Data Processing Agreement
Appendix to the Terms and Conditions of the Bulgaria Wants You Platform
Parties
1. DNA MEDIA AD, UIC 205882707, hereinafter referred to as the "OPERATOR", with its registered office and management address at Floor 3, 22 Galichitsa Street, Lozenets District, Sofia 1164, represented by Andrey Vasilev Arnaudov, Executive Director, operator of the bulgariawantsyou.com platform (the "Platform").
2. Any legal entity, sole trader or other legal organisation that has registered a corporate Profile on the Platform and accepted this Agreement in accordance with Clause 3. The Employer shall be identified by the name, UIC/BULSTAT (or foreign registration and/or VAT number, as applicable), registered office and management address, representative and contact details entered in its corporate Profile and included in the record under Clause 3.2, hereinafter referred to as the "EMPLOYER".
3. The Operator and the Employer are each referred to as a "Party" and together as the "Parties".
Section I. Subject Matter, Acceptance and Definitions
1. Subject Matter
1.1. This Agreement governs the processing of personal data in connection with the use of the Platform's services and sets out the rights and obligations of the Parties pursuant to Article 28 of Regulation (EU) 2016/679 (the "Regulation").
1.2. The Agreement forms an integral part of the Platform's Terms and Conditions for Employers and of each subscription or individual service agreement between the Parties (collectively, the "Main Agreement").
1.3. The designations "Operator" and "Employer" identify the parties to the Agreement and not their respective capacities within the meaning of the Regulation. The capacity in which each Party acts - as controller or processor - is determined separately for each group of operations in Section II and is not affected by the designations used elsewhere in this document.
2. Definitions
2.1. The terms defined in Article 4 of the Regulation shall have the meanings given to them in the Regulation. The terms "Talent", "Advertisement", "Application", "Profile", "Platform" and "Website" shall have the meanings given to them in the Terms and Conditions.
2.2. "Candidate" means a Talent who has submitted an Application for an Employer's Advertisement, as well as a person whose data have been made available to the Employer through the Platform in the context of a specific recruitment procedure.
3. Acceptance and Evidence
3.1. The Agreement is concluded electronically in accordance with the Electronic Document and Electronic Trust Services Act by ticking the box "I accept the Data Processing Agreement" when registering a corporate Profile or when ordering or paying for a service. Ticking the box constitutes an electronic statement by which the Employer accepts the Agreement and its Appendices in full.
3.2. For each acceptance, the Operator creates and retains an electronic record containing: the identifiers of the corporate Profile and user; the name and email address of the person accepting; the date and time (UTC); the IP address; and the version number and checksum (hash) of the text accepted. The record shall be retained for the term of the Main Agreement and five (5) years after its termination and shall be provided to the Employer upon written request.
3.3. The person accepting declares that they have representative authority to bind the Employer. The current version is permanently published at bulgariawantsyou.com/en/data-processing-agreement; the Operator maintains an archive of previous versions and provides the applicable version upon request.
Section II. Roles of the Parties
4. Operator as Independent Controller
4.1. The Operator acts as an independent controller of personal data and does not process data on the Employer's instructions in respect of:
registration, maintenance and closure of Talents' Profiles and the data contained in them;
creation, management and erasure of the database of Talents' Profiles (the "Talent Database");
visibility modes and the rules under which Talents' data are displayed to employers;
ranking, matching and recommendation algorithms;
notifications, reminders and newsletters sent to Talents;
aggregated and anonymised statistics, including the Talent Pool functionality;
security, access logs, moderation and prevention of misuse;
analysis of user behaviour on the Website and management of cookie consents;
registration and administration of corporate Profiles and sub-accounts, verification of the Employer, invoicing and accounting;
organisation of events and forwarding of enquiries in the "Real Estate" section.
4.2. In respect of the processing under Clause 4.1, the Operator independently determines the purposes and means, including retention periods and categories of recipients, and bears independent responsibility towards data subjects. The information under Articles 13 and 14 of the Regulation is provided through the Platform's Privacy Policy.
5. Employer as Independent Controller
5.1. The Employer acts as an independent controller of personal data in respect of:
its own recruitment process - screening, assessment, invitations to interview, rejection and hiring;
all personal data it has downloaded, exported or reproduced outside the Platform;
data to which it has obtained access through the Profile access and Talent search functionalities, from the time of access;
communications it conducts with Candidates outside the Platform;
subsequent management of the data of persons hired by it.
5.2. The Employer shall provide data subjects with the information under Articles 13 and 14 of the Regulation concerning its own processing and enable them to exercise their rights against the Employer.
6. Operator as Processor
6.1. The Operator acts as a processor of personal data on behalf of the Employer solely in respect of the operations exhaustively described in Appendix 1. Any operation outside Appendix 1 shall not constitute processing under this Agreement.
6.2. The Operator shall not use personal data processed under this Agreement for its own purposes.
7. Separation of Roles; No Joint Controllership
7.1. The Parties do not jointly determine the purposes and means of processing relating to the Talent Database. The Employer does not participate in its creation, population or structuring; Profiles are created and maintained by Talents themselves, and visibility decisions are made by the Talent through functionalities provided by the Operator.
7.2. Providing access to Talents' Profiles constitutes disclosure of data by the Operator in its capacity as controller to the Employer as an independent recipient. From the time of access, the Employer processes those data on its own legal basis and for its own purposes.
7.3. If a competent supervisory authority or court determines that the Parties act as joint controllers in respect of certain processing, they undertake within a reasonable period to enter into an arrangement pursuant to Article 26(1) of the Regulation and make the essence of that arrangement available to data subjects.
Section III. Employer's Instructions
8. Scope of Instructions
8.1. The Operator shall process personal data only on the Employer's documented instructions. The instructions are contained in: this Agreement and Appendix 1; the Terms and Conditions and the services ordered and paid for; the Employer's settings, configurations and actions in the corporate Profile, including publishing and editing Advertisements, assigning Application statuses, specifying filtering and sorting criteria, exporting, erasing and granting access to sub-accounts; and subsequent written instructions.
8.2. The Employer may amend the instructions by written notice. Where implementation requires technical modifications to the Platform or entails material additional costs, the Operator shall be entitled to refuse implementation or make it subject to additional remuneration, provided that it gives notice within ten (10) business days. In the event of refusal, the Employer shall be entitled to terminate the Main Agreement in respect of the affected services without penalty.
8.3. The Operator shall immediately inform the Employer if, in its opinion, an instruction infringes the Regulation or another applicable provision, and shall be entitled to suspend its implementation until the instruction is confirmed or amended in writing.
9. Special Categories of Data and Prohibited Practices
9.1. The Platform does not request or envisage the processing of personal data under Article 9(1) of the Regulation. The Employer undertakes not to use the functionalities to intentionally collect, search, filter or assess by reference to such data and not to request from Candidates through the Platform a Bulgarian Personal Number, identity document number or bank details.
9.2. Where a Candidate voluntarily includes data under Article 9(1) in documents uploaded by them, the Employer's instruction is limited to storing and displaying those data unchanged, without indexing, extraction, profiling or use as a recruitment criterion.
9.3. The Employer shall not specify criteria, requirements or instructions that result in direct or indirect discrimination. The Operator shall not be liable for recruitment practices arising from criteria specified by the Employer and shall be entitled to refuse to implement such instructions and remove the relevant content in accordance with the Terms and Conditions.
10. Prohibition on Use for Own Purposes; Retention Periods
10.1. The Operator shall not use personal data under this Agreement to develop, train, test, evaluate or validate artificial intelligence models or systems, except on the Employer's explicit prior written instruction.
10.2. The Operator shall be entitled to irreversibly anonymise the data and use the resulting anonymous and aggregated data. Anonymous data do not constitute personal data and fall outside the scope of the Agreement.
10.3. The Employer accepts as its instruction the periods specified in the Terms and Conditions: access to Applications and the documents attached to them shall end when the relevant Advertisement expires or is removed or archived, as applicable. The Employer may at any time specify a shorter period or erase specific Applications through its Profile functionalities.
Section IV. Obligations of the Operator
11. Confidentiality and Security
11.1. Access to personal data shall be limited to persons who require it on a need-to-know basis and who have undertaken a written confidentiality obligation or are subject to an appropriate statutory duty of confidentiality that continues after the termination of their relationship with the Operator.
11.2. The Operator shall implement the technical and organisational measures under Article 32 of the Regulation described in Appendix 2 and review them at least annually and after every material modification of the Platform. Amendment of Appendix 2 shall not require the Employer's consent, provided that the level of protection is not reduced.
12. Personal Data Breaches
12.1. The Operator shall notify the Employer without undue delay and no later than forty-eight (48) hours after becoming aware of a personal data breach affecting personal data under this Agreement, by email to the address specified in the corporate Profile and by a message on the Platform.
12.2. To the extent that the information is available, the notification shall describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken and proposed, and contact details. Where complete information is unavailable, it shall be provided in phases without further undue delay.
12.3. The Operator shall document each breach and assist with compliance with the obligations under Articles 33 and 34 of the Regulation. The Operator shall not notify the supervisory authority or data subjects on behalf of the Employer except on explicit written instruction or where it is required to do so in its own capacity as controller.
13. Rights of Data Subjects
13.1. The Operator shall assist the Employer through appropriate technical and organisational measures, including functionalities for access, rectification, export and erasure in the corporate Profile.
13.2. A request relating to processing under this Agreement shall be forwarded to the Employer within three (3) business days; the Operator shall not independently respond to the substance of the request without the Employer's written instructions.
13.3. Clause 13.2 shall not apply where the request relates to processing under Clause 4.1. In such cases, the Operator shall respond independently in its capacity as controller and, where necessary, inform the Employer.
13.4. Assistance shall be provided free of charge to a reasonable extent. In the event of recurrent, excessive or manifestly unfounded requests, the Operator shall be entitled, upon prior notice, to remuneration for the costs actually incurred.
14. Assistance, Records and Audits
14.1. The Operator shall assist the Employer in ensuring compliance with the obligations under Articles 32 to 36 of the Regulation, taking into account the nature of the processing and the information available to it, and shall maintain records under Article 30(2) of the Regulation, which it shall provide to the Employer or supervisory authority upon request.
14.2. The Operator shall make available the information necessary to demonstrate compliance with the obligations under Article 28 of the Regulation and shall allow for audits, including on-site inspections, subject to the following conditions: at least fifteen (15) business days' prior written notice; no more than one audit in any twelve (12)-month period, unless a personal data breach affecting the Employer has occurred or a supervisory authority has ordered otherwise; conduct during normal business hours without disrupting ordinary business operations; the auditor is not a competitor of the Operator and is bound by confidentiality; and the audit does not cover other clients' data, trade secrets or source code elements.
14.3. The costs of an audit shall be borne by the Employer unless a material breach by the Operator is established.
14.4. In respect of sub-processors providing cloud, hosting and infrastructure services, the obligation under Clause 14.2 shall be fulfilled by providing current certificates (e.g. ISO/IEC 27001) or reports from independent auditors (e.g. SOC 1 / SOC 2).
15. Erasure and Return of Data
15.1. Upon termination of the Main Agreement, the Operator shall, at the Employer's choice notified within thirty (30) days of termination, return the personal data in a structured, commonly used and machine-readable format or erase them together with existing copies. If the Employer does not notify its choice, the data shall be erased.
15.2. The Operator shall be entitled to retain data to the extent and for as long as European Union law or the law of the Republic of Bulgaria requires their retention, provided that processing is restricted to the purpose of retention.
15.3. Erasure from backups shall take place in accordance with the retention cycle, but no later than ninety (90) days. At the Employer's request, the Operator shall issue written confirmation that the erasure has been completed.
Section V. Sub-processors
16. Engagement, Objections and Liability
16.1. By accepting the Agreement, the Employer grants general written authorisation under Article 28(2) of the Regulation for the engagement of the sub-processors listed in Appendix 3.
16.2. The Operator shall inform the Employer of any intended change concerning the addition or replacement of a sub-processor at least fifteen (15) days in advance, by email to the address in the corporate Profile and by a message on the Platform. The Employer shall be entitled to submit a reasoned written objection within ten (10) business days; in the absence of an objection, the change shall be deemed approved.
16.3. In the event of a reasoned objection, the Parties shall make good-faith efforts to find a solution. If no solution is reached within twenty (20) business days, the Employer shall be entitled to terminate the affected part of the Main Agreement and receive a refund of the amount prepaid for the unused period. The objection shall not give rise to any other rights or claims.
16.4. The Operator shall be entitled to engage a new sub-processor immediately where necessary to address an imminent security risk or ensure continuity of the service, provided that it informs the Employer without delay.
16.5. The Operator shall enter into a written agreement with each sub-processor imposing the same data protection obligations and shall remain fully liable to the Employer for the performance of those obligations pursuant to Article 28(4) of the Regulation.
16.6. The Operator shall prevent user behaviour analytics tools (session recordings, heatmaps and similar tools) from collecting data from pages on which Applications, CVs, attached documents and messages are displayed.
Section VI. International Data Transfers
17. Transfers to Third Countries
17.1. Personal data under this Agreement shall be stored and processed within the European Union and the European Economic Area.
17.2. The Operator shall not transfer personal data to a third country or international organisation except on the Employer's documented instructions or where required to do so by European Union or Member State law; in the latter case, it shall inform the Employer before processing unless such information is prohibited on important grounds of public interest.
17.3. In the event of a transfer, the Operator shall provide appropriate safeguards under Chapter V of the Regulation, including an adequacy decision, Standard Contractual Clauses or another mechanism under Article 46, together with supplementary technical and organisational measures where necessary. If an adequacy decision is repealed, suspended or declared invalid, the Operator shall without delay switch to another mechanism under Article 46 or discontinue the transfer.
Section VII. Obligations of the Employer
18. Obligations
18.1. The Employer shall be responsible for ensuring a valid legal basis under Article 6 or, as applicable, Article 9 of the Regulation for the data it processes through the Platform.
18.2. The Employer shall provide the Operator with a current hyperlink to its own privacy policy for job applicants, which the Operator shall publish in the Employer's Advertisements. If the Employer fails to provide it, the Employer shall bear sole responsibility for non-compliance with its obligations under Articles 13 and 14 of the Regulation.
18.3. The Employer shall provide true, accurate and current information in the corporate Profile and Advertisements; grant access to the Profile and sub-accounts only to persons who require it and revoke access immediately when it is no longer required; maintain the confidentiality of access credentials; and notify the Operator without undue delay if unauthorised access is suspected.
18.4. The Employer shall bear sole responsibility, as controller, for the lawful processing, retention and erasure of all data downloaded outside the Platform and may not create its own Talent database by exporting, copying or reusing information obtained through the Platform outside the specific recruitment procedure.
18.5. Where the Employer processes through the Platform data from or on behalf of its subsidiaries, it warrants that the appropriate legal bases are in place and that it has regulated the data protection relationship with those subsidiaries.
Section VIII. Automated Processing and Artificial Intelligence
19. Current Status and Future Functionalities
19.1. As at the effective date of the Agreement, the Platform does not use artificial intelligence systems within the meaning of Article 3(1) of Regulation (EU) 2024/1689. Ranking and matching are carried out through deterministic algorithms with predefined rules and weights. The processing constitutes profiling under Article 4(4) of the Regulation but does not constitute automated decision-making under Article 22; the final decision whether to review an application, invite a candidate to an interview, reject or hire a candidate is made entirely by a natural person acting for the Employer.
19.2. Before activating artificial-intelligence-based functionalities, the Operator shall update the Agreement, Appendix 1 and the Privacy Policy, inform the Employer in accordance with Article 3(2) of Regulation (EU) 2019/1150, and provide information on the intended purpose, logic, limitations and human oversight measures.
19.3. Artificial intelligence systems used for filtering applications, evaluating candidates and targeted publication of job advertisements are classified as high-risk under Annex III, point 4 of Regulation (EU) 2024/1689. Upon their introduction, the Operator shall act as provider and the Employer as deployer. The Employer undertakes to use them in accordance with their instructions for use, assign human oversight to a competent person, ensure relevant and sufficiently representative input data, inform affected workers and their representatives in advance, and inform affected natural persons. The Employer shall bear sole responsibility for the criteria and instructions it enters.
Section IX. Liability
20. Liability and Indemnification
20.1. Each Party shall be liable for damage caused by processing that infringes the Regulation or this Agreement in accordance with Article 82 of the Regulation. The Operator shall be liable only where it has failed to comply with obligations under the Regulation specifically directed to processors or where it has acted outside or contrary to the Employer's lawful instructions.
20.2. The Operator's aggregate liability to the Employer for all claims under this Agreement shall be limited to the total fees actually paid under the Main Agreement during the twelve (12) months preceding the event giving rise to the damage. The limitation shall not apply in the event of wilful misconduct or gross negligence.
20.3. The limitation under Clause 20.2 applies only between the Parties and does not affect data subjects' rights under Article 82 of the Regulation or the powers of supervisory authorities. The limitations of liability in the Terms and Conditions shall apply to all other claims.
20.4. The Employer shall indemnify the Operator against loss, damage, financial penalties, costs and third-party claims arising from processing on its instructions without a valid legal basis, non-compliance with its obligations under Section VII, discriminatory or unlawful recruitment criteria entered by it, or false information provided by it.
Section X. Term, Amendment and Final Provisions
21. Final Provisions
21.1. The Agreement shall enter into force upon the electronic statement under Clause 3.1 and remain in effect for the term of the Main Agreement. Following termination, Clause 11.1, Clause 15, Section IX and Clause 21.4 shall remain in effect.
21.2. In the event of any conflict between the Agreement and the Terms and Conditions or any other part of the Main Agreement concerning the protection of personal data, the Agreement shall prevail.
21.3. The Operator shall be entitled to amend the Agreement by informing the Employer on a durable medium at least fifteen (15) days before the amendment takes effect in accordance with Article 3(2) of Regulation (EU) 2019/1150; the amendment shall not apply before the expiry of that period. During that period, the Employer shall be entitled to terminate the Main Agreement without penalty and receive a refund of the amount prepaid for the unused period. Continued use after expiry of the period constitutes acceptance. The period shall not apply where the amendment is necessary to comply with a legal obligation or an order of a competent authority.
21.4. The laws of the Republic of Bulgaria shall apply. Disputes shall be resolved through negotiations or, if no agreement is reached, by the competent court in Sofia.
21.5. The invalidity of an individual provision shall not affect the validity of the Agreement. The Agreement has been drawn up in Bulgarian and English; in the event of any conflict, the Bulgarian text shall prevail.
21.6. Appendix 1 (Description of Processing), Appendix 2 (Technical and Organisational Measures) and Appendix 3 (Sub-processors) form an integral part of the Agreement.
22. Data Protection Contact Details
Party | Contact Person | Contact Details |
Employer | The person specified in the corporate Profile | The email address and telephone number in the corporate Profile |
Operator | Data Protection Officer | Floor 3, 22 Galichitsa Street, Sofia 1164; [email protected] |
The Agreement is concluded electronically by acceptance on the Platform and does not require a signature.
Appendix 1 - Description of Processing
The Operator shall perform the operations listed below on behalf of and on the instructions of the Employer, solely within the Platform's functionalities and the services ordered and paid for.
1. Operations
1. Publication and Maintenance of Advertisements - receiving, moderating, publishing, editing, suspending, renewing and archiving the Employer's Advertisements, including displaying the contact details of the persons specified by it.
2. Receipt, Storage and Display of Applications - receiving Applications submitted for Advertisements and the documents attached to them; storing them in the Platform environment; displaying them in the corporate Profile; tracking Application statuses; and maintaining a history of Applications for the Employer's Advertisements.
3. Communication with Candidates - transmitting, storing and displaying messages between the Employer and Candidates through the internal messaging system in the context of a specific Application or Advertisement. The Operator remains controller in respect of the technical operation of the system, moderation and prevention of misuse.
4. Export and Erasure - providing functionalities for downloading, exporting and erasing Applications and related documents.
5. Forwarding to an External System (where ordered) - automatically forwarding Applications to an applicant tracking system, email address or application programming interface endpoint specified by the Employer.
6. Filtering and Sorting by Employer Criteria (where ordered) - applying criteria specified by the Employer to Applications received. The operation serves an assistive function and does not result in automated decision-making producing legal or similarly significant effects.
Outside the Scope: the operations under Clause 4.1 of the Agreement, in respect of which the Operator acts as an independent controller.
2. Purpose
Enabling the Employer to publish vacant positions, receive, review and manage Applications, and communicate with Candidates for the purposes of its own recruitment procedure.
3. Duration
Until the earliest of: expiry of the relevant Advertisement or its removal or archiving, as applicable, in respect of access to Applications and attached documents; erasure on the Employer's instruction; or termination of the Main Agreement, after which Clause 15 of the Agreement shall apply.
4. Categories of Data Subjects
Candidates - Talents who have submitted an Application for an Employer's Advertisement; contact persons specified by the Employer in Advertisements.
5. Categories of Personal Data
For Candidates: names; contact details (email address, telephone number and location); Profile photograph; education, professional experience, qualifications, skills and language proficiency; content of CVs, diplomas, certificates and other attached documents; Application data (Advertisement, date and time, status, and notes and assessments entered by the Employer); content of messages exchanged; and, where functionalities are enabled, filtering and sorting results.
For Contact Persons: names, position, business email address and telephone number.
Special Categories: not intentionally collected; Clause 9 of the Agreement shall apply to data voluntarily included by Candidates.
Expressly Excluded: Bulgarian Personal Number, identity document number, and Candidates' bank and payment details.
Appendix 2 - Technical and Organisational Measures
The Operator implements and maintains the measures set out below pursuant to Article 32 of the Regulation, independently and through its sub-processors.
I. Encryption and Pseudonymisation
encryption of data in transit (TLS using a current version and configuration) and at rest, including backups;
storage of passwords using a salted one-way cryptographic function;
pseudonymisation of identifiers and a prohibition on the use of real personal data in development and testing environments.
II. Access Control
individual user Profiles without shared identifiers;
multi-factor authentication for administrative access to the production environment;
permissions granted on the principle of least privilege and subject to explicit approval;
periodic review of permissions at least once every six months and immediate revocation when the legal basis or need ceases to apply;
separation of development, testing and production environments.
III. Infrastructure and Application Security
network firewalls and application-level protection; restriction of administrative access;
secure remote access with multi-factor authentication;
malware protection and anti-spam filtering of corporate email;
vulnerability management, including periodic scanning and timely security updates;
penetration testing at least annually and after material modifications;
a secure development process in accordance with good practice, code review and change control.
IV. Availability, Logging and Monitoring
regular backups, with periodic recovery testing and defined recovery time and recovery point objectives;
infrastructure redundancy at cloud service provider level;
logs of access to the system and personal data, protected against unauthorised alteration;
monitoring and logging of security incidents.
V. Organisational Measures
internal rules for the processing and protection of personal data, reviewed at least annually;
a documented procedure for managing incidents and personal data breaches, including notification periods;
confidentiality obligations for personnel and contractors, and regular training;
a procedure for selecting and periodically assessing sub-processors;
control of physical access to offices and information media; a secure destruction procedure.
VI. Data Protection by Design
collection only of data necessary for the relevant functionality;
default settings that restrict the visibility of Talents' Profiles;
exclusion of pages containing Applications, CVs and messages from user behaviour analytics tools;
automatic termination of access to Applications upon expiry of the applicable period.
Appendix 3 - Sub-processors
A. Sub-processors under this Agreement
No. | Sub-processor | Registered Office / Country | Activity |
1 | BULKOD 2016 OOD | Sofia, Bulgaria | Software development, technical support and administration of the Platform |
2 | Amazon Web Services EMEA SARL | Luxembourg (EU) | Cloud hosting infrastructure and data storage in regions within the EU |
B. Providers Used by the Operator as an Independent Controller
The providers listed below do not process personal data on behalf of the Employer and are not sub-processors under this Agreement. The list is provided for information; details are set out in the Privacy Policy.
No. | Provider | Registered Office / Country | Activity |
1 | Stripe Payments Europe, Ltd. / Stripe, Inc. | Ireland / USA | Payment processing and issuance of electronic invoices |
2 | Cybot A/S (Cookiebot) - consent management platform | Denmark (EU) | Management and auditing of cookie consents |
3 | Hotjar Ltd. | Malta (EU) | Analysis of user behaviour on the Website (disabled for the pages referred to in Clause 16.6) |
4 | Google Ireland Ltd. / Google LLC | Ireland / USA | Web analytics and sign-in through an existing account |
5 | Meta Platforms Ireland Ltd. | Ireland | Sign-in through an existing account |