Data Processing Agreement

Data Processing Agreement

Data Processing Agreement

Last Updated: July 2026

Overview

Schedule A to the Master Service Agreement

Version 1.0 — July 2026

This Data Processing Agreement (“DPA”) forms Schedule A to, and is incorporated into, the Master Service Agreement (“MSA”) between Hello Recruiter Inc. (“Processor,” “Hello Recruiter”) and the Client identified on the applicable Order Form (“Controller,” “Client”). It governs the Processing of Personal Data by Hello Recruiter on the Client’s behalf. In the event of a conflict between this DPA and the MSA, this DPA governs with respect to data protection matters. Capitalized terms not defined here have the meanings given in the MSA.

1. Definitions

  • “Applicable Data Protection Law” means all privacy and data protection laws applicable to the Processing of Personal Data under this DPA, including US federal and state privacy laws (such as the CCPA) and, where applicable, the GDPR, UK GDPR, and Swiss FADP.

  • “CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and its implementing regulations.

  • “GDPR” means Regulation (EU) 2016/679 and, as applicable, the UK GDPR and Swiss FADP.

  • “Personal Data” (or “Personal Information”) means any information relating to an identified or identifiable natural person Processed under this DPA, including Candidate Data as defined in the MSA.

  • “Processing” means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, transmission, or deletion.

  • “Sub-Processor” means a third party engaged by Hello Recruiter to Process Personal Data on the Client’s behalf.

  • “Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

  • “Standard Contractual Clauses” (or “SCCs”) means the clauses adopted in Implementing Decision (EU) 2021/914, together with the UK Addendum and Swiss amendments in Annex 3.

2. Roles and Responsibilities

2.1 Controller and Processor. The Client is the data controller and Hello Recruiter is the data processor with respect to Candidate Data and other Client Data. For CCPA purposes, the Client is the “business” and Hello Recruiter is a “service provider.”

2.2 Documented Instructions. Hello Recruiter shall Process Personal Data only on the Client’s documented instructions, including the MSA, this DPA, Documentation, and the Client’s configuration and use of the Platform, unless required by law.

2.3 Client Responsibilities. The Client is responsible for the accuracy and lawfulness of submitted Personal Data, for having a lawful basis and necessary consents, and for providing candidates the AI disclosure required under Section 3 of the MSA.

3. Processing Obligations

  • Process Personal Data only on documented instructions, including transfers to third countries.

  • Ensure authorized persons are bound by appropriate confidentiality obligations.

  • Implement and maintain the security measures described in Section 4.

  • Assist the Client with data subject and consumer rights requests.

  • Assist with security, Security Incident notification, and data protection impact assessments.

  • Delete or return Personal Data on termination as described in Section 11.

  • Make available information reasonably necessary to demonstrate compliance as described in Section 12.

No model training

Hello Recruiter shall not use Personal Data to train, fine-tune, or improve its AI or machine-learning models without the Client’s prior written consent. Hello Recruiter may use de-identified or aggregated data that cannot reasonably be linked to any individual or Client to maintain, secure, and improve the Platform, consistent with Section 6.3 of the MSA.

4. Security Measures

Technical Measures

  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).

  • Multi-factor authentication for administrative access to production systems.

  • Least-privilege access controls.

  • Regular penetration testing and vulnerability scanning.

  • Automated security monitoring and intrusion detection.

  • Regular backups with tested recovery procedures.

Organizational Measures

  • A designated privacy officer and security team.

  • Employee data protection and security training.

  • Background checks for employees with access to Personal Data.

  • Documented incident response procedures.

  • Annual security audits and risk assessments.

5. Security Incident Notification

5.1 Hello Recruiter shall notify the Client without undue delay, and no later than forty-eight (48) hours after becoming aware of a Security Incident affecting Personal Data.

5.2 The notification shall include, to the extent known, the nature of the incident, affected data subjects and records, likely consequences, and measures taken or proposed.

5.3 Hello Recruiter shall cooperate in investigating and remediating the Security Incident and provide reasonable assistance with the Client’s notification obligations.

6. Sub-Processors

6.1 General Authorization. The Client authorizes Hello Recruiter to engage Sub-Processors. The current list appears in Annex 2 and at hellorecruiter.ai/legal/subprocessors.

6.2 Flow-Down. Hello Recruiter shall impose obligations no less protective than this DPA and remains responsible for each Sub-Processor’s performance.

6.3 Change Notification. Hello Recruiter shall provide at least fourteen (14) days’ notice before adding or replacing a Sub-Processor. The Client may object on reasonable data protection grounds and may terminate the affected Order Form if unresolved.

7. Customer-Directed Integrations

  • The Client instructs Hello Recruiter to transmit specified data to the enabled third-party system; this is a Client-directed transfer.

  • The third-party system is the Client’s own processor or vendor, not a Hello Recruiter Sub-Processor; the Client is responsible for its agreement and lawful basis.

  • Only evaluation outputs (scorecards and reports) are transmitted. No recordings, raw audio or video, voiceprints, or other biometric data are transmitted through integrations.

  • Hello Recruiter’s responsibility for transmitted data ends upon delivery to the Client-designated system.

8. Data Subject and Consumer Rights

Hello Recruiter shall assist the Client in fulfilling requests under Applicable Data Protection Law. On request, Hello Recruiter shall provide access to, correct, or delete Personal Data within a commercially reasonable timeframe. The Client remains responsible for receiving and assessing requests and directing Hello Recruiter. Direct candidate requests will be referred to the relevant Client, with assistance provided to that Client.

9. International Data Transfers

9.1 Hello Recruiter’s infrastructure and Sub-Processors are located in the United States. Processing EEA, UK, or Swiss Personal Data therefore involves a transfer to the United States.

9.2 The SCCs are incorporated by reference as set out in Annex 3. Module Two applies between the Client and Hello Recruiter; Module Three applies to onward transfers. The UK Addendum and Swiss amendments apply respectively.

9.3 Data Privacy Framework certification may serve as an additional mechanism where available; the SCCs remain the primary safeguard.

10. CCPA Service Provider Terms

For Personal Information subject to the CCPA, Hello Recruiter acts as a Service Provider and shall:

  • Process only for the business purpose of providing the Platform under the MSA.

  • Not sell or share Personal Information as defined by the CCPA.

  • Not retain, use, or disclose Personal Information outside the direct business relationship or specified business purposes.

  • Not combine Personal Information with information from another party except as permitted by the CCPA.

  • Provide the same level of privacy protection required of the Client.

  • Notify the Client if it can no longer meet its CCPA obligations.

  • Permit reasonable steps to ensure compliant use and to stop and remediate unauthorized use.

Certification. Hello Recruiter certifies that it understands and will comply with the restrictions in this Section.

11. Data Retention and Deletion

Hello Recruiter retains Personal Data according to the following schedule and the MSA. After termination or expiry, Client Data remains available for export for thirty (30) days, then is deleted or returned unless retention is required by law.

Data Category

Retention Period

Client account data

Duration of subscription + 30 days for export, then deleted

Candidate application data

Duration of employer’s subscription + 30 days; employer-configurable for recordkeeping obligations, then deleted

Assessment results

Duration of employer’s subscription + 30 days, then deleted

Interview recordings

90 days from interview date by default; configurable by Client

Billing records

7 years

Security and audit logs

12 months

Support communications

3 years after last contact

12. Audit Rights

With at least thirty (30) days’ written notice, Hello Recruiter shall make available information reasonably necessary to demonstrate compliance. Hello Recruiter may provide its latest SOC 2 Type II or equivalent report instead of an on-site audit. Audit information is Hello Recruiter Confidential Information.

13. Liability

Each party’s liability arising from this DPA is subject to the exclusions and limitations in Section 9 of the MSA, and references there to the MSA include this DPA.

14. General Provisions

14.1 Governing Law. Delaware law governs this DPA, with exclusive jurisdiction in state and federal courts located in Broward County, Florida, consistent with Section 12.1 of the MSA, except where Annex 3 governs the SCCs.

14.2 Order of Precedence. For data protection matters: (1) the SCCs, (2) this DPA, (3) the MSA.

14.3 Incorporation. This DPA forms part of the MSA. Execution of the MSA or an Order Form constitutes acceptance.

Annex 1 — Details of Processing

Subject matter and duration: Provision of the Platform during the Subscription Term and post-termination export and deletion period.

Nature and purpose: AI-assisted resume screening, interviewing, evaluation, fraud detection, and generation of assessment outputs for the Client’s hiring team.

Data subjects: Job candidates and the Client’s Authorized Users.

Categories of Personal Data:

Category

Examples

Purpose

Candidate identity

Name, email, phone, address, professional profile

Identification and communication

Professional history

Resume, work history, education, skills

AI resume screening and evaluation

Interview recordings

Video/audio of AI interview sessions

Behavioral and competency assessment

Assessment results

AI-generated scores, evaluations, flags

Hiring decision support

Fraud detection signals

IP address, device information, behavioral patterns

Fraud and identity verification

Account data

Authorized User names, emails, login activity

Platform access and security

Annex 2 — Sub-Processor List

All listed Sub-Processors are located in the United States. Transfers of EEA, UK, or Swiss Personal Data are protected by the SCCs in Annex 3.

Sub-Processor

Purpose

Data Processed

Location

Microsoft Azure

Cloud hosting, storage, networking

All Platform data

US (East US / East US 2)

Google Cloud – Vertex AI (Gemini)

AI inference for interview conduct and evaluation

Transcripts, resumes, evaluation inputs

US

LiveKit Cloud

Real-time voice/video infrastructure

Live audio/video, session metadata

US

Deepgram

Speech-to-text

Candidate voice audio, transcripts

US

OpenAI

Speech-to-text / text-to-speech

Candidate voice audio, transcripts

US

Cartesia

Agent voice synthesis

Agent-side text with candidate context

US

OpenRouter

AI routing for coding interviews only

Code submissions, prompts

US

Temporal Cloud

Workflow orchestration

Workflow state with candidate identifiers

US

Postmark

Transactional email

Candidate name, email, message content

US

Twilio

SMS / telephony

Candidate name, phone number

US

Datadog

Monitoring and logging

Operational logs

US

Intercom

Customer support

Client contact and support content

US

Google Analytics

Product and candidate-flow analytics

Usage and device data

US

Microsoft 365

Business communications

Client contact and communications data

US

Stripe

Payment processing

Client billing and payment data

US

Annex 3 — Cross-Border Transfer Mechanism

EU Standard Contractual Clauses. The SCCs (Implementing Decision (EU) 2021/914) are incorporated by reference with the following elections:

  • Modules: Module Two applies between Client and Hello Recruiter; Module Three applies to onward transfers.

  • Clause 7 docking clause applies.

  • Clause 9 uses Option 2 with 14 days’ notice.

  • Clause 11 optional independent dispute resolution does not apply.

  • Clause 17 governing law: Ireland.

  • Clause 18 forum and jurisdiction: courts of Ireland.

  • Annex I.A: exporter is Client; importer is Hello Recruiter Inc.

  • Annex I.B: transfer details are in Annex 1; frequency is continuous.

  • Annex I.C: competent authority under Clause 13, defaulting to the Irish Data Protection Commission.

  • Annex II: measures in Section 4.

  • Annex III: Sub-Processors in Annex 2.

UK transfers. The UK International Data Transfer Addendum (version B1.0) applies; the UK-based Client is exporter, the ICO is competent authority, and the tables are completed by reference to this Annex.

Swiss transfers. GDPR references are read as Swiss FADP references, the Swiss FDPIC is competent authority, and the SCCs protect legal-entity data where required.

Acceptance

This DPA is incorporated into and forms part of the MSA. Execution of the MSA or an Order Form constitutes acceptance of this DPA by both parties.

Last Updated: July 2026

© 2026 Hello Recruiter Inc. ® All rights reserved.
© 2026 Hello Recruiter Inc. ® All rights reserved.
© 2026 Hello Recruiter Inc. ® All rights reserved.