Data Processing Agreement
Last updated: April 1, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Carevo Inc. ("Carevo," "Processor," "we," "us") and the employer entity subscribing to the Service ("Controller," "you," "your"), as identified in the applicable subscription agreement or Terms of Service (the "Agreement").
This DPA applies when Carevo processes personal data on behalf of the Controller in connection with providing recruitment, matching, and hiring services through the Carevo platform.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Carevo on behalf of the Controller through the Service.
- "Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, combination, restriction, erasure, or destruction.
- "Data Subject" means the identified or identifiable natural person to whom the Personal Data relates, typically job candidates who interact with the Controller through the Service.
- "Sub-processor" means any third party engaged by Carevo to process Personal Data on behalf of the Controller.
- "Data Protection Laws" means all applicable laws relating to the processing of Personal Data, including the California Consumer Privacy Act (CCPA), the General Data Protection Regulation (GDPR) where applicable, and any other relevant data protection legislation.
- "Security Incident" means any unauthorized or unlawful breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
2. Scope and Purpose of Processing
2.1 Subject Matter
Carevo processes Personal Data to provide the Controller with recruitment, talent matching, candidate screening, and hiring management services as described in the Agreement.
2.2 Categories of Data Subjects
- Job candidates who apply for or are matched with the Controller's open roles.
- The Controller's employees and authorized users who access the platform.
2.3 Types of Personal Data
- Candidate profile information: name, email address, phone number, location, and professional social media profiles.
- Career and employment data: work history, education, skills, certifications, and portfolio materials.
- Career DNA data: AI-generated profile attributes including skills assessments, work style preferences, motivations, and culture fit indicators.
- Application data: resumes, cover letters, application responses, and interview notes.
- Match and scoring data: fit scores, dimension breakdowns, and agent reasoning for matches.
- Communication data: messages exchanged between candidates and the Career Agent in the context of matching with the Controller's roles.
2.4 Duration
Processing shall continue for the duration of the Agreement. Upon termination of the Agreement, Carevo will handle Personal Data in accordance with Section 9 of this DPA.
3. Obligations of the Controller
The Controller agrees to:
- Ensure that it has a lawful basis for the processing of Personal Data and that all necessary consents have been obtained from Data Subjects where required.
- Provide Carevo with clear and documented instructions regarding the processing of Personal Data.
- Comply with all applicable Data Protection Laws in relation to its use of the Service and the Personal Data processed through it.
- Notify Carevo promptly of any changes to its processing instructions or of any Data Subject requests it receives that relate to Carevo's processing activities.
4. Obligations of the Processor
Carevo agrees to:
- Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law.
- Ensure that persons authorized to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing.
- Assist the Controller in fulfilling its obligations to respond to Data Subject requests, including requests for access, correction, deletion, and portability.
- Assist the Controller in ensuring compliance with its obligations regarding data protection impact assessments and prior consultations with supervisory authorities, where applicable.
- Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA.
- Not process Personal Data for any purpose other than providing the Service as described in the Agreement, unless instructed by the Controller or required by law.
5. Security Measures
Carevo implements and maintains the following technical and organizational security measures to protect Personal Data:
5.1 Access Controls
- Role-based access control (RBAC) for all internal systems and databases.
- Multi-factor authentication (MFA) required for all Carevo employees accessing production systems.
- Row-level security (RLS) policies in the database ensuring data isolation between Controllers.
- Principle of least privilege applied to all internal access grants.
5.2 Encryption
- Data in transit encrypted using TLS 1.3.
- Data at rest encrypted using AES-256 encryption.
- Database backups encrypted at rest.
5.3 Infrastructure
- Application hosted on Vercel with enterprise-grade security controls.
- Database hosted on Supabase with automated backups, point-in-time recovery, and SOC 2 Type II compliance.
- DDoS protection and Web Application Firewall (WAF) in place.
- Rate limiting via Upstash Redis to prevent abuse and unauthorized access.
5.4 Monitoring and Incident Response
- Continuous monitoring through Sentry for error tracking and anomaly detection.
- Automated alerts for suspicious activity, unauthorized access attempts, and system anomalies.
- Documented incident response procedures with defined escalation paths.
6. Sub-processors
6.1 Authorized Sub-processors
The Controller authorizes Carevo to engage the following sub-processors for the processing of Personal Data:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database hosting, authentication, and data storage | United States |
| Anthropic PBC | AI processing for career analysis, matching, and content generation | United States |
| Stripe Inc. | Payment processing | United States |
| Vercel Inc. | Application hosting and content delivery | United States |
| Resend Inc. | Transactional email delivery | United States |
| Upstash Inc. | Rate limiting and caching | United States |
| PostHog Inc. | Product analytics and feature flags | United States |
| Sentry (Functional Software Inc.) | Error monitoring and performance tracking | United States |
| Inngest Inc. | Background job processing | United States |
6.2 Changes to Sub-processors
Carevo will notify the Controller at least 30 days in advance of engaging any new sub-processor or replacing an existing sub-processor. The Controller may object to the new sub-processor by providing written notice within 14 days of receiving notification. If the Controller objects, Carevo will make reasonable efforts to provide an alternative arrangement. If no resolution is reached, the Controller may terminate the affected portion of the Service.
6.3 Sub-processor Obligations
Carevo ensures that each sub-processor is bound by contractual obligations that provide a level of data protection no less protective than this DPA. Carevo remains responsible for the acts and omissions of its sub-processors.
7. Data Subject Rights
Carevo will assist the Controller in responding to Data Subject requests in accordance with Data Protection Laws. This includes:
- Providing the Controller with tools and APIs to access, export, and delete candidate data.
- Promptly forwarding any Data Subject requests received directly by Carevo to the Controller, unless Carevo is legally authorized to respond directly.
- Implementing technical measures to support data portability in structured, commonly used, machine-readable formats (JSON).
8. Security Incidents
8.1 Notification
Carevo will notify the Controller of any Security Incident without undue delay, and in any event within 72 hours of becoming aware of the incident. The notification will include:
- A description of the nature of the Security Incident.
- The categories and approximate number of Data Subjects affected.
- The categories and approximate number of records concerned.
- A description of the likely consequences of the incident.
- A description of the measures taken or proposed to address the incident.
- The contact details of Carevo's designated point of contact.
8.2 Cooperation
Carevo will cooperate with the Controller and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of any Security Incident.
9. Data Return and Deletion
Upon termination of the Agreement, or upon the Controller's written request:
- Carevo will provide the Controller with a complete export of all Personal Data processed under this DPA in a structured, machine-readable format within 30 days.
- After the Controller confirms receipt of the data export (or after 30 days if no response is received), Carevo will delete all Personal Data from its active systems within 30 days.
- Copies of Personal Data in encrypted backups will be deleted within 90 days of the deletion from active systems.
- Carevo may retain Personal Data to the extent required by applicable law, in which case Carevo will continue to protect such data in accordance with this DPA.
10. Audits
Carevo will make available to the Controller, upon reasonable request and at the Controller's expense, information necessary to demonstrate compliance with this DPA. This may include:
- Providing copies of relevant third-party audit reports (such as SOC 2 Type II reports from Supabase).
- Responding to written questionnaires about security practices and data processing activities.
- Permitting audits conducted by the Controller or a qualified third-party auditor, subject to reasonable advance notice (at least 30 days), scope limitations, and confidentiality obligations. Audits shall be conducted no more than once per calendar year.
11. International Transfers
Personal Data processed under this DPA may be transferred to and stored in the United States. Where transfers occur to countries that have not been deemed to provide an adequate level of data protection, Carevo will ensure that appropriate transfer mechanisms are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms.
12. Limitation of Liability
Each party's liability arising out of or related to this DPA shall be subject to the limitations of liability set forth in the Agreement.
13. Governing Law
This DPA shall be governed by the same governing law as the Agreement, unless otherwise required by Data Protection Laws.
14. Contact Information
For questions or requests relating to this DPA, please contact:
- Email: dpa@carevo.tech
- Mail: Carevo Inc., Data Protection Team, San Francisco, CA, United States