Heroify Data Processing Agreement (DPA)
How this DPA works
The DPA forms an integral part of the Platform Terms and Conditions. It is accepted together with the Terms and Conditions when the Account is created, and its acceptance is a condition of using the Platform; the version of the DPA in force on the day the Account is created applies, subject to later amendments introduced in accordance with Section 13. The DPA forms an integral part of the agreement between Heroify and the Client.
Heroify offers an individually negotiated DPA to Subscription Clients on the terms set out in the Pricing and Billing Rules (contact: gdpr@heroify.co). Individual provisions agreed in writing take precedence over this DPA and are not subject to amendment in accordance with Section 13.
This Data Processing Agreement (hereinafter: the DPA) is concluded between the Client using the Heroify platform (hereinafter: the Controller) and Heroify sp. z o.o. with its registered office in Warsaw, ul. Padewska 23/7, 00-777 Warsaw, Poland, KRS 0000903229, NIP 5213930518, REGON 389112980, share capital 35,500.00 PLN (hereinafter: the Processor or Heroify), and governs the processing of personal data of Candidates/Participants to the extent that Heroify processes such data on behalf of the Controller in accordance with Article 28 GDPR.
1. Definitions
- Controller: the Client using the Platform who determines the purposes and means of processing the data of Candidates/Participants in its recruitment or employee assessment processes, including processes conducted on behalf of its own clients.
- Processor / Heroify: Heroify sp. z o.o., which processes the data of Candidates/Participants on behalf of and in accordance with the documented instructions of the Controller.
- Candidate/Participant: an adult natural person whose data are processed through the Platform: a candidate in a recruitment process or an employee undergoing assessment.
- Personal data: information relating to Candidates/Participants processed by Heroify on behalf of the Controller, as specified in Annex 1.
- Platform: the Heroify web application available at www.heroify.co.
- Sub-processor: a third party to which Heroify entrusts the processing of personal data for the purpose of providing services to the Controller, as specified in the List of Sub-processors.
- List of Sub-processors: the list constituting Annex 2, made available to the Controller for download upon acceptance of the DPA and on request (gdpr@heroify.co), which states the name, purpose, scope of data, processing location and transfer basis of each Sub-processor.
- AI System: the elements of the Platform that use artificial intelligence, including language models, described in the AI Transparency Note (summary information: https://heroify.co/ai; the full version is made available to the Controller on request: contact@heroify.co).
- Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data (Article 4(12) GDPR).
- GDPR: Regulation (EU) 2016/679. AI Act: Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744.
2. Subject matter and scope of the entrustment
2.1 The Controller entrusts Heroify with the processing of the data of Candidates/Participants to the extent necessary to provide the Platform services: creating and conducting Assessments, collecting responses, calculating and presenting results, generating reports and summaries using the AI System, communicating with Candidates/Participants, and exporting data to and integrating with systems designated by the Controller.
2.2 A detailed description of the subject matter, nature, purpose and duration of the processing, the categories of data subjects and the categories of data is set out in Annex 1.
2.3 Heroify processes data only on documented instructions from the Controller. The following in particular are deemed to be instructions: the configuration of the Account and Assessments, making an Assessment available to Candidates/Participants, invoking Platform functions (including generating an AI summary, export and integrations) and other actions taken by the Controller or its Users through the Platform. The standard operation of the Platform in accordance with the Terms and Conditions and this DPA carries out the Controller's instruction; however, Heroify remains responsible for the lawfulness and security of the Platform itself, its default settings and the scope of data collected automatically, and may not rely on the Controller's instruction to exclude this responsibility.
2.4 If Heroify is required to process data under Union or Member State law, it shall inform the Controller of that requirement before processing, unless that law prohibits such information.
2.5 Heroify performs certain Platform functionalities as an independent controller: verification of the contact channel of Candidates/Participants (one-time e-mail/SMS codes) and integrity mechanisms, the candidate profile, the development of statistical norms, and analyses of the psychometric quality of the tools and product development carried out on pseudonymized or aggregated data. The scope, legal bases and periods of this processing are described in the Privacy Policy for Candidates/Participants (https://heroify.co/privacy-policy-candidates) and in Annex 1, Part B. This processing does not go beyond the purposes stated there.
2.6 The Controller configures the method of verifying the contact channel of Candidates/Participants (e-mail code, SMS code or both). With SMS verification, the telephone number of the Candidate/Participant is processed on behalf of the Controller as contact data visible to its Users (Annex 1A) and, in parallel, by Heroify as a controller for the purposes of the verification itself (Annex 1B).
2.7 Making a feedback report available to the Candidate/Participant (general information on the level of results, without detailed numerical scores, notes or statuses) after completion of the Assessment is a permanent function of the Platform. By accepting the DPA, the Controller instructs Heroify to perform this activity on its behalf. Heroify also makes a copy of the feedback report available to the Candidate/Participant in an individual candidate profile, which Heroify manages as an independent controller under the Privacy Policy for Candidates/Participants. The profile contains only feedback reports intended for the Candidate/Participant; it does not contain the Controller's notes, statuses or evaluations, it is not accessible to other Heroify clients or to the Controller, and it is closed at the request of the Candidate/Participant or at the latest after 12 months of inactivity (closure ends the processing for the purposes of the profile and does not cover data processed on behalf of the Controller).
2.8 The Controller may export results and share them with its clients or other recipients, and transfer them to its own systems (ATS). This is processing carried out by the Controller on its own responsibility and does not constitute a breach of the DPA. The providers of systems designated by the Controller are not Sub-processors of Heroify.
2.9 If the Controller acts as a processor on behalf of its own client, Heroify acts as a further processor (sub-processor), and the Controller represents that it holds its client's authorization for further entrustment and that it will ensure that the information required by Article 28 GDPR is provided to that client.
2.10 The Controller acknowledges and does not object to Heroify, as an independent controller, using the test results of Candidates/Participants (without first name, surname and e-mail address, with the metadata: test, language, position level, quarter) to develop statistical norms (percentiles) and to analyze the psychometric quality of the tools, in the manner, on the basis and for the periods described in Annex 1, Part B and in the Privacy Policy for Candidates/Participants. Published norms contain only aggregated data, without identifiers or links to any Candidate/Participant, Assessment or Controller. The legal basis for this processing in relation to Candidates/Participants is Heroify's legitimate interest, not the Controller's consent; the Candidate/Participant may object directly to Heroify.
3. Obligations of Heroify as Processor
Heroify undertakes to:
- process data only in accordance with the documented instructions of the Controller and for the purposes set out in Annex 1, unless the processing is required by Union or Member State law;
- ensure that persons authorized to process the data have committed themselves to confidentiality and have received data protection training;
- implement and maintain security measures in accordance with Article 32 GDPR, as described in Section 4;
- comply with the conditions for engaging Sub-processors set out in Section 5;
- assist the Controller, taking into account the nature of the processing, in responding to requests from data subjects (Chapter III GDPR), in accordance with Section 10;
- assist the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to Heroify;
- make available to the Controller all information necessary to demonstrate compliance with the obligations under Article 28 GDPR and allow for audits in accordance with Section 7;
- immediately inform the Controller if, in Heroify's opinion, an instruction infringes the GDPR or other data protection provisions;
- upon completion of the provision of services, delete or return the data in accordance with Section 9.
4. Technical and organizational security measures
4.1 Heroify has implemented and maintains technical and organizational measures appropriate to the risk, including at least: application and database infrastructure in data centers located in the European Union (processing by Sub-processors is specified in the List); encryption of data in transit and at rest; role-based access control and logical separation of the data of individual Controllers; verification of the contact channel of Candidates/Participants with a one-time code and protection against automated traffic; pseudonymization of data transmitted to the language model provider and exclusion of their use for model training; backups with a defined retention period; logging of access to data; personnel access limited to what is necessary, based on authorizations and confidentiality undertakings; incident management procedures.
4.2 Heroify may update the security measures, provided that this does not lower the overall level of protection. At the Controller's request, Heroify makes available a current description of the measures.
5. Sub-processors
5.1 The Controller grants Heroify a general authorization to engage the Sub-processors specified in the List of Sub-processors. Heroify engages only Sub-processors that provide sufficient guarantees to implement the measures under Article 32 GDPR and imposes on them, by way of a contract, data protection obligations at least equivalent to the obligations under this DPA. For each Sub-processor, the List states the name, purpose, scope of data, processing location and transfer basis.
5.2 Heroify notifies the Controller of any intended addition or replacement of a Sub-processor processing the data of Candidates/Participants by e-mail to the address associated with the Account at least 14 days before the change, stating the purpose, scope of data, location and transfer basis.
5.3 Within 14 days of the notification, the Controller may raise a reasoned objection based on specific, documented grounds relating to data protection.
5.4 Until an objection raised within the time limit and meeting the conditions of clause 5.3 is resolved, Heroify does not transfer the Controller's data to the Sub-processor concerned; if this is not technically possible without interrupting Platform functions, Heroify disables for the Controller the function that uses that Sub-processor and informs the Controller accordingly. Heroify responds to the Controller within a reasonable time and, where possible, proposes a solution (for example, permanently disabling the given function for the Controller). If no solution is possible, the Controller may terminate the agreement with 30 days' notice, without additional costs, with the right to export data in accordance with Section 9 and to a refund of a proportional part of the fees for unused units; until the end of the notice period, the Controller's data are not transferred to the Sub-processor concerned. An objection that does not meet the conditions of clause 5.3 (in particular, one not supported by grounds relating to data protection) does not suspend the change and does not entitle the Controller to terminate the agreement on that basis; Heroify provides the Controller with written reasons (by e-mail) for refusing to accept the objection.
5.5 Heroify remains fully liable to the Controller for the performance of the Sub-processors' obligations.
5.6 To generate summaries of results, Heroify uses the language model provider specified in the List, transmitting only pseudonymized data within the scope described in the List (without identification data and without the content of the Candidate's/Participant's responses). Heroify contractually ensures that these data are not used to train the provider's models. The Controller is responsible for not entering personal data of third parties into the job description.
6. Personal data breaches
6.1 Heroify notifies the Controller of a Personal data breach concerning data processed on its behalf without undue delay after becoming aware of it, where feasible no later than within 72 hours. The absence of complete information does not delay the initial notification.
6.2 The notification contains at least: a description of the nature of the breach, the categories and approximate number of data subjects and records, the contact details of the person providing information, the likely consequences, and the remedial measures taken or proposed. Information not available at the time of the initial notification is provided by Heroify in phases, without undue delay.
6.3 Heroify supports the Controller in complying with the obligations under Articles 33 and 34 GDPR by providing the information it holds about the breach.
6.4 The notification is sent to the e-mail address designated by the Controller for data protection matters (notified to gdpr@heroify.co or in the Account settings, if the Platform allows this) and, in its absence, to the address of the Account administrator. The Controller is responsible for keeping these details up to date.
6.5 Heroify documents breaches in accordance with Article 33(5) GDPR.
7. Audits and inspections
7.1 Heroify makes available to the Controller the information necessary to demonstrate compliance with the obligations under Article 28 GDPR, including this DPA, the List of Sub-processors and a description of the security measures.
7.2 At the reasoned written request of the Controller, no more than once per calendar year (and additionally after a Personal data breach concerning the Controller, upon a reasonable suspicion of a material non-compliance with the DPA, in order to verify the implementation of agreed remedial actions, or at the request of a supervisory authority), Heroify allows an audit or inspection by the Controller or an authorized external auditor bound by a duty of confidentiality. The audit is carried out at the Controller's expense, after the scope and date have been agreed with at least 30 days' advance notice (this time limit does not apply to an audit following a Personal data breach, upon a reasonable suspicion of non-compliance, or at the request of an authority), in a manner that does not disrupt the normal course of Heroify's business or the rights of other clients; the audit does not include access to the data of other clients.
7.3 The Parties may agree that the audit will be replaced by making available current reports from independent security tests or certificates, if Heroify holds them.
8. Transfers of data outside the EEA
8.1 The main infrastructure of the Platform (application and databases) is located on servers in the European Union. Processing by Sub-processors, including outside the EEA, takes place within the scope and on the bases specified in the List of Sub-processors.
8.2 If a Sub-processor processes data outside the EEA, Heroify bases the transfer on a European Commission adequacy decision (Article 45 GDPR, including the EU-US Data Privacy Framework for certified Sub-processors from the USA) or on Standard Contractual Clauses approved by the Commission (Article 46 GDPR) together with a transfer impact assessment. Heroify makes copies of the safeguards applied available to the Controller on request. The transfer basis for each Sub-processor is specified in the List.
8.3 Heroify does not transfer data to third countries without the safeguards referred to in clause 8.2.
8.4 If the Controller is established outside the EEA, the processing takes place on servers in the EU, and making the data available to the Controller constitutes a transfer to a third country. If the country in which the Controller is established is not covered by a European Commission adequacy decision (in the case of the USA: if the Controller does not hold an active certification under the EU-US Data Privacy Framework), upon acceptance of the DPA the Parties conclude the Standard Contractual Clauses adopted by Commission Decision (EU) 2021/914, Module Four (processor to controller), which constitute Annex 3 to this DPA, with Heroify as the data exporter and the Controller as the data importer; Annex 1, Part A constitutes Annex I to the clauses, and Section 4 constitutes Annex II. If the Controller instructs the transfer of data to an ATS system located outside the EEA, the Parties determine, before the integration is launched, the role of the recipient (the Controller's processor or a separate controller) and the appropriate transfer basis; Heroify does not launch the integration until the basis has been determined.
9. Duration of processing, deletion and return of data
9.1 During the term of the agreement, Heroify retains Assessment data (responses, results, reports, AI summaries, notes and statuses) until they are deleted by the Controller or until the agreement ends. Heroify may delete the data of an Assessment that expired more than 24 months earlier, after giving the Controller 30 days' notice by e-mail and enabling export. The Controller may at any time instruct the deletion of the data of an individual Candidate/Participant or of an entire Assessment by writing to gdpr@heroify.co; Heroify carries out such an instruction without undue delay, so that the Controller can meet the time limits arising from the GDPR. Self-service deletion and archiving functions are available to the extent provided on the Platform; archiving, where available, does not extend the retention period.
9.2 The end of the agreement means the closure of the Account by the Controller, termination of the service agreement (by notice or otherwise), or the closure of the Account by Heroify after 24 months of inactivity in accordance with the Terms and Conditions (§ 4.12), announced twice by e-mail. The expiry of an Assessment, the depletion of the unit balance or the end of a Subscription does not end the agreement. After the end of the agreement, Heroify retains the data for 30 days (export window). In the case of a change of provider (§ 4.14 of the Terms and Conditions), the export window lasts at least 30 days from the end of the agreed transition period, regardless of the earlier expiry of the agreement; if the migration has not been completed within the transition period, Heroify does not delete the data until the Controller decides on an extension or on ending the arrangement in accordance with § 4.14 of the Terms and Conditions. During the export window, Heroify enables export at the Controller's request submitted within that period, in CSV or another commonly used machine-readable format.
9.3 Within 45 days after the end of the export window, Heroify deletes the data processed on behalf of the Controller and their copies, including backups, with the exception of data whose retention is required by law and data covered by a specific dispute, complaint or authority proceeding concerning those data, on the Controller's instruction or to the extent that Heroify has its own legal obligation to retain them (until the matter is concluded). Heroify does not restore previously deleted data from backups for production use. The Controller may instruct the deletion of data before the end of the export window; in that case Heroify deletes them immediately and the export window expires.
9.4 Before permanently deleting results, Heroify updates only aggregated cohort statistics (count, sum, distribution of results for the given test, language, position level and quarter), retaining no individual record and no link to any Candidate/Participant, Assessment or Controller, for the purposes of the norms described in clause 2.10; the results of persons whose objection to the norms has been accepted are not included in the aggregates. Percentile norms for a given test are made available only when the comparison population is large enough that an individual result cannot be read from a percentile; the decision to make norms available for a test is taken by Heroify with the involvement of a psychometrician.
9.5 The deletion of a Candidate's/Participant's data on the Controller's instruction covers the data processed on behalf of the Controller. The copy of feedback reports in the candidate profile and the data referred to in Annex 1, Part B are subject to the rules of the Privacy Policy for Candidates/Participants and are deleted at the request of the Candidate/Participant addressed to Heroify or after the periods stated there have elapsed.
9.6 At the Controller's request, Heroify confirms that the deletion has been carried out.
10. Exercise of data subject rights
10.1 The Controller is responsible for enabling Candidates/Participants to exercise their rights under the GDPR with respect to data processed on its behalf.
10.2 Where Heroify receives a request directly from a Candidate/Participant concerning data processed on behalf of the Controller, it forwards the request to the Controller without undue delay and informs the data subject accordingly; it does not respond on behalf of the Controller without the Controller's authorization.
10.3 Heroify provides the Controller with technical assistance in the exercise of rights, in particular by: exporting a Candidate's/Participant's data, deleting the data of an individual Candidate/Participant on instruction (Section 9.1), providing insight into the factors taken into account in the result (for the purpose of explaining the role of the AI System), and making the feedback report available to the Candidate/Participant.
10.4 Requests concerning data for which Heroify is an independent controller are handled by Heroify itself, and Heroify informs the Controller of this if the request also concerns the Controller's process.
11. Cooperation under the AI Act
11.1 Heroify is the provider and the Controller is the deployer of the AI System within the meaning of the AI Act. The rules for using the AI System, its limitations and the obligations of the deployer are described in the AI Transparency Note, made available to the Controller on request (contact@heroify.co); § 6 of the Terms and Conditions sets out the Controller's obligations in this regard.
11.2 With respect to data protection, Heroify: does not use the data of Candidates/Participants to train models; informs the Controller of material changes to the AI System affecting the processing of data; at the Controller's request, provides a description of the factors taken into account in the result, needed to give the Candidate/Participant an explanation of the role of the AI System in the decision.
11.3 The Controller does not configure its own systems (including ATS) so that they automatically reject Candidates/Participants on the basis of a score, ranking or trust indicator without human review.
12. Liability
12.1 Each Party is liable to data subjects for damage caused by processing that infringes the GDPR to the extent that it is responsible for such damage (Article 82 GDPR). The provisions of this Section govern only the settlement between the Parties and do not limit the rights of data subjects or the powers of the supervisory authority.
12.2 Heroify is exempt from liability towards the Controller if it is not at fault for the damage or acted in accordance with the Controller's instructions (in particular where the damage results from a configuration made by the Controller, content entered by its Users or the manner in which the results were used), subject to any liability that cannot be excluded under mandatory provisions of law. The exemption does not cover Heroify's liability for its own obligations set out in clause 2.3 (lawfulness and security of the Platform, its default settings and the scope of data collected automatically) or for a breach of this DPA.
12.3 Heroify's total liability to the Controller under the DPA, with the exception of damage caused intentionally or through gross negligence and liability arising from processing by Heroify outside the scope of or contrary to the Controller's instructions, is limited to the total fees paid by the Controller in the 12 months preceding the event giving rise to the damage. The Parties may agree a different limitation amount in the Service Agreement.
13. Amendments to the DPA
13.1 Heroify may amend the DPA for important reasons: changes in legal provisions or in the guidelines of supervisory authorities; changes to the List of Sub-processors (in accordance with Section 5); changes to Platform functions affecting the processing of data; and also to the extent that the amendment does not lower the level of data protection or the rights of the Controller.
13.2 Heroify notifies the Controller of each amendment by e-mail at least 14 days before it takes effect, stating the scope of the changes.
13.3 Continued use of the Platform after an amendment takes effect constitutes its acceptance. A Controller who does not accept an amendment may terminate the agreement before it takes effect, with the right to export data in accordance with Section 9 and to a refund of a proportional part of the fees for unused units on the terms set out in the Pricing and Billing Rules (Section 6). Upon the Controller's next purchase, the Controller is bound by the version of the DPA applicable to its Account in accordance with this Section; the purchase itself does not replace the notification and objection procedure and does not override an individual DPA.
13.4 Provisions individually agreed in writing are not subject to amendment in accordance with this Section.
14. Cooperation with the supervisory authority
14.1 In the event of a complaint or proceedings of a supervisory authority concerning the data of Candidates/Participants, the Parties inform each other and cooperate in order to clarify the matter.
15. Final provisions
15.1 The DPA is governed by Polish law and is interpreted in accordance with the GDPR. In the event of a discrepancy with the English version, the Polish version prevails.
15.2 In matters not regulated herein, the Platform Terms and Conditions (https://heroify.co/terms) and the Service Agreement, if concluded, apply.
15.3 In the event of a conflict between the DPA and the Terms and Conditions, the DPA takes precedence in data protection matters. The provisions of the Service Agreement or of an individually agreed DPA take precedence over this DPA.
15.4 The DPA remains in force for the term of the service agreement and, with respect to Section 9, until the data have been deleted or returned.
15.5 The Parties will endeavor to resolve disputes amicably; failing agreement, the court having jurisdiction over Heroify's registered office is competent.
15.6 The invalidity of one provision does not affect the validity of the remaining provisions.
15.7 Contact for DPA matters: gdpr@heroify.co.
ANNEX 1: Description of the processing
Part A. Data processed by Heroify on behalf of the Controller (Article 28 GDPR)
Subject matter: provision of the Platform services: creating and conducting Assessments that evaluate the competencies, abilities, fit and attitude of Candidates/Participants.
Nature of the processing: collection, recording, organization, storage, calculation of results, automated analysis of results using a language model in order to generate a summary supporting the User, presentation, disclosure within the Platform and on the Controller's instruction (export, ATS), restriction, deletion. Exclusively by electronic means, through the Platform.
Purpose: conducting the Assessments commissioned by the Controller, presenting the results to the Controller and its Users, making the results available to Candidates/Participants on the Controller's instruction, and enabling the exercise of data subject rights.
Duration: for the term of the agreement, until the data are deleted by the Controller; the export window and the deletion deadline after the end of the agreement, as well as Heroify's right to delete the data of Assessments that expired more than 24 months earlier, are set out in Section 9.
Categories of data subjects: candidates taking part in recruitment processes conducted by the Controller, including on behalf of the Controller's clients; employees and contractors of the Controller undergoing assessments. Adults only.
Categories of data:
- Identification and contact data: first name, surname, e-mail address, telephone number (with SMS verification); the candidate's identifier in the Controller's ATS system, if integrated.
- Responses: responses to closed questions (tests), responses to open questions, attachments.
- Results: test and scale scores, overall score, percentiles, competency reports, the summary generated by the AI System, statuses and notes assigned by the Controller's Users, the trust indicator label together with its explanation made available to Users (events in the browser window and response times), stored in the same way as the other results.
- Communication data: the content and delivery status of e-mail messages sent to Candidates/Participants on behalf of the Controller.
Special categories of data (Articles 9 and 10 GDPR): the Controller does not instruct Heroify to intentionally collect special categories of data or data relating to criminal convictions and offences, and does not formulate open questions aimed at obtaining them. If a Candidate/Participant discloses such data on their own initiative in an open response or attachment, Heroify stores them solely as part of the response on behalf of the Controller, does not use them to calculate results, does not transmit them to the language model provider (the content of responses is not transmitted) and does not allow searching by them. Once such a disclosure has been identified (by a User of the Controller or by Heroify), Heroify, on the Controller's instruction, restricts access to the response or attachment concerned to the persons who need it, and if Heroify identifies the disclosure itself, it informs the Controller and asks for instructions. The Controller is responsible for assessing the basis for further processing and may instruct the deletion or redaction of the indicated fragment, file or entire response; Heroify carries out the instruction without undue delay. Heroify does not perform automated detection of such content. Data relating to criminal convictions and offences (Article 10 GDPR) are treated under the same rules, separately from data under Article 9.
Part B. Data processed by Heroify as an independent controller (for information)
Beyond the entrustment, Heroify processes as an independent controller, on the basis of Article 6(1)(f) GDPR and after carrying out a balancing test: (1) contact channel verification data (use of the telephone number to send the code with SMS verification, records of codes sent) and technical session data used to calculate the trust indicator (IP address, device and browser type), for 6 months from the end of the session; the indicator itself and its explanation (events in the browser window, response times), once calculated, become part of the result processed on behalf of the Controller (Part A); (2) the candidate profile (identification data, login data, copy of feedback reports), until the profile is closed or for 12 months from the last login (from creation, if the candidate has never logged in); (3) test and scale scores without identification data, with the metadata test, language, position level and quarter, for the purposes of statistical norms and analyses of the psychometric quality of the tools (including with the involvement of the analytics tools provider specified in the List), for no longer than the data of the Assessment from which they originate, and thereafter only aggregates. An objection by a Candidate/Participant accepted by Heroify excludes their data from the norms and analyses. Details: the Privacy Policy for Candidates/Participants. Heroify does not use these data for any other purposes, in particular not to evaluate Candidates/Participants on behalf of other clients or for marketing purposes.
ANNEX 2: List of Sub-processors
The List of Sub-processors in the version dated 22 September 2026 constitutes an annex to this version of the DPA. Heroify makes it available to the Controller for download upon acceptance of the DPA and on request (gdpr@heroify.co), and notifies the Controller of changes in accordance with Section 5.
ANNEX 3: Standard Contractual Clauses, Module Four
The Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Four (transfer from processor to controller), as published in the Official Journal of the EU, are incorporated into the DPA by reference and apply in the cases specified in clause 8.4. Optional choices: Clause 7 (docking clause) applies; Clause 11(a): the option of an independent dispute resolution body does not apply; Clause 17: Polish law; Clause 18: Polish courts. Annex I.A (parties): Heroify sp. z o.o. as data exporter, the Controller as data importer, with the details from the Account. Annex I.B (description of the transfer): Annex 1, Part A. Annex II (technical and organizational measures): Section 4 of the DPA. Full text of the clauses: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj.