Värba

Asiakirja on englanninkielinen käännös. Oikeudellisesti sitova on vironkielinen versio.

Data Processing Agreement

Eesti keeles (siduv)

Effective from 20.09.2026

This is an English translation of the Estonian-language document. If the two versions differ, the Estonian version applies.

You are responsible for your candidates’ data. Värba processes it only on your behalf and on your instructions. This agreement describes what we do and do not do with the data, how we protect it and who helps us. It forms part of the Terms of Service and applies from the moment the account is created.

1. Parties and basis of the agreement

This agreement is made between the Customer (the controller) and SugarArt OÜ (registry code 16743720, “Värba”, the processor) under Article 28 of the General Data Protection Regulation (GDPR).

The agreement forms an integral part of the Terms of Service (varba.ee/en/terms) and remains in force for as long as they do. Terms have the meaning given to them in the GDPR.

2. Subject matter, purpose and duration of processing

  • Purpose: running the Customer’s recruitment using the Service — publishing job ads, receiving applications, assessing candidates, scheduling interviews and communicating with candidates.
  • Nature of processing: collecting data through the application form, storing and organising it, displaying it to the Customer’s users, sending emails, retaining and deleting it.
  • Duration: the term of the agreement and, after that, the time needed to delete the data (see section 9).

3. Data subjects and categories of data

Data subjects: candidates, the Customer’s users, and the Customer’s contact persons named in job ads and emails.

Categories of data:

  • contact details: name, email address, phone number, location;
  • CVs and other files uploaded by candidates, cover letters and answers to application form questions;
  • information added by the Customer’s users: notes, ratings, selection stage, reason for rejection;
  • interview time, place, link and participants;
  • emails exchanged with the candidate;
  • background check consent and a note of the result;
  • the wording and time of the candidate’s consent, and the language of the application.

The Service is not intended for collecting special categories of personal data (such as health data) or data relating to criminal offences. If the Customer nevertheless collects such data (for example, through a form question or a background check), the Customer is responsible for having a legal basis.

4. Processing on the Customer’s instructions

Värba processes personal data only on the Customer’s documented instructions. The instructions are this agreement, the Terms of Service and the Customer’s actions in the Service — for example, its settings, setting a retention period and deleting data. If the law requires Värba to process data in any other way, we will inform the Customer before processing, unless the law prohibits this.

If Värba considers an instruction from the Customer to be unlawful, we will inform the Customer without delay.

Värba does not use the Customer’s personal data for its own purposes, does not sell it and does not use it to train artificial intelligence models.

A Värba employee may access the Customer’s account only at the Customer’s request (for example, to resolve a support issue), to provide an agreed full service, or where this is strictly necessary to protect the security of the Service. Every such access is logged.

5. Confidentiality and security

Everyone at Värba who has access to the Customer’s personal data is bound by confidentiality.

Värba applies technical and organisational security measures in accordance with Article 32 of the GDPR. They are described in Annex 2. We may change the measures provided that the level of security does not fall.

6. Sub-processors

The Customer gives Värba general authorisation to engage sub-processors. Current sub-processors are listed in Annex 1.

We will notify the Customer by email at least 30 days before adding a new sub-processor or replacing an existing one. During that time the Customer may object on reasonable grounds. If no solution is found, the Customer may terminate the agreement before the change takes effect.

Värba enters into contracts with its sub-processors that impose equivalent data protection obligations on them, and remains liable to the Customer for the performance of those obligations.

7. Transfers outside the European Economic Area

Where a sub-processor processes data outside the European Economic Area, Värba ensures that the transfer complies with Chapter V of the GDPR — for example, on the basis of a European Commission adequacy decision (including the EU–US Data Privacy Framework) or the European Commission’s standard contractual clauses.

8. Assisting the Customer

  • Data subject requests: in the Service, the Customer can view, correct and delete candidates’ data. If a candidate contacts Värba directly, we forward the request to the Customer without delay and do not respond to it on the Customer’s behalf.
  • Breaches: if Värba becomes aware of a personal data breach, we notify the Customer without undue delay and in any event within 48 hours. The notice describes the nature of the breach, the data concerned, the likely consequences and the measures taken — as far as they are known at the time.
  • Impact assessments and prior consultation: we give the Customer the information reasonably needed about the Service and the processing.

9. Deletion of data when the agreement ends

When the agreement ends, Värba deletes the Customer’s personal data within 30 days, unless the Customer has requested an export of the data within that time. Data disappears from backups as they rotate, within 30 days at the latest. Data that the law requires us to keep is an exception.

While the agreement is in force, the Service automatically deletes candidates’ data once the retention period set by the Customer has passed.

10. Demonstrating compliance

At the Customer’s request, Värba provides the information needed to demonstrate compliance with this agreement. If that is not sufficient, the Customer may carry out an audit on at least 30 days’ notice. An audit may be carried out no more than once a year, unless there is reason to suspect a breach, and its costs are borne by the Customer.

11. The Customer’s obligations

  • The Customer has a legal basis for processing candidates’ data and has informed candidates about the processing.
  • The Customer sets the retention period for candidates’ data and does not collect more data than recruitment requires.
  • The Customer manages its users’ access and removes it from anyone who should no longer have it.
  • The Customer’s instructions to Värba comply with data protection requirements.

12. Liability

The parties’ liability is set out in the Terms of Service, taking into account Article 82 of the GDPR.

Annex 1. Sub-processors

ProviderPurposeDataLocation
Hetzner Online GmbHHosting of the application and the databaseAll data processed in the Service, except filesEU
Cloudflare, Inc.Storage of files (CVs, other attachments, logos) and of database backupsFiles uploaded by candidates. Backups also contain all data processed in the Service.EU
ResendSending emails (application confirmations, notifications, invitations, messages to candidates)Recipient’s name and email address, message contentUSA
Zoho Corporation B.V.Hosting of Värba’s own mailboxes — the addresses we use to correspond with customers and that receive support, sales and data protection enquiriesCorrespondence with us: sender’s name and email address, message content and attachments. A customer’s message may also contain candidate data if the customer includes it.EU
Anthropic PBCMachine translation of job ads and application forms, and reading candidate details from CVs during import. Both run only when the customer starts them.For translation, the text of the job ad and the form. For CV import, the whole imported file — including any candidate data in it.USA

Annex 2. Security measures

  • All connections are encrypted (HTTPS/TLS), including the application’s connection to the database, with certificate verification.
  • Passwords are stored only as hashes. Changing a password ends all other login sessions.
  • Signing in, password reset and the public application form are rate limited.
  • Candidates’ files are kept in private storage. A file can be opened only by a signed-in user whose right to that file is checked on every request.
  • Access to data is limited by organisation and role. Each organisation’s data is kept separate from the others.
  • A Värba employee’s access to a customer account is logged and lasts no more than one hour at a time.
  • A copy of the consent wording the candidate agreed to is stored with every application.
  • Candidates’ data is deleted automatically once the retention period set by the Customer has passed.
  • The database is backed up automatically every day. Backups are kept separately from the application, in private object storage in the European Union, and are deleted after 30 days.