Data Processing Agreement

Data Processing Agreement

Data Processing Agreement

Version 1.0 · Effective September 10, 2026

1. Introduction and Roles

Hello Recruiter Platform — Processor / Service Provider Terms. Version 1.0 — Effective September 10, 2026.

This Data Processing Agreement ("DPA") forms part of the agreement between Hello Recruiter Inc., a Delaware corporation with its principal place of business at 1520 NE 7th Street, Fort Lauderdale, FL 33304, USA ("Hello Recruiter" or "Processor"), and the customer that has entered into an order form, Master Services Agreement, or the Terms of Service governing use of the Hello Recruiter platform (the "Agreement") ("Customer" or "Controller"). This DPA governs Hello Recruiter's Processing of Personal Data on Customer's behalf in connection with the services described in the Agreement (the "Services").

For Personal Data of Candidates and other individuals Processed through Customer's hiring workflows, Customer is the Controller (or a processor acting on behalf of another controller) and Hello Recruiter is the Processor and, for purposes of US state privacy laws including the CCPA, a "service provider." Hello Recruiter Processes such Personal Data only as described in this DPA and the Agreement. This DPA is effective upon Customer's acceptance of the Agreement.

2. Definitions

• "Personal Data" means information relating to an identified or identifiable natural person that Hello Recruiter Processes on Customer's behalf under the Agreement.

• "Processing" means any operation performed on Personal Data, such as collection, recording, storage, analysis, disclosure, or deletion. "Process" has a corresponding meaning.

• "Data Protection Laws" means all laws applicable to the Processing of Personal Data under the Agreement, including, as applicable, the California Consumer Privacy Act as amended (CCPA), other US state privacy laws, and, where applicable, the EU and UK General Data Protection Regulation ("GDPR").

• "Candidate" means an individual participating in Customer's hiring process through the Services.

• "De-identified Data" means data created by Hello Recruiter from Personal Data or from data generated through use of the Services, from which identifiers have been removed or transformed such that the data cannot reasonably be used to identify, relate to, describe, be associated with, or be linked, directly or indirectly, with a particular individual, Candidate, or Customer, consistent with the standard for de-identified data under the CCPA.

• "Communications Data" means telephone numbers, email addresses, WhatsApp identifiers, message content, delivery metadata, and consent and opt-out records Processed to deliver application-related communications to Candidates on behalf of Customer.

• "Sub-processor" means a third party engaged by Hello Recruiter to Process Personal Data in connection with the Services.

• "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data Processed by Hello Recruiter.

3. Scope and Details of Processing

Item
Description
Subject matter
Provision of the AI-powered recruiting Services described in the Agreement
Duration
The term of the Agreement plus the post-termination period in Section 12
Nature and purpose
Hosting and operating hiring workflows; AI-led screening, interviews, and assessments scored against Customer-defined criteria; candidate communications; fraud detection; support; security
Categories of data subjects
Candidates; Customer's authorized users and personnel
Categories of Personal Data
Contact details; professional history (resumes, education, skills); interview recordings and transcripts; assessment data and scores; communications and consent records; usage, device, and fraud-detection signals
Sensitive data
Where enabled and consented: transient biometric data for same-person verification (Section 9); data revealing sensitive characteristics only as incidentally contained in candidate-provided materials

4. Processor Obligations

4.1 Instructions

Hello Recruiter will Process Personal Data only on Customer's documented instructions — as set out in the Agreement, this DPA, and Customer's configuration of the Services — unless required otherwise by applicable law, in which case Hello Recruiter will inform Customer unless legally prohibited. Hello Recruiter will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

4.2 CCPA Service Provider Commitments

Hello Recruiter certifies that it will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than performing the Services and as permitted for service providers under the CCPA, including the creation and use of De-identified Data under Section 7; (c) retain, use, or disclose Personal Data outside the direct business relationship with Customer; or (d) combine Personal Data with personal information from other sources except as permitted for service providers. Hello Recruiter will notify Customer if it can no longer meet its obligations under the CCPA, and Customer may take reasonable steps to stop and remediate unauthorized use.

4.3 Confidentiality

Hello Recruiter ensures that persons authorized to Process Personal Data are bound by contractual or statutory confidentiality obligations and receive appropriate data protection training.

4.4 Security

Hello Recruiter implements and maintains appropriate technical and organizational measures to protect Personal Data, including encryption in transit and at rest, role-based access controls, network security, logging and monitoring, secure development practices, personnel security, and regular testing, as further described in Annex II. Hello Recruiter maintains an information security program aligned with the SOC 2 Trust Services Criteria, with continuous control monitoring, and is pursuing SOC 2 Type II attestation; upon issuance, attestation reports will be made available upon reasonable request under confidentiality, and in the interim Hello Recruiter will provide reasonable security documentation describing its controls.

4.5 Assistance

Taking into account the nature of the Processing, Hello Recruiter will assist Customer through appropriate technical and organizational measures in fulfilling Customer's obligations to respond to data subject requests (access, deletion, correction, portability, objection, and automated decision-making rights, including the candidate contest and human-review workflows built into the Services) and, where applicable, with data protection impact assessments and consultations with supervisory authorities. If a data subject contacts Hello Recruiter directly, Hello Recruiter will promptly redirect the request to Customer and assist as its Processor.

4.6 Security Incident Notification

Hello Recruiter will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident, and will provide information reasonably available to help Customer meet its own notification obligations, followed by updates as the investigation progresses. Notification is not an acknowledgment of fault or liability.

4.7 Records and Audits

Hello Recruiter will maintain records of its Processing activities as required by Data Protection Laws and will make available information reasonably necessary to demonstrate compliance with this DPA. No more than once per twelve (12) months (or following a Security Incident affecting Customer's Personal Data), Customer may audit compliance, first through Hello Recruiter's available reports and certifications, and, where reasonably required, through an audit conducted with reasonable notice, during business hours, under confidentiality, and without unreasonable disruption to Hello Recruiter's operations.

5. Automated Decision-Making Support

The Services provide configurations supporting Customer's obligations regarding automated decision-making: human review of AI assessments before adverse decisions (default), structured requirement rules acting solely on Candidates' own answers, per-role enablement of criteria-based automated decisions where lawful with the applied criteria and scores recorded, candidate contest and human-review workflows, and jurisdiction-based restrictions (including for Candidates located in the European Union). Customer is responsible for its configuration choices and for compliance with laws governing automated employment decisions in the jurisdictions where it hires, as set out in the Agreement.

6. AI Processing; No Training on Identifiable Data

Hello Recruiter uses third-party AI infrastructure providers as Sub-processors to deliver AI functionality. Hello Recruiter will not use identifiable Personal Data Processed under this DPA to train artificial intelligence models, and will not permit any Sub-processor to use such Personal Data to train that Sub-processor's models; Hello Recruiter's agreements with AI Sub-processors prohibit training on data submitted through the Services. Biometric data and interview audio or video recordings are never used for the development or improvement of AI models.

7. De-identified Data

7.1 Right to Create and Use

Notwithstanding anything to the contrary in this DPA or the Agreement, nothing restricts Hello Recruiter from creating De-identified Data and using it for any lawful business purpose, including to maintain, secure, and improve the Services and to develop and improve the artificial intelligence technology that powers them — such as improving the fairness and accuracy of candidate assessment and strengthening fraud and risk identification. De-identified Data is not Personal Data and is not subject to the Processing restrictions, deletion obligations, or return obligations of this DPA.

7.2 Commitments

With respect to De-identified Data, Hello Recruiter shall: (a) implement technical safeguards and business processes that prohibit re-identification; (b) not attempt to re-identify De-identified Data, except solely to test the effectiveness of its de-identification process; (c) contractually obligate any recipient of De-identified Data to comply with commitments no less protective than this Section; and (d) never include biometric data, biometric identifiers, or interview audio or video recordings in De-identified Data used for the development or improvement of AI models.

7.3 Enterprise Opt-Out

Customer may elect to exclude data originating from its instance of the Services from the creation of De-identified Data under Section 7.1 only by written order form or addendum executed by both parties. No purchase order, vendor portal terms, or unilateral notice from Customer modifies this Section. Upon execution, Hello Recruiter will implement the exclusion within thirty (30) days for data collected thereafter.

8. Candidate Communications

Customer instructs Hello Recruiter to deliver application-related communications (email, SMS, WhatsApp messages and calls, and voice calls, including AI-conducted interview and video calls) to Candidates participating in Customer's hiring process, in accordance with Hello Recruiter's Messaging & Communications Terms and the regional program schedules therein. Hello Recruiter shall: (a) obtain and record Candidate consent as described in those terms; (b) honor opt-out requests promptly and maintain suppression across the platform; (c) retain consent and opt-out records for a minimum of four (4) years; and (d) not use Communications Data for marketing, and not share, sell, or transfer mobile opt-in data to third parties or affiliates for marketing or promotional purposes. Customer is responsible for the lawfulness of its instructions, including any additional consent requirements arising from Customer's own relationship with Candidates.

9. Biometric Data

Where the same-person verification feature is enabled, the Services Process biometric data (such as facial geometry or voice characteristics) in real time, solely to verify that the same individual participates across a Candidate's interviews for an application, and only after the Candidate's prior consent is captured as a distinct step. No biometric template is retained beyond the verification session; biometric data is never matched against external databases, never sold, and never used to train AI models. Customer is responsible for any additional biometric notice or consent obligations that apply to it as an employer under laws such as the Illinois Biometric Information Privacy Act.

10. Sub-processors

Customer provides general authorization for Hello Recruiter to engage Sub-processors. Hello Recruiter's current list of Sub-processors, including each Sub-processor's function and location, is published at hellorecruiter.ai/legal/subprocessors and is incorporated into this DPA as Annex III. Hello Recruiter will update the list at least thirty (30) days before authorizing a new Sub-processor to Process Personal Data and provides a mechanism on that page to receive notice of changes. Customer may object to a new Sub-processor on reasonable data-protection grounds within thirty (30) days of notice; the parties will work in good faith to resolve the objection, and if it cannot be resolved, Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees. Hello Recruiter imposes data protection obligations on Sub-processors no less protective than this DPA and remains liable for their performance.

11. International Transfers

Hello Recruiter Processes Personal Data primarily in the United States. Where Data Protection Laws of the European Economic Area, United Kingdom, or Switzerland apply to a transfer of Personal Data to Hello Recruiter, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), are incorporated by reference, with Customer as data exporter and Hello Recruiter as data importer, completed by the Annexes to this DPA; for UK transfers, the UK International Data Transfer Addendum applies; for Swiss transfers, the Clauses apply as adapted for Swiss law. In the event of conflict between the Clauses and this DPA, the Clauses control.

12. Return and Deletion

Upon termination or expiration of the Agreement, Hello Recruiter will make Customer's Personal Data available for export for thirty (30) days, after which it will delete Personal Data within a commercially reasonable period consistent with the retention schedule in the Privacy Policy, except where retention is required by applicable law, in which case the data remains protected under this DPA and is deleted when the requirement ends. Deletion from backups occurs in the ordinary course of backup rotation.

13. Liability; Order of Precedence; General

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Agreement. In the event of conflict: (a) the Standard Contractual Clauses control over this DPA for the transfers they govern; (b) this DPA controls over the Agreement with respect to the Processing of Personal Data; and (c) a written order form or addendum executed by both parties controls over this DPA for that Customer. This DPA is governed by the law governing the Agreement. Hello Recruiter may update this DPA for future versions of the Services or changes in law by publishing an updated version at hellorecruiter.ai/legal/dpa with notice to Customer as provided in the Agreement; updates apply prospectively from their effective date.

Annex I — Processing Details

As set out in Section 3 of this DPA. Competent supervisory authority (where GDPR applies): the authority of the EU member state of the data exporter.

Annex II — Technical and Organizational Measures

• Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256)

• Role-based access control, least privilege, MFA for personnel access to production systems

• Logical tenant separation; segregated environments for development, staging, and production

• Security logging and monitoring; audit trails for consent, communications, and review events

• Vulnerability management, security testing, and secure development lifecycle practices

• Personnel confidentiality obligations, background screening where permitted, and security training

• Vendor risk management for Sub-processors; contractual flow-down of security obligations

• Business continuity and backup procedures; documented incident response plan

• Information security program aligned with the SOC 2 Trust Services Criteria, with continuous control monitoring (SOC 2 Type II attestation in progress)

Annex III — Sub-processors

The current Sub-processor list, including function and location for each Sub-processor (cloud hosting, AI infrastructure, real-time communications, telephony and messaging, transactional email, monitoring, support, payments, and analytics), is maintained at hellorecruiter.ai/legal/subprocessors and is incorporated into this DPA. The page provides a subscription mechanism for change notices.

Version 1.0 · Effective September 10, 2026