Data Processing Addendum
Effective date: 2026-09-01
This Data Processing Addendum ("DPA") forms part of the Terms of Service, Order, master services agreement, or other agreement between the customer identified in the applicable agreement ("Customer") and Attia AS ("Attia") for Attia ATS and related services (the "Agreement").
Attia AS is located at Solheimgata 1a, 0267 Oslo, Norway. Contact: hello@attia.app. Data protection contact: Njål Wiik.
This DPA is written for Attia's B2B applicant tracking and recruiting workflow software. It governs Attia's processing of customer-controlled personal data as processor or subprocessor. Attia's Privacy Policy governs Attia's own controller processing, such as account administration, billing, support, security, legal compliance, analytics where used, and business communications.
1. Parties and Scope
Parties
This DPA is between Customer and Attia AS. Customer may enter into this DPA for itself and, where permitted by the Agreement and Data Protection Laws, for its affiliates that are authorized to use the Service.
Scope
This DPA applies when Attia processes Customer Personal Data on behalf of Customer in connection with Attia ATS, including recruiting workflows, candidate records, workspace content, files, prompts, integrations, support, security, and related service operations.
No controller processing under this DPA
This DPA does not govern Attia's processing of personal data as an independent controller. Attia controller processing is described in Attia's Privacy Policy and may include account administration, customer relationship management, billing, product security, legal compliance, vendor management, analytics or diagnostics where used, and marketing communications.
2. Definitions
"Customer Personal Data" means personal data contained in Customer Data that Attia processes on behalf of Customer.
"Customer Data" has the meaning given in the Agreement and includes data, content, files, records, prompts, outputs, and information submitted to or processed through the Service by or on behalf of Customer, including Candidate Data.
"Candidate Data" means personal data and recruiting records relating to candidates, applicants, prospective applicants, referrals, employees, or other individuals whose information is submitted to the Service in connection with recruiting or hiring.
"Data Protection Laws" means the GDPR, the Norwegian Personal Data Act, the UK GDPR, the Swiss Federal Act on Data Protection, and other privacy or data protection laws applicable to the relevant processing.
"GDPR" means Regulation (EU) 2016/679. "SCCs" means the European Commission standard contractual clauses for international transfers of personal data, as updated or replaced.
The terms "controller", "processor", "data subject", "personal data", "processing", "personal data breach", and "supervisory authority" have the meanings given in the GDPR.
3. Roles of the Parties
Customer is the controller of Customer Personal Data, or a processor acting on behalf of another controller. Attia is Customer's processor, or subprocessor where Customer is a processor.
Customer is responsible for the lawfulness of Customer Personal Data and Customer's recruiting and hiring activities. This includes providing notices, identifying lawful bases, obtaining consents or authorizations where required, responding to data subject requests, setting retention rules, and complying with employment, anti-discrimination, accessibility, background-check, immigration, recordkeeping, and other laws that apply to Customer.
Attia will process Customer Personal Data only as described in this DPA, the Agreement, Customer's configuration and use of the Service, and Customer's documented instructions.
4. Customer Instructions
Customer instructs Attia to process Customer Personal Data to provide, secure, support, maintain, and improve the Service as permitted by this DPA, the Agreement, Customer's settings and use of the Service, and any other documented instructions.
Attia will not process Customer Personal Data for purposes outside Customer's instructions unless required by applicable law. If Attia is legally required to process Customer Personal Data outside Customer's instructions, Attia will inform Customer before the processing unless the law prohibits notice on important grounds of public interest.
Attia will notify Customer if, in Attia's opinion, an instruction infringes Data Protection Laws, unless legally prohibited from doing so.
5. Processing Details
The subject matter, duration, nature, purpose, data subjects, data categories, and processing operations are described in Annex 1.
Attia may process Customer Personal Data by hosting, storing, organizing, retrieving, displaying, transmitting, securing, supporting, deleting, exporting, backing up, and otherwise processing Customer Personal Data as necessary to provide the Service and follow Customer's documented instructions.
6. Sensitive or Regulated Data
The Service is not intended for processing special-category personal data under GDPR Article 9, criminal-offense data, children's data, biometric data, government identifiers, health or disability data, immigration data, background-check data, or other regulated data unless Customer has confirmed that such processing is lawful, necessary, supported by appropriate safeguards, and expressly permitted by Attia in writing where required.
Because recruiting workflows may include free-form notes, resumes, attachments, messages, prompts, files, and integrations, Customer may technically submit sensitive or regulated data to the Service. Customer is responsible for ensuring that any such submission is lawful, necessary, proportionate, and covered by appropriate notices, lawful bases, safeguards, and retention rules.
Customer should not submit sensitive or regulated data to AI features unless Customer has confirmed that the feature, provider configuration, DPA terms, transfer safeguards, and Customer's own lawful basis are appropriate for that data.
7. Confidentiality
Attia will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations or are subject to appropriate statutory confidentiality duties.
Attia will restrict access to Customer Personal Data to personnel, contractors, and subprocessors who need access to provide, secure, support, or maintain the Service, or to comply with law.
8. Security Measures
Taking into account the state of the art, costs of implementation, nature, scope, context, and purposes of processing, and the risk to individuals, Attia will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, damage, alteration, or disclosure.
Current technical and organizational measures are described in Annex 2.
9. Subprocessors
Customer gives Attia general written authorization to engage subprocessors to provide the Service.
Attia will impose written data protection obligations on subprocessors that are materially equivalent to those in this DPA. Attia remains responsible to Customer for subprocessors' performance of those obligations.
Attia will maintain a public subprocessor list and provide advance notice of new subprocessors before they process Customer Personal Data. Notice period: 30 days. Customer may object to a new subprocessor on reasonable data-protection grounds by contacting hello@attia.app during the notice period.
If Customer reasonably objects and Attia cannot provide a commercially reasonable alternative, Customer may stop using the affected part of the Service. Any refund or termination rights are governed by the Agreement unless mandatory Data Protection Laws require otherwise.
Current subprocessors are listed in Annex 3.
10. International Transfers
Attia is established in Norway. Customer Personal Data is stored in the European Union (AWS eu-west-1, Ireland). More regions later. Attia does not state that all Customer Personal Data remains in the EU/EEA, because support, logging, AI and background-job paths are not all EU-resident.
Some vendors, support personnel, optional integrations, AI providers, payment providers, email providers, analytics providers, or support systems may process or access limited Customer Personal Data outside the EU/EEA.
Where Customer Personal Data is transferred outside the EU/EEA, United Kingdom, or Switzerland, Attia will use appropriate safeguards required by applicable Data Protection Laws. These may include adequacy decisions, SCCs, the UK International Data Transfer Addendum or International Data Transfer Agreement, Swiss transfer requirements, transfer impact assessments where required, and supplementary technical and organizational measures.
For EU transfers where the SCCs are required, Module Two applies where Customer is a controller and Attia is a processor, and Module Three applies where Customer is a processor and Attia is a subprocessor. The SCC annexes are completed by the processing details, subprocessors, and technical and organizational measures in this DPA.
11. AI Providers and AI Features
AI features may be available by default. Availability alone does not call a model or send Customer Personal Data to an AI provider. Processing begins only when Customer or a User invokes an AI feature, or when a Customer-configured schedule, record trigger, or delegation starts it. A workspace admin or owner may disable Agent workspace-wide.
AI processing may include prompts, selected text, workspace content, candidate or job information, files if included, instructions, metadata, model configuration, and AI-generated outputs. AI-specific terms are described in Annex 4.
Attia sends every AI request with zero data retention enforced, which also disallows use of that content to train models. Requests are routed only to providers that offer zero data retention for the model in question; where none is available, the request fails rather than proceeding without that protection. Attia does not promise EU-only AI processing. It may take place outside the EU/EEA, under the transfer safeguards in section 10.
12. Data Subject Requests
If Attia receives a request from a data subject relating to Customer Personal Data, Attia will, where legally permitted, direct the requester to Customer or notify Customer.
Taking into account the nature of the processing, Attia will reasonably assist Customer in responding to data subject requests, including requests for access, correction, deletion, restriction, portability, objection, withdrawal of consent, or information about automated processing, where Customer cannot reasonably respond without Attia's assistance.
13. DPIA and Regulator Assistance
Taking into account the nature of processing and information available to Attia, Attia will reasonably assist Customer with data protection impact assessments, prior consultations, and supervisory-authority inquiries relating to Customer Personal Data.
Customer remains responsible for determining whether a DPIA, bias assessment, automated-employment-decision assessment, or similar review is required for Customer's use of the Service, including any AI or automated features.
14. Security Incidents
Attia will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
Attia's notice will include information reasonably available to Attia, which may include the nature of the breach, affected categories of data subjects and personal data, likely consequences, mitigation steps, and a contact point for follow-up.
Attia will reasonably cooperate with Customer's breach assessment, regulator notification, and data subject notification obligations. Attia's notice or cooperation is not an admission of fault or liability.
15. Deletion and Return
Upon termination, expiry, or Customer's written request, Attia will return, export, delete, or de-identify Customer Personal Data in accordance with the Agreement and Customer's instructions, unless applicable law requires retention.
Export window after termination or workspace deletion: 30 days.
Deletion after termination or workspace deletion: at the end of that 30-day window, when Attia permanently deletes the workspace and its Customer Personal Data. Uploaded files are queued for removal at the same moment and cleared by a sweep that runs daily, so file deletion completes within a day of the purge rather than instantly. Attia keeps a record that the deletion happened, which does not contain Customer Personal Data.
Backup cycle: Encrypted backups are taken daily and retained on a rolling 7-day cycle; data deleted from the live database ages out of the last backup within 7 days.
Deletion from backups takes longer than deletion from active systems. Backup data is isolated from ordinary processing and ages out on the cycle above.
16. Audits and Compliance Information
Attia will make available information reasonably necessary to demonstrate compliance with this DPA.
Customer may request audits or inspections where required by Data Protection Laws, subject to reasonable notice, confidentiality, security restrictions, scope limits, and measures to avoid disruption to Attia's business or other customers.
Attia may satisfy audit requests by providing current security documentation, third-party certifications, summaries, completed questionnaires, or other appropriate compliance information where such materials are reasonably sufficient under Data Protection Laws.
Attia holds no security certification of its own. Attia operates SOC 2-aligned controls and can supply its subprocessors' current certifications and completed questionnaires on request.
17. Government and Law-Enforcement Requests
Attia will not voluntarily disclose Customer Personal Data to law enforcement or government authorities unless legally required.
Where legally permitted, Attia will notify Customer of a government or law-enforcement request for Customer Personal Data and reasonably cooperate with Customer's efforts to limit or challenge the request.
If legally compelled to disclose Customer Personal Data, Attia will seek to disclose only the minimum amount required by law.
18. Order of Precedence
For data-processing matters, the order of precedence is: mandatory transfer terms such as SCCs or the UK Addendum, this DPA, the Agreement, and then other referenced documents.
The Agreement governs commercial terms unless they conflict with mandatory data-processing obligations. This DPA does not add broad liability waivers, payment terms, or product disclaimers beyond what is necessary for data-processing matters.
19. Contact Details
Privacy and DPA questions can be sent to:
Attia AS
Solheimgata 1a
0267 Oslo
Norway
Email: hello@attia.app
Data protection contact: Njål Wiik
Annex 1: Processing Details
| Field | Details |
|---|---|
| Subject matter | Attia's provision of B2B applicant tracking and recruiting workflow software. |
| Duration | The subscription term, plus a 30-day export window after termination or workspace deletion, plus up to 7 further days for backups to age out, plus any legal-retention or dispute period. |
| Nature and purpose | Hosting, storing, organizing, retrieving, displaying, transmitting, securing, supporting, deleting, exporting, and otherwise processing Customer Personal Data to provide recruiting workflows and related service operations. |
| Data subjects | Candidates, applicants, prospective applicants, referrals, employees, recruiters, hiring-team members, workspace users, customer admins, and support contacts. |
| Personal data categories | Names, contact details, resumes, applications, profiles, employment and education history, skills, communications, interview notes, evaluations, attachments, job preferences, pipeline status, user and account metadata, prompts, AI outputs, logs, and integration data. |
| Sensitive data | Not intended unless expressly agreed and lawful. May be technically submitted by Customer in resumes, notes, files, prompts, messages, or integrations. |
| Processing operations | Collection on Customer's behalf, storage, structuring, retrieval, consultation, use, disclosure to subprocessors, transmission, restriction, erasure, export, backup, support, security monitoring, and optional AI processing. |
| Customer obligations | Lawful basis, candidate notices, consents, retention, access controls, human review, anti-discrimination compliance, AI-use assessment, special-data safeguards, and data subject request handling. |
Annex 2: Technical and Organizational Measures
| Measure | Details |
|---|---|
| Security governance | Attia maintains safeguards appropriate to risk, with its data paths and subprocessors recorded in an internal vendor register. Attia reviews them when a data path or vendor changes rather than on a fixed calendar. |
| Access control | Access is limited by role and least privilege, enforced in the database by row-level security, with unique accounts and removal of access when membership ends. Multi-factor authentication is available through Attia's identity provider. |
| Confidentiality | Personnel with access to Customer Personal Data are bound by confidentiality obligations or equivalent statutory duties. |
| Encryption in transit | Data is encrypted in transit. HTTPS is forced on all connections. |
| Encryption at rest | Data is encrypted at rest. |
| Tenant separation | Customer workspaces are logically separated, enforced in the database by row-level security on the tables holding Customer Personal Data rather than by application code alone. |
| Backups | Encrypted backups are taken daily and retained on a rolling 7-day cycle; data deleted from the live database ages out of the last backup within 7 days. Point-in-time recovery is not enabled. |
| Logging and monitoring | Security, access, and operational events are written to an append-only audit log, kept for 2 years from the event and then deleted automatically. The client IP address recorded when an access attempt is denied is removed after 90 days, ahead of the rest of that entry. Application errors are monitored through an EU-hosted error-tracking service configured without personal data, session replay, or user identification. |
| Secure development | Changes are reviewed and pass automated checks (type checking, linting, tests, build) before release. Dependencies are tracked and updated. Secrets are held as deployment environment variables and are never committed to the repository. |
| Incident response | Attia triages, contains, and investigates security incidents and notifies Customer as described in section 14. |
| Vendor management | Subprocessors are recorded in an internal vendor register naming the data each one receives, and are published in Annex 3 and in Attia's Privacy Policy. Annex 3 states the transfer and DPA position for each, including the ones still open. |
| Deletion and export | Customer Data stays available for export for 30 days after termination or workspace deletion, and is then permanently deleted. Uploaded files are queued for removal at that moment and cleared by a sweep that runs daily. Backups age out on the 7-day cycle above. |
| AI controls | Availability alone does not call a model or send Customer Data. Processing starts only when a User invokes an AI feature or a Customer-configured automation starts it. Every AI request is sent with zero data retention enforced, which also disallows use of that content to train models. A workspace admin or owner can disable Agent workspace-wide. |
Annex 3: Subprocessors
| Vendor | Service | Data processed | Region | Transfer mechanism | Retention | DPA/SCC status |
|---|---|---|---|---|---|---|
| Supabase | Primary database, file storage, and candidate authentication | All Customer Data and Candidate Data, including names, contact details, CV files, and application content | European Union (AWS eu-west-1, Ireland) | EEA processing | For the subscription term, then as set out in section 15 | Relying on Supabase's published data processing terms; not separately negotiated or countersigned, and open at Attia's next vendor review |
| Clerk | Authentication and organization identity for workspace members | Workspace member identity, email address, and organization membership. Candidates do not authenticate with Clerk | Provider-defined. Attia has not configured an EU data residency option for this instance | Per Clerk's published data processing terms; the mechanism is provider-defined and not independently verified by Attia | For the life of the account | Relying on Clerk's published data processing terms; not separately negotiated or countersigned, and open at Attia's next vendor review |
| Vercel | Hosting and deployment, Speed Insights, AI Gateway when used, and durable agent session state and its observability view when Agent or Loops run | Request metadata, performance data, logs, AI routing data, and — for agent features — the stored agent session record, which can include the workspace and Candidate Data an agent read or produced. The same session content, including the message that starts a session and the agent's replies, is readable as text in Vercel's agent observability dashboard by the Attia team members with access to that project | Functions run in the EU (Dublin, AWS eu-west-1), pinned in Attia's deployment configuration. The platform is operated from the United States, and the region of the stored agent session record is not pinned | SCCs under Vercel's published data processing terms | Agent session state expires automatically on the plan's schedule after a run completes, and the observability view of it expires on the platform's own schedule; Attia keeps no separate copy of the execution trace | Relying on Vercel's published data processing terms; not separately negotiated or countersigned, and open at Attia's next vendor review |
| Sentry | Error monitoring | Error reports and request metadata, which include page paths carrying workspace and record identifiers. Configured without default personal data, without session replay, and without user identification; credentials, invitation tokens, authorization headers, and cookies are removed before sending | European Union (Sentry EU region) | EEA processing | Per Sentry's plan retention for error events | DPA accepted 2026-07-29. SOC 2 Type II report received 2026-07-29, covering 2024-09-01 to 2025-08-31 |
| Stripe | Subscription billing and payments | The workspace administrator's email address, a workspace identifier, and a seat count, plus whatever the payer enters at checkout. No Candidate Data is sent | Provider-defined; not independently verified by Attia | Per Stripe's published data processing terms; the mechanism is provider-defined and not independently verified by Attia | Per Stripe's own retention for payment and tax records | Relying on Stripe's published data processing terms; not separately negotiated or countersigned, and open at Attia's next vendor review |
| Resend | Transactional email delivery, used as the authentication mail relay | Candidate email addresses and sign-in codes | Provider-defined; not independently verified by Attia | Per Resend's published data processing terms; the mechanism is provider-defined and not independently verified by Attia | Per Resend's own retention for delivery records | Relying on Resend's published data processing terms; not separately negotiated or countersigned, and open at Attia's next vendor review |
| Trigger.dev | Scheduled background jobs and maintenance sweeps | Job identifiers and operational metadata. Attia's engineering rules prohibit Candidate Data in job payloads, logs, tags, outputs, and errors | Provider-defined; not independently verified by Attia. Attia has not configured a region option | No transfer mechanism executed; the protection today is that no Candidate Data is sent | Vendor-defined; not yet confirmed with Trigger.dev | No data processing agreement has been executed. Open at Attia's next vendor review |
| OpenAI | Optional AI model provider, reached through the Vercel AI Gateway. Also provides the embeddings behind documentation search | Prompts, context, inputs, outputs, and metadata depending on the feature | Provider-defined; may be outside the EU/EEA | SCCs under the gateway's and provider's published terms | Zero data retention enforced on every request, which also disallows training on the content | Covered by the AI Gateway's terms; the direct provider agreement is open at Attia's next vendor review |
| Optional AI model provider, reached through the Vercel AI Gateway | Prompts, context, inputs, outputs, and metadata depending on the feature | Provider-defined; may be outside the EU/EEA | SCCs under the gateway's and provider's published terms | Zero data retention enforced on every request, which also disallows training on the content | Covered by the AI Gateway's terms; the direct provider agreement is open at Attia's next vendor review | |
| Anthropic | Optional AI model provider, reached through the Vercel AI Gateway | Prompts, context, inputs, outputs, and metadata depending on the feature | Provider-defined; may be outside the EU/EEA | SCCs under the gateway's and provider's published terms | Zero data retention enforced on every request, which also disallows training on the content | Covered by the AI Gateway's terms; the direct provider agreement is open at Attia's next vendor review |
| Customer-enabled integrations | Job boards, HRIS, email and calendar, assessments, background checks, video interviews, APIs | Integration data and Candidate Data | Depends on the integration | Customer and provider specific | Provider-defined | Customer selects and is responsible for the integration; whether the provider is Attia's subprocessor or Customer's own vendor depends on the integration |
GitHub and Untitled UI appear on Attia's public vendor list because Attia uses them for source control and for a private icon package. Neither receives Customer Personal Data, so neither is a subprocessor under this DPA.
Where a row says an agreement is open at Attia's next vendor review, Attia is relying on the vendor's published data processing terms and has not separately negotiated or countersigned one. Attia states this rather than implying more.
Annex 4: AI Processing
AI features may be available by default, but availability alone does not call a model or send Customer Personal Data to an AI provider. Processing begins only when a User invokes an AI feature or a Customer-configured schedule, record trigger, or delegation starts it. A workspace admin or owner may disable Agent workspace-wide. Customer controls whether to use or configure AI features and is responsible for determining whether the use is lawful for its recruiting and employment workflows.
Data sent to AI providers may include prompts, selected text, workspace content, files, instructions, document context, job or candidate information, metadata, and AI outputs.
Providers may include OpenAI, Google, Anthropic, Vercel AI Gateway, or other gateway/model providers confirmed in Attia's subprocessor list.
Attia sends every AI request with zero data retention enforced, which also disallows use of that content to train models, and routes requests only to providers offering zero data retention for the model in question. Attia does not promise EU-only AI processing. It may take place outside the EU/EEA.
Customer should not submit sensitive, special-category, children's, health, biometric, government ID, background-check, immigration, criminal-offense, or other regulated data to AI features unless Customer has confirmed lawful basis, safeguards, provider configuration, and DPA coverage.
Where the Service includes agents, they act within live permissions and Customer's configured scope. Routine actions may run automatically, and Customer may require additional approvals. A qualified human must review and approve AI output before a hiring or employability decision, advice, recommendation, or similar high-risk output is acted on. This includes screening, ranking or scoring recommendations; advancing, holding, rejecting or disqualifying an application; interview or assessment selection; offers, compensation or eligibility; and AI-generated Candidate-facing communications. Administrative reminders, internal task assignment, record formatting and logistics already decided by a human may run automatically when they do not evaluate or determine candidacy. Drafts and summaries require review before a high-risk decision relies on them; ambiguous actions require review. If high-risk AI output is presented to or relied on by a Candidate or other affected person, Customer must clearly disclose that AI was used. To run a multi-step task reliably, agent session state — including the workspace content the agent read and produced — is stored durably by Attia's hosting subprocessor for the duration of the task and a retention period after it.
| Topic | DPA position |
|---|---|
| Trigger | Agent may be available by default; provider processing starts only on user invocation or a Customer-configured schedule, record trigger, or delegation. |
| Inputs | Prompts, instructions, selected text, workspace content, files if included, metadata, and context. |
| Outputs | AI-generated summaries, drafts, classifications, edits, recommendations, or other outputs depending on the feature. |
| Providers | OpenAI, Google, Anthropic, Vercel AI Gateway, or other confirmed AI providers. |
| Training and retention | Zero data retention is enforced on every request, which also disallows training on the content. Where no provider offers it for the model in question, the request fails rather than proceeding. EU-only processing is not promised. |
| Sensitive data | Do not submit unless lawful basis, safeguards, provider controls, and DPA coverage are confirmed. |
| Agent actions | Routine actions may run automatically within live permissions and configured scope. Customer may require additional approvals. |
| Agent session state | Applies when Agent or a configured automation runs. Stored durably by Attia's hosting subprocessor while a task runs and after it ends. Can include workspace and candidate content the agent read or produced. The stored record expires automatically on the hosting subprocessor's schedule, measured from when the task ends, and individual sessions cannot be deleted on request. Where a deletion request covers agent activity, Attia deletes its own records and ends any task still running or waiting, so the provider-side record begins expiring. Attia intends to end automatically any task waiting on a person for more than 7 days; that control is not yet implemented. Credit- or limit-blocked work does not queue or auto-resume. |
| Employment decisions | A qualified human must review and approve AI output before a hiring or employability decision, advice, recommendation, or similar high-risk output is acted on. Clearly disclose AI use when high-risk output is presented to or relied on by a Candidate or other affected person. |