DRAFT — NOT FOR SIGNATURE. This document was prepared by the operator of Venditas with AI assistance. It has not been reviewed by a qualified solicitor, and it is not legal advice. It is a working draft intended to be sent to a data protection lawyer qualified in England & Wales for review, and to be used after that review as the standard form Venditas offers to customers.
Two things in particular must not be relied on until a lawyer has looked at them: the international transfer annex (Annex 4), which has to be executed using the correct current instrument and completed correctly to work at all, and the liability clause (clause 12), which is blank on purpose.
Draft version 0.1 — 2 September 2026
between
(1) [CUSTOMER LEGAL NAME], a company registered in [JURISDICTION] under number [NUMBER], whose registered office is at [ADDRESS] (the "Customer"); and
(2) Venditas, a sole proprietorship operated by Abin Johnson of Bhoomi Elite, Sector 28, Nerul, Navi Mumbai 400706, India ("Venditas"),
each a "party" and together the "parties".
Effective date: [DATE]
1. Background and scope
1.1 Venditas provides the Customer with a service that converts a candidate CV into a document in the Customer's branding, with the candidate's direct contact details removed (the "Service"), on the terms set out at https://venditas.in/terms (the "Principal Agreement").
1.2 In providing the Service, Venditas processes personal data on behalf of the Customer. This agreement sets out the terms on which it does so, and forms part of the Principal Agreement. Where this agreement conflicts with the Principal Agreement, this agreement prevails on matters of data protection.
1.3 The parties agree that, for the personal data described in Annex 1, the Customer is the controller and Venditas is the processor.
1.4 Venditas is a controller in its own right for the account and contact data of the Customer's users described in its Privacy Policy (their email address, agency name, timestamps, usage counters, and hashed request counters). That processing is outside the scope of this agreement.
2. Definitions
"Data Protection Law" means, as applicable to the processing: the UK GDPR and the Data Protection Act 2018; Regulation (EU) 2016/679 (the "EU GDPR") and national implementing laws; and any other data protection or privacy law applicable to a party, including India's Digital Personal Data Protection Act 2023.
"Personal Data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR.
"Sub-processor" means a third party engaged by Venditas to process Personal Data on the Customer's behalf.
"Candidate Data" means Personal Data contained in or derived from a CV uploaded to the Service.
3. Processing by Venditas
3.1 Venditas shall process Personal Data only on the Customer's documented instructions, including with regard to transfers to a third country, unless required to do otherwise by law to which it is subject; in which case, unless that law prohibits it on important grounds of public interest, Venditas shall inform the Customer of that legal requirement before processing.
3.2 The Customer's initial documented instruction is: to process an uploaded CV as described in Annex 1, and to return the resulting document. The Customer's use of the Service in accordance with its documentation constitutes a documented instruction. Any other instruction must be agreed in writing and may be subject to a charge.
3.3 Venditas shall inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
3.4 Venditas shall not sell Personal Data, use it for its own purposes, use it to train or fine-tune any machine learning model, or disclose it to any third party other than a Sub-processor listed in Annex 3. The Customer acknowledges that Google LLC, listed in Annex 3, receives CV text from which direct identifiers have been removed (or, for a scanned CV, page images) under the Gemini API terms for unpaid services, which permit Google to use submitted content to provide, improve and develop its products and machine learning technologies, including by human review.
3.5 The Customer warrants that it has a lawful basis for the processing, that it has given data subjects the information required by Articles 13 and 14 UK GDPR, and that it is entitled to disclose the Personal Data to Venditas.
4. Retention and deletion — no retention of Candidate Data
4.1 Venditas does not retain Candidate Data. An uploaded CV, the text extracted from it, any page images produced from it, the structured fields derived from it, and the output document, are held only in volatile memory for the duration of the HTTP request and are discarded when the response completes. None of them is written to persistent storage controlled by Venditas.
4.2 It follows that:
(a) there is no Candidate Data for Venditas to return or delete at the end of the Service, and clause 4.3 is satisfied by default; (b) Venditas cannot re-supply a document once returned; (c) Venditas cannot search for, retrieve, or produce a copy of any particular candidate's data, whether in response to a data subject request, a court order or otherwise.
4.3 On termination of the Principal Agreement, and at the Customer's choice, Venditas shall delete or return all Personal Data processed on the Customer's behalf and delete existing copies, unless required by law to retain it. Given clause 4.1 this obligation is, in practice, limited to the account data referred to in clause 1.4, which Venditas shall delete on request.
4.4 Venditas retains no backups of Candidate Data, because there is nothing to back up.
5. Confidentiality
5.1 Venditas shall treat Personal Data as confidential and shall not disclose it except as permitted by this agreement.
5.2 Venditas is a one-person business. Access to production systems is held by Abin Johnson alone, who is bound by the confidentiality obligations in this agreement. Venditas shall ensure that any person it later authorises to process Personal Data is subject to an appropriate written confidentiality obligation before being given access, and shall maintain a current record of who has access.
6. Security
6.1 Venditas shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 UK GDPR. The measures in place at the effective date are described in Annex 2.
6.2 Venditas shall not materially reduce the measures in Annex 2 during the term.
6.3 The Customer acknowledges that it has reviewed Annex 2 and considers the measures appropriate to the risk presented by the processing.
7. Sub-processors
7.1 The Customer gives general written authorisation for Venditas to engage Sub-processors. The Sub-processors authorised at the effective date are listed in Annex 3.
7.2 Venditas shall give the Customer at least thirty (30) days' notice by email before adding or replacing a Sub-processor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the Principal Agreement without penalty and without further charge.
7.3 Venditas shall impose on each Sub-processor data protection obligations no less protective than those in this agreement, and remains fully liable to the Customer for the performance of each Sub-processor's obligations.
8. Data subject rights
8.1 Venditas shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests to exercise data subject rights.
8.2 The parties record that, because Venditas retains no Candidate Data (clause 4.1), a request for access, rectification, erasure, restriction, portability or objection in respect of a candidate can and must be answered by the Customer from its own records. Venditas holds nothing responsive and can confirm that in writing to the Customer or, if the Customer asks, to the data subject.
8.3 If a data subject contacts Venditas directly, Venditas shall not respond on the substance, and shall tell the data subject to contact the Customer. Where Venditas can identify the Customer concerned, it shall notify the Customer without undue delay.
9. Personal data breach
9.1 Venditas shall notify the Customer without undue delay and in any event within forty-eight (48) hours of becoming aware of a personal data breach affecting Personal Data processed on the Customer's behalf.
9.2 The notification shall include, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where the information is not all available at once, Venditas shall provide it in phases without undue further delay.
9.3 Venditas shall not make any public statement about a breach affecting the Customer's Personal Data that identifies the Customer, without the Customer's prior written consent, unless required by law.
9.4 Venditas shall assist the Customer in meeting its own obligations under Articles 33 and 34 UK GDPR.
10. Assistance with impact assessments
Venditas shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultations under Articles 35 and 36 UK GDPR, taking into account the nature of the processing and the information available to Venditas. Venditas shall complete a reasonable security questionnaire, once per year at no charge.
11. Audit and information
11.1 Venditas shall make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 UK GDPR.
11.2 The Customer may audit Venditas's compliance once in any twelve-month period, on thirty (30) days' written notice, and additionally after a personal data breach affecting the Customer. An audit shall be conducted during business hours, shall not unreasonably disrupt Venditas's business, and shall be subject to confidentiality.
11.3 In the first instance the Customer shall accept a completed security questionnaire and written evidence in place of an on-site or remote inspection, where that reasonably satisfies the Customer's requirement. Given that Venditas retains no Candidate Data, the parties expect this to be sufficient in the great majority of cases.
11.4 The Customer shall bear its own costs of an audit. Venditas may charge for time spent on an audit beyond the first two working days in any twelve-month period, at its then-current rates.
12. Liability
Blank on purpose — to be agreed. A UK customer's procurement team will usually want data protection liability to sit outside any general liability cap, or to be capped at a much higher figure than the fees paid. A one-person business needs a real cap and probably needs insurance behind it. This clause must be negotiated deliberately and reviewed by a solicitor. See
legal/compliance-notes.md.
12.1 Each party's liability under this agreement is subject to [TO BE AGREED — see note above].
12.2 Nothing in this agreement limits either party's liability to a data subject or to a supervisory authority under Data Protection Law.
13. International transfers
13.1 The Customer acknowledges that Venditas is established in India and that its Sub-processors process Personal Data in the United States and elsewhere, as set out in Annex 3.
13.2 India is not, at the effective date, the subject of a UK adequacy regulation or an EU adequacy decision. Accordingly, transfers from the Customer to Venditas are made under the transfer mechanism set out in Annex 4, which forms part of this agreement.
13.3 Venditas shall notify the Customer if it becomes subject to a legal requirement that would prevent it from complying with the transfer mechanism in Annex 4, and shall assist the Customer with any transfer risk assessment the Customer is required to carry out.
13.4 Venditas shall notify the Customer of any legally binding request from a public authority for disclosure of the Customer's Personal Data, unless prohibited from doing so, and shall challenge a request that appears unlawful. Because Venditas retains no Candidate Data, it is in practice unable to comply with such a request in respect of a candidate.
14. General
14.1 This agreement takes effect on the effective date and continues for as long as Venditas processes Personal Data on the Customer's behalf.
14.2 If Data Protection Law changes so that this agreement no longer satisfies it, the parties shall negotiate in good faith to amend it.
14.3 Governing law and jurisdiction. This agreement is governed by
[TO BE AGREED — see legal/compliance-notes.md], and the courts of
[TO BE AGREED] have exclusive jurisdiction. Where the transfer mechanism in
Annex 4 specifies a governing law or forum for matters within its scope, that
specification prevails.
Annex 1 — Details of the processing
Subject matter. Conversion of a candidate CV supplied by the Customer into a document in the Customer's branding, with the candidate's direct contact details removed.
Duration. For the term of the Principal Agreement. Each individual processing operation lasts for the duration of a single HTTP request, typically a few seconds.
Nature and purpose of the processing. Receipt of an uploaded file; extraction of text from the file, or rendering of up to the first four pages as images where the file is a scan without a readable text layer; transmission of that text or those images to a third-party language model API for conversion into structured fields; generation of a Word document from those fields; removal of the candidate's direct contact details from that document; automated verification that those details are absent; return of the document to the Customer. All of it in volatile memory, with no persistent storage.
Types of Personal Data. Whatever the candidate has put in their CV. Typically: name, email address, telephone number, postal location, links to professional profiles, employment history (employers, job titles, dates, achievements), education history, qualifications, skills, languages and certifications. A CV may also contain, at the candidate's own choice and outside the Customer's or Venditas's control, special category data within the meaning of Article 9 UK GDPR — for example a health condition or disability, trade union membership, an employer or qualification that reveals religious belief, or a photograph — and information such as nationality, visa status or date of birth. Where the CV is a scan, the images of the pages are processed and may include a photograph and a signature.
Categories of data subjects. Job candidates whose CVs the Customer uploads.
Retention. None. See clause 4.1.
Frequency of transfer. Continuous, on each use of the Service.
Annex 2 — Technical and organisational security measures
This annex describes the measures actually implemented at the effective date, not an aspirational list.
A. The primary control: no retention
Candidate Data is processed in volatile memory and discarded when the HTTP response completes. It is not written to any database, file system, object store or backup controlled by Venditas. There is no store of candidate data to be breached, exfiltrated, mis-configured, subpoenaed or left behind on a decommissioned disk. Every other measure below is secondary to this one.
B. Encryption
- All traffic between the Customer's browser and the Service is over HTTPS/TLS.
- The call to the language model API is over HTTPS/TLS.
- The connection to the database is over HTTPS/TLS.
- Outbound email is sent over an implicitly encrypted SMTP connection (port 465), so the session is encrypted from the first byte.
C. Access control
- Production systems are accessible to one named individual only.
- Database access from the application uses a service credential held in an environment variable, never in source control.
- Row level security is enabled on both database tables, with no anonymous or authenticated access policies defined — the tables are reachable only with the service credential.
- The stored procedure used for metering has execute permission revoked from the public, anonymous and authenticated roles.
- Credentials are held in environment variables at the hosting provider and in a local environment file excluded from version control.
D. Data minimisation and pseudonymisation
- IP addresses are never stored. Request counting uses a SHA-256 hash of the IP address combined with a secret salt, truncated to 32 hexadecimal characters. The salt makes brute-force reversal of the (small) IPv4 space impractical.
- The account record holds only: email address, agency name, first and last seen timestamps, a usage count, a contact flag and an unsubscribe token.
- The Customer's uploaded logo, brand colour and footer text are held in memory for the request only and are not stored.
- The output document identifies the candidate only by a reference code formed from their initials and the current year and month.
E. Application controls
- Uploads are limited to 10 MB and to PDF, DOCX, TXT and MD file types.
- Rate limiting: five documents per day and ten in total per email address, and a hard daily cap per source IP hash, applied atomically in the database so that concurrent requests cannot both pass the same limit.
- Disposable email domains are rejected.
- Output verification: after the document is built it is read back and asserted to contain none of the candidate's name, email address, telephone number or links. A failure returns an error and no document — the request fails closed.
- The response carries
Cache-Control: no-store. - Error messages returned to users are generic; internal fault detail is not exposed to the client.
- The server does not advertise its framework in response headers.
F. Organisational measures
- One-person business; the operator is the sole person with access to production systems and to the account data.
- The operator maintains a record of processing activities under Article 30(2) UK
GDPR. (See
legal/compliance-notes.md— this must be true before the DPA is signed.) - Sub-processors are engaged under their own data processing terms and are listed in Annex 3.
G. Measures not in place
Stated openly, because a procurement team will find out anyway and an honest answer is worth more than a discovered omission:
- No SOC 2, ISO 27001 or other third-party security certification.
- No formal penetration test has been carried out.
- No 24/7 monitoring or on-call rotation; the Service is monitored during the operator's working hours.
- No formal business continuity or disaster recovery plan beyond the fact that no candidate data exists to recover.
- No cyber liability insurance at the effective date. (See
legal/compliance-notes.md.)
Annex 3 — Authorised Sub-processors
Google LLC (Gemini API) is used on its unpaid tier. Google's terms for that tier allow it to use submitted content to improve its products and machine learning technologies, including by human review. Venditas removes the candidate's name, email address, phone number, links and street address before any text is sent. Scanned CVs are sent as page images and cannot be de-identified this way.
As at the effective date.
| Sub-processor | Entity and location | What it processes | Retention |
|---|---|---|---|
Google LLC (Gemini API, generativelanguage.googleapis.com) |
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Processing in the United States and other Google locations. | The text extracted from the CV, or images of up to the first four pages where the CV is a scan. Sent up to three times per upload if a call fails and is retried. | Governed by Google's terms for the Gemini API. Venditas stores nothing returned by Google. [CONFIRM: the applicable Google terms, the tier in use, and Google's stated retention and human-review position — see legal/compliance-notes.md, item 1.] |
| Supabase (Postgres database, hosted on Amazon Web Services) | Supabase, Inc., USA; infrastructure operated by Amazon Web Services in [REGION — CONFIRM]. | Account and metering data only: user email address, agency name, first/last seen timestamps, usage count, contact flag, unsubscribe token, and request counters keyed to salted hashes of the IP and email address. No candidate data. | Until deleted on request; see clause 4.3. |
| Vercel (application hosting) | Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Serverless functions execute in region iad1 (US East, Washington D.C.). |
Executes the application. Processes the uploaded CV in memory for the duration of the request. Writes no candidate data to storage. Operational logs may exist — see legal/compliance-notes.md, item 3. |
Per the provider's log retention. |
GoDaddy (SMTP relay, smtpout.secureserver.net) |
GoDaddy.com, LLC, 2155 E GoDaddy Way, Tempe, AZ 85284, USA. | The user's email address and the content of email Venditas sends them. No candidate data. | Per the provider's terms. |
Note for review. The hosting and email providers above are inferred from the repository's configuration and must be confirmed and named properly, with the correct legal entity and processing region, before this annex is given to a customer. A sub-processor list with a placeholder in it will fail procurement.
Separately, the venditas.in web page loads typefaces from Google Fonts, which discloses a visitor's IP address to Google. This is not a sub-processor of the Customer's Candidate Data, but it is disclosed in the Privacy Policy and should either be removed by self-hosting the fonts or kept and disclosed.
Venditas will give thirty days' notice by email before this list changes (clause 7.2).
Annex 4 — International transfers
This annex is a description of the intended position, not an executed transfer instrument. The instruments referred to below must be executed in their official form, with the tables and options completed correctly. An incorrectly completed instrument provides no lawful basis for the transfer at all. This annex must be reviewed by a solicitor and the correct current form used.
A. The transfers being made
- Customer (UK/EEA) → Venditas (India). Candidate Data and account data. India has no UK adequacy regulation and no EU adequacy decision.
- Venditas → Google LLC (United States and other Google locations). CV text or page images, transiently, for structured extraction.
- Venditas → Supabase / Amazon Web Services (region per Annex 3). Account and metering data only.
- Venditas → hosting and email providers (regions per Annex 3).
B. Mechanism for UK customers
The parties shall enter into the UK International Data Transfer Agreement (IDTA) issued by the Information Commissioner under section 119A of the Data Protection Act 2018, or alternatively the EU Standard Contractual Clauses (Module Two: controller to processor) together with the UK International Data Transfer Addendum. The executed instrument is appended to this agreement and takes precedence over this Annex to the extent of any conflict.
The Customer, as exporter, remains responsible for carrying out a Transfer Risk Assessment. Venditas shall provide the information the Customer needs for it, including the information in Annexes 1 to 3 and any information it has about government access requests it has received (to the effective date: none).
C. Mechanism for EU/EEA customers
The parties shall enter into the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), with the following selections proposed:
| Clause | Selection |
|---|---|
| Clause 7 (docking) | Included |
| Clause 9 (sub-processors) | Option 2, general written authorisation, 30 days' notice |
| Clause 11 (redress) | Optional independent dispute resolution body: not included |
| Clause 17 (governing law) | [MEMBER STATE — TO BE AGREED] |
| Clause 18 (forum) | Courts of [MEMBER STATE — TO BE AGREED] |
| Annex I, II, III | Populated by Annexes 1, 2 and 3 of this agreement |
The Customer, as exporter, remains responsible for the Transfer Impact Assessment.
D. Points relevant to a transfer risk assessment
Offered as factual input to the Customer's own assessment, not as a conclusion:
- The volume of data at rest in India is nil. Candidate Data exists only in memory during a request. There is no database in India, no file store, and no backup, so there is nothing for an Indian authority to compel production of after the fact.
- Venditas has never received a government or law enforcement request for data.
- The operator will notify the Customer of any such request unless legally prohibited (clause 13.4).
- Indian law includes powers of interception and of compelled disclosure (for example under the Information Technology Act 2000 and the Telecommunications Act 2023). The Customer should assess these against the fact that Venditas holds no Candidate Data at rest.
- Transfers onward to Google LLC in the United States are governed by Google's own terms; where relevant, the Customer should consider whether Google LLC's certification under the EU-US Data Privacy Framework and the UK Extension is applicable to the service in use. [CONFIRM CURRENT POSITION.]
Signatures
For and on behalf of [CUSTOMER LEGAL NAME]
Name: ______________________ Title: ______________________
Signature: ______________________ Date: ______________
For and on behalf of Venditas
Name: ______________________ Title: Proprietor
Signature: ______________________ Date: ______________