1. Purpose
This Data Processing Statement provides the detailed technical and legal information required by GDPR Art. 13/14 and Swiss revised Federal Act on Data Protection (revFADP / nDSG) Art. 19 for all processing activities conducted by HumanCapital CXO® in connection with the HCV Model platform. It supplements the Privacy Notice. Where the platform is deployed as a high-risk AI system under EU AI Act 2024/1689 Annex III, this statement also constitutes part of the technical documentation required under Art. 11.
2. Processing Activities Register
| Activity | Data categories | Legal basis | Retention | Processors |
|---|---|---|---|---|
| User authentication | Email, hashed password, session tokens, login IP (truncated) | Art. 6(1)(b) | Account lifetime + 90 days logs | Supabase, Cloudflare |
| HCV calculation storage | Pseudonymised salary, service states, control factor scores, outputs | Art. 6(1)(b) | 24 months | Supabase |
| Access control enforcement | Session token, request URL, timestamp | Art. 6(1)(f) | 90 days | Cloudflare Workers |
| Support communications | Name, email, message content | Art. 6(1)(b)/(f) | 3 years | Internal only |
| Security monitoring | Truncated IP, user agent, error logs | Art. 6(1)(f) | 90 days | Cloudflare, Supabase |
3. Sub-Processors
| Processor | Country | Role | Transfer mechanism | DPA reference |
|---|---|---|---|---|
| Supabase Inc. | USA (EU region available) | Database, Auth, Storage | EU SCCs (2021/914) | supabase.com/privacy |
| Cloudflare Inc. | USA (EU PoPs) | CDN, Workers, DDoS | EU SCCs (2021/914) | cloudflare.com/privacypolicy |
| Google LLC (Fonts) | USA | Font delivery (public pages) | EU SCCs | policies.google.com/privacy |
4. Technical and Organisational Measures (TOMs)
- Encryption in transit: TLS 1.3 enforced on all connections via Cloudflare.
- Encryption at rest: AES-256 on Supabase database and storage.
- Pseudonymisation: HCV calculation records reference internal user IDs, not names, in the calculation engine.
- Access control: Role-based access; principle of least privilege; Cloudflare Worker enforces session validation on every request to /*.
- Audit logging: All authentication events and data access logged with timestamps; retained 90 days.
- Data minimisation: Only the data strictly necessary for each processing purpose is collected and retained.
- Breach response: Personal data breaches assessed within 24 hours; supervisory authority notification within 72 hours where required (GDPR Art. 33 / DSG Art. 24).
5. Automated Decision-Making
The HCV Model performs automated numerical calculations on data you provide. These calculations are a decision-support tool only. No automated decision producing legal or similarly significant effects is made by the platform without human intervention. See the Responsible Use Policy and Ethics & Governance pages for full detail and mandatory human-oversight obligations.
6. Data Subject Rights — Process
- Submit requests to: privacy@humancapitalcxo.com
- We will verify your identity before processing the request.
- Response within 30 days (extendable by 60 days for complex requests with notice).
- Requests are free of charge. Manifestly unfounded or excessive requests may be subject to a reasonable fee.
7. DPIA Obligations for Deployers
Organisations integrating the HCV Model via API or ERP for systematic processing of employee data must conduct a Data Protection Impact Assessment (DPIA) under GDPR Art. 35 / nDSG Art. 22 before deployment. Contact compliance@humancapitalcxo.com for DPIA support documentation.
8. EU AI Act — Technical Documentation Obligations
Where the HCV Model is deployed as a high-risk AI system under EU AI Act 2024/1689 Annex III (HR and employment management), deployers must maintain technical documentation per Art. 11 covering: (a) system purpose and intended use, (b) training data characteristics and bias audit results, (c) human oversight measures per Art. 14, (d) accuracy and performance metrics, and (e) post-market monitoring plan per Art. 72. HumanCapital CXO® can supply a conformity support package upon request. Deployers bear full responsibility for registration in the EU AI database per Art. 49 and for designating an EU representative where required under Art. 22.