Legal · Last updated 10 August 2026
Data Processing Agreement
Data Processing Agreement (GDPR Art. 28) between the client agency as data controller and OpenLeadGraph as data processor — processing scope, security measures, subprocessors and breach handling.
1. Parties and roles
This Data Processing Agreement (“DPA”) forms part of the agreement between the client agency (“Controller”) and the provider of OpenLeadGraph (“Processor”), operated and hosted by DK Engineering Lab (https://www.dkenglab.com). It governs the processing of personal data stored in the client's workspace on the platform.
The Controller determines the purposes and means of processing candidate, contact and vacancy data. The Processor processes such data solely on the Controller's documented instructions, as required by Article 28 GDPR. This DPA takes effect together with the service agreement and lasts for its duration.
2. Subject matter and duration
The subject matter is the hosting and processing of the Controller's data within a dedicated, isolated workspace: lead records, candidate profiles, client contacts, vacancies, notes, housing records, invoices and related files. Processing continues for the duration of the subscription plus the 30-day export window after termination.
3. Nature and purpose of processing
Processing consists of storage, organization, retrieval, display, automated ranking and AI-assisted analysis (fit scoring, CV tailoring, in-product assistant answers), backup, export and deletion — performed exclusively to provide the contracted platform modules (lead discovery, CRM, matching, housing, finance) to the Controller.
The Processor does not use the Controller's data for its own purposes, does not sell it, and does not use it to train models for the benefit of other clients.
4. Categories of data subjects
- Candidates and workers whose profiles the Controller stores in the workspace.
- Contact persons of the Controller's clients and prospects (hiring companies).
- The Controller's own staff — users of the workspace (owners, recruiters, sales, administrators).
- Housing-related contacts: property owners, caretakers and building administrators recorded by the Controller.
5. Types of personal data
- Identification data: names, photos where uploaded, dates of birth where provided.
- Contact data: email addresses, phone numbers, locations.
- Professional data: CVs, work history, skills, rates, availability, languages.
- Assignment data: vacancy matching, pipeline stages, notes, housing assignments.
- Account data of the Controller's users: names, emails, roles, access logs.
- Financial records: invoice and payment information entered by the Controller.
Special categories of data (Art. 9 GDPR) are not intended to be processed. The Controller must not upload such data; if it does, it bears full controller responsibility for the lawfulness of that processing.
6. Processor obligations
The Processor undertakes to:
- Process personal data only on the Controller's documented instructions, including with regard to transfers, unless required otherwise by applicable law (in which case the Controller will be informed where legally possible).
- Ensure that all persons authorized to process the data are bound by confidentiality obligations.
- Implement and maintain the technical and organizational measures described in Section 7.
- Engage subprocessors only under Section 8, with full liability for their compliance.
- Assist the Controller, taking into account the nature of processing, in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection).
- Assist the Controller in ensuring compliance with security, breach-notification, impact-assessment and prior-consultation obligations under Articles 32–36 GDPR.
- Notify the Controller without undue delay after becoming aware of a personal data breach, per Section 10.
- At the end of the service, return or delete the data per Section 12.
- Make available the information necessary to demonstrate compliance with this DPA and allow audits per Section 11.
7. Technical and organizational measures
The platform is operated on DK Engineering Lab server infrastructure with the following measures:
- Tenant isolation: each client's data is logically separated; cross-tenant access is architecturally prevented.
- Encryption in transit: TLS for all client-facing and administrative connections.
- Encryption at rest: stored data and backups are encrypted on DK Engineering Lab infrastructure.
- Access control: per-user accounts with role-based permissions inside each workspace; least-privilege, individually attributable access for Processor staff.
- Backups: daily, encrypted, with documented and periodically tested restore procedures.
- Monitoring: 24/7 infrastructure monitoring and alerting; access and audit logging of administrative actions.
- Change management: updates are tested before production rollout; security patches applied on a prioritized schedule.
- Confidentiality: all staff and contractors with production access are bound by confidentiality agreements.
8. Subprocessors
The Controller authorizes the engagement of the following subprocessors:
- DK Engineering Lab — hosting, infrastructure and technical operation of the platform (https://www.dkenglab.com).
If a new subprocessor is to be engaged, the Controller will be notified by email at least 14 days in advance and may object on reasonable data-protection grounds. If an objection cannot be resolved, the Controller may terminate the affected service before the change takes effect. Email delivery of service notifications is performed through the mail infrastructure configured by the Processor.
9. International transfers
Data is stored and processed on DK Engineering Lab infrastructure. Any future transfer of personal data outside the European Economic Area will only occur under an adequacy decision or Standard Contractual Clauses, with prior notice to the Controller and an updated version of this DPA.
10. Data-subject requests and breach notification
- Data-subject requests received by the Processor are forwarded to the Controller without undue delay; the Processor assists the Controller in fulfilling them within statutory deadlines.
- In the event of a personal data breach affecting the Controller's data, the Processor notifies the Controller without undue delay after becoming aware of it, providing the information reasonably required for the Controller to meet its own 72-hour notification duty to the supervisory authority.
- The notification includes the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.
11. Audits and information
The Processor will respond to reasonable written security questionnaires and provide an annual summary of its technical and organizational measures. On-site inspections may be agreed where required by law or where questionnaire responses are insufficient, at the Controller's reasonable cost, with prior notice and under confidentiality.
12. Return and deletion of data
Upon termination, the Controller has 30 days to export workspace data using the platform's export functions or by requesting a machine-readable export (CSV/JSON plus documents) at hello@openleadgraph.com. After this period, the workspace data is deleted from production systems; residual copies in backups expire within the normal backup rotation cycle. Deletion can be confirmed in writing on request.
13. Liability
Liability under this DPA is subject to the limitation-of-liability provisions of the Terms of Service. Nothing in this DPA limits liability that cannot be limited under GDPR or other mandatory law.
14. Precedence and contact
In case of conflict between this DPA and the Terms of Service on data-protection matters, this DPA prevails. Data-protection notices and requests: hello@openleadgraph.com. This DPA is governed by the same law as the Terms of Service, with GDPR and applicable EU data-protection law always applying.