Skip to content

Compliance

Data Processing Agreement

Processor: Evalgist BV, KBO 1037.260.590, VAT BE 1037.260.590, with its registered office at Bosstraat 13, 9820 Merelbeke, Belgium (privacy@evalgist.ai).

This Data Processing Agreement (“DPA”) forms part of the Shortlist Terms and applies whenever Evalgist processes personal data on the Customer’s behalf in Evalgist Shortlist (“Shortlist”).

Scope and roles

The Customer is the controller and Evalgist BV is the processor for personal data that the Customer submits to a Shortlist project or that Shortlist generates from it (“Project Personal Data”). This includes personal data about candidates and other people mentioned in uploaded documents or project records. The Customer determines why the data is used and the criteria and decisions applied to it.

This DPA does not cover account and billing data, support contact data, security records, or basic product analytics that exclude candidate and project content. Evalgist processes that data as controller, as described in the Privacy Policy.

This DPA applies for as long as Evalgist processes Project Personal Data. If it conflicts with the Shortlist Terms concerning that processing, this DPA controls.

How Evalgist processes project data

Evalgist processes Project Personal Data only to operate Shortlist as the Customer uses and configures it, including uploading, analysing, reviewing, exporting and deleting project data, and providing requested support. The Terms, this DPA and those product actions record the Customer’s instructions.

Evalgist uses Project Personal Data only to provide, secure, support and delete Shortlist data. It does not use it for advertising or to train models made available to other customers or general-purpose models.

If EU law or the law of an EU Member State requires Evalgist to process Project Personal Data in another way, Evalgist will inform the Customer before doing so unless that law prohibits the notice. If Evalgist believes that a configured or requested use would infringe applicable data-protection law, it will inform the Customer and may decline or suspend the affected processing.

The Customer is responsible for its lawful basis, authority, notices, selection criteria, retention decisions, and other controller obligations. It must not use or configure Shortlist to process data that it is not entitled to process.

Confidentiality and security

Project Personal Data is processed automatically by Evalgist systems and the subprocessors listed in the Subprocessors register. Evalgist personnel do not routinely view project content. Any exceptional access needed for support, security, incident investigation or compliance is limited to authorised persons who need it and are bound by confidentiality.

Evalgist maintains technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. Annex 2 describes the current measures. Evalgist may update the measures as technology and the service change while maintaining protection appropriate to the risk.

Subprocessors

By accepting this DPA, the Customer authorises Evalgist to use the subprocessors listed in the published Subprocessors register. The register describes their role and known processing locations.

Evalgist will give active customers at least 30 days’ notice of a material new or replacement subprocessor. An active customer is a Customer with usable, non-expired Shortlist credits, or within 30 days after its last credits expire. Evalgist sends the notice by email to the account owner and shows the date the change takes effect in the Subprocessors register. The Customer may object within 15 days on reasonable data-protection grounds. The parties will try to resolve the concern; if they cannot, the Customer may export and delete its project data and stop using Shortlist before the change takes effect. An urgent change needed for security, availability or legal compliance may be made sooner, with notice as soon as practical.

Evalgist uses subprocessors under their applicable service and data-processing terms. Evalgist remains responsible for its use of subprocessors to the extent required by the GDPR.

International transfers

The current Subprocessors register describes the known processing locations. Project storage is in the EU, but AI processing may take place outside the European Economic Area (“EEA”) and is not represented as EU-only.

Some subprocessors may process Project Personal Data outside the EEA. Evalgist uses such subprocessors only where their applicable data-processing terms provide for the required international transfer safeguards.

Privacy requests and assistance

If Evalgist receives a request from a candidate or other data subject concerning Project Personal Data, it will pass the request to the Customer or direct the person to the Customer. Evalgist will respond only if the Customer asks it to or the law requires it.

Taking account of how Shortlist processes data and the information available to Evalgist, Evalgist will provide reasonable help with data-subject rights, security incidents, data-protection impact assessments and any consultation with a supervisory authority required by the GDPR. The Customer remains responsible for its responses, decisions and regulatory submissions.

Personal-data breaches

Evalgist will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Project Personal Data. As information becomes available, the notice will describe the known nature and scope of the breach, a contact point, likely consequences, and measures taken or proposed. Information may be provided in phases without undue further delay.

Evalgist will investigate and take reasonable containment and remediation steps within its control, including coordinating with relevant subprocessors, and will provide available information needed for the Customer’s assessment. The Customer decides whether notification to a supervisory authority or data subject is required.

Return and deletion

The Customer can export available project data through Shortlist before deleting a project or account. When ending its use of Shortlist, the Customer may export the data before deletion or delete it without an export. Deletion is irreversible.

Shortlist keeps project data while the Customer has usable credits. When the last usable credits expire, the product deletes all of the Customer’s Shortlist project data 30 days later, unless new credits are added before then. The Customer may delete a project or individual candidate earlier, and deleting the shared Evalgist account deletes all Shortlist project data.

Deletion removes the relevant Project Personal Data from active Evalgist systems. Protected backup copies may remain until overwritten in the normal backup cycle; they are isolated from normal product use and remain subject to this DPA. Evalgist may retain data where EU law or the law of an EU Member State requires it.

Invoices, payment and credit records, and minimal security, deletion or compliance records that do not preserve project content are separate from Shortlist projects and are not deleted with a project. Evalgist processes any personal data in those records as controller under the Privacy Policy.

Information and audits

On reasonable request, Evalgist will provide information needed to demonstrate compliance with this DPA and allow a proportionate audit by the Customer or an independent auditor bound by confidentiality.

Audits should begin with documents and remote evidence, avoid access to other customers’ data or security-sensitive systems, and normally occur no more than once in a 12-month period on reasonable notice. These limits do not apply after a relevant personal-data breach or where a supervisory authority requires more. The Customer bears its audit costs.

Changes and contact

Evalgist may update this DPA to reflect changes to Shortlist or applicable law and will notify active customers before a material change.

The liability, Belgian law, and jurisdiction provisions in the Shortlist Terms also apply to this DPA. Privacy questions and requests under this DPA may be sent to privacy@evalgist.ai.

Annex 1 — Processing details

Subject matter and purpose. AI-assisted evaluation of candidate and application documents against criteria chosen by the Customer, with summaries, supporting passages, broad match bands, comparisons, proposed ordering, reviewer records and exports. Processing also supports operation, security, support and deletion of the service.

Duration. Processing begins when Project Personal Data is uploaded or generated and continues until it is deleted under the product retention rules. Operations occur when the Customer uses the relevant Shortlist functions or when automated storage, security and deletion processes run.

Processing operations. Receipt, upload, storage, retrieval, OCR, parsing, text extraction, transmission for zero-data-retention AI inference, analysis, evidence extraction, summarisation, scoring support, match banding, comparison, proposed ranking, display, annotation, export, support, security logging, and deletion.

Categories of data subjects

(a) candidates, applicants, prospective employees, and prospective contractors;

(b) Customer reviewers, administrators, and other authorised account users; and

(c) referees, former employers, contact persons, and other people mentioned in submitted documents.

Types of personal data

(a) names, contact details, identifiers, photographs, and information in resumes, application forms, motivation letters, and related documents;

(b) employment history, education, qualifications, skills, experience, publications, languages, references, and other candidate claims;

(c) vacancy information, selection criteria, reviewer notes, statuses, decisions, and communications entered by the Customer;

(d) extracted text, OCR results, candidate profiles, summaries, supporting passages, assessments, scores, match bands, comparisons, and proposed rankings; and

(e) reviewer names or identifiers, project actions, and project audit information where linked to a person and processed on the Customer’s behalf.

Special categories and criminal-offence data. Shortlist does not require the Customer to provide these data, but they may appear in candidate documents or notes. The Customer should submit them only where necessary and lawful. If submitted, they are Project Personal Data under this DPA.

Locations and transfers. Project database and file storage are hosted in Ireland (AWS eu-west-1). AI requests are routed through OpenRouter with zero data retention enabled and may be processed outside the EEA. The current Subprocessors register identifies the relevant providers and known processing locations.

Retention. Project data is deleted 30 days after the last usable credits expire, unless new credits are added, or when the Customer deletes it earlier. Removing a candidate deletes that candidate’s data while leaving the remainder of the project. Account deletion removes all Shortlist project data. Backup and limited-record exceptions are described in the Return and deletion section above.

Annex 2 — Technical and organisational measures

Access and confidentiality

(a) authentication and session management through Clerk;

(b) Customer-scoped data access enforced through application-level scoping on every query, with Postgres Row Level Security policies tied to the authenticated account as a further control;

(c) no routine viewing of project content by Evalgist personnel; and

(d) exceptional administrative access limited to authorised persons for support, security, incident investigation or compliance, with confidentiality obligations.

Infrastructure and data protection

(a) dedicated Shortlist database and file-storage projects hosted in AWS eu-west-1 (Ireland);

(b) encryption in transit and at rest for hosted database, storage, authentication, and session data;

(c) centrally managed credentials distributed only to services that require them; and

(d) protected recovery copies separated from normal product use and overwritten through the normal backup cycle.

AI processing and service monitoring

(a) OpenRouter zero-data-retention routing enabled for AI requests, so requests are sent only to endpoints that OpenRouter designates as not retaining prompts and responses;

(b) product analytics configured not to receive candidate documents, extracted text, candidate names, qualification content or other project content; and

(c) error monitoring configured to exclude candidate-data routes, with Session Replay disabled.

Operational security and incidents

(a) third-party software dependencies checked for release age and integrity before deployment;

(b) reported vulnerabilities and suspected incidents investigated, with affected providers involved in containment and remediation where relevant; and

(c) security and recovery controls reviewed periodically.

Questions? Email privacy@evalgist.ai.

Last updated 2026-10-01