Legal
Data Processing Agreement
This Data Processing Agreement (“DPA”) governs the processing of personal data by Orvensa on behalf of organizations using the platform. It forms part of the Terms of Service.
Processor: Kobenski BV
Brusselstraat 51, 2018 Antwerpen, Belgium
VAT / Enterprise number: BE0789853974
Trade name: Orvensa
Last updated: March 10, 2026
1. Roles
For personal data processed within recruitment workflows, the recruiting organization acts as the Controllerand Kobenski BV (Orvensa) acts as the Processor.
The Controller determines the purposes and means of processing applicant data. The Processor processes personal data solely on documented instructions from the Controller.
2. Scope of processing
The Processor provides the Orvensa platform, which allows recruiting organizations to manage candidate evaluation and recruitment workflows.
Processing activities may include:
- storing candidate CV files and application data,
- extracting structured information from documents,
- generating AI-assisted candidate evaluation outputs,
- storing recruiter notes and evaluation results,
- processing DSAR requests including deletion, restriction, and rectification.
3. Processing instructions
The Processor processes personal data only on documented instructions from the Controller, including instructions provided through use of the Orvensa platform.
If the Processor believes an instruction violates applicable data protection law, the Processor will inform the Controller.
4. Security measures
The Processor implements appropriate technical and organizational measures to protect personal data.
- role-based access control within organization workspaces,
- organization-scoped data separation,
- audit logging of sensitive actions,
- secure authentication flows,
- automatic deletion of CV files when applicant records are deleted,
- infrastructure and hosting security controls.
5. Subprocessors
The Processor may engage subprocessors to operate the service. Current subprocessors include:
- Stripe (billing and subscription management)
- SendGrid (transactional email delivery)
- OpenAI (AI inference services)
- Cloud infrastructure providers used for hosting and storage
The Processor will ensure subprocessors are bound by data protection obligations consistent with this agreement.
6. International transfers
Where personal data is transferred outside the European Economic Area, the Processor will ensure that appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
7. Data subject rights
The Processor will assist the Controller in responding to requests from data subjects exercising their rights under applicable data protection laws.
This includes support for:
- access requests,
- rectification of incorrect data,
- erasure of applicant records,
- restriction of processing,
- objection to automated processing.
8. Security incidents
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Controller.
9. Audits
The Controller may request reasonable information necessary to demonstrate compliance with this agreement.
Audit requests must be reasonable, proportionate, and not disrupt normal service operations.
10. Deletion and return
Upon termination of the service, the Controller may request deletion or return of personal data stored in the platform, subject to legal retention requirements.
Annex I — Processing description
Categories of data subjects:
- job applicants
- recruiters and hiring managers
- platform users
Categories of personal data:
- names and contact details
- CVs and application documents
- recruitment evaluation data
- user account information
Purpose of processing: recruitment workflow management and candidate evaluation.