This Data Processing Agreement ("DPA") forms an integral part of the Terms & Conditions (the "Agreement") between SourceGeek VoF, registered at Mozartlaan 33, 3603 BD Maarssen, the Netherlands ("SourceGeek") and the customer that has accepted the Agreement ("Customer"). It applies whenever SourceGeek processes personal data on behalf of Customer in providing the SourceGeek platform and related services (the "Services"). In case of conflict between this DPA and the Agreement regarding the processing of personal data, this DPA prevails.
Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given to them in Regulation (EU) 2016/679 (the "GDPR"). "Connected Systems" means the systems Customer chooses to connect to the Services (such as an applicant tracking system, e-mail, calendar or messaging platform). "Sub-processor" means a third party engaged by SourceGeek to process personal data on behalf of Customer.
2.1. Customer is the controller and SourceGeek is the processor of the personal data processed through the Services on Customer's behalf.
2.2. Where Customer itself acts as a processor for its own clients (for example, as a recruitment or staffing agency processing candidate data on behalf of a hiring organisation), SourceGeek acts as a sub-processor. Customer warrants that its agreement with the relevant controller permits the engagement of SourceGeek and that the instructions it gives under this DPA are consistent with that agreement.
2.3. SourceGeek acts as an independent controller for the limited processing described in its own Privacy Policy (such as Customer's account, billing and support data). That processing is outside the scope of this DPA.
3.1. The subject matter, nature and purpose of the processing, the categories of data subjects and the categories of personal data are described in Annex 1.
3.2. The duration of the processing is the term of the Agreement, plus the limited wind-down period needed to delete personal data in accordance with Section 12.
4.1. SourceGeek processes personal data only on Customer's documented instructions, unless required to do so by Union or Member State law to which SourceGeek is subject; in that case, SourceGeek informs Customer of that legal requirement before processing, unless that law prohibits it.
4.2. Documented instructions consist of: this DPA, the Agreement, Customer's configuration of the Services (including which Connected Systems are linked and which workspace settings are enabled), and the instructions Customer's authorised users give through the Services — including the questions they ask and the actions they approve. Write actions on Connected Systems require approval by an authorised user before they are executed, in accordance with the workspace's approval policy.
4.3. SourceGeek informs Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
SourceGeek ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to what is necessary to provide the Services.
6.1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, SourceGeek implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. The current measures are described in Annex 2.
6.2. SourceGeek may update the measures in Annex 2 from time to time, provided the updates do not materially reduce the overall level of protection.
7.1. Customer grants SourceGeek general authorisation to engage Sub-processors for the processing described in this DPA. The current list of Sub-processors is published at sourcegeek.com/sub-processors.
7.2. SourceGeek gives Customer at least 30 days' prior notice of the addition or replacement of a Sub-processor by updating that page and notifying workspace administrators. Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Services.
7.3. SourceGeek imposes on each Sub-processor, by way of contract, data protection obligations that provide at least the same level of protection as this DPA, and remains fully liable to Customer for the performance of each Sub-processor's obligations.
7.4. Connected Systems are not Sub-processors. They are Customer's own service providers, which SourceGeek accesses solely on Customer's instruction and using credentials Customer supplies.
8.1. Where the Services use large language models to process personal data (for example, to answer a question that requires data from a Connected System), the relevant data is transmitted to model providers through an AI gateway configured to route requests only to providers operating under zero-data-retention terms: prompts and outputs are processed to produce the response, are not stored by the model provider, and are not used to train models. Requests for which no zero-data-retention provider is available fail rather than fall back to a non-compliant provider.
8.2. Personal data from Connected Systems is retrieved on demand, per request. SourceGeek does not bulk-copy, synchronise or crawl Connected Systems.
8.3. The Services do not make automated decisions concerning data subjects that produce legal effects or similarly significantly affect them within the meaning of Article 22 GDPR. Actions that change data in Connected Systems require prior approval by an authorised user of Customer, and every such action is recorded in an audit log available to Customer.
9.1. SourceGeek may process personal data outside the European Economic Area only in accordance with Chapter V GDPR. Where a Sub-processor processes personal data in a third country without an adequacy decision, the transfer is safeguarded by the European Commission's Standard Contractual Clauses and/or certification under the EU–U.S. Data Privacy Framework, as indicated in the Sub-processor list.
10.1. Taking into account the nature of the processing, SourceGeek assists Customer with appropriate technical and organisational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to data subjects' requests under Chapter III GDPR. Where a data subject request is submitted directly to SourceGeek, SourceGeek forwards it to Customer without undue delay and does not respond itself except to refer the data subject to Customer.
10.2. SourceGeek assists Customer in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to SourceGeek.
SourceGeek notifies Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer's personal data. The notification describes, to the extent known: the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. SourceGeek documents breaches and cooperates with Customer's reasonable requests for further information.
12.1. During the term, Customer can delete personal data through the Services, including by deleting individual workspaces. Deleting a workspace permanently erases its chats, documents, memories, automations and audit logs.
12.2. Upon termination of the Agreement, SourceGeek deletes all personal data processed on Customer's behalf, unless Union or Member State law requires storage. SourceGeek may retain a content-free deletion receipt (operational metadata only) for up to 90 days as evidence that deletion occurred.
13.1. SourceGeek makes available to Customer all information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by Customer or an auditor mandated by Customer.
13.2. Audits take place at most once per year (unless required by a supervisory authority or following a personal data breach), on at least 30 days' written notice, during business hours, without unreasonably disrupting SourceGeek's operations, and subject to appropriate confidentiality undertakings. Each party bears its own costs.
14.1. The liability provisions of the Agreement apply to this DPA.
14.2. This DPA takes effect on acceptance of the Agreement and remains in force as long as SourceGeek processes personal data on Customer's behalf.
14.3. This DPA is governed by Dutch law. Disputes are resolved as set out in the Agreement.
Nature and purpose of the processing. Providing an AI assistant for recruitment teams: answering users' questions, researching and scoring candidates, drafting documents and outreach, and — subject to user approval — performing actions in Connected Systems; including the hosting, transmission, display and deletion of the data involved.
Categories of data subjects. Candidates and applicants; contacts of Customer (such as hiring managers and client contacts); Customer's authorised users of the Services.
Categories of personal data. Identification and contact data (name, e-mail address, phone number); professional data (CV/résumé content, work history, education, skills, public professional profiles); recruitment data (application and pipeline status, notes, evaluations, correspondence); content of chats and documents created in the Services; technical and usage data (log data, identifiers) to the extent it relates to identifiable persons.
Special categories of personal data. The Services are not intended for the processing of special categories of personal data (Article 9 GDPR). Customer instructs such processing only where it has a valid legal basis and appropriate safeguards.
Processing operations. Collection on demand from Connected Systems and data sources; storage; organisation; analysis and enrichment; drafting; transmission to Customer's authorised users; approved write actions on Connected Systems; erasure.
Questions about this DPA can be sent to support@sourcegeek.com.
Easy plug & play, no technical knowledge needed. Have your assistant ready in a matter of minutes.