Legal
Data Processing Addendum
A plain-language summary of ResumeCaliper's data-processing role, Art. 28 arrangements with service providers, and how to obtain related documents. This page complements the Privacy Policy; it is not a substitute for signed vendor contracts.
Last updated: 24 September 2026 (version 2026-09-24). Where this page is translated, the English version prevails in case of doubt, except where the law of your country requires otherwise.
1. Who this page is for
ResumeCaliper is a candidate-only product: individuals analyse their own CV against a job description. For that processing, Arseniy Rusentsov (the operator, established in Spain) is the data controller under the GDPR. End users are data subjects, not controllers who appoint ResumeCaliper as a processor for third-party CVs.
ResumeCaliper does not offer an employer/HR ranking product and does not process other people's CVs on a customer's instructions. A classic customer–processor DPA (controller → ResumeCaliper as processor) therefore does not apply to ordinary candidate accounts.
This page explains:
- the controller role toward users;
- that vendors who process personal data on the operator's instructions do so under GDPR Art. 28 arrangements;
- how to ask for copies of relevant safeguards;
- where the live list of processors appears.
2. Controller commitments toward users
As controller, the operator processes account, analysis and billing data as described in the Privacy Policy, including:
- lawful bases and purposes (contract, legal obligation, legitimate interests, consent where stated);
- retention and deletion (including Privacy & data export/delete in the app);
- security measures summarised in Privacy §10;
- international transfers with the safeguards in Privacy §8;
- rights under Arts. 15–22 and how to exercise them.
Nothing on this page reduces those rights or the operator's duties under the GDPR or Spanish LOPDGDD.
3. Processors (Art. 28)
The operator uses service providers who process personal data on the controller's instructions. For those relationships the operator:
- Uses only processors that provide sufficient guarantees (Art. 28(1)).
- Ensures processing is governed by a contract or other legal act with the Art. 28(3) content (or the vendor's standard DPA that meets those requirements).
- Remains responsible toward data subjects for choosing and instructing those processors.
- Publishes a current list on the Subprocessors page (aligned with Privacy §7).
Signing status. Acceptance of each vendor's click-through DPA / SCC pack in the vendor console, and retention of evidence, is an ops task. Until verified in the operator's records, treat signed status as pending — see also the internal vendors register. Public policy wording must stay accurate; do not treat this page as proof that a particular DPA is already on file.
4. Main processors (summary)
| Provider | Role toward ResumeCaliper | Typical data |
|---|---|---|
| OpenAI | Processor (AI scoring and generation) | Anonymised CV text, job description, notes, generated text |
| Google (Firebase Authentication) | Processor (account / sign-in) | E-mail, hashed password (email/password accounts), name/picture when provided, user ID, tokens |
| Contabo GmbH | Processor (hosting / storage) | Application, database and encrypted run files |
| Cloudflare | Processor (edge / security; country for price list) | IP, request metadata, edge country code |
| Stripe | Processor for checkout metadata; independent controller for payment instruments / fraud where Stripe says so | E-mail, amount, currency, package, Stripe session IDs — card numbers never touch ResumeCaliper |
| Google AdSense / optional analytics | Only after consent; advertising or analytics vendors under their terms | Ad/analytics identifiers — never CV content |
Full detail, locations and transfer tools: Privacy Policy §7–8 and Subprocessors.
5. International transfers
Where a processor processes outside the EEA, the operator relies on an EU adequacy decision (for example the EU–US Data Privacy Framework where the provider is certified) or Standard Contractual Clauses plus supplementary measures, as stated in the Privacy Policy. You may request information about the relevant safeguards at [email protected].
6. Requests for documents
Write to [email protected] (or use Contact) to:
- exercise GDPR rights;
- ask for a summary of the processor arrangements that apply to your data;
- ask whether a named vendor's DPA / SCCs have been accepted (subject to confidentiality and vendor terms).
The operator responds within the GDPR time limits (generally one month).
7. Changes
When processors change materially, the Subprocessors page and Privacy Policy are updated. The version date at the top of this page is updated when this Addendum changes.
8. Related documents
Arseniy Rusentsov — Placa Catalana 1, 1-4, 08032 Barcelona, Spain — NIF Z0402379E — [email protected] — Contact.