Data Processing Agreement
Version 2026-08-18
This Data Processing Agreement ("DPA") is entered into pursuant to Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and forms part of the commercial agreement (the "Agreement") concluded between:
(1) S.C. Transdesk Communications S.R.L., a limited liability company incorporated under the laws of Romania, having its registered office at Str. Valea Alba 8, Bl. 8, Sc. A, Ap. 4, 600004 Bacau, Romania, registered with the Trade Register under number J04/1695/2007, VAT identification number RO 37074538, trading as "mindsparx" ("mindsparx", the "Processor"); and
(2) the business customer identified in the Agreement (the "Client", the "Controller"),
each a "Party" and together the "Parties".
Where any provision of this DPA conflicts with any provision of the Agreement in respect of the Processing of Personal Data, this DPA shall prevail.
1. Definitions and Interpretation
1.1. In this DPA:
"Candidate" means a natural person who undertakes an Assessment commissioned by the Client and who is identified to mindsparx solely by a Code assigned by the Client.
"Candidate Data" means Personal Data relating to Candidates which mindsparx Processes on behalf of the Client in connection with the Services.
"Code" means the pseudonymous alphanumeric identifier assigned by the Client to a Candidate.
"Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach" and "Sub-Processor" shall bear the meanings respectively given to them in the GDPR.
"Services" means the mindsparx skill-assessment platform and the services provided under the Agreement.
"Standard Contractual Clauses" means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission pursuant to Article 46(2)(c) GDPR.
1.2. Clause headings are inserted for convenience only and shall not affect construction. The expressions "including", "includes" and "in particular" shall be construed without limitation. References to a Clause or an Annex are references to a Clause or an Annex of this DPA. References to any enactment include that enactment as amended, extended or re-enacted from time to time.
2. Allocation of Roles
2.1. In respect of Candidate Data Processed in the course of Assessments commissioned by the Client, the Client is the Controller and mindsparx is the Processor. The particulars of such Processing are set out at Annex A.
2.2. mindsparx acts as an independent controller, and not as Processor, in respect of: the Client's own account data; the security of the Services and the prevention and detection of abuse; the assessment integrity monitoring described in the mindsparx privacy policy; the derivation and retention of aggregate statistical data relating to no identified or identifiable natural person; and compliance with legal obligations to which mindsparx is itself subject. Such Processing is governed by the mindsparx privacy policy published at mindsparx.ai/privacy.
2.3. Design of the Services. The Services are designed such that mindsparx does not receive the identity of any Candidate. The Client assigns a Code to each Candidate and retains the mapping between Code and identity outside the Services.
2.4. Client warranties. The Client represents, warrants and undertakes that:
(a) it shall not employ any Code which itself constitutes or contains Personal Data, including any name, email address or publicly attributable reference;
(b) it shall not enter into the Services the name, email address or any other direct identifier of any Candidate; and
(c) it has informed its Candidates of the Processing contemplated by this DPA and has established and maintains a lawful basis for it.
2.5. Personal Data introduced into the Services in breach of Clause 2.4(a) or 2.4(b) shall nonetheless enjoy the protections of this DPA, and the Client shall be responsible for the consequences of such introduction.
3. Instructions
3.1. mindsparx shall Process Candidate Data only upon the documented instructions of the Client, including in respect of transfers to a third country, save where required to do otherwise by Union or Member State law to which mindsparx is subject. In such a case mindsparx shall inform the Client of that legal requirement prior to Processing, unless that law prohibits such information on important grounds of public interest.
3.2. The Agreement, this DPA, and the Client's use of the documented functionality of the Services, including the creation of assessment runs, the addition of Codes, the initiation of retests, the viewing of results and the deletion of Candidate records, together constitute the Client's documented instructions.
3.3. Instructions falling outside the documented functionality of the Services shall be agreed in writing and may be subject to a reasonable charge where they require effort beyond the provision of the Services.
3.4. mindsparx shall inform the Client without undue delay where, in its opinion, an instruction infringes the GDPR or any other Union or Member State data protection provision, and may suspend performance of the instruction concerned pending its confirmation or withdrawal.
4. Confidentiality
4.1. mindsparx shall ensure that each person authorised by it to Process Candidate Data, whether employee or contractor, is subject to an obligation of confidentiality, whether contractual or statutory, and Processes Candidate Data only to the extent necessary for the provision of the Services.
5. Security
5.1. mindsparx shall implement and maintain the technical and organisational measures set out at Annex B, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing, as required by Article 32 GDPR.
5.2. mindsparx may amend Annex B from time to time, provided that no such amendment shall materially diminish the level of protection afforded to Candidate Data.
6. Sub-Processors
6.1. The Client grants mindsparx general written authorisation, within the meaning of Article 28(2) GDPR, to engage the Sub-Processors listed at Annex C, which list is maintained at mindsparx.ai/subprocessors.
6.2. mindsparx shall give the Client not less than thirty (30) days' notice prior to the engagement or replacement of any Sub-Processor, by updating the said list and notifying the Client at its account email address. The Client may object to such engagement or replacement on reasonable data protection grounds within that period. Where such objection cannot be resolved between the Parties, the Client may terminate the affected part of the Agreement, whereupon Clause 10 shall apply.
6.3. mindsparx shall impose upon each Sub-Processor, by written contract, data protection obligations materially equivalent to those set out in this DPA, and shall remain fully liable to the Client for the performance of each Sub-Processor's obligations.
7. Assistance to the Client
7.1. Requests of Data Subjects. Taking into account the nature of the Processing, mindsparx shall assist the Client by appropriate technical and organisational measures, insofar as this is possible, in the fulfilment of the Client's obligation to respond to requests for the exercise of the rights conferred by Chapter III GDPR. mindsparx being unable to identify any Candidate, such assistance shall be rendered in respect of requests relayed by the Client and identified by Code, and may comprise the export, rectification, restriction or erasure of the records held against that Code.
7.2. Where a Data Subject addresses such a request to mindsparx directly in respect of an Assessment commissioned by the Client, mindsparx shall transmit the request to the Client without undue delay and shall not respond to its substance save as required by law.
7.3. Security, breach notification and impact assessments. mindsparx shall assist the Client in ensuring compliance with the obligations arising under Articles 32 to 36 GDPR, taking into account the nature of the Processing and the information available to mindsparx.
7.4. Assistance under this Clause 7 is included within the Services in respect of reasonable requests. mindsparx may charge a reasonable fee in respect of requests which are repetitive, manifestly excessive, or which require substantial manual effort, and shall notify the Client of any such fee prior to incurring it.
8. Personal Data Breach
8.1. mindsparx shall notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Candidate Data, and in any event within forty-eight (48) hours of becoming aware thereof, by notice to the Client's account email address.
8.2. Such notification shall describe, to the extent then known: the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects and of records concerned; the likely consequences; the measures taken or proposed to be taken; and a contact point. Information may be provided in phases as it becomes available.
8.3. mindsparx shall document each Personal Data Breach and shall cooperate with the Client in respect of the Client's own notification obligations. The Client, as Controller, shall be responsible for notifying its supervisory authority and its Candidates where required by Articles 33 and 34 GDPR.
9. Transfers to Third Countries
9.1. Candidate Data is stored within the European Union. Certain Sub-Processors listed at Annex C are established outside the European Economic Area, or may access Candidate Data from outside the European Economic Area for support purposes.
9.2. In respect of each such transfer, mindsparx shall ensure that a valid transfer mechanism under Chapter V GDPR subsists, being the Standard Contractual Clauses incorporated into the contract with the relevant Sub-Processor together with a transfer impact assessment, or an adequacy decision pursuant to Article 45 GDPR where the Sub-Processor is certified under a framework recognised by the European Commission. Copies of the applicable safeguards shall be furnished to the Client upon request.
10. Deletion or Return upon Termination
10.1. Upon cessation of the provision of the Services, mindsparx shall, at the election of the Client, delete or return all Candidate Data Processed on the Client's behalf and delete existing copies thereof, save to the extent that Union or Member State law requires the storage of any specific record, in which case mindsparx shall identify that record and the ground of retention.
10.2. In the absence of an election communicated within sixty (60) days of such cessation, mindsparx shall delete the Candidate Data in accordance with the retention provisions of the mindsparx privacy policy.
10.3. Return shall be effected by the provision of a machine-readable export in JSON format, keyed by Code, corresponding to the export available to the Client through the Services.
10.4. This Clause 10 shall not extend to aggregate statistical data referred to at Clause 2.2, nor to records which mindsparx retains as independent controller pursuant to that Clause. Any surviving records held against a Code identify no natural person once the Client has disposed of its code-to-identity mapping.
11. Audit
11.1. mindsparx shall make available to the Client all information necessary to demonstrate compliance with the obligations arising under Article 28 GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Client or by an auditor mandated by the Client.
11.2. The Client shall in the first instance have recourse to the documentation furnished by mindsparx, comprising this DPA, Annex B, the Sub-Processor list, and such third-party attestations of the Sub-Processors as are available.
11.3. Any on-site or hands-on audit shall be subject to not less than thirty (30) days' written notice, shall be conducted not more than once in any period of twelve (12) months, save following a Personal Data Breach affecting the Client's Candidates or where required by a competent supervisory authority, shall not compromise the confidentiality of the data of any other client or of the assessment content, and shall be conducted at the Client's cost.
12. Liability and Precedence
12.1. Liability arising under this DPA shall be subject to the exclusions and limitations set out in the Agreement, save to the extent that the GDPR does not permit such limitation, including in respect of the liability of either Party to a Data Subject under Article 82 GDPR.
12.2. Nothing in this DPA shall diminish the direct obligations of either Party under the GDPR.
13. Term, Governing Law and Jurisdiction
13.1. This DPA takes effect upon the commencement of the Agreement and shall continue for so long as mindsparx Processes Candidate Data on behalf of the Client, together with such further period as is required for the performance of Clause 10.
13.2. This DPA shall be governed by the law governing the Agreement, which shall be the law of a Member State of the European Union. In the absence of such a choice, this DPA shall be governed by the law of Romania.
Annex A: Particulars of the Processing
| Item | Particulars |
|---|---|
| Subject matter | The assessment of the Client's Candidates in respect of artificial intelligence data work upon the mindsparx platform |
| Duration | The term of the Agreement, together with the period contemplated by Clause 10 |
| Nature and purpose | The presentation of Assessments to Candidates identified by Codes assigned by the Client; the collection of responses; scoring against answer keys; the recording of assessment integrity signals; the enforcement of attempt limits and retest conditions; and the production of results, reports and certificates for the Client |
| Categories of Data Subjects | Candidates of the Client, being annotators, reviewers, transcribers and comparable contributors |
| Categories of Personal Data | Code assigned by the Client; Assessment responses, including free-text responses; scores and per-item outcomes; timing data; assessment integrity signals, comprising window focus duration, blocked copy operation counts, paste volume, and pointer and keyboard event counts, and excluding keystroke content; enquiries submitted to the in-Assessment assistant; certificate records; attempt records and records of items previously presented |
| Special categories of Personal Data | None intended or required. The Client shall instruct its Candidates not to include such data within free-text responses |
| Identifiability | mindsparx holds no name, email address or other contact detail of any Candidate. Candidate Data is pseudonymised by design, the Client retaining the sole code-to-identity mapping |
Annex B: Technical and Organisational Measures
mindsparx implements and maintains the following measures:
(a) storage of Candidate Data within the European Union, with encryption in transit by means of TLS and encryption at rest;
(b) row-level security enabled upon the database, with no public read policies, all access being effected server-side by means of service credentials which are never exposed to any browser;
(c) segregation of answer keys from all candidate-facing interfaces and from all third-party interfaces, scoring being performed server-side only;
(d) access by Candidates by means of cryptographically generated single-use tokens, one submission being permitted per token;
(e) passwordless authentication for administrative and Client access, no password being stored;
(f) pseudonymisation by design, Candidate records being held against Codes and not against identities;
(g) restriction of access to production data to those persons requiring such access for the provision of the Services;
(h) engagement of Sub-Processors only upon written contract in accordance with Clause 6, and publication and versioning of the Sub-Processor list;
(i) automatic erasure of detailed Assessment responses approximately thirty (30) days following the conclusion of an assessment run, and retention otherwise in accordance with the published retention schedule;
(j) procedures for the detection, documentation and notification of Personal Data Breaches in accordance with Clause 8, together with an internal breach register; and
(k) periodic review of the foregoing measures having regard to the state of the art.
Annex C: Authorised Sub-Processors
The current list is maintained at mindsparx.ai/subprocessors. As at the date of this version:
| Sub-Processor | Function | Location of Processing | Transfer mechanism |
|---|---|---|---|
| Supabase | Database and authentication infrastructure | European Union; support access may occur from the United States | Standard Contractual Clauses, or the EU-US Data Privacy Framework where certified |
| Vercel | Application hosting | European Union region; support access may occur from the United States | Standard Contractual Clauses, or the EU-US Data Privacy Framework where certified |
| Anthropic | Artificial intelligence processing in respect of the in-Assessment assistant | United States | Standard Contractual Clauses, or the EU-US Data Privacy Framework where certified |
| Resend | Transmission of transactional electronic mail | United States | Standard Contractual Clauses, or the EU-US Data Privacy Framework where certified |
Executed by the Parties as part of, and upon the date of, the Agreement.