Data Processing Addendum
Last updated: February 3, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Use between Ducker Ltd. ("Ducker," "Processor," "we") and the customer organization ("Customer," "Controller," "you") and governs our processing of personal data on your behalf.
It applies automatically when you use the Platform. You do not need to sign a separate copy, though we will countersign one on request at legal@ducker.ai. Where this DPA conflicts with the Terms of Use, this DPA governs for matters of data protection.
1. Definitions
Terms defined in the Terms of Use carry the same meaning here.
- "Data Protection Law" — every law applicable to the processing under this DPA, including the GDPR, the UK GDPR, the Swiss FADP, the CCPA/CPRA and other United States state privacy laws, and the Israeli Privacy Protection Law, 5741-1981.
- "Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Supervisory Authority" — as defined in the GDPR. Under United States state privacy law, "Controller" includes "Business" and "Processor" includes "Service Provider."
- "Customer Personal Data" — Personal Data contained in Customer Content and Candidate Data that we process on your behalf.
- "Sub-processor" — a third party we engage to process Customer Personal Data.
- "SCCs" — the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.
- "UK Addendum" — the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
2. Roles
You are the Controller of Customer Personal Data. We are the Processor.
You determine the purposes and means of processing: which candidates to assess, what to assess them on, what the results mean, and what to do about them. We process only to provide the Platform.
We are an independent Controller for a limited set of our own purposes — securing the Platform, preventing fraud and assessment cheating, complying with our legal obligations, billing you, and producing aggregated, de-identified analytics. Our Privacy Policy governs that processing. Nothing in this DPA makes us a joint Controller with you.
Under the CCPA/CPRA we act as a Service Provider. We do not sell or share Customer Personal Data, do not retain, use, or disclose it for any purpose other than performing the services, and do not combine it with personal information from other sources except as permitted for a Service Provider.
3. Your Instructions
We process Customer Personal Data only on your documented instructions, which comprise this DPA, the Terms of Use, your configuration of the Platform, and any further written instruction you give us.
We will tell you if, in our opinion, an instruction infringes Data Protection Law, and may suspend that processing until it is resolved.
If a law we are subject to requires us to process Customer Personal Data beyond your instructions, we will inform you before processing unless that law forbids it.
4. Your Obligations
You warrant that:
- You have a lawful basis to collect Customer Personal Data and to have us process it
- You have given Data Subjects the information Data Protection Law requires, including making our Candidate Privacy Notice available to Candidates before their assessment
- Your instructions comply with Data Protection Law
- You have completed any data protection impact assessment your use requires, given that AI systems used in recruitment are regulated as high-risk under the EU AI Act
- You will not send us special category data, government identifiers, financial account data, or health data through the Platform. The Platform is not designed for it and you must not upload it in Customer Content or task materials.
5. Confidentiality
We will keep Customer Personal Data confidential. Personnel authorised to process it are bound by written confidentiality obligations that survive the end of their engagement, and access is limited to those who need it to provide the Platform.
6. Security
We implement the technical and organisational measures described in Annex II, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing.
We may update these measures as the Platform evolves, provided we do not materially reduce the level of security.
7. Sub-processors
You give us general authorisation to engage Sub-processors. The current list, with each one's role, entity, and processing location, is published at ducker.ai/subprocessors.
Before we add or replace a Sub-processor, we will update that list and give at least 30 days' notice by email to your account's notification address, or by a mechanism you can subscribe to on that page.
You may object on reasonable data protection grounds within those 30 days. We will work with you in good faith to find a solution. If we cannot, you may terminate the affected part of the Platform without penalty and receive a pro-rata refund of prepaid fees for the unused term.
We impose data protection obligations on each Sub-processor no less protective than those in this DPA, and remain fully liable to you for their performance.
8. Data Subject Requests
We will not respond directly to a Data Subject request about Customer Personal Data, except to confirm that the request should be directed to you. Where a Candidate contacts us, we will tell them to contact the employer who invited them and notify you.
The Platform lets you access, correct, export, and delete Customer Personal Data yourself. Where you cannot fulfil a request through the Platform, we will provide reasonable assistance, taking into account the nature of the processing.
We provide this assistance at no charge unless a request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee.
9. Personal Data Breach
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will provide it in phases without undue delay.
We will assist you in meeting your own notification obligations to Supervisory Authorities and Data Subjects. Our notification is not an acknowledgement of fault or liability.
10. Assistance
Taking into account the nature of processing and the information available to us, we will assist you with:
- Data protection impact assessments and prior consultation with a Supervisory Authority
- Security of processing under GDPR Article 32
- Notification of Personal Data Breaches under Articles 33 and 34
- Responding to Data Subjects under Articles 12 to 22
11. Audit
We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by you or an auditor you mandate.
Audit rights are satisfied in the first instance by our documentation, our security overview, and any third-party certifications or penetration test summaries we hold. If those do not answer your question, you may request an audit no more than once in any 12 months — or more often following a Personal Data Breach or a Supervisory Authority's requirement — on 30 days' written notice, during business hours, without unreasonably disrupting our operations, subject to confidentiality, and at your cost. The auditor must not be a competitor of ours.
12. International Transfers
Customer Personal Data is stored in the European Union, in Amazon Web Services' eu-central-1 region in Frankfurt, Germany. Processing outside the EEA occurs where we, our personnel in Israel, or our Sub-processors access it.
- Transfers to Ducker in Israel rely on the European Commission's adequacy decision for Israel. Where adequacy is unavailable or withdrawn, the SCCs apply.
- Transfers to Sub-processors outside the EEA or the UK rely on the SCCs, on the UK Addendum for UK transfers, or on the recipient's EU-US Data Privacy Framework certification.
- Where the SCCs apply, they are incorporated into this DPA: Module Two (Controller to Processor) where you are a Controller, and Module Three (Processor to Processor) where you are yourself a Processor. Annex I is populated by Annex I below, Annex II by Annex II below, and Annex III by our sub-processor list. In Clause 7 the docking clause applies; in Clause 9 Option 2 applies with the 30-day notice period in section 7; in Clause 11 the optional redress body is not used; in Clause 17 the governing law is Irish law; in Clause 18(b) the forum is the courts of Ireland.
13. Deletion and Return
On termination or expiry, we will delete Customer Personal Data in accordance with the retention periods in our Privacy Policy.
For 30 days after termination you may request export of Customer Personal Data in a standard machine-readable format. After that period we may delete it.
We may retain Customer Personal Data where a law we are subject to requires it, for as long as that law requires, and will continue to protect it under this DPA.
Residual copies may persist in encrypted backups for up to 90 days before being overwritten.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Use. Nothing in this DPA limits any Data Subject's rights under Data Protection Law or the SCCs.
15. Term
This DPA takes effect when you first use the Platform and continues until we have deleted or returned all Customer Personal Data.
Annex I — Details of Processing
A. List of Parties
Data exporter: the Customer identified in the Ducker account, acting as Controller. Contact: the account's administrative and notification email addresses.
Data importer: Ducker Ltd., Israel, acting as Processor. Contact: privacy@ducker.ai.
B. Description of Transfer
| Item | Detail |
|---|---|
| Categories of Data Subjects | Candidates invited by the Customer; the Customer's Authorized Users |
| Categories of Personal Data | Identity and contact data (name, email address); account and authentication data; assessment configuration; assessment telemetry (prompts, agent responses, tool calls, code authored and generated, diffs, reverted changes, terminal commands, test runs, database operations, accepted and rejected suggestions); submissions and workspace snapshots; grader output, scores, and reports; device and pre-flight capability data; IP address and derived approximate location; usage and log data |
| Special category data | None. The Platform is not designed for it and the Customer must not submit it. |
| Frequency of transfer | Continuous, for the duration of the subscription |
| Nature of processing | Collection, recording, structuring, storage, retrieval, analysis (including AI-assisted analysis), disclosure to the Customer, erasure |
| Purpose of processing | Providing the assessment platform: delivering assessments, recording sessions, grading submissions, producing candidate reports, and supporting the Customer |
| Retention | As set out in the Privacy Policy — assessment telemetry, submissions, and snapshots for 24 months from submission or until the Customer deletes them, whichever is first |
| Sub-processors | As listed at ducker.ai/subprocessors, for the duration and purpose stated there |
C. Competent Supervisory Authority
Determined in accordance with Clause 13 of the SCCs, by reference to the Customer's establishment in the EEA or its appointed EU representative.
Annex II — Technical and Organisational Measures
Encryption. TLS for all data in transit. Encryption at rest for databases, object storage, and backups. Passwords stored only as salted hashes.
Access control. Least-privilege IAM roles for production access. Multi-factor authentication for administrative accounts. Role-based access control within the Platform, so Authorized Users see only what their role permits. Access reviewed periodically and revoked on role change or departure.
Network and application security. Internal service-to-service calls are cryptographically signed and do not traverse the public internet. Secrets are held in a managed parameter store, never in source code. Runtime artifacts are served from private object storage behind a content delivery network with origin access control. Hidden tests are never delivered to a candidate's browser.
Isolation. Customer data is logically separated by organization identifier and enforced at the data access layer. Assessment workspaces execute in the candidate's own browser, sandboxed from our infrastructure.
Logging and monitoring. Access and application logs are retained for 12 months. Anomalies and authentication failures are monitored.
Resilience. Automated encrypted backups with point-in-time recovery. Infrastructure defined as code and reproducible.
Secure development. Code review before merge. Automated testing, linting, and dependency scanning in continuous integration. Separate development, sandbox, and production environments with no production data in lower environments.
Personnel. Confidentiality obligations in every employment and contractor agreement. Data protection training. Access granted on a need-to-know basis.
Incident response. A documented procedure for detecting, triaging, escalating, and notifying Personal Data Breaches, with the notification timeline in section 9.
Sub-processor management. Written data protection terms with every Sub-processor, and a published, maintained list.
Contact
Questions about this DPA, or requests for a countersigned copy:
Ducker Ltd. legal@ducker.ai · privacy@ducker.ai