Data processing agreement
This agreement governs the processing of personal data by ARA.BG EOOD (АРА.БГ ЕООД), company number (ЕИК) 203301726 (the “Processor”) on behalf of the customer using AI People Hub (the “Controller”), under Article 28 of Regulation (EU) 2016/679 (GDPR). It forms part of the Terms of service or of the individual contract with the customer.
1. Subject matter, duration, nature and purpose
- Subject matter: hosting and processing HR data in AI People Hub.
- Duration: for the term of the Service contract and until the data is deleted or returned under section 9.
- Nature: storage, organisation, retrieval, display, calculation, document generation, sending notifications, AI processing at a user's request.
- Purpose: solely providing the Service to the Controller.
2. Categories of data subjects and data
Data subjects: employees, former employees, candidates, managers, contractors and other users entered by the Controller.
Data: identification and contact data; personal numbers (ЕГН) and ID card data; personnel file, position, contracts, orders; working time, leave and attendance; pay, benefits and bank details; performance reviews and training; applications, CVs, video interviews and test results; documents and signatures.
Special categories (Art. 9 GDPR) where the Controller enters them — for example health data for sick leave or a workplace accident.
3. Processor obligations
- Processes the data only on the Controller's documented instructions — the contract and the settings the Controller makes in the Service are such instructions.
- Ensures that persons with access to the data are bound by confidentiality.
- Applies the technical and organisational measures in section 5.
- Respects the conditions for sub-processors in section 6.
- Assists the Controller with data subject requests, impact assessments and consultations with the supervisory authority.
- Informs the Controller if, in its opinion, an instruction infringes the GDPR.
4. Controller obligations
The Controller is responsible for the legal basis of the processing, for informing the data subjects, and for the lawfulness of its instructions — including how it uses the AI features as a deployer under Regulation (EU) 2024/1689.
5. Security measures
- Encrypted connections (HTTPS/TLS) for all traffic.
- Encryption at rest (AES-256-GCM) of uploaded employee documents and of sensitive fields — personal numbers, ID card data, IBANs.
- Strict separation of data between customers; role-based access and field-level permissions.
- Two-factor authentication, which the Controller can make mandatory.
- Audit logs of access and changes; a user activity log.
- Encrypted backups, including off the main server.
- Anonymity of anonymous surveys and reports — identity is shown to nobody, administrators included.
The measures are described in detail in the “People Hub Security Architecture” document, which we provide to the Controller on request.
6. Sub-processors
The Controller gives general authorisation for the sub-processors below. We notify administrators of a new sub-processor at least 30 days in advance and update this page; the Controller may object on reasonable grounds. We impose on every sub-processor data protection obligations equivalent to those in this agreement.
| Sub-processor | Activity | Location |
|---|---|---|
| Spaceship, Inc. | Hosting of the application and database; email (Spacemail) | EU — the Netherlands (Amsterdam) |
| Backblaze, Inc. | Encrypted backups; archive of video interviews for closed jobs (if enabled) | EU — Amsterdam (EU Central) |
| Google (Gemini API) | AI features — only the data sent when a specific feature is used | May be processed outside the EU — EU–US Data Privacy Framework and standard contractual clauses |
| Stripe | Subscription payments — payer data, not HR data | EU / US (EU–US Data Privacy Framework) |
| BORICA AD (B-Trust) | Qualified electronic signatures — only if the Controller uses them | Bulgaria |
| Evrotrust Technologies AD | Qualified electronic signatures — only if the Controller uses them | Bulgaria |
Integrations the Controller switches on: sign-in with Google or Microsoft and Google Calendar sync work only if the Controller or a user switches them on; data is then exchanged with the chosen provider at their initiative.
7. Data subject requests
The Service includes a data subject request tool (access, rectification, erasure) with which the Controller prepares its answer. If we receive a request directly, we forward it to the Controller without delay and do not answer it on the merits without its instruction.
8. Personal data breaches
We notify the Controller without undue delay and no later than 48 hours after becoming aware of a personal data breach, with the information available under Art. 33(3) GDPR, and supplement it as it becomes known.
9. End of processing
On termination the Controller may export its data within 30 days. We then delete it, including from backups at their next cycle, unless the law requires it to be kept.
10. Audit
We make available to the Controller the information needed to demonstrate compliance with Art. 28, and allow audits on reasonable notice, carried out by the Controller or an auditor it mandates who is bound by confidentiality. We first provide documentation and answers to a security questionnaire. An on-site audit is possible at most once a year, with 30 days' notice and at the Controller's cost, unless it is prompted by a security breach we caused or by a supervisory authority.
11. Transfers outside the EEA
Data is transferred outside the European Economic Area only with appropriate safeguards under Chapter V GDPR — an adequacy decision (including the EU–US Data Privacy Framework) or standard contractual clauses.