Skip to main content

Legal

Data Processing Agreement

Article 28 GDPR · Australian Privacy Principles. This DPA is incorporated into the Scorafy Terms of Service and is binding when you accept those Terms - no separate signature is required.

Last updated: 27 September 2026

This Data Processing Agreement ("DPA") forms part of the Scorafy Terms of Service (the "Agreement") and governs how Cognitiv Pty Ltd (ACN 688 133 977), trading as Scorafy ("Scorafy", "we", the "Processor"), processes Personal Data on behalf of a customer ("you", the "Customer" or "Controller") who uses the Scorafy platform. By accepting the Terms of Service, you agree to this DPA.

1. Definitions

"Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Sub-processor", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). Where you or your Data Subjects are in Australia, equivalent terms under the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs") apply with corresponding meaning.

"Customer Personal Data" means Personal Data that Scorafy Processes on your behalf under the Agreement, including assessment respondents' answers, names, email addresses, and any audio/video responses and uploaded files.

2. Roles of the parties

You are the Controller of Customer Personal Data. Scorafy is the Processor and Processes Customer Personal Data only on your documented instructions, including the instructions in the Agreement, this DPA, and the configuration you select in the platform (for example, assessment design, response-capture settings, and retention period). For respondent data, you (as the account holder creating the assessment) are the Controller; Scorafy is the Processor under Article 28 GDPR and an equivalent processor obligation under the APPs.

3. Scope and purpose of processing

Subject matterProvision of the Scorafy AI assessment platform.
DurationThe term of the Agreement, plus the retention period in clause 7.
Nature and purposeHosting assessments; collecting respondent answers; AI analysis of open-ended responses against your rubric; human-in-the-loop scoring; report generation and delivery; account and team management.
Types of Personal DataRespondent name, email address, free-text answers, optional audio/video responses, optional uploaded documents (e.g. resumes); account-holder name and email.
Categories of Data SubjectsYour assessment respondents (e.g. candidates, learners, employees) and your authorised users.
Special categoriesScorafy does not require special-category data. Audio/video responses may constitute biometric data; you control whether these capture modes are enabled per assessment, and can switch them off for your whole organisation.

4. Processor obligations

Scorafy shall:

  • Process Customer Personal Data only on your documented instructions, including for international transfers, unless required by law (in which case we will notify you unless legally prohibited);
  • ensure persons authorised to Process Customer Personal Data are bound by confidentiality;
  • implement the technical and organisational measures in Schedule 2;
  • respect the conditions in clause 6 for engaging Sub-processors;
  • assist you, taking into account the nature of Processing, in responding to Data Subject requests (clause 5);
  • assist you with security, breach notification, data protection impact assessments, and prior consultation (Articles 32–36 GDPR);
  • at your choice, delete or return all Customer Personal Data at the end of the Agreement, and delete existing copies unless storage is required by law;
  • make available information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits (clause 9);
  • not use Customer Personal Data to train any AI model. Scorafy does not use Customer Personal Data to train any AI model. Anthropic's commercial terms prohibit training on customer content; for Deepgram, Scorafy opts every request out of Deepgram's model-improvement programme.

5. Data Subject rights

Scorafy will, taking into account the nature of the Processing, assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to Data Subject rights requests (access, rectification, erasure, restriction, portability, objection). The platform provides configurable PII retention (30/90/180/365-day windows, or indefinite retention where no window is configured - the default) and respondent anonymisation to support this directly. Owners and admins can also permanently delete an individual response, or an assessment with all of its responses, reports and files, in the platform; any other erasure is fulfilled on request.

6. Sub-processors

You provide general authorisation for Scorafy to engage the Sub-processors listed in Schedule 1. Scorafy imposes data-protection obligations on each Sub-processor that are materially equivalent to those in this DPA by written contract; remains liable to you for each Sub-processor's performance; and will give you at least 30 days' prior notice by email, and on scorafy.com/gdpr, before adding or replacing a Sub-processor (including any change of AI provider or AI inference region). You may object on reasonable data-protection grounds within that period. If we cannot offer a reasonable alternative, you may terminate the affected service and we will refund prepaid fees for the unused period.

7. Retention and deletion

Customer Personal Data is retained for the period you configure per assessment (PII retention setting). Where a retention window is configured, respondent personally identifying information is anonymised automatically after that window; where no window is configured (the default), it is retained for the life of the account and remains subject to erasure on request. On termination, Scorafy will delete or return Customer Personal Data in line with clause 4 and the "Effect of termination" provisions of the Terms (30-day export window; deletion of Customer Personal Data, including copies, within 60 days of termination; backup copies expire within 30 days). Before deletion, Scorafy keeps a minimised copy of the organisation's audit log (record identifiers, action names and timestamps only, with no names, email addresses or content), encrypted, for 24 months as a security record, and then deletes it.

8. International transfers

Customer Personal Data is stored in the European Union (Supabase, Dublin, Ireland), or in Australia (Sydney) where you have elected Australian hosting. Certain Sub-processors (Schedule 1) Process Personal Data in transit in the United States or other jurisdictions, and encrypted nightly backup copies are held by GitHub in the United States for up to 30 days. Where Personal Data is transferred outside the EEA or the UK, the transfer is governed by the European Commission's Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum where applicable, incorporated into each Sub-processor's own data-processing terms. For Australian Customers, Scorafy takes reasonable steps to ensure each overseas recipient handles Personal Data consistently with the APPs.

Material disclosure (AI processing). AI analysis (Anthropic) and audio/video transcription (Deepgram) are performed on United States-based models. Data is processed in transit and is not used for model training, but there is currently no Australian or EU model-hosting region for these functions. You acknowledge this where you enable AI analysis or audio/video response capture.

9. Audit

9.1 Scorafy will make available the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, including its Security Documentation, Sub-processor Register and completed security questionnaires.

9.2 If that information does not reasonably satisfy you, you (or an independent auditor bound by confidentiality who is not a competitor of Scorafy) may audit Scorafy's compliance on at least 30 days' written notice, no more than once in any 12-month period, unless required by a Supervisory Authority or following a Personal Data Breach affecting your data. Audits are conducted remotely and document-first unless an on-site element is strictly necessary, during business hours, and without access to other customers' data. Each party bears its own costs.

9.3 Scorafy relies on its Sub-processors' independent certifications and reports for their facilities; audits of Sub-processors are conducted through those reports.

10. Personal Data Breach

Scorafy will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide the information you reasonably require to meet your own notification obligations.

11. General

This DPA forms part of and is subject to the Agreement. In the event of conflict on data-protection matters, this DPA prevails. It is governed by the law stated in the Agreement. Nothing in this DPA excludes or limits any non-excludable right or remedy under the Australian Consumer Law.

Schedule 1 - Sub-processors

As at 27 September 2026. "DPF" is the EU-US Data Privacy Framework (checked on the official list on 27 September 2026); where a provider is not listed, EU transfers rely on the Standard Contractual Clauses (2021/914) and, for UK data, the UK Addendum.

Sub-processorPurposeLocationTransfer mechanism
Supabase (Supabase Pte. Ltd.; infrastructure on AWS)Database, authentication, file storage (primary data store)Dublin, Ireland, or Sydney, Australia for Australian-residency customersSCCs + UK Addendum
Anthropic PBCAI analysis of answers against your rubric; report generation. Not used to train models.United StatesSCCs + UK Addendum
Vercel Inc.Application hosting and serverless functions; edge deliveryFunctions: Dublin, Ireland (EU) or Sydney, Australia (AU). Edge: globalDPF + SCCs
Plus Five Five, Inc. (Resend)Transactional emailUnited StatesDPF + SCCs
Deepgram, Inc.Speech-to-text for audio/video answers, only where an assessment uses them; can be switched off for a whole organisation. Every request is opted out of Deepgram's model-improvement programme.United StatesDeepgram's data processing terms (SCC-based DPA available from Deepgram); engaged only where a customer enables spoken answers
StripeSubscription billing and payment processingUnited States / Ireland / AustraliaDPF + SCCs
GitHub, Inc.Source code hosting and CI; stores encrypted nightly database backup artifacts, deleted after 30 daysUnited StatesDPF + SCCs
Google LLCWeb analytics (GA4) on marketing pages only, after analytics-cookie consent. Never assessment, response or report data.United StatesGoogle Ads Data Processing Terms

Schedule 2 - Technical and organisational measures

  • Tenant isolation: every user belongs to an organisation; all Customer data is row-level-security (RLS) scoped by organisation. No cross-organisation read path exists.
  • Access control: role-based access within each organisation (Owner / Admin / Member / Assessor / Viewer); only the organisation's authorised users can access its data.
  • Encryption: data encrypted in transit (TLS 1.2+) and at rest (AES-256, Supabase/AWS managed); webhook signing secrets additionally encrypted by the application (AES-256-GCM).
  • Authentication: email/password with verification, optional authenticator-app multi-factor authentication (TOTP) that owners and admins can make mandatory for the whole organisation, and managed invite links for team members.
  • Audit trail: significant organisation actions, including exports of respondent data and deletions, are recorded with actor and timestamp in an append-only log.
  • Data minimisation: only the data needed to run an assessment is collected; PII retention is configurable per assessment with automated anonymisation; owners and admins can anonymise a respondent, or permanently delete a response or an assessment, at any time; audio and video responses can be switched off for the whole organisation.
  • Backups: nightly, encrypted before storage, kept 30 days, with documented restore testing.
  • Human-in-the-loop: AI scores are reviewable and overridable by a qualified assessor before a result is finalised.
  • Secure development: automated dependency-vulnerability and static-analysis scanning on every change; an internal authorisation/isolation test suite.
  • Sub-processor contracts: each Sub-processor is engaged under its own data-processing terms incorporating SCCs where relevant.
  • Breach response: documented notification process per clause 10 (72-hour notification).

Our Security and Data Pack is available on request at scorafy.com/trust.

Questions about this DPA or our data practices: adam@scorafy.com.