Data Processing Agreement (DPA / AVV) under Art. 28 GDPR

Stand: 01.09.2026

This Data Processing Agreement ('Auftragsverarbeitungsvertrag', AVV / DPA) under Article 28 of the General Data Protection Regulation (GDPR) is entered into between the controller (the customer) and the processor, talentmonkeys GmbH, operating tamo.ai.

It sets out the rights and obligations of the parties with regard to the processing of personal data when the customer uses tamo.ai.

1. Subject matter and duration of processing

The processor provides the cloud-based recruiting software tamo.ai to the controller.

In the course of using tamo.ai, the processor may process job information, user and company data, candidate information, search and evaluation results, communication data, and data related to recruiting and outreach processes.

Processing takes place for the duration of the main agreement and thereafter only where required by law, necessary for winding down the contractual relationship, or necessary for the establishment, exercise or defence of legal claims.

After termination of the agreement, personal data shall be deleted or returned in accordance with this DPA, applicable retention requirements and the processor's deletion procedures.

2. Nature and purpose of processing

Processing is carried out solely for the provision and operation of tamo.ai, including:

  • processing and analysing job and search requirements;
  • identifying, enriching, structuring and evaluating potential candidates;
  • creating rankings and shortlists;
  • managing candidates and recruiting processes;
  • supporting or carrying out outreach processes after approval by the customer;
  • processing and displaying candidate replies;
  • providing account, team, billing, support and security functionality;
  • maintaining the technical operation, availability and security of the platform.

The processor shall process personal data only on documented instructions from the controller, unless required otherwise by applicable law.

3. Categories of data subjects

Data subjects may include:

  • employees and users of the customer;
  • applicants and potential candidates;
  • contacts at customers, prospects and other business partners;
  • other persons whose personal data the customer lawfully processes through tamo.ai.

4. Categories of personal data

Depending on the customer's use of tamo.ai, the following categories may be processed:

  • name and professional contact details;
  • job title, employer and professional history;
  • publicly available professional profile data;
  • education information;
  • location and language information;
  • professional skills and experience;
  • communication and outreach data;
  • candidate evaluations and recruiting status;
  • account, login and usage information;
  • billing and company information.

Special categories of personal data under Art. 9 GDPR are not intended for the normal use of tamo.ai. The customer must not submit such data unless a valid legal basis exists and appropriate safeguards have been agreed.

5. Responsibility of the controller

The customer remains responsible for the lawfulness of the processing carried out under its instructions.

In particular, the customer is responsible for:

  • establishing a valid legal basis;
  • the lawfulness of its instructions;
  • compliance with information obligations;
  • the lawful use of personal data for recruiting and outreach;
  • the content of messages approved by the customer;
  • compliance with employment, data-protection, competition and communications law;
  • the configuration and use of connected third-party accounts.

The processor is not required to comprehensively assess the legality of each individual customer instruction, search request, candidate selection or communication measure.

Where an instruction is manifestly unlawful, the processor may suspend execution until the matter has been clarified.

6. Obligations of the processor

The processor shall:

  • process personal data only on documented instructions;
  • ensure that persons authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational measures;
  • reasonably assist the controller with data-subject requests;
  • notify the controller of relevant personal-data breaches in accordance with applicable law;
  • reasonably assist with data-protection impact assessments where applicable;
  • delete or return personal data after termination in accordance with agreed deletion procedures.

7. Technical and organisational measures

tamo.ai implements appropriate technical and organisational measures in accordance with Art. 32 GDPR, including where applicable:

  • role-based and organisation-based access controls;
  • tenant separation;
  • authentication and authorisation controls;
  • encryption of data in transit;
  • secure management of credentials and secrets;
  • logging of security-relevant events;
  • restricted access to production data;
  • backup and recovery mechanisms provided by the underlying infrastructure;
  • measures designed to prevent unauthorised access;
  • procedures for deletion or blocking of personal data;
  • maintenance and updating of software components;
  • monitoring and error detection.

The processor does not guarantee a security level beyond the standard required under Art. 32 GDPR, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing and the risks to data subjects.

8. Sub-processors

The controller grants the processor general authorisation to engage sub-processors.

The processor shall ensure that appropriate data-protection obligations are imposed on sub-processors.

A current list of material sub-processors shall be made available by the processor or published on the tamo.ai website.

The processor may add or replace sub-processors. Where required by law, the controller shall be informed of material changes and given the opportunity to object on legitimate data-protection grounds.

An objection does not entitle the controller to require the processor to permanently refrain from using a sub-processor that is necessary for the provision of the service. Where no reasonable alternative is available, the parties may terminate the affected service or agreement.

9. International data transfers

Where personal data is processed outside the EEA, the processor shall ensure compliance with Arts. 44 et seq. GDPR, including by relying where applicable on adequacy decisions or standard contractual clauses.

10. Data-subject requests

Where the processor receives a request from a data subject that clearly relates to processing carried out on behalf of the controller, the processor shall generally forward the request to the controller or reasonably assist the controller in responding.

The processor is not required to independently determine the substantive validity of a data-subject request where that determination falls within the responsibility of the controller.

11. Personal-data breaches

The processor shall notify the controller without undue delay of a personal-data breach of which it becomes aware and which affects data processed on behalf of the controller.

The notification shall include the information reasonably available to the processor at that time.

The controller remains responsible for determining whether a notification to a supervisory authority or affected individuals is required.

12. Deletion and termination

Following the end of the services, the processor shall delete or anonymise personal data in accordance with its deletion processes, unless continued storage is required by law or justified for the establishment, exercise or defence of legal claims.

Data contained in technical backups may remain until the end of the normal backup-retention period and shall not be used for productive purposes during that period.

13. Evidence and audits

The processor shall provide the controller, upon reasonable request, with the information necessary to demonstrate compliance with Art. 28 GDPR.

Audits should in the first instance be carried out through available documentation, certifications, security information or questionnaires.

On-site audits shall only be required where other evidence is insufficient and there is a concrete data-protection reason.

Audits shall be coordinated with reasonable advance notice and carried out in a way that protects trade secrets, operational security and the data of other customers.

Unless an audit is required because of a data-protection breach caused by the processor, the customer shall bear its own costs and the processor's reasonable additional costs arising from the audit.

14. Third-party services

Where tamo.ai relies on external services, data providers, communications platforms or other third-party infrastructure, the processor does not guarantee their uninterrupted availability or unchanged functionality.

This does not affect the processor's obligations regarding the proper selection and engagement of sub-processors.

15. Liability

Liability shall be governed by the GDPR, applicable law and the liability provisions of the main agreement.

To the extent permitted by law, the processor assumes no guarantees, strict-liability obligations or broader commitments beyond those expressly set out in this DPA.

This DPA is provided as the contractual data-processing framework for tamo.ai and should be reviewed together with the main agreement and applicable law.