Last Updated: July 2026
Overview
Schedule A to the Master Service Agreement
Version 1.0 — July 2026
This Data Processing Agreement (“DPA”) forms Schedule A to, and is incorporated into, the Master Service Agreement (“MSA”) between Hello Recruiter Inc. (“Processor,” “Hello Recruiter”) and the Client identified on the applicable Order Form (“Controller,” “Client”). It governs the Processing of Personal Data by Hello Recruiter on the Client’s behalf. In the event of a conflict between this DPA and the MSA, this DPA governs with respect to data protection matters. Capitalized terms not defined here have the meanings given in the MSA.
1. Definitions
“Applicable Data Protection Law” means all privacy and data protection laws applicable to the Processing of Personal Data under this DPA, including US federal and state privacy laws (such as the CCPA) and, where applicable, the GDPR, UK GDPR, and Swiss FADP.
“CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and its implementing regulations.
“GDPR” means Regulation (EU) 2016/679 and, as applicable, the UK GDPR and Swiss FADP.
“Personal Data” (or “Personal Information”) means any information relating to an identified or identifiable natural person Processed under this DPA, including Candidate Data as defined in the MSA.
“Processing” means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, transmission, or deletion.
“Sub-Processor” means a third party engaged by Hello Recruiter to Process Personal Data on the Client’s behalf.
“Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
“Standard Contractual Clauses” (or “SCCs”) means the clauses adopted in Implementing Decision (EU) 2021/914, together with the UK Addendum and Swiss amendments in Annex 3.
2. Roles and Responsibilities
2.1 Controller and Processor. The Client is the data controller and Hello Recruiter is the data processor with respect to Candidate Data and other Client Data. For CCPA purposes, the Client is the “business” and Hello Recruiter is a “service provider.”
2.2 Documented Instructions. Hello Recruiter shall Process Personal Data only on the Client’s documented instructions, including the MSA, this DPA, Documentation, and the Client’s configuration and use of the Platform, unless required by law.
2.3 Client Responsibilities. The Client is responsible for the accuracy and lawfulness of submitted Personal Data, for having a lawful basis and necessary consents, and for providing candidates the AI disclosure required under Section 3 of the MSA.
3. Processing Obligations
Process Personal Data only on documented instructions, including transfers to third countries.
Ensure authorized persons are bound by appropriate confidentiality obligations.
Implement and maintain the security measures described in Section 4.
Assist the Client with data subject and consumer rights requests.
Assist with security, Security Incident notification, and data protection impact assessments.
Delete or return Personal Data on termination as described in Section 11.
Make available information reasonably necessary to demonstrate compliance as described in Section 12.
No model training
Hello Recruiter shall not use Personal Data to train, fine-tune, or improve its AI or machine-learning models without the Client’s prior written consent. Hello Recruiter may use de-identified or aggregated data that cannot reasonably be linked to any individual or Client to maintain, secure, and improve the Platform, consistent with Section 6.3 of the MSA.
4. Security Measures
Technical Measures
Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
Multi-factor authentication for administrative access to production systems.
Least-privilege access controls.
Regular penetration testing and vulnerability scanning.
Automated security monitoring and intrusion detection.
Regular backups with tested recovery procedures.
Organizational Measures
A designated privacy officer and security team.
Employee data protection and security training.
Background checks for employees with access to Personal Data.
Documented incident response procedures.
Annual security audits and risk assessments.
5. Security Incident Notification
5.1 Hello Recruiter shall notify the Client without undue delay, and no later than forty-eight (48) hours after becoming aware of a Security Incident affecting Personal Data.
5.2 The notification shall include, to the extent known, the nature of the incident, affected data subjects and records, likely consequences, and measures taken or proposed.
5.3 Hello Recruiter shall cooperate in investigating and remediating the Security Incident and provide reasonable assistance with the Client’s notification obligations.
6. Sub-Processors
6.1 General Authorization. The Client authorizes Hello Recruiter to engage Sub-Processors. The current list appears in Annex 2 and at hellorecruiter.ai/legal/subprocessors.
6.2 Flow-Down. Hello Recruiter shall impose obligations no less protective than this DPA and remains responsible for each Sub-Processor’s performance.
6.3 Change Notification. Hello Recruiter shall provide at least fourteen (14) days’ notice before adding or replacing a Sub-Processor. The Client may object on reasonable data protection grounds and may terminate the affected Order Form if unresolved.
7. Customer-Directed Integrations
The Client instructs Hello Recruiter to transmit specified data to the enabled third-party system; this is a Client-directed transfer.
The third-party system is the Client’s own processor or vendor, not a Hello Recruiter Sub-Processor; the Client is responsible for its agreement and lawful basis.
Only evaluation outputs (scorecards and reports) are transmitted. No recordings, raw audio or video, voiceprints, or other biometric data are transmitted through integrations.
Hello Recruiter’s responsibility for transmitted data ends upon delivery to the Client-designated system.
8. Data Subject and Consumer Rights
Hello Recruiter shall assist the Client in fulfilling requests under Applicable Data Protection Law. On request, Hello Recruiter shall provide access to, correct, or delete Personal Data within a commercially reasonable timeframe. The Client remains responsible for receiving and assessing requests and directing Hello Recruiter. Direct candidate requests will be referred to the relevant Client, with assistance provided to that Client.
9. International Data Transfers
9.1 Hello Recruiter’s infrastructure and Sub-Processors are located in the United States. Processing EEA, UK, or Swiss Personal Data therefore involves a transfer to the United States.
9.2 The SCCs are incorporated by reference as set out in Annex 3. Module Two applies between the Client and Hello Recruiter; Module Three applies to onward transfers. The UK Addendum and Swiss amendments apply respectively.
9.3 Data Privacy Framework certification may serve as an additional mechanism where available; the SCCs remain the primary safeguard.
10. CCPA Service Provider Terms
For Personal Information subject to the CCPA, Hello Recruiter acts as a Service Provider and shall:
Process only for the business purpose of providing the Platform under the MSA.
Not sell or share Personal Information as defined by the CCPA.
Not retain, use, or disclose Personal Information outside the direct business relationship or specified business purposes.
Not combine Personal Information with information from another party except as permitted by the CCPA.
Provide the same level of privacy protection required of the Client.
Notify the Client if it can no longer meet its CCPA obligations.
Permit reasonable steps to ensure compliant use and to stop and remediate unauthorized use.
Certification. Hello Recruiter certifies that it understands and will comply with the restrictions in this Section.
11. Data Retention and Deletion
Hello Recruiter retains Personal Data according to the following schedule and the MSA. After termination or expiry, Client Data remains available for export for thirty (30) days, then is deleted or returned unless retention is required by law.
Data Category
Retention Period
Client account data
Duration of subscription + 30 days for export, then deleted
Candidate application data
Duration of employer’s subscription + 30 days; employer-configurable for recordkeeping obligations, then deleted
Assessment results
Duration of employer’s subscription + 30 days, then deleted
Interview recordings
90 days from interview date by default; configurable by Client
Billing records
7 years
Security and audit logs
12 months
Support communications
3 years after last contact
12. Audit Rights
With at least thirty (30) days’ written notice, Hello Recruiter shall make available information reasonably necessary to demonstrate compliance. Hello Recruiter may provide its latest SOC 2 Type II or equivalent report instead of an on-site audit. Audit information is Hello Recruiter Confidential Information.
13. Liability
Each party’s liability arising from this DPA is subject to the exclusions and limitations in Section 9 of the MSA, and references there to the MSA include this DPA.
14. General Provisions
14.1 Governing Law. Delaware law governs this DPA, with exclusive jurisdiction in state and federal courts located in Broward County, Florida, consistent with Section 12.1 of the MSA, except where Annex 3 governs the SCCs.
14.2 Order of Precedence. For data protection matters: (1) the SCCs, (2) this DPA, (3) the MSA.
14.3 Incorporation. This DPA forms part of the MSA. Execution of the MSA or an Order Form constitutes acceptance.
Annex 1 — Details of Processing
Subject matter and duration: Provision of the Platform during the Subscription Term and post-termination export and deletion period.
Nature and purpose: AI-assisted resume screening, interviewing, evaluation, fraud detection, and generation of assessment outputs for the Client’s hiring team.
Data subjects: Job candidates and the Client’s Authorized Users.
Categories of Personal Data:
Category
Examples
Purpose
Candidate identity
Name, email, phone, address, professional profile
Identification and communication
Professional history
Resume, work history, education, skills
AI resume screening and evaluation
Interview recordings
Video/audio of AI interview sessions
Behavioral and competency assessment
Assessment results
AI-generated scores, evaluations, flags
Hiring decision support
Fraud detection signals
IP address, device information, behavioral patterns
Fraud and identity verification
Account data
Authorized User names, emails, login activity
Platform access and security
Annex 2 — Sub-Processor List
All listed Sub-Processors are located in the United States. Transfers of EEA, UK, or Swiss Personal Data are protected by the SCCs in Annex 3.
Sub-Processor
Purpose
Data Processed
Location
Microsoft Azure
Cloud hosting, storage, networking
All Platform data
US (East US / East US 2)
Google Cloud – Vertex AI (Gemini)
AI inference for interview conduct and evaluation
Transcripts, resumes, evaluation inputs
US
LiveKit Cloud
Real-time voice/video infrastructure
Live audio/video, session metadata
US
Deepgram
Speech-to-text
Candidate voice audio, transcripts
US
OpenAI
Speech-to-text / text-to-speech
Candidate voice audio, transcripts
US
Cartesia
Agent voice synthesis
Agent-side text with candidate context
US
OpenRouter
AI routing for coding interviews only
Code submissions, prompts
US
Temporal Cloud
Workflow orchestration
Workflow state with candidate identifiers
US
Postmark
Transactional email
Candidate name, email, message content
US
Twilio
SMS / telephony
Candidate name, phone number
US
Datadog
Monitoring and logging
Operational logs
US
Intercom
Customer support
Client contact and support content
US
Google Analytics
Product and candidate-flow analytics
Usage and device data
US
Microsoft 365
Business communications
Client contact and communications data
US
Stripe
Payment processing
Client billing and payment data
US
Annex 3 — Cross-Border Transfer Mechanism
EU Standard Contractual Clauses. The SCCs (Implementing Decision (EU) 2021/914) are incorporated by reference with the following elections:
Modules: Module Two applies between Client and Hello Recruiter; Module Three applies to onward transfers.
Clause 7 docking clause applies.
Clause 9 uses Option 2 with 14 days’ notice.
Clause 11 optional independent dispute resolution does not apply.
Clause 17 governing law: Ireland.
Clause 18 forum and jurisdiction: courts of Ireland.
Annex I.A: exporter is Client; importer is Hello Recruiter Inc.
Annex I.B: transfer details are in Annex 1; frequency is continuous.
Annex I.C: competent authority under Clause 13, defaulting to the Irish Data Protection Commission.
Annex II: measures in Section 4.
Annex III: Sub-Processors in Annex 2.
UK transfers. The UK International Data Transfer Addendum (version B1.0) applies; the UK-based Client is exporter, the ICO is competent authority, and the tables are completed by reference to this Annex.
Swiss transfers. GDPR references are read as Swiss FADP references, the Swiss FDPIC is competent authority, and the SCCs protect legal-entity data where required.
Acceptance
This DPA is incorporated into and forms part of the MSA. Execution of the MSA or an Order Form constitutes acceptance of this DPA by both parties.
Last Updated: July 2026