Skip to main content
Nordly
Log in

Data processing agreement

Version 2026-09 · In effect from September 1, 2026

DRAFT — legal review pending

Data Processing Agreement

Version 2026-09 · Effective 1 September 2026

1. Parties

Controller: [Employer legal name], CVR [CVR], [Registered address] (the "Employer"). Processor: Nordly ApS (in formation), Copenhagen, Denmark ("Nordly").

This agreement is entered into under Article 28(3) of Regulation (EU) 2016/679 (GDPR) and forms part of the Terms of Service.

2. Subject matter and duration

Nordly processes personal data of Candidates on the Employer's behalf to run the Employer's recruiting on the Nordly platform, for as long as the Employer holds an account and until the deletion described in clause 9.

3. Nature, purpose and categories

  • Purpose: receiving and handling Applications, scheduling Interviews, keeping a Talent Pool with the Candidate's consent, and keeping a Decision Log.
  • Data subjects: Candidates; the Employer's Members.
  • Categories: contact details, CV and profile text, Application answers, Work-Permit Need (self-declared), Interview times, Decision Log entries, and — only when the Candidate chooses to share it — a Work Style Profile. No CPR numbers, birth dates, nationality, photos or addresses are collected as structured fields.

4. Instructions

Nordly processes only on the Employer's documented instructions, which are the settings and actions Members take in the platform and this agreement. Nordly informs the Employer if an instruction in its view infringes the GDPR.

5. Employer settings that shape the processing

  • Retention Period: 6 months for rejected and expired Applications, as currently set by the Employer.
  • AI-assisted ranking: not enabled.
  • AI-assisted evaluation (Candidate summaries and interview questions): enabled. Every AI-assisted output is a suggestion to a person; Nordly never rejects a Candidate and records every AI-assisted step with an AI Disclosure in the Decision Log.

6. Confidentiality and security

Nordly ensures that persons authorised to process the data are bound by confidentiality and implements the measures of Article 32: encryption in transit and at rest, EU-only hosting, server-side sessions without passwords, least-privilege access, hard deletion with deletion receipts, and no personal data in application logs.

7. Sub-processors

The Employer gives general authorisation to the following sub-processors:

  • Google Cloud EMEA Limited — Cloud Run, Cloud SQL, Cloud Storage, Vertex AI (hosting, database, files, AI models) — europe-west1 (Belgium), EU
  • Brevo (Sendinblue SAS) — Transactional email delivery — France, EU

Nordly notifies the Employer in-product at least 30 days before adding or replacing a sub-processor; the Employer may object in writing within that period.

8. Assistance

Nordly assists the Employer with data-subject requests through the compliance pages (export, erasure, retention), with Article 32–36 obligations, and notifies the Employer of a personal-data breach without undue delay and no later than 48 hours after becoming aware of it.

9. Deletion and return

Rejected and expired Applications are deleted automatically after the Retention Period. On termination the Employer's data is deleted 90 days after archiving; the Employer may export its data beforehand. Deletions are irreversible and receipted.

10. Audit

Nordly makes available the information necessary to demonstrate compliance, including the Decision Log, purge receipts and the audit export, and allows audits by the Employer or an auditor mandated by it, at most once a year, on 30 days' notice.

11. Transfers

All processing takes place in the EU. No transfer to a third country takes place without the Employer's prior written instruction.

12. Governing law

Danish law; the courts of Copenhagen.