DevParser

FeaturesHow It WorksIntegrationsPricingCompare
Sign In
GDPR Art. 28(3) · UK GDPR · AVV

Data Processing Agreement

Last updated: August 19, 2026

These are the standard data-processing terms R1 TECH sp. z o.o. (KRS 0001222088, NIP 9452324941, Józefa Chełmońskiego 142/8, 31-348 Kraków, Poland), operating DevParser, offers to every customer. You are the Controller; we are the Processor. Where you are established in the UK, references to Art. 28(3) are to the corresponding UK GDPR article and the competent authority is the ICO. Where you are established in Germany, this serves as the Auftragsverarbeitungsvertrag (AVV) under Art. 28 GDPR.

Need a signed counterpart, or your own paper? Email privacy@devparser.it and we will execute it. We do not require you to accept these terms unamended.

1. Subject matter and roles

You determine the purposes and means of processing candidate personal data. We process it only to provide the DevParser service and only on your documented instructions (Art. 28(3)(a)). This agreement overrides the Terms of Service on any conflict about personal-data processing.

2. Nature and purpose of processing

Automated evaluation of candidate code submissions, plagiarism and code-origin analysis, feedback generation, and screening support.

3. Categories of data subjects and personal data

Data subjects: your job candidates and your users. Personal data: identifiers (name, email), professional and employment data (CV, code submissions), assessment results and AI-generated evaluations. Special categories are not intentionally processed; candidates may include them in free-text CVs, and you instruct us not to use such data for any secondary purpose.

4. Duration

For the term of the service agreement, plus the retention periods published in the Privacy Policy, after which data is deleted or anonymised by an automated retention job.

5. Processor obligations (Art. 28(3))

We shall: (a) process only on your documented instructions, including for international transfers; (b) ensure persons authorised to process are bound by confidentiality; (c) implement the Art. 32 security measures in Annex 3; (d) respect the sub-processor conditions in section 6; (e) assist you with data-subject requests; (f) assist with your Art. 32–36 obligations covering security, breach notification and DPIAs; (g) at your choice, delete or return personal data at the end of service; and (h) make available the information needed to demonstrate compliance and allow audits.

6. Sub-processors

You give general authorisation for the sub-processors listed on our Sub-processors page, which forms Annex 2. We will inform you of intended changes and give you a chance to object. Sub-processors are bound by equivalent data-protection terms. Current sub-processors include Anthropic, Google, Stripe and Resend — the live list is authoritative.

7. Data-subject requests

We will forward any candidate request we receive to you without undue delay, and will not respond directly unless you instruct us to. We provide a full Art. 15 and Art. 20 candidate export endpoint and candidate deletion, so you can fulfil access, portability and erasure requests yourself.

8. International transfers

Transfers outside the EEA rely on the EU Standard Contractual Clauses, and on the EU–US Data Privacy Framework where the recipient is certified under it. The mechanism and current certification status for each sub-processor are listed on the Sub-processors page. For Controllers subject to UK GDPR, restricted transfers out of the UK are made under the ICO International Data Transfer Addendum (version B1.0, in force 21 March 2022) executed alongside the EU SCCs, or under the standalone IDTA where no EU SCCs are in place. The UK Addendum is Annex 4; Tables 1–3 are populated from Annexes 1–3 of this agreement, and in Table 4 neither party may end the Addendum as set out in Section 19.

9. Personal-data breach

We will notify you without undue delay after becoming aware of a personal-data breach, with the information you need for your Art. 33 notification.

10. Audit

We will make compliance information available and, on reasonable notice and confidentiality terms, support audits. We hold no SOC 2 or ISO 27001 certification today and do not claim one; when a third-party report exists we will make it available under this section. Our current control set is described in Annex 3 and our Compliance page states plainly what is and is not in place.

11. Interaction with the EU AI Act

DevParser is a high-risk AI system for employment purposes. We carry the obligations the EU AI Act allocates to the provider; you carry the deployer obligations. Our technical documentation is available on request. The AI Act applies where the system is placed on the market or put into service in the EU, or where its output is used in the EU. A Controller established in the UK using DevParser solely for UK hiring falls outside its scope; UK deployments remain subject to UK GDPR, including Art. 22 on automated decision-making, and to the Equality Act 2010.

Annexes

Annex 1 — Processing details

As set out in sections 2 and 3 above.

Annex 2 — Approved sub-processors

The live list on our Sub-processors page, as updated from time to time.

Annex 3 — Technical and organisational measures (Art. 32)

Encryption in transit and at rest; JWT httpOnly-cookie authentication; company-scoped data isolation enforced server-side from token claims; audit logging of automated decisions; least-privilege access; automated retention enforcement; encrypted storage of third-party integration credentials.

Annex 4 — UK Addendum (ICO)

The ICO International Data Transfer Addendum (B1.0) is attached for Controllers subject to UK GDPR, completed per section 8. It is not required for EU or EEA-only Controllers.

Related

Compliance overviewSub-processorsPrivacy PolicyTerms of Service

These are our standard processing terms, not legal advice. Have your own counsel review them before execution.

DevParser

AI-powered technical assessment platform. Screen candidates faster with Claude Haiku 4.5, Sonnet 5, and Opus 5 evaluation.

Product

FeaturesHow It WorksPricing

Resources

DocumentationLifetime DealsFAQ

Legal

Privacy PolicyTerms of ServiceSubprocessorsComplianceDPA

© 2026 R1 TECH sp. z o.o. (KRS: 0001222088, NIP: 9452324941). All rights reserved.

PrivacyTermsSubprocessors