Data Processing Agreement (DPA)

Last updated: September 2026

How this document fits with our other legal pages: our Privacy Policy explains how we handle YOUR personal information as a visitor or account holder. This Data Processing Agreement instead governs how we handle your candidates' and employees' personal data that you (a Team Admin or Team Member using BG HR AI on behalf of your organization, "Customer") submit to or generate through the Service — for example, resumes, candidate assessments, interview transcripts, or organigram/employee data. For that data, Customer is the data Controller and BOUGLAD HUMAN RESOURCES AI LLC ("BG HR AI", "Processor") processes it only on Customer's behalf and instructions.

This DPA is incorporated by reference into our Terms of Service for every business account and applies automatically — you do not need to sign anything separately for it to apply. If your organization requires a countersigned version for procurement/vendor-security purposes, contact legal@bghrai.com.

1. Definitions

  • "Applicable Data Protection Law" means, as applicable to the processing at hand: the EU General Data Protection Regulation (GDPR) 2016/679, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA, and other applicable data protection or privacy laws.
  • "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR, applied correspondingly under other Applicable Data Protection Laws.
  • "Customer Personal Data" means Personal Data relating to Customer's candidates, employees, and other individuals that is submitted to, or generated by, the Service on Customer's behalf — including resumes/CVs, cover letters, interview transcripts and audio/video recordings, anti-cheat proctoring logs (fullscreen-exit, tab-switch, and window-focus events recorded during AI interviews and BG Assessments), assessment/screening results, and organigram/employee records. It does not include the account/billing data of the Customer's own users, which is addressed under our Privacy Policy.
  • "Sub-processor" means any third party engaged by BG HR AI to process Customer Personal Data.

2. Roles of the Parties

Customer is the Controller of Customer Personal Data. BG HR AI is the Processor, processing Customer Personal Data solely to provide the Service in accordance with Customer's documented instructions (which include instructions given via the Service's normal configuration and use) and this DPA.

Customer represents and warrants that it has, and will maintain, a valid legal basis under Applicable Data Protection Law for collecting Customer Personal Data (including candidate resumes and assessment data) and for instructing BG HR AI to process it as contemplated by the Service — for example, appropriate candidate notices, consent where required, or another lawful basis for employment-related and recruitment processing. BG HR AI has no relationship with, and cannot independently verify the legal basis Customer has for, Customer's candidates or employees.

[DRAFT — pending attorney review] 2.1 Candidate Pool Sharing (optional feature). The Service offers an optional, Customer-configurable feature ("Candidate Pool Sharing") that, once enabled by Customer, makes Customer Personal Data relating to candidates visible to other BG HR AI customers who have also enabled the feature, and correspondingly gives Customer visibility into those other customers' candidate data on the same reciprocal basis. Candidate Pool Sharing is disabled by default and is enabled only by Customer's own affirmative action. If Customer enables Candidate Pool Sharing, Customer is solely responsible for having an appropriate legal basis (including any required candidate notice or consent) for that additional disclosure of Customer Personal Data to other BG HR AI customers, in the same way Customer is responsible under Section 2 above for its underlying collection and processing instructions. BG HR AI's role with respect to data shared through this feature remains that of a Processor acting on the instructions of the Customer(s) who enabled it; BG HR AI does not select which other customers see the shared data beyond mutual opt-in status.

3. Subject Matter, Duration, Nature and Purpose

Subject matterBG HR AI's processing of Customer Personal Data to provide the AI-powered HR platform (job description generation, job evaluation, resume screening, interview analysis, organigram/workforce planning, and related document automation).
DurationFor as long as Customer maintains an active subscription, plus any retention period described in Section 8 below or in our Privacy Policy.
Nature of processingCollection, storage, organization, AI-assisted analysis/generation, retrieval, and deletion of Customer Personal Data as directed by Customer's use of the Service.
PurposeProviding, securing, and supporting the Service for Customer, and no other purpose.
Categories of data subjectsJob applicants/candidates, Customer's employees (where used for organigram/workforce planning), and Customer's own authorized users.
Categories of personal dataName, contact details, employment/education history, resume/CV content, interview recordings/transcripts, assessment scores and AI-generated evaluations, and any other personal data Customer chooses to submit through the Service. Customer should avoid submitting special-category data (health, religion, trade union membership, biometric or genetic data, etc.) unless strictly necessary and lawful to do so, and is solely responsible for the lawfulness of doing so.

4. BG HR AI's Obligations as Processor

  • Process Customer Personal Data only on Customer's documented instructions, unless required to do otherwise by law (in which case BG HR AI will inform Customer, unless legally prohibited from doing so).
  • Ensure personnel authorized to process Customer Personal Data are subject to confidentiality obligations.
  • Implement appropriate technical and organizational security measures (see Section 5), taking into account the state of the art, costs, and the risk to data subjects.
  • Not engage a new Sub-processor without providing Customer prior notice and an opportunity to object, per Section 6.
  • Taking into account the nature of the processing, provide reasonable assistance to Customer in responding to data subject requests (access, rectification, erasure, restriction, portability, objection) relating to Customer Personal Data, insofar as this is possible through the Service's existing functionality or a reasonable manual process; direct requests received from a data subject rather than Customer will be forwarded to Customer without undue delay.
  • Provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities, where required by Applicable Data Protection Law and relating to Customer's use of the Service.
  • Notify Customer without undue delay, and in any event within 48 hours of becoming aware, of any Personal Data Breach affecting Customer Personal Data, and provide the information reasonably available to enable Customer to meet its own notification obligations.
  • At Customer's choice, delete or return all Customer Personal Data at the end of the provision of the Service, except to the extent applicable law requires retention (see Section 8), and delete existing copies unless applicable law requires storage.
  • Make available information reasonably necessary to demonstrate compliance with this DPA and allow for, and contribute to, audits (including inspections) conducted by Customer or an auditor mandated by Customer, subject to Section 7.

5. Security Measures

BG HR AI maintains technical and organizational measures appropriate to the risk, including (as applicable and as further described in our Privacy Policy and available on request):

  • Encryption of data in transit (TLS/HTTPS) between the Customer's browser, our application, and our database.
  • Password hashing using industry-standard algorithms (bcrypt); cryptographically random session/authentication tokens with expiry.
  • Role-based access control enforced server-side, restricting access to Customer Personal Data to the Customer's own authorized users and, internally, to BG HR AI personnel who need it to operate the Service.
  • Firm-level data isolation between different Customers within the multi-tenant platform.
  • Rate limiting and brute-force protections on authentication endpoints.
  • Logging and monitoring of administrative and security-relevant actions.
  • A documented process for identifying, triaging, and remediating security vulnerabilities.

Customer acknowledges that no system is completely secure, and BG HR AI's obligation is to implement and maintain measures appropriate to the risk, not to guarantee an absence of incidents.

6. Sub-processors

Customer authorizes BG HR AI to engage the following Sub-processors to process Customer Personal Data as necessary to provide the Service:

Sub-processorPurposeLocation
OpenAI, L.L.C.AI-assisted generation and analysis of job descriptions, resume screening, interview analysis, and related content, via API. Content submitted is used to generate the requested output and is subject to OpenAI's API data-usage terms (as of this writing, OpenAI does not use API-submitted content to train its models by default).United States
Hostinger (or successor hosting provider)Web application hosting, database hosting/storage, and transactional email delivery.EU/US data center regions, per hosting plan
Stripe, Inc.Payment processing for Customer's subscription (billing/payment data only — Stripe does not process candidate/employee data).United States / global

BG HR AI will provide at least 30 days' notice (via email to the Customer's account administrator or an in-app/website notice) before authorizing any new Sub-processor to process Customer Personal Data, except where a shorter period is necessary to address an urgent security or legal requirement. Customer may object on reasonable data-protection grounds within that period by contacting legal@bghrai.com; the parties will work in good faith to resolve the objection, which may include Customer suspending or terminating the affected part of the Service if no resolution is reached.

BG HR AI remains liable to Customer for the acts and omissions of its Sub-processors to the same extent BG HR AI would be liable if performing the services of each Sub-processor directly, and imposes data protection obligations on Sub-processors that are no less protective than those in this DPA.

7. Audits

BG HR AI will make available on request a summary of its current security practices and, where reasonably available, third-party certifications or assessments. Customer (or its mandated auditor, subject to a reasonable confidentiality undertaking) may request a more detailed audit or on-site/remote inspection no more than once per 12-month period, on at least 30 days' written notice, at Customer's expense, unless mandated by a supervisory authority or triggered by a confirmed Personal Data Breach affecting Customer Personal Data (in which case reasonable notice and cost-sharing will be discussed in good faith).

8. International Transfers

Where Customer Personal Data is transferred from the European Economic Area, United Kingdom, or Switzerland to BG HR AI or a Sub-processor located outside of that territory (including the United States), the transfer is made subject to the European Commission's Standard Contractual Clauses (or the equivalent UK/Swiss addendum), incorporated by reference into this DPA, or another valid transfer mechanism under Applicable Data Protection Law.

9. Retention and Deletion

Customer Personal Data is retained for as long as Customer's account/subscription is active, plus up to 90 days afterward to allow for account recovery, unless Customer requests earlier deletion or export. On written request (privacy@bghrai.com or legal@bghrai.com), BG HR AI will delete or export Customer Personal Data within a commercially reasonable time, except where retention is required by law (e.g., financial/billing records) or necessary to resolve disputes and enforce agreements.

10. Automated Processing and AI Use

The Service uses AI (including third-party large language models, see Section 6) to help generate job descriptions, screen resumes, and evaluate candidates against Customer-defined criteria. AI-generated scores, rankings, and recommendations are decision-support tools: BG HR AI does not itself make hiring, promotion, or termination decisions, and Customer is responsible for ensuring a qualified human reviews and makes the final call on any decision that produces legal or similarly significant effects on a candidate or employee (consistent with Article 22 GDPR and equivalent automated-decision-making rules in other jurisdictions), and for any additional obligations applicable to the use of AI in employment/recruitment contexts in Customer's jurisdiction (for example, obligations that may apply under the EU AI Act to "high-risk" AI systems used in recruitment, or US state/local automated-employment-decision-tool laws). BG HR AI will provide reasonable information about the Service's AI functionality to support Customer's own compliance assessment on request.

11. Liability and Term

Each party's liability arising out of or in connection with this DPA, whether in contract, tort, or otherwise, is subject to the limitations of liability set out in our Terms of Service. This DPA remains in effect for as long as BG HR AI processes Customer Personal Data on Customer's behalf, and terminates automatically upon completion of the deletion/return process described in Section 9.

12. Contact

Questions about this DPA, sub-processor changes, or requests for a countersigned version: legal@bghrai.com. Data protection questions generally: privacy@bghrai.com / dpo@bghrai.com.


This template DPA is designed to meet the requirements of GDPR Article 28(3) and equivalent provisions of other Applicable Data Protection Laws for a standard SaaS engagement. It is not a substitute for independent legal advice; enterprise customers with specific regulatory requirements should have their own counsel review it alongside our Terms of Service and Privacy Policy.