Data Processing Agreement
How Gapfy processes personal data on behalf of customer organisations, as required by Article 28 of the GDPR.
Last updated: 13 July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between GAPFY UNIPESSOAL LDA ("Gapfy", "Processor") and the customer organisation ("Customer", "Controller") that uses our Services. It governs Gapfy's processing of personal data contained in Customer Data on the Customer's behalf and applies in addition to our Terms of service and Privacy policy. For self-service customers this DPA is incorporated by reference into the Terms; a counter-signed copy is available on request at privacy@gapfy.io.
1. Definitions
"GDPR" means Regulation (EU) 2016/679. "Controller", "Processor", "Sub-processor", "Data Subject", "Personal Data", "Processing" and "Personal Data Breach" have the meanings given in the GDPR. "Customer Personal Data" means personal data within Customer Data that Gapfy processes on the Customer's behalf.
2. Roles and scope
For Customer Personal Data the Customer is the Controller and Gapfy is the Processor. Gapfy processes Customer Personal Data only to provide and support the Services and only on the Customer's documented instructions, including as set out in this DPA and the Terms, unless required to do otherwise by EU or Member State law, in which case Gapfy will inform the Customer unless that law prohibits it. Gapfy will immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. Where Gapfy determines the purposes and means of processing (for example account, billing and security data, and the aggregated, privacy-preserving usage analytics described in the Privacy policy), it acts as Controller under the Privacy policy. Where the Customer connects its own identity provider, Gapfy also processes directory identifiers (such as the Customer's tenant identifier, group identifiers and email domains) on the Customer's instructions to route single sign-on and provision users.
3. Processing details (Annex I)
- Subject matter: provision of the Gapfy Services subscribed to by the Customer.
- Duration: for the term of the subscription plus the deletion and return window in section 11.
- Nature and purpose: hosting, storage, organisation, retrieval, transmission and deletion of Customer Data as needed to operate the Services; where the Customer enables AI features, transmission of the content those features need to an AI sub-processor for processing within the EU solely to return the requested result; and, for the recruitment module, hosting public career sites and collecting job applications on the Customer's behalf. Where the Customer configures knockout questions on a job posting, the Service automatically declines applications whose answers do not match the configured requirement, as the Customer's documented instruction; the Customer is responsible for informing candidates about that automated screening (Art. 13(2)(f) GDPR) and for providing human review on request (Art. 22(3) GDPR). Applications in a terminal state are automatically deleted after the retention period the Customer configures on its career site (between 30 and 1095 days), and candidates without applications and without talent-pool consent are deleted with them - this sweep is likewise a documented instruction.
- Types of personal data: identifiers and contact details, content the Customer and its users create in the Services, usage and activity data, and any other personal data the Customer chooses to submit or solicits from data subjects through the Services. Depending on the modules used, this includes documents and files, timesheet entries, booking and resource data, saved links, tabs and bookmarks, API request definitions and environment values, source-repository metadata, candidate application data (CVs, cover letters, answers to application questions, self-declared languages and gender, talent-pool consent and application status), and the content of prompts submitted to and outputs returned by the AI features.
- Categories of data subjects: the Customer's authorised users; job applicants and candidates who submit applications through career sites the Customer publishes via the Services; and any other individuals whose personal data the Customer includes in Customer Data.
The Customer must not submit, or solicit from data subjects through the Services, special categories of personal data unless it has put appropriate safeguards in place, and is responsible for the lawfulness of the data it submits or solicits.
4. Confidentiality
Gapfy ensures that persons authorised to process Customer Personal Data are bound by confidentiality and process the data only as instructed.
5. Security (Annex II)
Gapfy implements appropriate technical and organisational measures under Article 32 GDPR, including encryption of data in transit and at rest, access controls and least-privilege access, network isolation, logging and monitoring, secure software development practices, and regular review. For AI features, content is screened for personal data and prompt-injection patterns before it is sent to the AI sub-processor, processing stays within the EU, and content is not used to train AI models. These measures are summarised here and described further in our Privacy policy; they may be updated as technology evolves, provided the level of protection is not reduced.
6. Sub-processors (Annex III)
The Customer authorises Gapfy to engage the sub-processors listed on our Sub-processors page, which include our cloud, identity, email, security and AI providers. (Payment providers process billing data under Gapfy's own controllership, as described in section 2 and the Privacy policy, not as sub-processors under this DPA.) Gapfy imposes data-protection obligations on each sub-processor that are no less protective than this DPA and remains responsible for their performance. Gapfy will give at least 30 days' advance notice of any new or replacement sub-processor by updating the Sub-processors page and notifying the Customer's administrators through the Services; the Customer may object within that period on reasonable data-protection grounds, and the parties will work in good faith to resolve the objection. If the objection cannot be resolved, the Customer may terminate the affected Services in accordance with the Cancellation and refund policy.
7. Assistance with data subject rights
Taking into account the nature of the processing, Gapfy assists the Customer with appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Chapter III GDPR. The Services include self-service privacy features - for example the candidate privacy page of each career site, through which job applicants can exercise erasure, export and restriction of their application data directly - and the Customer instructs and authorises Gapfy to operate those features on its behalf; this DPA constitutes the Customer's documented instruction to do so. Where Gapfy receives any other request directly, it will refer the data subject to the Customer.
8. Assistance with security, breaches and impact assessments
Gapfy assists the Customer in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to Gapfy.
9. Personal Data Breach notification
Gapfy notifies the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provides the information the Customer reasonably needs to meet its own notification obligations.
10. International transfers
Gapfy hosts Customer Personal Data in the European Union, and AI processing in the default configuration also takes place within the EU. Where a sub-processor transfers data outside the European Economic Area, the transfer relies on an adequacy decision or the European Commission's Standard Contractual Clauses with additional safeguards, as indicated on the Sub-processors page.
11. Return and deletion
When the Customer deletes its organisation (or the provision of the Services otherwise ends and the Customer requests deletion), the deletion enters a reversible grace window of 30 days during which the Customer can still export Customer Data or cancel the deletion; when the window lapses, Customer Personal Data is permanently deleted from production systems, unless EU or Member State law requires storage. A data export requested before the purge additionally holds it for up to 7 further days until the export is delivered. Deleting an item also removes it from the AI semantic-search index, and short-lived AI caches expire automatically. The Customer can export Customer Data at any time during the subscription. Cancelling a paid plan alone does not trigger deletion: the workspace and its data remain available under the free tier until the Customer deletes them.
12. Audits
Gapfy makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable prior notice and subject to confidentiality.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms or any signed agreement between the parties.
14. Contact
To request a counter-signed DPA or to raise a processing question, contact privacy@gapfy.io.
This English-language version is the authoritative, legally binding version of this document. Translations are provided for convenience only.