Data Processing Agreement
Version 1.0 — last updated 14 July 2026
Overview
This page summarises Mentum's Data Processing Agreement (the "DPA") for employer customers. The DPA is the contractual basis on which Mentum processes personal data on your behalf when you use the Mentum platform to post jobs, review matched candidates, record hiring decisions, and collaborate with your team.
The DPA applies in addition to our Terms of Service and is structured to satisfy the requirements of UK GDPR Article 28, the EU Standard Contractual Clauses (Module Two, 2021/914), and the UK International Data Transfer Addendum.
How to execute the DPA
The DPA is a bilateral agreement that requires signature by both parties. To request a signable copy:
- Email privacy@mentumjobs.com with the subject line "DPA request".
- Include your organisation's legal name, registered address, authorised signatory, and contact email for data-protection notices.
- We will send you a counter-signable PDF within two working days.
You can review the full text of the DPA below before requesting a signable copy.
Key clauses at a glance
Roles
You (the employer) are the data controller for the personal data you submit to Mentum through your team's use of the platform. Mentum is the data processor for that data. Candidates registering directly with Mentum have a separate controller relationship with Mentum governed by our Privacy Policy.
What data the employer feeds in
- Job postings (titles, descriptions, salary, location, skills)
- Match decisions and rejection reasons (including any free-text notes you record)
- Interview feedback (rubric scores, notes, hire recommendations)
- Employer team membership and internal comments on candidate matches
- Company profile information (description, website, logo, founding year, mission, HQ location, industry, employee count)
Mentum's core obligations
- Process the data only on your documented instructions (Article 28(3)(a))
- Maintain confidentiality undertakings (Article 28(3)(b))
- Implement the technical and organisational measures described in Annex II (Articles 28(3)(c) and 32)
- Notify you of any new sub-processor at least 30 days before engagement, with your right to object (Article 28(3)(d))
- Assist you in responding to data-subject-rights requests (Article 28(3)(e))
- Notify you of any personal data breach within 72 hours of becoming aware (Article 28(3)(f) and Article 33)
- Make available the compliance evidence you reasonably need to assess our processing (Article 28(3)(h))
- Return or delete your personal data on termination, save for the backup residual disclosed in section 13.9 of the DPA
Sub-processors
The full list of sub-processors is in Annex III of the DPA. The principal sub-processors are:
- Supabase Inc. (database, authentication, storage, real-time)
- Google LLC (Gemini for standard scoring narrative, extraction, classification, personas and embeddings)
- OpenAI (GPT-5.6 Luna Responses API for premium Career Advisor, interview practice, insights, CV optimisation, career recommendations and trajectory, hiring advice and job-description generation; production DPA and account-control evidence required before activation)
- Twilio SendGrid (transactional and lifecycle email)
- Railway Corp (API and frontend hosting, including server-side rendering and its session cookies; managed Redis)
- GitHub, Inc. (source code and CI/CD)
- Functional Software, Inc. (Sentry) (error tracking)
- Plus an optional Redis cache provider, an open-source malware scanner, and inbound feed data from Adzuna Ltd.
See the public sub-processor list for the always-current version with notification subscription.
International transfers
Some sub-processors host data in the United States. Where personal data is transferred outside the UK, the DPA incorporates the EU Standard Contractual Clauses (Module Two, 2021/914) together with the UK International Data Transfer Addendum, signed automatically on execution of the DPA.
Security commitments
- Encryption at rest (AES-256, managed by Supabase) and in transit (TLS 1.2 or higher with HSTS preload)
- Row-Level Security on every table;
SECURITY DEFINERdiscipline on all admin functions - Three-client database access isolation (service-role, per-request user, anonymous)
- Dual JWT verification path (HS256 + ES256 with JWKS) and an algorithm-confusion-proof validator
- Adversarial test suite covering eleven in-repo attack surfaces (Schemathesis fuzz, OWASP ZAP, AI red-team, race-condition chaos, IDOR, uploads, auth enumeration, SSRF, CSV injection, frontend monkey, webhook authenticity)
- 72-hour breach notification commitment; automated anomaly-detection cron compressing detection latency to a worst-case 5 minutes
- Recovery Time Objective target of 4 hours; Recovery Point Objective target of 5 minutes (targets bounded by vendor capability, not yet validated by an executed restore drill — see the SLA § 5)
The full technical and organisational measures inventory — with source-code citations — is in Annex II of the DPA.
Honest disclosures
Mentum is a single-developer pre-launch organisation. The DPA discloses this and the resulting accepted residuals (no segregation of duties, no formal training programme, no workstation MDM) with documented trigger conditions to revisit on headcount growth. The DPA also discloses:
- The Supabase backup restore drill has been documented but not yet executed end-to-end (deferred pending a paid staging environment).
- Some sub-processor Data Processing Agreement executions remain outstanding (Google Cloud, Twilio SendGrid, Sentry, Railway, Redis provider, and the Supabase UK GDPR addendum). Mentum commits to completing each before any production Customer Personal Data flows to the affected sub-processor in your tenancy.
- Multi-Factor Authentication for admin accounts is not yet implemented (deferred to paid-tier launch); admin sessions are instead bounded by a 4-hour
iatcap plus OTP re-auth for sensitive actions.
Full text
The complete DPA — including Annex I (subject matter, categories, and retention), Annex II (technical and organisational measures with source-code citations), Annex III (sub-processor list), and Annex IV (open privacy items disclosed to the controller) — is maintained in version control at docs/legal/dpa.md in the Mentum source repository and is available as a signable PDF on request.
For audit access to the source-code references cited in Annex II, contact privacy@mentumjobs.com.
Contact
- Privacy and DPA requests: privacy@mentumjobs.com
- Data Protection Officer: dpo@mentumjobs.com
Related: Privacy Policy | Terms of Service | Cookie Policy