Last updated: 8 August 2026
Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") forms part of the Business Terms and governs the processing of personal data between the client company (the "Company") and Gorka El Bochi Morillo (empresario individual), tax ID 46099276P, registered address Carrer Romaní 15, 08184 Barcelona, España ("CyberProfile"), in the context of CyberProfile's recruiting product, in accordance with Regulation (EU) 2016/679 (GDPR) and other applicable law.
1. Roles of the parties
With respect to the data the Company enters or manages on the platform (its Members' accounts, internal notes, pipeline data and any data the Company provides), CyberProfile acts as PROCESSOR on behalf of the Company, which is the CONTROLLER.
With respect to the Candidate profile data that CyberProfile obtains and verifies from its own sources, CyberProfile is the CONTROLLER. When the Company accesses that data for its hiring process, it becomes an INDEPENDENT CONTROLLER of the data it receives, with its own GDPR obligations. This DPA governs the part where CyberProfile acts as Processor.
2. Subject matter and duration
The subject matter is the processing of personal data by CyberProfile on behalf of the Company, necessary to provide the Business Service. Duration matches the term of the plan or the Organization, plus any legally required retention periods.
3. Nature and purpose of processing (Annex I)
- Nature and purpose: hosting, management of the Organization account and its Members, management of the hiring pipeline, billing, and delivery of managed services.
- Types of data: identification and contact data of the Company's Members; notes and assessments the Company records about Candidates; billing data (handled via the payment provider); usage metadata.
- Categories of data subjects: the Company's staff with platform access and Candidates referenced in the Company's pipeline.
- No processing of special categories of data is requested; the Company will refrain from entering sensitive data unnecessary for hiring.
4. Controller instructions
CyberProfile will process the data only on the Company's documented instructions — these Terms and the use of the platform being the initial instruction — unless required by law, in which case it will inform the Company where permitted. CyberProfile will inform the Company if, in its opinion, an instruction infringes the law.
5. Confidentiality
CyberProfile ensures that persons authorized to process the data have committed to confidentiality or are under a statutory duty of confidentiality, and that access is limited to what is necessary.
6. Security measures (Annex II)
- Encryption in transit (HTTPS/TLS) and of sensitive secrets at rest (e.g. platform tokens with AES-256-GCM).
- Role-based access control and least privilege; authorization verified server-side on every operation.
- Multi-tenant isolation per organization: each Company's data is filtered by its identifier and not accessible to others.
- Audit logging of sensitive operations and of accesses to Candidate data (traceability).
- Periodic backups and recovery procedures; server security maintenance and updates.
- Pseudonymization/minimization where appropriate (e.g. truncated IPs or their hash are exposed, never secrets).
7. Sub-processors (Annex III)
The Company authorizes CyberProfile to use the following sub-processors to provide the Service. CyberProfile imposes data protection obligations equivalent to this DPA on them and remains responsible for their performance.
- IONOS (server hosting, EU): infrastructure where the application runs and the database is hosted.
- MongoDB database: self-hosted on the above server (not a managed third-party service).
- Own (self-hosted) mail server for sending notifications and transactional emails.
- Resend: email provider used as a delivery fallback/reinforcement.
- Stripe Payments Europe: payment processing and subscription billing.
- Identity providers for sign-in (Google, GitHub, LinkedIn), when the user chooses to log in with them.
8. New sub-processors
CyberProfile will inform the Company of the addition or replacement of sub-processors with reasonable notice, giving it the chance to object on reasonable data-protection grounds. If the objection cannot be resolved, the Company may terminate the contract as to the affected part.
9. Assistance to the controller
Taking into account the nature of processing, CyberProfile will assist the Company, with reasonable measures, in responding to data-subject rights requests and in meeting its security, breach-notification and impact-assessment obligations, to the extent the Company cannot do so itself through the platform's features.
10. Personal data breach notification
CyberProfile will notify the Company without undue delay after becoming aware of a security breach affecting personal data processed on its behalf, providing the information reasonably available so the Company can meet its own notification obligations.
11. Deletion or return
On termination of the Service, and at the Company's choice, CyberProfile will delete or return the personal data processed on its behalf, and delete existing copies, unless it must retain them by law. Deleting a Member's account and the opt-out mechanisms available on the platform allow some of these actions to be exercised directly.
12. Audit
CyberProfile will make available to the Company the information reasonably necessary to demonstrate compliance with this DPA and will allow proportionate audits, on notice, subject to confidentiality and without compromising the security of other clients.
13. International transfers
Processing takes place preferably within the European Economic Area. Where a sub-processor involves a transfer outside the EEA, it will be covered by a valid GDPR mechanism (adequacy decision or standard contractual clauses with additional safeguards where appropriate).
14. Liability and precedence
Liability for breach of this DPA is subject to the limits set out in the Business Terms, to the extent permitted by law. In case of conflict between this DPA and the Terms on data protection matters, this DPA prevails.
15. Contact
For data protection matters related to this DPA, email gorka@cyber-profile.com.