Data Processing Agreement
Version 1.0 — effective 3 August 2026
Courtesy English translation. The French version is the legally binding one.
1. Parties and incorporation
This agreement binds the professional subscribing to aiKip (the Controller) and Axel Gilbert, sole trader, SIREN 923 027 155 (the Processor). It forms an integral part of the Terms of Sale from subscription and prevails over them for personal-data processing matters.
2. Processing instructions
The Processor processes data solely on documented instructions from the Controller, including the settings and actions performed by its authorized users, to host and operate the ATS. If an instruction appears unlawful, the Processor informs the Controller without delay and may suspend it pending clarification. No candidate data is sold, used for advertising or used to train a general-purpose AI model.
3. Processing schedule
- Subject and duration: provision of aiKip for the contract term, followed by the 30-day reversibility period and deletion.
- Nature and purposes: collection, hosting, organization, search, communication, interview management, export, deletion and AI-assisted analysis of applications.
- Data subjects: candidates, prospects or referred profiles, recruiter users and interview participants.
- Data: identity and contact details, CV and career history, application documents, screening answers, messages, notes, interview data, pipeline events, recruiter assessments and AI-generated scores/explanations.
- Controller obligations: lawful basis, transparent candidate information, data minimization, access governance, retention choices, rights handling, DPIA where required and human oversight of every hiring decision.
4. Confidentiality and security
Authorized persons are bound by confidentiality. The Processor applies proportionate measures, including France-based hosting, TLS in transit, access control and tenant isolation, password hashing, short-lived document links, logging, backups, vulnerability management and incident procedures. Security measures evolve without reducing the overall protection level.
5. Subprocessors and location
The Controller gives general authorization for these subprocessors:
- Scaleway SAS, France: application, PostgreSQL, object storage and Generative APIs used for CV analysis;
- Mollie B.V., Netherlands: payments and billing identifiers only.
Data covered by this agreement is processed in the European Union. The Processor gives at least 30 days’ notice before adding or replacing a subprocessor. The Controller may object on documented legitimate data-protection grounds; the parties seek a reasonable solution, failing which the affected service may be terminated. Equivalent obligations are imposed downstream.
6. Assistance and breaches
Taking account of the processing nature, the Processor assists with data-subject requests and obligations under Articles 32 to 36 GDPR. It informs the Controller without undue delay after becoming aware of a breach affecting entrusted data and provides available information on its nature, likely consequences, affected categories and remediation. The Controller remains responsible for notifications to the supervisory authority and data subjects where required.
7. Return, deletion and reversibility
The Controller can export structured company and recruitment data during the subscription and for 30 days after it ends. During that period the workspace is read-only and candidate documents remain individually downloadable by authorized users. At the deadline, operational data and copies are deleted or irreversibly anonymized, unless Union or French law requires retention. Accounting invoices are isolated and retained for ten years solely to meet legal obligations. Minimal evidence that the agreement was accepted is isolated for five years to establish or defend contractual rights.
8. Evidence and audits
The Processor provides information reasonably necessary to demonstrate compliance. Audits are normally satisfied through current documentation and security evidence; an on-site or third-party audit may be requested once per year on reasonable notice, subject to confidentiality, security and non-disruption requirements. Additional audit costs remain with the Controller unless a material breach by the Processor is found.
9. Contact and governing terms
Data-protection requests: contact@aikip.fr. The liability, term and governing-law provisions of the Terms of Sale apply, without limiting rights or obligations that cannot lawfully be limited under the GDPR.