← Back to EDGE

DATA PROCESSING AGREEMENT

Last updated: 19 June 2026

Between EDGE (the “Processor”) and the Customer (the “Controller”) · UK GDPR / Data Protection Act 2018

This Data Processing Agreement (“DPA”) forms part of the agreement between EDGE, operated by USEEDGE LTD (company no. 17307416), registered in England & Wales (“EDGE”, “we”) and the customer that has accepted EDGE’s Terms of Service (“Customer”, “you”) (together the “Agreement”) and governs EDGE’s processing of personal data on the Customer’s behalf. Where this DPA conflicts with the Terms of Service on data protection, this DPA prevails.

1. Definitions

Terms not defined here have the meaning given in UK GDPR. “UK GDPR” means the UK General Data Protection Regulation and the Data Protection Act 2018. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Special Category Data” and “Processing” have the meanings in UK GDPR. “Customer Personal Data” means personal data EDGE processes on the Customer’s behalf under the Agreement. “Sub-processor” means a third party engaged by EDGE to process Customer Personal Data. “Candidate Data” means personal data relating to a job candidate that the Customer handles using the Candidate Screening features.

2. Roles of the parties

2.1 For Customer Personal Data, the Customer is the Controller and EDGE is the Processor.

2.2 For EDGE’s own account, billing and service-administration data, EDGE is a Controller in its own right, as described in EDGE’s Privacy Policy.

2.3 EDGE processes Customer Personal Data only on the Customer’s documented instructions, including those in the Agreement and this DPA, unless required otherwise by law (in which case EDGE will inform the Customer unless legally prohibited).

3. Scope and purpose of processing

3.1 The subject matter, nature, purpose, duration, types of personal data and categories of data subjects are set out in Annex 1.

3.2 EDGE will not process Customer Personal Data for any purpose other than performing the services, and will not sell Customer Personal Data or use it to train EDGE’s own models.

4. Candidate data (Candidate Screening features)

4.1 Roles. For Candidate Data, the Customer is the Controller and EDGE is the Processor.

4.2 On-device handling. The parties acknowledge that candidate CV content is processed and displayed within the Customer’s own browser and is not transmitted to, received by, or stored on EDGE’s systems or those of its Sub-processors. EDGE receives only role requirement labels, the Customer’s coverage assessments, and EDGE-generated screening questions. EDGE does not receive or process candidate CV content.

4.3 Customer warranties. The Customer warrants that, for all Candidate Data: (a) it has a valid lawful basis under Article 6 UK GDPR; (b) where the data includes Special Category Data (including where a CV contains such data, whether solicited or not), it has identified and can evidence a valid Article 9 UK GDPR condition and, where applicable, a Schedule 1 Data Protection Act 2018 condition with an Appropriate Policy Document; (c) it has given candidates the privacy information required by Articles 13–14; and (d) it will handle candidates’ data subject rights requests, EDGE having no candidate CV data.

4.4 Support. EDGE makes available the materials in its Controller Toolkit to support the Customer’s obligations; the Customer remains responsible for meeting them.

5. Confidentiality and security

5.1 EDGE ensures that persons authorised to process Customer Personal Data are bound by confidentiality.

5.2 EDGE implements appropriate technical and organisational measures as set out in Annex 3.

6. Sub-processors

6.1 The Customer provides general authorisation for EDGE to engage the Sub-processors listed in Annex 2.

6.2 EDGE imposes data protection obligations on each Sub-processor no less protective than those in this DPA, and remains liable for each Sub-processor’s performance.

6.3 EDGE will give advance notice of any intended addition or replacement of a Sub-processor, and the Customer may object on reasonable data protection grounds.

7. International transfers

7.1 Customer Personal Data in EDGE’s primary database is stored in the United Kingdom (London region).

7.2 Where EDGE or a Sub-processor transfers Customer Personal Data outside the UK, the transfer is made under an appropriate safeguard — the UK International Data Transfer Addendum, or the UK Addendum to the EU Standard Contractual Clauses — as recorded in Annex 2.

8. Assistance to the Customer

8.1 Taking into account the nature of the processing, EDGE assists the Customer in responding to data subject rights requests.

8.2 EDGE assists the Customer with its security, breach-notification, and data protection impact assessment obligations, taking into account the information available to EDGE.

9. Personal data breach

9.1 EDGE notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provides information to help the Customer meet its own obligations.

9.2 For data where the Customer is Controller (including prospect and Candidate Data), the Customer is responsible for notifying the ICO and affected data subjects where required; EDGE supports this. For EDGE’s own controller data, EDGE notifies directly. EDGE maintains a breach response process consistent with the 72-hour standard.

10. Return and deletion

10.1 On termination, and at the Customer’s choice, EDGE deletes or returns Customer Personal Data, unless retention is required by law.

10.2 EDGE applies a default 12-month retention period to transcript-derived Customer Personal Data, with automated deletion, and provides a right-to-erasure tool covering calls, briefs, reports and post-call packs.

11. Audit

11.1 EDGE makes available information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, subject to reasonable confidentiality and frequency limits.

12. General

12.1 Governed by the laws of England and Wales.

12.2 If any provision is unenforceable, the remainder continues.

12.3 This DPA takes effect on the Customer’s acceptance of the Agreement and continues for as long as EDGE processes Customer Personal Data.

Annex 1 — Details of processing

Subject matterProvision of EDGE’s AI sales co-pilot and candidate-screening features.
DurationTerm of the Agreement plus the retention periods in clause 10.
Nature & purposeTranscription and analysis of BD calls; generation of briefs, analyses, post-call packs; generation of candidate screening questions from Customer-supplied requirements and statuses.
Types of personal dataRecruiter account data; prospect data within BD-call transcripts (names, roles, employers, statements); for candidate screening, role labels and Customer statuses only — no candidate CV content reaches EDGE.
Special category dataNot intentionally processed by EDGE. Candidate CV content (which may contain such data) is not transmitted to EDGE. Incidental content in BD-call transcripts is retention-bounded and subject to erasure.
Categories of data subjectsRecruiter users; prospects (hiring managers); candidates (CV handled on-device by the Customer, not by EDGE).

Annex 2 — Sub-processors

Sub-processorServiceDataTransfer mechanismLocation
SupabaseAuth & databaseAccount + prospect dataUK Addendum on EU SCCs (data resident UK)UK (London)
AnthropicAI analysis & screening questionsTranscript-derived text; labels + statuses onlyUK Addendum to SCCsUS
DeepgramTranscriptionAudio to transcriptEU SCCs (2021/914) with UK Addendum (ICO IDTA, 21 Mar 2022) — per executed Deepgram DPAUS
StripePaymentsBilling dataUK IDTAUS/global
ResendEmailRecruiter emailUK SCCs (EU SCCs + UK Addendum)US
VercelHostingApp trafficUK IDTAUS/global

The current list of sub-processors is published at /subprocessors.

Annex 3 — Technical and organisational measures

Access controlRow-level security isolating each customer’s data; authenticated access only.
EncryptionData encrypted at rest and in transit.
Data minimisationTranscripts only (audio not persisted); ephemeral AI inputs; candidate CV never transmitted to EDGE; covered requirements not sent to the AI.
Retention12-month automated deletion of transcript-derived data; right-to-erasure tooling.
Client-side handlingCandidate CV held in tab-scoped browser storage, wiped on generation, reset and tab close.
Integrity controlsStrict server validation rejecting CV content in screening requests; automated tests guarding the contract.
Sub-processor governanceDPAs with all Sub-processors; UK transfer mechanisms; published sub-processor list.

Questions about this DPA? Contact us at info@useedge.co.uk. See also our Terms of Service and Privacy Policy.