Skip to main content
Competrace
Back to Terms of Service

Data Processing Agreement

Last updated: July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between Competrace ("Processor", "we", "us") and the customer organization that accepts the Agreement ("Controller", "you"). It governs our processing of personal data on your behalf under Article 28 of the EU General Data Protection Regulation (GDPR). Where this DPA conflicts with the rest of the Agreement on data protection, this DPA prevails.

1. Roles & Scope

You determine the purposes and means of processing the employee evaluation data your users enter into Competrace and act as the Controller. We process that data only as your Processor, to provide the competence-tracking service.

2. Subject Matter & Details of Processing

  • Subject matter: provision of the Competrace platform.
  • Duration: the term of the Agreement.
  • Nature & purpose: storing and displaying skill ratings, assessments, and review notes entered or uploaded by your users.
  • Categories of data subjects: your employees and staff.
  • Categories of personal data: name, email, role, skill ratings, assessment records, and free-text assessor notes.

3. Our Obligations (Art. 28(3))

Competrace shall:

  • (a) process personal data only on your documented instructions, including on transfers, unless required by law (and then notify you first unless the law prohibits it);
  • (b) ensure persons authorized to process the data are bound by confidentiality;
  • (c) implement the technical and organizational measures in Annex 2 (Art. 32);
  • (d) engage sub-processors only under the conditions in Section 4;
  • (e) assist you, by appropriate measures, to respond to data subject rights requests — supported by our self-service data export, and by admin-initiated permanent deletion of a member and the evaluation records about them. Activity-log entries recording which administrator took an action are retained under Art. 6(1)(f) and Art. 17(3)(e). On request, and where those grounds do not apply, we pseudonymize the entry for the requesting individual: their name is replaced with "Erased user" wherever the entry names them — as actor and as subject — and the entry is unlinked from them. The other person named on the entry, and the record of the action, remain;
  • (f) assist you with security, breach notification (Section 5), and data protection impact assessments;
  • (g) at your choice, delete or return all personal data at the end of the Agreement, and delete existing copies unless law requires retention;
  • (h) make available the information necessary to demonstrate compliance and allow for and contribute to audits.

4. Sub-processors

You grant general authorization for the sub-processors listed on our sub-processors page (currently Supabase, Vercel, Resend, and Paddle). We give at least 30 days' notice before adding or replacing a sub-processor, during which you may object on reasonable data-protection grounds. We remain liable for our sub-processors' performance.

5. Personal Data Breach

We notify you without undue delay (target: within 48 hours) after becoming aware of a personal data breach affecting your data, with the information you need to meet your own Art. 33/34 obligations.

6. International Transfers

Where a sub-processor is located outside the EEA, transfers are covered by the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework, with a transfer impact assessment on file.

7. Liability & Term

This DPA is governed by the same law and subject to the same liability terms as the Agreement, and takes precedence over conflicting Agreement provisions on data protection.


Annex 1 — Processing Details

As set out in Section 2 above.

Annex 2 — Technical & Organizational Measures (Art. 32)

  • Data hosted in the EU (Frankfurt) with encryption in transit and at rest.
  • Row-Level Security isolating each organization's data.
  • Rate-limiting on login, password reset, and one-time-password flows.
  • Access to production data limited to authorized personnel under confidentiality.
  • Regular review of security advisories and dependency patching.

Annex 3 — Sub-processors

The current list, with purpose and location, is maintained on our sub-processors page.

Contact & Signature

By accepting the Terms of Service, you and Competrace agree to this DPA. Enterprise customers who require a counter-signed copy with our full registered legal entity name and address may request one at support@competrace.com.