Skip to content
CandidateBrief
Menu
Sign in
Start free trial
Legal

Data processing agreement

The processor terms that apply to personal data uploaded by an agency. This summary is what the agreement commits to; a signature-ready copy is available on request.

The English text is the authoritative version of this document. It is not translated, because four translations of a legal notice are four texts that can disagree.

Roles

The agency is the controller. The operator of candibrief.com is the processor, and acts only on the agency's documented instructions — which are the operations the service performs when a member uses it.

The agency decides what is uploaded, why, how long it is kept within the retention window, and who it is shared with.

Security measures

Encryption in transit for every connection. Encryption at rest by the storage and database providers. Row-level security in the database, so a query that loses its workspace filter returns nothing rather than another agency’s rows. Access control that is re-read on every request. An audit trail of every field a person changed, with the reason and their name.

Sub-processors

The current list with regions is on the sub-processors page. A change is announced to workspace owners before it takes effect.

  • A PostgreSQL database provider — structured data: candidates, facts, review decisions and access logs.
  • An S3-compatible object storage provider — uploaded originals and generated documents, in a private bucket. Every read goes through an authorised route.
  • A transactional email provider — recipient address and message body. Messages carry a verification or invitation link and never candidate content.
  • A model provider, only when a workspace switches the drafting assistant on. It receives the structured profile, never the original uploaded file. Off by default.
  • A content delivery network — request metadata for the application itself. No candidate data.
  • Waffo — payment processing, receipts and tax. It never receives candidate data.

Assistance and breach notification

The processor assists the agency in answering a data subject request, and notifies the agency without undue delay after becoming aware of a personal data breach affecting its data.

Deletion on termination

On termination the agency may export everything it holds. After the retention window the data is deleted, including backups on their own cycle. A record that a deletion happened is kept, without the data.