Legal

Data Processing Addendum

The Article 28 processor terms governing our handling of personal data on your behalf, including processing details, security measures, sub-processors, and transfer mechanisms.

Effective 20 July 2026 · TechAIVV Technologies

1.Scope and application

This Data Processing Addendum ("DPA") forms part of the agreement between TechAIVV Technologies ("Processor", "we") and the customer ("Controller", "you") for use of the HireAivv platform (the "Agreement"). It applies where we process personal data on your behalf and data protection law applies to that processing.

Where this DPA conflicts with the Agreement, this DPA controls in respect of the processing of personal data. Where it conflicts with the Standard Contractual Clauses, the Clauses control.

Need this executed as a signed document for your records, or need it on your own paper? Email legal@hireaivv.ai and we will arrange signature.

2.Definitions

  • Data Protection Law — all laws applicable to the processing of personal data under this DPA, including the EU GDPR, the UK GDPR, and India's Digital Personal Data Protection Act, 2023.
  • Controller, Processor, Data Subject, Personal Data, Processing, and Personal Data Breach have the meanings given in the GDPR. Where the DPDP Act applies, Data Fiduciary, Data Processor, and Data Principal carry the corresponding meanings.
  • Customer Personal Data — personal data contained in Customer Data that we process on your behalf under the Agreement.
  • Sub-processor — a third party engaged by us to process Customer Personal Data.
  • Standard Contractual Clauses or SCCs — the clauses annexed to European Commission Implementing Decision (EU) 2021/914, and where relevant the UK International Data Transfer Addendum.

3.Roles of the parties

You are the Controller and we are the Processor in respect of Customer Personal Data. You determine the purposes and means of processing — which roles you hire for, which candidates you assess, which features you enable, and how long records are kept.

Where you are yourself a processor for a third party — for example a recruitment agency acting for a client employer — you warrant that you have the authority of that controller to instruct us, and that the instructions you give us are consistent with theirs.

We act as an independent controller for a limited set of data described in our Privacy Policy, including account administrator contact details, billing records, and security and usage telemetry. That processing is governed by our Privacy Policy rather than this DPA.

4.Annex I — Details of processing

ItemDetail
Subject matterProvision of the HireAivv AI recruitment platform under the Agreement.
DurationThe term of the Agreement, plus the deletion and return period set out in this DPA.
Nature and purposeHosting and storage; parsing of résumés and documents; AI-assisted skill extraction, matching, scoring and ranking; screening question generation and evaluation; AI voice screening; interview scheduling, recording, transcription and summarisation; candidate communication by email, SMS and WhatsApp; reporting and analytics; support and troubleshooting.
Categories of Data SubjectJob candidates and applicants; your employees and contractors who use the platform (recruiters, hiring managers, administrators); interview panellists; and where applicable, the contacts of your client organisations.
Categories of Personal DataIdentity and contact data (name, email, phone, location); professional data (work history, education, skills, certifications, salary expectations, notice period); application data (résumés, cover letters, portfolios, uploaded documents); assessment data (match scores, rankings, screening responses, evaluations, recruiter notes); interview data (schedules, call recordings, transcripts, summaries); communication data (message content and delivery status); and account and usage data (credentials, roles, IP address, activity logs).
Special category dataNot requested and not required. Candidates occasionally volunteer such information in free-text documents. It is not used for scoring or ranking. You should not deliberately submit special category data unless you have a lawful basis under Article 9 and have instructed us in writing.
Frequency of transferContinuous, for the duration of the Agreement.
Automated decision-makingThe platform generates scores and rankings as decision support. It is configured on the basis that you maintain meaningful human review of every decision affecting a Data Subject.

5.Our obligations as Processor

We will:

  1. 1.Process Customer Personal Data only on your documented instructions, including the Agreement, this DPA, and your configuration of the platform — unless required otherwise by law, in which case we will inform you first unless the law prohibits it.
  2. 2.Immediately inform you if, in our opinion, an instruction infringes Data Protection Law.
  3. 3.Not sell Customer Personal Data, and not process it for our own purposes, for advertising, or for any purpose outside providing the Service.
  4. 4.Not use Customer Personal Data to train or fine-tune machine learning models, and contractually prohibit our AI sub-processors from training their models on data we submit.
  5. 5.Ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations that survive the end of their engagement, and are granted access on a least-privilege, need-to-know basis.
  6. 6.Implement and maintain the technical and organisational measures in Annex II.
  7. 7.Assist you, taking into account the nature of processing and the information available to us, in meeting your obligations under Articles 32 to 36 GDPR and the corresponding provisions of other Data Protection Law.

6.Your obligations as Controller

You will:

  1. 1.Ensure you have a lawful basis for the collection and processing of Customer Personal Data, and that your instructions to us comply with Data Protection Law.
  2. 2.Provide Data Subjects with the privacy notices and information required by law, including notice that automated tools are used in your process where that is required.
  3. 3.Obtain any consent required in the relevant jurisdiction — in particular for recording screening calls and interviews, which several jurisdictions require every participant to consent to.
  4. 4.Maintain meaningful human review of hiring decisions, and not use the Service to make decisions based solely on automated processing where prohibited.
  5. 5.Configure retention periods appropriate to your legal obligations and the jurisdictions you recruit in.
  6. 6.Manage access for your Users, and revoke it promptly when no longer needed.
  7. 7.Not submit special category data, or data of children, except where you have a lawful basis and have instructed us in writing.

7.Sub-processors

You give general authorisation for us to engage sub-processors. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

The current list is published in our Privacy Policy and covers infrastructure (database and object storage), AI processing, voice screening, meeting transcription, and messaging and email delivery providers.

We will give you at least 30 days' notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If we cannot offer a reasonable alternative, you may terminate the affected part of the subscription and receive a pro-rated refund of prepaid unused fees. TODO: confirm the notice period and the refund position with counsel and finance.

8.Annex II — Technical and organisational measures

AreaMeasures
EncryptionTLS for data in transit; encryption at rest for databases, object storage, and backups.
Access controlRole-based permissions; server-side authorisation on every request; tenant isolation between customer organisations; hashed credentials; scoped, expiring session tokens; federated sign-in support.
Internal accessLeast-privilege production access limited to personnel who require it, granted on request and reviewed periodically; confidentiality obligations for all personnel.
Logging and monitoringAudit logs of access to candidate records and administrative actions, with actor and timestamp; availability and error monitoring.
ResilienceEncrypted, access-controlled backups with documented restore procedures.
Development securityCode review before merge; dependency vulnerability monitoring; separation of development, staging, and production; secrets held in managed configuration.
Data minimisationProcessing limited to data required for the hiring purpose; protected characteristics excluded from scoring inputs.
DeletionConfigurable retention; deletion or return on termination as set out in this DPA.
Sub-processor managementAssessment before onboarding; written contracts imposing equivalent obligations; published list with change notification.

We may update these measures as technology evolves, provided the overall level of security is not reduced.

9.Data Subject requests

The platform provides functionality to search, export, correct, and delete an individual's records, allowing you to respond to access, rectification, erasure, restriction, portability, and objection requests yourself.

Where a Data Subject contacts us directly about data we process on your behalf, we will not respond substantively unless legally required, and will promptly forward the request to you. Where you need additional help, we will provide reasonable assistance taking into account the nature of the processing.

10.Personal Data Breach

We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event within the period stated in the Agreement. TODO: state the committed notification window — 48 or 72 hours is typical, and enterprise buyers will ask for it in writing.

Our notification will include, to the extent known:

  • The nature of the breach, including the categories and approximate number of Data Subjects and records affected.
  • The likely consequences of the breach.
  • The measures taken or proposed to address it and mitigate its effects.
  • A contact point for further information.

We will cooperate with you and take reasonable steps to assist in your investigation, mitigation, and remediation, including any notification you must make to a supervisory authority or to Data Subjects. Our notification is not an acknowledgement of fault or liability.

11.Impact assessments and prior consultation

AI-assisted recruitment will usually require a Data Protection Impact Assessment. We will provide reasonable assistance, including documentation on data flows, categories of data processed, retention, security measures, sub-processors, transfer mechanisms, and the logic and intended effect of our automated processing. Where a DPIA indicates high residual risk and you must consult a supervisory authority, we will provide the information reasonably needed for that consultation.

12.International transfers

Where we transfer Customer Personal Data out of the EEA, the UK, or another jurisdiction imposing transfer restrictions, and the destination is not covered by an adequacy decision, the transfer is governed by the Standard Contractual Clauses, which are incorporated into this DPA by reference.

  • EU transfers — Module Two (Controller to Processor) applies where you are a controller; Module Three (Processor to Processor) applies where you are a processor.
  • Docking clause — applies. Clause 9 — Option 2, general written authorisation, with the notice period stated in the Sub-processors section. Clause 11 — the optional independent dispute resolution body is not adopted. Clause 17 — TODO: specify the governing law of the Clauses. Clause 18(b) — TODO: specify the forum.
  • UK transfers — the UK International Data Transfer Addendum applies to the EU SCCs, with the tables completed by reference to this DPA and Annexes I and II.
  • Supplementary measures — encryption in transit and at rest, access control, and a commitment to challenge any legally invalid government request for Customer Personal Data and to notify you where legally permitted.

TODO: counsel must complete the Clause 17 and 18(b) entries above, and confirm which SCC modules apply given TechAIVV's establishment. These are the first fields an enterprise privacy team checks.

13.Deletion and return of data

  • You may export Customer Personal Data at any time during the term, and for 30 days after termination or expiry.
  • After that period, we will delete Customer Personal Data from active systems, unless retention is required by law, in which case we will continue to protect it and process it only for the purpose requiring retention.
  • Backup copies are deleted on our normal backup rotation cycle.
  • We will certify deletion in writing on request.

14.Audits

We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint.

  • In the first instance we will provide our security documentation, current sub-processor list, and any available third-party audit reports.
  • Where that is insufficient, you may request an audit on at least 30 days' written notice, no more than once in any 12-month period, unless required more often by a supervisory authority or following a Personal Data Breach.
  • Audits will be conducted during business hours, subject to confidentiality obligations, and in a manner that does not unreasonably disrupt our operations or compromise the data of other customers.
  • You bear the costs of the audit, except where it reveals material non-compliance with this DPA.

15.Liability, term, and general

  • Liability. Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement. TODO: confirm whether data protection claims sit inside the general cap or take a separate super-cap — this is a standard enterprise negotiation point.
  • Term. This DPA takes effect with the Agreement and continues until we have deleted or returned all Customer Personal Data.
  • Changes. We may update this DPA where required by a change in Data Protection Law or our processing operations, provided the update does not materially reduce the protection afforded to Customer Personal Data.
  • Severability. If a provision is held invalid, the remainder stays in effect.
  • Governing law. This DPA is governed by the law of the Agreement, except where Data Protection Law or the SCCs require otherwise.

TODO: insert TechAIVV's registered company name, registration number, and full registered address, and the name and contact details of the privacy contact or Data Protection Officer. Under the SCCs these must appear in Annex I, and a privacy team will reject the document without them.

Questions about this document?

Write to legal@hireaivv.ai. For privacy requests or data-protection matters, use privacy@hireaivv.ai.