintenance, and appropriate protection of Personal Data under the Client's control.

5.3 Technical and Organizational Measures.
The Client is responsible for its secure use of the Services, protecting the security of Personal Data when in transit to and from the Services, and taking any appropriate technical, organizational, and security measures to securely encrypt or backup any Personal Data uploaded to the Services. The Client is also responsible for the use of the Services by any person authorized by the Client to access or use the Services, and any person who gains access to its Personal Data or the Services as a result of its failure to use reasonable security precautions, even if the Client did not authorize such use. The Client agrees to notify the Provider immediately upon becoming aware of any unauthorized use of the Services or any other breach of security involving the Services.

6. Cooperation

6.1 Data Subject Rights.
To the extent that the Client is unable to access the relevant Personal Data within the Services independently, the Provider shall, taking into account the nature of the Processing, provide assistance (including by appropriate technical and organizational measures) to provide reasonable cooperation to the Client in order to (i) respond to any requests from a data subject seeking to exercise any of its rights under Data Protection Legislation (including its right of access, correction, objection, erasure and data portability, as applicable); and (ii) any other correspondence, enquiry or complaint received from a data subject, regulator or other third party in connection with the Processing of the Personal Data (collectively "Correspondence").

In the event that any such Correspondence is made directly to the Provider, it shall promptly notify the Client and shall not respond directly unless legally compelled to do so. If the Provider is required to respond to such Correspondence, the Provider shall promptly notify the Client and provide it with a copy of the request, unless legally prohibited from doing so.

6.2 Data Protection Impact Assessment.
To the extent required by Data Protection Legislation, the Provider shall provide reasonable cooperation regarding the Services to enable the Client to carry out data protection impact assessments or prior consultations with data protection authorities as required by Data Protection Legislation.

6.3 Request for Disclosure.
The Provider is obliged to promptly notify the Client about any legally binding request for disclosure of the personal data by a judicial or regulatory authority unless otherwise prohibited, such as the obligation under criminal law to preserve the confidentiality of a judicial enquiry and to assist the Client accordingly (at the Client's expense).

7. Security incidents

7.1 Data Breach.
Upon becoming aware of a Data Breach, the Provider shall notify the Client without undue delay and shall provide such timely information and cooperation as the Client may reasonably require in order to fulfil its data breach reporting obligations under Data Protection Legislation, including the type of data affected and the identity of the affected person(s) as soon as such information becomes known or available to the Provider.

7.2 No acknowledgement.
The Client agrees that any notification that the Provider provides to the Client in relation to a Data Breach shall not be construed or understood as an acknowledgement of any fault or liability.

7.3 Further Conduct.
The Provider shall further take all such measures and actions as are reasonable to remedy or mitigate the effects of the Data Breach and shall keep the Client informed of all developments in connection with the Data Breach.

7.4 Cooperation.
If a Data Breach is caused or materially contributed to by the Client, the Provider will cooperate in the investigation of the Data Breach subject to the Client's obligation to compensate the Provider for its expenses and costs.

8. Sub-processing

8.1 Authorized Sub-processors.
The Client provides a general authorization for the Provider to engage Sub-processors to Process Personal Data on the Client's behalf. The Sub-processors currently engaged by the Provider are included under Annex C. 

8.2 New Sub-processors.
The Provider may engage or replace Sub-processors at its discretion, provided that it updates Annex B of the DPA available at Terms of Service to reflect such changes. The Provider shall provide at least ten (10) days' prior written notice to the Client of any new Sub-processor engagement.

8.3 Objections.
If the Client has a reasonable objection to any new Sub-processor, it shall notify the Provider of such objections in writing to info@finlay.ai within ten (10) days from receiving the notification and the Parties will seek to resolve the matter in good faith. If the Client does not provide a timely objection to any new Sub-processor in accordance with this Section 8.3, the Client will be deemed to have consented to the Sub-processor and waived its right to object.

8.4 Liability for Sub-processors.
The Provider remains liable for any breach of this DPA caused by an act, error, or omission of such Sub-processor.

9. Data transfers

9.1 International Data Transfers.
The Provider shall take all such measures necessary to ensure that the Processing and transfer of Personal Data in or to a territory other than the territory in which the Personal Data was first collected complies with Data Protection Legislation.

9.2 Application of Standard Contractual Clauses.
The Parties agree that when and to the extent the transfer of Personal Data from the Client to the Provider is a restricted transfer and EU Data Protection Laws require that appropriate safeguards are put in place, such transfer shall be governed by the EU SCCs, which shall be incorporated by reference into and form an integral part of this DPA.

9.3 EU Data.
For the purposes of Personal Data that is subject to the EU Data Protection Laws ("EU Data"):

a) where the Client is a Controller of Personal Data, Module Two (Controller to Processor Clauses) will apply and where the Client is a Processor acting on behalf of third-party Controllers, Module 3 (Processor to Processor Clauses) will apply; 

b) in Clause 7 (Docking Clause), the optional docking clause will apply;

c) in Clause 9 (Use of Sub-processors), Option 2 will apply, and the time period for prior notice of Sub-processor changes shall be as set out in Section 8.2 of this DPA and the period for notification of objections in Section 8.3 of this DPA;

d) in Clause 11 (Redress), the optional language to permit data subjects to lodge complaints with an independent dispute resolution body will not apply;

e) in Clause 17 (Governing Law), Option 1 will apply, and the EU SCCs will be governed by Czech law;

f) in Clause 18(b) (Choice of forum and jurisdiction), disputes shall be resolved before the courts of Prague, Czech Republic;

10. Limitation of liability

The The Client's remedies, including its Affiliates, and the Provider's liability arising out of or in relation to this DPA (including Standard Contractual Clauses), are subject to those limitations of liability and disclaimers set forth in the Agreement. For the avoidance of doubt, nothing in this DPA is intended to limit the rights a Data Subject may have against either Party arising out of such Party's breach of the Standard Contractual Clauses, where applicable.

11. Final provisions

11.1 Third-Party Beneficiaries.
Data Subjects are the sole third-party beneficiaries to the Standard Contractual Clauses, and there are no other third-party beneficiaries to this DPA, unless specified to the contrary in the Agreement.

11.2 Governing Law and Jurisdiction.
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless and to the extent required otherwise by the Data Protection Legislation or the Standard Contractual Clauses.

11.3 Scope of this DPA.
For the avoidance of doubt, the processing of information other than Personal Data for the Permitted Purposes does not fall under the scope of this DPA.

11.4 Amendments.
The Provider may amend this DPA subject to the conditions set forth in the Agreement. Any such amendments shall be communicated to the Client in accordance with the provisions outlined in the Agreement and shall become effective as specified therein.

11.5 Term.
This DPA shall continue to be in effect for the term of the Agreement plus the period from expiry of the Agreement until the Provider ceases to process Personal Data on behalf of the Client (the "Processing Term").

Annex A
Description of the Processing Activities / Transfer
Annex A(1) List of Parties:
Data Exporter
Data Exporter
Name: Client, as identified in the Order
Name: Provider, as identified in the Agreement
Address: As identified in the Order
Address: As identified in the Agreement
Contact details: As identified in the Order
Contact details: As identified in the Agreement
Activities relevant to the transfer: See Annex A(2) below
Activities relevant to the transfer: See Annex A(2) below
Role: Controller
Role: Processor
Annex A(3): Competent supervisory authority With respect to EU Data the competent supervisory authority is The Office of the Information Commissioner of Czech Republic (the "Supervisory Authority").  
Annex A(2)  Description of Transfer:  
Description
Description
Categories of data subjects:
●  Job Candidates
Categories of Personal Data:




●  Job Candidates: Identification and contactdata (name, address, title, contact details, username); employment details (employer, job title, geographic location, area of responsibility, qualifications, references); identification documents (e.g., passport, driver's license) where required by law; salary expectations, job preferences, and availability
‌Sensitive data:
The Provider does not require any special categories of personal data to provide the Services and does not intentionally collect or process such data in connection with the provision of the Services.
Frequency:
Continuous
Nature and subject matter of processing:
The Personal Data may be subject to the following processing activities:

●  
storage (hosting) and other processing necessary to provide, maintain and improve the Services provided to Client under the Agreement,

support provided to the Client on a case by case basis,

disclosures in accordance with the Agreement and the DPA, as compelled by law, and

collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Duration of the processing:
Processing Term
Purpose(s) of the data transfer and further processing:
(i) Processing to provide, maintain, support, and improve the Services provided to the Client in accordance with the Agreement;

(ii) Processing to comply with other documented reasonable instructions provided by the Client (e.g., via email) where such instructions are consistent
Retention period (or, if not possible to determine, the criteria used to determine that period):
Processing Term.
Annex A(3): Competent supervisory authority With respect to EU Data the competent supervisory authority is The Office of the Information Commissioner of Czech Republic (the "Supervisory Authority").  
Annex B
Technical and Organisational Measures
The Provider has implemented the following technical and organisational measures that ensure an appropriate level of security taking into account the nature, scope, context, and purposes of the processing, and the risks for the rights and freedoms of natural persons: 
1. Access Control Measures
● Controls to specify authorized individuals permitted to access personal data● Logging and monitoring of access attempts
2. Data Encryption & Pseudonymization
● Implementation of a password policy

● Encryption of personal data in transit
3. Network & System Security
● Firewalls, intrusion detection, and prevention systems (IDS/IPS)

● Regular vulnerability scanning and patch management

● Secure software development lifecycle (SDLC) practices
4. Operational Security & Incident Response
● Security monitoring and threat detection

● Regular security awareness training for employees

● Confidentiality obligation for employees

● Defined incident response plan with breach notification procedures
5. Data Resilience & Backup
● Regular automated backups with encrypted storage

● Disaster recovery and business continuity planning

● Periodic data integrity checks
6. Audit & Compliance
● Regular internal security audits

● Compliance with industry standards (e.g., ISO 27001, SOC 2)
Annex C
Approved Sub-processors
Country
Identificati
on of sub-processon
Services
Ireland
Google Ireland Limited, with the registered office at Gordon House, Barrow Street, Dublin 4, Ireland
Analytics, Hosting, Search and Storage
New Zealand, Global
Soul Machines Ltd.,L1, 106 Customs Street West, Auckland, 1010, New Zealand
AI, Interviews
Israel, Global
Bright Data Ltd., 4 Hamahsh
ev St., Netanya 4250714, Israel
Web data collection & Proxy services
France,      
Global
Unipile SAS, 168 Rue de l a Rotonde, 42153 Riorges, France
Messaging
& Commun-
ication API's
Ireland, USA
Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg
Hosting