Data Processing Agreement
Version 1.0 — June 2026
Parties
Data Controller (“Controller”): The company or organisation on behalf of which this Data Processing Agreement was accepted during Proveit onboarding, as identified by the account holder's company name and registered details.
Data Processor (“Processor”): Verid (eenmanszaak), trading as Proveit, Amsterdam, Netherlands.
Each a “Party” and together the “Parties”.
Background
The Controller uses the Proveit platform to assess job candidates' skills and authenticity as part of its hiring processes. In providing this service, the Processor processes personal data of candidates on behalf of the Controller.
This Data Processing Agreement (“DPA”) governs that processing in accordance with Article 28 of Regulation (EU) 2016/679 (“GDPR”). By accepting this DPA during onboarding, the individual doing so confirms they have authority to bind the Controller to these terms.
1. Definitions
- “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council, and any national implementing legislation.
- “Personal Data” has the meaning given in Article 4(1) GDPR, and in this DPA refers specifically to personal data of candidates processed via the Proveit platform.
- “Processing” has the meaning given in Article 4(2) GDPR.
- “Data Subject” means the identified or identifiable natural person to whom Personal Data relates — in this context, the candidate completing the assessment.
- “Sub-processor” means any third-party processor engaged by the Processor to carry out processing activities in connection with the Proveit service.
- “SCCs” means the Standard Contractual Clauses for the transfer of personal data to third countries adopted by the European Commission pursuant to Article 46 GDPR.
2. Subject matter and duration
The subject matter of this DPA is the skill and authenticity assessment of job candidates on behalf of the Controller using the Proveit platform.
This DPA applies from the date of acceptance during onboarding and remains in effect for the duration of the Controller's active subscription, plus a further six (6) months to cover the retention period described in section 12. It terminates automatically once all Personal Data has been deleted in accordance with this DPA.
3. Nature and purpose of processing
Purpose: Processing is carried out to conduct candidate skill assessments and authenticity verification to support the Controller's hiring decisions. The Processor does not use Personal Data for any other purpose.
Data collected:
- Candidate full name
- Candidate email address
- Written assessment responses
- Written answers to follow-up probe questions
- Aggregated behavioural signals: typing speed variation, revision counts, response timing, copy-paste event counts, and fullscreen exit counts
- Consent timestamp (date and time consent was given)
Data NOT collected:
- Raw keystroke content or individual keystrokes
- Screen recordings
- Video or audio recordings
- Location data
- Device identifiers or IP addresses (beyond what is inherent in standard web traffic)
4. Processor obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable Union or Member State law, in which case the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits such notification.
- Ensure that all personnel authorised to process Personal Data are bound by appropriate confidentiality obligations, whether by contract or statutory duty.
- Implement and maintain appropriate technical and organisational security measures, including: TLS encryption for all data in transit; AES-256 encryption for data at rest; and Row Level Security (RLS) on all database tables, ensuring that Controllers cannot access Personal Data belonging to other Controllers' accounts.
- Notify the Controller of any intended addition or replacement of Sub-processors at least 14 days in advance. The Controller may object to the change within 14 days by contacting info@getproveit.io. If the Processor proceeds with the change over a timely objection, the Controller may terminate the service without penalty.
- Assist the Controller in fulfilling Data Subject rights requests (access, rectification, erasure, restriction, portability) within 72 hours of receiving a request from the Controller or from a Data Subject directly.
- Notify the Controller of a Personal Data breach without undue delay and in any event within 72 hours of becoming aware of it. Notification shall include: (a) the nature of the breach; (b) the categories and approximate number of Data Subjects affected; (c) the categories and approximate number of records affected; (d) the likely consequences of the breach; and (e) the measures taken or proposed to address the breach.
- Delete all Personal Data within 30 days of termination of this DPA or written request from the Controller, and provide written confirmation of deletion.
5. Controller obligations
The Controller shall:
- Ensure there is a valid lawful basis under the GDPR for processing candidate Personal Data via the Proveit platform before any assessment is initiated.
- Inform candidates that their personal data will be processed by Proveit (operated by Verid (eenmanszaak), trading as Proveit, Amsterdam, Netherlands) before the assessment begins, including what data is collected, for what purpose, and how long it will be retained.
- Use assessment results only as decision support. All final hiring decisions must be made by a human being. Candidates shall not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, unless an applicable exemption under Article 22 GDPR applies and appropriate safeguards are in place.
- Not instruct the Processor to process Personal Data in a manner that would violate applicable law, including the GDPR.
6. Sub-processors
The Controller grants general authorisation for the Processor to engage the Sub-processors listed in Annex 1 to this DPA. All Sub-processors are bound by data protection obligations equivalent to those in this DPA. Sub-processors located outside the EEA are engaged under Standard Contractual Clauses.
7. International transfers
Personal Data is primarily stored within the European Union on Supabase infrastructure in Frankfurt, Germany. Where Sub-processors operate outside the EEA (including the United States), all transfers are conducted under Standard Contractual Clauses adopted by the European Commission pursuant to Article 46 GDPR, and the Processor maintains records of such transfer mechanisms.
8. Data subject rights
The Processor shall assist the Controller in fulfilling Data Subject rights requests. Where a candidate submits a request directly to the Processor (including via getproveit.io/gdpr-request), the Processor shall forward the request to the Controller within 5 business days and provide reasonable technical assistance to fulfil it.
9. Retention and deletion
Candidate Personal Data is automatically deleted 6 months after the assessment submission date. The Controller may request earlier deletion at any time by contacting info@getproveit.io.
Anonymised statistical records (containing no Personal Data) may be retained indefinitely for product improvement purposes.
Billing and transactional records are retained for 7 years in accordance with Dutch accounting law requirements.
10. Security and breach notification
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including those described in section 4.
In the event of a Personal Data breach, the Processor shall notify the Controller within 72 hours of discovery, providing all information required under Article 33 GDPR including the nature of the breach, data categories and volumes affected, likely consequences, and remediation measures taken or planned.
11. Liability
Each Party shall be liable for damage caused by processing that infringes the GDPR in accordance with Articles 82 and 83 GDPR.
The Processor's aggregate liability under this DPA is limited to direct damages not exceeding the total fees paid by the Controller to the Processor in the 12 months immediately preceding the event giving rise to the claim, to the maximum extent permitted by applicable law.
12. Governing law
This DPA is governed by and construed in accordance with the laws of the Netherlands, without regard to its conflict of law principles. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of Amsterdam, the Netherlands.
Signatures
By accepting this DPA during Proveit onboarding, the Controller acknowledges it has read, understood, and agrees to be bound by its terms.
On behalf of the Controller
Company name
Full name
Job title
Signature
Date
On behalf of the Processor
Verid, trading as Proveit · info@getproveit.io · Amsterdam, Netherlands
Annex 1 — Approved Sub-processors
Current as of June 2026. The Processor will notify the Controller of any changes with 14 days' notice.
| Sub-processor | Location | Purpose | Safeguard |
|---|---|---|---|
| Anthropic, PBC | USA | AI analysis of assessment text and generation of challenge content | SCCs |
| Supabase, Inc. | EU (Frankfurt) | Database and file storage | EU-based |
| Vercel, Inc. | USA / EU | Application hosting and edge delivery | SCCs |
| Stripe, Inc. | USA | Payment processing (billing data only — no candidate data) | SCCs + PCI-DSS |
| Resend, Inc. | USA | Transactional email delivery | SCCs |
| Inngest, Inc. | USA | Background job processing (analysis orchestration, scheduled deletion) | SCCs |
