Data Processing Agreement

Loomee Group (Pty) Ltd, trading as Qcandidate, acts as a data processor for the candidate data your organisation submits. These terms form part of our contract with you and apply automatically to every paid and free account.

Last updated September 2026

1. Roles

You are the data controller for candidate personal data. Qcandidate is the processor and acts only on your documented instructions, which are the instructions given through the product (posting a job, running a screen, approving a Growth Kit send). We never repurpose candidate data for our own ends.

2. Categories of data and data subjects

Data subjects are job applicants and your own HR users. Candidate data includes name, email, the contents of a submitted CV (which may include work history, education, and any personal detail the candidate chose to include), the generated score and rubric evidence, and the skills gap used to select a Growth Kit. HR user data is limited to name, work email and role.

3. Purpose and duration

Candidate data is processed solely to rank applications against your rubric, produce the explainability record, and deliver a Growth Kit to candidates you have declined. Processing lasts for the term of your subscription plus the retention window below.

4. Retention and deletion

Applications and screening runs are retained for 12 months from the close of the job, so that you can answer an audit or discrimination query with the original evidence. Candidate portal tokens expire after 14 days. You can delete a job, an application or your entire account at any time; deletion removes candidate records within 30 days, including from backups.

5. Automated decision-making

Qcandidate ranks candidates but does not reject them. Every rejection and every Growth Kit send requires an explicit human sign-off from one of your HR users after reviewing the evidence table. This design supports Article 22 GDPR and the human-oversight requirements of the EU AI Act, and produces the audit trail NYC Local Law 144 expects.

6. Security measures

Row-level security on every table, role-scoped database grants, no anonymous read access to job rubrics or applications, encrypted transport (TLS 1.2+) and encryption at rest, short-lived candidate portal tokens, and a full audit log of every score, override and send. We run an automated security scan on every deploy and can supply the current audit report on request.

7. Subprocessors

We use the subprocessors listed below. We will give you 30 days' notice before adding a new one, and you may object on reasonable data-protection grounds.

SubprocessorPurposeRegionData
SupabaseDatabase, authentication and file storage for jobs, applications and CV filesEU / US regionsCandidate name, email, CV text, scores, audit logs
Google (Gemini via Lovable AI Gateway)CV parsing, rubric extraction and candidate scoringUS / globalJob spec text and CV text submitted for a screening run
LovableApplication hosting, edge delivery and outbound emailEU / USRequest metadata, candidate email addresses for Growth Kit delivery
Lemon Squeezy LLCMerchant of record, subscription billing and invoicingUSCustomer billing name, email, company and payment details (no candidate data)

8. International transfers

Candidate data may be processed outside your country, including in the United States, by the subprocessors above. Transfers rely on Standard Contractual Clauses or an equivalent lawful transfer mechanism with each subprocessor.

9. Assisting you

We will help you respond to data-subject requests (access, correction, erasure, objection), data-protection impact assessments and regulator queries. Candidates can already see their own score breakdown and skills gap in the candidate portal, which resolves most access requests without involving you.

10. Breach notification

We will notify you without undue delay, and in any case within 48 hours, of becoming aware of a personal data breach affecting your candidate data, with the facts known at that time and the steps taken.

11. Audit

On reasonable notice, and no more than once a year, you may request our current security audit report and reasonable written answers to a security questionnaire.

12. Contact

Data protection questions, DPA countersignature requests and subprocessor objections: p.sweleni@loomeeremote.com.