Data processing agreement
Last updated 2026-10-02
This agreement applies when you use ClearSubmittal (clearsubmittal.com) for your business or organisation and the content you submit contains personal data about other people. It is part of our terms and conditions. It does not need to be signed. It applies from the day you start using the service. If you use ClearSubmittal for purely personal purposes, it does not apply to you.
1. Roles
You are the controller of the personal data in the content you submit. NETBEARS TEAM SRL, VAT ID RO37261366, Corneliu Baba 8, Iași, Romania, is your processor. We process that data only to provide the service to you.
For your account, billing and support data, and for technical logs, we are the controller. The privacy policy covers those. This agreement does not.
The words controller, processor, personal data, processing and personal data breach have the meaning they have in Regulation (EU) 2016/679 (GDPR).
2. What we process, and why
- Subject matter and purpose: ClearSubmittal turns a CV, interview notes and a job requisition into a client-ready candidate submittal package, formatted and toned to match each end client, in under a minute. We process your content to do that, and for nothing else.
- Duration: as long as your account is open, and then for the retention periods in the privacy policy.
- Types of content: Pasted or uploaded CV text; Pasted interview notes (rough recruiter shorthand); Pasted job requisition text; Selected end-client format/tone profile. These may contain names, contact details and other personal data of the people in your documents. Please do not submit special categories of personal data unless you need to, and then only where you have a lawful basis.
- People concerned: the people whose data is in the content you submit, for example your customers, employees and suppliers.
3. What we do as your processor
As required by Article 28 of the GDPR, we:
- process personal data only on your documented instructions. Your use of the dashboard, the API and connected apps, and these terms, are your instructions. If we think an instruction breaks the law, we tell you;
- make sure everyone who may access the data is bound by a duty of confidentiality;
- keep the data secure as Article 32 requires. Data is encrypted in transit (TLS) and at rest, access is limited to what the service needs to run, access and activity are logged, and the content of your jobs is deleted on the schedule in the retention list;
- use only the sub-processors in section 5, under written terms that give the same data protection duties as this agreement;
- help you answer requests from individuals who use their rights under Chapter III of the GDPR, as far as this is possible. If someone writes to us about data we process for you, we pass the request to you;
- help you meet your duties under Articles 32 to 36 of the GDPR (security, breach notice, impact assessments and prior consultation), taking into account what the service does and the information we have;
- delete the data at the end of the service (see section 10);
- give you the information you need to show that we meet Article 28, and allow audits (see section 7).
4. What you do as controller
You make sure that you may submit the content to us, that you have a lawful basis for the processing, and that you have told the people concerned what the law requires. You are responsible for the content you submit.
5. Sub-processors
You give us general authorisation to use these sub-processors for content you submit:
- Amazon Web Services (AWS) — hosting and storage, in the eu-central-1 (Frankfurt, Germany) region.
- Amazon Bedrock, an AWS service — runs the AI models that draft and review your results, on Bedrock's EU cross-region inference profiles. Anthropic, the models' developer, does not receive your data, and the calls are not used to train any model.
- Amazon SES — sends the notifications this product sends to you, and receives the email you send to hello@clearsubmittal.com.
We will tell you at least 30 days before we add or replace a sub-processor. We do this by email to your account address and by updating this page. If you object on reasonable data protection grounds within that time, we will work with you to find a solution. If we cannot, you may stop using the service and ask for your remaining credits under the rules in our terms, and the change will not apply to you until then.
We are responsible to you for the sub-processors we use for your content.
6. Creem
Creem is our payment provider and the merchant of record for credit-pack purchases. Creem is an independent controller of the payment and billing data it collects, such as card details, tax and invoice data. It handles that data under its own privacy policy. Creem is not a sub-processor under this agreement, and this agreement does not cover its processing.
7. Audits and information
On request, we give you the information needed to show that we keep to this agreement. You may audit us once a year, or after a personal data breach, if you give us reasonable notice, keep the audit short, and keep what you learn confidential. We may meet an audit request first by sending our current documentation and the compliance reports of our sub-processors. Audits are at your cost.
8. Personal data breaches
We tell you without undue delay, and within 48 hours of becoming aware of it, if there is a personal data breach affecting the content you submit. We tell you by email to your account address. We include what we know about the nature of the breach, the data affected, the likely consequences and the steps we are taking. We add more information as we learn it.
9. International transfers
We store and process your content in the EU: eu-central-1 hosting and the EU Bedrock inference profiles. We do not transfer it outside the European Economic Area for this service. If that ever changes, we will give you notice as in section 5, and any transfer will rest on a lawful mechanism. Where a transfer of personal data from the EEA to a country without an adequacy decision is needed, the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914) apply. Module Two (controller to processor) applies, and the clauses are part of this agreement. Their details are the ones in this agreement and in section 5. The competent supervisory authority is ANSPDCP (the Romanian National Supervisory Authority for Personal Data Processing).
10. Deletion or return at the end
When your account is deleted or the service ends, we delete the content you submitted and the results made from it, on the schedule in the retention list of our privacy policy. Until then you can download your results from the dashboard. We keep only what the law requires us to keep, such as billing records, and that is not content you submitted.
11. US state privacy law addendum
This section applies when US state privacy laws apply to the personal data we process for you. These laws include the California Consumer Privacy Act as amended (CCPA), and the privacy laws of Virginia, Colorado, Connecticut, Utah and other states. In this section you are the business (or controller) and we are your service provider (or processor).
- We process personal data only for the business purposes in section 2, and as you instruct us.
- We do not sell or share personal data, as those words are defined in these laws. We do not use it for targeted advertising.
- We do not retain, use or disclose the data outside our direct business relationship with you, or for any purpose other than the one in this agreement. We do not combine it with personal data from other sources, except as the laws allow.
- We keep to the duties that these laws put on a service provider or processor, and we give you the same level of privacy protection that they require. We tell you if we can no longer do so.
- You may take reasonable steps to make sure we use the data in line with your duties, and to stop and fix any use that is not. We help you answer requests from consumers as in section 3.
- Our sub-processors are bound by written terms with the same duties. See section 5.
- We certify that we understand these rules and will keep to them.
12. Liability and order of terms
The limits on liability in our terms apply to this agreement, to the extent the law allows. If this agreement and the terms disagree about the processing of personal data, this agreement comes first. Nothing here changes the Standard Contractual Clauses if they apply.
13. Changes
We may update this agreement, for example when the law changes or when we change a sub-processor. The date at the top of this page is when it was last updated. For changes that reduce the protection of your data, we give you 30 days' notice by email before they apply.
14. Contact details
Questions about this agreement, or a request for a signed copy, go to hello@clearsubmittal.com. See also our privacy policy.
Company: NETBEARS TEAM SRL
Trade Register: J2017000687229
EUID: ROONRC.J2017000687229
VAT ID: RO37261366
Address: Corneliu Baba 8, Iași, Romania
Phone: +40 742 121 246
Email: hello@clearsubmittal.com