For customers

Data Processing Agreement

Our standard DPA under GDPR Art. 28 and UK GDPR, including transfer mechanisms and technical and organisational measures.

Last updated 23 September 2026
On this page
  1. Definitions
  2. Roles of the parties
  3. Details of processing
  4. Hireall's obligations as Processor
  5. Customer's obligations as Controller
  6. Sub-processors
  7. Data Subject requests
  8. Personal Data Breach
  9. Impact assessments and prior consultation
  10. International transfers
  11. Audits
  12. Return and deletion
  13. Jurisdiction-specific terms
  14. Liability, term and changes
  15. Annex I: Details of processing
  16. Annex II: Technical and organisational measures
  17. Annex III: Sub-processors

This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Hireall Technology ("Hireall") and the customer organisation identified in the Agreement ("Customer"). It sets out the terms on which Hireall processes personal data on Customer's behalf when providing the Hireall applicant tracking platform (the "Service").

How this DPA applies. It is incorporated into the Agreement automatically when Customer accepts the Terms of Service or signs an Order Form; no separate signature is needed. Customers who require a countersigned copy for their records can request one from legal@hireall.com. Accepting this DPA does not by itself conclude any transfer instrument that a particular data flow requires (for example the KVKK Standard Contract). Those instruments are executed separately when the transferring party requires them, as described in the section on international transfers. In case of conflict with the Agreement, this DPA prevails on matters of personal data processing; in case of conflict between this DPA and the SCCs, the UK Addendum, the UK IDTA or the KVKK Standard Contract, those instruments prevail for the transfer they govern.

01Definitions

  • "Data Protection Laws" — all laws applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and the Data Protection Act 2018, the Turkish Personal Data Protection Law No. 6698 ("KVKK") and its secondary legislation, and, to the extent applicable, the California Consumer Privacy Act as amended ("CCPA").
  • "Customer Personal Data" — Personal Data that Customer or its Users submit to the Service, or that the Service collects on Customer's behalf, as described in Annex I.
  • "Personal Data", "Controller", "Processor", "Data Subject", "Processing", "Personal Data Breach" and "Supervisory Authority" — have the meanings given in the GDPR; equivalent terms in other Data Protection Laws (such as "veri sorumlusu", "veri işleyen", "business" and "service provider") are read accordingly.
  • "Sub-processor" — a third party engaged by Hireall to process Customer Personal Data.
  • "Standard Contractual Clauses" or "SCCs" — the clauses approved by European Commission Decision 2021/914 (Module Two, controller to processor, or Module Three, processor to processor, as applicable); "UK Addendum" — the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018; "UK IDTA" — the UK International Data Transfer Agreement issued by the Information Commissioner under the same section; "KVKK Standard Contract" — the standard contract for transfers abroad adopted by the Turkish Personal Data Protection Board under KVKK Article 9.
  • Capitalised terms not defined here have the meaning given in the Agreement.

02Roles of the parties

Customer is the Controller of Customer Personal Data and Hireall is its Processor. Where Customer itself acts as a processor for another organisation (for example a recruitment agency hiring on behalf of a client), Customer warrants that it has the authority to instruct Hireall on that controller's behalf, and Hireall acts as a sub-processor.

Where Customer obtains the Service under a contract with Hireall's affiliate STJ İnsan Kaynakları Bilişim ve Danışmanlık A.Ş. ("STJ") rather than directly from Hireall, Customer is the Controller. STJ is Customer's Processor only to the extent Customer's contract with STJ appoints STJ as processor and authorises a sub-processor outside Türkiye. Hireall then processes Customer Personal Data as STJ's sub-processor on the terms of this DPA, which STJ flows down to Hireall in its written agreement. Customer's instructions reach Hireall through STJ or through Customer's own use of the Service; use of the Service and STJ issuing an invoice do not, without that appointment, establish the processor role. The KVKK Standard Contract between STJ and Hireall, where concluded in that processor-to-sub-processor capacity, covers the transfer of Customer Personal Data from STJ to Hireall as described in the section on international transfers.

Hireall is an independent Controller only of the account, authentication, billing, security and communications data about Customer's Users that it processes for its own purposes, as described in the Privacy Policy; that processing is outside the scope of this DPA. Everything Users create or the Service records on Customer's behalf, including interview notes, scorecards, internal comments, offers, automation rules, workflow actions and the audit-log entries of Users' activity within Customer's account, is Customer Personal Data within the scope of this DPA even where it identifies a User, as set out in Annex I. Where one record serves both purposes (for example a sign-in event that is also an audit-log entry Customer can review), Hireall processes it as Processor for Customer's use of the Service and as Controller only for its own security and account-administration purposes.

03Details of processing

The subject matter, duration, nature and purpose of processing, the types of Personal Data and the categories of Data Subjects are set out in Annex I. Hireall processes Customer Personal Data for the sole purpose of providing the Service to Customer and as otherwise instructed under this DPA.

04Hireall's obligations as Processor

Hireall will:

  • Instructions. Process Customer Personal Data only on Customer's documented instructions, including with regard to transfers to a third country, unless required to do so by law, in which case Hireall informs Customer of that requirement before processing unless the law prohibits it. The Agreement, this DPA and Customer's use of the Service's features and settings constitute Customer's complete instructions. For video interview invitations sent from the Service's send screen, those instructions include the list of Candidates the User confirms on that screen, and invitations are sent only to the Candidates on that list. Hireall will inform Customer immediately if, in its opinion, an instruction infringes Data Protection Laws.
  • Confidentiality. Ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and limit access to those who need it to perform the Service.
  • Security. Implement and maintain the technical and organisational measures described in Annex II, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, so as to ensure a level of security appropriate to the risk (GDPR Article 32). Hireall may update these measures provided the overall level of protection is not reduced.
  • Sub-processors. Engage Sub-processors only in accordance with the section on Sub-processors below.
  • Assistance. Assist Customer, taking into account the nature of the processing, in fulfilling its obligations to respond to Data Subject requests and in complying with Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), as described in the sections below.
  • Deletion and return. At the end of the provision of the Service, delete or return Customer Personal Data as described in the section on return and deletion.
  • Demonstrating compliance. Make available to Customer all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits as described in the section on audits.
  • Records. Maintain a record of processing activities carried out on behalf of Customer as required by Article 30(2) GDPR.

05Customer's obligations as Controller

  • Customer is responsible for the lawfulness of its processing, including having a lawful basis for collecting Candidate data, providing privacy notices to Candidates and Users, obtaining consent where required (for example for talent-pool retention or for video recording in certain jurisdictions), and responding to Data Subject requests.
  • Customer will not instruct Hireall to process Customer Personal Data in a way that infringes Data Protection Laws, and will not submit special-category data except in fields the Service provides for that purpose and where Customer has a lawful basis.
  • Customer is responsible for configuring the Service appropriately, including User roles and permissions, sensitive-field settings, the video-interview retention period that comes with its Subscription plan, integrations and exports, and for the security of its Users' credentials.
  • Customer will keep a current privacy contact in its account settings (Settings → Compliance → "Legal notices from Hireall") to receive breach notifications and Sub-processor notices. If none is set, Hireall uses the compliance contact and, failing that, the Account e-mail address.

06Sub-processors

  • General authorisation. Customer gives Hireall general written authorisation to engage the Sub-processors listed at hireall.com/legal/sub-processors (Annex III).
  • Youthall. Customer specifically authorises Hireall to engage its affiliate Youthall (STJ İnsan Kaynakları Bilişim ve Danışmanlık A.Ş., Istanbul, Türkiye) as a Sub-processor to (i) receive applications that Candidates choose to make with a Youthall profile, (ii) publish Customer's jobs to the Youthall talent network and receive and exchange the resulting applications where Customer enables that channel, and (iii) support joint customer support and fraud prevention. Youthall is bound to Hireall by a written data-processing agreement and the transfer safeguards in the section on international transfers. Where a Candidate also holds a Youthall account, Youthall processes that account as a separate controller under its own terms, which the Candidate accepts directly with Youthall.
  • Notice of changes. Hireall gives Customer at least 30 days' notice before a new Sub-processor processes Customer Personal Data, by updating the published list and e-mailing the privacy contact designated in Customer's account settings (or, if none, the compliance contact or the Account e-mail address). Each notice states the provider, its purpose and location, the transfer mechanism where the provider processes data outside the EEA and the UK, and the effective date; Hireall keeps a record of every notice sent.
  • Urgent replacement. If a Sub-processor must be replaced urgently to protect the security or continuity of the Service, Hireall will, wherever possible, move the affected processing to a Sub-processor already on the published list for that purpose, so that no new Sub-processor is engaged. Where that is not possible, Hireall asks Customer for specific authorisation before the new Sub-processor first processes Customer Personal Data, giving the information required for an ordinary notice and the reason the ordinary notice period cannot be kept; Customer may grant the authorisation on shortened notice or object, and the right to object below applies in full. Hireall does not rely on a general exception permitting notice only after the fact.
  • Right to object. Customer may object on reasonable, documented data-protection grounds within the notice period. The parties will discuss the objection in good faith. If Hireall cannot reasonably accommodate the objection, for example by offering an alternative configuration, Customer may terminate the affected part of the Service on written notice before the change takes effect; prepaid Fees attributable to the terminated part for the period after termination are refunded under section 7.6(d) of the Terms of Service and no further recurring Fees accrue for it. Termination and that refund are Customer's sole contractual remedy for a Sub-processor change that Hireall makes in accordance with this section; they do not limit Customer's rights or remedies for a breach of this DPA or of Data Protection Laws, including a change made without the notice this section requires.
  • Flow-down and liability. Hireall imposes on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and remains fully liable to Customer for the performance of its Sub-processors' obligations.
  • Customer-enabled integrations. Third-party services that Customer chooses to connect to the Service using its own account or credentials (job boards, calendar and meeting providers, messaging and assessment tools) receive Customer Personal Data on Customer's instruction and for Customer's purposes; they are Customer's processors or independent controllers, not Sub-processors of Hireall. Whether a provider is a Sub-processor depends on whether it processes Customer Personal Data on Hireall's behalf to deliver the Service, not on whether it appears on the published list: Hireall keeps the list complete and current, and an omission does not change the provider's role or Hireall's responsibility for it under this DPA.

07Data Subject requests

Hireall will, taking into account the nature of the processing, assist Customer through appropriate technical and organisational measures in responding to requests from Data Subjects to exercise their rights (access, rectification, erasure, restriction, portability, objection and rights relating to automated decision-making). The Service provides self-service tools for search, export and correction of Candidate records, and sourced Candidates can object through a personal privacy page that anonymises their record automatically. Deletion or anonymisation of an individual Candidate record or a whole job is carried out by Hireall on Customer's written instruction promptly, normally within five business days and in any event within 30 days of the instruction, with confirmation to Customer. These periods never extend Customer's own statutory deadline towards the Data Subject: where applicable law, that remaining deadline or another provision of this DPA requires a shorter period, the shorter period applies, and Hireall acts within the time left if the instruction is received late. A deletion instructed during the term is carried out on this timeline and is never postponed to the end of Customer's subscription; the retrieval period in the section on return and deletion does not apply to it, and backup copies are handled as described in that section.

If Hireall receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond substantively but will forward the request to Customer without undue delay, normally within two business days, together with the information Customer needs to decide, and inform the Data Subject that it has done so, unless the law requires otherwise. Customer's statutory deadline runs from the Data Subject's request, not from Hireall's forwarding. Assistance beyond the Service's built-in tools is provided at Customer's reasonable request; Hireall may charge reasonable costs for assistance that is excessive or repetitive.

08Personal Data Breach

Hireall will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach and a contact point. Information may be provided in phases as it becomes available. Hireall will cooperate with Customer and take reasonable steps to contain and remediate the breach. Notification is not an acknowledgement of fault or liability.

Customer is responsible for notifying Supervisory Authorities and Data Subjects where required; Hireall will provide the information reasonably needed for those notifications.

09Impact assessments and prior consultation

Where Customer is required to carry out a data protection impact assessment or to consult a Supervisory Authority in connection with its use of the Service, Hireall will provide reasonable assistance by making available the information in this DPA, the Sub-processor list, the security page, the AI Transparency Notice and, on request, further documentation of the Service's features and security measures.

10International transfers

Customer Personal Data is stored and primarily processed in the European Union (Amazon Web Services, Frankfurt region, eu-central-1). Storage location is not the whole picture. AI model providers process requests in the United States or the European Union; other Sub-processors process data in the United States or the European Union as stated for each on the Sub-processor page; and Hireall's affiliate Youthall processes data in Türkiye. Each remote access and each onward disclosure is a separate transfer, assessed by its actual parties and direction and covered by the safeguards in this section, not by the hosting location.

  • Customer to Hireall. Transfers between the EU and the UK rely on the respective adequacy decisions. Where Customer is established in Türkiye, its disclosure of Customer Personal Data to Hireall is a transfer abroad under KVKK Article 9 and is governed by the KVKK paragraph below.
  • Hireall to Sub-processors outside the EEA and the UK. Where a Sub-processor processes Customer Personal Data in a country without an EU or UK adequacy decision, Hireall concludes the SCCs (Module Three, processor to processor, with Hireall as data exporter) together with the UK Addendum for data subject to the UK GDPR, or relies on the recipient's certification under the EU-U.S. Data Privacy Framework and its UK Extension, in each case with a transfer risk assessment and supplementary measures where that assessment requires them. The instrument in place for each Sub-processor is stated on the Sub-processor page and is concluded before the Sub-processor first processes Customer Personal Data.
  • Hireall to Youthall (Türkiye). Transfers from Hireall to Youthall rely on the EU SCCs (Module Three) and the UK transfer instrument recorded in the executed Hireall–Youthall intra-group data transfer agreement (the UK IDTA or the UK Addendum, as that agreement records), together with a transfer risk assessment and supplementary measures. The published description follows the executed instrument; a copy identifying which UK instrument is in force is available on request from legal@hireall.com. The annexes to those instruments reflect the processing described in Annexes I to III of this DPA. Remote access by personnel located in Türkiye is covered by the same instruments. Those instruments govern the Hireall-to-Youthall direction. They do not themselves authorise a transfer from Türkiye to Hireall.
  • Youthall or STJ to Hireall. A disclosure of personal data from STJ or Youthall in Türkiye to Hireall is a separate transfer abroad under KVKK Article 9. It is assessed by the capacity in which STJ makes that disclosure, not by the existence of the Hireall-to-Youthall instruments above. Where a Customer established in Türkiye and Youthall exchange data within Türkiye through a channel Customer enables (for example publishing a job to Youthall and receiving the resulting applications), that exchange takes place between them in Türkiye; the onward flow of the same data to Hireall remains a KVKK Article 9 transfer. Where STJ makes that onward flow as Customer's processor under the appointment described in the section on roles, the KVKK Standard Contract between STJ and Hireall in the processor-to-sub-processor form, notified by STJ, is the mechanism for that Customer Personal Data. Where STJ or Youthall discloses data as an independent controller — including account and sign-in data of organisations or individuals held in STJ's own user database and passed to Hireall when they sign up to Hireall through Youthall — that disclosure is not treated as covered by a standard contract concluded only in STJ's capacity as Customer's processor. A KVKK Standard Contract in the controller-to-processor form between STJ and Hireall, notified by STJ as transferring controller, is required for that flow if no other Article 9 mechanism applies.
  • KVKK. Where Customer is subject to KVKK and contracts directly with Hireall, Customer's transfer of Customer Personal Data to Hireall relies on KVKK Article 9 as amended in 2024: an adequacy decision of the Personal Data Protection Board where one applies to the recipient country, and otherwise the KVKK Standard Contract (data controller to data processor) between Customer and Hireall if Customer chooses to conclude it. The transferring party in Türkiye starts that process and notifies the Board within five business days of signature. Hireall does not initiate the contract, does not chase Customer for it and does not notify the Board. If Customer asks, Hireall executes the contract and provides the signed copy and the information the notification requires. Where Customer obtains the Service from Hireall's affiliate STJ under a contract with STJ that appoints STJ as processor and authorises a sub-processor outside Türkiye, STJ concludes the KVKK Standard Contract with Hireall in that processor-to-sub-processor capacity and notifies the Board; that filing covers Hireall's processing of that Customer Personal Data. STJ invoicing the Customer, or the Customer's tenant sitting on Hireall's infrastructure, does not by itself make STJ the processor or support that single filing. The exceptional grounds in KVKK Article 9(6), including explicit consent, are not relied on for the continuous processing under this DPA and may be used only for an occasional, non-repetitive transfer that the transferring party specifically documents.
  • Relationship with this DPA. Accepting this DPA does not by itself execute any of the instruments above. Where the SCCs, the UK Addendum, the UK IDTA or the KVKK Standard Contract govern a transfer, their terms prevail over this DPA and the Agreement in case of conflict, and the liability, governing-law and jurisdiction provisions of the Agreement do not limit the rights of Data Subjects or the mandatory terms of those instruments. Customer may request a copy of the instruments Hireall has concluded with its Sub-processors, with commercial terms redacted.
  • Changes. If a transfer mechanism relied on is invalidated or amended, the parties will cooperate in good faith to implement an alternative mechanism without undue delay; until then Hireall suspends the affected transfer where Data Protection Laws so require.

11Audits

  • Hireall makes available, on request and subject to confidentiality, the information necessary to demonstrate compliance with this DPA: this DPA, the security page, the Sub-processor list, completed security questionnaires and, where available, summaries of third-party assessments or penetration tests.
  • Where this information is not sufficient to meet a requirement under Data Protection Laws, Customer, or an independent auditor appointed by Customer and bound by confidentiality, may audit Hireall's compliance no more than once in any 12-month period, on at least 30 days' written notice, during business hours, in a manner that does not unreasonably disrupt Hireall's operations and does not give access to other customers' data. Additional audits are permitted where required by a Supervisory Authority or following a Personal Data Breach.
  • Each party bears its own costs of an audit. Customer will share audit findings with Hireall and treat them as Confidential Information.

12Return and deletion

  • During the term. Customer can export Customer Personal Data at any time using the Service's export tools (including spreadsheet exports and, where available, the API) and can correct Candidate records itself. The Service has no self-service deletion for Candidate records: deletion or anonymisation of an individual Candidate record or a whole job is carried out by Hireall on Customer's written instruction on the timeline in the section on Data Subject requests (normally five business days, at the latest 30 days, and always within any shorter period Data Protection Laws or the Data Subject's request requires) and is never postponed to the end of the subscription or to any retrieval period. Records Users delete themselves (notes, evaluations, saved filters and similar) are hidden immediately and permanently deleted by the scheduled job described in Annex II.
  • Customer's choice at the end of the Service. When the Service ends, Customer chooses whether Customer Personal Data is returned before deletion or deleted without return. Return is made by Customer's own export or, on request, by a reasonable machine-readable export provided by Hireall. Customer may give its instruction at any time by written notice to legal@hireall.com or through an Account administrator; absent an instruction, the retrieval period below runs and deletion follows.
  • Retrieval period. For 30 days after the end of the Service, Customer can continue to sign in to export its data. If Customer instructs deletion earlier, Hireall does not wait for the retrieval period to expire and deletes on the timeline for instructed deletions (normally five business days, at the latest 30 days from the instruction).
  • Deletion from active systems. After the retrieval period Hireall deletes or anonymises Customer Personal Data from active systems normally within 30 days and in any event no later than 60 days after the retrieval period ends, except to the extent that retention of a specific record is required by law, in which case Hireall protects that record from further processing and does not extend the retention of any other Customer Personal Data on that ground. Any shorter period required by Data Protection Laws, by another provision of this DPA or by a content-specific rule, such as video retention, takes precedence.
  • Backups. Encrypted backup copies are isolated from ordinary processing, are not used for it, and are overwritten or deleted in the ordinary course of Hireall's backup rotation, no later than 90 days after deletion from active systems. If a backup is restored for disaster recovery in the meantime, the deletion instruction is applied again before the data is returned to ordinary processing. Taken together, in an ordinary end of subscription the retrieval period, the deletion window and the backup rotation mean that no copy of Customer Personal Data remains later than 180 days after the Service ends; this is the outer limit for residual backup copies, not a period of continued use or access.
  • Video interview recordings are deleted 60, 90 or 365 days after recording according to Customer's subscription, or earlier at Customer's request.
  • Confirmation. Hireall confirms completion of an instructed deletion, and of deletion at the end of the Service, in writing on request.

13Jurisdiction-specific terms

United Kingdom

Where the UK GDPR applies, references to the GDPR are read as references to the UK GDPR and the Data Protection Act 2018, references to the EU or Member States as references to the UK, and references to the Supervisory Authority as references to the Information Commissioner.

Türkiye (KVKK)

Where KVKK applies, Customer is the veri sorumlusu (data controller) and Hireall the veri işleyen (data processor). Hireall processes Customer Personal Data only within the scope of Customer's instructions under KVKK Article 12(2), takes the technical and administrative measures required to prevent unlawful processing and access and to ensure preservation of the data, and keeps the data confidential without time limit. Customer is responsible for information notices under KVKK Article 10, for obtaining explicit consent where required, for registration with VERBİS where applicable and for notifying the Personal Data Protection Board of data breaches within 72 hours; Hireall notifies Customer without undue delay so that this deadline can be met.

California (CCPA)

Where the CCPA applies, Hireall acts as a "service provider" to Customer and this DPA is the written contract required by the CCPA and its regulations (California Code of Regulations, title 11, section 7051). Customer discloses Customer Personal Data to Hireall only for the limited and specified business purpose of providing the Service described in Annex I. Hireall will: (a) not sell or share Customer Personal Data; (b) not retain, use or disclose it for any purpose, including any commercial purpose, other than that business purpose or as otherwise permitted by the CCPA and its regulations; (c) not retain, use or disclose it outside the direct business relationship between Hireall and Customer; (d) not combine it with personal information received from another person or collected from Hireall's own interactions with consumers, except as the regulations permit; (e) comply with the CCPA and provide the same level of privacy protection as the CCPA requires of businesses, including cooperating with Customer in responding to consumer requests and implementing reasonable security procedures and practices; (f) enable Customer to comply with consumer requests, and act on Customer's instruction to delete, correct or provide Customer Personal Data in response to a verified request; (g) notify Customer no later than five business days after determining that it can no longer meet its obligations under the CCPA; and (h) engage a Sub-processor only under a written contract imposing the same obligations and notify Customer of that engagement as described in the section on Sub-processors. Customer has the right to take reasonable and appropriate steps to ensure that Hireall uses Customer Personal Data in a manner consistent with Customer's obligations under the CCPA, including through the information and audit rights in the section on audits, and, on notice, to stop and remediate any unauthorised use. Hireall certifies that it understands and will comply with these restrictions.

14Liability, term and changes

  • Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Agreement, including the higher combined limit that the Terms of Service apply to claims for breach of this DPA, except to the extent that Data Protection Laws do not permit liability to be limited. Nothing in this DPA limits the rights of Data Subjects or Supervisory Authorities.
  • This DPA takes effect when the Agreement takes effect and remains in force for as long as Hireall processes Customer Personal Data, including during the return-and-deletion period.
  • Hireall may update this DPA to reflect changes in Data Protection Laws or in the Service. Material changes are notified in the same way as changes to the Terms of Service; changes that reduce the protection of Customer Personal Data require Customer's agreement.
  • This DPA is governed by the law and jurisdiction clause of the Agreement, unless Data Protection Laws require otherwise. Where the SCCs, the UK Addendum, the UK IDTA or the KVKK Standard Contract govern a transfer, their own governing-law, jurisdiction, third-party-beneficiary and liability terms apply to that transfer and are not limited by this section or by the Agreement.

15Annex I: Details of processing

ItemDescription
Subject matterProvision of the Hireall applicant tracking platform and related support to Customer
DurationThe term of the Agreement plus the return-and-deletion period
Nature and purposeHosting, storing, organising, searching, scoring, communicating about and reporting on recruitment data as instructed by Customer through its use of the Service: publishing jobs, receiving and screening applications, scheduling and recording interviews, evaluating Candidates, issuing offers and pre-employment documents, managing talent pools and referrals, and running automations Customer configures
Categories of Data SubjectsCandidates (applicants, sourced and imported candidates, talent-pool members, referred candidates); Customer's Users and employees who take part in hiring; Customer's own employees whom Customer records as internal talent and considers for its own roles; referrers; contacts named by Candidates, such as references
Categories of Personal DataIdentity and contact details; CV and application content (education, work history, skills, cover letters, portfolios); answers to screening questions; assessment results; interview schedules, notes, scorecards and video-interview recordings; AI-generated match scores and structured summaries of application material; offer letters and their acceptance records; document-verification records as described in the next row; communications sent through the Service; for employees Customer records as internal talent, the employment details Customer enters (job title, department, manager's name, work location, employee number, start date, whether the employee is open to a move, the lawful basis Customer records for the assessment and Customer's own notes) together with the readiness figures and development summaries generated from them; technical data such as IP address and timestamps; audit-log entries recording Users' actions within Customer's account
Document verificationCustomer can ask a Candidate to present a document (for example a diploma, an employment record, a reference, a criminal-record certificate or a fitness-for-work certificate). The Service stores the request, its type, the legal basis and statutory reference Customer records, the Candidate's acknowledgement of the disclosure shown, a verification reference where the Candidate supplies one (such as a certificate barcode number), and the outcome recorded by the authorised User (satisfied, not satisfied or waived) with a short note. Where Customer asks for a document, the Candidate uploads it through the Candidate's own verification link and the file is held in private storage, released only to an authorised User of that Customer, with every access written to the audit log; alternatively the Candidate presents the document to Customer outside the Service and supplies only a reference. An uploaded file is checked for signs of tampering or inconsistency by fixed rules and, unless Customer has switched the feature off, by a large-language model, which returns a risk flag and a short note; the flag moves no Candidate and decides nothing. A file for a criminal-record or fitness-for-work check is stored, and submitted to that check, only where the Candidate has given the separate explicit consent described in Annex II, and the free-text note of the automatic check is not retained for those types. Each uploaded file is erased on the purge date of its item (180 days by default, 365 at the most) and immediately if the request is cancelled or Customer deletes it. Each record carries a mandatory purge date set when it is created; when that date passes a daily scheduled job erases the outcome, the verification reference, the notes and the Candidate's acknowledgement, leaving only the fact that a check of that type was requested, on which legal basis, by whom and when, for accountability
Special categories of dataNot required by the Service. Customer may enable specific optional fields (for example disability or diversity monitoring) where it has a lawful basis. The outcome of a fitness-for-work verification is health-related data: the Service stores the outcome and the basis Customer records, together with the certificate itself where the Candidate has given the separate explicit consent the Service asks for,, applies to it the additional access and retention controls in Annex II, and Customer is responsible for the lawful basis under GDPR Article 9 or KVKK Article 6
Criminal-conviction dataThe outcome of a criminal-record verification is data relating to criminal convictions and offences under GDPR Article 10 and KVKK Article 6. The Service stores the outcome, the statutory basis Customer records for the request and the purge date. The certificate itself is stored only where the Candidate has given the separate explicit consent the Service asks for; that consent may not be made a condition of applying or of completing the check, the Service does not allow Customer to require a file for this type, and the certificate is erased on the purge date, when the request is cancelled or when Customer deletes it. Customer may request such a verification only where the law of the relevant jurisdiction authorises it for the role and is responsible for that authorisation
FrequencyContinuous, for the duration of the Agreement
RetentionDetermined by Customer through its use of the Service and its instructions; video recordings 60, 90 or 365 days according to subscription; document-verification records until their purge date; see the sections on Data Subject requests and on return and deletion

16Annex II: Technical and organisational measures

  • Encryption — TLS 1.2 or higher for data in transit; encryption at rest for databases, file storage and backups.
  • Tenant isolation — every Customer record is linked to Customer's tenant, and the application layer restricts each User to the records of the tenant they belong to through tenant-scoped repository queries and per-request ownership checks in the code paths that serve Customer data. Hireall does not represent that a single mechanism filters every database query; the control is the access outcome, verified through code review against a written tenant-isolation standard and through tests, and any deviation found is treated as a security defect and fixed with priority.
  • Access control — role-based permissions for Users (administrators, recruiters, hiring managers, interviewers); optional two-step verification for User sign-in, by one-time e-mail code or by a time-based one-time password from the User's authenticator application (TOTP, RFC 6238) with single-use recovery codes; where a User signs in through the Customer's own identity provider and that provider states in its token that it has already verified a second factor, Hireall accepts that statement instead of requiring a further step, and records the acceptance in the audit log; least-privilege, individually accountable access to production systems for Hireall personnel, revoked promptly when a role ends.
  • Audit logging — hiring and administrative events (stage moves, exports, permission changes, AI actions, deletions) are recorded with actor and timestamp and available to Customer administrators.
  • Data minimisation, deletion and retention — configurable sensitive fields; blind-hiring mode that masks name, photo and gender during evaluation; records deleted by Users are hidden immediately and permanently removed from active systems by a scheduled job that runs daily and completes no later than 30 days after deletion, with each run and any failure logged and monitored and a failed run treated as an incident to be resolved rather than only reported; automatic deletion of video recordings according to subscription and of document-verification records at their purge date; anonymisation on objection by sourced Candidates; document-verification outcomes are visible only to Users whose role allows them to manage offers and verifications and are not included in the data sent to AI features.
  • AI features — AI outputs are advisory and are shown with the explanation the model returned; an automation rule that uses an AI score does not move a Candidate to a rejected or offer stage or create an offer without a User's confirmation for that Candidate; an automation rule conditioned on gender, nationality, military-service or smoking status does not move a Candidate, send a message or create an offer without such a confirmation; Customer may set rules that use an AI score to present every step to a User for confirmation, or to run only after an approval recorded for the Account (approver, time and rule version) that lapses if the rule is changed; AI actions, automatic moves, suggestions and User decisions are recorded in the audit log; the structured name, gender, date-of-birth and nationality fields are not sent to model providers; Customer Personal Data is not used to train or fine-tune any model, as section 10.5 of the Terms of Service provides, and model providers are contractually prohibited from training on it.
  • Availability and resilience — hosting in Amazon Web Services (Frankfurt) with encrypted, regularly tested backups; monitoring and alerting; incident-response procedures.
  • Secure development and logging — code review, dependency monitoring, separation of environments, a logging standard under which application logs carry record identifiers rather than names, e-mail addresses or identity numbers, enforced through code review; security and access logs kept for 12 months with restricted access; and a vulnerability reporting channel at security@hireall.com.
  • Personnel — confidentiality undertakings and data-protection and security training for all personnel with access to Customer Personal Data.
  • Sub-processor management — written contracts with data-protection terms, transfer mechanisms and periodic review of the Sub-processor list.

Hireall does not currently hold ISO 27001 or SOC 2 certification and does not represent otherwise.

17Annex III: Sub-processors

The current list of Sub-processors, with purpose and location, is published at hireall.com/legal/sub-processors and forms part of this DPA.