Data Processing & Sharing Agreement
Version 1.0 — 29 July 2026
This DPA applies automatically to every PlacementFlow customer
This DPA applies automatically to every PlacementFlow customer and forms part of the Terms of Service. Version 1.0 — 29 July 2026. Pending independent legal review.
No signature is required for it to apply. If your organisation needs a countersigned copy or amendments, email privacy@placementflow.com.
0. How this instrument is structured
PlacementFlow's relationship with a customer agency is hybrid: joint controllership of the cold sourcing phase, then independent controllership of the two copies of the candidate record, then processorship of the customer's workspace. One document therefore carries two distinct legal engines.
| Part | Instrument | Governs |
|---|---|---|
| Part A | Data Sharing Agreement (Article 26) | The Sourcing Phase — joint controllership of candidate data pre-approval |
| Part B | Handoff | The moment of Qualifier Approval and what each party holds afterwards |
| Part C | Data Processing Agreement (Article 28) | Post-approval workspace processing, where PlacementFlow is the processor |
| Part D | Common terms | Security, sub-processors, transfers, term and termination, return-or-delete |
Definitions used throughout: "Customer" means the recruitment agency; "PlacementFlow" means the platform operator; "Candidate Data" means personal data relating to an individual identified, contacted, or screened through the Service; "Sourcing Phase" and "Qualifier Approval" are defined at Sections 1.1 and 3.1. Two annexes complete the instrument: Annex 1 (authorised sub-processors) and Annex 2 (technical and organisational measures).
Part A — Data Sharing Agreement (joint controllership of the Sourcing Phase)
1.1 Parties and roles by phase
| Phase | Processing activities | PlacementFlow | Customer |
|---|---|---|---|
| 1. Sourcing Phase — identification through cold outreach and the qualifier conversation, up to and including recruiter review | Prospect identification against Customer's targeting criteria; contact-data enrichment; cold outreach; qualifier chat; qualifier scoring and flagging; recruiter review | Joint controller (Art. 26) | Joint controller (Art. 26) |
| 2. Handoff (Qualifier Approval) | Disclosure of the candidate record into Customer's workspace | Independent controller of its copy | Independent controller of its copy |
| 3. Workspace Phase — post-approval: stage-2 screening, submission, interview, offer, placement | All recruitment operations conducted by Customer through the Service | Processor (Art. 28) | Controller |
| Customer account data — users, billing, support, telemetry | Account administration, billing, support, service security and improvement | Controller | Data subject / account holder |
1.2 Joint-controller declaration
During the Sourcing Phase, Customer and PlacementFlow are joint controllers within the meaning of Article 26 UK GDPR / GDPR and share responsibility for the Candidate Data processed in that phase. Each party determines, jointly with the other, the purposes and essential means of that processing: Customer determines who is searched for and whether a Candidate proceeds; PlacementFlow determines the platform, channels, message, and conversational instrument through which Candidates are identified and engaged. Neither party acts as the other's processor during the Sourcing Phase.
1.3 Joint purpose and lawful basis
- Purpose: identifying and qualifying candidates for recruitment opportunities.
- Lawful basis: Article 6(1)(f) legitimate interests, assessed per campaign in a Legitimate Interests Assessment that PlacementFlow maintains and makes available to Customer on request. Customer warrants that its targeting criteria are lawful, role-relevant, and free of protected-characteristic proxies.
- No special-category data is knowingly collected in the Sourcing Phase. No national identifier or date of birth is collected at any stage.
- Objection: an objection under Article 21(1) is honoured immediately and permanently by both parties (Section 11).
1.4 Article 26 allocation matrix
| Responsibility | Allocated to | Detail |
|---|---|---|
| Article 13/14 candidate notices | PlacementFlow | Layered notice in the first outreach message (identity, purpose, basis, rights, privacy-notice link) and on every candidate-facing screening surface |
| AI transparency (EU AI Act Article 50) | PlacementFlow | The Candidate is told they are interacting with an AI assistant before the qualifier conversation begins |
| Candidate rights requests — front line | PlacementFlow | Single published contact point; PlacementFlow answers Articles 15, 16, 17, 18, 20 and 21 requests relating to the Sourcing Phase |
| Forwarding duty (both directions) | Both | A party receiving a request or objection that is wholly or partly the other's to answer forwards it within 5 business days of receipt, with enough context to act |
| Response deadline to the data subject | Party answering | One month from receipt by the first party (Art. 12(3)); the forwarding duty does not restart the clock |
| Accuracy | Both | PlacementFlow for data it sources and enriches; Customer for corrections it learns of; each notifies the other of a correction affecting the shared record |
| Security of systems | Each party for its own systems | Section 12 sets the floor; Annex 2 specifies PlacementFlow's measures |
| Retention of the unapproved pool (pre-handoff) | PlacementFlow | Maximum three years from last contact, non-renewing — the period does not reset on further campaign activity (Section 8) |
| Targeting criteria and campaign audience | Customer | Customer is accountable for the lawfulness and role-relevance of what it asks to be searched |
| The decision to progress or decline a Candidate | Customer | Always a human recruiter; PlacementFlow's instrument flags, it does not reject |
| Personal data breach notification (Sourcing Phase) | Party suffering the breach notifies the other without undue delay and in any event within 24 hours | Articles 33 and 34; PlacementFlow notifies the supervisory authority where the breach occurred in its systems |
| Record of processing (Article 30) | Each party for its own record | PlacementFlow maintains its record of processing activities and makes the relevant extract available to Customer on request |
| Data protection impact assessment | PlacementFlow for the platform instrument; Customer for its own deployment where required | Assistance as set out at Section 4.8 |
1.5 Published essence (Article 26(2))
The essence of this arrangement is made available to data subjects in PlacementFlow's privacy policy and in Customer's terms. The published sentence is:
The allocation of responsibilities between PlacementFlow and each agency is set out in our customer terms; regardless of that allocation, you can exercise your rights against either of us.
1.6 Identification of the parties to the Candidate
- PlacementFlow is named to the Candidate from first contact, as the entity processing their data and as the first point of contact for privacy questions.
- Customer is described, not named,prior to Qualifier Approval — as "the specialist recruitment agency running this search". This relies on the Article 13(1)(e) and 14(1)(e) limb permitting "the recipients or categories of recipients". Customer is named to the Candidate at Handoff (Section 3.2).
- Neither party may conceal the identity of the sender of a marketing communication. Marketing this arrangement as "anonymous outreach" is prohibited (PECR regulation 23 and Article 6 of the e-Commerce Directive); the approved framing is "confidential search under our neutral platform identity".
Part B — Handoff
3.1 Definition
"Qualifier Approval" means the moment a human recruiter of Customer approves a Candidate at the qualifier gate in the Service. A Candidate who is not approved never leaves the Sourcing Phase.
3.2 Handoff clause
Upon Qualifier Approval, Customer and PlacementFlow shall each be independent controllers of the respective copies of the Candidate Data. Each party is thereafter separately and independently responsible for its own copy, including for its own lawful basis, notices, retention, security, and responses to data subject requests in respect of that copy. Neither party is liable for the other's compliance in respect of the other's copy.
3.3 Notice at Handoff
At or before the first disclosure of the Candidate Data into Customer's workspace (Article 14(3)(c)), PlacementFlow delivers a transfer notice to the Candidate that:
- names Customer;
- states that PlacementFlow handled the Candidate's data up to that point and that Customer is responsible from that point;
- links Customer's privacy notice.
Customer owes the Candidate its own Article 14 notice within one month of receipt. This duty is non-delegable— PlacementFlow's transfer notice does not discharge it. Customer shall maintain a privacy notice at a stable URL and keep the URL supplied to PlacementFlow current.
3.4 Where PlacementFlow's copy sits after Handoff
PlacementFlow retains its own copy as an independent controller for platform operation, suppression, audit, and security. PlacementFlow's copy is subject to the segregation clause at Section 9.
Part C — Data Processing Agreement (Workspace Phase, Article 28)
For all processing in the Workspace Phase, Customer is the controller and PlacementFlow is Customer's processor.This Part is the parties' agreement under Article 28(3) UK GDPR / GDPR. Where this Part conflicts with Part A or Part B in respect of Sourcing-Phase processing, Parts A and B prevail: PlacementFlow is notCustomer's processor before Qualifier Approval (Section 4.2.3).
4.1 Subject-matter, duration, nature and purpose
| Element | Specification |
|---|---|
| Subject-matter | Provision of the PlacementFlow recruitment platform (the "Service") to Customer, and the processing of personal data necessary to provide it in the Workspace Phase |
| Duration | From the earlier of Customer's first use of the Service and the effective date of the Terms of Service, until the later of (a) termination of the Terms of Service and (b) completion of the return-or-delete process at Section 4.9 |
| Nature of the processing | Collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure by transmission to Customer's own recipients, alignment, combination, restriction, erasure and destruction — by automated means, including AI inference on text |
| Purpose of the processing | Conducting Customer's recruitment operations: stage-2 screening and scoring, candidate records and notes, CV handling, submission of candidates to Customer's clients, interview scheduling and analysis, offers, placements, invoicing records, client-portal collaboration, and Customer's own outreach from Customer's own mailbox |
| Type of personal data | Identity and contact data; professional history, skills, qualifications and CV content; screening answers, scores, flags and recruiter notes; interview scheduling data, recordings and transcripts where Customer enables them; offer and placement terms; communications content and metadata on Customer's warm channels |
| Categories of data subjects | Candidates whose records have reached Qualifier Approval or whom Customer itself enters into the Service; Customer's own personnel (users); contacts at Customer's client companies |
| Special-category data | Not requested, not required, and not knowingly processed. National identifiers, date of birth and salary history are never collected by the Service. Customer must not upload special-category data into free-text fields; if it does, it does so as controller and warrants it has a lawful basis under Article 9 |
| Obligations and rights | Customer's obligations and rights as controller are as set out in the Terms of Service, this instrument, and applicable data protection law |
4.2 Documented instructions (Article 28(3)(a))
4.2.1 Scope of instructions
PlacementFlow processes Workspace-Phase personal data only on Customer's documented instructions, including as regards transfers to a third country. The following constitute Customer's documented instructions, and no others are required for PlacementFlow to provide the Service:
- the Terms of Service, this instrument, and any order form;
- Customer's configuration of, and use of, the Service and its features by Customer's authorised users — including campaign configuration, questionnaire authoring, submission and interview actions, integration enablement, and retention settings;
- support requests submitted by Customer's authorised users.
4.2.2 Unlawful instructions
PlacementFlow shall inform Customer without undue delay if, in its opinion, an instruction infringes applicable data protection law, and may suspend performance of the affected instruction until it is confirmed, amended, or withdrawn. PlacementFlow is not obliged to give, and does not give, legal advice on Customer's instructions.
4.2.3 Joint-phase carve-out — this clause does not reach the Sourcing Phase
Processing in the Sourcing Phase (identification, enrichment, cold outreach, the qualifier conversation, qualifier flagging, and recruiter review up to and including Qualifier Approval) is governed by Part A and is notperformed on Customer's instructions as processor. In that phase:
- each party acts as a joint controller in its own right (Section 1.2), and PlacementFlow determines the platform, channels, sender identity, master outreach copy, and the conversational instrument;
- Customer's contribution to that phase — its targeting criteria and its approve or decline decisions — is exercised as a controller, not as controller instructions to a processor, and Customer is accountable for it under Section 1.4;
- accordingly, Customer may not instruct PlacementFlow to alter the sourcing sender identity, the master outreach copy, the cold geographic allowlist, the suppression list, or the AI-transparency and privacy notices delivered to Candidates. Those are PlacementFlow's controller decisions and several of them are safety controls (Annex 2);
- PlacementFlow's own retention of, and access to, Sourcing-Phase data as a controller of that phase (for platform operation, quality assurance, debugging, security, and suppression) is not Workspace-Phase processing and is not restricted by this Part. It remains subject to Section 9 (segregation) and Section 10 (confidentiality).
4.2.4 PlacementFlow's own controller processing
PlacementFlow processes Customer account data (users, billing, support, security telemetry, aggregated and de-identified service statistics) as an independent controller under its privacy policy (Section 1.1, final row). That processing is outside this Part.
4.3 Personnel and confidentiality (Article 28(3)(b))
PlacementFlow ensures that every person it authorises to process Workspace-Phase personal data:
- is subject to a written duty of confidentiality that survives the end of their engagement, whether by contract of employment, contractor agreement, or statutory duty;
- has access only where necessary for a defined purpose, on the least-privilege basis described in Annex 2;
- has received data protection and security awareness instruction appropriate to their role;
- has their access revoked promptly on role change or departure.
Platform-administrator access to a customer workspace is an audited, impersonation-flagged action: security, credential, and billing-sensitive actions are blocked outright while impersonating, and the impersonation trail is retained (Annex 2, item 6).
4.4 Security (Articles 28(3)(c) and 32)
PlacementFlow implements and maintains the technical and organisational measures set out in Annex 2, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing as well as the risk to data subjects. PlacementFlow may change a measure provided the change does not materially reduce the overall level of security. Annex 2 measures apply to the systems under PlacementFlow's control; Customer is responsible for its own devices, accounts, credential hygiene, and its users' access decisions.
4.5 Sub-processors (Articles 28(2) and 28(3)(d))
4.5.1 General authorisation. Customer gives PlacementFlow general written authorisation to engage sub-processors. The sub-processors authorised at the date of this version are listed in Annex 1.
4.5.2 Flow-down.PlacementFlow imposes on each sub-processor, by written contract, data protection obligations no less protective than those in this Part, including the Article 32 measures appropriate to what that sub-processor does. PlacementFlow remains fully liable to Customer for a sub-processor's performance of its data protection obligations.
4.5.3 Change notice and objection. PlacementFlow gives Customer at least 30 days' noticebefore a new sub-processor begins processing Workspace-Phase personal data, or before an existing sub-processor's role materially changes, by updating Annex 1 and the published sub-processor list and notifying Customer's registered administrator contact. Customer may object on reasonable data protection grounds within that 30-day period. The parties shall then discuss the objection in good faith; if PlacementFlow cannot offer a reasonable alternative or safeguard, Customer may terminate the affected part of the Service, or the Terms of Service, without penalty and with a pro-rata refund of prepaid fees for the unused period. An unobjected-to change takes effect on expiry of the notice period.
4.5.4 Emergency replacement.Where a sub-processor must be replaced urgently to preserve security or service continuity, PlacementFlow may engage the replacement before the notice period expires and shall notify Customer as soon as practicable; Customer's objection right under Section 4.5.3 then applies retrospectively.
4.6 Assistance with data subject rights (Article 28(3)(e))
PlacementFlow shall not respond to a Workspace-Phase data subject request itself except on Customer's instruction or where required by law, and shall instead forward it to Customer without undue delay and in any event within 5 business days of identifying it. Taking into account the nature of the processing, PlacementFlow assists Customer in fulfilling requests under Articles 15 to 22 by:
- the self-service export, correction, restriction, erasure, and objection controls available to Customer's administrators in the Service;
- the candidate portal, which lets a candidate see and act on their own record;
- reasonable additional assistance where the Service's own controls cannot satisfy a request, chargeable at PlacementFlow's then-current professional-services rate only where the request volume is manifestly disproportionate.
Requests relating to the Sourcing Phaseare answered by PlacementFlow at first line under Sections 1.4 and 11 — Customer must not refuse such a request on the ground that PlacementFlow is the "real" controller, and vice versa (Article 26(3)).
4.7 Personal data breach (Articles 28(3)(f) and 33(2))
PlacementFlow notifies Customer of a personal data breach affecting Workspace-Phase personal data without undue delay and in any event within 48 hours of becoming aware of it."Awareness" means PlacementFlow has a reasonable degree of certainty that a security incident has led to a compromise of personal data. The notice shall include, to the extent then known: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point. Where the information is not all available at once, PlacementFlow provides it in phases without further undue delay.
PlacementFlow shall not notify a supervisory authority or a data subject on Customer's behalfin respect of Workspace-Phase data unless Customer instructs it to or the law requires it; Article 33 and 34 decisions for that data are Customer's. For Sourcing-Phase breaches, Section 14 applies instead and the mutual notification window is 24 hours. Neither party makes a public statement identifying the other in connection with a breach without prior consultation, save where required by law.
4.8 Impact-assessment and prior-consultation assistance (Articles 35 and 36)
PlacementFlow assists Customer, on reasonable request and taking into account the nature of the processing and the information available to it, with:
- data protection impact assessments concerning Customer's use of the Service — by supplying the platform impact assessment, the EU AI Act technical documentation pack, the relevant extract of PlacementFlow's record of processing activities, Annex 1, and Annex 2;
- prior consultation with a supervisory authority under Article 36, including responding to reasonable follow-up questions on the platform's processing;
- Customer's own Article 30 record and its EU AI Act deployer obligations for stage-2 scoring and interview analysis (Section 5).
PlacementFlow's assistance does not transfer Customer's accountability for its own assessment.
4.9 Return or deletion at termination (Article 28(3)(g))
At Customer's election, PlacementFlow returns Workspace-Phase personal data in a commonly used machine-readable format, or deletes it, and deletes existing copies:
- Election window. Customer may elect export, deletion, or both at any time up to 30 daysafter the effective date of termination. Self-service export remains available to Customer's administrators throughout that window.
- Default. Absent an election, PlacementFlow deletes Workspace-Phase personal data within 30 days of the end of the retention window stated in the Terms of Service.
- Backups. Deletion propagates through backups as those backups expire on their ordinary rotation cycle. PlacementFlow does not restore deleted data from backup for its own purposes, and re-applies the deletion if a restore occurs for any other reason.
- Carve-outs. The following survive and are not returned or deleted under this clause:
- suppression records — the minimal record needed to honour an objection or opt-out (contact identifier, reason, timestamp), retained for as long as necessary to honour it (Sections 8 and 15). Deleting one would cause the individual to be contacted again, so neither party may delete it;
- PlacementFlow's own Sourcing-Phase copy, which is retained and deleted under Section 8 (maximum three years from last contact, non-renewing) and, after Handoff, under Sections 3.4 and 15 as PlacementFlow's independent-controller copy — not under this clause;
- records PlacementFlow must keep by law (billing and tax records, audit and security logs, records needed to establish or defend legal claims), retained for the statutory or limitation period and then deleted;
- aggregated, de-identified statistics that cannot reasonably be re-identified.
- Confirmation. PlacementFlow confirms completion in writing on request.
4.10 Audit and information rights (Article 28(3)(h))
4.10.1 Reports first.PlacementFlow makes available the information necessary to demonstrate compliance with this Part — Annex 1, Annex 2, the platform impact assessment, the relevant extract of its record of processing activities, the EU AI Act documentation pack, any security-testing and vulnerability-management summaries PlacementFlow holds, and its sub-processors' own certifications and audit reports where PlacementFlow is permitted to share them. Customer shall accept these where they reasonably address the subject of the audit.
4.10.2 On-site or on-system audit.Where the documentation in Section 4.10.1 does not reasonably address the subject, Customer (or an independent auditor mandated by Customer, who is not a competitor of PlacementFlow and who is bound by confidentiality) may audit PlacementFlow's processing:
- on at least 30 days' prior written notice;
- during business hours, with minimum disruption, and subject to PlacementFlow's security, safety, and confidentiality requirements;
- no more than once in any 12-month period, save where Customer's supervisory authority requires more, or following a personal data breach affecting Customer's data, in which case one additional audit may be conducted;
- scoped to Customer's own data and to the systems processing it — never to another customer's data, to multi-tenant data PlacementFlow cannot segregate for the purpose, or to third-party confidential information;
- at Customer's cost, including PlacementFlow's reasonable time, except where the audit reveals a material breach of this Part by PlacementFlow.
4.10.3 Regulators.PlacementFlow cooperates with a supervisory authority exercising its own powers in respect of Customer's data, and informs Customer of any binding request concerning Customer's data unless prohibited by law.
4.11 International transfers (Chapter V)
4.11.1 Primary location.Customer's Workspace-Phase personal data is hosted in the United Kingdom / EEA, and Customer agencies and their candidates are, as currently structured, UK/EEA-based. Cold outreach is confined to the geographies on PlacementFlow's cold-outreach allowlist.
4.11.2 Sub-processors outside the UK/EEA. Some sub-processors in Annex 1 process personal data in the United States — stated plainly: Z.AI (AI inference), OpenAI (outage fallback only), Twilio (SMS), Meta Platforms (WhatsApp Cloud API messaging), Stripe (billing — customer and account data, never candidate screening data), and PandaDoc (e-signature). Others operate multi-region infrastructure with US-based operational support. Annex 1 states the processing location for each entry.
4.11.3 Transfer mechanisms. Where personal data is transferred out of the UK or the EEA to a country without an adequacy decision, the transfer is made under, and the parties incorporate into this instrument by reference:
- the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) for the Workspace Phase, and Module One (controller to controller) where the relationship is controller-to-controller under Parts A and B — with Clause 7 (docking) included, Clause 9(a) Option 2(general written authorisation, 30 days' notice, per Section 4.5.3), Clause 11(a)'s optional independent-redress body not selected, Clause 17 governed by the law of Ireland, and Clause 18(b) forum Ireland;
- the UK International Data Transfer Addendum to those clauses (UK Addendum, version B1.0), or the UK IDTAwhere the parties agree to use it instead, for UK-origin transfers, with Tables 1 to 4 completed from this instrument and Table 4 "Importer" not selected;
- Annex I (parties and description of transfer), Annex II (technical and organisational measures), and Annex III (sub-processors) of the Standard Contractual Clauses are populated by Section 4.1, Annex 2, and Annex 1 respectively.
4.11.4 Transfer risk assessment. PlacementFlow maintains a transfer risk assessment for each transfer relying on Section 4.11.3 and makes it available to Customer on request. If a mechanism is invalidated or a sub-processor can no longer be used lawfully, PlacementFlow shall without undue delay implement an alternative safeguard or cease the transfer.
4.11.5 Government access requests. PlacementFlow notifies Customer of any legally binding request from a public authority for Workspace-Phase personal data unless prohibited, challenges requests that appear unlawful or overbroad, and discloses only the minimum required.
4.12 Liability
Each party's liability under this Part is subject to the limitations and exclusions of liability in the Terms of Service, which apply to this instrument as if set out in it — save that nothing in this instrument limits liability that cannot lawfully be limited, and save that where the Standard Contractual Clauses apply, the liability provisions of those Clauses prevail as between the parties to the extent of any conflict, in respect of the transferred data only. Nothing in this Part limits a data subject's rights against either party under Article 26(3) or Article 82.
4.13 Order of precedence
This instrument prevails over the Terms of Service in respect of the processing of personal data. Within this instrument: Parts A and B prevail over Part C for Sourcing-Phase processing (Section 4.2.3); Part D applies to all Parts; and where the Standard Contractual Clauses apply, those Clauses prevail over this instrument to the extent of a conflict in respect of transferred data.
5. AI-specific processor terms
- No Candidate Data is used to train or fine-tune any model. All AI processing is stateless inference via the provider API.
- Automated scoring produces a flag or a score for human review; it never rejects a Candidate. Disqualified status is set exclusively by a human recruiter.
- Under the EU AI Act, PlacementFlow is provider and deployer of the qualifier and intake conversational engine in the Sourcing Phase; Customer is the deployer of stage-2 scoring and interview analysis in the Workspace Phase.
Part D — Common terms
6. ICO Data Sharing Code — checklist coverage
The Information Commissioner's Data Sharing Code of Practice requires a data sharing agreement to address the following. Coverage in this instrument:
| ICO checklist item | Covered at | Note |
|---|---|---|
| Purpose of the sharing | 1.3 | Identifying and qualifying candidates for recruitment opportunities |
| Which data items are shared | 7 | Enumerated below |
| Lawful basis of each party | 1.3, 3.2 | Article 6(1)(f) in the Sourcing Phase; each party's own basis for its copy after Handoff |
| Who the parties are and their roles | 1.1, 1.2 | Phase table plus joint-controller declaration |
| Single contact point for individuals | 1.4, 1.5 | PlacementFlow, published in the privacy policy; rights exercisable against either party |
| Data quality and accuracy | 1.4 | Mutual correction-notification duty |
| Retention and deletion | 1.4, 8, 15 | Three-year non-renewing cap pre-handoff; independent retention post-handoff |
| Deletion and objection propagation | 1.4, 11 | Five-business-day forwarding duty, both directions |
| Security standards | 12, Annex 2 | Each party for its own systems; stated floor |
| Individuals' rights and how they are handled | 1.4, 4.6, 11 | Front-line with PlacementFlow pre-handoff |
| Breach handling | 1.4, 4.7, 14 | 24-hour mutual notification in the Sourcing Phase; 48 hours to Customer in the Workspace Phase |
| Review of the agreement | 16 | Annually, or on any material change to the flow |
| What happens on termination (return or delete) | 4.9, 15 | Return-or-delete, with a carve-out only for suppression and legally required records |
7. Data items shared
| Category | Items | Source |
|---|---|---|
| Identity | Name | Public professional profile |
| Professional | Current and prior job titles, employer, seniority, location (country or region), publicly stated skills | Public professional profile |
| Contact | Business email address; phone number where the Candidate supplies it by contacting us | Enrichment providers; Candidate-supplied |
| Engagement | Outreach and reply history, message timestamps, opt-out and suppression status | Platform |
| Qualifier | Free-text answers to qualifier questions, must-know flags, qualifier score where applicable | Candidate-supplied |
Not shared and not collected: national identifiers, date of birth, salary history, and special-category data.
8. Retention of the unapproved pool
Candidate Data for a Candidate who has not reached Qualifier Approval is deleted no later than three years from the date of last contact with that Candidate. The period is finite and non-renewing: subsequent campaign activity does not extend it. On objection or erasure, deletion happens sooner. A minimal suppression record (contact identifier, suppression reason, timestamp) survives deletion and is retained for as long as necessary to honour the objection — deleting it would cause the individual to be contacted again.
9. Segregation clause
Personal data that PlacementFlow processes on Customer's behalf as a processor is never used to build or enrich PlacementFlow's own talent network, prospect database, or any product offered to other customers.
10. Confidentiality of the Customer relationship
PlacementFlow shall not disclose Customer's identity to a Candidate before Qualifier Approval, save where disclosure is required by law or is necessary to answer a data subject request that cannot otherwise be answered. This confidentiality operates in favour of Customer's own end clients absolutely: the identity of Customer's hiring client is never disclosed to a Candidate by PlacementFlow.
11. Data subject requests — mechanics
- Published contact point: privacy@placementflow.com; self-service erasure at placementflow.com/candidate-portal/erasure-request.
- A request received by either party that engages the other is forwarded within 5 business days.
- The receiving party acknowledges the forward and confirms the action taken.
- Neither party may refuse a request on the ground that the other party is the "real" controller of the Sourcing Phase — Article 26(3) makes the right exercisable against either.
12. Security floor
Encryption in transit (TLS 1.2 or higher) and at rest; role-based access control on least privilege; authenticated and logged administrative access; personnel confidentiality obligations; documented incident response. Each party warrants this floor for the systems under its control. PlacementFlow's own measures are specified in full at Annex 2, which also serves as the Article 32 schedule for Part C (Section 4.4).
13. Sub-processors and onward parties
PlacementFlow engages sub-processors under written terms no less protective than these. The authorised list is Annex 1, mirrored in the privacy policy and updated on change. Customer may object to a new sub-processor on reasonable data protection grounds, on the 30-day notice and objection mechanics at Section 4.5.3.
Cold-outreach execution:the cold-outreach partner executes the Sourcing Phase on PlacementFlow's behalf as PlacementFlow's processor, not as a joint controller with Customer. Customer has no direct relationship with it.
14. Personal data breach
Each party notifies the other without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting shared Candidate Data, with sufficient detail for the other to meet its own Article 33 and 34 obligations. Neither party makes a public statement identifying the other in connection with a breach without prior consultation, save where required by law. The Workspace-Phase notification duty is at Section 4.7.
15. Term, termination, and return-or-delete
This instrument runs for as long as either party processes Candidate Data arising from the Service. On termination:
- Workspace Phase (processor) data:returned to Customer in a machine-readable format or deleted, at Customer's election, on the mechanics at Section 4.9.
- Sourcing Phase data:PlacementFlow deletes its unapproved pool for that Customer's campaigns on the Section 8 schedule or on termination, whichever is earlier.
- Independent copies after Handoff:each party retains and deletes its own copy under its own policy; termination does not create a duty to delete the other party's copy.
- Suppression records survive termination (Section 8) and may not be deleted by either party.
- Sections 9 (segregation), 10 (confidentiality), 14 (breach), and 4.12 (liability) survive termination.
16. Review
Reviewed annually, and on any material change to the sourcing flow, the handoff point, the geographic scope of cold outreach, or the AI instrument used in the qualifier conversation.
17. International transfers
The customer relationshipis UK/EEA to UK/EEA as currently structured: PlacementFlow and its customers operate within the UK/EEA, Workspace-Phase data is hosted in the UK/EEA, and cold outreach is confined to PlacementFlow's allowlisted geographies.
Some sub-processors nevertheless process personal data in the United States (Annex 1 states the location for each; Z.AI, OpenAI, Twilio, Meta Platforms, Stripe and PandaDoc are the plainly US-processing entries). Those transfers are made under the mechanisms incorporated by reference at Section 4.11.3 — EU Standard Contractual Clauses Module Two for processor transfers and Module One where the relationship is controller-to-controller, plus the UK Addendum or UK IDTA for UK-origin transfers — with a transfer risk assessment per Section 4.11.4. Section 4.11 is the operative text; this section is the Part D signpost to it.
Annex 1 — Authorised sub-processors (as at 29 July 2026)
Authorised under Section 4.5.1. A change to this Annex is notified under Section 4.5.3 (30 days' notice, right to object). "Via FlexIQ" means the entity is engaged by PlacementFlow's cold-outreach sub-processor rather than by PlacementFlow directly; PlacementFlow remains liable for it under Section 4.5.2.
| Sub-processor | Purpose | Data categories | Processing location |
|---|---|---|---|
| FlexIQ | Cold-outreach orchestration — runs the Sourcing Phase on PlacementFlow's behalf: campaign execution, sequence scheduling, reply capture, opt-out and bounce suppression | Candidate identity, professional and contact data; outreach and reply history | UK/EEA, with onward providers as listed below |
| Smartlead (via FlexIQ) | Email delivery — sends cold outreach and follow-ups from FlexIQ's managed sender pool and returns delivery and reply events | Candidate name, business email address, message content and delivery metadata | United States |
| JustLinked (via FlexIQ) | Prospect sourcing and business-email enrichment against public professional profiles | Candidate name, employer, job title, seniority, location, derived business email | EEA / United States |
| Supabase | Managed PostgreSQL database — the primary system of record for the Service | All personal data processed by the Service | EEA (project database region), with vendor operational support access |
| Vercel | Application hosting, serverless execution, edge delivery and platform analytics | All personal data in transit through the application; request and usage telemetry | United States and regional edge locations |
| Resend | Transactional platform email only — account, notification, billing and system messages (never cold outreach) | Recipient name and email address, message content | United States |
| Twilio | SMS delivery — screening links, availability and interview notifications | Mobile number, message content, delivery metadata | United States |
| Meta Platforms (WhatsApp Business Cloud API) | WhatsApp messaging — the candidate-facing qualifier and screening conversation channel | WhatsApp phone number, profile name, message content | United States |
| Z.AI | AI processing — stateless inference for the qualifier and screening conversation, scoring, classification, summarisation and drafting | Text submitted for inference: screening answers, message bodies, CV text | Singapore (see note 2) |
| OpenAI | AI processing — outage fallback only, used when the primary provider is unavailable | As above, only for requests failed over during an outage | United States |
| Stripe | Billing and subscription management — customer and account data only; no candidate data | Customer billing contact, payment method tokens, invoice and subscription records | United States and Ireland |
| MeetingBaas | Interview recording and transcription, where Customer enables it for an interview | Interview audio and video, transcript, participant names | EEA |
| PandaDoc | E-signature for offer documents | Signatory name and email, offer document content, signature audit trail | United States |
| Sentry | Error monitoring and diagnostics (supporting measure; personal data only incidentally, in error context) | Request and user identifiers in error payloads | United States and EEA |
Note 1 — processing locations are provider-documented.Each location above is derived from the provider's public documentation and PlacementFlow's own configuration. Confirming each against a countersigned data processing agreement with every provider is in progress.
Note 2 — Z.AI processing region.Z.AI's international API platform is operated by JINGSHENG HENGXING TECHNOLOGY PTE. LTD (Singapore); per its published privacy policy, customer data is generally processed in Singapore, API content is deleted after serving the request, and API inputs are not used for model training. Singapore has no EU adequacy decision, so the Section 4.11.3 transfer mechanism applies to this entry.
Note 3 — cold-outreach chain. FlexIQ executes the Sourcing Phase as PlacementFlow's processor, not as a joint controller with Customer, and Customer has no direct relationship with it or with its onward providers (Section 13).
Annex 2 — Technical and organisational measures (Article 32)
The measures below are the ones actually implemented in the Service. They also populate Annex II of the Standard Contractual Clauses (Section 4.11.3).
| # | Measure | What is in place |
|---|---|---|
| 1 | Encryption in transit | TLS 1.2 or higher (TLS 1.3 where the client supports it) on every application, API, webhook and database connection; HTTPS enforced platform-wide |
| 2 | Encryption at rest | AES-256 at the managed database and storage layer. In addition, high-value secrets — OAuth mailbox and calendar tokens above all — are encrypted at the application layer with AES-256-GCM under a versioned key before being written, so read access to the database alone does not yield a usable mailbox token |
| 3 | Tenant isolation | Every tenant-scoped record carries an agency identifier, and every query path is scoped by it. Cross-tenant reads are structurally prevented rather than filtered in the interface; tenant-scoped ownership checks additionally guard identifiers supplied by a caller |
| 4 | Role-based access, least privilege | Distinct roles (owner, admin, manager, recruiter) with permission checks enforced server-side, not merely in the interface; desk-level visibility resolved through a single source of truth so a recruiter sees only the desks they are entitled to; work-creating actions additionally gated by an operator licence check |
| 5 | Authentication and session control | Database-backed sessions with httpOnly cookies; email verification required on password signup; Microsoft OAuth as the primary sign-in path; scoped, expiring, HMAC-signed capability tokens for every candidate- and client-facing public link, with per-feature signing secrets |
| 6 | Audit logging and impersonation trail | Lifecycle and security-relevant actions are written to an append-only audit log with the acting user recorded (a null actor means system or AI and is never faked). Platform-administrator impersonation of a customer workspace is flagged and logged, and credential, billing and security actions are refused outright while impersonating |
| 7 | Fail-closed suppression | Every outbound send path checks the global and agency suppression lists first, normalised case-insensitively, and fails closed on error — a database failure blocks the send rather than allowing it. Suppression triggers are spam classification, hard bounce, a soft-bounce threshold, and explicit unsubscribe or objection |
| 8 | Kill switch | A per-agency flag halts all AI-initiated outreach immediately. Because cold campaigns run on external infrastructure, the switch explicitly pauses them too, awaited and retried rather than fire-and-forget; the inbound webhook self-heals if an event arrives for an unpaused campaign. Any automation that sleeps re-checks the switch at run time before each send |
| 9 | Integrity of inbound events | HMAC-SHA256 signature verification on inbound webhooks, failing closed on an invalid or missing signature; rate limiting on public routes and on keyed identifiers such as email, IP address and token |
| 10 | Output and injection handling | HTML escaping in warm-email composition; prompt-injection markers in inbound candidate or client replies are routed to human review rather than acted on |
| 11 | Data minimisation by design | National identifiers, date of birth and salary history are never collected. Screening is text-only by deliberate design — no voice or emotion analysis, so no voiceprints or inferred emotional state are ever processed. Automated-processing opt-outs recorded against a candidate are honoured by the scorer, CV screening and comparison surfaces |
| 12 | No training on customer or candidate data | All AI processing is stateless inference via provider APIs. No candidate or customer data is used to train or fine-tune any model (Section 5) |
| 13 | Human-in-the-loop safeguards | Automated scoring produces a flag or score for human review and never rejects a candidate; a failed or missing must-know answer flags, and disqualification is set exclusively by a human recruiter. Compensation and counter-offer messages are always routed to a human. Degraded-AI states surface visibly in the interface rather than silently defaulting |
| 14 | Segregation of processor data | Data processed on Customer's behalf is never used to build or enrich PlacementFlow's own talent network, prospect database, or any product offered to another customer (Section 9) |
| 15 | Monitoring and incident response | Error and exception monitoring with environments kept separate so production triage is not polluted by preview data; a global background-job failure handler surfaces automation failures rather than swallowing them; documented incident response with the notification duties at Sections 4.7 and 14 |
| 16 | Resilience and recovery | Managed PostgreSQL with vendor-operated backups and point-in-time recovery; stateless application tier on managed hosting; deletion re-applied after any restore (Section 4.9.3) |
| 17 | Change management | Typed schema with versioned, generated migrations; static type and lint gates plus an automated test suite enforced pre-commit; staging-first deployment; AI prompt changes gated behind an evaluation harness |
| 18 | Personnel | Written confidentiality duties surviving termination, least-privilege access provisioning, prompt revocation on role change or departure (Section 4.3) |
Contact
Data protection questions, sub-processor objections, audit requests, and requests for a countersigned copy: privacy@placementflow.com. Candidates can also read the candidate-facing privacy policy or its French-language version.