Data Processing Agreement
Loomee Group (Pty) Ltd, trading as Qcandidate, acts as a data processor for the candidate data your organisation submits. These terms form part of our contract with you and apply automatically to every paid and free account.
Last updated September 2026
1. Roles
You are the data controller for candidate personal data. Qcandidate is the processor and acts only on your documented instructions, which are the instructions given through the product (posting a job, running a screen, approving a Growth Kit send). We never repurpose candidate data for our own ends.
2. Categories of data and data subjects
Data subjects are job applicants and your own HR users. Candidate data includes name, email, the contents of a submitted CV (which may include work history, education, and any personal detail the candidate chose to include), the generated score and rubric evidence, and the skills gap used to select a Growth Kit. HR user data is limited to name, work email and role.
3. Purpose and duration
Candidate data is processed solely to rank applications against your rubric, produce the explainability record, and deliver a Growth Kit to candidates you have declined. Processing lasts for the term of your subscription plus the retention window below.
4. Retention and deletion
Applications and screening runs are retained for 12 months from the close of the job, so that you can answer an audit or discrimination query with the original evidence. Candidate portal tokens expire after 14 days. You can delete a job, an application or your entire account at any time; deletion removes candidate records within 30 days, including from backups.
5. Automated decision-making
Qcandidate ranks candidates but does not reject them. Every rejection and every Growth Kit send requires an explicit human sign-off from one of your HR users after reviewing the evidence table. This design supports Article 22 GDPR and the human-oversight requirements of the EU AI Act, and produces the audit trail NYC Local Law 144 expects.
6. Security measures
Row-level security on every table, role-scoped database grants, no anonymous read access to job rubrics or applications, encrypted transport (TLS 1.2+) and encryption at rest, short-lived candidate portal tokens, and a full audit log of every score, override and send. We run an automated security scan on every deploy and can supply the current audit report on request.
7. Subprocessors
We use the subprocessors listed below. We will give you 30 days' notice before adding a new one, and you may object on reasonable data-protection grounds.
| Subprocessor | Purpose | Region | Data |
|---|---|---|---|
| Supabase | Database, authentication and file storage for jobs, applications and CV files | EU / US regions | Candidate name, email, CV text, scores, audit logs |
| Google (Gemini via Lovable AI Gateway) | CV parsing, rubric extraction and candidate scoring | US / global | Job spec text and CV text submitted for a screening run |
| Lovable | Application hosting, edge delivery and outbound email | EU / US | Request metadata, candidate email addresses for Growth Kit delivery |
| Lemon Squeezy LLC | Merchant of record, subscription billing and invoicing | US | Customer billing name, email, company and payment details (no candidate data) |
8. International transfers
Candidate data may be processed outside your country, including in the United States, by the subprocessors above. Transfers rely on Standard Contractual Clauses or an equivalent lawful transfer mechanism with each subprocessor.
9. Assisting you
We will help you respond to data-subject requests (access, correction, erasure, objection), data-protection impact assessments and regulator queries. Candidates can already see their own score breakdown and skills gap in the candidate portal, which resolves most access requests without involving you.
10. Breach notification
We will notify you without undue delay, and in any case within 48 hours, of becoming aware of a personal data breach affecting your candidate data, with the facts known at that time and the steps taken.
11. Audit
On reasonable notice, and no more than once a year, you may request our current security audit report and reasonable written answers to a security questionnaire.
12. Contact
Data protection questions, DPA countersignature requests and subprocessor objections: p.sweleni@loomeeremote.com.