Legal
Data Processing Agreement (AVV)
Last updated: October 2026
This English version is a convenience translation. Only the German version (Auftragsverarbeitungsvertrag) is legally binding.
For companies that manage applications and interviews, or their employees in Mirage Office, with Mirage. The agreement meets the requirements of Art. 28 GDPR and becomes part of the terms and conditions with a business account.
§ 1 Subject matter and duration
- This agreement governs the processing of personal data by Lehel Kakonyi, sole proprietorship, trading as “Miragescouting.de”, Mühlenstraße 8 a, 14167 Berlin, Germany (“processor” or “Mirage”) on behalf of the business customer (“controller”) when providing the services under the terms and conditions.
- The agreement is concluded with the contract for a business account and becomes part of the terms and conditions; electronic conclusion satisfies the form required by Art. 28(9) GDPR. On request we provide a signed copy.
- The term corresponds to the term of the main contract. Obligations regarding deletion, return and confidentiality continue beyond it.
§ 2 Allocation of responsibilities
Mirage processes on behalf of the controller:
- the controller's job postings, applications and hiring process,
- AI interviews, transcripts, evaluations and reports on applications to the controller,
- interviews the controller requests through the interface (API) from its applicant tracking system,
- employee data in Mirage Office.
Where candidates have their own Mirage account, Mirage processes the data of that account as a controller in its own right; the privacy policy sets out the details. The same applies to data Mirage processes for its own operation, such as billing and platform security.
§ 3 Nature and purpose of the processing
- providing, hosting and storing the platform and its data,
- conducting structured AI voice interviews, including transcription,
- evaluating conversation content against the criteria set by the controller and producing reports with supporting quotes and recommendations,
- sending invitations and notifications,
- pipeline, analyses and metrics for the controller's recruiting,
- in Mirage Office: employee profiles, feedback, pulse surveys, performance reviews and self-assessments,
- support, error analysis and security.
§ 4 Types of data and data subjects
Types of personal data:
- master and contact data of applicants, of the controller's users and of employees,
- application documents such as CVs and details of qualifications,
- interview content: speech is processed in real time during the interview; Mirage stores no audio recordings, but the transcript, evaluations, supporting quotes and the report,
- records of notices and consents shown before the interview,
- communication, usage and log data,
- in Mirage Office: organisational data, feedback, pulse survey responses (pseudonymised), performance reviews and self-assessments.
Special categories of personal data (Art. 9 GDPR) are not processed intentionally. The controller designs criteria and questions so that such data is not collected.
Data subjects:
- the controller's applicants and candidates,
- the controller's users, such as recruiters and hiring managers,
- the controller's employees, where Mirage Office is used.
§ 5 Instructions and rights of the controller
- Mirage processes the data only on documented instructions from the controller, unless Mirage is required to process it by Union or Member State law; in that case Mirage informs the controller beforehand unless the law prohibits this.
- Instructions are this agreement, the terms and conditions, the configuration in the controller's account and individual instructions in text form.
- If Mirage considers that an instruction infringes data protection law, Mirage informs the controller without delay and may suspend execution until it is clarified.
- The controller is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects. It has the right to give instructions and to verify compliance with this agreement (§ 11).
§ 6 Mirage's obligations
- Mirage does not process the data for its own purposes and does not pass it on to third parties other than the authorised sub-processors.
- Mirage commits all persons with access to the data to confidentiality, unless they are under a statutory obligation of confidentiality.
- Mirage implements the technical and organisational measures under Art. 32 GDPR described in Annex 1. Mirage may develop them further provided the level of protection is not reduced.
- Mirage assists the controller with appropriate measures in responding to requests from data subjects (Art. 12 to 22 GDPR). Requests received directly by Mirage are forwarded without delay.
- Mirage assists the controller in meeting the obligations under Art. 32 to 36 GDPR, in particular with a data protection impact assessment, taking into account the nature of the processing and the information available.
- Mirage's contact for data protection is Lehel Kakonyi, reachable at legal@miragescouting.de.
§ 7 Sub-processors
- The controller authorises the sub-processors listed in Annex 2.
- Mirage informs the controller of intended changes at least 30 days in advance in text form. The controller may object within 14 days for an important data protection reason. If the parties find no solution, the controller may terminate the affected services with effect from the change.
- Mirage contractually imposes on every sub-processor the same data protection obligations as set out in this agreement. If a sub-processor fails to fulfil its data protection obligations, Mirage remains fully liable to the controller for the performance of that sub-processor's obligations (Art. 28(4) GDPR).
§ 8 Transfers to third countries
The platform's databases are located in Frankfurt am Main. Some sub-processors, in particular providers of AI models, process data outside the European Economic Area. Such transfers only take place under Chapter V GDPR: on the basis of an adequacy decision, including the EU-US Data Privacy Framework where the recipient is certified, and otherwise on the basis of the EU standard contractual clauses.
§ 9 Personal data breaches
Mirage notifies the controller of a personal data breach without undue delay after becoming aware of it, with the information under Art. 33(3) GDPR as far as available, and assists with the investigation and any notifications.
§ 10 Deletion and return
- Until the end of the contract, the controller can retrieve reports and transcripts.
- After the end of the contract, Mirage deletes the data processed on the controller's behalf within 30 days, or hands it over beforehand on request, unless there is a legal obligation to retain it. On request, Mirage confirms the deletion in text form.
- During the contract, Mirage deletes individual data on the controller's instruction.
- Data in backups is deleted when the backup retention period expires and is not otherwise processed until then.
§ 11 Evidence and audits
- Mirage makes available to the controller all information necessary to demonstrate compliance with this agreement.
- The controller, or an auditor appointed by it and bound to confidentiality, may carry out audits by arrangement with at least four weeks' notice during normal business hours, as a rule once a year and additionally where there is a specific reason. The powers of the supervisory authorities remain unaffected.
§ 12 Liability and final provisions
- Liability is governed by Art. 82 GDPR; otherwise the liability rules of the terms and conditions apply.
- In the event of conflict between this agreement and the terms and conditions, this agreement prevails on data protection matters.
- Changes must be made in text form. German law applies.
Annex 1 · Technical and organisational measures (Art. 32 GDPR)
Confidentiality
- Hosting in data centres of the providers listed in Annex 2, with their physical access control; the databases run in Frankfurt am Main.
- Access only with a personal account; sessions use encrypted, httpOnly session cookies with limited validity.
- Logical separation by organisation within the application: each company sees only its own jobs, applications and employees.
- Role-based permissions within an organisation.
- Internal services only accept calls with a valid service credential.
- Stored files such as transcripts are not public and can only be retrieved through short-lived, signed links.
- Pulse survey responses in Mirage Office are stored pseudonymised.
Integrity
- Encrypted transport (TLS) for all connections over the internet.
- Interview decisions are recorded in a decision journal; access to performance reviews is logged.
Availability and resilience
- Encryption of stored data at rest by the hosting and storage providers.
- Database backup and restore through the database provider.
Review and evaluation
- Code changes are released through pull requests with automated checks, including scanning for accidentally published credentials and dependency checks.
- These measures are reviewed and adjusted whenever the processing changes.
Annex 2 · Sub-processors
| Provider | Service | Place of processing | Basis for third-country transfer |
|---|---|---|---|
| Hetzner Online GmbH | Servers for the application services | Germany | — |
| Neon (on Amazon Web Services) | Databases | Frankfurt am Main, Germany | EU standard contractual clauses; DPF where certified |
| Cloudflare, Inc. | File storage (R2), incl. transcripts | EU and worldwide | EU standard contractual clauses; DPF where certified |
| Vercel Inc. | Delivery of the web application | worldwide (edge network) | EU standard contractual clauses; DPF where certified |
| Google (Gemini, Google Cloud) | Voice AI for interviews and coaching, other AI features | USA and other locations | EU standard contractual clauses; DPF where certified |
| Anthropic PBC | AI evaluation and question plans | USA | EU standard contractual clauses; DPF where certified |
| OpenAI | Indexing of role documents, alternative voice output | USA | EU standard contractual clauses; DPF where certified |
| Resend | E-mail delivery | USA | EU standard contractual clauses; DPF where certified |
| Functional Software, Inc. (Sentry) | Error monitoring | USA | EU standard contractual clauses; DPF where certified |
| PostHog, Inc. | Usage analytics, only with consent | USA | EU standard contractual clauses; DPF where certified |