Data Processing Agreement
Last updated: June 24, 2026. Applies to Sage tier and enterprise customers.
1. Scope and applicability
This Data Processing Agreement (“DPA”) applies to customers on the ResuBlue Sage tier who use the platform to process personal data on behalf of their own clients (“Data Subjects”). If you are an individual user on a personal plan, the Privacy Policy governs instead.
2. Roles under GDPR
When a Sage customer uses ResuBlue to process resume data for their own clients, the customer is the “Data Controller” and ResuBlue (operated by the entity listed in our Terms of Service) is the “Data Processor” under GDPR Article 4(8). ResuBlue processes personal data only on documented instructions from the customer.
3. Nature and purpose of processing
ResuBlue processes the following categories of personal data on behalf of the controller: name, contact information, employment history, education records, skills, and AI-generated resume content. Processing is carried out for the purpose of providing the ResuBlue resume-building, AI generation, and career coaching services as described in the Terms of Service.
4. Sub-processors
ResuBlue engages the following sub-processors, each bound by data protection obligations equivalent to those in this DPA:
- Clerk Technologies, Inc.:authentication and identity management
- Stripe, Inc.:payment processing
- Neon (Neon, Inc.):cloud PostgreSQL database hosting
- Vercel, Inc.:application hosting and edge delivery
- Sentry (Functional Software, Inc.):error monitoring
- Groq, Inc.:AI inference for resume generation
- Resend, Inc.:transactional email delivery
We will notify customers of any intended changes to the sub-processor list with at least 14 days notice via email to the account owner. See our AI Transparency page for details on AI sub-processors.
5. Data subject rights
ResuBlue will assist the controller in fulfilling Data Subject requests (access, rectification, erasure, portability, restriction) within the timescales required by applicable law. Requests should be directed to privacy@resublue.com.
6. Security measures
ResuBlue implements appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS 1.2+), encryption at rest, access controls, audit logging, and regular security testing. Details are available on request.
7. Data transfers
ResuBlue primarily stores and processes data in the United States. Transfers of personal data from the European Economic Area to the US are covered by Standard Contractual Clauses (SCCs) entered into with each sub-processor, or by adequacy decisions where applicable.
8. Breach notification
ResuBlue will notify the controller of any personal data breach without undue delay and, where feasible, within 72 hours of becoming aware, providing sufficient information to allow the controller to meet its own notification obligations.
9. Execution and term
This DPA is incorporated by reference into the ResuBlue Terms of Service and takes effect upon the customer's acceptance of those terms. It remains in force for the duration of the subscription and terminates automatically upon account closure. For a countersigned DPA or custom data processing terms, contact legal@resublue.com.