jobdownup
DATA PROCESSING AGREEMENT

For business customers with GDPR obligations.

Most jobdownup users are individual job-seekers — the standard Privacy Policy governs. If you are a company using jobdownup on behalf of your employees (rare), the DPA below governs the processing we do on your behalf.

Effective 16 August 2026 · Applies to jobdownup.app and the jobdownup service
DRAFT — LEGAL REVIEW PENDING
Substantive template — not a substitute for advice from a qualified lawyer. Every placeholder in [[BRACKETS]] below must be filled with real information before ads run.

1. Who needs a DPA

You need a DPA with us if you are an EU/UK-established organisation (or otherwise subject to GDPR) and you are the controller of personal data that we process on your behalf as part of your use of the service. Individual consumers do not need to sign a DPA; the Privacy Policy covers them.

2. Summary of terms

Our DPA follows the European Commission’s Standard Contractual Clauses (Module 2, Controller-to-Processor) and the guidance of the European Data Protection Board. Highlights:

  • We process personal data only on your documented instructions.
  • Confidentiality obligations bind everyone who accesses your data.
  • We implement the security measures described at /security.
  • We help you meet DSAR obligations and, where required, DPIAs and consultation with the supervisory authority.
  • We notify you of personal-data breaches without undue delay.
  • At end of service we return or delete personal data as you choose.
  • We allow reasonable audits, satisfied by third-party attestations where available.

3. Scope of processing

  • Subject matter: providing the jobdownup service to your users.
  • Duration: the term of your subscription plus any legally-required retention.
  • Nature and purpose: reading company career pages, scoring roles against user profiles, coaching, drafting messages, delivering morning briefs.
  • Personal data categories: account credentials, professional profile (CV, experience, skills), search activity, technical metadata.
  • Data subject categories: your users (the individuals you have authorised to use the service).

4. Our obligations

Beyond the SCC requirements, we:

  • Confirm any subprocessor changes at least 30 days in advance (see /subprocessors).
  • Do not train external AI models on your data.
  • Do not use your data to enrich other customers or resell it.

5. Subprocessors

The live list of subprocessors is at /subprocessors. You authorise the current list by executing the DPA; you may object to future additions per §4 of that DPA.

6. International transfers

For transfers outside the EEA/UK we rely on the EU-U.S. Data Privacy Framework where the subprocessor is certified, otherwise on the SCCs Module 2 (2021) and, for UK data, the UK IDTA or the UK Addendum to the SCCs, as applicable.

7. Get the executed DPA

Request the executable PDF at contact@jobdownup.app. Include your company’s legal name, address, and a signatory. Where a fully-standard DPA is acceptable to you, we can normally return a countersigned copy within 2 working days.