Status — read first
AI-assisted best-effort draft · not legal advice · not lawyer-reviewed.
This document was drafted with AI assistance as a best-effort starting point. No licensed attorney has reviewed, approved, or certified it, and it is not safe to rely on as a binding or compliant document. A qualified attorney in each operating jurisdiction must review and finish it before it is published or enforced. Nothing here claims an audit, certification, corporate registration, or executed contract that has actually happened.
A DPA is a binding GDPR Art. 28 instrument. The processor is now named — Vettika, a service operated by Nexprove — but this is not an executable contract in this state: a lawyer must review and finish it, and must confirm the SCC module selection and the UK/Swiss addenda before it is offered to any customer. Nothing here claims a signed agreement, an audit, or a certification that has actually happened.
0. Open items counsel must resolve
- The processor's registered identity. The processor is Vettika, a service operated by Nexprove. That names the party, but the SCC completion needs a registered legal form, incorporation jurisdiction, registration number, and address for Nexprove as the data importer — none of which is asserted here. Counsel inserts that detail; an SCC that names a non-existent or unspecified importer is not executable.
- Article 27 representative. An Art. 28 DPA that also admits “no EU representative appointed” is a red flag in enterprise procurement and a standalone compliance gap. Appoint the Art. 27 representative before offering this DPA to EU-facing customers.
- SCC module selection. Counsel confirms whether Module 2 (controller-to-processor) or Module 3 applies to each flow, and that the UK IDTA and any Swiss addendum are actually executable, not just referenced.
- A real security questionnaire. §10 lets Vettika satisfy an audit request with a security questionnaire and the subprocessor list first. That promise is only deliverable if a current, filled-in questionnaire artifact exists on day one. Produce it.
- Countersignature path. “Auto-effective on accepting the Terms” is fine for click-through, but many enterprise buyers want a countersigned DPA. Make sure support@vettika.com can actually produce and return one.
Parties
- Controller: the Recruiter customer (the legal entity named in the order form).
- Processor: Vettika, a service operated by Nexprove (Nexprove as operator), providing the Service across vettika.com and airecruiter.nexprove.com. Registered form, number, and address to be confirmed by counsel — see §0.
1. Subject matter and duration
The Processor processes personal data on the Controller's behalf only to deliver the Service (as reached on either vettika.com and airecruiter.nexprove.com), for the term of the master agreement and any wind-down period needed to return or delete the data.
2. Nature and purpose
Running AI screening interviews, storing transcripts and AI scoring (and audio, to the extent any is stored), sending transactional email, and producing analytics for the Controller. The Processor does not process the personal data for its own purposes, and does not sell it or use it to train foundation models.
3. Data subjects
Job candidates the Controller submits or who apply through the Controller's apply links.
4. Categories of personal data
Identity, contact details, application content, interview audio, transcript, AI scoring, and derived analytics. A transcript may incidentally contain special-category data if a candidate volunteers it; the Processor does not solicit it. Full detail in the Privacy Policy §3.
5. Controller obligations
The Controller will collect personal data lawfully under its own privacy notice, obtain candidate consent where required, run the bias audit that NYC Local Law 144 requires before screening NYC-located candidates, avoid instructing the Processor to do anything unlawful, and keep its own Art. 30 records. The Controller warrants it has a lawful basis for every instruction it gives.
6. Processor obligations
The Processor will:
- Process only on the Controller's documented instructions.
- Bind everyone with access to confidentiality.
- Apply the Art. 32 security measures in Annex II.
- Help the Controller with its Art. 32–36 duties (security, DPIA, breach notice).
- Delete or return personal data at the end of the Service, per the retention schedule on the Data Handling page. Deletion is enforced automatically: a nightly retention sweep scrubs candidate personal data inactive for 12 months and hard-deletes the tombstone within 30 days, and an explicit erasure request scrubs the personal data immediately.
- Provide the information needed to show Art. 28 compliance and support audits, within the limits in §10.
- Notify the Controller of a personal data breach without undue delay, and no later than 72 hours after becoming aware. (This 72 hours figure is the single standard across the Privacy Policy, the Data page, and this DPA. The downstream subprocessor DPA uses a shorter 24-hour window on purpose, so the chain can meet this 72 hours commitment.)
7. Subprocessors
The Controller gives general authorization to engage the subprocessors in the single canonical list below. That list — not a hand-copied table in this DPA — is the authoritative one, so the two cannot disagree. The Processor imposes data-protection terms on each subprocessor no less protective than this DPA, and remains liable for their acts and omissions. The Processor gives 30 days' advance notice (email plus product banner) before adding or replacing a subprocessor. The Controller may object within that window, and the parties will work in good faith to resolve it; if it cannot be resolved, the Controller may terminate the affected Service.
| Subprocessor | Purpose | Data categories | Processing location | Transfer mechanism | Retention by subprocessor |
|---|---|---|---|---|---|
| Vercel Inc. (US) | Hosting the web app, APIs, and agent runtime | All categories, at request time | US | DPA + EU SCCs — verify executed + capture version/date | Logs ~30 days |
| Neon, a Databricks company (US) | Managed Postgres for application data | All categories, at rest | US, us-east-1 (production). us-east-2 is the separate QA database and holds no production candidate data | DPA + EU SCCs — verify | Per Vettika's retention schedule |
| LiveKit Inc. (US) | Real-time audio transport for the interview | Interview audio | US | DPA + EU SCCs — verify | Egress/recording behavior must be confirmed — see the audio note |
| Deepgram Inc. (US) | Speech-to-text, via LiveKit Inference | Interview audio (streamed) | US | DPA + EU SCCs — verify | Zero-data-retention target — verify contractually |
| Google LLC (US) | Gemini LLM, via LiveKit Inference, for interviewer dialog and scoring | Transcript snippets, scoring context | US | DPA + EU SCCs — verify | Zero-data-retention target — verify contractually |
| Cartesia Inc. (US) | Text-to-speech for the interviewer voice | Interview turn text (no identity) | US | DPA + EU SCCs — verify | Zero-data-retention target — verify |
| Resend (US) | Transactional email | Recipient email, subject, body | US | DPA + EU SCCs — verify | ~30 days in dispatch logs |
| Upstash Inc. (US) | Rate-limiting store (Redis) | IP and token hashes for rate limits | US | DPA + EU SCCs — verify | Short-lived rate-limit keys |
| Cloudflare Inc. (US) | Turnstile bot/abuse check on auth forms | IP, challenge token | US | DPA + EU SCCs — verify | Per Cloudflare policy |
| Google LLC (OAuth) | Recruiter "Sign in with Google" | Recruiter identity, email, OAuth token | US | DPA + EU SCCs — verify | Token lifetime |
| Have I Been Pwned (HIBP) | Breached-password check at signup | k-anonymized password hash prefix only (no email, no full password) | US/UK | Assess — likely not a personal-data processor given k-anonymity; counsel to confirm | None retained by Vettika's use |
| Stripe Inc. (US) | Recruiter payment processing | Recruiter billing identity, payment metadata | US | DPA + EU SCCs — verify | Per Stripe policy |
| Polar Software Inc. (US) | Alternative billing surface where used | Recruiter billing identity | US | DPA + EU SCCs — verify | Per Polar policy |
Error tracking (Sentry or similar) is not selected. No vendor is listed here until one is actually in use. Vettika gives recruiter customers 30 days' advance notice before adding or replacing a subprocessor; a recruiter who objects may terminate per the DPA.
8. International transfers
Where transfers fall under Chapter V GDPR, the parties rely on the EU SCCs 2021/914 (modules as counsel selects) plus the supplementary measures in Annex III, with the UK IDTA appended where relevant. Counsel confirms the module choice and that the addenda are executable.
9. Data subject rights
The Processor helps the Controller answer rights requests (access, deletion, and so on) through the candidate token endpoints and the recruiter account UI, and promptly forwards any request it receives directly from a data subject to the Controller.
10. Audits
Once every 12 months, on 30 days' notice, the Controller may audit compliance, subject to confidentiality and reasonable limits on frequency and disruption. The Processor may satisfy this first with a current security questionnaire and the subprocessor list, and later with a SOC 2 Type II report when one exists. (A real security questionnaire must exist for this to be deliverable — see §0.)
11. Liability
Per the master agreement. Counsel confirms the interaction with the Terms' liability cap and any statutory liability under GDPR Art. 82 that a cap cannot exclude.
12. Governing law
Per the master agreement, and consistent with the forum counsel selects in the Terms. Governing law: to be set by counsel (the jurisdiction where Nexprove is established).
Annex I — Description of processing
- Data exporter: the Controller (Recruiter customer named in the order form).
- Data importer: the Processor — Vettika, a service operated by Nexprove (Nexprove), reached via vettika.com and airecruiter.nexprove.com.
- Data subjects, categories, purpose, duration: as described in §§1–4 and the retention schedule on the Data Handling page.
- Frequency: continuous, for the term of the Service.
Counsel confirms this cross-reference actually satisfies the SCC Annex I requirement rather than just gesturing at it, and completes the competent-supervisory-authority field.
Annex II — Technical and organizational measures
- TLS in transit; encryption at rest (AES-256) for the database and any stored audio.
- Role-based access control on every recruiter resource; server-side campaign-ownership checks; production/QA database separation (production candidate data does not sit in the QA database).
- Audit logging for privileged actions; security logging for authentication events.
- Encrypted secrets and token storage; least-privilege service credentials.
- Vendor security review before onboarding any subprocessor.
- Vulnerability disclosure via
security.txt. - Penetration testing: planned, not yet completed — do not represent it as done.
Annex III — Subprocessors
See the single canonical subprocessor list in §7 above (the same list rendered on the Privacy Policy and the Data Handling page).