Last updated: June 2026
Data Processing Agreement (DPA)
under Art. 28 GDPR
between the respective customer of the Pickr platform (hereinafter the “Controller”) and Pickr (Agusta GmbH), Oberdorferstraße 4, 6850 Dornbirn, Austria (hereinafter the “Processor”).
§ 1 Subject Matter and Duration of the Data Processing
(1) Subject Matter
The Processor processes personal data on behalf of the Controller in connection with the provision of the Pickr platform (Applicant Tracking System, hereinafter the “Service”). The precise subject matter is set out in the main agreement (Terms of Service) between the parties.
(2) Duration
The data processing begins upon conclusion of this Agreement and ends upon termination of the main agreement, unless this DPA provides otherwise.
§ 2 Specification of the Scope of Processing
(1) Nature of the Processing
Collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, and destruction of personal data.
(2) Purpose of the Processing
Operation of a cloud-based applicant tracking system (ATS) to support the Controller's recruiting processes, including AI-assisted analysis and communication features.
(3) Categories of Data
- Master data of applicants (name, contact details, address)
- Application documents (CV, cover letter, certificates)
- Communication data (emails, conversation notes)
- Evaluation data (scorecards, interview assessments)
- Employment-related data (salary expectations, availability)
- Platform usage data (log files, activity logs)
(4) Categories of Data Subjects
- Applicants and candidates
- Employees of the Controller (recruiters, hiring managers)
- Where applicable, contact persons at the Controller's clients
§ 3 Technical and Organisational Measures
The Processor implements the technical and organisational measures described in Annex 1 in accordance with Art. 32 GDPR. The Processor may adapt these measures, provided that the agreed level of protection is not reduced.
§ 4 Rectification, Erasure, and Restriction of Data
The Processor may only rectify, erase, or restrict the data on the Controller's instructions. Where a data subject contacts the Processor directly, the Processor shall forward the request to the Controller without undue delay.
§ 5 Quality Assurance and Other Obligations of the Processor
The Processor undertakes, in particular, to:
- process the data solely within the scope of the Controller's instructions;
- bind persons authorised to process the data to confidentiality;
- inform the Controller without undue delay if an instruction given violates data protection law;
- make available all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR;
- enable and support inspections and audits carried out by the Controller or auditors appointed by the Controller.
§ 6 Sub-Processing Relationships (Sub-Processors)
(1) Approved Sub-Processors
The Controller hereby grants general authorisation for the engagement of sub-processors. The sub-processors engaged as of the date this Agreement is concluded are listed in Annex 2.
(2) Changes
The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors. The Controller has the right to object to such changes.
(3) Obligations towards Sub-Processors
The Processor shall contractually bind sub-processors to the same data protection obligations as those set out in this DPA.
§ 7 Controller's Rights of Inspection
The Controller is entitled to verify, in an appropriate manner, the Processor's compliance with data protection and data security requirements. Inspections must be announced with at least 2 weeks' notice and may not unreasonably interfere with the Processor's operations.
§ 8 Notification of Breaches
The Processor shall support the Controller in complying with its obligations under Art. 32–36 GDPR (security of processing, notification of breaches, data protection impact assessment, prior consultation). The Processor shall notify the Controller without undue delay of any breach of the protection of personal data.
§ 9 Controller's Right to Issue Instructions
The Controller is entitled to issue the Processor with supplementary instructions at any time regarding the nature, scope, and procedure of the data processing. Instructions may be given verbally but must be confirmed in writing.
§ 10 Erasure and Return of Data
Upon completion of the provision of services, the Processor shall erase all personal data or — at the Controller's option — return it, unless there is a statutory obligation to retain it. Erasure shall take place no later than 30 days after termination of the main agreement.
§ 11 Liability
The liability of the parties is governed by the provisions of the main agreement and by applicable statutory law, in particular Art. 82 GDPR.
§ 12 Final Provisions
This Agreement is governed by the laws of the Republic of Austria. The place of jurisdiction is Dornbirn, Austria. Amendments and supplements to this Agreement must be made in writing. Should individual provisions be or become invalid, the validity of the remaining provisions shall not be affected.
Annex 1: Technical and Organisational Measures (TOMs)
§ 1 Confidentiality (Art. 32(1)(b) GDPR)
Physical access control: Server infrastructure is operated exclusively at certified cloud providers (Supabase/AWS Frankfurt). Physical access is restricted to authorised personnel.
System access control: Access to the platform requires a valid user account. Passwords are hashed in line with the current state of the art (bcrypt). Minimum password length of 8 characters.
Data access control: Role-based access control system (RBAC) with at least 6 hierarchy levels. Database access is governed by Row-Level Security (RLS) at the database level. Multi-factor authentication (MFA) is available.
Separation control: Tenant separation at the database level via organisation-based data isolation (org_id). Complete data separation between different customer organisations.
§ 2 Integrity (Art. 32(1)(b) GDPR)
Transmission control: All data transfers are encrypted using TLS 1.2 or higher. API access is secured using API keys.
Input control: Changes to personal data are logged. Audit logs document security-relevant events.
§ 3 Availability and Resilience (Art. 32(1)(b) GDPR)
Availability control: Automated database backups. Redundant infrastructure at the cloud provider. Monitoring and alerting for system outages.
Recoverability: Point-in-Time Recovery (PITR) for the database. Defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO).
§ 4 Procedures for Regular Review
Regular security reviews of the infrastructure. Dependency updates and security patches are applied promptly. Annual review and update of the TOMs.
Annex 2: Approved Sub-Processors
| Provider | Location | Purpose | Third-Country Legal Basis |
|---|---|---|---|
| Supabase, Inc. | USA (data storage: EU/Frankfurt) | Database hosting, authentication | EU Standard Contractual Clauses |
| Vercel, Inc. | USA (serverless: Frankfurt) | Application hosting | EU Standard Contractual Clauses |
| Anthropic, PBC | USA | AI processing services (text analysis, summarisation) | EU Standard Contractual Clauses |
| Voyage AI (Voyage AI Lab, Inc.) | USA | AI processing services (semantic search / embeddings) | EU Standard Contractual Clauses |
| Deepgram, Inc. | USA | Transcription of interview audio | EU Standard Contractual Clauses |
| Daily (Pluot Labs, Inc.) | USA | Video interview infrastructure | EU Standard Contractual Clauses |
| Resend (Plus Five Five, Inc.) | USA | Transactional email delivery | EU Standard Contractual Clauses |
| Stripe, Inc. | USA | Payment processing | EU Standard Contractual Clauses |
| Google LLC | USA | Email integration (Gmail, optional) | EU Standard Contractual Clauses |
| Microsoft Corporation | USA | Email integration (Outlook, optional) | EU Standard Contractual Clauses |
| HeyReach | EU | LinkedIn outreach integration (optional, only when the channel extension is activated) | EU Standard Contractual Clauses |
| Meta Platforms Ireland Limited | EU/EEA | WhatsApp integration (optional, only when the channel extension is activated) | Within the EU/EEA |
Note on channel integrations: HeyReach and WhatsApp (Meta) are optional extensions. When an integration is activated, message content is processed via the respective third-party provider's infrastructure. That provider's privacy terms apply to the message content. Pickr stores only metadata (sender, timestamp, candidate association) for the Unified Inbox.
Annex 3: Data Protection Contact Details
Processor:
Agusta GmbH
Oberdorferstraße 4
6850 Dornbirn
Austria
Email: datenschutz@pickr.dev
For questions regarding data processing or to exercise your rights as a data subject, please contact the email address above.
Last updated: June 2026 · Agusta GmbH, Dornbirn, Austria