Data Processing Agreement
Version 2025.3 | Annex to the Main Agreement
Data Processing Agreement
This Data Processing Agreement ("DPA") governs all processing of personal data performed by Selection Lab in the context of its assessment, selection, and recruitment technology services, in accordance with Article 28(3) of the General Data Protection Regulation ("GDPR").
Incorporation, no separate signature required
This DPA is attached as an annex to, and forms an integral part of, the agreement(s) between the Parties under which Selection Lab provides its services (the "Main Agreement"). By signing the Main Agreement, each Party also agrees to and enters into this DPA. No separate signature of this DPA is required. This DPA enters into force on the effective date of the Main Agreement.
Parties
This DPA applies between:
- The Selection Lab B.V., trading as Selection Lab, a private limited liability company registered in the Netherlands (Chamber of Commerce no. 71341730), with its registered office at Sint Pieterspoortsteeg 19, 1012 HM Amsterdam ("Selection Lab" or "Processor"); and
- the party identified as the client in the Main Agreement ("Client" or "Controller"), whose corporate details, registered office and registration number are as stated in the Main Agreement.
Hereinafter collectively referred to as the "Parties", and individually as a "Party".
Recitals
A.
The Parties have entered into the Main Agreement, under which Selection Lab provides services that involve the processing of personal data.
B.
In the context of the GDPR, the Client acts as Data Controller and Selection Lab acts as Data Processor. In addition, Selection Lab acts as an independent Data Controller for its proprietary assessment content, psychometric methodology and algorithms, as further described in Annex 1 (split responsibility model).
C.
The Parties wish to set out their respective rights and obligations regarding such processing in this DPA. The specific processing details are described in Annex 1.
The terms "Personal Data", "Processing", "Data Subject", "Controller" and "Processor" have the meanings given in the GDPR. Other capitalised terms have the meanings assigned below:
Data Breach
Any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
EU Standard Contractual Clauses
The European Commission's standard clauses for transferring Personal Data to third countries under Article 46(2)(c) and (d) GDPR.
Main Agreement
The agreement(s) between the Parties under which Selection Lab provides its services and to which this DPA is annexed.
Privacy Legislation
All applicable laws governing data protection and privacy, including the GDPR and the Dutch GDPR Implementation Act (UAVG).
Sub-Processor
Any third party engaged by the Processor to process Personal Data on behalf of the Controller.
Article 2.
General principles and incorporation
2.1
Each Party shall comply with all applicable Privacy Legislation and process Personal Data only for legitimate business purposes.
2.2
This DPA forms an integral part of the Main Agreement. In case of conflict between this DPA and the Main Agreement with respect to the processing of Personal Data, this DPA shall prevail.
2.3
Acceptance of the Main Agreement (by signature or by any other means of acceptance provided for in the Main Agreement) constitutes acceptance of this DPA by both Parties. No separate signature of this DPA is required for it to be valid and binding.
Article 3.
Technical and organisational measures
3.1
The Processor shall maintain appropriate and auditable technical and organisational measures ("TOMs") to ensure the security, integrity, and availability of Personal Data.
3.2
These measures include, at minimum: confidentiality obligations, role-based access control, encryption, network protection, logging, and incident response. A summary is included in Annex 1, section 5.
3.3
The Processor shall periodically review and improve its TOMs to ensure continued compliance with the GDPR.
Article 4.
Processing instructions and Sub-Processors
4.1
The Processor shall process Personal Data only on documented instructions from the Controller, unless otherwise required by law.
4.2
The Processor shall promptly inform the Controller if, in its opinion, an instruction infringes Privacy Legislation.
4.3
Sub-Processors may be engaged only with the Controller's prior written approval. The Sub-Processors listed in Annex 1, section 4 are deemed approved by the Controller upon acceptance of the Main Agreement.
4.4
The Processor shall inform the Controller in advance of any intended addition or replacement of Sub-Processors, giving the Controller the opportunity to object on reasonable grounds.
4.5
The Processor remains fully liable for the performance of its Sub-Processors.
Article 5.
International data transfers
No Personal Data shall be transferred outside the EEA unless authorised in writing by the Controller and in full compliance with Chapter V of the GDPR, including, where applicable, the EU Standard Contractual Clauses.
Article 6.
Assistance and DPIA
The Processor shall assist the Controller in performing data protection impact assessments and in consultations with supervisory authorities when required.
The Controller may audit the Processor's compliance with this DPA once annually, or upon reasonable suspicion of non-compliance. The Processor shall cooperate fully and provide all necessary evidence.
Article 8.
Supervisory authority access
The Parties shall cooperate fully with competent supervisory authorities and provide access to systems and documentation as legally required.
9.1
The Processor shall notify the Controller of any Data Breach within 24 hours of discovery.
9.2
The notification shall include all relevant details, including the nature of the breach, the affected data, the potential impact, and remedial actions.
9.3
The Processor shall not contact Data Subjects or authorities regarding a Data Breach without the Controller's prior approval, unless legally required to do so.
Article 10.
Data Subject rights
The Processor shall assist the Controller in responding to Data Subject requests under Articles 15 to 22 GDPR (access, rectification, erasure, restriction, portability, and objection).
Article 11.
Retention and deletion
Upon termination of the Main Agreement, the Processor shall return or delete all Personal Data as instructed by the Controller, unless retention is legally required.
Article 12.
Liability and insurance
Each Party is responsible for its own actions and omissions. The Processor shall maintain adequate insurance and shall be liable up to the limits set forth in the Main Agreement.
This DPA enters into force on the effective date of the Main Agreement and remains in effect for as long as the Processor processes Personal Data on behalf of the Controller, including after termination of the Main Agreement to the extent such processing continues.
Article 14.
Governing law and jurisdiction
This DPA is governed by Dutch law. Disputes shall be submitted exclusively to the competent court in Rotterdam, the Netherlands.
Annex 1
Description of processing
1. Contact details
- Controller: the contact person designated by the Client in the Main Agreement or, in the absence thereof, the Client's signatory of the Main Agreement.
- Processor: Beau Mosterd, Privacy Lead, [email protected].
2. Nature and purpose of processing
The Processor invites candidates on behalf of the Client to complete an online assessment used for recruitment or development purposes.
- Categories of Data Subjects: job applicants of the Client.
- Categories of Personal Data: name, email address, (optional) phone number, assessment data (psychometric responses and results).
- Purpose: to enable the Client to assess the suitability of candidates for employment or development programs.
3. Clarification of roles (split responsibility)
For the invitation, delivery, and data handling of candidate information, Selection Lab acts as Data Processor on behalf of the Client.
For the assessment content, psychometric algorithms, and analytical results generated through its proprietary models, Selection Lab acts as an independent Data Controller in accordance with the GDPR.
Selection Lab determines the analytical framework, scientific methodology, and processing logic and may use aggregated and anonymised data to improve its services.
4. Approved Sub-Processors
The following Sub-Processors are approved by the Controller upon acceptance of the Main Agreement. All Sub-Processors process Personal Data within the EEA. The current list is also published in Selection Lab's privacy statement at www.selectionlab.com/pages/privacy.
Sub-Processor
Location
Role
Brevo (SendinBlue)
France
Email delivery.
360dialog / Meta
EU
WhatsApp messaging.
Auth0
Germany
Authentication and login management.
HubSpot
Germany / Ireland
Communication platform and customer support.
Amazon Web Services
Germany
Database storage.
Redis
EU
Temporary data storage.
CloudAMQP
EU
Message processing.
Google Workspace
Europe
Email and file storage.
Pendo
Europe
User statistics and analytics.
Sentry
Germany / EU
Application logging.
Chatbase, Chatwith, VideoAsk
EU
Chat and form processing.
Applicable only to Clients using SmartChat (AI chat screening):
Sub-Processor
Location
Role
OpenAI
EEA processing, via a PII gateway
Language model processing for AI chat screening (SmartChat). Personal identifiers are filtered through a PII gateway before processing.
The OpenAI Sub-Processor applies exclusively where the Client has contracted SmartChat under the Main Agreement. For Clients without SmartChat, no Personal Data is processed by OpenAI.
5. Security measures
Selection Lab maintains security aligned with ISO 27001 standards, including:
- Access control and authentication;
- Encryption of data at rest and in transit;
- Logging and monitoring;
- Incident response and breach management procedures;
- Secure hosting within the EEA;
- Annual external audits (ISAE 3000 type II or equivalent).
Document control
This DPA is version 2025.3, prepared by The Selection Lab B.V., Amsterdam, the Netherlands. Contact: [email protected] | www.selectionlab.com. Amendments to this DPA are made in accordance with the amendment provisions of the Main Agreement.