W
Wilma

Data Processing

GDPR & Data Processing — withWilma

This page explains withWilma’s controller-processor model and how we support customer privacy and data-protection obligations.

Last Updated

May 8, 2026

Applies To

withWilma customers, candidates, and connected-account users.

1. Overview

This page summarises how withWilma supports customers with data-protection obligations under the GDPR, UK GDPR, Swiss data protection law, and similar privacy frameworks.

2. Controller and Processor Roles

In most cases, the customer organisation using withWilma is the data controller for candidate and recruiter data processed in the platform.

withWilma acts as the data processor or service provider, processing personal information on the customer’s behalf and according to the customer’s instructions.

3. Processing Activities

  • Application collection and candidate workflow management
  • Recruiter-to-candidate communication
  • Interview scheduling and coordination
  • Transcription, summarisation, and structured review support

4. Subprocessors

withWilma may engage subprocessors to provide hosting, infrastructure, email delivery, analytics, customer support, and AI-assisted functionality. We require subprocessors to implement appropriate safeguards and contractual protections.

5. Data Subject Rights

Where withWilma processes data on behalf of customers, we support customers in responding to valid requests relating to access, correction, deletion, portability, or objection rights.

6. International Transfers

Where personal information is transferred outside the EEA, UK, or Switzerland, withWilma relies on appropriate safeguards such as contractual protections, including Standard Contractual Clauses where applicable.

7. Data Processing Agreement

withWilma can provide a Data Processing Agreement where required for customer use of the service. Customers who need a DPA in place should contact privacy@withwilma.com.