Human Capital CXO
Legal & Trust — DPS-RSS-001
Data Processing Statement
Effective: 2026-06-01  •  Version 1.2  •  Review cycle: Annual

1. Purpose

This Data Processing Statement provides the detailed technical and legal information required by GDPR Art. 13/14 and Swiss revised Federal Act on Data Protection (revFADP / nDSG) Art. 19 for all processing activities conducted by HumanCapital CXO® in connection with the HCV Model platform. It supplements the Privacy Notice. Where the platform is deployed as a high-risk AI system under EU AI Act 2024/1689 Annex III, this statement also constitutes part of the technical documentation required under Art. 11.

2. Processing Activities Register

ActivityData categoriesLegal basisRetentionProcessors
User authenticationEmail, hashed password, session tokens, login IP (truncated)Art. 6(1)(b)Account lifetime + 90 days logsSupabase, Cloudflare
HCV calculation storagePseudonymised salary, service states, control factor scores, outputsArt. 6(1)(b)24 monthsSupabase
Access control enforcementSession token, request URL, timestampArt. 6(1)(f)90 daysCloudflare Workers
Support communicationsName, email, message contentArt. 6(1)(b)/(f)3 yearsInternal only
Security monitoringTruncated IP, user agent, error logsArt. 6(1)(f)90 daysCloudflare, Supabase

3. Sub-Processors

ProcessorCountryRoleTransfer mechanismDPA reference
Supabase Inc.USA (EU region available)Database, Auth, StorageEU SCCs (2021/914)supabase.com/privacy
Cloudflare Inc.USA (EU PoPs)CDN, Workers, DDoSEU SCCs (2021/914)cloudflare.com/privacypolicy
Google LLC (Fonts)USAFont delivery (public pages)EU SCCspolicies.google.com/privacy

4. Technical and Organisational Measures (TOMs)

5. Automated Decision-Making

The HCV Model performs automated numerical calculations on data you provide. These calculations are a decision-support tool only. No automated decision producing legal or similarly significant effects is made by the platform without human intervention. See the Responsible Use Policy and Ethics & Governance pages for full detail and mandatory human-oversight obligations.

6. Data Subject Rights — Process

7. DPIA Obligations for Deployers

Organisations integrating the HCV Model via API or ERP for systematic processing of employee data must conduct a Data Protection Impact Assessment (DPIA) under GDPR Art. 35 / nDSG Art. 22 before deployment. Contact compliance@humancapitalcxo.com for DPIA support documentation.

8. EU AI Act — Technical Documentation Obligations

Where the HCV Model is deployed as a high-risk AI system under EU AI Act 2024/1689 Annex III (HR and employment management), deployers must maintain technical documentation per Art. 11 covering: (a) system purpose and intended use, (b) training data characteristics and bias audit results, (c) human oversight measures per Art. 14, (d) accuracy and performance metrics, and (e) post-market monitoring plan per Art. 72. HumanCapital CXO® can supply a conformity support package upon request. Deployers bear full responsibility for registration in the EU AI database per Art. 49 and for designating an EU representative where required under Art. 22.