Data Processing Agreement
Version 2026.9 · Valid from 28 September 2026 · Reference PRIV-DPA-01

Processing of Personal Data

This Data Processing Agreement ("DPA") governs all processing of personal data performed by Selection Lab in the context of its assessment, selection, and recruitment technology services, in accordance with Article 28(3) of the General Data Protection Regulation ("GDPR").

Incorporation, no separate signature required

This DPA is attached as an annex to, and forms an integral part of, the agreement(s) between the Parties under which Selection Lab provides its services (the "Main Agreement"). By signing the Main Agreement, each Party also agrees to and enters into this DPA. No separate signature of this DPA is required. This DPA enters into force on the effective date of the Main Agreement.

Parties

This DPA applies between:

Hereinafter collectively referred to as the "Parties", and individually as a "Party".

Recitals

A.
The Parties have entered into the Main Agreement, under which Selection Lab provides services that involve the processing of personal data.
B.
In the context of the GDPR, Selection Lab acts as an independent Data Controller for the assessment processing: it determines the purposes and means of processing candidates' assessment data, obtains their consent and handles their requests to exercise their rights. The Client acts as an independent Data Controller for its own recruitment process, including the decision whether to make an offer. For tasks Selection Lab performs strictly on the Client's instructions, such as sending assessment invitations on the Client's behalf, Selection Lab acts as Data Processor and this DPA applies, as described in Annex 1.
C.
The Parties wish to set out their respective rights and obligations regarding such processing in this DPA. The specific processing details are described in Annex 1.
1

Definitions

The terms "Personal Data", "Processing", "Data Subject", "Controller" and "Processor" have the meanings given in the GDPR. Other capitalised terms have the meanings assigned below:

Term
Definition
Data Breach
Any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
EU Standard Contractual Clauses
The European Commission's standard clauses for transferring Personal Data to third countries under Article 46(2)(c) and (d) GDPR.
Main Agreement
The agreement(s) between the Parties under which Selection Lab provides its services and to which this DPA is annexed.
Privacy Legislation
All applicable laws governing data protection and privacy, including the GDPR and the Dutch GDPR Implementation Act (UAVG).
Sub-Processor
Any third party engaged by the Processor to process Personal Data on behalf of the Controller.
2

General principles and incorporation

2.1
Each Party shall comply with all applicable Privacy Legislation and process Personal Data only for legitimate business purposes.
2.2
This DPA forms an integral part of the Main Agreement. In case of conflict between this DPA and the Main Agreement with respect to the processing of Personal Data, this DPA shall prevail.
2.3
Acceptance of the Main Agreement (by signature or by any other means of acceptance provided for in the Main Agreement) constitutes acceptance of this DPA by both Parties. No separate signature of this DPA is required for it to be valid and binding.
3

Technical and organisational measures

3.1
The Processor shall maintain appropriate and auditable technical and organisational measures ("TOMs") to ensure the security, integrity, and availability of Personal Data.
3.2
These measures include, at minimum: confidentiality obligations, role-based access control, encryption, network protection, logging, and incident response. A summary is included in Annex 1, section 5.
3.3
The Processor shall periodically review and improve its TOMs to ensure continued compliance with the GDPR.
4

Processing instructions and Sub-Processors

4.1
The Processor shall process Personal Data only on documented instructions from the Controller, unless otherwise required by law.
4.2
The Processor shall promptly inform the Controller if, in its opinion, an instruction infringes Privacy Legislation.
4.3
Sub-Processors may be engaged only with the Controller's prior written approval. The Sub-Processors listed in Annex 1, section 4 are deemed approved by the Controller upon acceptance of the Main Agreement.
4.4
The Processor shall inform the Controller in advance of any intended addition or replacement of Sub-Processors, giving the Controller the opportunity to object on reasonable grounds.
4.5
The Processor remains fully liable for the performance of its Sub-Processors.
5

International data transfers

Personal Data is transferred outside the EEA only to the Sub-Processors listed in Annex 1, section 4, on the basis stated there for each, being an adequacy decision or the European Commission's Standard Contractual Clauses, and in full compliance with Chapter V GDPR. Approval of that list under Article 4.3 is the Controller's written authorisation.

6

Assistance and DPIA

The Processor shall assist the Controller in performing data protection impact assessments and in consultations with supervisory authorities when required.

7

Audit rights

The Controller may audit the Processor's compliance with this DPA once annually, or upon reasonable suspicion of non-compliance. The Processor shall cooperate fully and provide all necessary evidence.

8

Supervisory authority access

The Parties shall cooperate fully with competent supervisory authorities and provide access to systems and documentation as legally required.

9

Data Breaches

9.1
The Processor shall notify the Controller of any Data Breach within 24 hours of discovery.
9.2
The notification shall include all relevant details, including the nature of the breach, the affected data, the potential impact, and remedial actions.
9.3
The Processor shall not contact Data Subjects or authorities regarding a Data Breach without the Controller's prior approval, unless legally required to do so.
10

Data Subject rights

The Processor shall assist the Controller in responding to Data Subject requests under Articles 15 to 22 GDPR (access, rectification, erasure, restriction, portability, and objection).

11

Retention and deletion

Upon termination of the Main Agreement, the Processor shall return or delete all Personal Data as instructed by the Controller, unless retention is legally required.

12

Liability and insurance

Each Party is responsible for its own actions and omissions. The Processor shall maintain adequate insurance and shall be liable up to the limits set forth in the Main Agreement.

13

Duration

This DPA enters into force on the effective date of the Main Agreement and remains in effect for as long as the Processor processes Personal Data on behalf of the Controller, including after termination of the Main Agreement to the extent such processing continues.

14

Governing law and jurisdiction

This DPA is governed by Dutch law. Disputes shall be submitted exclusively to the competent court in Rotterdam, the Netherlands.

Annex 1

Description of processing

1. Contact details

2. Nature and purpose of processing

The Processor invites candidates on behalf of the Client to complete an online assessment used for recruitment or development purposes.

3. Clarification of roles

Selection Lab acts as an independent Data Controller for the assessment: the assessment content and psychometric methodology, the processing of candidates' responses and results, the consent candidates give, and their rights requests. The Client acts as an independent Data Controller for its own recruitment process, including the decision whether to make an offer. Selection Lab acts as Data Processor on the Client's behalf only for tasks it performs strictly on the Client's instructions, such as sending assessment invitations; this DPA governs those tasks.

4. Approved Sub-Processors

The following Sub-Processors are approved by the Controller upon acceptance of the Main Agreement. Sub-Processors process Personal Data within the EEA unless the table states otherwise; in that case the transfer rests on the European Commission's Standard Contractual Clauses (SCCs). The current list is also published in Selection Lab's privacy statement at www.selectionlab.com/pages/privacy.

Sub-Processor
Location
Role
Amazon Web Services
Germany (Frankfurt)
Database and file storage.
Heroku (Salesforce)
Ireland (Dublin)
Application hosting.
Auth0
Germany
Authentication and login management.
Brevo
France
Email delivery.
Cloudflare
Global network; United States (SCCs)
DNS, TLS termination and content delivery.
Typeform
Spain; responses hosted in the United States (SCCs)
Assessment questionnaires.
VideoAsk
Spain; responses hosted in the United States (SCCs)
Video-based assessment forms.
Testportal
Poland
Hard-skill tests.
Redis Cloud
Germany (Frankfurt)
Temporary data storage.
CloudAMQP
EU
Message processing.
Papertrail (SolarWinds)
United States (SCCs)
Central application log storage.
Sentry
Germany / EU
Application logging.
HubSpot
Germany / Ireland
Communication platform and customer support.
Pendo
Europe
User statistics and analytics.
Google Workspace
Europe
Email and file storage.
Superhuman
United States (SCCs)
Email client for staff mailboxes.

Applicable only where the Client uses the assessment concerned:

Sub-Processor
Location
Role
Aivy
Germany
Game-based psychometric assessment.
Brght
EU
IQ and personality assessment with proctoring.
Cappr
Netherlands
Assessment, under a pseudonymous identifier only.
CriteriaCorp
United States and Australia (SCCs)
Cognitive aptitude test; existing clients only.
Talogy (Cubiks)
EU
IQ assessment.
Ixly
Netherlands
Psychometric assessment.
NOA
Netherlands / Germany
Psychometric assessment and talent portal.

Applicable only to Clients using SmartChat (AI chat screening):

Sub-Processor
Location
Role
OpenAI
United States (SCCs)
Language model processing for AI chat screening (SmartChat). Personal identifiers are filtered through a PII gateway before processing.
Langfuse
Ireland
Prompt management and monitoring of the language model calls.
360dialog
Germany
WhatsApp Business API.
WhatsApp Ireland (sub-processor of 360dialog)
Ireland
WhatsApp message delivery.

The Sub-Processors in this table apply exclusively where the Client has contracted SmartChat under the Main Agreement. For Clients without SmartChat, no Personal Data is processed by them.

5. Security measures

Selection Lab maintains security aligned with ISO 27001 standards, including:

Reference documents

Document
Version used
Main Agreement
per client, no version
Data Protection Impact Assessment (DPIA), PRIV-DPIA-01
2026.9
Technical and Organisational Measures (TOMs), SEC-TOM-01
2026.9; available to the Client on request
Document control

This DPA is version 2026.9, September 2026, prepared by The Selection Lab B.V., Amsterdam, the Netherlands. Contact: [email protected] | www.selectionlab.com. Amendments to this DPA are made in accordance with the amendment provisions of the Main Agreement.

Data Processing Agreement | Version 2026.9