Draft. This text is under legal review and may change.

Data processing agreement

Version 0.4 · Last updated: 24.09.2026

This agreement governs the processing of personal data by ARA.BG EOOD (АРА.БГ ЕООД), company number (ЕИК) 203301726 (the “Processor”) on behalf of the customer using AI People Hub (the “Controller”), under Article 28 of Regulation (EU) 2016/679 (GDPR). It forms part of the Terms of service or of the individual contract with the customer.

1. Subject matter, duration, nature and purpose

2. Categories of data subjects and data

Data subjects: employees, former employees, candidates, managers, contractors and other users entered by the Controller.

Data: identification and contact data; personal numbers (ЕГН) and ID card data; personnel file, position, contracts, orders; working time, leave and attendance; pay, benefits and bank details; performance reviews and training; applications, CVs, video interviews and test results; documents and signatures.

Special categories (Art. 9 GDPR) where the Controller enters them — for example health data for sick leave or a workplace accident.

3. Processor obligations

4. Controller obligations

The Controller is responsible for the legal basis of the processing, for informing the data subjects, and for the lawfulness of its instructions — including how it uses the AI features as a deployer under Regulation (EU) 2024/1689.

5. Security measures

The measures are described in detail in the “People Hub Security Architecture” document, which we provide to the Controller on request.

6. Sub-processors

The Controller gives general authorisation for the sub-processors below. We notify administrators of a new sub-processor at least 30 days in advance and update this page; the Controller may object on reasonable grounds. We impose on every sub-processor data protection obligations equivalent to those in this agreement.

Sub-processorActivityLocation
Spaceship, Inc.Hosting of the application and database; email (Spacemail)EU — the Netherlands (Amsterdam)
Backblaze, Inc.Encrypted backups; archive of video interviews for closed jobs (if enabled)EU — Amsterdam (EU Central)
Google (Gemini API)AI features — only the data sent when a specific feature is usedMay be processed outside the EU — EU–US Data Privacy Framework and standard contractual clauses
StripeSubscription payments — payer data, not HR dataEU / US (EU–US Data Privacy Framework)
BORICA AD (B-Trust)Qualified electronic signatures — only if the Controller uses themBulgaria
Evrotrust Technologies ADQualified electronic signatures — only if the Controller uses themBulgaria

Integrations the Controller switches on: sign-in with Google or Microsoft and Google Calendar sync work only if the Controller or a user switches them on; data is then exchanged with the chosen provider at their initiative.

7. Data subject requests

The Service includes a data subject request tool (access, rectification, erasure) with which the Controller prepares its answer. If we receive a request directly, we forward it to the Controller without delay and do not answer it on the merits without its instruction.

8. Personal data breaches

We notify the Controller without undue delay and no later than 48 hours after becoming aware of a personal data breach, with the information available under Art. 33(3) GDPR, and supplement it as it becomes known.

9. End of processing

On termination the Controller may export its data within 30 days. We then delete it, including from backups at their next cycle, unless the law requires it to be kept.

10. Audit

We make available to the Controller the information needed to demonstrate compliance with Art. 28, and allow audits on reasonable notice, carried out by the Controller or an auditor it mandates who is bound by confidentiality. We first provide documentation and answers to a security questionnaire. An on-site audit is possible at most once a year, with 30 days' notice and at the Controller's cost, unless it is prompted by a security breach we caused or by a supervisory authority.

11. Transfers outside the EEA

Data is transferred outside the European Economic Area only with appropriate safeguards under Chapter V GDPR — an adequacy decision (including the EU–US Data Privacy Framework) or standard contractual clauses.