Last edited on: 01-10-2026 · Version 1.0
This Agreement governs business use of SimplyOS, the recruitment platform provided by SimplyAi B.V. It consists of the subscription terms (Part A), the data processing agreement (Part B) and the support and availability terms (Part C). Your accepted order or checkout confirmation records your plan, users, prices and subscription period.
Part A: Subscription terms
1 Parties and agreement
1.1 “Simply”, “we” and “us” mean SimplyAi B.V., registered with the Dutch Chamber of Commerce under number 89521811, at De Nieuwe Erven 12, 5431 NT Cuijk, the Netherlands. Our VAT number is NL865008565B01. Contact us at info@simplyrecruit.ai. “Customer” and “you” mean the business or organisation identified in the accepted order or account registration. The Service is offered for professional use, not consumer use.
1.2 The “Service” is SimplyOS, our hosted recruitment platform, including the features, applications and integrations in your subscription. An “Order” is a written order accepted by both parties, or a completed online checkout. “Documentation” means the feature descriptions for your plan on the product and pricing pages at simplyrecruit.ai and the user instructions at docs.simplyrecruit.ai, each as they stand when your Order is accepted and as later updated under clause 14. Documentation does not include roadmap or planned features, “coming soon” or beta announcements, blog posts, case studies or other marketing material, or material for legacy products, unless your Order expressly includes them. “Customer Data” means the data you or your users provide, import or connect to the Service, such as candidate and contact records, files, communications and configurations, and the outputs generated from them. “Service Data” means data about the operation and use of the Service that is not Customer Data, such as account and billing details, usage statistics, logs and performance metrics. A “business day” is Monday to Friday, excluding Dutch public holidays.
1.3 This Agreement starts when an authorised representative creates the Customer’s account at ats.simplyrecruit.ai and accepts these terms through a clearly displayed notice, or accepts them electronically or in writing in another way. The representative confirms authority to bind the Customer. These terms, including Parts B and C, can be viewed and downloaded before acceptance, and we record the accepted version and the acceptance. Our Privacy Policy explains our own processing; acknowledging it is not consent to optional processing. The paid subscription starts on the date in the Order. Part B applies from the first time we receive personal data, including for a trial, demonstration or migration, so this Agreement must be accepted before any such data is supplied.
1.4 Mandatory law and any applicable EU standard contractual clauses prevail. Subject to that, an expressly negotiated Order prevails over these terms, but an Order changes Part B or our security, EU-processing or no-training commitments only if it identifies the provision it changes. Part B governs personal data processing, Part C governs support and availability, and Part A governs everything else. Documentation describes the Service but does not override this Agreement. The Customer’s general purchasing terms do not apply unless we accept them in writing.
2 Service and access
2.1 We grant you a non-exclusive right, for the subscription period, to use the Service and Documentation for your recruitment and related business activities within your Order. You may authorise employees, contractors and client or hiring-manager users where supported by your plan. You remain responsible for their use and for administrators acting within the authority you give them. Individual accounts must not be shared. Seats may be reassigned when personnel or responsibilities change, but not rotated to circumvent purchased user quantities.
2.2 We provide the Service with reasonable skill and care, materially in accordance with the Documentation and applicable law, including the advertised permission controls, approval defaults and audit history. A feature is not experimental merely because it uses AI. Beta features are clearly identified and enabled only when an authorised administrator opts in. They may change, malfunction or be withdrawn, should be tested before business-critical use, and carry no warranty or service level under Part C. Part B, confidentiality and mandatory liability still apply to them, and an incident in a beta feature that affects production functionality is treated as a production incident.
2.3 Your administrators control workspace access, connected accounts, permissions, automations and AI settings. You must use the available security controls, protect credentials and keys, keep administrator and billing contacts current and promptly report suspected unauthorised access. You are responsible for incidents and losses to the extent caused by your permission settings, credentials, compromised accounts or other acts or omissions of your users. Where both parties contribute to an incident, responsibility is shared according to each party’s contribution. Our own security and incident obligations remain, and clause 11 applies.
2.4 We provide support and availability commitments under Part C. We do not promise that software will be entirely error-free or that recruitment results, placements, revenue or candidate suitability will meet a particular outcome. These limitations do not diminish an express service, security or compliance obligation in this Agreement.
2.5 You authorise our designated personnel to access your workspace and relevant Customer Data where reasonably necessary to investigate and resolve a support request or an incident. Access is limited to the necessary people, data and duration, is logged, and is subject to our confidentiality and security obligations. We use a test environment where that is reasonably sufficient, and we do not use this access for monitoring, training or marketing. We do not make material changes to your records without your instruction, except where strictly necessary to contain an urgent incident, in which case we inform you promptly. This clause is a documented instruction under Part B.
3 Trial and implementation
3.1 The standard trial lasts 14 days, provides the advertised trial functionality and requires no payment card. It does not convert automatically into a paid subscription. We may end a trial at our discretion on notice, or immediately where we reasonably suspect misuse, a security risk or unlawful activity. Keep your own copies of valuable data during a trial. When a trial ends, you can retrieve your Customer Data under clause 13.7, and Part B and confidentiality continue while we hold it. Trial support is governed by clause C1.3.
3.2 Where you buy our managed migration, we use reasonable endeavours to complete the agreed standard migration within four weeks of the agreed kickoff, unless the Order sets a binding date. The migration plan identifies the included data and work and the exports, access, mappings and decisions you must provide on time. If unforeseeable data complexity or an agreed custom requirement needs more time, we explain the issue promptly and propose a revised completion date for your written agreement. Delays you cause extend the affected milestones by their actual impact. When we deliver the migrated data for review, you have ten business days to accept it or report material deficiencies in writing. We correct reported deficiencies, after which you have five business days to re-check them. The migration is accepted if you report no deficiencies in time or start using the migrated data in production, except for deficiencies that could not reasonably have been detected during review. Migration fees and additional scope are recorded in the Order or an accepted quote, and we do not charge for additional work without your approval.
4 Customer data and confidentiality
4.1 You retain all rights in Customer Data. You grant us only the rights necessary to host, process, transmit and otherwise use it to deliver, secure and support the Service on your instructions and comply with law. We do not sell Customer Data, use it for advertising, create a shared candidate or contact database from it, or disclose it to other customers. Any customer-authorised sharing remains subject to your permissions and instructions.
4.2 We and our subprocessors will not use Customer Data, including recordings, communications, prompts and outputs, to train or fine-tune any AI model. Processing needed to produce your requested outputs, index your workspace or retrieve its context is permitted solely to provide the Service to you. We may use Service Data, and anonymous statistics that cannot identify you or any individual or reconstruct Customer Data, to operate, secure and improve the Service in accordance with our Privacy Policy. Personal data processed on your behalf remains subject to Part B.
4.3 Each party will protect the other’s confidential information with at least reasonable care, use it only to perform or exercise rights under this Agreement, and disclose it only to people who need it and are bound by appropriate confidentiality obligations. Confidential information includes Customer Data, credentials, non-public product information, security reports and commercial terms. The receiving party is responsible for its permitted recipients.
4.4 Confidentiality does not cover information the recipient can establish was already lawfully known, became public without breach, was independently developed, or was lawfully received without restriction. A legally required disclosure is permitted only to the extent required, with prior notice where lawful and reasonable assistance to seek protection. These duties continue for five years after termination, and for personal data, credentials and trade secrets for as long as they remain protected by applicable law or their nature.
5 AI and recruitment decisions
5.1 The Service may search, parse, transcribe, translate, summarise, score, rank, recommend, draft and execute configured actions using AI. These features assist recruitment work. Outputs can contain errors, omissions or inappropriate inferences and must be assessed in context. You must review material facts before relying on them, sending them externally or making decisions affecting a person. Generated contracts and other legal documents require your own appropriate review.
5.2 AI actions require approval by default. Only an authorised administrator may give AI greater autonomy for specified tools or workflows. We apply the configured permissions, record approvals and executions, and let administrators change or revoke authorisations; an expired proposal does not execute without renewed authorisation. Enabling autonomy authorises the configured actions and their disclosed usage costs, and nothing outside that configuration. Revocation stops further execution but cannot recall a message already delivered or an external action already completed.
5.3 Candidate matching provides the advertised filters, scores, explanations, adjustable criteria and human overrides, and applies the advertised masking of names, age and gender before AI evaluation. Masking does not make the dataset anonymous or remove all risk of bias. You must choose relevant, lawful selection criteria, consider data quality and possible discriminatory effects, and ensure meaningful review by a person with authority to change the result.
5.4 You must not use the Service to make a solely automated rejection or other decision producing legal or similarly significant effects for a person unless that use is expressly supported, permitted by applicable law and configured with the required safeguards. Ordinary approval or autonomy settings do not, by themselves, establish a lawful exception. You must not use the Service for prohibited AI practices, unlawful discrimination or unlawful workplace emotion inference.
5.5 Each party performs the AI Act and other regulatory duties that apply to its actual role. As provider of the Service, we remain responsible for our duties concerning its design, documentation, logging, transparency, human-oversight features, risk management and conformity. As deployer, you are responsible for competent oversight, staff instruction, required notices and impact assessments. Neither party transfers its statutory responsibilities to the other, and we cooperate on material AI incidents, corrective measures and lawful regulatory enquiries.
6 Connected services and communications
6.1 You may connect supported email, messaging, calendar, meeting, telephony, data-source and other services. You must have authority to connect the accounts and share the relevant data, observe the third party’s terms and configure access and recipients appropriately. Services you contract for directly are supplied by their providers under their own terms and charges. We are not responsible for their availability or performance, or for a loss caused solely by such a provider. We remain responsible for our connector code, routing and permission handling, and for the subprocessors we engage under Part B.
6.2 Recording, transcription and communication capture require a lawful basis, appropriate information to participants and any consent the circumstances require. You are responsible for obtaining those permissions, giving the required notices and complying with employment, communications and direct-marketing rules, including opt-outs. We do not obtain or verify participant permission for you. You control the recipients and publication of documents, reports and messages, including automated sequences, and we apply the Service’s advertised access and approval safeguards. We are not responsible for a missing permission or notice except to the extent our own breach contributes to it. A recording feature does not itself authorise recording.
6.3 Enrichment retrieves information from external sources on your instruction. Results may be incomplete or out of date; you must assess their lawful use, accuracy and any transparency obligations before contacting or evaluating a person. We do not pool your contacts into a database for other customers. Availability of an email address or telephone number does not establish consent to contact its owner.
6.4 With your own AI provider key, you choose a supported provider and region, contract directly for its usage charges and are responsible for that provider’s suitability, account terms, geographic settings and spending controls. We follow the endpoint and routing you configure and do not substitute another provider or region. Enabling that configuration is your processing instruction under clause B3.2, and any international transfer must comply with clause B3.3. Usage costs are addressed in clause 8.3.
6.5 Supported channels depend on the plan, region and third-party access. If a third party withdraws access, we give prompt notice and use reasonable efforts to restore it or offer a materially equivalent solution; clause 14.2 applies if purchased functionality is materially reduced. Simply does not provide payroll administration, employment-law advice or collective-agreement compliance. External career sites, job boards and back-office systems remain third-party services, and our integrations with them are limited to the functionality you purchased.
6.6 Third-party platforms may restrict, suspend or close a connected account, for example because of messaging volume, automation or policy changes. You accept that risk when you enable a connection and must follow the platform’s rules, applicable law and the usage controls we communicate. We maintain the safeguards described for the connection, such as rate limits and approval controls, but we are not liable for a restriction caused by your conduct or by an independent platform decision.
7 Acceptable use and service limits
7.1 You must not use the Service to infringe rights, process unlawfully obtained data, send unlawful bulk communications, introduce malware, evade security or access restrictions, or disrupt the Service. You must not run penetration tests or vulnerability scans without our written consent, or extract data from the Service by automated means other than our export functions and APIs. You must not resell access outside an agreed arrangement, reverse engineer the software except where a non-excludable legal right permits it, or copy our protected software or Documentation to create a competing product. Ordinary data exports, lawful interoperability and use of your own business knowledge are permitted.
7.2 We may apply reasonable technical and usage limits to protect the Service, including limits on storage, bandwidth, API calls, communications and AI activity. If your use materially exceeds the advertised purposes and purchased capacity, or creates a material risk to security, stability or other customers, we may ask you to reduce it or propose a plan or fee change. If no solution is agreed, we may proportionately throttle or restrict the affected activity. We give notice and an opportunity to respond where practicable, but may act immediately to contain an urgent risk. Additional fees require your agreement, and these measures will not override an express purchased allowance or obstruct exports or switching.
8 Fees and renewal
8.1 Your Order states the currency, subscription price, seat commitment, billing frequency and initial term. Prices exclude VAT and other applicable taxes. Monthly and annual subscriptions are prepaid for each period. Invoiced services outside the prepaid Order, including invoiced Enterprise subscriptions, are payable within 30 days of invoice unless the Order states otherwise. Metered usage is billed monthly in arrears unless prepaid credits apply. A good-faith dispute notified promptly suspends collection of the disputed amount while the parties resolve it; undisputed amounts remain payable. A discounted multi-year commitment and its payment schedule must be stated in the Order.
8.2 The subscription renews automatically for the same period unless either party gives notice of non-renewal at least 30 days before the end of an annual period, or at any time before the end of a monthly period. You can give notice in the account or by email to info@simplyrecruit.ai, and we confirm the effective date. Non-renewal takes effect at the end of the period, subject to the termination and switching rights below. Upgrades and additional seats require an authorised request at the price shown before confirmation and are charged pro rata for the rest of the period. Seat reductions and downgrades take effect at renewal.
8.3 With a Simply-managed AI key, AI usage is charged at the underlying provider’s price plus a 20% Simply service charge. With your own key, the provider bills you directly and we add no markup. You are responsible for the models and settings you choose and the usage they generate, including input size, output length, repeated runs and workflow volume, and for configuring and monitoring the available limits. The usage overview in settings and our workflow cost examples are estimates, not quotes, spending caps or guaranteed maximums. You are not responsible for charges caused by our unauthorised execution or our failure to apply an agreed control. Changes to underlying provider prices apply to usage after they are notified or displayed; changes to our service charge follow clause 8.5.
8.4 Some services, including enrichment, use prepaid credits, which only authorised administrators may buy through the platform at the price and terms shown before purchase. Enrichment uses one credit for an email result and ten for a telephone result. No credit is charged if no result is returned, a request fails or a request is retried for technical reasons; a deliberate new lookup that returns a result is charged again. Purchased credits expire 12 months after purchase, can be used only during an active subscription, and are not transferable, redeemable for cash or refundable on cancellation, non-renewal or early switching. This does not exclude correcting an erroneous charge, a refund required by mandatory law, or repaying unused credits where our breach or withdrawal prevents their agreed use. Promotional credits have no cash value and expire as disclosed when granted.
8.5 Subscription price increases apply only from a renewal, with at least 60 days’ notice for annual and 30 days’ notice for monthly subscriptions; if notice comes too late, the increase applies from the next renewal for which enough notice was given. You may prevent renewal before an increase takes effect. New credit prices apply to new purchases. Changes to our AI service charge follow the same rule, and changes to underlying provider prices follow clause 8.3.
8.6 If an undisputed amount remains unpaid 14 days after our written notice, we may proportionately restrict paid functionality. If it remains unpaid 30 days after that notice, the non-payment is a material breach and we may terminate under clause 12.1 without a further cure period. Dutch statutory commercial interest and reasonable collection costs accrue from the due date as permitted by law. Non-payment does not affect your statutory data access and switching rights, and we will not withhold Customer Data because an invoice is disputed.
9 Intellectual property and claims
9.1 We and our licensors retain all rights in the software, underlying models, Documentation and reusable tools. As between the parties, you retain or receive all transferable rights we hold in outputs generated from your Customer Data; where an assignment is ineffective, we grant you a perpetual, worldwide, royalty-free right to use, modify and share those outputs for any lawful purpose. This does not transfer our underlying technology or third-party rights. Outputs may resemble other outputs and may not be protectable as intellectual property. You retain rights in your templates and configurations.
9.2 We may use voluntarily provided product feedback without restriction, but that permission does not extend to personal data, confidential information or your protected content included with it. We may not use your name or logo in publicity without your prior permission.
9.3 If a credible intellectual-property claim prevents lawful provision of the Service, we may obtain the necessary rights or provide a materially equivalent non-infringing solution. If neither is reasonably available, we may terminate the affected Service, refund its unused prepaid fees and provide exit assistance under clause 13. We do not defend or indemnify you against third-party intellectual-property claims unless an Order expressly says so, without affecting our liability for our own breach under clause 11.
9.4 You will defend us against third-party claims, including claims by candidates, contacts, data subjects and platform providers, and indemnify us against the resulting damages, costs and, to the extent recovery is legally permitted, fines, to the extent they arise from: (a) Customer Data or instructions you provide without the necessary rights or legal basis; (b) your recruitment decisions and your dealings with candidates and contacts; (c) communications, recordings or enrichment you initiate through the Service; or (d) your breach of clause 5.4, 6.2, 7.1 or B2.2. This does not cover a claim to the extent caused by our breach. We must notify you promptly, give reasonable cooperation at your expense and let you control the defence, and may participate at our own cost. Delay releases you only to the extent it materially prejudices you. No settlement may admit fault or impose a non-monetary obligation on us without our consent, not unreasonably withheld. Clause 11.3 sets the applicable limit.
10 Remedies and suspension
10.1 If the Service materially fails to meet this Agreement, notify us with reasonable detail. We will investigate and remedy the failure without undue delay. A material breach is a breach that substantially deprives the other party of what it is entitled to expect under this Agreement, including non-payment under clause 8.6. Where performance is still possible, a party seeking termination for material breach must give written notice specifying the breach and a reasonable cure period, normally 30 days. No further cure period is needed where performance is permanently impossible, a breach cannot be remedied or mandatory law permits immediate termination.
10.2 We may temporarily suspend affected access where reasonably necessary to stop a serious security threat, unlawful processing or material misuse, or where legally required. We give notice and an opportunity to remedy unless urgency or law prevents it, limit the suspension to what is necessary and promptly restore access when the reason ends. We preserve data and provide safe export access where lawful and technically possible.
11 Liability
11.1 Each party is responsible for loss caused by its attributable breach or wrongful act, subject to this clause. Neither party is liable for lost profits, lost business opportunities, loss of goodwill or indirect or consequential loss.
11.2 Subject to clauses 11.3 and 11.4, each party’s aggregate liability for events first occurring in a contract year is limited to the Base Amount. A contract year is each 12-month period from the paid subscription start, or from acceptance for a trial. The Base Amount is the fees paid or payable under this Agreement for the 12 months before the first event giving rise to a claim, capped at EUR 100,000. If that event occurs in the first 12 months, the Base Amount is 12 times the monthly subscription fee (an annual fee divided by 12) plus usage and implementation fees paid or payable before the event, subject to the same cap. Related events count as one event, occurring on the date of the first.
11.3 Your obligations under clause 9.4 are not subject to the Base Amount but to a separate aggregate limit of EUR 250,000 per contract year. All other claims, including for breach of confidentiality, data protection or security, fall under the single Base Amount limit in clause 11.2. The limits cover contractual and non-contractual claims and reasonable claim expenses, without double recovery, and are subject to clause 11.4.
11.4 No exclusion or limit applies to fraud, intent or conscious recklessness of the liable party’s management, or to liability that cannot lawfully be excluded or limited, including for death or personal injury. Properly due fees are payment obligations, not damages subject to a limit. Nothing limits a data subject’s rights, a regulator’s powers or the recourse rules of Article 82 GDPR. Fines pass to the other party only to the extent legally permitted and attributable to that party.
11.5 Each party must take reasonable steps to limit its loss and notify the other of a material claim without undue delay after discovering it. A late notice affects recovery only to the extent the other party is materially prejudiced. Statutory limitation periods apply.
11.6 Our directors, employees and subcontractors may rely on the exclusions and limits in this clause 11 as a third-party stipulation under article 6:253 of the Dutch Civil Code. Their liability and ours together does not exceed the limits that apply to us.
12 Termination and force majeure
12.1 Either party may terminate the affected Order for the other’s material breach under clause 10.1. Either may terminate where the other ceases business or becomes subject to insolvency proceedings, to the extent permitted by applicable insolvency law. Cancellation of renewal under clause 8.2 does not require a breach.
12.2 If you terminate for our uncured material breach, an unresolved subprocessor objection under clause B6.2 or a materially adverse change under clause 14.2, we refund prepaid fees for the unused period and no further commitment charges apply. If we terminate for your uncured material breach, fees properly due remain payable and we may claim damages under applicable law. Voluntary early switching or erasure is governed by clause 13.5. Ceasing to use the Service does not end a commitment or create a refund right. Credits are governed by clause 8.4.
12.3 A party is excused from affected obligations to the extent and for as long as an event beyond its reasonable control prevents performance despite appropriate precautions. Lack of funds, avoidable staffing shortages and supplier failures that reasonable continuity measures should address do not qualify. The affected party must notify the other promptly and mitigate. If a material interruption lasts 30 days, either party may terminate the affected Service and we refund unused prepaid fees. Accrued payment, confidentiality, security, incident-response and exit obligations continue as far as they can still be performed.
13 Switching export and deletion
13.1 You may export Customer Data at any time during the subscription. You may also request a switch to another provider or to your own infrastructure, or the erasure of your data, by notice to info@simplyrecruit.ai. The notice period before a requested switch starts is two months from receipt of your request, unless we agree a shorter period. We acknowledge the request promptly, identify known technical limitations and provide reasonable assistance so that you and your new provider can plan the transfer.
13.2 The transition takes no more than 30 calendar days after the notice period. If this is technically unfeasible, we notify you within 14 working days of your request, justify the reasons and specify an alternative transition period of no more than seven months. You may extend the transition period once, for a period you consider more appropriate for your purposes. During the transition we maintain the Service, business continuity and security and cooperate in good faith with you and your destination provider. You remain responsible for the destination, the accuracy of your instructions and the import process.
13.3 Exportable data comprises your input and output data and relevant metadata, including records and identifiers, fields, relationships, schema, pipelines, views, configurations, workflows, templates, uploaded files, recordings, transcripts, retained communications, generated documents, reports and customer-visible audit and approval history. We provide structured data in commonly used machine-readable formats such as CSV or JSON, files in their original or a commonly usable format, and documentation sufficient to preserve relationships. We make our available open interfaces available free of charge to you and your destination provider. We do not promise that another service can reproduce SimplyOS functionality.
13.4 Excluded from export are only our source code, model weights, internal infrastructure and security configurations, secret credentials, proprietary algorithms and internal diagnostic records containing our trade secrets. These exclusions do not permit withholding your data, configurations or necessary export metadata. Secret credentials must be re-established at the destination. We maintain an up-to-date online export register, linked from our website, describing the export data structures and formats, relevant interoperability specifications, switching procedures and known technical restrictions, and we provide this information before you contract.
13.5 We do not charge for standard exports, retrieval or switching assistance, except that until 12 January 2027 we may charge reduced switching charges that do not exceed our direct costs, as disclosed in advance. Optional additional professional services require an accepted quote. Subscription and usage charges continue while we provide the Service during the notice and transition periods. If you switch or request erasure before the end of a committed term, a proportionate early termination fee applies, which does not exceed the remaining committed subscription charges for that term after credit for payments already made. The committed term and this fee are disclosed before you accept the Order. No early termination fee applies to an exit under clause 9.3 or 12.2 or where mandatory law excludes it. Switching and termination cannot be refused because fees are disputed.
13.6 The affected subscription ends when the switch is successfully completed, which we confirm to you, or at the end of the notice period if you request erasure instead. We reconcile prepaid amounts against charges properly due and any early termination fee under clause 13.5, and refund any overpayment, or any amount the law requires us to repay, within 30 days of that reconciliation. Ending one Order does not end other Orders unless they depend on the terminated Service.
13.7 After the transition ends, you have at least 30 calendar days to retrieve your exportable data. For an ordinary expiry, terminated trial or other termination without a transition, the same retrieval period starts at termination. Access may be limited to a secure export facility. You may instruct earlier deletion once you have the required data, subject to applicable law.
13.8 After the retrieval period we erase Customer Data from active systems, including derived indexes and caches, without undue delay and within 30 calendar days. Residual copies in backups are erased through the normal backup rotation within a further 90 calendar days; until then they are isolated from ordinary use and used only where strictly necessary for recovery, and deletions are reapplied after any restoration. We keep specific data longer only where EU or Member State law requires it, segregated and used solely for that purpose. We confirm completion on request. Part B and confidentiality apply while we hold any data.
14 Changes
14.1 We may improve the Service, correct errors and update security measures. We will not materially reduce purchased functionality, security or data-protection commitments during a paid term, except under clause 14.2. A change of plan name or website wording does not by itself remove an existing commitment.
14.2 We give at least 30 days’ written notice of a materially adverse change to the Service or these terms, explaining its effect and identifying the new version. If you object before it takes effect, you may terminate the affected Service from the date of the change and receive a pro rata refund of prepaid fees for the unused period. A shorter notice period applies only where required by law or an urgent security issue, with the same termination right if the adverse effect is material. Changes do not affect accrued rights or claims. Price changes follow clause 8.5 and subprocessor changes follow clause B6.
15 General provisions
15.1 Notices may be sent by email to the contact addresses in the account or Order; routine service notices may also appear in the Service. Notices of material amendments, price changes, termination or subprocessor changes must be emailed to the designated administrator or legal contact, and each party must keep its addresses current. A notice is effective when delivered to the designated address. If the sender knows that delivery failed, it must resend through another available channel.
15.2 Neither party may transfer this Agreement without the other’s consent, not unreasonably withheld. Either party may transfer it without consent to an affiliate or to a successor acquiring substantially all of the relevant business, provided the transferee assumes all obligations and the transfer does not reduce data-protection commitments; the transferring party notifies the other. Subcontracting does not release us from our obligations.
15.3 Failure to enforce a provision is not a waiver. If a provision is invalid, the remainder continues and the parties will replace it with a lawful provision closest to its intended purpose. This Agreement and the incorporated Order and Documentation contain the agreement on their subject matter; neither this clause nor a liability exclusion excludes fraud or overrides mandatory rights. Provisions intended to continue, including payment reconciliation, intellectual property, confidentiality, liability, dispute resolution and data return or deletion, survive termination.
15.4 Dutch law governs this Agreement, excluding its conflict-of-law rules. The parties will first try in good faith to resolve a dispute through their authorised representatives, without delaying urgent remedies or statutory rights. The competent court in the district of Oost-Brabant, the Netherlands, has exclusive jurisdiction, subject to mandatory jurisdiction rules. This English version governs unless the parties expressly agree another governing language.
Part B: Data processing agreement
B1 Scope and roles
B1.1 This Part is the parties’ agreement under Article 28 GDPR. “GDPR” means Regulation (EU) 2016/679; its definitions apply, together with applicable Dutch implementing law and other applicable data-protection law. The Customer is the controller and Simply the processor of personal data in Customer Data. If the Customer processes on another controller’s behalf, Simply acts as its subprocessor and the Customer confirms authority to give the instructions in this Agreement.
B1.2 Annex B1 specifies the subject matter, duration, nature, purposes, personal-data types and categories of people. This Part applies to every relevant plan and to trial, demonstration, migration, support and exit processing. It continues until the personal data has been returned or erased in accordance with the Agreement. The Customer retains the controller’s rights and obligations, including deciding purposes, lawful grounds, retention and disclosures.
B1.3 Each party acts as a separate controller for the business-contact, contracting, invoicing and compliance records it needs for its relationship with the other, as described in our Privacy Policy. This does not make us controller of candidate records, communications or other workspace content, or permit their reuse for product training or marketing. The role of an external enrichment source or a provider you connect follows its actual activities.
B2 Instructions and personnel
B2.1 We process personal data only on documented instructions from you, comprising this Agreement, the Order and your authorised use and configuration of the Service, including documented support requests. We will not determine a separate purpose for Customer Data. If EU or Member State law requires other processing, we will inform you before processing unless that law prohibits notice on important public-interest grounds.
B2.2 You must ensure that your instructions and your provision of personal data are lawful, that individuals receive the required information and that you have the necessary authority for your processing. If we become aware of an instruction that in our opinion infringes EU or Member State data-protection law, we inform you immediately and may pause that instruction, but not unrelated lawful processing, while the parties resolve it. This is not a promise to review every user action or to give legal advice. The Service may block particular actions for security or compliance reasons, but that does not guarantee the lawfulness of actions it does not block.
B2.3 Access is limited to authorised people who need it to perform the instructed work, are subject to enforceable confidentiality duties and receive appropriate security and privacy instruction. We maintain access controls, review access rights and remove access when no longer needed. We do not permit routine access to workspace content for unrelated internal purposes.
B3 Location and international transfers
B3.1 Customer Data held in your workspace, such as candidate and contact records, files and communications, is stored in the Netherlands and processed only within the EU, including its backups and Simply-managed AI processing. The default managed AI route uses Microsoft Azure in an EU region. No fallback, remote-access arrangement or subprocessor may move processing of Customer Data outside the EU. This EU commitment covers Customer Data only; it does not cover Service Data, our website or our own business records, which our Privacy Policy governs.
B3.2 Where you supply your own provider key or enable an integration you select, you choose and are responsible for checking the provider, account terms, endpoint, processing region and destination, including any processing outside the EU. Your configuration and use of that connection is your documented instruction to transmit the specified data there; no separate approval by us is needed. We follow your configuration and provide the information about our own routing reasonably needed to assess it, but we do not certify the settings of a provider account you control. Clause B3.3 and our responsibility for our own processing and transmission continue to apply.
B3.3 A transfer subject to GDPR Chapter V needs a lawful transfer mechanism before it starts, such as an adequacy decision or the appropriate EU standard contractual clauses with any required supplementary measures. We provide the information reasonably needed for the transfer assessment and implement the measures within our responsibility. If the required protection cannot be maintained, we suspend the affected transfer and work with you on an EU alternative. A subprocessor notice cannot amend clause B3.1.
B3.4 We assess, and where there are reasonable grounds challenge, public-authority demands for access that are unlawful or conflict with EU or Member State law. We disclose only what is legally required and notify you unless legally prohibited. For non-personal data, we maintain the safeguards against conflicting third-country government access required by the Data Act, and our website security page identifies the jurisdiction of our infrastructure and the measures that address such access.
B4 Security and assistance
B4.1 We implement and maintain the technical and organisational measures in Annex B2, appropriate to the risks under Article 32 GDPR, and assess, test and review them regularly. Measures may evolve with technology and threats, but their overall level of protection will not be reduced. We maintain ISO 27001 certification covering our information-security management for the Service and provide the current certificate and its scope on request.
B4.2 Taking account of the nature of processing and information available to us, we assist you with data-subject requests, security obligations, breach assessments, data-protection impact assessments and prior consultation with supervisory authorities. We provide information and functionality reasonably necessary for you to meet your deadlines. If a request comes directly to us, we promptly forward it to you and do not respond on your behalf unless instructed or legally required.
B4.3 Routine assistance, information demonstrating compliance and assistance arising from our breach are included in the fees. For exceptional work beyond normal service functionality, we may charge reasonable costs after giving you an estimate in advance. A disagreement about additional fees must not prevent urgent mandatory assistance. We cooperate with competent supervisory authorities and preserve relevant evidence securely.
B5 Personal data breaches
B5.1 We notify your designated privacy or administrator contact of a personal data breach affecting Customer Data without undue delay and in any event within 24 hours after becoming aware of it, not counting Saturdays and Sundays. Notification does not wait for a complete investigation or for a conclusion that you must notify a regulator.
B5.2 The first notice gives the facts then available, including the nature of the breach, the affected systems and data, likely consequences, containment measures and a contact for follow-up, with the categories and approximate numbers of people and records affected where known. We provide further information in phases without undue delay, investigate, contain and remedy the breach, support your required notifications and keep a record of the incident. We do not notify affected individuals for you unless you instruct us or the law requires it. A notice is not by itself an admission of liability.
B6 Subprocessors
B6.1 You give general written authorisation to engage the subprocessors listed in the Subprocessor Register in Annex B3, as provided before acceptance and updated under this clause. The register identifies each legal entity, its service, the relevant data, the processing and storage locations and any transfer mechanism, and distinguishes our subprocessors from services you contract for directly. Membership of a named corporate group does not authorise an unlisted entity.
B6.2 We give at least 30 days’ email notice of an intended new or replacement subprocessor, with enough information to assess the data-protection implications. You may object within that period on reasonable data-protection grounds, and we then discuss the objection and propose an alternative or safeguards. If no satisfactory solution is reasonably available, either party may terminate the affected Service before that subprocessor processes your data; clause 12.2 then applies. Unaffected services continue where reasonably separable.
B6.3 Before a subprocessor processes Customer Data, we bind it by a written processing agreement meeting Article 28(4) GDPR, which may be the provider’s standard DPA, and assess its ability to comply. We remain responsible to you for our subprocessors’ performance of their data-protection obligations as the GDPR requires, subject to clause 11 where legally permitted. Appointing a subprocessor does not weaken our EU-processing, no-training, security, confidentiality or deletion commitments. A service you contract for directly is not our subprocessor merely because it connects to the Service.
B7 Demonstrating compliance
B7.1 We make available the information reasonably necessary to demonstrate compliance with this Part and Article 28 GDPR, including our ISO 27001 certificate, security summaries and independent assurance reports. Where you reasonably consider that information insufficient, we allow and contribute to audits and inspections by you or an independent auditor bound by confidentiality and without a conflict of interest. Audits must be proportionate and must not expose other customers’ data or our security secrets. You bear your own and your auditor’s costs.
B7.2 On-site audits require at least 30 days’ notice, take place during business hours and occur no more than once in any 12 months, unless a supervisory authority requires an audit or a personal data breach has affected Customer Data. We agree a proportionate scope that does not prevent an effective audit. Standard compliance information is free of charge. We may charge reasonable costs for staff time spent on audits beyond that, at rates notified in advance, but not for remediating our own non-compliance. A disagreement over costs does not delay cooperation required by law.
B8 Retention return and responsibility
B8.1 You select lawful retention periods and use the available deletion and retention controls; automated retention is an Enterprise feature. Every customer may give access, rectification and deletion instructions. We carry out in-service deletions in active systems without undue delay and within 30 days, and remove residual backup copies through the normal backup rotation within a further 90 days, isolated from ordinary use in the meantime. End-of-service deletion follows clause 13.8.
B8.2 At the end of the Service, at your choice, we return the data and erase remaining copies or erase it without return, following the timetable in clause 13. We honour an earlier documented erasure instruction where the law allows, require corresponding erasure by our subprocessors and confirm completion on request. A statutory retention exception is limited as stated in clause 13.8 and never permits continued service, analytics or training use.
B8.3 Liability between the parties is governed by clauses 9.4 and 11, subject to mandatory data-protection law, and responsibility for a claim is allocated according to each party’s conduct. This Part does not restrict an individual’s right to compensation or to complain, or a supervisory authority’s powers. The parties cooperate reasonably on any claim.
Annex B1: Processing details
Subject and duration. Providing the Customer’s SimplyOS recruitment operating system and purchased associated services, from the first authorised receipt of personal data through the end of the agreed return and erasure process. Processing can be continuous or occur when a user, configured automation or authorised integration triggers an activity.
Nature and purposes. Collection and import; storage, organisation, retrieval and search; document parsing and field extraction; recording and transcription; translation and summarisation; candidate matching, scoring and ranking; drafting and document generation; communication synchronisation and delivery; enrichment requests; workflow execution; reporting; permissions and audit logging; support, security, backup, export and deletion. Each operation serves the Customer’s documented recruitment, staffing, relationship-management or related administrative instructions.
People. Candidates, applicants, prospective candidates, employees, temporary and contract workers, referees, client and prospect contacts, hiring managers, meeting and communication participants, and authorised workspace users.
Data. Identifiers and contact details; CVs, education, qualifications, employment histories and portfolios; vacancies, applications, preferences, availability and assessments; correspondence, meeting content, audio and video; extracted facts, summaries, scores and explanations; placements, assignments, rates and commercial records; user, activity, permission and audit metadata; uploaded documents and the Customer’s custom fields. Data may be received from the Customer, connected accounts, authorised users and instructed external sources.
Restricted data. Health, disability, ethnicity, beliefs, union membership, sexual orientation and other Article 9 data, criminal-offence information, national identification numbers and similar restricted data may appear in recruitment materials. Their presence is not required for ordinary use. The Customer must minimise these data, restrict access and process them only with the legal conditions and safeguards that apply. Ordinary audio, photographs, age and contact details are not automatically Article 9 data; biometric processing for unique identification can be. These terms do not authorise prohibited biometric, emotion-recognition or other AI uses. Simply will process inadvertently included restricted data only on lawful instructions, including removal.
Annex B2: Security measures
Governance and people. An ISO 27001-certified information-security management system covers the Service, with documented responsibilities, risk assessments, policies, personnel confidentiality, security instruction, supplier assessment and periodic control review.
Access and tenant separation. Unique accounts, least-privilege access, available two-factor authentication, controlled privileged access and timely access removal protect the Service. Workspace, object, record and field permissions govern ordinary use, AI tools and reporting. Customer workspaces are logically separated. Access to Customer content for support is limited to authorised work and recorded appropriately.
Encryption and secrets. Customer Data is encrypted in transit using secure transport protocols and encrypted at rest in databases, file storage and backups. Credentials, integration tokens and API keys are protected against unauthorised disclosure, with restricted access and secure key handling. Supported webhooks use the advertised signature and verification controls.
Application and AI controls. Development and change controls, vulnerability management, monitoring and timely remediation protect the platform. AI follows configured access rights and approval settings; administrative autonomy changes and consequential actions are logged. Candidate matching applies the advertised masking before AI evaluation. Customer Data is not used for model training. Simply-managed processing follows the EU location controls in clause B3.
Continuity and incident handling. Backup and restoration arrangements protect availability and recoverability, with regular restoration testing and incident-response procedures. We monitor for security incidents, preserve relevant evidence and operate the notification process in clause B5. Backup retention and deletion follow the agreed time limits. Any specific recovery-time or recovery-point guarantee must be stated in the Order.
Audit and deletion. The Service maintains audit records of material record changes, permissions, approvals and executions, protects those records against unauthorised alteration, and supports authorised access, export, correction and deletion. Deletion covers active records, source files, derived indexes and caches and is propagated to contracted subprocessors and backup rotation.
Annex B3: Subprocessor Register
This register lists the subprocessors authorised to process Customer Data for Simply, with their functions, the relevant data, storage and processing or access locations, and any transfer mechanism. Changes follow clause B6. Services you contract for directly and independent data sources are not Simply subprocessors and are not listed.
| Legal entity and address | Function and Customer Data | Storage locations | Processing and access locations | Transfer basis |
|---|---|---|---|---|
| Slack Technologies Limited, Salesforce Tower, 60 R801, North Dock, Dublin, Ireland (registered in Dublin under number 558379). | Internal messaging and support. Customer Data only if pasted into messages or files, eg: when collaborating on customer issues. | Data storage in the US with backups in the EU. | Ireland, plus the US through the affiliate’s support role. | SCCs (Slack Technologies, LLC is the signatory). |
| GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA | Source code hosting and CI/CD. No Customer Data intended; we keep it out of repositories, logs and issues. | Data storage in the US. | US and other locations, including GitHub affiliates and subprocessors. | EU SCCs in the GitHub Data Protection Agreement (transfers to the US and third countries without an adequacy decision). |
| Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland | Email, calendar, documents and file storage. Customer Data only if it appears there, eg: email communication with clients about their data. | Data storage in the US and Europe. | Data processing in the US and Europe. | SCCs under the Google Cloud Data Processing Addendum. |
| Worldstream B.V., Industriestraat 24, 2671 CT Naaldwijk, Netherlands (KvK 60223650). | Hosting and infrastructure for all Customer data in the form of databases and back-ups. | Company-owned Dutch data centers in Naaldwijk. | Netherlands (Worldstream personnel). | EU only; no transfer mechanism needed. |
| Plus Five Five, Inc. (trading as Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA | Transactional email delivery: recipient email addresses, message content and metadata, plus any names or attachments the sender includes. Not intended for sensitive Customer data. | Data storage in the US. | Primary processing in the United States. | EU SCCs, plus the EU-US Data Privacy Framework (Resend states it complies). |
| Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland | Simply-managed AI processing (Azure OpenAI): the Customer Data included in AI requests, such as CVs, transcripts and messages, and the generated outputs. Not used to train models. | Not applicable; no data is stored. | EU (Microsoft Azure EU regions). | EU only; no transfer mechanism needed. Microsoft Products and Services Data Protection Addendum, including EU SCCs. |
Part C: Support and availability
C1 Support
C1.1 Support is available by email at info@simplyrecruit.ai and through in-product chat where provided. Standard support hours are 09:00 to 17:00 Europe/Amsterdam, Monday to Friday, excluding Dutch public holidays. Requests may be submitted at any time. A business hour is an hour within that support window; time received outside it starts at the next opening.
C1.2 The initial substantive support-response times for paid production use are set out below, unless a different period is expressly agreed in the Order. Business hours count only within the window in clause C1.1; 24 business hours ordinarily span three working days. A substantive response states the assessed priority and next action, not necessarily a final resolution.
| Subscription | Standard requests | Critical incidents |
|---|---|---|
| Core | 24 business hours | 8 business hours |
| Professional | 16 business hours | 4 business hours |
| Enterprise | 8 business hours | 4 business hours |
C1.3 Trial users have no guaranteed response time or entitlement to paid support priority. They may use their assigned sales contact, where provided, or request support subject to availability. Beta support is also subject to availability unless the Order states otherwise. A critical incident makes core production functionality unavailable or causes a substantial loss of essential functionality without a reasonable workaround. We work diligently to restore production service, prioritise material impact and provide updates at least once each business day while a critical incident remains open. The breach notification in clause B5.1 applies regardless of subscription tier, trial status or support hours.
C2 Availability
C2.1 The monthly availability commitment for paid production workspaces is 99%+. To calculate availability, subtract Unavailable Minutes from Eligible Minutes, divide the result by Eligible Minutes, and multiply by 100. Eligible Minutes are all minutes in the month during which the paid Service is contracted, less only the permitted exclusions in clause C2.3. A month with no Eligible Minutes has no availability measurement.
C2.2 Unavailability means that properly authenticated users cannot access the production workspace’s core application, or cannot read or write its essential recruitment and business records, because of a failure in the Service. We measure continuously, including weekends, using our monitoring and reasonably substantiated customer evidence. A failure confined to an optional feature is not downtime unless it prevents essential use; it is handled under our general support obligations. Beta functionality is excluded under clause 2.2, but a beta-origin incident that affects covered production functionality is measured normally.
C2.3 The only exclusions are: scheduled maintenance notified at least 24 hours in advance, outside standard support hours and totalling no more than eight hours a month; a failure caused solely by your systems or an unauthorised configuration; a third-party service you contracted independently, to the extent our Service otherwise works; a justified suspension under this Agreement; and a force-majeure event under clause 12.3. Maintenance beyond the monthly allowance, and unplanned or emergency maintenance, counts as downtime unless another exclusion applies. Failures of our hosting, managed AI or other subcontractors are not excluded as such.
C2.4 This standard schedule does not provide automatic service credits or a separate repeated-failure termination formula. The general remedies for an attributable breach, including the material-breach process in clauses 10 and 12, remain subject to clause 11 and mandatory law. An Enterprise Order may expressly agree additional service levels or remedies.