NEXT Platform · Legal

Data Processing Addendum

How Wonderkind processes personal data on your behalf, as a processor under the GDPR, for candidate data flowing through the Attract, Qualify, and Deliver modules.

Version
1.0
Effective
7 July 2026
Wonderkind Global B.V.  ·  KvK 66092302  ·  VAT NL825299937B01  ·  H.J.E. Wenckebachweg 123, 1096 AM Amsterdam, the Netherlands

This Data Processing Addendum (the "DPA") forms part of the Terms and Conditions for NEXT by Wonderkind (the "Agreement") between:

  • Wonderkind Global B.V., registered with the Dutch Chamber of Commerce (KvK) under number 66092302, VAT number NL825299937B01, registered office at H.J.E. Wenckebachweg 123, 1096 AM Amsterdam, the Netherlands ("Wonderkind", the "Processor"); and
  • the Customer identified in the Order (the "Controller").

It governs Wonderkind's processing of Personal Data on the Customer's behalf in connection with the Services. Capitalised terms not defined here have the meaning given in the Agreement.


1. Definitions

  • GDPR: Regulation (EU) 2016/679 (the General Data Protection Regulation) and, where applicable, the UK GDPR as defined in the UK Data Protection Act 2018.
  • Data Protection Law: the GDPR, the UK GDPR, the Dutch GDPR Implementation Act (UAVG), and any other data-protection or privacy law applicable to a party's processing under this DPA.
  • Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Special Categories of Personal Data, Supervisory Authority: as defined in the GDPR.
  • Candidate Data: Personal Data relating to applicants and candidates, captured or processed through the Services, as further described in Annex 1.
  • Sub-Processor: any third party engaged by Wonderkind to process Personal Data on the Customer's behalf.
  • Standard Contractual Clauses or SCCs: the clauses approved by the European Commission in Implementing Decision (EU) 2021/914 for the transfer of Personal Data to third countries.
  • UK Addendum: the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner.

2. Roles and scope

2.1For Candidate Data processed through the Qualify and Deliver Modules, the Customer acts as Controller and Wonderkind acts as Processor.

2.2Wonderkind processes Personal Data only to provide the Services and only as described in Annex 1, on the Customer's documented instructions.

2.3Channels are independent controllers. When Campaigns run on Channels (for example Meta, Google, LinkedIn, or TikTok), each Channel determines its own purposes and means of processing for ad delivery, audience building, and measurement, and acts as an independent controller (or, where applicable, joint controller with the Customer) under its own terms. Wonderkind is not a Sub-Processor of the Channels for that activity, and this DPA does not govern the Channels' own processing. The Customer is responsible for the lawful basis and notices required for advertising activity on the Channels.

2.4Customer account data. Wonderkind processes Personal Data about the Customer's Authorized Users (for example name, work email, and login activity) as a controller, to operate accounts, provide support, and secure the Platform. That processing is governed by Wonderkind's own privacy notice, not by this DPA.

2.5Anonymised and aggregated insights. The Customer instructs Wonderkind to process Personal Data to create anonymised, aggregated statistics and benchmarks (as referred to in Article 11.2 of the Agreement). Wonderkind applies a minimum aggregation threshold so that no statistic or benchmark is derived from a group small enough to allow any Data Subject, candidate, or Customer to be singled out or re-identified. Once data has been irreversibly anonymised so that no Data Subject can be identified, it is no longer Personal Data and falls outside this DPA.

2.6If Wonderkind believes an instruction infringes Data Protection Law, it will inform the Customer without undue delay and may suspend the affected processing until the instruction is confirmed, withdrawn, or amended.


3. Processing on documented instructions

3.1Wonderkind processes Personal Data only on the Customer's documented instructions, including the instructions set out in the Agreement, this DPA, and the configuration the Customer sets in the Platform (for example the fields, knock-out questions, and qualification criteria it defines).

3.2Wonderkind will not process Personal Data for its own purposes, except for the anonymised, aggregated processing described in clause 2.5 and as required by law.

3.3If law requires Wonderkind to process Personal Data beyond the Customer's instructions, Wonderkind will inform the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.


4. Confidentiality

4.1Wonderkind ensures that persons authorised to process the Personal Data are bound by an appropriate duty of confidentiality, whether contractual or statutory.

4.2Wonderkind limits access to the Personal Data to personnel who need it to provide the Services, and ensures those personnel are informed of the confidential nature of the data and trained on their obligations.


5. Security

5.1Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects, Wonderkind implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Those measures are described in Annex 2.

5.2Wonderkind may update its security measures from time to time, provided the updates do not materially reduce the overall level of security of the Personal Data.


6. Sub-Processors

6.1The Customer gives Wonderkind general authorisation to engage Sub-Processors to process Personal Data, subject to this Article. The Sub-Processors approved at the effective date are listed in Annex 3.

6.2Wonderkind imposes on each Sub-Processor, by written contract, data-protection obligations that are no less protective than those in this DPA, and remains fully liable to the Customer for the Sub-Processor's performance.

6.3Wonderkind will give the Customer at least 30 days' notice of any intended addition or replacement of a Sub-Processor (through the Platform, by email, or via a subscribed list). The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Services by written notice, and Article 18.4 of the Agreement applies to the resulting wind-down.


7. Assistance with Data Subject rights

7.1Taking into account the nature of the processing, Wonderkind assists the Customer by appropriate technical and organisational measures, insofar as this is possible, to respond to requests from Data Subjects exercising their rights under Data Protection Law (including access, rectification, erasure, restriction, portability, and objection).

7.2If Wonderkind receives a request from a Data Subject relating to Personal Data processed on the Customer's behalf, it will not respond directly (except to confirm that the request has been forwarded), and will pass the request to the Customer without undue delay.


8. Personal Data Breach

8.1Wonderkind notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting the Customer's Personal Data.

8.2The notification describes, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for more information. Where the information cannot all be provided at once, it may be provided in phases without undue further delay.

8.3Wonderkind provides reasonable assistance to the Customer in meeting the Customer's own breach-notification and communication obligations to Supervisory Authorities and Data Subjects.


9. Data protection impact assessments

9.1Taking into account the nature of the processing and the information available to it, Wonderkind provides reasonable assistance to the Customer with any data protection impact assessments and prior consultations with Supervisory Authorities that the Customer is required to carry out under Data Protection Law in relation to the Services.


10. International transfers

10.1Wonderkind will not transfer Personal Data to a country outside the European Economic Area (EEA), or to an international organisation, unless it has taken measures that provide an adequate level of protection under Data Protection Law, such as an adequacy decision or the Standard Contractual Clauses (supplemented by the UK Addendum where the UK GDPR applies).

10.2At the effective date, all Sub-Processors listed in Annex 3 process Personal Data within the EEA, and no transfer of Personal Data to a country outside the EEA takes place. If such a transfer later becomes necessary, Wonderkind will put in place the Standard Contractual Clauses (supplemented by the UK Addendum where applicable), with the Customer as data exporter and Wonderkind or the relevant Sub-Processor as data importer, and with the annexes to this DPA populating the annexes to the SCCs, before any such transfer occurs.


11. Audits

11.1Wonderkind makes available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates.

11.2To satisfy an audit request in the first instance, Wonderkind may provide its most recent third-party certifications, audit reports, or a completed security questionnaire. An on-site inspection is limited to once per 12 months (unless required by a Supervisory Authority or following a Personal Data Breach), on reasonable prior written notice, during business hours, subject to confidentiality, and in a manner that does not disrupt Wonderkind's operations. Each party bears its own costs.


12. Return and deletion

12.1On termination or expiry of the Agreement, deletion and return of Personal Data follow Article 18.4 of the Agreement: for 30 days after the effective termination date the Customer may export its data, and after 90 days from that date Wonderkind may permanently delete the account and associated Personal Data.

12.2Wonderkind will delete or return the Personal Data as instructed by the Customer within those windows, and will delete existing copies unless Data Protection Law requires continued storage, in which case Wonderkind will keep the data confidential and process it only as required by that law.

12.3Wonderkind will confirm deletion in writing on the Customer's request.


13. Liability

13.1Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in Article 15 of the Agreement.


14. Duration

14.1This DPA takes effect when the Agreement takes effect and continues for as long as Wonderkind processes Personal Data on the Customer's behalf. Provisions that by their nature should survive (including confidentiality and the return and deletion obligations) survive termination.


15. Precedence and general

15.1This DPA forms part of the Agreement. In the event of a conflict between this DPA and the rest of the Agreement on matters of data protection, this DPA prevails.

15.2This DPA is governed by the laws of the Netherlands. Any dispute arising out of or in connection with it is subject to the exclusive jurisdiction of the competent court in Amsterdam, the Netherlands.

15.3Except as amended by this DPA, the Agreement remains in full force and effect.


Annex 1: Description of the processing

  • Subject matter: processing of Candidate Data and related Personal Data to provide the Services (the Attract, Qualify, and Deliver Modules).
  • Duration: the term of the Agreement, plus the wind-down and deletion periods set out in Article 18.4 of the Agreement.
  • Nature and purpose: distributing job advertising, capturing applications and leads, running qualification flows (knock-out questions and job-description criteria as configured by the Customer), delivering qualified candidates into the Customer's ATS or other systems, and reporting and optimisation.
  • Types of Personal Data: identification and contact data (for example name, email address, telephone number); application content the candidate provides (for example CV, cover letter, answers to application and knock-out questions); eligibility and profile information the candidate submits; and technical data (for example IP address, device, and interaction data) used for delivery, attribution, and fraud prevention. The Customer must not configure the Services to collect Special Categories of Personal Data unless it has a lawful basis and has instructed Wonderkind accordingly in writing.
  • Categories of Data Subjects: the Customer's job applicants and candidates.

Annex 2: Technical and organisational security measures

Wonderkind implements the following technical and organisational measures. A detailed description of controls is available to enterprise customers under a confidentiality agreement as part of security due diligence.

  • Encryption: Personal Data encrypted in transit (TLS) and at rest.
  • Access control: role-based access with least-privilege principles; authentication and identity management via the Platform's identity provider; individual accounts, no shared credentials; multi-factor authentication for administrative access.
  • Network and application security: segregation of environments, secure development practices, dependency and vulnerability management, and regular patching.
  • Logging and monitoring: access and event logging, with alerting on anomalous activity.
  • Resilience and backup: regular backups, tested restore procedures, and documented business-continuity measures.
  • Data segregation: logical separation of Customer data in a multi-tenant environment.
  • Personnel: confidentiality undertakings and periodic data-protection and security training.
  • Vendor management: security review of Sub-Processors before onboarding.

Annex 3: Approved Sub-Processors

All Sub-Processors listed below process Personal Data within the EEA. No international transfer mechanism is required while hosting remains in the EEA.

Sub-ProcessorPurposeHosting regionTransfer mechanism
SupabaseDatabase, storage, and application hostingEEA (EU region)None required (EEA hosting)
Microsoft Azure OpenAIAI processing for content generation and candidate qualificationEEA (EU region)None required (EEA hosting)

Stripe (payment processing) and the Platform's authentication provider process the Customer's account and billing data, for which Wonderkind acts as controller and those providers act as independent controllers or processors under their own terms. They do not process Candidate Data and are therefore outside the scope of this Annex and this DPA. Payment processing is addressed in Article 10.2 of the Agreement.