Skip to main content

Data Processing Agreement

1. Purpose and scope

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Service or applicable Order Form between Customer and Max Kugland, trading as Quinta ("Quinta") (together, "the Agreement"). It applies whenever Quinta processes personal data contained in Customer Data on Customer's behalf in the course of providing the Service, and reflects the parties' obligations under Art. 28 of Regulation (EU) 2016/679 ("GDPR"). In this relationship, Customer is the controller and Quinta is the processor.

2. Definitions

"Personal data," "processing," "controller," "processor," "data subject," "personal data breach," and "supervisory authority" have the meanings given in Art. 4 GDPR. "Sub-processor" means a third party engaged by Quinta to process personal data in order to provide the Service. "Customer Data" has the meaning given in the Terms of Service.

3. Subject matter, duration, nature, and purpose

The subject matter, duration, nature and purpose of processing, the categories of data subjects, and the types of personal data are set out in Annex 1. This DPA remains in effect for as long as Quinta processes personal data on Customer's behalf under the Agreement.

4. Customer's instructions

Quinta will process personal data only on Customer's documented instructions, including as necessary to provide the Service in the ordinary course (e.g. storage, search, and AI-assisted analysis of records Customer or its users add), unless required to do otherwise by EU or member state law, in which case Quinta will inform Customer of that legal requirement before processing, unless the law prohibits doing so. Quinta will inform Customer if, in its opinion, an instruction infringes the GDPR or another data protection provision.

5. Confidentiality

Quinta ensures that persons authorized to process personal data under this DPA have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

6. Security of processing

Quinta implements the technical and organizational measures set out in Annex 2, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects, consistent with Art. 32 GDPR.

7. Sub-processors

Customer authorizes Quinta to engage the sub-processors listed in Annex 3. Quinta will give Customer at least 30 days' notice before engaging a new sub-processor, so Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, either party may terminate the affected part of the Service. Quinta will impose data protection obligations substantially similar to those in this DPA on each sub-processor, and remains liable to Customer for a sub-processor's performance of those obligations.

8. International transfers

Where a sub-processor is located, or processes personal data, outside the EU/EEA, Quinta ensures the transfer is subject to appropriate safeguards under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses, an adequacy decision, or another legally recognized transfer mechanism.

9. Assistance to Customer

Taking into account the nature of the processing, Quinta will reasonably assist Customer, insofar as this is possible, in fulfilling Customer's obligations to respond to requests from data subjects exercising their rights under Chapter III GDPR, and with Customer's obligations under Art. 32–36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the information available to Quinta.

10. Personal data breaches

Quinta will notify Customer without undue delay, and in any event within 72 hours of becoming aware, after confirming a personal data breach affecting Customer Data, and will provide the information reasonably available to it to help Customer meet its own notification obligations under Art. 33 and 34 GDPR.

11. Audits

Quinta will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including by providing a written summary of its technical and organizational measures on request. Customer may request an on-site or third-party audit of Quinta's relevant processing activities on reasonable prior written notice (at least 30 days), no more than once per 12-month period absent a specific concern, conducted during business hours in a manner that avoids unnecessary disruption and preserves the confidentiality of Quinta's other customers.

12. Deletion and return of data

At Customer's choice, and upon termination of the Agreement or on earlier request, Quinta will delete or return all personal data processed on Customer's behalf, and delete existing copies, unless EU or member state law requires continued storage of that personal data.

13. Liability

Each party's liability arising out of or in connection with this DPA is subject to the limitations of liability set out in the Terms of Service, except where GDPR itself assigns liability directly to a party (e.g. Art. 82 GDPR).

14. Order of precedence and term

This DPA applies for as long as Quinta processes personal data on Customer's behalf under the Agreement. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls.

Annex 1 — Details of processing

Subject matter
Hosting, storage, search, and AI-assisted analysis of records (briefs, CVs, interview notes, and related material) that Customer or its users upload to or generate within Quinta, in order to provide the Service.
Duration
For the term of the Agreement, plus any retention period agreed with Customer or required by law, followed by deletion or return per Section 12.
Nature of processing
Collection, storage, organization, structuring, retrieval, search (including AI-assisted semantic search), and AI-assisted analysis and drafting (e.g. embeddings and language-model-based report generation).
Purpose of processing
To provide the Service to Customer as instructed, and for no other purpose (including no use of Customer Data to train general-purpose AI models).
Categories of data subjects
Customer's own users; and individuals referenced in Customer Data that Customer uploads, which may include candidates, referees, interviewees, and other third parties Customer chooses to include.
Types of personal data
Contact and identification details, professional/employment history, interview and assessment notes, and any other personal data Customer includes in the material it uploads. Customer determines what personal data it includes and is responsible for ensuring it has a lawful basis to do so; special categories of data (Art. 9 GDPR) should only be included where Customer has confirmed a lawful basis and appropriate safeguards apply.

Annex 2 — Technical and organizational measures

Annex 3 — Approved sub-processors

OpenAI
AI-assisted analysis of Customer Data (e.g. embeddings and language-model-based drafting of assessments and reports). Located outside the EU/EEA; transfers are subject to the EU Standard Contractual Clauses or another appropriate safeguard.
United Domains AG
Email delivery. Used solely to deliver transactional sign-in emails; does not receive Customer Data. Located in the EU (Germany); no international transfer.
Hetzner Online GmbH
Infrastructure hosting. Located in the EU (Germany); no international transfer.

Contact

Questions about this DPA can be sent to maxtrainbombing. Our full legal contact details are listed in the imprint.