DPA

Data Processing Addendum

Last updated July 9, 2026 · Effective July 9, 2026. For enterprise customers and hiring partners. GDPR Article 28 and CCPA processor terms, the full sub-processor list, EU/UK/Swiss/Brazil transfer clauses, security measures, breach notice, and audit rights.

Last updated: July 9, 2026 · Effective: July 9, 2026 · Version: 2.0.

This DPA governs the Processing of Personal Data by Jobeezy, Inc., a Delaware corporation with its principal place of business at 800 Brazos St., Suite 400, Austin, TX 78701, USA (“Jobeezy,” “Processor,” “we,” “us,” or “our”) on behalf of the enterprise customer or business partner that has entered into the underlying agreement for the Jobeezy services (the “Controller” or “Customer”). It is entered into under, and forms part of, that agreement (the “Agreement”).

This DPA reflects the requirements of the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), the Brazilian Lei Geral de Proteção de Dados (“LGPD”, Law No. 13.709/2018), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”) and other US state comprehensive privacy laws, and comparable data-protection laws (together, “Applicable Data Protection Law”). It replaces the “other applicable data-protection law” hand-wave of prior versions with these named regimes.

1. Definitions

Capitalized terms used but not defined in this DPA have the meaning given in the Agreement or in the GDPR. In this DPA:

  • “Agreement” means the Terms of Service or master agreement between Controller and Jobeezy into which this DPA is incorporated.
  • “Applicable Data Protection Law” means all data-protection and privacy laws applicable to the Processing of Personal Data under the Agreement, including the GDPR, UK GDPR, Swiss FADP, LGPD, and the CCPA/CPRA and other US state comprehensive privacy laws.
  • “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” “Special-Category Data,” and “Supervisory Authority” have the meanings given in the GDPR (or their functional equivalents under other Applicable Data Protection Law). “Business,” “Service Provider,” “Sell,” “Share,” and “Sensitive Personal Information” have the meanings given in the CCPA/CPRA.
  • “Services” means the Jobeezy job-search and application-intelligence services provided under the Agreement, including résumé and cover-letter tailoring, job matching and Fit-Score guidance, and Auto-Apply.
  • “Instructions” means the Controller’s documented, lawful directions for Processing Personal Data, as set out in this DPA and the Agreement, in the configuration of the Services, and in any subsequent written instruction the parties agree.
  • “Data Subject Request” means a request from a Data Subject to exercise a right under Applicable Data Protection Law (for example access, correction, deletion, portability, restriction, objection, or opt-out).
  • “Special-Category Data” and “Criminal-Record Data” mean data revealing racial or ethnic origin, health, and other categories protected by GDPR Article 9, and personal data relating to criminal convictions and offences protected by GDPR Article 10 — which, for the Services, include voluntary EEO/diversity self-identification and user-provided fair-chance / justice-impacted information (as described in the Special-category, criminal-record & EEO data section).
  • “Sub-processor” (always hyphenated) means any third party engaged by Jobeezy to Process Personal Data on Jobeezy’s behalf under Jobeezy’s Instructions, as distinct from an independent controller (such as Apple or Google Play for store billing, or an Employer System).
  • “Employer System” or “ATS” means an employer’s careers page or a third-party applicant-tracking system into which an application is submitted. Each Employer System is an independent controller for the data it receives — not a Jobeezy Sub-processor.
  • “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed under this DPA.
  • “De-identified / Aggregated Data” means data that can no longer reasonably be linked to a Data Subject or household, Processed only in de-identified or aggregated form.
  • “Restricted Transfer” means a transfer of Personal Data to a country that Applicable Data Protection Law treats as requiring a transfer safeguard (for example, a transfer from the EEA, the UK, Switzerland, or Brazil to the United States).
  • “SCCs” means the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, together with the UK International Data Transfer Addendum (“UK Addendum / IDTA”) and the Swiss adaptations, each as applicable to a Restricted Transfer.

2. Roles, scope & order of precedence

2.1 Roles. For Personal Data Processed under the Agreement on the Controller’s behalf, the Controller is the Controller (or, for onward Processing, a processor acting for its own controller) and Jobeezy is the Processor. Jobeezy acts on the Controller’s documented Instructions. Jobeezy is an independent controller for the limited Processing described in the Controller-vs-processor role delineation section.

2.2 Scope. This DPA applies to all Processing of Personal Data that Jobeezy carries out on behalf of the Controller in connection with the Services. It remains in effect for the duration of the Agreement and for as long as Jobeezy retains any Personal Data covered by it.

2.3 Order of precedence. If there is a conflict, the following order controls, with the higher-listed instrument prevailing to the extent of the conflict: (1) the SCCs (on matters of Restricted Transfers); (2) this DPA (on data-protection matters); (3) the Agreement (on all other matters). Nothing in the Agreement limits a Data Subject’s rights under the SCCs.

3. Subject-matter, duration, nature & purpose (Annex I.B)

The following table describes the Processing and also serves as Annex I.B to the SCCs. Retention periods are stated by category; the full retention schedule mirrors the How long we keep your information section of our Privacy Policy.

4. Processor obligations

Jobeezy will, in respect of Personal Data Processed on the Controller’s behalf (GDPR Art. 28(3)):

  1. Documented Instructions. Process Personal Data only on the Controller’s documented Instructions (including as to Restricted Transfers), unless required to Process by law to which Jobeezy is subject; in that case Jobeezy will inform the Controller of the legal requirement before Processing, unless the law prohibits such information on important grounds of public interest.
  2. Confidentiality. Ensure that personnel authorized to Process Personal Data are bound by a written or statutory duty of confidentiality.
  3. Security. Implement and maintain the technical and organizational measures described in the Security measures section (Annex II).
  4. Sub-processors. Engage Sub-processors only under the conditions in the Sub-processors section, and flow down data-protection obligations no less protective than those in this DPA.
  5. Assistance with Data Subject Requests. Taking into account the nature of the Processing, assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to Data Subject Requests.
  6. Assistance with Arts. 32–36. Assist the Controller in ensuring compliance with its obligations regarding security, Personal Data Breach notification, data-protection impact assessments, and prior consultation, taking into account the nature of Processing and the information available to Jobeezy.
  7. Deletion or return. At the Controller’s choice, delete or return all Personal Data after the end of the provision of the Services, as described in the Return or deletion section.
  8. Demonstrating compliance. Make available to the Controller the information necessary to demonstrate compliance with Art. 28, and allow for and contribute to audits as described in the Audits section.
  9. Purpose limitation; no sale. Process Personal Data only for the purposes set out in the Agreement and this DPA and not for Jobeezy’s own purposes; and not Sell, Share, rent, or otherwise disclose Personal Data for consideration or for cross-context behavioral advertising.
  10. Notice of unlawful Instructions. Inform the Controller without undue delay if, in Jobeezy’s opinion, an Instruction infringes Applicable Data Protection Law; Jobeezy may suspend performance of the affected Instruction until the Controller confirms or amends it.

5. Controller obligations

  1. Ensure that a valid legal basis (and, for Special-Category or Criminal-Record Data, a valid Article 9/10 condition or equivalent) exists for all Personal Data it makes available to Jobeezy for Processing.
  2. Provide Jobeezy with accurate, complete, and lawful Instructions, and be responsible for the accuracy and quality of the Personal Data it provides.
  3. Comply with Applicable Data Protection Law in its own collection, use, and transfer of Personal Data to Jobeezy.
  4. Obtain and maintain all notices, consents, and rights required from Data Subjects, including for any Special-Category or Criminal-Record Data.
  5. Be responsible, as between the parties, for the lawfulness of the disclosure of Personal Data to Jobeezy.

6. Sub-processors

6.1 General authorization. The Controller grants Jobeezy general written authorization to engage the Sub-processors listed in Annex III and, as updated, at jobeezy.com/trust/subprocessors/. That list is the authoritative, current record of Jobeezy’s Sub-processors; it matches the Sub-processors section of our Privacy Policy.

6.2 Notice and objection. Jobeezy will give the Controller at least 30 days’ notice of any new or replacement Sub-processor via the sub-processors page and by email to the Controller’s designated contact. The Controller may object on reasonable data-protection grounds before the new Sub-processor begins Processing. The parties will work in good faith to resolve the objection; if it cannot be resolved, the Controller may terminate the affected part of the Services without penalty and receive a pro-rata refund of any prepaid, unused fees for that part.

6.3 Flow-down and liability. Jobeezy will impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, including the relevant SCC obligations for any onward Restricted Transfer. Jobeezy remains fully liable to the Controller for each Sub-processor’s performance to the same extent Jobeezy would be if performing the Services itself. On reasonable request, and subject to confidentiality, Jobeezy will make available a summary of the relevant Sub-processor terms.

7. Security measures (Annex II)

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risks to Data Subjects, Jobeezy maintains the technical and organizational measures set out below. These measures also constitute Annex II to the SCCs. Jobeezy runs on Render (compute, hosting, cron, logging), MongoDB Atlas (database), Cloudflare R2 (object storage), and Clerk (authentication) — the legacy Google Cloud compute, database, storage, and Firebase Auth stack (Cloud Run, Firestore, Cloud Storage, Firebase Auth) described in prior versions has been decommissioned and is no longer operated. A limited residual Google surface remains live — Google Analytics (GA4, including server-side events), Firebase mobile analytics and Remote Config, and a conditional non-PII-only Gemini generation path — each disclosed as a Sub-processor in Annex III.

  • Encryption in transit. TLS 1.2 or higher for all API and web traffic.
  • Encryption at rest. AES-256, provider-managed, for data stored in MongoDB Atlas and Cloudflare R2.
  • Network protection. Cloudflare web-application-firewall and DDoS mitigation in front of the public edge; HTTPS enforced.
  • Authentication & access control. End-user authentication, session management, and credential storage are handled by Clerk; Jobeezy does not store end-user passwords in plaintext. Access to production data follows least-privilege principles. Internal scheduler and maintenance endpoints are gated by a shared secret key header (not exposed to end users).
  • Logging & monitoring. Structured application and audit logging with PII-scrubbing rules; product analytics events are pseudonymized and stripped of direct identifiers before transmission (PostHog); error and crash traces are scrubbed before transmission (Sentry).
  • Isolated processing for Auto-Apply. Each Auto-Apply run executes in an isolated, single-use cloud browser session (Browserbase) that is torn down after the run.
  • AI provider controls. Content sent to AI providers for matching, tailoring, or Auto-Apply form-fill is Processed under no-training API terms, and under zero-retention terms where the provider supports it (for the primary router, OpenRouter, requests are configured to deny provider data collection).
  • EEO isolation. Voluntary EEO/diversity self-identification is stored in a dedicated, isolated collection under a pseudonymized key and is never read by matching, scoring, tailoring, or any AI model (see the Special-category, criminal-record & EEO data section).
  • No payment-card data. Jobeezy does not store payment-card numbers; billing is handled by Apple, Google Play, and RevenueCat.
  • Supply-chain hygiene. Exact dependency pinning and dependency-security review.
  • Environment separation. Development, staging, and production are separated, with no production Personal Data used in non-production environments.
  • Incident response. A documented incident-response process, including the breach-notification workflow in the Personal Data Breach notification section.

8. Personal Data Breach notification

8.1 Notice to the Controller. Jobeezy will notify the Controller of a Personal Data Breach affecting the Controller’s Personal Data without undue delay and in any event no later than forty-eight (48) hours after Jobeezy becomes aware of it, so that the Controller can meet its own notification deadlines (for example, the GDPR 72-hour Supervisory-Authority clock, or shorter clocks under LGPD or US state law).

8.2 Content. The notice will, to the extent then known and as it becomes available, describe: the nature of the breach and the categories and approximate number of Data Subjects and records concerned; the likely consequences; and the measures taken or proposed to address the breach and mitigate its effects. Jobeezy will provide updates as the investigation progresses.

8.3 Cooperation. Jobeezy will take reasonable steps to identify the root cause, contain and remediate the breach, preserve relevant evidence, and reasonably cooperate with the Controller’s investigation and lawful forensic requirements.

8.4 No independent notice. Jobeezy will not notify the Controller’s Data Subjects or any Supervisory Authority on the Controller’s behalf unless required by law or instructed in writing by the Controller. Jobeezy’s notice is not an acknowledgment of fault or liability.

9. International data transfers

9.1 Storage location. Personal Data Processed under this DPA is stored and Processed primarily in the United States (Render, MongoDB Atlas at AWS us-east-1, and Cloudflare R2, with global edge), and by the Sub-processors in Annex III.

9.2 Transfer mechanism — SCCs are the mechanism. For any Restricted Transfer, the parties incorporate the SCCs by reference as follows:

  • EEA: the EU SCCs (Decision (EU) 2021/914). Module Two (Controller → Processor) applies where the Controller is a controller and Jobeezy is its processor; Module Three (Processor → Sub-processor) applies to onward transfers to Sub-processors; and Module One (Controller → Controller) applies to any transfer to an independent controller. The optional docking clause (Clause 7) applies; Clause 9 Option 2 (general authorization) applies with the 30-day notice period in the Sub-processors section; the Clause 17 governing law and Clause 18 forum are the law and courts of Ireland. Annex I, II, and III to the SCCs are the correspondingly titled Annexes below.
  • United Kingdom: the UK International Data Transfer Addendum (IDTA / UK Addendum) to the EU SCCs, with its Tables 1–4 completed by reference to the Annexes below and the Part 2 mandatory-clause protections applied.
  • Switzerland: the EU SCCs with the Swiss adaptations (references to the GDPR read as references to the FADP; the Swiss FDPIC as competent authority; protection extended to legal persons during the transfer).
  • Brazil: the ANPD Standard Contractual Clauses (Cláusulas-Padrão Contratuais) required by Resolution CD/ANPD No. 19/2024 for “guarantees”-based transfers, and/or reliance on contract-performance necessity and the user’s specific, highlighted consent.

9.3 No Data Privacy Framework self-certification. Jobeezy does not rely on, and does not claim, EU-US, UK, or Swiss Data Privacy Framework self-certification as its transfer mechanism; the SCCs above are the mechanism. Where a Sub-processor is itself certified under the Data Privacy Framework, that certification may provide an additional safeguard for the relevant leg — but only for Sub-processors actually listed on the U.S. Data Privacy Framework List, and it does not replace the SCCs.

9.4 Transfer impact assessment & supplementary measures. Jobeezy maintains a transfer impact assessment (TIA) considering the laws and practices of the destination country, and applies supplementary technical and organizational measures — including encryption in transit and at rest, access controls, and the no-training / zero-retention-where-supported AI terms — consistent with the guidance of competent authorities. A copy of the relevant safeguard is available on request from legal@jobeezy.com.

9.5 Government-access requests (Schrems II). If Jobeezy receives a legally binding request from a public authority for Personal Data Processed under this DPA, Jobeezy will, to the extent legally permitted: (a) notify the Controller of the request, and where prohibited from notifying, use reasonable efforts to obtain a waiver of the prohibition and to challenge or narrow the prohibition; (b) review the legality of the request and challenge any request that appears unlawful, overbroad, or inconsistent with international law; and (c) disclose only the minimum Personal Data necessary to comply with a valid, binding request. Jobeezy documents such requests, will report on them as and where legally permitted, and intends to publish periodic transparency reporting once there is meaningful volume. Government-request handling is described further in our Privacy Policy.

10. Assistance with data-subject rights

Taking into account the nature of the Processing, Jobeezy will assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to Data Subject Requests (including access, correction, deletion, restriction, portability, objection, and opt-out). Data Subjects can exercise their rights directly through the in-product settings or the rights and choices described in the Your privacy rights and Your Privacy Choices sections of our Privacy Policy. If Jobeezy receives a Data Subject Request that relates to the Controller’s Personal Data and reasonably requires the Controller’s involvement, Jobeezy will promptly forward it to the Controller and will not respond directly except to confirm receipt or as legally required.

11. Audits, reports & certifications

11.1 Information & audits. Jobeezy will make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA and Art. 28, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to: (a) reasonable advance notice of at least 30 days; (b) audits during normal business hours, no more than once per year (except following a Personal Data Breach or where a Supervisory Authority requires more), and in a manner that does not unreasonably interfere with Jobeezy’s operations; (c) the auditor signing a reasonable non-disclosure agreement; (d) the Controller bearing its own audit costs, unless the audit reveals a material breach by Jobeezy, in which case Jobeezy bears the reasonable costs; and (e) Jobeezy’s reasonable security and confidentiality requirements.

11.2 Certification status — roadmap only. Jobeezy is not currently SOC 2 or ISO 27001 certified. A formal certification program is under consideration on our roadmap; we will not represent otherwise. If and when Jobeezy obtains an independent audit report or certification, the Controller may rely on it to help satisfy its audit obligations under Art. 28(3)(h), without limiting the audit rights in this section.

12. Return or deletion of data

12.1 Return or deletion. At the Controller’s choice, on termination or expiry of the Services or earlier on written request, Jobeezy will return a copy of the Personal Data in a commonly used, machine-readable format and/or delete the Personal Data and existing copies, unless Applicable Data Protection Law requires storage. For end-user-initiated deletion, Jobeezy removes Personal Data from active production systems within about 30 days of a verified request, erases EEO/diversity data immediately, and erases Auto-Apply screenshots and session traces together with the rest of the user’s data. Jobeezy will confirm deletion in writing on request.

12.2 Backups. Personal Data residing in encrypted backups is retained on a rolling basis under Jobeezy’s and its providers’ standard backup rotation and is overwritten in the ordinary course; data no longer present in production is purged from backups as they cycle. Jobeezy does not use backups to rebuild a deleted account.

12.3 Retained records. Consistent with the Privacy Policy retention schedule, limited records may be retained where the law requires or permits — for example, security and audit logs for a limited period, suppression/opt-out records, and a minimal record that a deletion occurred. Subscription and tax records are held by Apple, Google Play, and RevenueCat under their own retention; Jobeezy holds no payment-card data. Applications already submitted to an Employer System reside in that employer’s systems and cannot be recalled by Jobeezy.

13. Special-category, criminal-record & EEO data

Because Jobeezy serves job seekers — including many who are justice-impacted (“fair chance”) — the Services may Process Special-Category Data (GDPR Art. 9) and Criminal-Record Data (GDPR Art. 10), and “Sensitive Personal Information” under the CCPA/CPRA. Two categories are handled differently, and this DPA states the distinction exactly:

13.1 EEO / diversity data — isolated, never used by AI or scoring. Voluntary EEO/diversity self-identification (race, ethnicity, sex, veteran status, disability self-ID) is stored in a dedicated, isolated collection under a pseudonymized key. It is never read by matching, Fit-Score computation, ranking, embeddings, tailoring, or any AI model; Jobeezy’s Auto-Apply engine never banks it or sends it to a form-fill or vision model. It reaches an Employer System only if the user explicitly approves sending it, and it is erased immediately on a deletion request. This isolation commitment is a binding technical and organizational measure under Annex II.

13.2 Fair-chance / criminal-record & health-gap data — sensitive, and used to help the user. Fair-chance / justice-impacted information and health-related employment-gap reasons that a user chooses to add are treated as sensitive and are never sold or shared. Unlike EEO data, this information is used by our AI to tailor the user’s own applications and to help match jobs, and it contributes to the fairness dimension of the Fit Score. It is not isolated the way EEO data is, and this DPA does not represent otherwise. Jobeezy uses it only to deliver the Services the user requested, discloses it to an Employer System only as the user directs, and does not use it to infer characteristics about the user for any other purpose. For EEA/UK Data Subjects, the Controller is responsible for ensuring a valid Art. 9/10 condition (typically explicit consent) for this data, and Jobeezy will honor instructions to minimize or restrict it.

13.3 No re-identification. Jobeezy will not attempt to re-identify De-identified / Aggregated Data except as permitted by law to test the de-identification.

14. Automated decisions, AI-in-hiring & no-training

14.1 Jobeezy is a candidate-side tool. Jobeezy scores jobs for the user, drafts materials the user reviews and approves, and submits only pre-approved applications as the user’s agent. Jobeezy makes no hiring, screening, rejection, promotion, or firing decision, and does not deliver its Fit Score or AI outputs to employers as a screening input about the candidate. The employer, through its Employer System, decides hiring. On these facts Jobeezy is generally outside the employer-facing scope of NYC Local Law 144, the Colorado AI Act successor (SB 26-189), Illinois AI/BIPA hiring rules, Texas TRAIGA employer duties, and EU AI Act Annex III(4) high-risk employment obligations.

14.2 Transparency & human-in-the-loop. The Fit Score is guidance to the user, not a solely-automated significant decision about the user, and each Auto-Apply submission is individually approved by the user (genuine human-in-the-loop). Jobeezy provides AI-interaction transparency consistent with GDPR Arts. 13–15 and 22, UK Arts. 22A–22D, EU AI Act Art. 50 (in force 2 Aug 2026), LGPD Art. 20, and Québec Law 25 — described in our AI Transparency Notice. The parties will reasonably cooperate on any transparency notices, opt-outs, or human-review requests that Applicable Data Protection Law allocates between them.

14.3 No model training; retention limits. Jobeezy contractually requires that Personal Data sent to AI providers is Processed only to return the requested output, is not used to train or improve any third-party model, and is not retained beyond what is needed to provide the service, where the provider supports zero retention. Jobeezy’s primary AI providers are OpenRouter (primary router and embeddings) and Anthropic (fallback); Jobeezy does not use OpenAI as a provider.

15. CCPA/CPRA service-provider terms

To the extent the CCPA/CPRA applies and Jobeezy Processes Personal Information as a Service Provider to the Controller as a Business, Jobeezy:

  1. Processes Personal Information only for the specific business purpose(s) of providing the Services set out in the Agreement, and does not Process it for any other purpose;
  2. does not Sell or Share Personal Information;
  3. does not retain, use, or disclose Personal Information outside the direct business relationship with the Business, or for any purpose other than the Services, except as permitted by the CCPA/CPRA;
  4. does not combine the Personal Information with personal information it receives from, or on behalf of, another person, or collects from its own interaction with the consumer, except as permitted by the CCPA/CPRA;
  5. certifies that it understands and will comply with these restrictions;
  6. grants the Business the right to take reasonable and appropriate steps to help ensure that Jobeezy Processes Personal Information consistent with the Business’s obligations, and to stop and remediate unauthorized use;
  7. will notify the Business if it determines it can no longer meet its obligations under the CCPA/CPRA; and
  8. acknowledges that the Business’s disclosure of Personal Information to Jobeezy is not a Sale or Share and is made only to enable Jobeezy to perform the Services.

16. Auto-Apply, agency & Employer Systems

16.1 Agency of the user. When a user approves an application, the user instructs Jobeezy to act on the user’s behalf to complete and submit that specific application to the employer or its Employer System, using the profile information and materials the user has reviewed. Jobeezy submits only the applications the user approves and only the information needed for each application.

16.2 Mechanism. Auto-Apply runs in an isolated, single-use cloud browser (Browserbase). For most Employer Systems, Jobeezy applies as a guest (no user account credentials are used). For Workday only, Jobeezy creates a candidate account on the user’s behalf using a Jobeezy-managed email alias and a generated, vaulted password — it does not use the user’s own account credentials. CAPTCHAs encountered during a run may be solved via a CAPTCHA-solving Sub-processor (2captcha), which receives the employer page URL and CAPTCHA site key, not profile identifiers. Confirmation screenshots and session traces are stored in Cloudflare R2 to evidence submission and to diagnose errors, and are erased with the user’s data on deletion.

16.3 Employer Systems are independent controllers. Each Employer System is an independent controller for the application data it receives; it is not a Jobeezy Sub-processor, and Jobeezy’s processor role ends when the data reaches the Employer System. Applications already submitted cannot be recalled by Jobeezy, although the user may withdraw pending, not-yet-submitted applications.

17. Controller-vs-processor role delineation

Jobeezy acts as an independent controller — not the Controller’s processor — for a limited set of Processing carried out for Jobeezy’s own purposes, including: administering and securing the Jobeezy account and platform; product analytics and service improvement; security, fraud-prevention, and audit logging; billing and entitlement reconciliation; and Jobeezy’s own marketing to its prospects. That Processing is governed by Jobeezy’s Privacy Policy, not by this DPA. This DPA governs only Jobeezy’s processor-role Processing on the Controller’s behalf.

18. Brazil (LGPD) terms

To the extent the LGPD applies, Jobeezy acts as an operator (operador) Processing personal data on the Controller’s (controlador’s) documented instructions, and the obligations in this DPA apply with equivalent effect. For transfers of Brazilian personal data to the United States, there is no ANPD adequacy decision; Jobeezy relies on contract-performance necessity and, where applicable, the user’s specific and highlighted consent, and incorporates the ANPD Standard Contractual Clauses (Resolution CD/ANPD No. 19/2024) into Sub-processor contracts where the Sub-processor will sign them. Sensitive data under LGPD Art. 11 (including criminal-record / fair-chance data) is Processed only on the applicable Art. 11 basis, and Brazilian Data Subjects may request review of decisions made solely on automated Processing (LGPD Art. 20). The point of contact for Brazilian data-protection matters (Encarregado) is privacy@jobeezy.com (see the Records, cooperation, representatives & DPO section).

19. Records, cooperation, representatives & DPO

19.1 Records of processing. Jobeezy maintains a record of the Processing activities carried out on the Controller’s behalf (GDPR Art. 30(2)) and makes it available to the Controller and Supervisory Authorities on request.

19.2 Cooperation with authorities. Jobeezy will reasonably cooperate with, and respond to requests from, a Supervisory Authority in respect of Processing under this DPA.

19.3 Representatives & DPO. If and where Jobeezy is required to designate an EU or UK representative under Article 27 GDPR, a Swiss representative under the revised FADP, a Brazilian Encarregado, or a Data Protection Officer, Jobeezy will do so and publish the contact details here. In the meantime, all data-protection, rights, and DPO-type inquiries may be directed to privacy@jobeezy.com.

20. Liability, indemnity & insurance

20.1 Liability cap. Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference to a party’s liability means the aggregate liability under the Agreement and this DPA together. This DPA does not expand or contract the Agreement’s liability allocation except to the extent the SCCs require otherwise for the benefit of Data Subjects.

20.2 Insurance. Jobeezy maintains, or will maintain commensurate with the scale of Processing, commercially reasonable cyber and technology errors-and-omissions insurance.

21. Governing law & relationship to the Terms

21.1 Governing law. Except as stated in the next sentence, this DPA is governed by the laws of the State of Texas, USA, without regard to its conflict-of-laws principles, and disputes are subject to the dispute-resolution, venue (Travis County, Texas), and arbitration (JAMS, with a class-action waiver and mass-arbitration batching) provisions of the Agreement’s Terms of Service. The SCCs, however, are governed by the law and subject to the courts stated in the SCCs themselves (Clauses 17–18 — the law and courts of Ireland for the EU leg), and nothing in the Agreement’s governing-law, venue, or arbitration provisions limits a Data Subject’s rights or choice of forum under the SCCs, the GDPR, the UK GDPR, the FADP, or the LGPD. For EEA Data Subjects, the GDPR governs; for UK Data Subjects, the UK GDPR and the Data Protection Act 2018 govern.

22. Amendment & versioning

Jobeezy may update this DPA to reflect changes in Applicable Data Protection Law, the transfer mechanisms, the Sub-processor list, or the Services, provided that no update materially reduces the protections for Data Subjects. Material changes will be published here with an updated version number and effective date and, for customers under an executed DPA, notified as set out in the Agreement. The current version is stated at the top of this page. This Version 2.0 supersedes prior versions in full — including their legacy all-Google-Cloud security description and Data-Privacy-Framework self-certification language, which are withdrawn.

23. Contact

DPA execution, subpoenas & legal notices: legal@jobeezy.com
Privacy, data-subject & DPO/Encarregado inquiries: privacy@jobeezy.com
Security & breach reports: security@jobeezy.com
Jobeezy, Inc. · 800 Brazos St., Suite 400, Austin, TX 78701, USA

Annex I — Parties & description of processing

A. List of parties. Data exporter / Controller: the enterprise customer or hiring partner identified in the Agreement, acting as controller of the Personal Data it makes available to Jobeezy; contact as stated in the Agreement; activities relevant to the transfer: procuring the Jobeezy Services for its users. Data importer / Processor: Jobeezy, Inc., 800 Brazos St., Suite 400, Austin, TX 78701, USA; contact legal@jobeezy.com; activities relevant to the transfer: providing the job-search, matching, tailoring, and Auto-Apply Services described in this DPA. Role: Processor (Module Two), and Processor engaging Sub-processors (Module Three); Module One applies to any controller-to-controller transfer.

B. Description of processing. The categories of Data Subjects and Personal Data, the special-category and criminal-record data, frequency, nature, purpose, retention, and Sub-processor transfers are set out in the Subject-matter, duration, nature & purpose table above, which is incorporated here as Annex I.B.

C. Competent supervisory authority. For the EU SCCs, the competent Supervisory Authority is determined under Clause 13 — where the Controller is established in an EEA member state, that member state’s authority; where the Controller relies on the representative mechanism, the authority of the member state where the representative is established. For the UK, the Information Commissioner’s Office (ICO); for Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); for Brazil, the ANPD.

Annex II — Technical & organizational measures

The technical and organizational security measures for this Annex II are the measures set out in full in the Security measures section above (real Render / MongoDB Atlas / Cloudflare R2 / Clerk stack; TLS 1.2 or higher in transit; AES-256 provider-managed at rest; Cloudflare WAF/DDoS; least-privilege access; Clerk-managed credentials; structured audit logging with PII-scrubbing; isolated single-use Auto-Apply browser sessions; no-training AI terms and zero-retention where the provider supports it; EEO isolation; no payment-card data; dependency pinning; environment separation; documented incident response), which are incorporated here by reference.

Annex III — Sub-processors

The following is the current list of Sub-processors engaged by Jobeezy, matching the Sub-processors section of our Privacy Policy and the sub-processors page, which is the authoritative, continuously updated record. Legal-entity names are provided for identification and should be confirmed against each executed vendor DPA. All are Processors unless marked otherwise. Deployment regions are US unless noted.

Content sent to the AI providers above is Processed under no-training terms and, for OpenRouter, under configuration that denies provider data collection; zero-retention applies where the provider supports it. Apple and Google Play act as independent controllers for store billing, not as Jobeezy Sub-processors.