Data Processing Agreement
pursuant to Article 28 GDPR
Version of 8 September 2026
This Agreement is concluded between
the Account Owner as defined in our Terms of Service — the customer that uses the CometHire platform and determines the purposes and means of the processing of personal data described here (the "Controller"),
and
CometHire UG (haftungsbeschränkt), Hermannstraße 91, 12051 Berlin, Germany, registered at Amtsgericht Charlottenburg under HRB 289332 B (the "Processor").
This Agreement forms part of our Terms of Service and takes effect when the Controller accepts those Terms or begins using the Service, whichever is earlier. Art. 28 (9) GDPR permits electronic form, so no signature is required. Controllers who prefer a signed copy can request one from anja@comethire.com — the signed document is identical to this text.
Where the Controller and the Processor have signed an individually negotiated data processing agreement, that document prevails over this one to the extent of any conflict.
The Processor provides software for recruitment and evidence-based candidate review workflows.
The Processor processes personal data solely on behalf of and under the documented instructions of the Controller in accordance with Article 28 GDPR.
This Agreement governs all processing of personal data performed by the Processor on behalf of the Controller in connection with the use of the CometHire platform.
This Agreement remains in force for the duration of the service relationship between the parties and for as long as the Processor processes personal data on behalf of the Controller.
The Processor provides recruitment software that enables the Controller to manage, review and assess candidate applications.
Processing activities may include:
- storage of application documents
- OCR extraction of text from application documents
- AI-assisted de-identification of personal information
- extraction of role-related evaluation criteria from job descriptions
- AI-supported analysis of application documents against criteria defined by the Controller
- generation of requirement-level evidence assessments
- aggregation of requirement-level assessments into an overall evidence level per candidate
- generation of evidence-linked candidate reports and summaries
- collaboration features for recruitment teams
- audit logging
- deletion and retention management
The software is designed as a decision-support tool. The Processor does not make hiring decisions on behalf of the Controller.
- job applicants
- recruiters
- hiring managers
- other users of the Controller
- names
- contact information
- employment history
- education history
- qualifications
- certifications
- skills
- project descriptions
- application documents
- interview notes
- recruiter comments
- review-related information
Applicants may voluntarily provide special category data within application documents. The Processor does not intentionally process special category data for review purposes. Where such information is included by applicants, processing is limited to what is necessary for providing the contracted services.
The Processor shall:
- process personal data only on documented instructions from the Controller
- ensure that personnel authorised to process personal data are subject to confidentiality obligations
- implement appropriate technical and organisational measures
- assist the Controller in fulfilling data subject rights requests
- support the Controller with Data Protection Impact Assessments where required
- notify the Controller without undue delay of any personal data breach
- make available information reasonably necessary to demonstrate compliance with Article 28 GDPR
The Processor provides AI-supported functionality intended solely to support candidate review workflows.
De-identification
Before the evaluation step, application documents are passed through an AI-assisted de-identification process intended to reduce personally identifying information, including names, contact details, age-related information and gender indicators where detected. The de-identification step is performed by the AI provider named for that purpose in Annex III, which receives the application document in its original form in order to perform it. The model that carries out the subsequent evaluation receives only the de-identified text.
The purpose of this process is to support more job-related and less bias-prone candidate reviews. Because the process is AI-assisted, complete removal of all identifying information cannot be guaranteed in every case.
No automated decisions
The software does not automatically hire, reject or advance candidates.
For each requirement defined by the Controller, the software indicates the level of supporting evidence found in the application — Limited, Partial, Good or Strong — and links it to the passage it came from. These levels describe how well the application evidences the Controller's requirements. They are not assessments of a candidate's suitability for the role.
The software aggregates these requirement-level assessments into a single overall evidence level per candidate, using a fixed rule and the requirement weightings defined by the Controller. Candidate lists can be sorted by this overall level and by the ratings assigned by the Controller's own users. Sorting changes the order in which candidates are displayed and has no further effect.
The Processor does not generate candidate suitability scores, hiring recommendations or advice on which candidates to select. Ratings expressing a user's own assessment of a candidate are entered by the Controller's users; no such rating exists until a user enters it.
Advancing or rejecting a candidate requires a separate, individual action by a user of the Controller for each candidate. The software provides no function that advances or rejects candidates in bulk, and no action is triggered by an evidence level or by any calculated value.
The requirement-level assessments and the aggregated overall level constitute profiling within the meaning of Art. 4 (4) GDPR. They do not constitute a decision within the meaning of Art. 22 GDPR. The Controller remains responsible for ensuring that every decision affecting a candidate is taken by a competent person on the basis of an individual review, and that the aggregated level is not applied as a threshold that determines the outcome.
Recruiters remain responsible for:
- defining or approving role-specific requirements
- reviewing evidence identified by the system
- independently evaluating candidates
- assigning candidate scores or ratings where applicable
- making hiring decisions
All hiring decisions remain under the control and responsibility of the Controller.
No model training
Personal data processed under this Agreement shall not be used by the Processor to train, fine-tune or otherwise improve artificial intelligence models. The Processor does not authorise the AI providers named in Annex III to use such data to train or improve their own models, and has contracted with them on terms that exclude this.
The Processor shall implement and maintain appropriate technical and organisational measures in accordance with Article 32 GDPR. The measures currently implemented are described in Annex II and include, among others:
- encryption in transit
- encryption at rest
- role-based access controls
- audit logging
- infrastructure monitoring
- secure deletion procedures
- access management controls
The Processor may update such measures from time to time provided that the overall level of security is not materially reduced.
The Controller authorises the use of the subprocessors listed in Annex III.
The Processor shall inform the Controller of material changes to subprocessors at least 30 days in advance and provide the Controller with the opportunity to object. Where the Controller objects on reasonable data protection grounds and the parties cannot agree a solution, either party may terminate the affected part of the service relationship.
All subprocessors shall be bound by data protection obligations substantially equivalent to those set out in this Agreement.
Processing under this Agreement takes place within the European Union. Personal data is not transferred to third countries.
Should a transfer outside the European Economic Area become necessary in future, the Processor will inform the Controller in advance in accordance with Section 9 and implement appropriate safeguards in accordance with Chapter V GDPR.
Taking into account the nature of the processing and the information available to the Processor, the Processor shall provide reasonable assistance to the Controller regarding:
- Data Protection Impact Assessments
- AI governance reviews
- risk assessments
- supervisory authority inquiries
- data subject rights requests
- compliance obligations under GDPR
The Controller may verify compliance with this Agreement upon reasonable notice and during normal business hours.
The Processor may satisfy audit requests through documentation, security reports, certifications, independent assessments or other evidence demonstrating compliance.
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed under this Agreement.
The notification shall include the information reasonably available at the time and shall be supplemented as further information becomes available.
Candidate data.
Candidate-related data, including application documents, OCR transcripts, AI-supported analyses, generated reports and associated audit records, is retained only as long as necessary for the recruitment process. Unless otherwise instructed by the Controller, such data is automatically deleted six (6) months after the corresponding recruitment process has been closed.
Processing and diagnostic logs.
Technical logs generated during processing, including those kept for debugging and quality assurance, are deleted after seven (7) days.
End of the agreement.
Upon termination of the service relationship, personal data shall be deleted or returned to the Controller unless retention is required by applicable law.
The Processor may amend this Agreement where necessary to reflect changes in law, in the Service, or in its technical or organisational setup, provided the level of protection for data subjects is not reduced. The Controller will be notified in writing at least 30 days in advance and may object; Section 9 applies accordingly to changes of subprocessors.
Purpose of processing.
Support recruitment workflows through AI-assisted document analysis, requirement-level evidence assessments and structured candidate review.
Nature of processing.
Storage, extraction, de-identification, analysis, reporting, audit logging, deletion.
Categories of data subjects.
Job applicants, recruiters, hiring managers, other users of the Controller.
Categories of personal data.
Application documents, professional experience, qualifications, education, skills, recruiter-generated information.
Processing sequence.
- The application document is received and converted into a text transcript.
- The transcript is de-identified by the provider named in Annex III for that purpose.
- The de-identified transcript, together with the requirement profile defined by the Controller, is analysed to produce requirement-level evidence assessments. These are aggregated into an overall evidence level per candidate using a fixed rule and the Controller's requirement weightings.
- Results are made available to the Controller's users, who review them and decide.
Access control.
Role-based permissions, authenticated user access, least-privilege principles.
Data protection.
Encryption in transit, encryption at rest, secure backups.
Infrastructure security.
Infrastructure monitoring, access logging, security investigations.
AI processing safeguards.
De-identification before evaluation, human oversight, no automated hiring decisions, no AI model training on customer data, contractual exclusion of model training by AI providers.
Logging.
Audit records may include processing timestamps, analysis generation events, prompt versions, model versions, user actions, scoring changes and deletion events.
Storage limitation.
Automated deletion of candidate-related information six months after the associated recruitment process has been closed; deletion of processing and diagnostic logs after seven days.
| Subprocessor | Role | Location | Data received |
|---|---|---|---|
| Hetzner Online GmbH | Hosting and storage of the platform | Germany | All data stored in the platform |
| Mistral AI SAS | AI-assisted de-identification of application documents | France | Application transcript in its original form, including identifying information |
| Amazon Web Services EMEA SARL, region eu-central-1 (Frankfurt) | Operation of the AI models used for evaluation and for analysis of job descriptions | Germany | De-identified application transcript and the Controller's requirement profile |
| Brevo SAS | Transactional email delivery | France | Email addresses and message content of platform notifications |
Note on the evaluation models.
The AI models used for evaluation are operated by Amazon Web Services within the region stated above. The model developer does not receive the data and is therefore not a subprocessor. Prompts and outputs are not made available to the model developer and are not used for model training.
All subprocessors are established in the European Union. No processing under this Agreement takes place outside the European Union.