pr

Data Processing Addendum

Version 1.0 · Effective July 10, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Use between Logical Pure Minds SRL, a company registered in Romania under Trade Registry number J33/1494/2020, VAT RO43302770, with its registered office at Strada Lazăr Vicol nr. 15, bl. E37, sc. A, ap. 47, Suceava 720245, Romania (“LinkMatch”, “we”, “us”), and the customer entity that has agreed to those Terms (“Customer”, “you”).

This DPA applies automatically from the moment you use the Services. No signature is required. If your procurement process needs a countersigned copy, email [email protected] and we will return one.

Capitalised terms not defined here have the meaning given in the Terms of Use. “GDPR” means Regulation (EU) 2016/679, and where applicable the UK GDPR and the Data Protection Act 2018. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR.


1. Roles of the parties

1.1 In relation to Customer Personal Data (defined in Annex I), the Customer acts as Controller and LinkMatch acts as Processor. Where the Customer is itself a Processor acting for a third party controller, LinkMatch acts as sub-processor and the Customer warrants that it has the authority to give the instructions set out in this DPA.

1.2 In relation to account, billing and website data about the Customer’s own personnel, LinkMatch acts as an independent Controller. That processing is governed by our Privacy Policy, not by this DPA.

1.3 Each party is responsible for its own compliance with applicable data protection law.

2. Scope and instructions

2.1 LinkMatch will Process Customer Personal Data only on the Customer’s documented instructions, including in relation to transfers to a third country, unless required to do otherwise by Union or Member State law. Where such a legal requirement applies, LinkMatch will inform the Customer before Processing, unless that law prohibits it on important grounds of public interest.

2.2 The Terms of Use, this DPA, and the Customer’s use of the Services through its configuration settings and in-product actions together constitute the Customer’s complete documented instructions. Any other instruction must be agreed in writing and may be subject to additional charges where it requires work outside the standard Services.

2.3 LinkMatch will immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

2.4 LinkMatch will not sell Customer Personal Data, disclose it for cross-context behavioural advertising, retain or use it outside the direct business relationship with the Customer, or use it to train machine learning or artificial intelligence models.

3. Customer obligations

3.1 The Customer is responsible for the lawfulness of the Personal Data it Processes through the Services, including:

(a) establishing and documenting a lawful basis under Article 6, and where special category data such as health, ethnicity or trade union membership appears in a profile or CV, a condition under Article 9;

(b) providing the information required by Article 14 to Data Subjects whose Personal Data it obtains through the Services, generally within one month of obtaining the data or at the point of first contact if that is sooner;

(c) responding to Data Subject requests addressed to it;

(d) complying with the terms of use of any third party platform from which it obtains data.

3.2 The Customer will not upload or Process through the Services any Personal Data that is outside the categories described in Annex I without first notifying LinkMatch, and will not Process special category data through the Services as a routine or bulk activity.

4. Confidentiality

LinkMatch will ensure that every person authorised to Process Customer Personal Data is bound by an appropriate obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement. Access is granted on a least privilege basis and only where necessary to provide, secure or support the Services.

5. Security

5.1 LinkMatch will implement and maintain appropriate technical and organisational measures under Article 32, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing. The measures in place as at the effective date are described in Annex II.

5.2 LinkMatch may update those measures over time provided the overall level of protection is not reduced.

6. Sub-processors

6.1 The Customer gives general written authorisation for LinkMatch to engage sub-processors, subject to this clause.

6.2 The sub-processors engaged as at the effective date are listed in Annex III. The current list is available to the Customer at any time on request to [email protected].

6.3 LinkMatch will give at least 30 days’ notice by email, sent to the Customer’s registered account contact, of any intended addition or replacement of a sub-processor that Processes Customer Personal Data. It is the Customer’s responsibility to keep that contact address current.

6.4 The Customer may object on reasonable data protection grounds within 30 days of the notice, by writing to [email protected] with its reasons. The parties will discuss the objection in good faith. If LinkMatch cannot offer a reasonable alternative, the Customer may terminate the affected Services without penalty and receive a pro rata refund of prepaid fees for the unused period.

6.5 LinkMatch will impose on each sub-processor data protection obligations that are no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor’s obligations.

7. International transfers

7.1 Customer Personal Data is hosted in the European Union, save that OpenAI, engaged for the AI-assisted features described in Annex III, Processes data in the United States. On request, and subject to the applicable commercial terms of the Customer’s plan, LinkMatch will arrange for that Processing to be carried out within the European Union. LinkMatch will not otherwise transfer Customer Personal Data outside the European Economic Area except as described in Annex III or with the Customer’s agreement.

7.2 Where a transfer to a third country does occur, LinkMatch will ensure it is covered by an adequacy decision, by the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914, or by another valid Article 46 safeguard.

7.3 Where the Standard Contractual Clauses apply, they are incorporated into this DPA and completed as follows: Module Two (controller to processor) applies where the Customer is a Controller, and Module Three (processor to sub-processor) applies where the Customer is a Processor. The optional docking clause in Clause 7 applies. In Clause 9, Option 2 (general written authorisation) applies with the notice period in section 6.3 above. In Clause 11, the optional independent dispute resolution wording does not apply. In Clause 17, the governing law is the law of Romania. In Clause 18(b), the forum is the courts of Romania. Annexes I, II and III to this DPA populate Annexes I, II and III to the Standard Contractual Clauses.

7.4 For transfers subject to UK data protection law, the UK International Data Transfer Addendum (version B1.0) to the Standard Contractual Clauses applies, with Tables 1 to 4 populated by the corresponding information in this DPA and Annex I. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Swiss Federal Data Protection and Information Commissioner.

8. Personal Data Breach

8.1 LinkMatch will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event within 48 hours of becoming aware.

8.2 The notification will describe, to the extent known at the time: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. Where the information cannot be provided at once, LinkMatch will provide it in phases without undue further delay.

8.3 LinkMatch will provide reasonable assistance to the Customer in meeting its own obligations under Articles 33 and 34. LinkMatch will not notify a Supervisory Authority or any Data Subject on the Customer’s behalf unless the Customer asks it to or the law requires it.

8.4 Notification under this clause is not an acknowledgement of fault or liability.

9. Assistance to the Customer

9.1 Data Subject requests. Taking into account the nature of the Processing, LinkMatch will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests to exercise Data Subject rights under Chapter III of the GDPR. Where LinkMatch receives such a request directly, it will not respond substantively and will refer the Data Subject to the Customer, informing the Customer without undue delay.

9.2 Other assistance. LinkMatch will provide reasonable assistance with data protection impact assessments and prior consultation under Articles 35 and 36, and with the Customer’s obligations under Article 32, taking into account the nature of the Processing and the information available to LinkMatch.

9.3 LinkMatch may charge a reasonable fee for assistance that goes materially beyond the functionality of the Services, and will tell the Customer before incurring it.

10. Audits and information

10.1 LinkMatch will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

10.2 The Customer will exercise this right by first requesting LinkMatch’s current security documentation, questionnaire responses and any third party certifications or reports. Where those do not reasonably satisfy the Customer, the Customer may request an on-site or remote audit, on at least 30 days’ written notice, no more than once in any twelve month period, during normal business hours, subject to confidentiality obligations, and in a manner that does not disrupt LinkMatch’s operations or compromise the confidentiality of other customers’ data. The Customer bears its own costs and LinkMatch’s reasonable costs.

10.3 The once per year limit does not apply where an audit is required by a Supervisory Authority or follows a confirmed Personal Data Breach affecting the Customer.

11. Deletion and return

11.1 On termination or expiry of the Services, LinkMatch will, at the Customer’s choice, delete or return all Customer Personal Data, and delete existing copies, unless Union or Member State law requires it to be stored.

11.2 The Customer may export its data at any time using the functionality of the Services, or by written request within 30 days of termination. After that period LinkMatch will delete Customer Personal Data in accordance with the retention periods in Annex II.

11.3 Deletion takes effect in live systems on request and propagates through backups within the backup rotation cycle described in Annex II. Data held in backups remains subject to this DPA until it is overwritten.

11.4 Deletion propagates to the matching cache described in Annex II. LinkMatch removes cached records when the corresponding CRM record is deleted, when the Customer disconnects the CRM integration, on termination, and when the Customer actions a Data Subject erasure request.

12. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Use. Nothing in this DPA limits liability that cannot be limited under applicable law, including the liability of either party to a Data Subject under Article 82.

13. Term, precedence and governing law

13.1 This DPA takes effect when the Customer first uses the Services and continues until all Customer Personal Data has been deleted or returned.

13.2 In the event of conflict, the order of precedence is: the Standard Contractual Clauses, then this DPA, then the Terms of Use.

13.3 This DPA is governed by the laws of Romania and the parties submit to the exclusive jurisdiction of the Romanian courts, without prejudice to any Data Subject’s rights under Articles 79 and 82 of the GDPR.

13.4 If any provision is held invalid, the remainder continues in force.


Annex I: Description of the Processing

A. Parties

Data exporter (Controller): the Customer, as identified in its LinkMatch account. Contact: the account administrator’s email address on file. Activities: use of the LinkMatch Services for recruitment or sales purposes.

Data importer (Processor): Logical Pure Minds SRL, Strada Lazăr Vicol nr. 15, bl. E37, sc. A, ap. 47, Suceava 720245, Romania. Contact: [email protected]. Activities: provision of the LinkMatch browser extension and CRM synchronisation service.

B. Description

Subject matter. Provision of the LinkMatch browser extension, which matches profile information viewed by the Customer’s users on supported professional networking platforms (the “Supported Platforms”) against records in the Customer’s connected CRM or ATS, and writes selected fields to that CRM or ATS at the user’s direction.

Duration. For the term of the Terms of Use, plus the deletion period in section 11.

Nature and purpose. Retrieval, matching, structuring, temporary storage, transmission and deletion of Personal Data, for the purpose of enabling the Customer to maintain records in its CRM or ATS.

Categories of Data Subjects.

  • Candidates and prospective candidates
  • Business contacts, prospects and leads
  • The Customer’s own personnel who use the Services

Categories of Personal Data.

  • Identity: name, photograph, profile URL
  • Contact: email address, telephone number, location
  • Professional: current and previous job titles, employers, dates, education, skills, certifications, languages
  • Any free-text notes, tags or custom field values the Customer’s users choose to record
  • Technical: user account identifier, IP address, timestamps of sync actions

Special category data. Not intentionally Processed. The Customer is responsible for any special category data that appears in free text or profile content, and for having an Article 9 condition for it.

Frequency. Continuous, on the initiative of the Customer’s users.

Retention. As set out in Annex II.

Sub-processors. As set out in Annex III, for the duration and purposes described there.

C. Competent Supervisory Authority

The National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28 to 30, Sector 1, 010336 Bucharest, Romania. Where the Standard Contractual Clauses apply, the competent authority is determined in accordance with Clause 13.


Annex II: Technical and organisational measures

Encryption

  • HTTPS only. TLS 1.2 or above for all data in transit
  • Encryption at rest for CRM credentials, OAuth tokens and cached records
  • Passwords stored only as salted hashes

Access control

  • Role based access control on a least privilege basis
  • Multi factor authentication on administrative and production systems
  • Access to production systems logged and reviewed
  • Access revoked promptly on change of role or departure

Data location and segregation

  • All Customer Personal Data hosted in the European Union
  • Logical separation of customer data

Resilience and recovery

  • Encrypted backups taken daily, retained on a 7 day rotation before being overwritten
  • Restore procedures tested quarterly

Retention

  • Matching cache: profile fields are stored on LinkMatch servers in the EU for 7 days from first storage. The cache is isolated per Customer: data cached for one Customer is never served to another, and profile data is never combined across Customers. Expiry is absolute and is not renewed when a record is accessed again. The cache is deleted immediately on disconnection of the CRM integration or closure of the account, and individual records are removed when the corresponding CRM record is deleted or an erasure request is actioned.
  • Application and security logs: 90 days, retained for security monitoring, incident investigation and debugging. These record account identifiers, IP addresses, endpoints, timestamps and error codes, and do not contain profile or CRM record content
  • Support tickets: 365 days from resolution
  • Customer Personal Data on termination: deleted within 30 days, subject to backup rotation

Organisational

  • Confidentiality obligations binding on all personnel with access to Personal Data
  • Security review of every sub-processor before engagement
  • Vulnerability scanning quarterly
  • Documented incident response procedure with a 48 hour customer notification commitment
  • Security contact: [email protected]

Annex III: Sub-processors

The sub-processors engaged as at the effective date, with their purpose, entity, location and transfer safeguard, are set out in the LinkMatch Sub-processor List, version 1.0 dated 10 July 2026, which forms part of this Annex and is provided to the Customer on request to [email protected].

Categories engaged: application hosting and managed database; content delivery and network security; payment processing; transactional email; marketing email; customer support; meeting scheduling; website analytics; advertising measurement; and AI processing for certain product features.

AI processing. The AI-assisted features of the Services are provided using OpenAI (OpenAI Ireland Ltd, with OpenAI, L.L.C. in the United States), currently the GPT-5.2 model. Processing takes place in the United States under the EU-US Data Privacy Framework and the Standard Contractual Clauses. OpenAI does not train its models on data submitted through its API. Processing within the European Union is available on request, subject to the commercial terms of the Customer’s plan.

Changes are notified by email at least 30 days in advance in accordance with section 6.3.


Questions about this DPA: [email protected]