General Data Processing Agreement (GDPA)
Version 1.0, Effective 01 January 2026
This Data Processing Agreement (“DPA” or “GDPA”) forms an integral part of the service agreement between the customer (“Controller”) and AeroSelect UG (haftungsbeschränkt), Mühlenstraße 20, 10243 Berlin, Germany (“Processor”). It governs the processing of personal data that the Processor carries out on behalf of the Controller when providing the AeroHire applicant-tracking and recruitment platform.
1. Subject Matter and Duration
The subject matter of this DPA is the processing of personal data by the Processor on behalf of the Controller in connection with the provision of the AeroHire platform. The duration of this DPA corresponds to the term of the underlying service agreement. Processing shall commence upon the Controller's activation of AeroHire services and shall continue until termination of the service agreement unless otherwise required by applicable law.
2. Nature and Purpose of Processing
The Processor processes personal data for the following purposes:
- (a) hosting and operating the AeroHire recruitment platform
- (b) receiving, storing, and displaying candidate applications
- (c) AI-assisted analysis of CVs and resumes for skill extraction and job matching
- (d) facilitating communication between the Controller and candidates via email and push notifications
- (e) generating recruitment analytics and reporting
- (f) processing subscription payments
3. Categories of Data Subjects
The personal data processed under this DPA relates to the following categories of data subjects:
- (a) candidates/applicants who submit applications via the AeroHire platform
- (b) employees and representatives of the Controller who use the AeroHire dashboard
- (c) contact persons of the Controller for billing and account management purposes
4. Types of Personal Data
The following types of personal data are processed: name, email address, phone number, postal address, date of birth, nationality, photographs, CVs/resumes (including education history, employment history, skills, certifications, and references), cover letters, application status and notes, login credentials (hashed), IP addresses, browser and device information, communication logs, and payment-related data (processed by Stripe as a separate controller).
5. Obligations of the Processor
The Processor shall:
- Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law
- Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality
- Implement and maintain appropriate technical and organisational measures as set out in Appendix 1
- Respect the conditions for engaging sub-processors as set out in Section 8
- Assist the Controller in responding to data subject requests pursuant to Chapter III GDPR
- Assist the Controller in ensuring compliance with obligations under Articles 32 to 36 GDPR
- At the Controller's choice, delete or return all personal data after the end of the provision of services and delete existing copies unless Union or Member State law requires storage
- Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allow for and contribute to audits
6. Obligations of the Controller
The Controller shall:
- (a) ensure that the processing of personal data is carried out in accordance with applicable data protection law, including having a valid legal basis for processing
- (b) provide documented instructions to the Processor regarding the processing of personal data
- (c) ensure that data subjects are informed about the processing of their personal data in accordance with Articles 13 and 14 GDPR
- (d) respond to data subject requests within the timeframes stipulated by the GDPR
- (e) ensure the accuracy and completeness of personal data provided to the Processor
7. Instructions
The Processor shall process personal data only in accordance with the Controller's documented instructions. The use of the AeroHire platform in accordance with the service agreement and this DPA constitutes the Controller's complete initial instructions. Any additional or deviating instructions must be agreed in writing. The Processor shall immediately inform the Controller if, in the Processor's opinion, an instruction infringes applicable data protection law.
8. Sub-processors
The Controller hereby grants the Processor general written authorisation to engage sub-processors. The current list of authorised sub-processors is set out in Appendix 2. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes within 14 calendar days of notification. Where the Processor engages a sub-processor, the Processor shall impose the same data protection obligations as set out in this DPA on the sub-processor by way of a contract. The Processor remains fully liable to the Controller for the performance of the sub-processor's obligations.
9. International Transfers
The Processor shall not transfer personal data to a third country or international organisation unless:
- (a) the European Commission has decided that the third country ensures an adequate level of protection (Art. 45 GDPR)
- (b) appropriate safeguards have been provided pursuant to Art. 46 GDPR, in particular EU Standard Contractual Clauses (SCCs) as adopted by Commission Implementing Decision (EU) 2021/914
- (c) the Controller has given explicit prior written consent
Where sub-processors are located outside the EU/EEA, the applicable safeguards are detailed in Appendix 2.
10. Data Subject Rights
The Processor shall, taking into account the nature of the processing, assist the Controller by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights under Chapter III GDPR. This includes the rights of access, rectification, erasure, restriction of processing, data portability, and the right to object. Where a data subject contacts the Processor directly, the Processor shall promptly redirect the request to the Controller.
11. Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within 36 hours, after becoming aware of a personal data breach. The notification shall include:
- (a) a description of the nature of the breach, including the categories and approximate number of data subjects and records concerned
- (b) the name and contact details of the Processor's data protection contact
- (c) a description of the likely consequences of the breach
- (d) a description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects
The Processor shall cooperate with the Controller and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of the breach.
12. Data Protection Impact Assessment
The Processor shall provide reasonable assistance to the Controller with any data protection impact assessments and prior consultations with supervisory authorities that the Controller is required to carry out under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to the Processor.
13. Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and Art. 28 GDPR. The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Audits shall be conducted with reasonable prior notice (at least 30 calendar days), during normal business hours, and shall not unreasonably interfere with the Processor's business operations. The Controller shall bear the costs of any audit unless the audit reveals material non-compliance by the Processor.
14. Deletion and Return of Data
Upon termination of the service agreement, the Processor shall, at the Controller's choice, delete or return all personal data processed on behalf of the Controller. The Controller may request the return of data in a commonly used, machine-readable format within 30 days of termination. After this period, the Processor shall delete all remaining personal data, unless Union or Member State law requires further storage. The Processor shall certify the deletion in writing upon the Controller's request.
15. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the underlying service agreement, except where such limitations are not permitted by applicable data protection law. Nothing in this DPA shall limit either party's liability for breaches of its obligations under the GDPR where such liability cannot be lawfully excluded or limited.
16. Final Provisions
This DPA shall be governed by the laws of the Federal Republic of Germany. The exclusive place of jurisdiction for all disputes arising out of or in connection with this DPA shall be Berlin, Germany. In the event of any conflict between this DPA and the underlying service agreement, the provisions of this DPA shall prevail with respect to data protection matters. Amendments to this DPA must be made in writing. Should any provision of this DPA be or become invalid, the validity of the remaining provisions shall not be affected.
Appendix 1: Technical and Organisational Measures (TOMs)
The Processor implements and maintains the following technical and organisational measures in accordance with Art. 32 GDPR:
1.1 Physical Security
- Infrastructure is hosted in Tier 3+ certified data centres located in Germany / EU with 24/7 on-site security, biometric access controls, and CCTV surveillance
- Redundant power supplies and climate control systems ensure continuous availability
1.2 Encryption
- All data in transit is encrypted using TLS 1.3 (minimum TLS 1.2 for legacy compatibility)
- All data at rest is encrypted using AES-256 encryption
- Database backups are encrypted and stored in geographically separated locations within the EU
1.3 Access Control
- Role-based access control (RBAC) is enforced across all systems. Access is granted on a least-privilege basis
- Multi-factor authentication (MFA) is required for all administrative access
- Access rights are reviewed quarterly and revoked immediately upon personnel changes
1.4 Availability and Resilience
- Automated daily backups with a recovery point objective (RPO) of 24 hours
- Disaster recovery plan tested annually with documented results
- Monitoring and alerting systems provide real-time visibility into system health and security events
1.5 Pseudonymisation and Data Minimisation
- Personal data is pseudonymised where technically feasible and compatible with the processing purpose
- Only personal data that is strictly necessary for the respective processing purpose is collected and processed
1.6 Incident Response
- Documented incident response plan with defined escalation procedures
- Security incidents are logged, investigated, and reported in accordance with Section 11 of this DPA
1.7 Employee Measures
- All employees with access to personal data are bound by confidentiality obligations
- Regular data protection and information security training is provided to all relevant personnel
Appendix 2: Authorised Sub-processors
The following sub-processors are authorised to process personal data on behalf of the Processor as of the effective date of this DPA:
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| NetCup GmbH | Cloud hosting & infrastructure | Germany / EU | EU-based processing |
| OpenAI, Inc. | AI-powered CV analysis & job matching | USA | EU Standard Contractual Clauses (SCCs) |
| Mailgun Technologies, Inc. | Transactional email delivery | EU / USA | EU Standard Contractual Clauses (SCCs) |
| Stripe, Inc. | Payment processing & billing | EU / Ireland | EU-based processing; SCCs for ancillary transfers |
For questions regarding this Data Processing Agreement, please contact: [email protected]