MAGNET.ME DATA PROCESSING AGREEMENT

Revision: 2026.07.15.01

This Data Processing Agreement forms an integral part of the Agreement between Magnet.me NL B.V. and Client. The capitalised terms used in this DPA have the meaning given to them in the Client TOS unless defined otherwise in this DPA.

Whereas

A. This DPA applies only where Magnet.me processes Personal Data as processor on behalf of Client. Magnet.me also processes certain personal data as sole independent controller for its own purposes. Such processing is not processing on behalf of Client and is not governed by this DPA, but is governed by Magnet.me’s Privacy Policy.

B. Magnet.me acts as sole independent controller for, among other things: (i) personal data of Client contact persons and Users processed for account administration, platform security, authentication, contract management, billing, customer relationship management, support administration, enforcement of the Agreement, legal requests, fraud prevention, abuse prevention and platform integrity; (ii) personal data of Members processed in relation to their own Magnet.me account, profile, Platform use, matching, recommendations, communications with Magnet.me, platform analytics, security and service improvement; (iii) personal data processed for moderation, security, fraud prevention, abuse prevention, legal compliance, dispute handling and protection of the lawful operation of the Platform; and (iv) limited Disposition Data processed for Magnet.me’s own product analytics, matching improvement, recommendation improvement, security, fraud and abuse prevention and service improvement purposes, subject to the limitations, safeguards and opt-out mechanism set out in the Client TOS and Privacy Policy.

C. For the avoidance of doubt, Company Connect Data and ATS-derived data processed before an individual activates or creates a Magnet.me account are processed by Magnet.me as processor on behalf of Client, as described herein. If the individual activates or creates a Magnet.me account, Magnet.me acts as sole independent controller for the Member account, profile and Platform usage data in accordance with Magnet.me’s Privacy Policy and Member Terms of Service.

D. The parties lay down their respective rights and obligations with respect to the processing of Personal Data by Magnet.me as processor in this DPA.

1. General

1.1 In this DPA, "Personal Data" means personal data processed by Magnet.me as processor on behalf of Client for the processing activities described herein.

1.2 Magnet.me shall process Personal Data only for the purpose of providing the Services requested or enabled by Client and in accordance with the Agreement, this DPA and Client’s documented instructions.

1.3 The processing activities described herein apply only to the extent the relevant Service is enabled, requested or specified in the Order Summary. The DPA itself is not customer-specific; the applicable Services are determined by the Order Summary and the Services enabled by Client.

2. Compliance by Client and Mutual Data Protection Indemnity

2.1 Each party is responsible for compliance with applicable Data Protection Laws within its own role and sphere of control. Client is responsible for complying with applicable Data Protection Laws in relation to Personal Data for which Client acts as controller and in relation to the instructions, Personal Data and other information made available to Magnet.me for processing on behalf of Client. Client shall ensure that it is entitled to provide such Personal Data and instructions to Magnet.me for the purposes of the Services enabled or requested by Client.

2.2 Magnet.me is responsible for complying with applicable Data Protection Laws in relation to personal data for which Magnet.me acts as independent controller, as described in the Client TOS and Privacy Policy, and for complying with its obligations as processor under this DPA where it processes Personal Data on behalf of Client.

2.3 Client shall indemnify and hold Magnet.me harmless from reasonable third-party claims, costs and damages finally awarded by a competent court or agreed in a settlement approved by Client, to the extent arising from or caused by Client’s breach of applicable Data Protection Laws, unlawful instructions, unlawful or inaccurate Personal Data made available to Magnet.me, or Client’s own recruitment, talent community, assessment, selection or hiring activities.

2.4 Magnet.me shall indemnify and hold Client harmless from reasonable third-party claims, costs and damages finally awarded by a competent court or agreed in a settlement approved by Magnet.me, to the extent arising from or caused by Magnet.me’s breach of this DPA when acting as processor, Magnet.me’s breach of its security obligations under this DPA, or Magnet.me’s unlawful processing of personal data for which Magnet.me acts as independent controller.

2.5 Each indemnity applies only to the extent the relevant claim is caused by the indemnifying party and does not apply to the extent the claim is caused by the indemnified party’s breach of the Agreement, unlawful instructions, negligence, misuse of the Services or failure to comply with applicable law. The indemnities are subject to the liability limitations and exclusions set out in the Agreement, except to the extent liability cannot be limited under mandatory law.

3. Instructions and Company Connect

3.1 Magnet.me will process Personal Data only on Client’s documented instructions, consisting of the processing activities set out in Schedule 1, the Agreement and any reasonable written instructions otherwise given by Client, including by email, to the extent such instructions are consistent with the Agreement.

3.2 Magnet.me shall not use Company Connect Data for its own matching, recommendation logic, model improvement or cross-client analytics purposes unless and until the relevant individual activates or creates a Magnet.me account except for security, fraud prevention, troubleshooting, legal compliance and other processing necessary to provide and protect the Services. If the individual does not activate or create a Magnet.me account, Magnet.me shall delete or otherwise destroy the Company Connect Data in accordance with this DPA and Client’s documented instructions, unless continued retention is required by applicable law.

3.3 For the avoidance of doubt, Magnet.me processes Disposition Data as processor where such processing is necessary to provide the Services requested or enabled by Client, including ATS synchronisation, Client reporting, customer success, Client support and Client troubleshooting. Magnet.me’s separate use of limited Disposition Data for its own product analytics, matching improvement, recommendation improvement, fraud and abuse prevention, security and service improvement purposes, as described in the Client TOS and Privacy Policy, is not performed as processor under this DPA but as independent controller.

3.4 If Magnet.me is required to process Personal Data pursuant to a legal obligation to which Magnet.me is subject, Magnet.me may process Personal Data outside Client’s instructions and shall notify Client of that legal requirement unless prohibited on important grounds of public interest.

3.5 Magnet.me shall notify Client if, in Magnet.me’s opinion, an instruction infringes applicable Data Protection Laws, in which case Magnet.me is not required to comply with the instruction.

4. Assistance and Data Subject Requests

4.1 Taking into account the nature of the processing, Magnet.me shall provide reasonable assistance to Client, insofar as possible and within the scope of the Services, to enable Client to respond to Data Subject requests relating to Personal Data processed by Magnet.me as processor on behalf of Client.

4.2 If Magnet.me receives a request from a Data Subject that clearly relates to Personal Data processed by Magnet.me as processor on behalf of Client, Magnet.me shall forward the request to Client without undue delay and, where reasonably feasible, within two business days after identifying the request as relating to such Personal Data. Magnet.me shall not respond to such request on Client’s behalf unless instructed by Client or required by applicable law.

4.3 Where a request relates to personal data for which Magnet.me acts as independent controller, Magnet.me shall handle the request in accordance with its Privacy Policy and applicable Data Protection Laws. Where a request relates to both the Personal Data and Magnet.me controller data, the parties shall reasonably cooperate to handle the relevant parts of the request within their respective roles.

4.4 Taking into account the nature of the processing and the information available to Magnet.me, Magnet.me shall assist Client in complying with its obligations relating to security, Personal Data Breaches, investigations by competent data protection authorities, data protection impact assessments and prior consultations where legally required.

5. Security

5.1 Magnet.me shall implement and maintain appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, and to ensure a level of security appropriate to the risk of the processing, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks for Data Subjects.

5.2 Such measures include measures relating to access control and identity management, authentication, confidentiality, logging and monitoring, infrastructure and cloud security, secure software development and change management, vulnerability and patch management, backup and recovery, incident response, data protection and privacy controls, vendor and third-party service review, employee security awareness, subprocessor controls and deletion procedures.

5.3 Magnet.me may update or replace its security measures from time to time, provided that such updates do not materially reduce the overall level of protection for Personal Data.

5.4 Upon reasonable request, Magnet.me shall provide Client with its then-current Security Governance Statement, a summary thereof, or other relevant security measures information for security, privacy, legal or procurement assessment purposes, subject to confidentiality, security, legal and commercial sensitivity limitations. Magnet.me is not required to disclose information that would compromise the security, integrity or lawful operation of the Platform, reveal confidential information of other clients, disclose trade secrets, or disclose highly sensitive technical or operational details.

5.5 Unless expressly agreed otherwise in an Order Summary or separate written addendum, Magnet.me does not warrant or represent that it holds ISO 27001 certification, SOC 2 certification or any other external security certification or audit report.

5.6 Client remains responsible for the security and proper use of its Accounts, Users, access rights, devices, networks, credentials and systems used to access the Services. Magnet.me remains responsible for implementing and maintaining the technical and organisational measures applicable to the Platform and to Magnet.me’s own systems and personnel.

6. Confidentiality

6.1 Magnet.me shall keep Personal Data confidential and ensure that persons authorised to process Personal Data under Magnet.me’s responsibility are bound by appropriate confidentiality obligations.

7. Personal Data Breaches

7.1 Magnet.me shall notify Client without undue delay and, where reasonably feasible, within 48 hours after becoming aware of a breach of security on the part of Magnet.me or its sub-processors leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data processed by Magnet.me as processor on behalf of Client (a "Personal Data Breach").

7.2 Magnet.me shall provide Client with information reasonably available to Magnet.me and reasonably necessary for Client to assess the Personal Data Breach and comply with its obligations under applicable Data Protection Laws. Such information shall, to the extent known at the time, include: (a) the nature of the Personal Data Breach; (b) the categories of Personal Data and Data Subjects affected or potentially affected; (c) the known or likely consequences of the Personal Data Breach; and (d) the measures taken or proposed to address the Personal Data Breach and mitigate possible adverse effects.

7.3 Where not all information is available at the time of the initial notification, Magnet.me may provide the information in phases without undue further delay.

8. Sub-processors

8.1 Client grants Magnet.me general authorisation to engage sub-processors for the processing of Personal Data. Magnet.me shall maintain a list of its then-current sub-processors and shall make this list available to Client upon request.

8.2 Magnet.me shall ensure that sub-processors are bound by written obligations that are, in substance, no less protective than the relevant obligations in this DPA, to the extent applicable to the nature of the services provided by the sub-processor. Magnet.me remains responsible for the performance of its sub-processors in accordance with this DPA.

8.3 Magnet.me shall provide prior notice of any intended addition or replacement of a sub-processor that will process Personal Data, where reasonably practicable at least 30 days before the relevant change takes effect.

8.4 Client may object to the intended addition or replacement by notifying Magnet.me in writing within the notice period, stating reasonable and substantiated grounds relating to data protection, security or compliance. If Client objects, the parties shall discuss the objection in good faith and Magnet.me shall use commercially reasonable efforts to address it, for example by providing additional information, applying reasonable safeguards, or offering an alternative where commercially and technically feasible.

8.5 If the objection cannot reasonably be resolved and the relevant sub-processor is necessary to provide the affected Services, either party may terminate the affected Services by written notice. The objection does not affect Magnet.me’s right to continue using the sub-processor for services not provided to Client or for processing that does not involve Client’s Personal Data.

9. International Transfers and Access Outside the EEA

9.1 Magnet.me stores Personal Data processed as processor on behalf of Client within the European Economic Area.

9.2 Where Magnet.me initiates a transfer of such Personal Data outside the European Economic Area, Magnet.me shall ensure that an appropriate transfer mechanism is in place in accordance with applicable Data Protection Laws.

9.3 Client is responsible for ensuring that any access to, download, export, storage or further processing of Personal Data by Client, its Users or persons acting on Client’s behalf from or in a country outside the European Economic Area complies with applicable Data Protection Laws, including any applicable requirements relating to international transfers.

9.4 Magnet.me is not responsible for international transfers resulting from Client’s or its Users’ access to, download, export, storage or further processing of Personal Data outside the European Economic Area.

10. Audit and Information Rights

10.1 Magnet.me shall make available to Client the information reasonably necessary to demonstrate Magnet.me’s compliance with this DPA. Magnet.me will in the first instance provide its then-current available documentation, which may include its Security Governance Statement, a summary of relevant technical and organisational measures, subprocessor information, and other relevant documentation or evidence that Magnet.me makes available for security, privacy, legal or procurement assessment purposes.

10.2 Following review of the information made available, Client may request additional information reasonably necessary to verify Magnet.me’s compliance with this DPA. Magnet.me may satisfy such requests through available documentation or other reasonable means.

10.3 Client may exercise its audit rights no more than once per calendar year, unless an additional audit is required by applicable Data Protection Laws, a competent supervisory authority, or following a Personal Data Breach affecting Personal Data processed by Magnet.me on behalf of Client.

10.4 Any audit shall be conducted on reasonable written notice, during normal business hours, in a manner that does not unreasonably disrupt Magnet.me’s business operations, and shall be limited to matters reasonably necessary to verify Magnet.me’s compliance with this DPA. Before any audit, the parties shall agree in good faith on the scope, timing, duration, format and auditor. Any auditor must be independent and bound by appropriate confidentiality obligations.

10.5 Magnet.me is not required to provide access to source code, trade secrets, information relating to other clients, highly sensitive security information, internal financial information, or information that would compromise the security, integrity or lawful operation of the Platform.

10.6 Where requested assistance exceeds Magnet.me’s normal assistance under the Services, Magnet.me may charge reasonable compensation in accordance with Article 12.2, unless the audit is required due to a Personal Data Breach caused by Magnet.me’s breach of this DPA.

11. Term and Exit Assistance

11.1 This DPA has the same term as the Agreement and terminates when the Agreement ends, except for provisions that by their nature must survive termination until fulfilled.

11.2 Upon termination or expiry of the Agreement, Magnet.me shall make Personal Data processed by Magnet.me as processor on behalf of Client available for download through the standard functionality of the Services for a period of 30 days.

11.3 During the period between 30 and 90 days after termination or expiry, Magnet.me will, upon Client’s request, use commercially reasonable efforts to make available such Personal Data where it remains available in backups, archives or internal systems, to the extent technically and operationally feasible. Magnet.me does not guarantee that such Personal Data will remain complete, current, directly accessible or recoverable during this period.

11.4 After 90 days, Magnet.me may delete or otherwise destroy such Personal Data and has no obligation to retain, restore, export or otherwise make it available, unless retention is required by applicable law.

11.5 This obligation does not apply to personal data processed by Magnet.me as independent controller, including Member account, profile or Platform usage data, which is handled in accordance with Magnet.me’s Privacy Policy and Member Terms of Service.

11.6 Magnet.me’s payment claims and remedies under the Agreement remain unaffected by this Article.

12. Miscellaneous

12.1 The provisions of the Agreement and Client TOS apply to this DPA and prevail over clauses that do not concern data protection, such as liability, fees and amendments, unless this DPA expressly provides otherwise.

12.2 Where Magnet.me’s assistance under this DPA exceeds the assistance normally included in the Services or requires bespoke, client-specific, manual or disproportionate work, Magnet.me may charge reasonable compensation based on its then-current consulting or professional services rates. Magnet.me will inform Client in advance where reasonably practicable. No compensation will be charged to the extent the assistance is required due to a Personal Data Breach caused by Magnet.me’s breach of this DPA or to the extent not permitted by applicable laws.

Schedule 1 - Information with Respect to the Processing

  1. General. This Schedule describes processing activities for the Services. The listed activities apply only to the extent the relevant Service is enabled, requested or specified in the Order Summary. The DPA is not customer-specific; the Order Summary determines which Services apply to Client.
  2. Categories of Data Subjects. The categories of Data Subjects may include: (a) Users; (b) Members whose data is processed in Client’s account or in relation to Client-enabled Services; (c) persons included in Client’s applicant tracking system or other Client-approved source, including non-activated Company Connect invitees; and (d) Client employees or representatives included in Content placed on the Platform.
  3. Categories of Personal Data. The categories of Personal Data may include, depending on the enabled Services: names, email addresses, telephone numbers, business contact details, account data, profile information, messages, resume or CV information, education, skills, interests, career preferences, application information, application identifiers, vacancy identifiers, status or stage information, timestamps, source or channel information, photographs and other personal data included in Client Accounts, Client Content or Client-approved sources.
  4. Processing of Personal Data in Client Accounts. Magnet.me processes Personal Data of Members and Users to provide Client and Users with access to Accounts and Platform functionalities, including facilitating messaging, making accessible resume or profile information shared with Client, Client support, Client troubleshooting, customer success and account management activities.
  5. Company Connect and ATS Integration. Where Client chooses Company Connect or enables an ATS integration, Magnet.me may process Personal Data from Client’s ATS or other Client-approved source on behalf of Client, including contact details and resume or profile information, for ATS synchronisation, to invite individuals to Client’s talent community, send related communications on behalf of Client, prepare a draft or pre-filled Magnet.me account or profile flow, manage the talent network, provide reporting, customer success, Client support, Client troubleshooting and security of these Services. If the individual does not activate or create a Magnet.me account, Magnet.me deletes or otherwise destroys the Company Connect Data in accordance with this DPA and Client’s documented instructions, unless retention is required by law. Magnet.me may inform individuals on behalf of the Client at the time of the first invitation or related communication that their personal data was obtained from the Client’s ATS or other Client-approved source.
  6. Outsourced Messaging. Where Client chooses Continuous Outsourced Messaging or Outsourced Messaging Credits, Magnet.me processes Personal Data as processor on behalf of Client for the purpose of preparing, facilitating and sending Client messages to Members within the Platform. Client determines the campaign purpose, the job or Client content to be promoted, the target audience or selection criteria, message content or approval parameters, timing, frequency and any other material instructions. Magnet.me may identify recipient Members, prepare recipient lists and send messages only within those documented instructions and using the Platform functionality and operational criteria necessary to provide the service.
  7. Content Placed on the Platform. Magnet.me processes personal data contained in Client Content, such as names, photographs or other data of Client employees or representatives, to host, publish, moderate, maintain and support the relevant Content and Services.
  8. Job Sync and Employer Branding Services. Where enabled, Magnet.me may process personal data contained in vacancy pages, career event pages, office photos, office videos, testimonials or other materials provided by Client or made available through a Client-designated source, to provide the relevant Services.
  9. Processing Activities. Processing activities include collection, retrieval, recording, organisation, structuring, storage, hosting, adaptation, alteration, consultation, use, transmission, disclosure to Client and Users, alignment, restriction, deletion and destruction, as required to provide the Services.
  10. Updates. Magnet.me may update this Schedule by notification to Client to reflect relevant changes. Material changes to processing activities, categories of Personal Data or categories of Data Subjects will be notified or otherwise reflected in an updated Schedule. Non-material changes or changes resulting from Services enabled, requested or specified by Client may be reflected without formal renegotiation of this DPA.