Data Processing Agreement
Version 1.0 · Last updated: August 2, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer organization using Kendor (the “Controller”) and Kendor (the “Processor”) under our Terms of Service, into which it is incorporated by reference. It governs the processing of candidate personal data that Kendor carries out on the Controller’s behalf under Article 28 of the GDPR. If your procurement process requires a countersigned copy, email hello@kendor.io and we will provide one.
1. Subject matter, duration, nature and purpose
Kendor processes candidate personal data to run technical assessments, screening and job-application workflows on the Controller’s behalf: delivering assessments, executing and grading submitted code, capturing assessment-integrity signals the Controller has enabled, and presenting results to the Controller’s reviewers. Processing lasts for the duration of the Controller’s use of the service, plus the deletion period in Section 8.
2. Data and data subjects (Annex I)
Data subjects: candidates invited to or applying through the Controller’s assessments and job postings, and the Controller’s own platform users.
- Contact and identity data — name, email address.
- Assessment data — submitted code and answers, workspace files, test results, scores, timing.
- Assessment-integrity signals — tab switches, paste events, typing timeline, and screen recordings where the Controller enables proctoring (candidates are told what is captured before the assessment begins).
- Job-application data — the fields the Controller requests (headline, location, links, resume link, cover note, answers).
- Reviewer content about candidates — notes, comments, ratings, feedback.
No special categories of data are required by the service; the Controller agrees not to instruct Kendor to process any.
3. Instructions and confidentiality
Kendor processes candidate data only on the Controller’s documented instructions — given through the platform’s configuration (which assessments run, whether proctoring is enabled, who can review) and this DPA — unless EU or member-state law requires otherwise, in which case Kendor informs the Controller before processing unless the law prohibits it. Kendor will immediately inform the Controller if, in its opinion, an instruction infringes the GDPR. All persons authorized to process the data are bound by confidentiality obligations.
4. Security (Annex II)
Kendor implements the technical and organizational measures described in Annex II below, taking into account the state of the art and the risks of the processing (Art. 32 GDPR), and keeps them current as the platform evolves.
5. Sub-processors
The Controller grants general authorization for the sub-processors listed at kendor.io/legal/subprocessors. Kendor gives at least 30 days’ advance notice before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds and, if no alternative can be offered, terminate the affected service. Kendor imposes data-protection obligations on every sub-processor equivalent to those in this DPA and remains fully liable for their performance.
6. Assistance with data-subject rights
Kendor assists the Controller in responding to data-subject requests with built-in tooling: per-candidate erasure that removes database records and stored artifacts (submissions, recordings, playback captures), machine-readable export bundles, and automated retention sweeps. Requests reaching Kendor directly are forwarded to the Controller without undue delay.
7. Personal-data breach
Kendor notifies the Controller without undue delay after becoming aware of a personal-data breach affecting candidate data — targeting notification within 72 hours of awareness — including the information the Controller needs for its own Art. 33/34 obligations, and cooperates in the investigation and remediation.
8. Deletion and return
On termination of the service, Kendor deletes candidate personal data processed on the Controller’s behalf within 30 days, unless EU or member-state law requires longer storage. Before deletion the Controller can export its data through the platform. Deletion covers both database records and stored artifacts.
9. Audit and information
Kendor makes available the information reasonably necessary to demonstrate compliance with this DPA — this documentation, the sub-processor list, and written answers to security questionnaires — and allows for and contributes to audits conducted by the Controller or its mandated auditor, subject to reasonable notice, confidentiality, and at most once per year unless a breach or supervisory authority requires otherwise.
10. International transfers
Kendor’s infrastructure — application servers, database, code execution and artifact storage — is located in the European Union (Frankfurt, Germany). Where a sub-processor’s corporate structure could involve access from a third country, transfers are safeguarded by the EU–US Data Privacy Framework and/or Standard Contractual Clauses, as noted in the sub-processor list. Kendor will not transfer candidate data outside the EU/EEA except under a valid transfer mechanism.
Annex II — Technical and organizational measures
- EU hosting. All servers and storage are located in Frankfurt, Germany (netcup; AWS eu-central-1).
- Isolated code execution. Untrusted candidate code runs in per-session sandboxed containers on a dedicated execution host, physically separate from the application and database server. Grading re-runs execute in clean, version-pinned environments with network access cut.
- Encryption. TLS for all traffic in transit; server-side encryption at rest for stored artifacts. Storage objects are private and accessed only through short-lived signed URLs.
- Access control. Role-scoped organization membership — candidate data is visible only to the hiring organization’s authorized members; candidates access only their own sessions. Authentication uses hashed passwords, httpOnly session cookies and rotating refresh tokens.
- Data minimization in operations. Application logs mask email addresses and never contain credentials, tokens, candidate code or recording URLs. No third-party analytics or tracking scripts run on the platform.
- Retention and erasure. Automated retention sweeps delete proctoring recordings and editor-session captures 12 months after the assessment, expired invitations after 90 days and expired reset tokens after 30 days. Built-in erasure removes a candidate’s database records and stored artifacts together.
- Change management. All changes go through version control and continuous integration; production configuration and secrets never leave the production servers.
Changes and contact
Material changes to this DPA are versioned and dated, with notice to organization owners. Questions or a countersigned copy: email hello@kendor.io.