Notice: This is a template document provided for product setup and is pending review by legal counsel before production use.

GDPR Supplement

This supplement applies to individuals in the European Economic Area (EEA) and the United Kingdom (UK) and supplements our Privacy Policy. It provides additional information required by the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR.

1. Data Controller and Processor Roles

OctoRecruit acts in two distinct roles depending on the context:

  • Controller — for data relating to your OctoRecruit account (name, email, company, subscription, usage logs). We determine the purposes and means of processing this data.
  • Processor — for candidate data that you (the recruiter) store in OctoRecruit. You are the controller; we process candidate personal data on your instructions to provide the service. We will enter into a Data Processing Agreement (DPA) with you on request.

2. Legal Bases for Processing

We rely on the following legal bases under GDPR Article 6:

  • Contract (Art. 6(1)(b)) — processing your account data to perform the service contract with you (account management, billing, email notifications).
  • Legitimate interests (Art. 6(1)(f)) — security monitoring, fraud prevention, service improvement, and aggregate analytics where these interests are not overridden by your rights.
  • Legal obligation (Art. 6(1)(c)) — retaining records as required by applicable law (e.g. financial/tax records).
  • Consent (Art. 6(1)(a)) — where we ask for consent (e.g. optional marketing communications). You may withdraw consent at any time.

For candidate data that you process using OctoRecruit, you are responsible for identifying and documenting your own legal basis as controller.

3. Data Subject Rights

As an EEA or UK data subject, you have the following rights regarding your personal data held by OctoRecruit (in our controller capacity):

  • Right of access (Art. 15) — obtain a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) — correct inaccurate or incomplete data.
  • Right to erasure / "right to be forgotten" (Art. 17) — request deletion of your data, subject to our legal retention obligations.
  • Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
  • Right to restriction of processing (Art. 18) — ask us to limit processing in certain circumstances.
  • Right to object (Art. 21) — object to processing based on legitimate interests.
  • Rights related to automated decision-making (Art. 22) — AI candidate scores are used as informational signals; final hiring decisions are made by humans. No solely automated decisions with legal or similarly significant effects are made based on OctoRecruit scores alone.

To exercise any of these rights, contact us at ···. We will respond within 30 days (extendable to 3 months for complex requests with notice).

You also have the right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, or the relevant DPA in your EEA member state). As we are established in Poland, our lead supervisory authority is the Polish UODO (Urząd Ochrony Danych Osobowych).

4. Candidate Data — Recruiter Obligations

When you upload or receive candidate personal data through OctoRecruit, you act as the data controller for that data. You are responsible for:

  • Establishing and documenting a lawful basis for processing candidates' data.
  • Providing candidates with appropriate privacy notices at the point of collection.
  • Responding to candidate data subject requests.
  • Not retaining candidate data longer than necessary for the recruitment purpose.

We process candidate data solely on your instructions to provide the OctoRecruit service. We will assist you in responding to data subject requests that relate to data stored in OctoRecruit (Art. 28(3)(e)).

5. Data Processing Agreement (DPA)

If you require a signed DPA to satisfy your own GDPR compliance obligations, please contact us at ···. We will provide a DPA incorporating standard contractual clauses where applicable.

6. International Data Transfers

Our primary data storage is in the EU (Supabase hosted on AWS eu-central-1). Some sub-processors (Anthropic, OpenAI, Stripe, Resend, Vercel) are based in or transfer data to the United States. Where this occurs, we rely on:

  • EU Standard Contractual Clauses (SCCs) with each sub-processor.
  • The EU–US Data Privacy Framework (DPF) where applicable sub-processors are certified.

7. Sub-processor List

The following sub-processors may process personal data on our behalf. We maintain contractual safeguards with each:

  • Supabase Inc. — Database and object storage (EU region)
  • Anthropic PBC — AI language model API (US)
  • OpenAI L.L.C. — Embedding API (US)
  • Stripe Inc. — Payment processing (US / EU)
  • Resend Inc. — Transactional email (US)
  • Vercel Inc. — Cloud hosting and edge compute (US / EU)
  • Google LLC — Gmail and Google Calendar OAuth / APIs (US), when connected by user
  • Microsoft Corporation — Outlook and Microsoft Graph calendar OAuth / APIs (US), when connected by user

We will provide at least 14 days' notice before adding new sub-processors that materially change the processing activities.

In addition, our public website and sign-in pages use Microsoft Clarity and Google Analytics for website analytics. These tools are never loaded inside the logged-in application and do not process candidate data.

8. Data Protection Contact

We do not currently have a statutory obligation to appoint a Data Protection Officer; however, all privacy queries and data subject requests are handled by our privacy contact: