Last updated: June 2026

ENDE
This English translation is provided for convenience only. The German version is the legally binding text. View the German version.

Data Processing Agreement (DPA)

under Art. 28 GDPR

between the respective customer of the Pickr platform (hereinafter the “Controller”) and Pickr (Agusta GmbH), Oberdorferstraße 4, 6850 Dornbirn, Austria (hereinafter the “Processor”).


§ 1 Subject Matter and Duration of the Data Processing

(1) Subject Matter

The Processor processes personal data on behalf of the Controller in connection with the provision of the Pickr platform (Applicant Tracking System, hereinafter the “Service”). The precise subject matter is set out in the main agreement (Terms of Service) between the parties.

(2) Duration

The data processing begins upon conclusion of this Agreement and ends upon termination of the main agreement, unless this DPA provides otherwise.

§ 2 Specification of the Scope of Processing

(1) Nature of the Processing

Collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, and destruction of personal data.

(2) Purpose of the Processing

Operation of a cloud-based applicant tracking system (ATS) to support the Controller's recruiting processes, including AI-assisted analysis and communication features.

(3) Categories of Data

  • Master data of applicants (name, contact details, address)
  • Application documents (CV, cover letter, certificates)
  • Communication data (emails, conversation notes)
  • Evaluation data (scorecards, interview assessments)
  • Employment-related data (salary expectations, availability)
  • Platform usage data (log files, activity logs)

(4) Categories of Data Subjects

  • Applicants and candidates
  • Employees of the Controller (recruiters, hiring managers)
  • Where applicable, contact persons at the Controller's clients

§ 3 Technical and Organisational Measures

The Processor implements the technical and organisational measures described in Annex 1 in accordance with Art. 32 GDPR. The Processor may adapt these measures, provided that the agreed level of protection is not reduced.

§ 4 Rectification, Erasure, and Restriction of Data

The Processor may only rectify, erase, or restrict the data on the Controller's instructions. Where a data subject contacts the Processor directly, the Processor shall forward the request to the Controller without undue delay.

§ 5 Quality Assurance and Other Obligations of the Processor

The Processor undertakes, in particular, to:

  • process the data solely within the scope of the Controller's instructions;
  • bind persons authorised to process the data to confidentiality;
  • inform the Controller without undue delay if an instruction given violates data protection law;
  • make available all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR;
  • enable and support inspections and audits carried out by the Controller or auditors appointed by the Controller.

§ 6 Sub-Processing Relationships (Sub-Processors)

(1) Approved Sub-Processors

The Controller hereby grants general authorisation for the engagement of sub-processors. The sub-processors engaged as of the date this Agreement is concluded are listed in Annex 2.

(2) Changes

The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors. The Controller has the right to object to such changes.

(3) Obligations towards Sub-Processors

The Processor shall contractually bind sub-processors to the same data protection obligations as those set out in this DPA.

§ 7 Controller's Rights of Inspection

The Controller is entitled to verify, in an appropriate manner, the Processor's compliance with data protection and data security requirements. Inspections must be announced with at least 2 weeks' notice and may not unreasonably interfere with the Processor's operations.

§ 8 Notification of Breaches

The Processor shall support the Controller in complying with its obligations under Art. 32–36 GDPR (security of processing, notification of breaches, data protection impact assessment, prior consultation). The Processor shall notify the Controller without undue delay of any breach of the protection of personal data.

§ 9 Controller's Right to Issue Instructions

The Controller is entitled to issue the Processor with supplementary instructions at any time regarding the nature, scope, and procedure of the data processing. Instructions may be given verbally but must be confirmed in writing.

§ 10 Erasure and Return of Data

Upon completion of the provision of services, the Processor shall erase all personal data or — at the Controller's option — return it, unless there is a statutory obligation to retain it. Erasure shall take place no later than 30 days after termination of the main agreement.

§ 11 Liability

The liability of the parties is governed by the provisions of the main agreement and by applicable statutory law, in particular Art. 82 GDPR.

§ 12 Final Provisions

This Agreement is governed by the laws of the Republic of Austria. The place of jurisdiction is Dornbirn, Austria. Amendments and supplements to this Agreement must be made in writing. Should individual provisions be or become invalid, the validity of the remaining provisions shall not be affected.


Annex 1: Technical and Organisational Measures (TOMs)

§ 1 Confidentiality (Art. 32(1)(b) GDPR)

Physical access control: Server infrastructure is operated exclusively at certified cloud providers (Supabase/AWS Frankfurt). Physical access is restricted to authorised personnel.

System access control: Access to the platform requires a valid user account. Passwords are hashed in line with the current state of the art (bcrypt). Minimum password length of 8 characters.

Data access control: Role-based access control system (RBAC) with at least 6 hierarchy levels. Database access is governed by Row-Level Security (RLS) at the database level. Multi-factor authentication (MFA) is available.

Separation control: Tenant separation at the database level via organisation-based data isolation (org_id). Complete data separation between different customer organisations.

§ 2 Integrity (Art. 32(1)(b) GDPR)

Transmission control: All data transfers are encrypted using TLS 1.2 or higher. API access is secured using API keys.

Input control: Changes to personal data are logged. Audit logs document security-relevant events.

§ 3 Availability and Resilience (Art. 32(1)(b) GDPR)

Availability control: Automated database backups. Redundant infrastructure at the cloud provider. Monitoring and alerting for system outages.

Recoverability: Point-in-Time Recovery (PITR) for the database. Defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO).

§ 4 Procedures for Regular Review

Regular security reviews of the infrastructure. Dependency updates and security patches are applied promptly. Annual review and update of the TOMs.


Annex 2: Approved Sub-Processors

ProviderLocationPurposeThird-Country Legal Basis
Supabase, Inc.USA (data storage: EU/Frankfurt)Database hosting, authenticationEU Standard Contractual Clauses
Vercel, Inc.USA (serverless: Frankfurt)Application hostingEU Standard Contractual Clauses
Anthropic, PBCUSAAI processing services (text analysis, summarisation)EU Standard Contractual Clauses
Voyage AI (Voyage AI Lab, Inc.)USAAI processing services (semantic search / embeddings)EU Standard Contractual Clauses
Deepgram, Inc.USATranscription of interview audioEU Standard Contractual Clauses
Daily (Pluot Labs, Inc.)USAVideo interview infrastructureEU Standard Contractual Clauses
Resend (Plus Five Five, Inc.)USATransactional email deliveryEU Standard Contractual Clauses
Stripe, Inc.USAPayment processingEU Standard Contractual Clauses
Google LLCUSAEmail integration (Gmail, optional)EU Standard Contractual Clauses
Microsoft CorporationUSAEmail integration (Outlook, optional)EU Standard Contractual Clauses
HeyReachEULinkedIn outreach integration (optional, only when the channel extension is activated)EU Standard Contractual Clauses
Meta Platforms Ireland LimitedEU/EEAWhatsApp integration (optional, only when the channel extension is activated)Within the EU/EEA

Note on channel integrations: HeyReach and WhatsApp (Meta) are optional extensions. When an integration is activated, message content is processed via the respective third-party provider's infrastructure. That provider's privacy terms apply to the message content. Pickr stores only metadata (sender, timestamp, candidate association) for the Unified Inbox.


Annex 3: Data Protection Contact Details

Processor:

Agusta GmbH
Oberdorferstraße 4
6850 Dornbirn
Austria
Email: datenschutz@pickr.dev

For questions regarding data processing or to exercise your rights as a data subject, please contact the email address above.


Last updated: June 2026 · Agusta GmbH, Dornbirn, Austria