Legal

Compliance

The security controls we operate, the data protection and AI regulations we design against, and what we can provide for your vendor review.

Effective 20 July 2026 · TechAIVV Technologies

1.Our approach

Recruitment data is among the most sensitive information an organisation handles. It concerns identifiable people, it drives decisions with material consequences for their livelihoods, and it is increasingly regulated on two fronts at once — data protection and algorithmic accountability.

This page sets out the controls we operate, the regulatory frameworks we design against, and what we can provide to your security, privacy, and legal teams during a vendor review.

Running a formal vendor assessment? Email security@hireaivv.ai for our security documentation pack, current sub-processor list, and completed assessment questionnaires.

2.Certifications and audits

TODO — REQUIRED BEFORE LAUNCH. Replace this section with the true, current status of each item. If an audit is in progress, say so plainly and give the target window; buyers accept honest roadmaps and reject discovered overstatements. If nothing is certified yet, delete the table and describe the control environment instead.

FrameworkStatusEvidence available
SOC 2 Type IITODO: Not started / In progress / Report available (period covered)TODO
ISO/IEC 27001TODO: Not started / In progress / Certified (certificate number, body, expiry)TODO
GDPR readiness assessmentTODOTODO
Penetration testTODO: date of last test, testing firm, remediation statusTODO

3.Security controls

The controls below are operated as part of the platform today.

  • Encryption. TLS for data in transit; encryption at rest for databases, object storage, and backups.
  • Tenant isolation. Every record is scoped to an organisation, and access is enforced server-side on each request rather than in the interface alone.
  • Authentication. Hashed password storage, scoped and expiring session tokens, and federated sign-in via Google OAuth.
  • Role-based access control. Permissions are granted by role — administrator, recruiter, hiring manager, client — so people see only the candidates and roles their function requires.
  • Audit logging. Access to candidate records and administrative actions are logged with actor and timestamp, supporting after-the-fact review.
  • Least-privilege internal access. Production access is restricted to personnel who require it, granted on request, and reviewed periodically. Personnel are bound by confidentiality obligations.
  • Environment separation. Development, staging, and production are separated, and production data is not used for development.
  • Secure development. Code review before merge, dependency vulnerability monitoring, and secrets held in managed configuration rather than source control.
  • Backups. Encrypted, access-controlled backups with defined restore procedures.

4.GDPR and UK GDPR

For candidate data, our customers are the controller and we act as processor. We support customers in meeting their obligations through:

  • A Data Processing Addendum incorporating Article 28 processor terms, available to every customer.
  • Standard Contractual Clauses and the UK International Data Transfer Addendum for restricted transfers, with encryption as a supplementary measure.
  • A published sub-processor list, with advance notice of additions and a right to object.
  • Data subject request support — tooling to locate, export, correct, and delete an individual's records, and cooperation on requests received directly by us.
  • Breach notification to affected customers without undue delay, with the detail needed for their own 72-hour regulatory notification.
  • DPIA assistance — documentation on data flows, retention, and the logic of our automated processing, which customers need for the impact assessment recruitment AI typically requires.
  • Deletion and return of data on termination, within the periods set out in the DPA.

5.India — Digital Personal Data Protection Act, 2023

TechAIVV Technologies operates from India, and the DPDP Act applies to personal data processed here as well as to processing of Indian residents' data offered from abroad.

  • We act as a Data Processor to our customers, who are the Data Fiduciary for candidate data, and we process only under their instruction and a written contract.
  • We support fiduciary obligations around notice and consent, including consent for recording screening calls.
  • We support the rights of Data Principals to access, correct, and erase their data, and the right to nominate another person to exercise those rights.
  • We assist with breach intimation to the Data Protection Board and to affected Data Principals within the timelines the Act requires.
  • Children's data. The Act restricts tracking and behavioural monitoring of children. HireAivv is a business hiring tool and is not directed at children.
  • TODO: confirm whether any customer or processing volume triggers Significant Data Fiduciary obligations, which add DPIA, audit, and Data Protection Officer requirements.

6.AI regulation in hiring

Recruitment is one of the most heavily regulated applications of AI, and the obligations fall on you as the employer as well as on us as the provider. The frameworks below are the ones most likely to apply to your programme.

FrameworkWhat it coversWho it lands on
EU AI ActAI used for recruitment, candidate screening, and evaluation is classified as high-risk under Annex III. Obligations include risk management, data governance, technical documentation, logging, transparency, human oversight, and accuracy and robustness testing.Both — provider obligations on us, deployer obligations on you
NYC Local Law 144Automated employment decision tools used for candidates in New York City require an annual independent bias audit, publication of the results, and advance notice to candidates.You, as the employer or employment agency
EEOC / Title VII (US)Selection procedures with a disparate impact on a protected group must be job-related and consistent with business necessity.You, as the employer
Illinois AIVIANotice, explanation, and consent before AI analysis of video interviews, with deletion on request.You, as the employer
Colorado AI ActDuty of reasonable care for developers and deployers of high-risk AI systems in employment, including impact assessments and consumer notice.Both

TODO: confirm which of these apply to your actual customer base and go-live geography, and have counsel verify the EU AI Act obligation split before publishing — provider versus deployer allocation determines what documentation TechAIVV itself must produce and maintain.

7.Responsible AI practices

  • Human in the loop by design. HireAivv produces rankings and recommendations. Our Terms require customers to keep a human reviewer accountable for every decision affecting a candidate.
  • Job-relevant inputs only. Matching operates on skills, experience, and qualifications against stated role requirements. Protected characteristics are not scoring inputs.
  • No training on customer data. Candidate data is not used to train or fine-tune our models, and our AI sub-processors are contractually barred from training on data we submit.
  • Traceability. Assessment output is retained with its role context and timestamp so a shortlist can be reconstructed and reviewed.
  • Override and correction. Recruiters can override any score, and candidates can request review through the employer.
  • Explainability. The platform surfaces the factors behind a match rather than presenting a bare number.
  • TODO: state whether TechAIVV runs internal fairness or adverse-impact testing on its matching models, at what cadence, and whether results are shared with customers. Enterprise buyers and Local Law 144 auditors both ask for this early.

8.Sub-processors and supply chain

We publish the full sub-processor list in our Privacy Policy, covering infrastructure, AI processing, communications, and meeting-intelligence providers. Each is engaged under a written contract restricting processing to our instructions and requiring appropriate security measures. We assess new providers before onboarding and notify customers before a sub-processor is added, giving them the opportunity to object.

9.Incident response and breach notification

  • Defined severity levels, with an on-call path for security incidents.
  • Containment and investigation, with preservation of relevant logs and evidence.
  • Notification to affected customers without undue delay, including the nature of the incident, categories and volume of data involved, likely consequences, and remediation steps — the information a controller needs for a 72-hour regulatory notification.
  • Post-incident review with corrective actions tracked to closure.
  • TODO: publish the target notification window committed to in the DPA, and confirm the incident response plan is documented and tested.

10.Availability and continuity

The platform is monitored for availability and errors, with encrypted backups and documented restore procedures supporting recovery. TODO: state the uptime commitment, RPO and RTO targets, and whether a formal SLA is offered — enterprise procurement will request all three.

11.Reporting a vulnerability

If you believe you have found a security vulnerability in HireAivv, report it to security@hireaivv.ai. Please include enough detail to reproduce the issue, and give us reasonable time to investigate and remediate before public disclosure.

We will acknowledge your report, keep you updated on remediation, and credit you if you would like. We ask that you do not access, modify, or delete data belonging to others, degrade the service, or run automated scanning against production without written authorisation. TODO: confirm the acknowledgement SLA and whether a formal safe-harbour or bounty policy is offered.

12.Talk to us

Security and vendor assessments — security@hireaivv.ai. Privacy and data protection — privacy@hireaivv.ai. Contracts and legal — legal@hireaivv.ai.

Questions about this document?

Write to legal@hireaivv.ai. For privacy requests or data-protection matters, use privacy@hireaivv.ai.