Data Processing Agreement
Version 1.1, last updated July 18, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Servicebetween easyboard ("we", "us", the "Processor") and the customer ("you", the "Controller") and applies whenever we process personal data on your behalf in connection with your job board. It is deemed accepted when you accept the Terms of Service; no separate signature is required. For enterprise customers who require a countersigned copy, contact support@easyboard.co.
1. Roles and scope
For candidate, employer, and other end-user personal data submitted to or collected by your job board, you act as the data controller and we act as the data processor. This DPA reflects Article 28 of the EU General Data Protection Regulation (GDPR) and the equivalent UK GDPR. Where we process personal data as a controller (for example your own account details), our Privacy Policy applies instead.
2. Details of processing
- Subject matter and duration: processing for the term of the Terms of Service, plus any retention period described below.
- Nature and purpose: hosting and operating your job board, including publishing jobs, receiving applications, managing candidate and employer accounts, sending notifications, and providing analytics.
- Types of personal data: names, contact details, account credentials (managed by our authentication provider), profiles, CVs and resumes, applications, messages, and usage data.
- Categories of data subjects: job seekers, employers, and other visitors to your board.
3. Our obligations
As your processor, we will:
- process personal data only on your documented instructions (including as set out in the Terms and this DPA), unless required by law;
- ensure that people authorized to process the data are bound by confidentiality;
- implement appropriate technical and organizational security measures (Article 32), described in Section 9;
- assist you, taking into account the nature of processing, in responding to data subject requests (Section 6) and in meeting your security, breach-notification, and data protection impact assessment obligations;
- at the end of the service, delete or return personal data as described in Section 8.
4. Sub-processors
You provide general authorization for us to engage sub-processors to help deliver the service. Our current sub-processors are listed at easyboard.co/sub-processors, and we impose data protection obligations on each of them that are no less protective than this DPA. Where a sub-processor fails to meet its data protection obligations, we remain liable to you for the performance of its obligations.
We will give at least 30 days' notice before a new sub-processor begins processing your personal data (except for an urgent replacement needed to maintain security or availability, where we will give as much notice as is practicable). You may object within 30 days of that notice on reasonable data protection grounds; if we cannot resolve the objection, you may terminate the affected service.
5. International transfers
Candidate and employer data is stored in the European Union. Where personal data is transferred outside the European Economic Area (for example to a US-based sub-processor), the transfer is governed by the European Commission's Standard Contractual Clauses (and, for UK data, the UK International Data Transfer Addendum), which are incorporated into this DPA by reference, together with any applicable adequacy framework such as the EU-US Data Privacy Framework.
6. Data subject requests
Where a data subject contacts us directly about board data, we will refer them to you without undue delay. We provide tools in the dashboard for you to give effect to data subject rights, including access, rectification, erasure, portability, restriction, and objection, and we will provide reasonable assistance with requests those tools do not cover. We bear the cost of assistance made necessary by our breach; other assistance beyond the standard dashboard tools may be charged at reasonable rates.
7. Personal data breach
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data, to the extent reasonably practicable. The notice will describe, so far as known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed, so you can meet your own notification obligations.
8. Retention and deletion
You may delete personal data at any time using the dashboard. On termination of the service, we will, at your choice, delete or return your personal data within 60 days, except where retention is required by law. Any residual copies in backups are deleted on their normal rotation cycle, and we restrict processing of such data until it is deleted. We will confirm deletion in writing on request.
9. Security measures
We maintain appropriate technical and organizational measures, kept up to date, which currently include:
- Tenant isolationenforced at the database level (row-level security), so each board's data is scoped to that board;
- Encryption in transit (TLS) and at rest for the database and file storage;
- Access controls and least-privilege service credentials; authentication handled by a dedicated identity provider (we never store passwords);
- Monitoring, error tracking, and documented incident-response procedures, with alerting on production issues;
- regular security reviews and prompt application of security updates.
10. Audits
We will make available the information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied by our own and our sub-processors' up-to-date certifications, audit reports, or security documentation. Where an on-site or direct audit is required, it will be limited to once per 12-month period (unless required by a supervisory authority or following a breach attributable to us), on at least 30 days' notice, during business hours, in a manner that minimizes disruption, at your cost unless the audit reveals a material breach by us, and subject to the auditor signing a confidentiality agreement.
11. US state privacy laws
To the extent US state privacy laws such as the CCPA/CPRA apply, you are the Business and we are the Service Provider. We will not sell or share personal data, will not retain, use, or disclose it except as necessary to provide the service, and will not combine it with personal data from other sources except as permitted by those laws.
12. Liability and general
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, to the extent permitted by applicable law. If there is a conflict between this DPA and the Terms of Service on the processing of personal data, this DPA prevails. This DPA is governed by the same law as the Terms.