Customer
Data Processing Agreement

Keep in mind that your data is safe and private with us, and we don’t spam – we don’t send other emails except to keep you informed about our latest tests and other content.
Introduction
This Data Processing Agreement (“DPA”) is entered into between the Customer (and, if applicable, the Customer’s Affiliates) and Envision Your Evolution (“E.Y.E.”, “we”, “us” or “our”). This DPA contains the legal terms and conditions governing the processing of Customer Personal Data by E.Y.E. in connection with the use of our services and platform.
This DPA forms part of the Agreement between the parties and is subject to the Customer Terms of Service and Privacy Policy.
1. Scope
This DPA governs the processing of Customer Personal Data, including personal data of Users, institutional clients, and professionals using the platform, in accordance with applicable Data Protection Laws such as the General Data Protection Regulation (GDPR).
2. Definitions
Agreement: The Customer Terms of Service, Privacy Policy, applicable order forms, and related policies governing the use of E.Y.E. services.
Customer Personal Data: Any personal data provided by or on behalf of the Customer to E.Y.E. in connection with the services, including names, contact details, assessment data, and communications.
Data Protection Laws: All applicable laws governing data privacy and protection, including the GDPR and relevant legislation.
DPA: This Customer Data Processing Agreement.
Information Security Measures: The technical and organizational safeguards implemented by E.Y.E. to ensure confidentiality, integrity, and availability of Customer Personal Data.
Security Incident: Unauthorized access, disclosure, alteration, or destruction of Customer Personal Data compromising confidentiality or security.
3. Roles and Responsibilities
3.1. Processor Role
E.Y.E. acts as a processor when handling Customer Personal Data on documented instructions from the Customer, unless required by law.
3.2. Compliance
E.Y.E. will process Customer Personal Data in compliance with Data Protection Laws and provide reasonable assistance to the Customer in fulfilling obligations related to data subject rights, impact assessments, and supervisory authority consultations.
3.3. Personnel
All personnel with access to Customer Personal Data are bound by confidentiality obligations.
3.4. Sub-Processors
E.Y.E. may engage authorized sub-processors (see Appendix 1) for specific services necessary to operate the platform. E.Y.E. remains responsible for their compliance with this DPA.
3.5. Cross-Border Transfers
Where data is transferred outside the EEA, appropriate safeguards (including Standard Contractual Clauses and supplementary measures) will be applied in compliance with GDPR.
4. Customer Personal Data Processing
Subject Matter: Processing of Customer Personal Data as necessary for delivering services.
Duration: Processing continues until termination of the Agreement.
Purpose: To provide, maintain, and improve services offered by E.Y.E.
Categories of Data Subjects: Institutional staff, professionals, clients, and candidates using the platform.
Categories of Personal Data:
Identification data (name, email, business contact information).
Account credentials and usage data.
Assessment responses, evaluation results, and feedback.
Device/IP information, cookies, and analytics data.
Sensitive Data: The platform is not intended for processing special categories of data unless explicitly required and consented to.
5. Security and Incident Response
E.Y.E. maintains appropriate technical and organizational measures including encryption, access controls, pseudonymization, backup and recovery systems, and regular security testing.
In the event of a Security Incident, E.Y.E. will promptly:
Notify the Customer without undue delay.
Provide details of the incident and mitigation steps.
Cooperate to minimize impact and comply with legal obligations.
6. Retention and Deletion
Upon termination of the Agreement, Customer Personal Data will either be securely deleted or returned upon request, unless retention is required by law.
7. Sub-Processors (Appendix 1)
The Customer authorizes E.Y.E. to use the following sub-processors for the operation of its services:
Sub-Processor | Purpose | Location | Safeguards |
---|---|---|---|
Google Analytics | Analytics, traffic monitoring, usage statistics | EU/US | SCCs, DPA in place |
Hosting.com | Hosting infrastructure and data storage | EU | DPA in place |
MailPoet | Email delivery, newsletters, user communication | EU | DPA in place |
OpenAI (ChatGPT) | Conversational AI processing for platform interactions | US | SCCs, supplementary safeguards |
Anthropic (Claude) | Conversational AI processing for platform interactions | US | SCCs, supplementary safeguards |
Google (Gemini) | AI-based analysis and processing for platform features | EU/US | SCCs, DPA in place |
8. Compliance with Laws
Both parties shall comply with all applicable Data Protection Laws. The Customer represents that its transfer of personal data to E.Y.E. complies with relevant laws and regulations.
9. Liability
This DPA does not alter the limitation of liability provisions in the Agreement.
10. Conflicts
If there is a conflict between this DPA and the Terms of Service, this DPA shall prevail for data processing activities.