SkillCort Legal
Data Processing Addendum
Incorporated into the agreement between the customer organization (controller) and SkillCort LLC (processor). Structured on GDPR Art. 28(3), with a KVKK annex note. Version 1.0, effective August 9, 2026.
Parties."Customer": the organization identified in the Order Form (data controller). "SkillCort": SkillCort LLC, 7901 4th St N, Ste 300, St. Petersburg, FL 33702, USA(data processor). This Data Processing Addendum ("DPA") is incorporated into the agreement between Customer and SkillCort and takes effect as of the Agreement's effective date.
1. Subject matter, duration, nature and purpose
SkillCort processes personal data on Customer's behalf to provide the SkillCort assessment platform: delivering assessments to candidates, capturing responses and work-sample outputs, optional proctoring configured by Customer, evaluation and reporting. Processing lasts for the term of the Agreement plus the deletion period in Section 8.
2. Categories of data subjects and personal data
- Data subjects:candidates and participants invited by Customer; Customer's staff users.
- Personal data: identity and contact data (name, email); assessment responses, uploaded files and work-sample outputs; technical data (IP address, browser/device, timestamps); evaluation results and decision records; where enabled by Customer, proctoring data (camera photos/video, screen captures/recordings, behavioral integrity events).
- Special categories:none solicited — assessments must not be designed to elicit special-category data (Terms §7). Where Customer enables identity verification, the candidate's selfie and ID-document image are processed and an automated one-to-one face-similarity estimate may be computed (on-device or via AWS Rekognition in the EU region) with the candidate's separate explicit consent; no face template is stored, no gallery or cross-candidate matching is performed, and a person makes the identity decision. Customer acknowledges camera/microphone recordings contain imagery and voice of a person and will assess special-category requirements in its jurisdiction.
3. Documented instructions
SkillCort processes personal data only on Customer's documented instructions (the Agreement, this DPA, and Customer's configuration in the platform — including which proctoring features are enabled and the proctoring retention window), unless required by law; in that case SkillCort informs Customer before processing unless the law prohibits it. SkillCort will inform Customer if, in its opinion, an instruction infringes applicable data protection law.
4. Confidentiality and personnel
Persons authorized to process personal data are bound by confidentiality obligations and access data on a need-to-know, least-privilege, role-based basis.
5. Security (Art. 32)
SkillCort implements appropriate technical and organizational measures, including: encryption in transit and at rest; tenant separation; role-based access controls; private (non-public) storage for proctoring media; daily backups; append-only audit history for scores and decisions; automated deletion of proctoring data at the end of the configured retention window. A current description of measures is available at skillcort.com/trust.
6. Subprocessors
Customer grants general authorization to the subprocessors listed at skillcort.com/legal/subprocessors (Annex 1). SkillCort will notify Customer of intended additions or replacements at least 30 days in advance; Customer may object on reasonable data-protection grounds, in which case the parties will seek a solution and Customer may terminate the affected service if none is found. SkillCort imposes data-protection obligations on subprocessors no less protective than this DPA and remains liable for their performance.
SkillCort conducts a documented review of each material subprocessor at least once every twelve (12) months and following any material change, confirmed security incident, or other event reasonably affecting the subprocessor's data protection risk profile; the current review record is maintained in SkillCort's provider compliance register.
7. International transfers
Platform data is hosted in the EU (Frankfurt). Data is accessible from the US by SkillCort (a US entity) for the operation of the service, and transactional email is processed in the US. Transfers are made under: (a) for EU/EEA data — Standard Contractual Clauses (Module Two: controller → processor, and Module Three where applicable), which the parties agree form part of this DPA, supported by a transfer impact assessment and supplementary measures; (b) for data subject to Turkish law — the standard contract published by the Turkish Personal Data Protection Authority under Art. 9 of Law No. 6698, executed by the parties with the Order Form for Türkiye-related processing and notified to the Authority within five business days.
8. Deletion and return
Following termination or expiry, Customer Data may remain available for up to 30 days to allow Customer to complete data export. At the end of this period SkillCort deletes the data from active production systems; residual copies in encrypted backups are deleted or overwritten through the ordinary backup cycle within a maximum of 90 days. Records required by applicable law, and records narrowly necessary for the establishment, exercise or defence of legal claims, are excluded. Security, access and audit logs are governed by the retention periods in the Privacy Policy, separately from backups. Proctoring data is deleted automatically at the end of the retention window configured by Customer (default 90 days) regardless of contract status; Customer can also trigger immediate erasure per attempt in-product.
9. Assistance
Taking into account the nature of processing, SkillCort assists Customer with appropriate technical and organizational measures in responding to data subject requests (Arts. 12–23 GDPR; Art. 11 KVKK), and with Customer's obligations under Arts. 32–36 GDPR (security, breach notification, DPIAs, prior consultation). Data subject requests received directly by SkillCort are forwarded to Customer without undue delay.
10. Personal data breach
SkillCort notifies Customer without undue delay after becoming aware of a personal data breach affecting Customer's data, and provides information reasonably required for Customer's notification obligations (Arts. 33–34 GDPR; Art. 12(5) KVKK).
11. Audits
SkillCort makes available information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by Customer or its mandated auditor. Customer may exercise its audit rights no more than once in any twelve (12)-month period, except following a confirmed personal data breach, a request from a competent supervisory authority, or reasonable evidence of material non-compliance with this DPA. Audits require at least 30 days' advance written notice, are subject to confidentiality undertakings, must be conducted so as to minimize disruption to SkillCort's operations, and never include access to other customers' data. The parties will first rely on existing independent audit reports and SkillCort's published security documentation where they reasonably address the scope; costs of excessive or bespoke audit requests beyond that baseline are borne by Customer.
12. Liability and order of precedence
Liability is governed by the Agreement. In case of conflict between the Agreement and this DPA regarding personal data processing, this DPA prevails; executed SCCs and standard contracts prevail over both to the extent of the conflict.
KVKK annex
Where Customer is established in Türkiye or candidates are located in Türkiye, the parties additionally execute the Turkish DPA standard contract (processor relationship) and file it with the Authority within five business days. The aydınlatma (information notice) duty toward candidates rests with Customer as controller, using its own notice or the template SkillCort provides.
To execute this DPA for your organization, or for signed copies and transfer documentation: privacy@skillcort.com.