Data Processing Agreement
This agreement governs how SetpointHQ handles personal data that you put into Studio or send us during a service engagement. It forms part of our Terms and Conditions and applies automatically when you use Studio. You do not need to sign anything separately.
It is written to meet Article 28 of the UK GDPR. If your organisation requires its own DPA on your paper, email privacy@setpointhq.com and we will review it.
1. Who Is Who
For data about you, our customer, including your account, your billing and your correspondence with us, SetpointHQ is the controller. That processing is described in our Privacy Policy.
For data you put into Studio about other people, most often candidates, you are the controller and SetpointHQ Limited is your processor. You decide what to collect, why, and how long to keep it. We act only on your instructions.
This agreement covers the second of those. Where the two conflict on the same data, this agreement takes precedence for data you upload.
2. What We Process, and Why
| Item | Detail |
|---|---|
| Subject matter | Providing the Studio product and any agreed services to you |
| Duration | For as long as your subscription or engagement is active, plus the deletion windows in section 8 |
| Nature and purpose | Storing, generating, structuring, summarising, ranking and presenting recruitment content and candidate information at your direction |
| Types of personal data | Names, contact details, employment and education history, CV and application content, correspondence, and anything else you choose to enter |
| Categories of data subject | Your candidates and applicants, your own staff who use the product, and contacts at your client organisations |
| Special category data | Studio is not designed for special category data. Do not upload it. If your process requires it, contact us first. |
3. Our Obligations
We will:
- process personal data only on your documented instructions, which include your use of the product and anything you ask us in writing, unless we are required to do otherwise by law, in which case we will tell you first unless the law prevents us;
- make sure everyone we authorise to process the data is bound by confidentiality;
- apply the security measures in section 5;
- not engage a sub-processor except as set out in section 6;
- help you respond to requests from data subjects, as set out in section 7;
- help you with security, breach notification and data protection impact assessments, taking account of what we know and what is available to us;
- delete or return the data as set out in section 8; and
- make available the information you reasonably need to show we are meeting these obligations, and allow audits as set out in section 9.
We will tell you if, in our opinion, an instruction from you would breach data protection law.
4. Your Obligations
You confirm that you have a lawful basis to collect the personal data you put into Studio and to share it with us, that you have given the people concerned the information the law requires, and that your instructions to us are lawful. You are responsible for the accuracy of what you upload and for deciding how long it needs to be kept.
5. Security
We apply appropriate technical and organisational measures, including:
- encryption in transit for all traffic to and from the product, and for every call to a sub-processor;
- access to your data restricted to your own authenticated account, with product access controlled by subscription;
- automatic deletion on the timetable in section 8, so data does not accumulate indefinitely;
- separation of your working data from other customers’ at the account level;
We review these measures as the product changes. They may be updated, but not weakened.
6. Sub-processors
You give general authorisation for us to use the sub-processors below. Each is bound by written terms no less protective than this agreement.
| Sub-processor | What it does | Location |
|---|---|---|
| IONOS SE | Hosting and storage of the product and everything in it | Germany |
| Anthropic PBC | Generates playbook content and screens CVs. Receives the job and candidate text you submit for those tools. | United States |
| ScraperAPI | Retrieves public web pages for the research and hiring radar tools | United States |
| Twilio SendGrid | Delivers transactional email from the product | United States |
| Stripe Payments Europe Limited | Subscription billing. Receives your billing data, not candidate data. | Ireland and United States |
On AI processing specifically. Where a Studio tool generates or screens content, the text you submit is sent to Anthropic’s API and the result is returned to you. Under Anthropic’s commercial terms, that content is not used to train models. We do not use candidate data uploaded by one customer to train anything, to build our own database, or for any purpose other than running the product for that customer.
We will give you at least 30 days’ notice before adding or replacing a sub-processor, by email to your account address and by updating this page. If you object on reasonable data protection grounds within that period, tell us and we will work with you to find a solution. If we cannot, you may terminate the affected part of your subscription and we will refund any prepaid amount covering the unused period.
7. Data Subject Rights
If a candidate contacts us directly about data you control, we will not respond to the substance. We will tell them to contact you, and tell you promptly.
You can access, correct, export and delete the data you hold in Studio yourself, at any time, through the product. Where you need something the product does not do, email privacy@setpointhq.com and we will help within a timescale that lets you meet your own one-month deadline.
8. Retention, Return and Deletion
| Data | What happens |
|---|---|
| Uploaded CVs | Deleted automatically 90 days after upload |
| Anything you delete | Held in a recycle bin for 30 days, then removed permanently |
| Everything else in your account | Kept while your subscription is active |
| On termination | Export your data before you close the account. We delete it within 30 days of the subscription ending, unless you ask us in writing to return it first. |
Backups are overwritten on their own cycle and any copy in a backup is deleted as that cycle completes.
9. Audits
On reasonable written notice, and no more than once in any twelve months unless a regulator requires otherwise, we will provide the information you need to verify that we are meeting this agreement. We will answer a reasonable security questionnaire. Where that is not enough for your regulator, we will discuss an inspection in good faith, at your cost, on terms that protect other customers’ data and our own confidentiality.
10. Personal Data Breaches
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any event within 48 hours of becoming aware. We will tell you what we know, what we are doing, and what we recommend you do. We will not notify a regulator or any data subject on your behalf unless you ask us to in writing, because that decision is yours as controller.
11. International Transfers
Personal data is stored in Germany. Transfers to the sub-processors in the United States listed in section 6 are made under the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, under each provider’s data processing terms. We keep a copy of the relevant terms for each and will point you to them on request.
12. Liability and Precedence
The limitations of liability in our Terms and Conditions apply to this agreement. Nothing here limits liability that cannot be limited by law. If this agreement conflicts with the Terms on the handling of personal data you upload, this agreement wins.
13. Contact
Questions about this agreement, or about a signed copy on your own paper, go to privacy@setpointhq.com.
SetpointHQ Limited, registered in England and Wales, company number 17124602. Registered office: 22 Heath Road, Ipswich IP4 5SA. ICO registration ZC165802.