Data Processing Agreement
Last updated: 8 August 2025 | Version 1.1 | Applies to: UK GDPR, EU GDPR (Regulation 2016/679) & Data Protection Act 2018
1. Parties
| Data Controller | The organisation, company, or individual that has registered for and is using the CVAtlas platform to upload and process curriculum vitae data (“the Controller”, “you”, or “your”). |
| Data Processor | CVAtlas (“we”, “us”, or “our”), the operator of the CVAtlas platform at cvatlas.com, reachable at support@cvatlas.com. |
2. Definitions
Terms used in this DPA have the meanings given in the UK General Data Protection Regulation (UK GDPR, as retained in UK law by the European Union (Withdrawal) Act 2018 and amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019), the Data Protection Act 2018 (“DPA 2018”), and/or the EU General Data Protection Regulation (EU GDPR, Regulation (EU) 2016/679), as applicable.
- Personal Data — any information relating to an identified or identifiable natural person contained within the CV files uploaded by the Controller.
- Processing — any operation performed on Personal Data, including storage, analysis, scoring, extraction, and deletion.
- Sub-processor — any third-party processor engaged by CVAtlas to process Personal Data on the Controller’s behalf (see Annex B).
- Supervisory Authority — the Information Commissioner’s Office (ICO) for UK-based Controllers; the relevant EU Data Protection Authority for EU-based Controllers.
3. Subject-Matter and Nature of Processing
CVAtlas processes Personal Data solely to provide its CV bulk-scoring and reporting service. The specific activities are:
- Receiving and temporarily storing uploaded CV files (PDF or ZIP) in encrypted Azure Blob Storage.
- Extracting text from CV files using Optical Character Recognition (OCR) where required.
- Analysing extracted text using AI-assisted scoring against a job description supplied by the Controller.
- Generating AI-powered Talent Insights (gap analysis, skill scoring, interview questions) using OpenAI via Microsoft Azure OpenAI Service.
- Temporarily caching AI enrichment results — stored in memory, on disk, and in the CVAtlas database — to avoid repeated AI calls and reduce cost. Cache entries are stored per batch (not per individual) and expire automatically after the retention window defined in Clause 8. All caches are permanently wiped when the Controller deletes a batch.
- Generating a ranked PDF report returned exclusively to the Controller.
- Deleting all source files, extracted text, and AI enrichment data within the retention period defined in Clause 8.
4. Controller’s Obligations
The Controller warrants and represents that:
- It has a valid and lawful basis under UK/EU GDPR Article 6 (and, where applicable, Article 9) for sharing the Personal Data with CVAtlas.
- It has informed data subjects (CV applicants) that their CVs may be processed using automated AI tools, or is exempt from doing so under a legitimate recruitment-process exception.
- It will not upload CVs of individuals who are under 18 years of age.
- It will comply with its own obligations as a Controller under applicable data protection law.
- It will immediately notify CVAtlas if it becomes aware that any data uploaded has been obtained unlawfully.
- It has the authority to bind the Controller to this DPA.
5. Processor’s Obligations (CVAtlas)
CVAtlas, as the Processor, shall:
- Process Personal Data only on documented instructions from the Controller (i.e., the job description and scoring parameters provided at upload time) and not for any other purpose.
- Ensure that persons authorised to process Personal Data have committed to confidentiality or are under a statutory obligation of confidentiality.
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (see Clause 7).
- Not engage a Sub-processor without giving the Controller at least 14 days’ prior written notice of the intended change, providing the Controller with the opportunity to object before the new Sub-processor begins processing. Current Sub-processors are listed in Annex B.
- Assist the Controller, by appropriate technical and organisational measures, in fulfilling its obligation to respond to requests from data subjects exercising their rights under UK/EU GDPR.
- Notify the Controller without undue delay (and no later than 36 hours after discovery) upon becoming aware of a Personal Data Breach affecting the uploaded data.
- Delete or return all Personal Data to the Controller at the end of the service and delete existing copies in accordance with Clause 8.
- Make available all information necessary to demonstrate compliance with the obligations laid down in UK GDPR Article 28 / EU GDPR Article 28, and allow for audits as described in Clause 10.
6. Purpose Limitation and Processing Instructions
CVAtlas shall process Personal Data solely for the purpose of providing the CV scoring and reporting service. CVAtlas shall never:
- Use uploaded CV data to train AI models, unless the Controller has given explicit, separate written consent.
- Share, sell, or license CV data to any third party other than the Sub-processors listed in Annex B.
- Use the data for advertising, marketing, or any purpose unrelated to the agreed service.
- Transfer Personal Data to a country outside the UK or EEA without an appropriate safeguard being in place (see Clause 9).
7. Security Measures
CVAtlas has implemented and maintains the following technical and organisational measures:
- Encryption in transit: All data is transmitted over TLS 1.2 or higher.
- Encryption at rest: All CV files are stored in Microsoft Azure Blob Storage with Azure Storage Service Encryption (AES-256).
- Access control: CV files are accessible only to the authenticated employer account that uploaded them. Temporary Shared Access Signatures (SAS) are used with short expiry windows.
- Queue security: Processing queue messages are stored in Azure Queue Storage with encryption at rest and in transit.
- Logical isolation: Each batch is keyed by a UUID; no batch can be accessed by another Controller’s account.
- Penetration testing: The application undergoes security review prior to major releases.
- Staff access: No CVAtlas employee has routine access to CV content. Access is granted only for debugging under a break-glass policy with audit logging.
- Incident response: CVAtlas maintains documented incident-response procedures covering detection, containment, investigation, notification, and post-incident review. Procedures are reviewed at least annually.
8. Retention and Deletion
| Data Category | Retention Period |
|---|---|
| Uploaded CV source files (original PDF / ZIP blobs) | Deleted automatically upon completion of the processing batch — typically within minutes to hours. |
| Extracted text & AI scoring results | Maximum 90 days from batch completion to allow report re-download, then permanently deleted. Deleted immediately if the Controller triggers “Delete Batch”. |
| Customer account data (profile, settings, job descriptions) | Duration of active account, plus up to 2 years after account closure for legal and dispute-resolution purposes, then deleted. |
| Billing and transaction records | 7 years from transaction date (legal requirement under UK tax and accounting law). |
| Backup copies | Retained for up to 30 days in encrypted backups before rotation. Deleted data may persist in backups for up to 30 days. |
| Anonymised aggregated statistics (e.g., number of CVs processed) | Retained indefinitely. This data cannot identify any individual and does not constitute Personal Data. |
The Controller may delete any batch and all associated CV data at any time by clicking the “Delete Batch” button on the Reports page. Clicking this button triggers the following irreversible sequence:
- All in-memory and on-disk enrichment cache entries for that batch are immediately purged.
- All CV source blobs and result blobs are deleted from Azure Blob Storage.
- All database records for that batch (file results, file metadata, batch record, and the
EnrichedJsonAI cache column) are permanently deleted in a single operation.
Deletion is irreversible. Upon account closure, all remaining Personal Data will be deleted within 30 days, subject to the billing records and backup retention periods stated above.
9. International Data Transfers
CVAtlas hosts and stores all data within Azure UK South and West Europe regions. However, certain sub-processors (including AI processing services) may route requests through infrastructure located outside the UK and EEA, including the United States. Where such transfers occur, they are governed by one or more of the following safeguards:
- An adequacy decision made by the UK Secretary of State (UK GDPR) or the European Commission (EU GDPR);
- Standard Contractual Clauses (SCCs) approved by the European Commission; or
- The UK International Data Transfer Agreement (IDTA), as applicable.
In particular, Microsoft Azure OpenAI Service operates under Microsoft’s Data Processing Addendum and the EU Standard Contractual Clauses / UK IDTA. Under Microsoft’s API usage policies, CV data submitted for AI processing is not used to train AI models. The applicable transfer mechanisms for each sub-processor are detailed in Annex B and Annex C.
10. Audit Rights
The Controller has the right to audit CVAtlas’s compliance with this DPA no more than once per 12-month period, upon reasonable written notice of at least 30 days to support@cvatlas.com. CVAtlas may satisfy an audit request by providing a current third-party security assessment or ISO/SOC compliance report in lieu of a direct on-site audit.
11. Data Subject Rights
Where CVAtlas receives a request directly from a data subject (e.g., a CV applicant) exercising rights under UK/EU GDPR (access, erasure, rectification, restriction, portability, objection), CVAtlas will:
- Promptly forward the request to the Controller; and
- Not respond to the data subject directly except on documented instructions from the Controller or as required by law.
The Controller remains responsible for responding to such requests within the statutory timeframes.
Right to Erasure — Individual Candidates: AI Talent Insights enrichment data is stored as a single encrypted JSON blob per batch, not as individually addressable records. As a result, CVAtlas cannot delete the enrichment data for a single candidate without deleting the entire batch enrichment. Where a data subject exercises the right to erasure, the Controller should use the “Delete Batch” function to immediately and permanently remove all data (CV results, enrichment cache, and associated files) for that batch. Scored CV data (extracted text, AI scores) for individual candidates is stored in individually addressable database rows and is deleted automatically at end of the 90-day retention period or immediately upon batch deletion. CVAtlas will provide technical assistance to Controllers fulfilling erasure requests upon written request to support@cvatlas.com.
12. Personal Data Breach Notification
In the event of a Personal Data Breach, CVAtlas will:
- Notify the Controller without undue delay and no later than 36 hours after becoming aware of the breach.
- Provide, to the extent then known: (a) a description of the nature of the breach; (b) categories and approximate number of data subjects affected; (c) categories and approximate number of records affected; (d) likely consequences; (e) measures taken or proposed.
- Cooperate with the Controller and take reasonable commercial steps to assist the Controller in meeting its own notification obligations to the Supervisory Authority and data subjects.
13. Liability
Each party’s liability under this DPA is subject to any limitation of liability set out in the CVAtlas Terms & Conditions. To the maximum extent permitted by law:
- CVAtlas shall not be liable for any breach caused by the Controller’s failure to provide lawful instructions, unlawful upload of data, or the Controller’s own non-compliance with UK/EU GDPR.
- Nothing in this DPA limits either party’s liability for fraud, death, or personal injury caused by negligence, or any other liability that cannot be excluded by law.
- Where both parties are responsible for damage caused by processing, each is liable for the entire damage unless it can prove it is not responsible for the portion that caused the damage.
14. Term and Termination
This DPA is effective from the date the Controller first ticks the DPA consent checkbox and remains in force for as long as CVAtlas processes Personal Data on behalf of the Controller. Upon termination of the Controller’s account or the underlying services agreement, CVAtlas will delete all Personal Data in accordance with Clause 8.
15. Governing Law and Jurisdiction
This DPA shall be governed by and construed in accordance with the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales for any dispute arising under this DPA.
Where the Controller is established in an EU member state, nothing in this clause shall limit the Controller’s rights under EU GDPR or the jurisdiction of the competent EU Supervisory Authority.
16. Updates to this DPA
CVAtlas may update this DPA from time to time to reflect changes in applicable law or our processing activities. Material changes will be notified to registered Controllers by email at least 30 days before they take effect. Continued use of the platform after the effective date constitutes acceptance of the revised DPA. The version date at the top of this page always reflects the current version.
17. Automated Decision-Making and Human Review (Article 22 UK/EU GDPR)
CVAtlas uses AI to generate scores and ranking tiers for CV applicants. The Controller acknowledges and agrees that:
- AI scores are advisory only. All AI-generated scores, rankings, and screening buckets are tools to assist human decision-making. No hiring, rejection, or shortlisting decision is made solely by automated processing without human involvement.
- Human review obligation. The Controller, as the Data Controller, is responsible for ensuring that a human being reviews the AI-generated output before any decision with a legal or similarly significant effect is taken in respect of any data subject.
- Candidate rights. In accordance with UK GDPR Article 22 / EU GDPR Article 22 and DPA 2018 Schedule 2, data subjects (CV applicants) have the right to request human review of any automated assessment, to contest a decision, and to obtain an explanation of the logic involved. The Controller is responsible for facilitating these rights directly with the data subject. CVAtlas will provide the Controller with the scoring rationale data necessary to fulfil such requests upon written request.
- No special category profiling. CVAtlas’s AI does not infer, profile, or score candidates on the basis of any special category data (Article 9) such as health, disability, ethnicity, religion, political opinion, or sexual orientation. Controllers must not submit CVs for the purpose of special category automated profiling.
Annex A — Details of Processing
| Categories of data subjects | Job applicants whose CVs are uploaded by the Controller. |
| Types of Personal Data | Name, contact details (email, phone, address), work history, education, skills, qualifications, and any other information voluntarily included by the data subject in their CV. |
| Special Category Data | Not intentionally collected. Controllers must not upload CVs where special category data (health, religion, ethnicity, political opinion, etc.) is the basis for scoring. CVAtlas makes no use of special category inferences. |
| Nature of Processing | Storage, OCR text extraction, AI-based scoring and ranking, report generation, deletion. |
| Purpose of Processing | To rank and score CV applicants against a job description at the Controller’s request. |
| Duration | For the duration of the batch processing job and report availability period (maximum 90 days), unless deleted earlier by the Controller. |
Annex B — Approved Sub-processors
| Sub-processor | Service Provided | Location | Transfer Safeguard |
|---|---|---|---|
| Microsoft Azure | Cloud hosting, Blob Storage, Queue Storage, SQL Database | UK South / West Europe | UK/EU adequacy & Azure Data Processing Addendum (incl. EU SCCs / UK IDTA) |
| Microsoft Azure OpenAI / AI Services | AI-assisted CV scoring and text analysis | UK South / West Europe (requests may route via US infrastructure) | Azure Data Processing Addendum & EU SCCs / UK IDTA; CV data not used for model training |
Annex C — International Transfer Mechanisms (SCCs & UK IDTA)
Where Personal Data is transferred to a country outside the UK or EEA by CVAtlas or its Sub-processors, the following transfer mechanisms apply:
| Transfer Scenario | Mechanism | Reference |
|---|---|---|
| UK Controller → Sub-processor in non-adequate country | UK International Data Transfer Agreement (UK IDTA) | ICO template IDTA, version in force at the date of this DPA |
| EU Controller → Sub-processor in non-adequate country | EU Standard Contractual Clauses (Module 2: Controller to Processor) | EC Decision 2021/914 (June 2021 SCCs) |
| Microsoft Azure / Azure OpenAI | Microsoft Online Services Data Processing Addendum incorporating EU SCCs and UK IDTA | Microsoft DPA |
To request a copy of the applicable Standard Contractual Clauses or UK IDTA for your records, contact support@cvatlas.com.
Questions about this DPA? Contact us at support@cvatlas.com.