1.Scope and application
This Data Processing Addendum ("DPA") forms part of the agreement between TechAIVV Technologies ("Processor", "we") and the customer ("Controller", "you") for use of the HireAivv platform (the "Agreement"). It applies where we process personal data on your behalf and data protection law applies to that processing.
Where this DPA conflicts with the Agreement, this DPA controls in respect of the processing of personal data. Where it conflicts with the Standard Contractual Clauses, the Clauses control.
Need this executed as a signed document for your records, or need it on your own paper? Email legal@hireaivv.ai and we will arrange signature.
2.Definitions
- Data Protection Law — all laws applicable to the processing of personal data under this DPA, including the EU GDPR, the UK GDPR, and India's Digital Personal Data Protection Act, 2023.
- Controller, Processor, Data Subject, Personal Data, Processing, and Personal Data Breach have the meanings given in the GDPR. Where the DPDP Act applies, Data Fiduciary, Data Processor, and Data Principal carry the corresponding meanings.
- Customer Personal Data — personal data contained in Customer Data that we process on your behalf under the Agreement.
- Sub-processor — a third party engaged by us to process Customer Personal Data.
- Standard Contractual Clauses or SCCs — the clauses annexed to European Commission Implementing Decision (EU) 2021/914, and where relevant the UK International Data Transfer Addendum.
3.Roles of the parties
You are the Controller and we are the Processor in respect of Customer Personal Data. You determine the purposes and means of processing — which roles you hire for, which candidates you assess, which features you enable, and how long records are kept.
Where you are yourself a processor for a third party — for example a recruitment agency acting for a client employer — you warrant that you have the authority of that controller to instruct us, and that the instructions you give us are consistent with theirs.
We act as an independent controller for a limited set of data described in our Privacy Policy, including account administrator contact details, billing records, and security and usage telemetry. That processing is governed by our Privacy Policy rather than this DPA.
4.Annex I — Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the HireAivv AI recruitment platform under the Agreement. |
| Duration | The term of the Agreement, plus the deletion and return period set out in this DPA. |
| Nature and purpose | Hosting and storage; parsing of résumés and documents; AI-assisted skill extraction, matching, scoring and ranking; screening question generation and evaluation; AI voice screening; interview scheduling, recording, transcription and summarisation; candidate communication by email, SMS and WhatsApp; reporting and analytics; support and troubleshooting. |
| Categories of Data Subject | Job candidates and applicants; your employees and contractors who use the platform (recruiters, hiring managers, administrators); interview panellists; and where applicable, the contacts of your client organisations. |
| Categories of Personal Data | Identity and contact data (name, email, phone, location); professional data (work history, education, skills, certifications, salary expectations, notice period); application data (résumés, cover letters, portfolios, uploaded documents); assessment data (match scores, rankings, screening responses, evaluations, recruiter notes); interview data (schedules, call recordings, transcripts, summaries); communication data (message content and delivery status); and account and usage data (credentials, roles, IP address, activity logs). |
| Special category data | Not requested and not required. Candidates occasionally volunteer such information in free-text documents. It is not used for scoring or ranking. You should not deliberately submit special category data unless you have a lawful basis under Article 9 and have instructed us in writing. |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Automated decision-making | The platform generates scores and rankings as decision support. It is configured on the basis that you maintain meaningful human review of every decision affecting a Data Subject. |
5.Our obligations as Processor
We will:
- 1.Process Customer Personal Data only on your documented instructions, including the Agreement, this DPA, and your configuration of the platform — unless required otherwise by law, in which case we will inform you first unless the law prohibits it.
- 2.Immediately inform you if, in our opinion, an instruction infringes Data Protection Law.
- 3.Not sell Customer Personal Data, and not process it for our own purposes, for advertising, or for any purpose outside providing the Service.
- 4.Not use Customer Personal Data to train or fine-tune machine learning models, and contractually prohibit our AI sub-processors from training their models on data we submit.
- 5.Ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations that survive the end of their engagement, and are granted access on a least-privilege, need-to-know basis.
- 6.Implement and maintain the technical and organisational measures in Annex II.
- 7.Assist you, taking into account the nature of processing and the information available to us, in meeting your obligations under Articles 32 to 36 GDPR and the corresponding provisions of other Data Protection Law.
6.Your obligations as Controller
You will:
- 1.Ensure you have a lawful basis for the collection and processing of Customer Personal Data, and that your instructions to us comply with Data Protection Law.
- 2.Provide Data Subjects with the privacy notices and information required by law, including notice that automated tools are used in your process where that is required.
- 3.Obtain any consent required in the relevant jurisdiction — in particular for recording screening calls and interviews, which several jurisdictions require every participant to consent to.
- 4.Maintain meaningful human review of hiring decisions, and not use the Service to make decisions based solely on automated processing where prohibited.
- 5.Configure retention periods appropriate to your legal obligations and the jurisdictions you recruit in.
- 6.Manage access for your Users, and revoke it promptly when no longer needed.
- 7.Not submit special category data, or data of children, except where you have a lawful basis and have instructed us in writing.
7.Sub-processors
You give general authorisation for us to engage sub-processors. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
The current list is published in our Privacy Policy and covers infrastructure (database and object storage), AI processing, voice screening, meeting transcription, and messaging and email delivery providers.
We will give you at least 30 days' notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If we cannot offer a reasonable alternative, you may terminate the affected part of the subscription and receive a pro-rated refund of prepaid unused fees. TODO: confirm the notice period and the refund position with counsel and finance.
8.Annex II — Technical and organisational measures
| Area | Measures |
|---|---|
| Encryption | TLS for data in transit; encryption at rest for databases, object storage, and backups. |
| Access control | Role-based permissions; server-side authorisation on every request; tenant isolation between customer organisations; hashed credentials; scoped, expiring session tokens; federated sign-in support. |
| Internal access | Least-privilege production access limited to personnel who require it, granted on request and reviewed periodically; confidentiality obligations for all personnel. |
| Logging and monitoring | Audit logs of access to candidate records and administrative actions, with actor and timestamp; availability and error monitoring. |
| Resilience | Encrypted, access-controlled backups with documented restore procedures. |
| Development security | Code review before merge; dependency vulnerability monitoring; separation of development, staging, and production; secrets held in managed configuration. |
| Data minimisation | Processing limited to data required for the hiring purpose; protected characteristics excluded from scoring inputs. |
| Deletion | Configurable retention; deletion or return on termination as set out in this DPA. |
| Sub-processor management | Assessment before onboarding; written contracts imposing equivalent obligations; published list with change notification. |
We may update these measures as technology evolves, provided the overall level of security is not reduced.
9.Data Subject requests
The platform provides functionality to search, export, correct, and delete an individual's records, allowing you to respond to access, rectification, erasure, restriction, portability, and objection requests yourself.
Where a Data Subject contacts us directly about data we process on your behalf, we will not respond substantively unless legally required, and will promptly forward the request to you. Where you need additional help, we will provide reasonable assistance taking into account the nature of the processing.
10.Personal Data Breach
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event within the period stated in the Agreement. TODO: state the committed notification window — 48 or 72 hours is typical, and enterprise buyers will ask for it in writing.
Our notification will include, to the extent known:
- The nature of the breach, including the categories and approximate number of Data Subjects and records affected.
- The likely consequences of the breach.
- The measures taken or proposed to address it and mitigate its effects.
- A contact point for further information.
We will cooperate with you and take reasonable steps to assist in your investigation, mitigation, and remediation, including any notification you must make to a supervisory authority or to Data Subjects. Our notification is not an acknowledgement of fault or liability.
11.Impact assessments and prior consultation
AI-assisted recruitment will usually require a Data Protection Impact Assessment. We will provide reasonable assistance, including documentation on data flows, categories of data processed, retention, security measures, sub-processors, transfer mechanisms, and the logic and intended effect of our automated processing. Where a DPIA indicates high residual risk and you must consult a supervisory authority, we will provide the information reasonably needed for that consultation.
12.International transfers
Where we transfer Customer Personal Data out of the EEA, the UK, or another jurisdiction imposing transfer restrictions, and the destination is not covered by an adequacy decision, the transfer is governed by the Standard Contractual Clauses, which are incorporated into this DPA by reference.
- EU transfers — Module Two (Controller to Processor) applies where you are a controller; Module Three (Processor to Processor) applies where you are a processor.
- Docking clause — applies. Clause 9 — Option 2, general written authorisation, with the notice period stated in the Sub-processors section. Clause 11 — the optional independent dispute resolution body is not adopted. Clause 17 — TODO: specify the governing law of the Clauses. Clause 18(b) — TODO: specify the forum.
- UK transfers — the UK International Data Transfer Addendum applies to the EU SCCs, with the tables completed by reference to this DPA and Annexes I and II.
- Supplementary measures — encryption in transit and at rest, access control, and a commitment to challenge any legally invalid government request for Customer Personal Data and to notify you where legally permitted.
TODO: counsel must complete the Clause 17 and 18(b) entries above, and confirm which SCC modules apply given TechAIVV's establishment. These are the first fields an enterprise privacy team checks.
13.Deletion and return of data
- You may export Customer Personal Data at any time during the term, and for 30 days after termination or expiry.
- After that period, we will delete Customer Personal Data from active systems, unless retention is required by law, in which case we will continue to protect it and process it only for the purpose requiring retention.
- Backup copies are deleted on our normal backup rotation cycle.
- We will certify deletion in writing on request.
14.Audits
We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint.
- In the first instance we will provide our security documentation, current sub-processor list, and any available third-party audit reports.
- Where that is insufficient, you may request an audit on at least 30 days' written notice, no more than once in any 12-month period, unless required more often by a supervisory authority or following a Personal Data Breach.
- Audits will be conducted during business hours, subject to confidentiality obligations, and in a manner that does not unreasonably disrupt our operations or compromise the data of other customers.
- You bear the costs of the audit, except where it reveals material non-compliance with this DPA.
15.Liability, term, and general
- Liability. Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement. TODO: confirm whether data protection claims sit inside the general cap or take a separate super-cap — this is a standard enterprise negotiation point.
- Term. This DPA takes effect with the Agreement and continues until we have deleted or returned all Customer Personal Data.
- Changes. We may update this DPA where required by a change in Data Protection Law or our processing operations, provided the update does not materially reduce the protection afforded to Customer Personal Data.
- Severability. If a provision is held invalid, the remainder stays in effect.
- Governing law. This DPA is governed by the law of the Agreement, except where Data Protection Law or the SCCs require otherwise.
TODO: insert TechAIVV's registered company name, registration number, and full registered address, and the name and contact details of the privacy contact or Data Protection Officer. Under the SCCs these must appear in Annex I, and a privacy team will reject the document without them.
Questions about this document?
Write to legal@hireaivv.ai. For privacy requests or data-protection matters, use privacy@hireaivv.ai.