Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Dunross AI s.r.o. ("Processor," "Dunross AI," "we," "us") and the Customer ("Controller," "you") that has accepted the Terms of Service for the Klara AI pre-screening platform (the "Service"). This DPA governs the processing of personal data by Dunross AI on behalf of the Customer in connection with the Service.
By using the Service, you accept this DPA on behalf of yourself and the legal entity you represent. If you require a signed copy of this DPA for your records, contact [email protected].
1. Definitions
Terms used in this DPA have the meanings set out in the EU General Data Protection Regulation 2016/679 ("GDPR") unless otherwise defined:
- "Controller" means the Customer, who determines the purposes and means of processing personal data.
- "Processor" means Dunross AI s.r.o., who processes personal data on behalf of the Controller.
- "Personal Data" means any information relating to an identified or identifiable natural person processed under this DPA.
- "Processing" means any operation performed on Personal Data, including collection, recording, organization, storage, alteration, retrieval, use, disclosure, erasure, or destruction.
- "Data Subject" means the natural person to whom Personal Data relates (e.g., a Candidate).
- "Sub-processor" means any third party engaged by Dunross AI to process Personal Data on behalf of the Controller.
- "Data Subject Request" means a request from a Data Subject to exercise rights under GDPR (e.g., access, erasure, rectification).
- "Personal Data Breach" has the meaning set out in Article 4(12) of the GDPR.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission for the transfer of Personal Data to third countries.
Terms not defined here have the meanings set out in the Terms of Service.
2. Subject matter and duration
2.1 Subject matter
This DPA governs the processing of Personal Data by Dunross AI on behalf of the Customer as part of providing the Service. Details of the processing are set out in Annex 1.
2.2 Duration
This DPA takes effect when the Customer accepts the Terms of Service and continues for as long as Dunross AI processes Personal Data on behalf of the Customer. Termination of the Terms of Service automatically terminates this DPA, subject to the surviving obligations set out herein.
3. Roles and responsibilities
3.1 Controller
The Customer is the Controller of Personal Data processed through the Service, including Candidate data. The Customer:
- Determines the purposes and means of processing
- Is responsible for obtaining any required consents from Candidates
- Is responsible for providing required notices to Candidates, including notice that they will be screened by an AI tool
- Is responsible for the lawfulness of the processing instructions given to Dunross AI
- Is responsible for ensuring that its use of the Service complies with applicable data protection laws
3.2 Processor
Dunross AI is the Processor of Personal Data processed through the Service on behalf of the Customer. Dunross AI:
- Processes Personal Data only on documented instructions from the Controller, as set out in this DPA and the Terms of Service
- Implements appropriate technical and organizational security measures
- Engages Sub-processors only in accordance with this DPA
- Assists the Controller with its obligations under GDPR
- Returns or deletes Personal Data on termination
4. Processing instructions
4.1 Documented instructions
Dunross AI processes Personal Data only on documented instructions from the Controller. The Terms of Service, this DPA, and the Customer's use of the Service constitute the Controller's documented instructions. Additional instructions outside the scope of the Service may be agreed in writing between the parties.
4.2 Lawfulness of instructions
The Customer represents and warrants that:
- Its instructions to Dunross AI comply with applicable data protection laws
- It has a lawful basis for the processing of Personal Data through the Service
- It has provided all required notices and obtained all required consents from Candidates
4.3 Notification of unlawful instructions
If Dunross AI believes that an instruction from the Controller violates applicable data protection laws, Dunross AI will notify the Controller and may refuse to act on the instruction until clarified.
5. Confidentiality
Dunross AI ensures that personnel authorized to process Personal Data:
- Are bound by confidentiality obligations
- Have received appropriate training on data protection
- Process Personal Data only as necessary to perform their duties
Confidentiality obligations survive termination of employment or engagement with Dunross AI.
6. Security
6.1 Technical and organizational measures
Dunross AI implements the technical and organizational measures set out in Annex 2 to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
6.2 Security review
Dunross AI reviews and updates its security measures regularly to maintain a level of security appropriate to the risk, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing.
6.3 Customer's own security
The Customer is responsible for the security of its own systems, including the confidentiality of its account credentials and the security of its personnel's access to the Service.
7. Sub-processors
7.1 Authorization
The Customer provides general authorization for Dunross AI to engage Sub-processors for the provision of the Service. The current list of Sub-processors is set out in Annex 3.
7.2 Sub-processor obligations
Dunross AI ensures that each Sub-processor is bound by written terms that impose data protection obligations substantially equivalent to those in this DPA, including:
- Processing Personal Data only on documented instructions
- Implementing appropriate security measures
- Assisting with Data Subject Requests
- Notifying of Personal Data Breaches
- Returning or deleting Personal Data on termination
7.3 Liability for Sub-processors
Dunross AI remains liable to the Controller for the performance of each Sub-processor's obligations under this DPA.
7.4 Notification of changes
Dunross AI will notify the Controller of any intended addition or replacement of Sub-processors with at least thirty (30) days' advance notice. The Customer may object to a new Sub-processor on reasonable data protection grounds within fifteen (15) days of notification. If the parties cannot agree on a resolution, the Customer may terminate this DPA and the relevant Service component without penalty.
8. Data Subject Requests
8.1 Forwarding requests
If Dunross AI receives a Data Subject Request directly from a Candidate or other Data Subject regarding Personal Data processed on behalf of the Controller, Dunross AI will:
- Promptly forward the request to the Controller without responding to the substance of the request (except to acknowledge receipt and redirect)
- Provide reasonable assistance to the Controller in responding to the request
8.2 Direct requests for Candidate rights
Notwithstanding Section 8.1, Dunross AI may respond directly to Candidate requests regarding processing where Dunross AI is the Controller (e.g., requests regarding our Privacy Policy, our use of aggregated data, or our account management practices).
8.3 Assistance
Dunross AI assists the Controller, by appropriate technical and organizational measures, in fulfilling its obligation to respond to Data Subject Requests under GDPR Articles 15-22.
9. Personal Data Breach notification
9.1 Notification timing
If Dunross AI becomes aware of a Personal Data Breach affecting Personal Data processed on behalf of the Controller, Dunross AI will notify the Controller without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach.
9.2 Notification content
The notification will include, to the extent known at the time:
- The nature of the breach, including the categories and approximate number of Data Subjects and records affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach and mitigate its effects
- Contact details for follow-up
Where complete information is not available within seventy-two (72) hours, Dunross AI will provide initial notification within that timeframe and follow up with additional information as it becomes available.
9.3 Assistance
Dunross AI assists the Controller in fulfilling the Controller's own notification obligations under GDPR Articles 33 and 34, including notification to supervisory authorities and affected Data Subjects.
10. Data Protection Impact Assessments
Dunross AI provides reasonable assistance to the Controller with Data Protection Impact Assessments (DPIAs) and prior consultations with supervisory authorities under GDPR Articles 35 and 36, taking into account the nature of the processing and the information available to Dunross AI.
11. International transfers
11.1 EU/EEA processing
Dunross AI processes Personal Data primarily within the European Union or European Economic Area.
11.2 Transfers outside the EU/EEA
Where Dunross AI transfers Personal Data outside the EU/EEA (including to Sub-processors located outside the EU/EEA), Dunross AI ensures that appropriate safeguards are in place, including:
- An adequacy decision by the European Commission, or
- Standard Contractual Clauses, or
- Other valid transfer mechanism under GDPR Chapter V
The Standard Contractual Clauses referenced in Annex 4 apply to such transfers.
11.3 Controller's role in transfers
By accepting this DPA, the Customer authorizes Dunross AI to transfer Personal Data outside the EU/EEA in accordance with this Section and the Sub-processor list in Annex 3.
12. Audits
12.1 Right to audit
The Controller has the right to audit Dunross AI's compliance with this DPA, including its security measures, no more than once per calendar year unless a Personal Data Breach has occurred or a regulatory investigation requires it.
12.2 Audit procedure
Audits are conducted as follows:
- The Controller provides at least thirty (30) days' advance written notice
- Audits take place during normal business hours and do not unreasonably interfere with Dunross AI's operations
- The auditor signs a confidentiality agreement before access is granted
- The Controller bears the costs of the audit, except where the audit reveals material non-compliance by Dunross AI, in which case Dunross AI bears the costs
12.3 Alternative to physical audits
In lieu of physical audits, the Controller may accept third-party audit reports, security certifications, or written responses to security questionnaires provided by Dunross AI.
13. Return or deletion of Personal Data
13.1 On termination
Upon termination of the Terms of Service, Dunross AI will, at the Controller's choice:
- Return all Personal Data to the Controller in a structured, commonly used, machine-readable format, or
- Delete all Personal Data from Dunross AI's systems
The Controller must specify its choice within thirty (30) days of termination. If no choice is specified, Dunross AI may delete the Personal Data after that period.
13.2 Backups and legal retention
Personal Data contained in routine backups may be retained until the backup cycle overwrites them. Personal Data subject to legal retention obligations may be retained for the period required by law.
13.3 Confirmation
Dunross AI will provide written confirmation of deletion or return on request.
14. Liability
Liability under this DPA is governed by the Limitation of Liability provisions of the Terms of Service, except where applicable data protection law mandates a different allocation.
Nothing in this DPA limits the rights of Data Subjects under applicable data protection law.
15. Governing law and jurisdiction
This DPA is governed by the laws of the Czech Republic and is subject to the jurisdiction provisions of the Terms of Service.
To the extent of any conflict between this DPA and the Terms of Service in matters of data protection, this DPA prevails.
16. Changes to this DPA
We may update this DPA from time to time to reflect changes in applicable data protection law, our processing practices, or our Sub-processors. Material changes will be communicated by email at least thirty (30) days before they take effect.
For changes required by law, the new version takes effect on the effective date specified in the notice, regardless of the thirty (30) day notice period.
17. Contact
For questions about this DPA or to exercise rights under it:
- Email: [email protected]
- Postal: Dunross AI s.r.o., Pod Chytárnou 46, Zaječice - Pyšely, 251 67, Czech Republic
Annex 1 — Details of processing
Subject matter and nature of processing
The Processor processes Personal Data in connection with providing the Klara AI pre-screening platform, which conducts structured voice interviews with job Candidates on behalf of the Controller.
Purpose of processing
To enable the Controller to screen job Candidates using AI-powered voice interviews, including:
- Conducting voice interviews with Candidates
- Generating transcripts and structured screening reports
- Storing Candidate data for the Controller's hiring use
- Facilitating next-step scheduling (e.g., interview booking)
- Providing analytics and reporting to the Controller
Duration of processing
For the duration of the Terms of Service, and as set out in the Privacy Policy data retention schedule.
Categories of Data Subjects
- Job Candidates invited by the Controller to complete Klara interviews
- Users of the Controller (e.g., recruiters, HR staff, administrators)
Categories of Personal Data
Candidate data:
- Identity data (name, email address, phone number, preferred language)
- Voice recordings of interviews
- Transcripts of interviews
- Responses to screening questions
- Pass/fail status against eligibility criteria
- Technical data (IP address, browser type, device information)
User data:
- Account information (name, email address, organization, role)
- Authentication credentials (hashed passwords, tokens)
- Usage data (features used, actions taken)
Special categories of Personal Data
Klara is not designed to process special categories of Personal Data under GDPR Article 9 (e.g., racial or ethnic origin, political opinions, religious beliefs, health data, biometric data for unique identification, etc.).
While voice recordings could theoretically be analyzed as biometric data, Klara does not perform biometric identification or categorization. Voice recordings are used solely for transcription and linguistic analysis of the content of Candidate responses.
The Controller agrees not to instruct Klara to process special categories of Personal Data unless a specific lawful basis applies and the Controller has notified Dunross AI in writing.
Processing operations
Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission (to the Controller), restriction, erasure, and destruction.
Annex 2 — Technical and organizational security measures
Dunross AI implements the following technical and organizational measures to ensure a level of security appropriate to the risk:
Access control
- Multi-factor authentication for administrative access to production systems
- Role-based access control with least-privilege principles
- Regular review of access permissions
- Immediate revocation of access on personnel departure
Encryption
- TLS encryption for all data in transit (HTTPS, TLS 1.2 or higher)
- Encryption at rest for all Personal Data stored in production databases
- Encryption of OAuth access and refresh tokens
- Secrets management for credentials and API keys
Network security
- Firewall protection for production infrastructure
- DDoS mitigation through CDN provider
- Network segmentation between application, database, and administrative layers
- Regular security patching of operating systems and dependencies
Application security
- Secure development practices, including code review
- Input validation and output encoding to prevent injection attacks
- Protection against common web vulnerabilities (OWASP Top 10)
- Regular dependency vulnerability scanning
Logging and monitoring
- Logging of access to Personal Data and administrative actions
- Monitoring for unusual activity and potential security incidents
- Log retention sufficient to support incident investigation
Personnel security
- Confidentiality obligations binding all personnel
- Background checks where legally permitted and relevant
- Data protection training for personnel handling Personal Data
Incident response
- Documented incident response procedures
- Designated personnel responsible for incident response
- Personal Data Breach notification procedures consistent with Section 9 of this DPA
Business continuity
- Regular backups of Personal Data
- Backup restoration testing
- Disaster recovery procedures
Physical security
Physical security of the underlying infrastructure is provided by the hosting Sub-processors, who maintain certifications including ISO 27001 and SOC 2 Type II as applicable.
Continuous improvement
These measures are reviewed and updated regularly to reflect changes in the threat landscape, the state of the art, and the scope of processing.
Annex 3 — Sub-processors
The following Sub-processors are engaged by Dunross AI to provide the Service:
| Sub-processor | Role | Location | Personal Data processed |
|---|---|---|---|
| Hetzner Online GmbH | Cloud hosting and infrastructure | Germany (EU) | All Personal Data |
| Supabase, Inc. | Managed database services | EU region | All Personal Data |
| OpenAI, OpCo LLC | AI inference for natural language processing | United States | Interview transcripts and screening criteria |
| Cartesia, Inc. | Text-to-speech voice generation | United States | Klara-generated text only (no Candidate data) |
| LiveKit, Inc. | Real-time voice infrastructure | United States and EU | Voice streams during active interview sessions |
| Soniox, Inc. | Speech-to-text transcription | United States | Voice streams during active interview sessions |
| Resend, Inc. | Email delivery | United States | Email addresses and email content |
| Cloudflare, Inc. | Content delivery network and edge security | Global edge network | IP addresses, technical data |
Updates to this list
This list is reviewed regularly. Updates are communicated in accordance with Section 7.4 of this DPA. The current list is always available at this URL or on request to [email protected].
Transfers outside the EU/EEA
Sub-processors located outside the EU/EEA process Personal Data under the Standard Contractual Clauses referenced in Annex 4 or other valid transfer mechanism.
Annex 4 — Standard Contractual Clauses
Where Personal Data is transferred outside the EU/EEA to a Sub-processor in a country not subject to an adequacy decision by the European Commission, the parties incorporate by reference the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, specifically:
- Module Two (Controller-to-Processor) applies to transfers from the Controller through Dunross AI to Sub-processors acting as further processors.
- Module Three (Processor-to-Processor) applies to transfers between Dunross AI and Sub-processors where both act as processors.
The following selections apply to the Standard Contractual Clauses:
- Docking clause (Clause 7): applies
- Sub-processor authorization (Clause 9): Option 2 (general written authorization) applies, with notification period as set out in Section 7.4 of this DPA
- Governing law (Clause 17): the law of the Czech Republic applies
- Choice of forum (Clause 18): the courts of the Czech Republic apply
The annexes to the Standard Contractual Clauses are populated as follows:
- Annex I.A (List of parties): the Controller is the Customer identified in the Terms of Service; the data importer is Dunross AI or the relevant Sub-processor
- Annex I.B (Description of transfer): as set out in Annex 1 of this DPA
- Annex I.C (Competent supervisory authority): the supervisory authority of the Controller's establishment, or the lead supervisory authority where applicable
- Annex II (Technical and organizational measures): as set out in Annex 2 of this DPA
- Annex III (List of Sub-processors): as set out in Annex 3 of this DPA