Legal
Data Processing Addendum
talentcost (Kliqer Holding B.V.) Standard SaaS Data Processing Addendum
Version 1.0 · Effective date: 21 July 2026 · GDPR Article 28
Parties
This DPA is issued by Kliqer Holding B.V., trading as talentcost, of Kliqer Holding B.V., Radarweg 29, 1043 NX Amsterdam, Netherlands (KVK: 95340629) ("talentcost", "Processor"). It applies, without any further signature or action required by either party, to every customer that accepts the talentcost Terms of Service and uses the Services in a manner involving talentcost's Processing of Personal Data on that customer's behalf (each, "Customer", "Controller"). talentcost and Customer are together the "Parties", each a "Party".
Customer acts as Controller of Personal Data submitted to or generated through the Services. talentcost acts as Processor, processing Personal Data solely on Customer's documented instructions and subject to this DPA. Where the UK GDPR or Swiss Federal Act on Data Protection applies, references to the GDPR include those equivalent regimes and their equivalent authorities.
1. Definitions
Terms below have the meaning given in the GDPR unless defined separately here.
| Term | Meaning |
|---|---|
| GDPR | Regulation (EU) 2016/679, including the UK GDPR where applicable. |
| Personal Data, Processing, Controller, Processor, Data Subject, Personal Data Breach | The meanings given in Article 4 GDPR. |
| Sub-processor | Any processor engaged by talentcost to process Personal Data on Customer's behalf. |
| SCCs | The Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914. |
| Services | The Scale API and associated dashboard, account, billing, and support features. |
2. Incorporation, Acceptance, and Updates
This DPA is a standard-form addendum published by talentcost. It is not individually negotiated or signed per Customer. It automatically forms part of the Agreement, and takes effect, on the earlier of: (a) Customer's acceptance of the talentcost Terms of Service, or (b) Customer's first use of the Services in a way that involves talentcost Processing Personal Data on Customer's behalf.
Each Party represents that the individual or system accepting the Agreement on its behalf has authority to bind that Party to this DPA.
talentcost may update this DPA from time to time, including to reflect changes in applicable data protection law, the Sub-processors listed in Annex III, or the Services. talentcost will notify Customer of material changes by email and/or a notice within the Services at least 7 days before the change takes effect. The version published at talentcost.com/dpa at the relevant time governs. Continued use of the Services after a change's effective date constitutes acceptance of the updated DPA.
A Customer that requires a bilaterally signed, individually negotiated version may request one by contacting legal@talentcost.com. talentcost may require additional or different terms for a bilaterally signed version, agreed in writing.
3. Scope and Roles
This DPA applies to talentcost's Processing of Personal Data on behalf of Customer in the course of providing the Services. The Parties agree that:
- Customer is the Controller (or, where Customer itself processes Personal Data on behalf of a third party, the Processor) of Personal Data submitted to or generated through the Services.
- talentcost is the Processor (or, in that second scenario, Sub-processor) with respect to that Personal Data.
- The details of the Processing, including subject matter, duration, nature and purpose, categories of Personal Data, and categories of Data Subjects, are set out in Annex I.
talentcost will Process Personal Data only for the purposes described in Annex I and the Agreement, and will not Process it for its own purposes, including for training or fine-tuning any machine learning or AI model, without Customer's prior written consent.
4. Processing on Instructions
talentcost will Process Personal Data only on Customer's documented instructions, including with regard to transfers of Personal Data to a third country, unless required to do otherwise by EU or EU Member State law to which talentcost is subject. In that case, talentcost will inform Customer of that legal requirement before Processing, unless the law prohibits this on important grounds of public interest.
The Agreement, this DPA, and Customer's use of the Services' documented API parameters and account configuration constitute Customer's complete initial instructions. Any additional or different instruction requires the Parties' written agreement, including as to any additional fees. talentcost will promptly inform Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
Customer represents and warrants that it has, and will maintain throughout the term of the Agreement, a lawful basis under GDPR for all Personal Data it submits to or generates through the Services, and that such Personal Data is accurate and was lawfully collected. talentcost is not responsible for the accuracy, completeness, or lawfulness of Personal Data supplied by Customer, and Processes it as received.
5. Confidentiality of Personnel
talentcost ensures that any person it authorises to Process Personal Data, including employees, contractors, and Sub-processor personnel, is subject to an appropriate obligation of confidentiality, whether contractual or statutory, and Processes Personal Data only as instructed.
6. Security of Processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to Data Subjects, talentcost implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. A summary of the measures in place at the date of this DPA is set out in Annex II.
talentcost may update its security measures from time to time provided that any change does not materially reduce the overall level of protection.
7. Sub-processors
Customer provides talentcost with general written authorisation to engage the Sub-processors listed in Annex III as of the date of this DPA.
talentcost will inform Customer of any intended addition or replacement of a Sub-processor, giving Customer the opportunity to object on reasonable data-protection grounds within 7 days of notice, failing which Customer is deemed to have approved the addition or replacement. If a timely objection cannot be resolved, talentcost will either take reasonable steps to address it or, if talentcost elects not to, Customer's sole remedy is to terminate the affected part of the Services on written notice; no refund, credit, or other compensation is owed for the terminated portion beyond what the Agreement otherwise provides.
talentcost imposes data protection obligations on each Sub-processor that are substantially equivalent to those in this DPA, by written contract, and remains liable to Customer for each Sub-processor's performance of those obligations.
8. Assistance with Data Subject Rights
Taking into account the nature of the Processing, talentcost assists Customer, insofar as reasonably possible, by appropriate technical and organisational measures, with fulfilling Customer's obligation to respond to requests from Data Subjects exercising their rights under Chapter III GDPR, including access, rectification, erasure, restriction, portability, and objection.
If talentcost receives a request directly from a Data Subject concerning Personal Data it Processes on Customer's behalf, talentcost will not respond directly other than to acknowledge receipt and will forward the request to Customer without undue delay.
Assistance under this Clause is provided through talentcost's standard account tools and support channels at no additional charge. Where Customer's request requires materially extensive or repeated non-standard engineering, legal, or manual effort beyond what those tools and channels provide, talentcost may charge Customer its reasonable costs of providing that additional assistance, quoted in advance.
9. Assistance with Compliance Obligations
Taking into account the nature of Processing and the information available to it, talentcost assists Customer in ensuring compliance with Customer's obligations under Articles 32 to 36 GDPR, including data security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
As with Clause 8, talentcost may charge Customer its reasonable costs of providing assistance under this Clause that is materially extensive or repeated, quoted in advance, except where the assistance directly concerns a Personal Data Breach caused by talentcost's own failure to comply with this DPA.
10. Personal Data Breach Notification
talentcost notifies Customer without undue delay, and in any event within 72 hours after talentcost confirms that a Personal Data Breach affecting Personal Data Processed on Customer's behalf has occurred, as distinct from a mere suspected incident or anomaly under initial investigation.
The notification describes, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where information is not available at the time of the initial notice, talentcost provides it in phases without undue further delay as it becomes available.
talentcost's notification of a breach is not, and must not be construed as, an admission of fault or liability. This notification obligation is subject to Clause 16 (Force Majeure).
11. International Transfers
Personal Data may be transferred to, and Processed in, countries outside the European Economic Area ("EEA") by the Sub-processors listed in Annex III. Where such a transfer takes place, talentcost ensures an appropriate safeguard under Chapter V GDPR applies, in particular:
- An adequacy decision of the European Commission under Article 45 GDPR in respect of the destination country.
- The SCCs, entered into between talentcost and the relevant Sub-processor, incorporating the appropriate module for the transfer.
The Parties acknowledge that the EU-U.S. Data Privacy Framework and comparable adequacy-style certification schemes remain subject to ongoing legal challenge before the Court of Justice of the European Union. talentcost's primary transfer safeguard for its U.S.-based Sub-processors is therefore the SCCs described above, rather than reliance on a certification scheme alone. talentcost will notify Customer of any material adverse development affecting the validity of its transfer mechanism and will work with Customer in good faith to implement a suitable alternative safeguard.
On request, talentcost provides Customer with a copy of the relevant SCCs or other transfer safeguard documentation.
12. Audits and Compliance Information
talentcost makes available to Customer, on reasonable written request and no more than once in any 12-month period, except following a Personal Data Breach or where required by a supervisory authority, the information reasonably necessary to demonstrate compliance with this DPA, which may include a summary of relevant third-party audit or certification reports where available.
Where a documentary review is insufficient, talentcost permits and contributes to an audit, including inspection, conducted by Customer or an independent auditor mandated by Customer, subject to: at least 45 days' written notice; execution during talentcost's normal business hours; a maximum duration of 1 business day; confidentiality undertakings from the auditor; and no access to data or systems of talentcost's other customers. talentcost may object to an auditor that is a competitor or otherwise unsuitable, or that is not bound by professional confidentiality obligations.
Customer bears its own costs and talentcost's reasonable costs of participating in the audit, invoiced in advance, unless the audit identifies a material breach of this DPA by talentcost, in which case talentcost bears its own costs and refunds any amount Customer prepaid toward talentcost's costs.
talentcost may, at its option, satisfy an audit request by providing a recent independent third-party audit, penetration-test summary, or certification report covering the relevant period and controls, where one exists and reasonably addresses the request, in place of an on-site or system-level inspection.
13. Return or Deletion of Personal Data
On termination or expiry of the Agreement, and at Customer's election, talentcost deletes or returns to Customer all Personal Data Processed on Customer's behalf, and deletes existing copies, within the retention periods described in talentcost's published Privacy Policy (currently up to 30 days following an account deletion request, or as otherwise required to wind down the Services), unless EU or Member State law requires talentcost to continue storing the Personal Data, in which case talentcost isolates it from further Processing except as required by that law.
14. Liability
This Clause limits the Parties' monetary exposure. It does not reduce, and is subject to, talentcost's substantive obligations under Clauses 3 to 13 of this DPA, which remain in full force regardless of the cap below.
Subject to the exclusions below, each Party's total aggregate liability to the other arising out of or in connection with this DPA, whether in contract, tort (including negligence), or otherwise, is limited to the greater of: (a) the total fees paid or payable by Customer under the Agreement in the 12 months preceding the event giving rise to the claim; or (b) €5,000. This cap applies in aggregate to all claims arising under this DPA in any 12-month period, and is separate from and does not stack with any cap in the Terms of Service.
Neither Party is liable to the other under this DPA for indirect, incidental, special, consequential, or punitive damages, or for loss of profits, revenue, goodwill, anticipated savings, or loss or corruption of data beyond the reasonable cost of restoring it from the most recent available backup, even if advised of the possibility.
This Clause states the Parties' sole and exclusive remedy, and talentcost's entire liability, for any claim arising out of or in connection with this DPA, in place of any other remedy in contract, tort, or otherwise, except as set out below.
Nothing in this DPA limits or excludes either Party's liability for death or personal injury caused by negligence; fraud or fraudulent misrepresentation; gross negligence or wilful misconduct; or any other liability that cannot lawfully be limited or excluded, including a Party's liability to a Data Subject or a supervisory authority for infringement of GDPR and talentcost's obligation under Clause 7 to remain liable to Customer for a Sub-processor's performance of its data protection obligations.
Neither Party may bring a claim arising out of or in connection with this DPA more than 12 months after the Party first became aware, or ought reasonably to have become aware, of the facts giving rise to that claim.
15. Indemnification
Customer indemnifies and holds talentcost harmless against third-party claims, damages, regulatory fines, and reasonable costs arising from: (a) Customer's breach of this DPA, including an instruction that Customer knew or ought reasonably to have known was unlawful; or (b) any Personal Data submitted by Customer that was inaccurate, unlawfully collected, or processed by Customer without a valid legal basis, including any breach of Customer's warranty in Clause 4.
talentcost indemnifies and holds Customer harmless against third-party claims and reasonable costs directly arising from talentcost's gross negligence or wilful misconduct in Processing Personal Data under this DPA.
Each Party's indemnification obligation under this Clause is subject to, and capped in accordance with, Clause 14 (Liability), except to the extent a claim falls within the carve-outs in that Clause that cannot lawfully be limited.
16. Force Majeure
Consistent with the talentcost Terms of Service, neither Party is liable for a failure or delay in performing its obligations under this DPA, including the notification timing in Clause 10, to the extent caused by circumstances beyond that Party's reasonable control, for example natural disasters, war, widespread internet or infrastructure outages, cyberattacks or other malicious third-party acts directed at talentcost or a Sub-processor, or regulatory actions, provided the affected Party uses reasonable efforts to mitigate the impact and resumes performance as soon as reasonably practicable.
Where a delay in talentcost's performance of a timing obligation under this DPA is itself caused by a Sub-processor's delay that falls within this Clause, that delay is likewise excused for talentcost, without affecting talentcost's continuing liability to Customer under Clause 7 for the Sub-processor's performance of its substantive data protection obligations.
17. Term
This DPA takes effect on the date Customer accepts the Agreement and continues for as long as talentcost Processes Personal Data on Customer's behalf under the Agreement, notwithstanding the expiry or termination of the Agreement until such Processing ends.
18. General
Precedence. In the event of a conflict between this DPA and the Agreement regarding the Processing of Personal Data, this DPA prevails.
Governing law and jurisdiction. This DPA is governed by the laws of the Netherlands and subject to the exclusive jurisdiction of the competent courts of Amsterdam, the Netherlands, without prejudice to a Data Subject's right to bring proceedings before their own competent court under GDPR.
Notices. Notices under this DPA are sent to talentcost at legal@talentcost.com (or such other address as talentcost notifies) and to Customer at the contact details on Customer's account.
Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force and effect, and the Parties replace the invalid provision with a valid one that most closely reflects its intent.
Assignment. Customer may not assign or transfer this DPA, in whole or in part, without talentcost's prior written consent, except to a successor in a merger, acquisition, or sale of substantially all its assets, provided the successor agrees in writing to be bound by this DPA. talentcost may assign or transfer this DPA in connection with a merger, acquisition, reorganisation, or sale of substantially all of the assets to which this DPA relates, provided the assignee agrees in writing to be bound by this DPA.
No waiver. A Party's failure to enforce any provision of this DPA is not a waiver of its right to do so later, and a waiver is only effective if made in writing.
Entire agreement. This DPA, together with the Agreement, is the entire agreement between the Parties regarding the Processing of Personal Data under the Services and supersedes any prior data processing terms between them on that subject.
Annex I: Details of Processing
A. Subject matter and duration
The subject matter of the Processing is talentcost's provision of the Scale API and related account, billing, and support features to Customer. The duration of the Processing is the term of the Agreement, plus any post-termination retention period described in Clause 13.
B. Nature and purpose of the Processing
- Receiving API requests containing salary, country, employment-period, and residency-status parameters, and returning calculated employer-cost and net-pay results.
- Authenticating API requests via hashed API keys and enforcing per-account rate and usage limits.
- Where Customer's users access the talentcost dashboard directly, account authentication, calculation history, CV analysis, and AI-assisted Q&A features.
- Billing and subscription management for Customer's account.
- Security monitoring, abuse prevention, and service reliability logging.
C. Categories of Data Subjects
- Customer's employees, prospective employees, contractors, or candidates, whose compensation or role data Customer submits through the Services.
- Individual users authorised by Customer to access the talentcost dashboard on Customer's behalf.
D. Categories of Personal Data
By design, the Scale API's documented request schema (country, salary amount, pay period, gross/net type, residency status) does not require directly identifying fields such as name, email address, or a national identifier. Personal Data may nonetheless arise if Customer chooses to include identifying information in optional or free-text fields, or if its own systems map API responses back to identified individuals.
Customer's dashboard users are identified by name and email address as part of their own talentcost account. Customer's use of the CV Analyser feature processes the content of an uploaded CV, which is likely to contain identifying and career-history data about a named individual.
talentcost does not intentionally process special category data under Article 9 GDPR, and Customer should not submit special category data through the Services unless the Parties separately agree appropriate additional safeguards.
Annex II: Technical and Organisational Security Measures
These measures are designed to provide a level of security appropriate to the risk in accordance with Article 32 GDPR; they reduce but cannot eliminate risk, and no security measure guarantees that a Personal Data Breach will not occur. Further detail on any measure in this table is available to Customer on reasonable request. talentcost's obligations in the event of a breach are set out in Clause 10, and the Parties' respective liability is set out in Clause 14.
| Measure | Description |
|---|---|
| Access control | API bearer tokens are used for API access. API keys are one-way hashed, never stored in plaintext, shown only once, and may be revoked at any time, with revocation effective within the stated service level. |
| Encryption in transit | All endpoints use HTTPS/TLS and HSTS with max-age 31536000, includeSubDomains, and preload. |
| Encryption at rest | Customer data is stored using hosting and database Sub-processors in accordance with their security documentation, available on request. |
| Data isolation | Data is scoped per account and Team organisation, with database row-level security rather than application checks alone. |
| Rate limiting and abuse prevention | Each API key is rate limited, with a coarse monthly request cap enforced server-side independently of the commercial allowance. |
| Logging and monitoring | Server and security logs, including IP address, request metadata, timestamps, and errors, are retained for 90 days and then purged. |
| Personnel confidentiality | Authorised personnel are subject to confidentiality obligations as described in Clause 5. |
| Subprocessor management | Sub-processors are managed in accordance with Clause 7 and Annex III. |
| Data minimisation | The API schema does not require directly identifying fields, as described in Annex I, Section D. |
| Business continuity | Business continuity relies on hosting and database Sub-processors' backup, retention, and disaster-recovery capabilities. talentcost has not independently formalised or tested separate recovery procedures. |
| Certifications | talentcost has not obtained independent SOC 2 or ISO 27001 certification. Individual Sub-processor certification status is available on their respective trust pages. |
Annex III: Authorised Sub-processors
As of the date of this DPA, talentcost engages the following Sub-processors. This list mirrors the Sub-processor table published in the Privacy Policy.
| Sub-processor | Service | Location | Transfer safeguard |
|---|---|---|---|
| Supabase, Inc. | Authentication, database storage | USA / EU (selectable region) | SCCs / adequacy where applicable |
| Stripe, Inc. | Payment processing, billing | USA / EU | SCCs / adequacy where applicable |
| Google LLC (Analytics) | Website analytics | USA | SCCs |
| Cloudflare, Inc. (Turnstile) | Bot and abuse protection | USA / EU | SCCs / adequacy where applicable |
| Resend, Inc. | Transactional email delivery | USA | SCCs |
| Groq, Inc. | AI language model inference for CV Analyser and AI Q&A | USA | SCCs |
| Render Services, Inc. | Calculation engine application hosting | USA | SCCs |
| Vercel, Inc. | Web application hosting and edge CDN | USA / EU (selectable) | SCCs / adequacy where applicable |
talentcost will update this Annex, and notify Customer, in line with Clause 7 whenever it adds or replaces a Sub-processor.