Data processing agreement
Last updated: June 2026
This data processing agreement ("the Agreement") applies to companies that use Worktube for recruiting. It supplements the terms of use and is entered into between the company ("Controller") and Appit AS, company no. 933 898 210 ("Processor"). The Agreement meets the requirements of GDPR art. 28.
1. Roles
When the company uses Worktube to assess candidates for its own positions, the company is the controller and Appit AS is the processor for the personal data processed on the company's behalf (for example interviews, scorecards and assessments the company initiates).
For candidates' own profiles on the platform, Appit AS is itself the controller. That is governed by the privacy policy, not by this Agreement.
2. Purpose and duration
The Processor processes personal data only to deliver the recruiting service to the Controller. The Agreement applies for as long as the company uses the service.
3. Nature of processing and data types
- Categories of data subjects: candidates and the company's own users.
- Data types: name, contact info, work experience, education, skills, interview answers and assessments.
- Processing activities: storage, structuring, AI assisted assessment, collation and presentation.
The Processor shall not process special categories of personal data on behalf of the Controller.
4. Instructions
The Processor processes personal data only on documented instructions from the Controller, as set out in the Agreement and the use of the service, unless otherwise required by law.
5. Confidentiality
The Processor ensures that everyone with access to the personal data is bound by confidentiality.
6. Security
The Processor implements appropriate technical and organisational measures under GDPR art. 32, including encryption, row-level access control, logging and anonymisation of candidates toward other employers.
7. Sub-processors
The Controller gives general consent to the use of sub-processors. The Processor currently uses:
| Sub-processor | Function |
|---|---|
| Supabase | Database, login, storage |
| Vercel | Operations and hosting |
| Anthropic / OpenRouter | AI processing |
| Twilio SendGrid | |
| Stripe | Payment |
| Telegram | Optional agent communication |
The Processor notifies of changes to the list so the Controller can object.
8. Transfer outside the EEA
Some sub-processors are in the US. Transfer is based on the EU Commission's Standard Contractual Clauses (SCC) with necessary supplementary measures.
9. Assistance
The Processor assists the Controller in responding to requests from data subjects and in safeguarding security, breach notification and data protection impact assessments, cf. GDPR art. 32–36.
10. Breach notification
The Processor notifies the Controller without undue delay on a personal data breach.
11. Deletion
On termination, the Processor deletes or returns the personal data at the Controller's choice, unless law requires further storage.
12. Audit
The Processor makes available the information necessary to demonstrate compliance, and allows for audits to a reasonable extent.
13. Conclusion
The Agreement is considered entered into when the company starts using the service for recruiting. If you want a signed version, contact trond@worktube.com.
Worktube is operated by Appit AS, company no. 933 898 210, Kokstadveien 41, 5257 Kokstad, Norway. Contact: trond@worktube.com · +47 56 32 00 00