Data processing agreement
Version 2026-09 · In effect from September 1, 2026
DRAFT — legal review pending
Data Processing Agreement
Version 2026-09 · Effective 1 September 2026
1. Parties
Controller: [Employer legal name], CVR [CVR], [Registered address] (the "Employer"). Processor: Nordly ApS (in formation), Copenhagen, Denmark ("Nordly").
This agreement is entered into under Article 28(3) of Regulation (EU) 2016/679 (GDPR) and forms part of the Terms of Service.
2. Subject matter and duration
Nordly processes personal data of Candidates on the Employer's behalf to run the Employer's recruiting on the Nordly platform, for as long as the Employer holds an account and until the deletion described in clause 9.
3. Nature, purpose and categories
- Purpose: receiving and handling Applications, scheduling Interviews, keeping a Talent Pool with the Candidate's consent, and keeping a Decision Log.
- Data subjects: Candidates; the Employer's Members.
- Categories: contact details, CV and profile text, Application answers, Work-Permit Need (self-declared), Interview times, Decision Log entries, and — only when the Candidate chooses to share it — a Work Style Profile. No CPR numbers, birth dates, nationality, photos or addresses are collected as structured fields.
4. Instructions
Nordly processes only on the Employer's documented instructions, which are the settings and actions Members take in the platform and this agreement. Nordly informs the Employer if an instruction in its view infringes the GDPR.
5. Employer settings that shape the processing
- Retention Period: 6 months for rejected and expired Applications, as currently set by the Employer.
- AI-assisted ranking: not enabled.
- AI-assisted evaluation (Candidate summaries and interview questions): enabled. Every AI-assisted output is a suggestion to a person; Nordly never rejects a Candidate and records every AI-assisted step with an AI Disclosure in the Decision Log.
6. Confidentiality and security
Nordly ensures that persons authorised to process the data are bound by confidentiality and implements the measures of Article 32: encryption in transit and at rest, EU-only hosting, server-side sessions without passwords, least-privilege access, hard deletion with deletion receipts, and no personal data in application logs.
7. Sub-processors
The Employer gives general authorisation to the following sub-processors:
- Google Cloud EMEA Limited — Cloud Run, Cloud SQL, Cloud Storage, Vertex AI (hosting, database, files, AI models) — europe-west1 (Belgium), EU
- Brevo (Sendinblue SAS) — Transactional email delivery — France, EU
Nordly notifies the Employer in-product at least 30 days before adding or replacing a sub-processor; the Employer may object in writing within that period.
8. Assistance
Nordly assists the Employer with data-subject requests through the compliance pages (export, erasure, retention), with Article 32–36 obligations, and notifies the Employer of a personal-data breach without undue delay and no later than 48 hours after becoming aware of it.
9. Deletion and return
Rejected and expired Applications are deleted automatically after the Retention Period. On termination the Employer's data is deleted 90 days after archiving; the Employer may export its data beforehand. Deletions are irreversible and receipted.
10. Audit
Nordly makes available the information necessary to demonstrate compliance, including the Decision Log, purge receipts and the audit export, and allows audits by the Employer or an auditor mandated by it, at most once a year, on 30 days' notice.
11. Transfers
All processing takes place in the EU. No transfer to a third country takes place without the Employer's prior written instruction.
12. Governing law
Danish law; the courts of Copenhagen.