Data Processing Agreement

Last updated: September 20, 2026

This Data Processing Agreement ("DPA") applies when an employer uses jobox to receive and manage job applications. In that case the employer decides what happens to the candidates' data and we handle it for the employer. It forms part of our Terms of Service and is accepted when those Terms are accepted. No separate signature is needed.

1. When this applies, and when it does not

1.1. It applies to applications submitted through jobox and everything an employer does with them in its company account: storing the application and resume, statuses, ratings, notes, email to the candidate, and forwarding to an applicant tracking system the employer has connected. For that processing the Employer is the controller and Code Radix s.r.o., Varšavská 715/36, Prague, Czech Republic, company ID 17335086, is the processor.

1.2. It does not apply where an advertisement sends candidates to the employer's own site or applicant tracking system. Those applications never reach us, so there is nothing for us to process on the employer's behalf.

1.3. It does not cover our own processing. We are the controller, not a processor, for the public job catalog, company profiles, accounts, job seeker profiles, search, recommendations, billing, security and fraud prevention. Our Privacy Policy governs that, and nothing in this DPA makes the Employer responsible for it.

1.4. Words defined in the General Data Protection Regulation ("GDPR"), such as controller, processor, personal data, processing and personal data breach, carry the same meaning here. "Candidate Data" means personal data we process for the Employer under Section 1.1.

2. What we process

ItemDetail
Subject matterReceiving and managing job applications for the Employer through jobox
DurationWhile the Employer's account is active, then as set out in Section 8
Nature and purposeCollection, storage, organization, retrieval, display to the Employer's users, transmission to a connected applicant tracking system, and deletion
Categories of data subjectPeople who apply to the Employer's advertisements
Types of personal dataName, email address, phone number, links to websites and professional profiles, cover letter, resume, possible start date, desired salary, preferred working arrangements, anything else the candidate writes, and the statuses, ratings and notes the Employer's users record
Special categoriesNone requested. A candidate may include such data in a resume or cover letter, and it is then processed as part of that document

3. What we will do

3.1. We process Candidate Data only on the Employer's documented instructions, which are these Terms, this DPA and the Employer's use of the product's features, unless the law requires otherwise. If the law requires otherwise, we tell the Employer first unless that law forbids it.

3.2. We tell the Employer if, in our view, an instruction breaks data protection law. We may refuse an instruction that does.

3.3. Everyone we allow to access Candidate Data is bound by confidentiality and sees only what their work requires.

3.4. We keep the security measures in Annex 2, which we may improve over time but not materially weaken.

3.5. We help the Employer answer candidate requests to access, correct, delete, restrict, port or object, so far as the product allows, and we pass on any request a candidate sends us about the Employer's role.

3.6. We give the Employer reasonable help with security, breach notification, impact assessments and prior consultation, taking into account what we know and what the product does.

3.7. We tell the Employer without undue delay after becoming aware of a personal data breach affecting Candidate Data, with the information we have, and we update the Employer as we learn more. Notifying the supervisory authority and the candidates is the Employer's decision and duty.

3.8. We give the Employer the information needed to show compliance with Article 28, and we allow audits under Section 9.

4. What the Employer must do

4.1. The Employer is responsible for having a lawful basis for the processing, for giving candidates the notices its own law requires, and for the accuracy and lawfulness of its instructions.

4.2. The Employer uses Candidate Data only to assess candidates for the role they applied to and, where the candidate agrees, other roles at the Employer, as Section 5.5 of the Terms sets out.

4.3. The Employer must not ask candidates for special category data through jobox, must not upload it into notes, and must not instruct us to process Candidate Data in a way that would breach the law.

4.4. The Employer manages who in its organization has access, and removes access when someone no longer needs it.

4.5. If the Employer connects an applicant tracking system, the transfer to that system and everything afterwards are the Employer's responsibility.

5. Subprocessors

5.1. The Employer gives us general authorization to use subprocessors. Annex 3 lists the ones we use today.

5.2. Each subprocessor is bound by written terms no less protective than this DPA, and we remain fully liable for what they do.

5.3. We give reasonable notice before adding or replacing a subprocessor, by updating Annex 3 and, for a material change, by email. The Employer may object on reasonable data protection grounds within 14 days, and if we cannot resolve the objection the Employer may stop using the parts of the Services affected and close its account. Fees already paid are not refunded.

6. Where data is processed

We and the providers in Annex 3 process Candidate Data in the United States. Where a transfer needs a safeguard under Chapter V of the GDPR, we rely on the European Commission's standard contractual clauses, or on the provider's certification under the EU to US Data Privacy Framework where it holds one, together with the measures in Annex 2.

7. Candidate requests and authorities

If a candidate or an authority contacts us directly about the Employer's processing, we do not answer on the Employer's behalf except to say who the Employer is and to pass the request on, unless the law requires us to respond.

8. Return and deletion

8.1. The Employer can delete Candidate Data in its account at any time.

8.2. When the Employer's account closes or this DPA ends, we delete Candidate Data within 90 days, unless the Employer asks for a copy first, or unless the law requires us to keep it. Backups are overwritten on their ordinary cycle.

8.3. Data the Employer has already exported or forwarded to its own systems is outside our control.

9. Audits

9.1. We answer reasonable written questions and security questionnaires about our processing, and share the documentation we hold, such as Annex 2 and our provider contracts. We do not currently hold an independent security certification or audit report, and nothing here commits us to obtain one.

9.2. If that is not enough, the Employer may audit once every 12 months, on 30 days' written notice, during business hours, under confidentiality, without disrupting the Services and without access to other customers' data. The Employer bears its own costs and ours, unless the audit finds a material breach by us.

10. Liability and precedence

10.1. The limitation of liability in Section 13 of the Terms applies to this DPA and to everything arising from it, taken together with all other claims under the Terms and not in addition to them.

10.2. Each party is responsible for its own breach of data protection law.

10.3. If this DPA conflicts with the Terms, this DPA wins for the processing it covers. If it conflicts with mandatory data protection law, that law wins.

10.4. We may update this DPA where the law, our providers or the product change. Material changes are notified as Section 1.4 of the Terms describes.

Annex 1: Processing details

See the table in Section 2.

Annex 2: Security measures

  • Encryption in transit over HTTPS, and encryption at rest with our hosting, database and storage providers.
  • Passwords stored only as salted hashes. Sign in sessions expire and can be revoked.
  • Resumes and other private files held in non public storage and served only through short lived signed links.
  • Access to production data limited to the people who need it, over authenticated connections.
  • Per account and per address rate limiting, and automatic blocking of abusive traffic.
  • Application logging and monitoring, with regular dependency updates.
  • Employer accounts separated, so one company's users can only reach their own company's applications.
  • Automated database backups, encrypted at rest, on a rolling schedule.
  • Written instructions to our staff on confidentiality, and contracts with every provider in Annex 3.

Annex 3: Subprocessors

ProviderWhat it doesLocation
RenderApplication hosting and the managed PostgreSQL databaseUnited States
Amazon S3 or Cloudflare R2Stored files, including resumes and imagesUnited States
ResendTransactional and alert emailUnited States
StripePayments for job advertisements. It handles the Employer's billing data, not Candidate DataUnited States
UpstashRate limiting and cachingUnited States
PostHogProduct analytics for jobox's own measurement. It receives event names and identifiers, not applications, resumes or notesUnited States
GoogleOptional sign in for accountsUnited States
OpenAISearch interpretation and drafting help for advertisements. It does not receive Candidate DataUnited States

Contact

Data protection questions: privacy@jobox.io
Everything else: support@jobox.io
Code Radix s.r.o., Varšavská 715/36, Prague, Czech Republic, company ID 17335086