Data Processing Agreement.
Version 2026-10-04.2 · Effective on explicit acceptance
Agreement availability
Business customers can accept these agreements in the portal, test with synthetic data in Jobo’s sandbox, and submit a request for live access. Viewing this page does not accept an agreement or activate an account.
Live access requires current agreement acceptance and Jobo approval of a submitted business review. Before live processing, the DPA also requires an agreed Processing Schedule covering the actual providers, countries, retention, and required transfer safeguards. Jobo approval does not certify a customer’s legal compliance.
Read the Auto Apply Terms, Data Processing Agreement, general Terms and Conditions, and Privacy Policy.
1. Parties, scope, and definitions
This Data Processing Agreement (DPA) is between Jobo AI LLC, at 30 N Gould St, STE R, Sheridan, WY 82801, United States (Jobo), and the business identified in the Auto Apply acceptance record (Customer). It forms part of the Auto Apply Terms and takes effect on their authenticated acceptance. Contact Jobo at support@jobo.world. Customer's account and designated business/privacy contacts identify its contracting representative. Annexes A–C form part of this DPA; an agreed Processing Schedule meeting Annex C supplements them for the authorized live service.
Applicable Data Protection Law means privacy and personal-data protection law applicable to the particular processing, including the EU GDPR, UK GDPR and applicable UK data protection legislation, Swiss Federal Act on Data Protection, and applicable US state privacy laws, where each applies. Personal Data means information about an identified or identifiable person and equivalent protected personal information under such law. Customer Personal Data means Personal Data Jobo processes on Customer's behalf through Auto Apply, including candidate information, documents, application answers, relevant verification messages, and connected mailbox secrets. A Personal Data Breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Controller, processor, subprocessor, processing, and data subject have their applicable statutory meanings.
For Customer Personal Data, Customer is the controller, or an authorized processor for an identified controller, and Jobo is the processor or subprocessor respectively. Roles follow the actual processing, not contractual labels. Customer must secure any upstream controller's authorization and transmit its relevant instructions and restrictions to Jobo. Each party remains responsible for its own statutory duties. Jobo acts separately as controller for business account administration, billing, agreement/review evidence, and necessary account-security records as described in its Privacy Policy; this does not authorize secondary use of candidate application content. Selected employers and their ATS providers receive applications under Customer's instructions and their own applicable arrangements, rather than becoming Jobo subprocessors merely by receiving a submission.
2. Documented instructions and purpose limitations
Jobo will process Customer Personal Data only on lawful documented instructions contained in this DPA, the approved Processing Schedule, authorized API requests, and authenticated support requests consistent with them. Processing is limited to the purposes and categories in Annex A, including necessary service security, support, and troubleshooting on Customer's behalf. Customer determines which candidates, employers, positions, answers, and documents are included. Customer must provide the instructions and information needed for lawful performance and must not instruct processing outside the approved scope.
Jobo will not sell or share Customer Personal Data for advertising, use it to create unrelated profiles or make employment decisions, train or improve general-purpose models with it, or disclose it for a provider's independent commercial purposes. Jobo will not combine it with other customers' candidate data for independent profiling. Statistical service information may be used only after effective anonymization meeting applicable law; pseudonymization alone does not make data anonymous. A contractual instruction cannot override a statutory prohibition.
Jobo will immediately inform Customer if, in Jobo's opinion, an instruction infringes applicable data protection law and pause affected processing while the issue is resolved. If law requires processing outside Customer's instructions, Jobo will notify Customer before that processing unless the law prohibits notice, limit processing to the legal requirement, and record the requirement. For GDPR-covered processing, the exception applies only to a qualifying legal requirement under the applicable GDPR provision; a conflicting foreign demand is addressed under Section 9 and any transfer clauses. Jobo will not treat a general law-enforcement request as blanket authority to disclose data.
3. Customer's obligations and lawful disclosure
Customer is responsible for the lawfulness, fairness, transparency, accuracy, and necessity of its collection, instructions, and selected recipients, including candidate authorization to act, applicable lawful bases, privacy notices, sensitive-data conditions, and rights procedures. Authorization to apply is not automatically privacy-law consent. Customer must not rely on acceptance of this DPA as consent from candidates or as an international transfer derogation. Customer must maintain its own evidence of candidate authorization; routine onboarding uses blank wording and workflow descriptions, not actual candidate consent records.
Customer must minimize data, restrict its own personnel and credentials, promptly report withdrawal or correction affecting pending instructions, and respond to candidates and authorities as required. Where Customer is a processor, it must identify the upstream controller in the Processing Schedule, ensure that this DPA implements the required obligations, and provide instructions and notices through the proper chain. Jobo may request reasonably necessary clarification but does not assume Customer's controller responsibilities or certify its compliance.
4. Personnel, confidentiality, and security
Jobo will ensure persons authorized to process Customer Personal Data have a need for access, receive relevant privacy and security instruction, and are bound by confidentiality obligations or an appropriate statutory duty. Access must be removed when no longer needed. Jobo will implement and maintain risk-appropriate technical and organizational measures, including the minimum commitments in Annex B, and regularly assess their effectiveness. Measures must address the nature and sensitivity of the data, the service's external submissions, and risks to individuals, considering the state of the art and implementation costs as applicable law allows.
Jobo will document implemented measures before permitting live processing and will not materially reduce their overall protection during the service. Material changes require appropriate notice and, where they change an approved processing detail, the procedure in Annex C. No statement in this DPA represents an audit certification or guarantees that security incidents cannot occur. Customer may request information reasonably necessary to assess the measures under Section 8.
5. Subprocessor authorization and changes
Customer grants general written authorization only for subprocessors specifically identified in the agreed, dated Processing Schedule and subprocessor register. A brand or technical integration mentioned in Annex C is not an authorized subprocessor entry. Before a provider processes Customer Personal Data, Jobo must identify its legal entity, service, data categories, processing and remote-access countries, retention, relevant onward providers, and transfer safeguards; perform appropriate diligence; and bind it by a written agreement imposing materially equivalent data protection duties, including confidentiality, security, instructions, rights assistance, incident notification, deletion, and applicable transfer obligations. Jobo remains responsible to Customer for its subprocessors' performance as required by applicable law.
Jobo will give at least 30 calendar days' written notice before adding or replacing a subprocessor or materially changing its authorized countries or purpose. Customer may object during that period on reasonable, documented data protection grounds. Jobo will discuss a suitable alternative or measures to address the objection. Jobo will not use the disputed provider for Customer's data while the objection is unresolved. If no reasonable solution is available, either party may terminate the affected feature or service; Customer receives a proportional refund of prepaid unused fees for that terminated service, without a termination penalty, and data is returned or deleted under Section 7.
If an urgent security event requires a faster replacement, Jobo must give notice as soon as practicable and obtain Customer's specific written authorization before the replacement processes its data; otherwise affected processing must pause. Subprocessor approvals from an upstream controller must be obtained where required. Model-router fallbacks and remote support are subject to the same authorization rules; a provider's dynamic routing cannot expand the approved register.
6. Rights assistance, impact assessments, and breaches
Taking account of the nature of processing, Jobo will assist Customer through appropriate technical and organizational measures with applicable access, correction, deletion, restriction, portability, objection, and other individual rights. Requests should identify the relevant account and application IDs through support@jobo.world or an agreed secure channel. Jobo will verify the requester's authority, promptly route requests received directly from individuals to Customer, and refrain from substantive responses except on Customer's instructions or as legally required. Jobo will promptly provide available information or carry out feasible instructed actions in time for Customer's statutory deadline; Customer must communicate that deadline and must not postpone forwarding a request. Employer or ATS copies require requests to those recipients.
Considering the information available and the nature of processing, Jobo will assist Customer with security obligations, data protection impact assessments, transfer assessments, prior consultations, and required regulator inquiries. Jobo will identify relevant service information, risks, measures, and subprocessors and cooperate with competent authorities as required. Reasonable documented costs for unusually extensive assistance may be agreed in advance; Jobo will not condition urgent or mandatory assistance on resolving fees, and assistance required because of Jobo's breach is at Jobo's cost.
Jobo will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, through the designated privacy/security contact and account email. It will provide available information about the nature and timing, affected data and individuals and approximate counts, likely consequences, mitigation, and a contact for follow-up; incomplete information will be supplemented without undue further delay. Jobo will investigate, contain and remediate the breach, preserve appropriate evidence, and reasonably cooperate with Customer's response. Notification does not require a completed investigation and is not an admission of liability. Customer decides its notices to individuals and authorities unless law requires Jobo to act directly; Jobo will coordinate where permitted. A Customer acting as processor must promptly notify its controller. The parties must maintain reachable incident contacts and a tested escalation procedure before live processing.
7. Retention, return, and deletion
Jobo will retain Customer Personal Data only for the authorized service and documented retention periods. The default is deletion of finished applications, their steps and answers 180 days after submission, failure, or cancellation, and deletion of captured browser troubleshooting commands/results after 30 days. Pending applications remain while active; Customer and Jobo must review abandoned work and close it when no longer needed. Customer may instruct earlier deletion or shorter agreed retention. No deployment setting may disable an applicable deletion obligation.
On termination or a valid instruction, Customer may choose return or deletion. Jobo will provide available Customer Personal Data in a commonly used machine-readable form through a secure method and delete active copies within 30 calendar days of the instruction or termination, unless a shorter statutory deadline applies. If Customer requests return, Jobo will allow a reasonable retrieval period within that window before deletion. Files, temporary browser/session artifacts, mailbox connections and secrets, message caches, support copies, logs, and subprocessor copies must follow the category-specific schedule in Annex C. Disconnecting an authorized mailbox must revoke or delete Jobo's stored access credentials; copies in the mailbox provider's own system remain subject to Customer's arrangements with that provider.
Backup deletion must have a verified maximum calendar period specified in the Processing Schedule, which may not exceed 90 days after deletion from active systems unless a different period is expressly agreed in writing, lawful, and supported by documented necessity. Residual backup data must remain isolated, protected, unavailable for ordinary use, and expire under that schedule. On disaster recovery, relevant deletions must be reapplied before restored data returns to ordinary processing. Retaining a fixed number of snapshots is not itself a calendar deletion guarantee. Jobo will ensure equivalent deletion instructions reach subprocessors and, on request, confirm completion and any lawful exceptions in writing.
If applicable law requires retaining particular data, Jobo will identify the legal ground, categories and duration where legally permitted, restrict the data to that obligation, protect it, and delete it when the obligation ends. Contract and review evidence is separate controller processing: Jobo will retain minimal acceptance and approved-review evidence for six years after the Auto Apply relationship ends, and unsuccessful review material for no longer than 12 months after the final decision unless needed for a documented dispute, legal duty, or renewed review. A justified legal hold may extend those periods only for the relevant records; necessity must be reviewed periodically. This policy does not authorize retaining candidate content with contract evidence or override lawful erasure rights. Jobo must operate these finite retention periods and a documented process for lawful exceptional erasure from the start of collecting agreement and review evidence. These obligations also apply during onboarding and sandbox use.
Deleting Jobo's copy cannot recall data already received by an employer or ATS. Customer remains responsible for required recipient requests; Jobo will assist with available submission identifiers.
8. Records, information, and audits
Jobo will keep records of processing and compliance information required by applicable law, make available information necessary to demonstrate its processor obligations, and allow and contribute to audits and inspections by Customer or its independent mandated auditor. An initial request may be addressed through current documentation or relevant independent reports, but those materials do not extinguish a lawful inspection right. Customer may verify compliance through reasonable assessments, tests, and audits and require steps to stop or remediate unauthorized processing.
Ordinary audits should use reasonable advance notice, business hours, proportionate scope, and safeguards for security and other customers' confidentiality. Auditors must be competent, independent, and bound by confidentiality. These arrangements must not prevent required access, urgent investigation of a breach or credible noncompliance, regulator access, or audits mandated by transfer clauses. Reasonable mutually agreed costs may apply to additional ordinary audits; Jobo bears remediation and reasonable audit costs attributable to its material breach. Jobo will notify Customer if it can no longer comply with this DPA or applicable service-provider duties and promptly address the issue or stop affected processing.
9. International transfers and government requests
Jobo will not initiate a restricted international transfer, including relevant remote access, until the applicable lawful mechanism and required assessment and supplementary measures are completed for the actual parties, roles, locations, and data. The Processing Schedule must identify the mechanism for each relevant route. These Terms do not rely on the Customer's click as an individual's transfer consent and do not themselves complete Standard Contractual Clauses, a UK transfer instrument, or a transfer assessment.
Where required and legally suitable, the parties must separately execute the unmodified applicable EU Standard Contractual Clauses with the correct module, options, parties and completed annexes; a Customer-controller relationship will generally call for a controller-to-processor module and an authorized Customer-processor relationship for a processor-to-processor module. Applicability must be assessed for the actual transfer; another approved instrument must be used where necessary. UK restricted transfers require a suitable completed UK Addendum or International Data Transfer Agreement and applicable assessment. Swiss transfers require applicable adaptations and safeguards. Adequacy or another lawful mechanism may be used only within its valid scope. Mandatory transfer provisions control conflicts with these agreements, including governing law, audits, third-party rights, and liability.
Jobo will assess government disclosure requests, seek clarification or challenge unlawful or disproportionate demands where there are reasonable grounds and legally available remedies, notify Customer and any other required party where legally permitted, and disclose only the minimum legally required information. Jobo will not voluntarily provide unrestricted access to Customer Personal Data. If a safeguard becomes invalid or cannot be met, Jobo must notify Customer and suspend affected transfers until a lawful solution is established, or return/delete affected data and terminate affected processing. Neither worldwide availability nor a customer's instruction proves a transfer lawful.
10. US state service-provider and contractor obligations
To the extent applicable US state privacy law treats Customer as a business/controller and Jobo as its service provider, contractor, or processor, Customer discloses Personal Data solely for the specific service purposes in Annex A. Jobo will provide the same level of protection required by applicable law, process only under those instructions, and not sell or share the data, retain, use or disclose it outside the specified purposes or direct business relationship, or combine it with information received from other persons or collected through Jobo's own interactions except as expressly permitted by that law and this DPA. These restrictions apply to sensitive information where that law requires.
Jobo certifies that it understands these restrictions and will comply with them. Jobo will notify Customer if it can no longer meet them. Customer may take reasonable and appropriate steps under Section 8 to ensure consistent use and stop and remediate unauthorized use. Jobo will assist with applicable consumer requests and assessments, impose required restrictions on authorized downstream providers, and make available the information required for Customer's statutory contract obligations. Nothing in this section expands processing beyond Sections 2 and 5 or allows an exception merely because it might be commercially useful.
11. Duration, amendments, and responsibility
This DPA applies while Jobo processes Customer Personal Data and survives service termination until that data is returned or deleted as required. Each party is responsible for its own compliance, and Jobo remains responsible for its applicable processor duties and authorized subprocessors. Commercial liability allocation in the Auto Apply Terms applies only to the extent lawful and cannot restrict statutory individual rights, regulator powers, or mandatory transfer-clause provisions. No contractual label or indemnity excuses unlawful processing.
Material changes to this DPA require explicit acceptance of a new agreement version or a written agreement by authorized representatives. Processing Schedule changes follow Annex C, and subprocessor changes follow Section 5. No material reduction in data protection is accepted merely through continued use or website publication. If a provision conflicts with mandatory law or transfer clauses, those requirements prevail and the remaining provisions continue to apply.
ANNEX A — Processing description and instructions
Subject matter: operating Customer-directed applications through supported employer and ATS interfaces and associated application verification, status reporting, troubleshooting, and support.
Nature and operations: receive and validate supplied data; retrieve authorized application fields and files; temporarily store and encrypt payloads; map supplied answers to native fields/options; operate supported forms or APIs; transmit to selected employers/ATS; read relevant verification/confirmation messages when an authorized mailbox integration is enabled; report status; investigate failures; and carry out instructed export/deletion. AI search/matching, where separately authorized, may use the supplied answer, field type, provider identifier and candidate form-option labels. It is not authorization to send an entire resume or inbox to an AI model.
Specific purposes: perform the particular candidate applications and verification steps instructed by Customer, maintain their service status, secure that processing, troubleshoot it, and provide necessary customer support. No independent recruitment scoring, data brokerage, advertising, general model training, or unrelated profiling is included.
Duration and frequency: the service term and instructed retention under Section 7; processing occurs per API request and associated asynchronous steps, with support and deletion as needed. The Processing Schedule records anticipated frequency and volume.
Data subjects: candidates whose applications Customer is authorized to submit; other persons named in supplied references/documents only to the extent necessary and lawfully disclosed; authorized mailbox users where that feature is approved.
Ordinary data categories: names, contact details, location, resumes and cover letters, employment/education/qualification history, professional links, role preferences, application answers and declarations, uploaded application documents, employer/position identifiers, timestamps, technical status and troubleshooting records, and verification codes or relevant confirmation messages. Mailbox connection identifiers, IMAP secrets or Microsoft OAuth tokens are included only for an approved connection.
Restricted categories: demographic, health/disability, other special-category or sensitive information, or criminal-offence information only if necessary for a supported application, lawfully provided, specifically covered in the Processing Schedule, and subject to appropriate access/minimization safeguards. Biometric templates, unrelated health records, payment details, identity documents, and children's data are outside the default scope. Customer must not provide them without express supported approval and a lawful additional arrangement.
Recipients: the employer/ATS selected for each application; authorized subprocessors only for their approved functions; authorized Jobo personnel; and authorities only under a qualifying legal duty. Customer's API instruction identifies each application recipient. The candidate must receive the required recipient and processing information through Customer's notices.
ANNEX B — Minimum technical and organizational commitments
Access and isolation: authenticated account access and scoped ownership checks; explicit agreement and live-approval enforcement at intake and submission boundaries; least-privilege staff and service permissions; controlled privileged access; separation of customer records; prompt credential revocation; and records of relevant administrative access and decisions. Multi-factor authentication must protect privileged production administration.
Encryption and secrets: encrypted public transport; authenticated, appropriately protected internal service communications; encryption of stored candidate payloads and mailbox credentials using strong contemporary cryptography; encrypted backups; keys/secrets kept separately from protected payloads; controlled rotation and access; and no credentials, full candidate payloads, or unnecessary sensitive information in ordinary logs. Repository code supports AES-256-GCM protection for application payloads and mailbox secrets; deployed key management and coverage must be verified before live use.
Submission and network controls: validate supported targets and file sources; prevent access to private/internal addresses through customer-supplied URLs; use bounded, authorized file retrieval and short-lived scoped file access; isolate browser sessions; restrict automation to approved flows; protect callback and service credentials; and check permission before dispatching writes. Cancellation and uncertain outcomes must be reported accurately. These controls do not replace ATS access permissions.
Minimization and supplier controls: limit diagnostic capture to needed fields, restrict diagnostic access, and apply the 30-day deletion period; limit mailbox reads to relevant application verification/confirmation; remove temporary session artifacts; prevent candidate-content model training or unrelated provider reuse; and ensure routing/fallbacks remain within approved providers, regions and data-use settings. If these conditions cannot be ensured, affected processing must be disabled.
Operations and resilience: maintain security updates and vulnerability handling; proportionate logging and alerting; an incident escalation and customer notification process; protected backups; restore and deletion replay procedures; and periodic assessment of security, access, retention, and recovery controls. Staff must receive relevant confidentiality, phishing, access, and incident training. Production changes must be controlled and appropriate security defects remedied promptly.
Deletion and rights: identify application, file, mailbox, log, support, vendor and backup copies; operate the agreed retention and secure export/deletion procedures; verify sweeps and expiry; restrict lawfully retained records; and maintain a process for authenticated rights assistance. Jobo must document the implemented measures and responsible functions. These are contractual minimum commitments, not a statement that an independent auditor has certified a deployment.
ANNEX C — Processing Schedule, provider register, and live-processing condition
Before any live candidate processing, Jobo and Customer must agree a dated Processing Schedule in a signed document or an authenticated written exchange between authorized representatives. Jobo must retain that agreement and provide Customer a durable copy. It must identify Customer's legal entity and contacts, controller/processor role and any upstream controller, authorized use and markets, data categories including any restricted categories, recipient types, features, expected volume, term, and relevant retention instructions. A business-review approval alone is not acceptance of an undisclosed processing schedule.
The schedule must attach a provider register identifying every entity handling Customer Personal Data on Jobo's behalf, its legal name, function, data exposed, hosting and remote-access countries, relevant onward providers, maximum retention/deletion period, and transfer mechanism. It must identify Jobo's own processing and support-access countries, specific security/incident and rights-request procedures and contacts, file/session/mailbox/support retention, a maximum backup expiry measured in calendar days, and the necessary completed transfer instruments and assessments. Customer-specific restrictions and any disabled feature must be recorded. An upstream controller must approve where applicable.
Technical integrations presently identified in the repository are Hetzner server infrastructure for the mono deployment; Cloudflare public edge and R2 database backups; Jobo-operated browser/session services; 2Captcha residential proxy and CAPTCHA services; OpenRouter answer-search/option matching with configured DeepSeek and Google Gemini model families and possible model-hosting providers; and Microsoft Graph/Outlook or Customer-selected IMAP mailbox connections. Brevo is configured for business-account notifications, which are separate account-controller processing unless Customer Personal Data is included. These are implementation disclosures, not a complete authorized legal-entity register or proof of signed vendor agreements. The operator must distinguish a model brand from the entity actually receiving the prompt, and a Customer-selected mailbox/ATS recipient from a supplier engaged by Jobo.
Repository infrastructure documentation includes a Hetzner mono tier and an older OVH deployment/cutover path; it does not prove which tier currently processes live data or all processing countries. The backup runbook describes nightly encrypted restic database snapshots in Cloudflare R2 keeping the last seven snapshots; this must not be represented as a verified seven-day deletion deadline. The register must use the actual deployed service and contracts, not infer locations from IP addresses, provider names, or model names.
No incomplete register, unknown country, unsigned required vendor DPA, unverified model data-use setting, or missing required transfer arrangement is authorized by this DPA. Jobo must pause the affected feature or live service until those conditions are resolved. During that period Customer may use only the configured sandbox with synthetic data once agreement acceptance is available. Agreement acceptance and synthetic sandbox use may begin before the live-processing arrangements are completed. Jobo must verify the contractual security and candidate-data retention commitments before live processing; Customer's acceptance does not waive that condition or complete the required Processing Schedule.
Later changes within the approved purposes that do not reduce protection must be recorded and notified in writing. New purposes, markets, restricted data categories, or changes requiring new transfer arrangements need prior written agreement; subprocessor changes additionally follow Section 5. A Processing Schedule cannot silently amend the accepted DPA, expand model training rights, or authorize an unlawful transfer.