Data Processing Agreement
Senast uppdaterad: 8 August 2026
This DPA is provided for transparency. For a negotiated or countersigned agreement, contact gerald@taplo.app.
This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between Taplo and the Customer and applies where Taplo processes personal data on the Customer's behalf under EU/UK GDPR. Where the Customer determines the purposes of processing candidate and interview data, the Customer is the controller and Taplo is the processor.
By accepting the Terms and Conditions or using the Service to process personal data, the Customer agrees to this DPA. Customers requiring a countersigned copy may request one at gerald@taplo.app.
1. Definitions
Terms such as "controller", "processor", "personal data", "data subject", "sub-processor", and "processing" have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR (together, "GDPR"), as applicable. "Customer" means the organisation or individual that uses the Service under the Terms and Conditions. "Service" means the Taplo application and related services.
2. Subject matter and duration
The subject matter of processing is the provision of the Taplo Service to the Customer. Processing continues for the term of the Terms and Conditions (and any period thereafter during which Taplo retains personal data as required by this DPA or applicable law).
3. Nature and purpose of processing
Taplo processes personal data to provide recording, transcription, AI analysis, storage, and generation of interview scorecards and candidate records for the Customer's recruitment activity, and related support for those features.
4. Types of personal data
Depending on how the Customer uses the Service, processing may include:
- Names and contact details;
- Audio recordings and transcripts;
- CV / role context and related recruitment materials;
- AI-generated assessments, summaries, and scorecards;
- Calendar and meeting metadata.
5. Categories of data subjects
Job candidates, interview participants, and the Customer's own users of the Service.
6. Processor obligations
Taplo shall:
- process personal data only on documented instructions from the Customer, including with regard to transfers of personal data, unless required to do otherwise by applicable law;
- ensure that persons authorised to process personal data are bound by confidentiality;
- implement appropriate technical and organisational measures as described in Annex 1;
- taking into account the nature of processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, for the fulfilment of the Customer's obligation to respond to requests for exercising data subject rights;
- assist the Customer in ensuring compliance with obligations relating to security of processing, personal data breach notification, data protection impact assessments, and prior consultation, taking into account the nature of processing and the information available to Taplo.
7. Sub-processing
The Customer grants Taplo a general authorisation to engage sub-processors. The current list of sub-processors is maintained at taplo.app/subprocessors. Taplo will update that list before adding or replacing a sub-processor and will impose data-protection obligations on each sub-processor that are equivalent in substance to those in this DPA. Taplo remains liable to the Customer for the performance of its sub-processors' data-protection obligations under this DPA.
8. International transfers
Where personal data is transferred outside the EEA or the United Kingdom, Taplo relies on Standard Contractual Clauses or another transfer mechanism recognised under Article 46 GDPR (or the UK equivalent), as applicable to the relevant sub-processor or recipient.
9. Data subject rights
Taking into account the nature of the processing, Taplo will assist the Customer in responding to requests from data subjects to exercise their rights of access, rectification, erasure, restriction, portability, and objection under GDPR, including hard deletion from shared candidate corpora where Taplo controls such storage, insofar as this is possible given the Service architecture.
10. Personal data breach
Taplo will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, and will provide information reasonably available to Taplo to support the Customer's own notification and documentation duties under GDPR.
11. Deletion or return
On termination of the Service (or earlier on the Customer's written request), Taplo will, at the Customer's choice, delete or return personal data processed under this DPA, and delete existing copies, except where retention is required by applicable law. Local copies held solely on the Customer's devices remain under the Customer's control.
12. Audit
Taplo will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, including relevant documentation. The Customer may conduct audits or inspections of Taplo's compliance remotely (for example, by reviewing policies, questionnaires, and evidence), subject to reasonable prior notice, confidentiality, and avoiding disruption to Taplo's operations. On-site audits are not offered as a standard entitlement.
13. Order of precedence
In the event of a conflict between this DPA and the Terms and Conditions with respect to the processing of personal data, this DPA prevails.
Annex 1 — Technical and organisational security measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Taplo maintains measures including:
- Encryption of data in transit (for example, TLS);
- Access controls and authentication for systems that process personal data;
- Local-first storage of sensitive interview and candidate data on the Customer's device where the Service architecture provides for it;
- Logging and monitoring of relevant systems where applicable;
- Least-privilege access for personnel and systems;
- Vendor due diligence on sub-processors engaged to help deliver the Service.
Annex 2 — Sub-processors
The current list of sub-processors, including purpose, processing location, and transfer safeguards, is maintained at taplo.app/subprocessors and forms part of this DPA by reference.