Last updated: 17-08-2026
Applyfin B.V., a private limited liability company under Dutch law, having its registered office in Utrecht and its place of business at Wittevrouwenstraat 38B, 3512 CV Utrecht, the Netherlands, registered in the trade register of the Chamber of Commerce under number 92570968 (hereinafter: Applyfin), is a combined Recruitment Process Outsourcing (RPO) and ATS service provider.
Applyfin operates a multi-tenant SaaS Applicant Tracking System with which employers manage their recruitment and selection process, and in addition carries out, in whole or in part, recruitment and selection activities on behalf of its clients. In providing the Platform and the associated services, Applyfin processes personal data on behalf of those clients. This data processing agreement sets out the conditions under which that takes place, as prescribed by Article 28(3) GDPR.
1.1 This data processing agreement (hereinafter: Data Processing Agreement) applies to:
all personal data that Applyfin processes within the Client’s Company, including data of applicants, shortlisted candidates, referees, talent pool participants and Users;
the searches and screenings that Applyfin carries out with the Data Supplier on the Client’s instructions, and the temporary storage of the results thereof;
the career pages that Applyfin hosts on behalf of the Client, including the processing operations that take place in that context in respect of visitors;
the managed delivery (RPO) and the add-ons purchased by the Client, including recruitment activities that Applyfin staff carry out on behalf of the Client.
1.2 Applyfin uses three interrelated documents:
The general terms and conditions govern the commercial and usage arrangements between the Client and Applyfin: packages, rates, term, liability and termination.
This Data Processing Agreement governs the processing of personal data. It is an Annex to the general terms and conditions and is concluded at the same time.
The Privacy and Information Security Policy explains to data subjects how Applyfin handles their data, and further sets out the security measures and the AI governance.
1.3 The division of roles between the Parties is delineated in Article 4.
1.4 In the event of conflict, this Data Processing Agreement prevails over all other documents forming part of the Agreement, including the Quotation and the SLA, exclusively insofar as the protection of personal data is concerned (Article 4.3 of the general terms and conditions). For all other matters, the order of precedence in Article 4.2 of the general terms and conditions applies.
1.5 The Privacy and Information Security Policy serves as a further elaboration of this Data Processing Agreement. References in this document to sections thereof are intended as an elaboration and not as a limitation of the obligations laid down here.
2.1 Terms written with a capital letter in this Data Processing Agreement — including Balance, Annexes, Company, Consent functionality, Credit, Data Supplier, User, Job Slot, Client, Quotation, Agreement, Package, Parties, Platform, Pricing Page, Privacy and Information Security Policy and SLA — have the meaning given to them in Article 2 of the general terms and conditions.
2.2 Terms from the GDPR, including personal data, processing, controller, processor, data subject and data breach, have the meaning given to them by the GDPR.
2.3 GDPR means Regulation (EU) 2016/679, as well as the Dutch implementing legislation. AI Act means Regulation (EU) 2024/1689.
3.1 This Data Processing Agreement is entered into between:
Applyfin, as described in Article 1, acting as processor; and
the Client, as further specified in Article 3.3, acting as controller,
hereinafter jointly referred to as the Parties and each individually as a Party.
3.2 The Data Processing Agreement is concluded at the same moment as the Agreement: upon creation of the Company, or upon acceptance of the Quotation (Articles 3.1 and 21.2 of the general terms and conditions).
3.3 The Client is the business or legal entity for which the Company has been created or with which Applyfin has otherwise entered into an Agreement, as identified upon registration of the Company or in the Quotation, with the statutory name, place of business and trade register number stated therein. The person who creates the Company or accepts the Quotation declares that they are authorised to bind the Client.
3.4 Applyfin makes this Data Processing Agreement available electronically prior to acceptance, in a manner that allows the Client to store it and consult it at a later date (Article 6:234 Dutch Civil Code), and records the version number, the time and the accepting User for every acceptance (Articles 3.3 and 3.4 of the general terms and conditions).
4.1 Applyfin as processor. Applyfin acts as processor for all personal data that it processes on behalf of the Client. For those processing operations, the Client is the controller and determines the purpose, legal basis and retention period.
4.2 Searches, screening and shortlisting. Applyfin does not maintain a candidate database of its own. If a search is carried out within the Platform for a vacancy, or an applicant or candidate is screened, Applyfin queries the Data Supplier at that moment and on the Client’s instructions. Under a self-serve Package, the search, the screening and the selection are carried out by the Client; under managed delivery, Applyfin performs these actions on behalf of the Client, with the consequences attached thereto by Article 4.8. Applyfin is processor under Article 4.1 for the query, for the temporary storage of the results referred to in Article 4.3, and for creating the records of the selected candidates within the Company. There is no stage at which Applyfin is an independent controller for that data.
4.3 Temporary storage of search results. Results of a search are stored for a maximum of thirty minutes in a temporary cache outside the Company, solely in order to avoid a repeated query of the Data Supplier. On expiry of that period they are erased automatically and irrevocably. Results that are not selected are not stored in the Company.
4.4 Applyfin as independent controller. Applyfin is an independent controller for:
a. the suppression list with which Applyfin gives lasting effect to an objection raised by a data subject across all of its clients. This list contains only an irreversible hash value of an email address or profile identifier and the date of inclusion, and is applied to the results of every search. Applyfin necessarily keeps this processing outside the Company, because an objection would otherwise apply only at the Client with which it was lodged;
b. the data of the Client and its Users that Applyfin processes for its own business operations, including account, authentication, invoicing and contract data, which is stored in Applyfin’s central database and not within the Company;
c. system and security logs that Applyfin generates for the purposes of security, stability and traceability;
d. aggregated data that is not traceable to a natural person or to the Client, insofar as Applyfin uses it for statistics and improvement of its services (Article 23.4 of the general terms and conditions). This data is anonymised within the meaning of recital 26 GDPR and falls outside the scope of Article 4.1.
4.5 The Parties are not joint controllers within the meaning of Article 26 GDPR.
4.6 Applyfin does not independently determine the purpose or the means of the processing operations referred to in Article 4.1. If it nevertheless does so, it is regarded as the controller for that processing (Article 28(10) GDPR).
4.7 Responsibility follows actual conduct. Within the division of roles in this Article, the Party that actually carries out a processing operation, delivery or intervention bears responsibility for it. Applyfin therefore bears responsibility for the technical configuration and default settings of the Platform, the Consent functionality as delivered by it (Article 6.6 of the general terms and conditions), the AI applications and automated workflows that it provides and operates, and the changes that it makes in the context of support. The Client bears responsibility for the data that it enters or has entered itself, its own configuration choices, its own integrations and API connections, and the lawfulness of the data it enters. Which actions have been performed by which Party is recorded in the Platform’s activity logs.
4.8 Performance by Applyfin under managed delivery (RPO). If the Client purchases managed delivery, Applyfin staff carry out recruitment activities on the Client’s behalf within its Company, including drawing up and carrying out searches, selecting and shortlisting candidates, screening, and approaching and corresponding with candidates. Pursuant to Article 4.7, these actions are attributed to Applyfin.
In that case, the Client’s responsibility is limited to: issuing the assignment and the vacancy requirements, determining the purpose, legal basis and retention period, its own configuration choices, and the data that it enters itself or via its own Users. Applyfin bears responsibility for the lawful performance of the actions carried out by its staff, including compliance with the duty to inform under Article 14 GDPR upon first contact with a candidate, the application of the suppression list, and not processing data that falls outside the assignment.
This division is without prejudice to the fact that the Client remains the controller vis-à-vis the data subject and the supervisory authority; it operates between the Parties inter se, including the indemnity in Article 15.3.
4.9 Duty to inform in self-serve use. If the Client itself approaches a candidate found through a search, it bears responsibility for compliance with the duty to inform under Article 14 GDPR upon that first contact. To that end, Applyfin makes standard texts and functionality available within the Platform with which the required information, including a statement of the source of the data and a reference to the Privacy and Information Security Policy, is included in the first message. The suppression list is applied by Applyfin in all cases.
5.1 Applyfin processes personal data on behalf of the Client for the purposes of making the Platform available, hosting the Client’s career pages and, if purchased, the managed delivery (RPO) and the add-ons.
5.2 The nature of the processing concerns the collection, storage, consultation, use, transmission, combination, enrichment, restriction, erasure and anonymisation of data, querying the Data Supplier on the Client’s instructions and the temporary storage of the results thereof (Articles 4.2 and 4.3), the placement and reading of cookies and similar techniques on the career pages that Applyfin hosts on behalf of the Client, as well as — insofar as activated by the Client — AI-supported functionality as referred to in Article 11.
5.3 The purpose is exclusively recruitment and selection for the benefit of the Client. Applyfin does not process the personal data referred to in Article 4.1 for any other purpose. This is without prejudice to the processing operations for which Applyfin is an independent controller under Article 4.4.
5.4 The processing lasts for as long as the Agreement is in force, and thereafter until return or deletion in accordance with Article 13.7.
6.1 Applyfin processes personal data of the following data subjects on behalf of the Client:
a. Applicants — from submission of an application for a vacancy of the Client: name and address details, contact details, date of birth, CV and cover letter, education and employment history, skills, location indication, application and process data, correspondence and screening and assessment results. If the Client has an applicant screened as referred to in Article 4.2, additional professional profile data and its source are also processed.
b. Candidates found through a search and shortlisted — from selection by the Client, or, in the case of managed delivery, by Applyfin on the Client’s behalf, and inclusion in the Company with a view to being approached for a vacancy: name, job title and employer, employment history, educational background, skills, location indication, reference to the public profile, enriched contact details including email address and telephone number, the source of the data, and outreach and process data and correspondence. Non-selected search results are processed only temporarily in accordance with Article 4.3.
c. Referees — from being named as a reference by an applicant or candidate: name, relationship to the data subject, business contact details and the reference and associated correspondence.
d. Talent pool participants — from inclusion in a talent pool on the basis of consent: the data referred to under a or b, supplemented with talent pool preferences and consent data (time, scope and withdrawal).
e. Users of the Client — the recruiters and other staff to whom the Client grants access to the Company: name and business contact details, role and authorisation and activity logs, insofar as Applyfin processes these within the Company. For the account, authentication and invoicing data of Users, Applyfin is an independent controller (Article 4.4(b)).
f. Visitors to the Client’s career pages — insofar as Applyfin processes data on those pages on behalf of the Client that qualifies as personal data: IP address, device and browser data, session and visit data and the recorded consent. The Client is the controller for this processing and determines, via the Consent functionality, which non-essential techniques are deployed. Processing based on anonymised data falls outside this.
6.2 Applyfin does not process special categories of personal data as referred to in Article 9 GDPR, unless the Client has a valid legal basis for this and the Parties have made an additional written arrangement in that respect.
7.1 Applyfin processes exclusively on the documented instructions of the Client. The Agreement, the configuration of the Company and the use by the Client and its Users constitute those instructions.
7.2 If Applyfin considers an instruction to be in conflict with the GDPR or other applicable data protection legislation, it notifies the Client of this without delay and is not obliged to carry out that instruction.
7.3 Persons who have access to the personal data under Applyfin’s authority are bound by a duty of confidentiality, on the basis of least privilege and need-to-know.
7.4 The duty of confidentiality in Article 20 of the general terms and conditions applies in full. The limitation in time in Article 20.4 of the general terms and conditions does not apply to personal data; for that data, confidentiality is not limited in duration.
8.1 Applyfin takes appropriate technical and organisational measures, including an isolated database per Company with environment-bound access, encryption in transit and at rest, back-ups separated and encrypted per Company, multi-factor authentication for production access, central logging and monitoring, and periodic vulnerability scans and penetration tests.
8.2 The full elaboration of these measures is set out in section 8 of the Privacy and Information Security Policy. Applyfin updates these measures periodically; changes do not lower the level of security.
8.3 Data from one Company is not shared with, disclosed to, or used for the purposes of another Company. AI models within the Platform are not trained on client data aggregated across Companies.
8.4 By way of derogation from storage within the Company, the temporary cache (Article 4.3) and the suppression list (Article 4.4(a)) are kept outside the Company. The cache contains only results of an ongoing search by the Client concerned and no data from a Company; the suppression list contains only the data referred to in Article 4.4(a). Neither is used for the purposes of another Client.
9.1 The Client grants Applyfin general written authorisation to engage sub-processors (Article 28(2) GDPR). A current overview of the sub-processors engaged is available on request; the categories are listed in section 7 under B of the Privacy and Information Security Policy. Those sub-processors include in any event the Data Supplier that Applyfin queries on the Client’s instructions (Article 4.2).
9.2 Applyfin informs the Client at least thirty days before the intended effective date of the addition or replacement of a sub-processor. The Client may object to this in writing on reasonable grounds within fourteen days of the announcement.
9.3 If the Parties do not reach a solution within fourteen days of the objection, the Client may cancel the Agreement in writing with effect from the intended effective date of the change. If no solution is reached within that period and the Client does not cancel, Applyfin suspends the use of the sub-processor concerned for the Client until the Parties do reach agreement, insofar as that is technically and operationally possible. Article 28 of the general terms and conditions applies to a cancellation; amounts already due remain payable.
9.4 Applyfin imposes on every sub-processor the same obligations as those set out in this Data Processing Agreement (Article 28(4) GDPR) and remains fully liable towards the Client for that sub-processor’s performance.
10.1 Applyfin provides the Client, taking into account the nature of the processing and the information available to it, with reasonable assistance in respect of data subjects’ requests (Articles 12 to 23 GDPR) and in respect of the Client’s obligations under Articles 32 to 36 GDPR. Functionality for handling requests is available in the Platform.
10.2 Data subjects’ requests that reach Applyfin directly and that relate to processing operations under Article 4.1 are forwarded by Applyfin to the Client without delay. Requests relating to processing operations under Article 4.4 are handled by Applyfin itself, in accordance with section 10 of the Privacy and Information Security Policy. In addition, Applyfin gives effect to an objection to being approached raised by a data subject independently and on an ongoing basis via the suppression list (Article 4.4(a)), so that the data subject does not appear in the results again in searches by other clients either. This use of the suppression list is without prejudice to the Client’s assessment of the objection as controller.
10.3 In the event of a data breach or a suspected data breach, Applyfin informs the Client without undue delay and at the latest within twenty-four hours of becoming aware, with the information that the Client needs for its notification obligation (Articles 33 and 34 GDPR).
10.4 For processing operations under Article 4.1, Applyfin does not notify the Dutch Data Protection Authority or data subjects independently, unless the Parties agree otherwise in writing; that notification is for the Client as controller. For processing operations under Article 4.4, Applyfin makes the notification itself, within the statutory period of seventy-two hours.
10.5 After becoming aware of a data breach or a suspected data breach, Applyfin takes appropriate technical and organisational measures without delay to end and remedy the data breach, or to limit its adverse consequences, and informs the Client of the measures already taken and those still to be taken.
10.6 The Client in turn informs Applyfin without delay of a data breach or GDPR infringement within its Company that affects Applyfin or its services.
11.1 Insofar as the Client activates AI functionality within the Platform, Applyfin processes the personal data involved exclusively within the instructions in Article 7.1. The deployment of AI does not constitute an independent purpose of Applyfin.
11.2 No decision-making takes place that is based solely on automated processing and that produces legal effects concerning the data subject or similarly significantly affects them (Article 22 GDPR). AI outputs support the recruiter; every decision about a candidate requires human assessment and confirmation.
11.3 Applyfin is the provider and the Client is the deployer within the meaning of the AI Act, as further set out in Article 22 of the general terms and conditions and section 9 of the Privacy and Information Security Policy. The deployment of AI is logged and is available to the Client to substantiate its own accountability (Article 12 AI Act).
11.4 The Client does not deploy the Platform for applications prohibited under the AI Act (Article 5 AI Act and Article 22.3 of the general terms and conditions).
12.1 Applyfin’s primary infrastructure is hosted within the European Union.
12.2 Transfers of personal data to a country outside the European Economic Area take place exclusively on the documented instructions of the Client, on the basis of a legal obligation, or because Applyfin engages a sub-processor in accordance with Article 9, and in all cases with appropriate safeguards as referred to in Chapter V GDPR, including the Standard Contractual Clauses or an adequacy decision, supplemented where necessary with additional measures. In the announcement referred to in Article 9.2, Applyfin states whether the sub-processor concerned processes data outside the EEA and on what basis.
13.1 Retention periods. Retention periods are determined by the Client as controller, within the limits of the GDPR and on the basis of a valid legal basis. Applyfin deletes, anonymises or pseudonymises personal data in accordance with the periods and instructions determined by the Client.
13.2 Standard periods. In the absence of a deviating instruction or setting, Applyfin applies the following standard periods:
a. applicant data: four weeks after completion of the procedure, or one year if the data subject has consented to this, in accordance with the guidance of the Dutch Data Protection Authority;
b. shortlisted candidates who are not approached: a maximum of one month after placement on the shortlist, after which the data is deleted or anonymised;
c. shortlisted candidates who have been approached and have not responded: a maximum of six months after the first moment of approach;
d. talent pool participants: a maximum of two years after the last contact or the last update, with a reconfirmation moment before the end of that period.
Section 6 under B of the Privacy and Information Security Policy refers to this Article for these periods.
13.3 Limit on deviating instructions. An instruction from the Client to retain shortlisted candidates who have not been approached for longer than the period in Article 13.2(b) is regarded by Applyfin as conflicting with the duty to inform under Article 14(3) GDPR. Applyfin notifies the Client of this and does not carry out that instruction, in accordance with Article 7.2.
13.4 Non-selected search results are processed and erased in accordance with Article 4.3; this Article does not otherwise apply to them.
13.5 Request from the data subject. If a data subject has requested erasure or has withdrawn their consent, Applyfin deletes, on the Client’s instructions, all personal data relating to that data subject within the Company, irrespective of the periods in Article 13.2. If the request reaches Applyfin directly, Article 10.2 applies.
13.6 Processing-bound deletion. At the Client’s request, Applyfin sets up processing-bound deletion at no additional cost: as soon as a processing operation has been completed, including the closure of a vacancy, the personal data bound to it is deleted or anonymised, except for data that the Client wishes to retain for longer on a valid legal basis.
13.7 Return and deletion after the end of the Agreement. After the end of the Agreement, Applyfin erases the personal data processed on the Client’s behalf, or returns it to the Client, at the Client’s choice (Article 28(3)(g) GDPR). The Client makes that choice no later than thirty days after the termination date, in accordance with Articles 28.3 and 28.4 of the general terms and conditions. If the Client does not make a choice within that period, Applyfin erases the data.
In doing so, Applyfin also deletes existing copies, unless Union law or Dutch law requires the data to be stored. Copies in back-ups are deleted upon expiry of the regular back-up retention period and, until that moment, are accessible exclusively for recovery following an incident. At the Client’s request, Applyfin confirms the deletion in writing.
A suspension of access under Article 13 or Article 27 of the general terms and conditions does not lead to deletion of data and does not trigger the periods in this Article.
13.8 Scope of the return. The return covers all personal data that the Client has entered or that has been created within its Company, including the identifying data of shortlisted candidates, the contact details added through enrichment, and all status, process and correspondence data.
Excluded from the return are the fields that Applyfin obtains under licence from the Data Supplier and that it may not disclose to third parties on the basis of that licence: employment history, education history, headline, summary text, skills and labour market signals (Article 18.4 of the general terms and conditions). This exclusion is based on the Data Supplier’s licence conditions and not on a ground under the GDPR; it is without prejudice to the rights of the data subject. If a data subject requests access to or portability of their own data (Articles 15 and 20 GDPR), Applyfin also provides these fields.
Applyfin informs the Client at the outset which fields fall under this exclusion and notifies changes therein in accordance with Article 9.2.
13.9 Statutory retention obligation. For data subject to a statutory retention obligation, that statutory period applies and Applyfin retains the data in pseudonymised form, exclusively for the purpose for which the retention obligation has been imposed.
14.1 Applyfin makes available to the Client the information necessary to demonstrate compliance with Article 28 GDPR and cooperates with audits.
14.2 Applyfin may respond to an audit request first with documentation, reports of vulnerability scans and penetration tests, and available certifications. Section 8 of the Privacy and Information Security Policy describes the status of Applyfin’s information security policy at the time of publication.
14.3 If this reasonably provides insufficient assurance, an on-site audit may take place, at most once every twelve months, after at least thirty days’ notice, during office hours, by an independent auditor bound by confidentiality, and with due observance of the data isolation of other clients.
14.4 The Client bears its own audit costs. If a supervisory authority imposes an audit, Applyfin cooperates with it within the period set by the supervisory authority.
15.1 Each Party is liable for damage, fines and claims arising from an attributable failure on its part, in accordance with the division in Articles 4.7, 4.8 and 4.9 of this Data Processing Agreement and Article 24.1 of the general terms and conditions.
15.2 Applyfin’s own failures. Applyfin bears responsibility for a breach of the GDPR arising from its own acts or omissions, including inadequate security measures, a data breach on its side, processing outside the Client’s instructions, a failure in the onboarding, platform configuration, Consent functionality, AI applications or workflows that it provides or configures, and the actions referred to in Article 4.8. It cannot invoke the Client’s responsibility as controller in respect of those failures.
15.3 Indemnity. Applyfin indemnifies the Client against claims from data subjects, third parties and supervisory authorities, and against administrative fines, insofar as those claims or fines arise from a failure as referred to in Article 15.2. The Client notifies such a claim without delay, conducts the defence in consultation with Applyfin and does not enter into any settlement without Applyfin’s prior written consent. The indemnity does not apply insofar as the claim has been caused by an instruction, configuration choice or data entry by the Client, or by use of the Platform in breach of the Agreement.
15.4 The Parties’ liability under this Data Processing Agreement, including the indemnity in Article 15.3, is governed by Articles 24.3 and 24.4 of the general terms and conditions. For liability due to a data breach or a breach of the GDPR, the separate cap in Article 24.3, third bullet point, applies.
15.5 This Article applies in full to the indemnities in Article 25 of the general terms and conditions; Article 25.6 of the general terms and conditions determines the relationship between the two arrangements.
16.1 This Data Processing Agreement applies for as long as the Agreement is in force.
16.2 Applyfin may amend this Data Processing Agreement in accordance with Article 29 of the general terms and conditions. Amendments that are necessary on the basis of mandatory law, a decision of a supervisory authority or a ruling of a competent court may take effect with a shorter period.
16.3 After the end of the Agreement, Articles 7 (instructions and confidentiality), 10 (assistance and data breaches), 13 (retention, return and deletion), 14 (audits) and 15 (liability) remain in force, for as long as Applyfin still holds personal data of the Client and, in the case of Articles 7 and 15, thereafter as well.
16.4 This Data Processing Agreement is governed by Dutch law. Article 32 of the general terms and conditions applies to disputes.