Data Processing Agreement

How we handle data on your behalf

Last updated: 28 July 2026

This Data Processing Agreement (“DPA”) forms part of our Terms of Use and applies whenever Beagler processes personal data on your behalf, such as the client and candidate data inside your workspace. It explains each party’s responsibilities under data-protection law, including the GDPR.

1

Parties & Roles

This DPA is between:

  • You, the Customer — the data controller, who decides why and how personal data is processed
  • Beagler — the data processor, which processes that data on your documented instructions
2

Subject Matter & Duration

Beagler processes personal data solely to provide the recruitment services described in the Terms of Use. Processing continues for as long as you use the Service and ends when your workspace is closed and data is deleted in line with this DPA.

3

Types of Personal Data

The personal data processed may include:

  • Names
  • Email addresses and phone numbers
  • Postal addresses
  • Resumes and supporting documents
  • Salary expectations and availability
  • Interview notes and scorecards
  • Client and user contact details
4

Categories of Data Subjects

  • Job candidates
  • Client contacts
  • Your employees and workspace users
5

Processing Activities

On your behalf, Beagler may:

  • Store and organize recruitment data
  • Manage job postings and candidate submissions
  • Schedule interviews and record feedback
  • Generate invoices, payroll and expenses
  • Provide AI-assisted parsing, tagging and matching
  • Send transactional emails and route the messages you send
  • Perform backups and restores
6

Your Responsibilities (Controller)

As the controller, you:

  • Confirm you have a lawful basis to process the data
  • Obtain candidate consent or provide notice where required
  • Are responsible for the accuracy of the data you enter
  • Control access through roles and permissions
  • Issue processing instructions only through lawful use of the Service
7

Beagler's Responsibilities (Processor)

As the processor, Beagler will:

  • Process personal data only on your documented instructions
  • Ensure people authorized to process data are bound by confidentiality
  • Implement appropriate technical and organizational security measures
  • Assist you in responding to data subject requests
  • Notify you of personal data breaches without undue delay
  • Delete or return personal data at the end of the Service, subject to legal obligations
8

Sub-Processors

Beagler engages the following sub-processors to process Customer Personal Data on your behalf:

  • Hetzner Online GmbH (Germany). Hosts the application and stores your workspace database and uploaded files, including resumes and documents.
  • Amazon Web Services. Stores encrypted backups of the database and of uploaded files, which contain the same categories of personal data as the live system, including resumes and documents. Backups are stored in the European Union (Frankfurt).
  • OpenAI, L.L.C. (United States). Processes text you submit to an AI feature, including resume content, to return parsing, tagging, scoring and matching results. The model used is GPT-4o mini. OpenAI does not train its models on data submitted through its API.
  • Email delivery. Sends transactional messages generated by the Service, such as notifications, invoices and candidate correspondence.
  • Expo (United States), with Apple and Google. Deliver push notifications to the mobile app using a device token.

Stripe processes subscription payments. That relates to your own billing data rather than Customer Personal Data, and for it Beagler acts as controller.

The analytics and advertising technologies described in our Privacy Policy run on our public website and apply to visitors, not to data inside your workspace. They are not sub-processors under this DPA.

All sub-processors are bound by contract to data protection obligations no less protective than this DPA. We will give reasonable notice of any new sub-processor so you can object on legitimate grounds.

9

Security Measures

Our safeguards include:

  • Encryption in transit (TLS 1.3) and at rest (AES-256), covering the live database, uploaded files and backups
  • Hashed passwords and secure authentication tokens
  • Role-based access control
  • Logical isolation of every workspace
  • Continuous activity logging and monitoring
  • Regular, secure backups
10

Data Subject Requests

Beagler will assist you, where reasonably possible, in responding to requests from data subjects to:

  • Access their data
  • Correct inaccurate data
  • Delete their data
  • Restrict or object to processing
  • Receive a portable copy
11

Personal Data Breaches

If a personal data breach occurs, Beagler will:

  • Notify you without undue delay after becoming aware of it
  • Provide the information you reasonably need to meet your own notification obligations
  • Take reasonable steps to contain and remediate the breach
12

Data Retention & Deletion

  • Data is retained for as long as you use the Service
  • Archived records remain stored but inactive until restored or deleted
  • On termination, you can request export or deletion of your data
  • Residual copies may remain in encrypted backups for up to 30 days, after which the backup containing them is automatically deleted
13

International Transfers

  • Where personal data is transferred out of the EEA or the UK, the transfer is made under the mechanisms in the relevant sub-processor’s data processing agreement, such as the European Commission’s Standard Contractual Clauses or the EU to US Data Privacy Framework where that provider is certified.
  • Beagler will make available, on request, details of the safeguards applying to a specific transfer.

Customer Personal Data is hosted in Germany, in the European Union, on Hetzner infrastructure. Some sub-processors listed above are established in the United States and will therefore process personal data outside the EEA and the United Kingdom. The most significant is OpenAI, because resume text submitted to an AI feature is processed there.

14

Audits & Compliance

On reasonable written request, Beagler will make available the information necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by you or an auditor you appoint, subject to confidentiality and without compromising the security of other customers.

15

Liability

Liability under this DPA is subject to the limitations and exclusions set out in the Terms of Use.

16

Governing Law

This DPA is governed by the laws of the State of Delaware, United States, consistent with the Terms of Use, while applying the data-protection safeguards required by the GDPR and other applicable laws.

17

Contact

For any data-protection question, or to exercise rights under this DPA, contact our team:

We use cookies to understand traffic and make Beagler better, a few for analytics and marketing. You can accept them, reject them, or choose category by category. See our Privacy Policy.