Data Processing Agreement (DPA) - Sonar Air
Last updated: July 2026
Contact: info@sonarair.com
DRAFT - Pending counsel review. Not legal advice. English is the controlling language.
This Data Processing Agreement ("DPA") forms part of the agreement between:
- Customer - the organization using Sonar Air under the Terms of Service
- Processor - Sonar Air, operating Sonar Air (Amsterdam, Netherlands)
1. Subject matter and duration
Processor provides recruitment-sourcing software (role profiles, scans, candidate evaluation, agents, exports). Processor processes personal data on documented instructions from Customer for the duration of the subscription and until deletion/return under Section 10.
2. Nature and purpose of processing
- Storage and display of role profiles and search configuration
- Discovery and evaluation of publicly available professional profiles per Customer configuration
- Optional language-model assistance for summaries and search-query building (not used to score or rank candidates; assistive; human review expected)
- Optional agent outputs (assistive; human review expected)
- Account administration, security, support, and backups
3. Types of personal data and data subjects
Special categories of data are not intentionally collected.
4. Processor obligations
Processor shall:
- Process personal data only on documented instructions from Customer (including these terms, the Privacy Policy, and Customer's use of the product), unless required by law
- Ensure persons authorized to process data are bound by confidentiality
- Implement appropriate technical and organizational measures (see Section 8)
- Not engage another processor without Customer authorization (Section 6)
- Assist Customer with data subject requests where feasible (Section 9)
- Assist with security and breach notifications (Section 9)
- Delete or return personal data at end of service (Section 10)
- Make available information necessary to demonstrate compliance and allow audits on reasonable notice (Section 11)
5. Customer obligations
Customer shall:
- Have a lawful basis for processing and instructing Processor
- Configure sources and use outputs lawfully (employment, privacy, platform terms)
- Not instruct Processor to process special-category data intentionally
- Ensure human review before significant decisions about individuals
6. Subprocessors
Customer authorizes Processor to use subprocessors listed in Annex II. Processor will notify Customer of material changes (email or in-app notice). Customer may object on reasonable grounds relating to data protection; parties will discuss in good faith.
7. International transfers
Where personal data is transferred outside the EEA/UK, Processor uses appropriate safeguards (e.g. EU Standard Contractual Clauses). See our Standard Contractual Clauses note in the sales pack or on request.
8. Security measures
Measures include, as applicable to deployment:
- TLS in transit
- Access control and authentication (Auth)
- Secrets in environment configuration
- Application-level tenant scoping for customer data
- Retention limits and deletion APIs
- Logging and monitoring
Details may be updated; material reductions will be notified.
9. Data subject requests and incidents
Requests: Customer is primary contact for its data subjects. Processor will forward requests received at info@sonarair.com and assist Customer within reasonable time.
Incidents: Processor will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer data, and provide information to support Customer's regulatory obligations.
10. Deletion and return
On termination or Customer request, Processor deletes or returns Customer personal data within 30 days, except where law requires retention. Backups may persist until overwritten per backup schedule.
11. Audits
Customer may audit compliance no more than once per year on reasonable notice, or accept Processor's summaries / third-party reports where available. Audits shall not unreasonably disrupt operations.
12. Liability
Liability under this DPA follows the limitation of liability in the Terms of Service unless mandatory law requires otherwise.
13. Order of precedence
If this DPA conflicts with the Terms on data protection, this DPA prevails. If EU/UK SCCs are executed separately, SCCs prevail on transfer matters.
Annex I - Processing details
Annex II - Subprocessors (production)
The current production subprocessor schedule is not published openly on this page.
View it on the subprocessors page:
- If you already have access, the full list opens there.
- If you do not have access, you can request access on that page (sign-in required). Approved customers under this DPA may also request the schedule by emailing info@sonarair.com.
Public data APIs (GitHub, Stack Exchange, Hacker News, Kaggle, etc.) retrieve publicly available data; counsel may classify as recipients rather than subprocessors. Supported platforms are searched by default as part of the service.
Processor will update the subprocessor schedule when vendors change materially.
Annex III - Security contacts
- Privacy / security: info@sonarair.com