Data Processing Agreement
Annex 1 to the Hiringly Terms of Service · Effective from: 24 September 2026
1. Parties and Conclusion of the Agreement
This data processing agreement (the “Agreement”) is concluded between the User of the Service as the controller of personal data (the “Controller”) and SearchTeam One s.r.o., Company ID (IČO): 23868945, with its registered office at Pacholíkova 2310/22, Modřany, 143 00 Prague 4, as the processor (the “Processor”), pursuant to Article 28 of Regulation (EU) 2016/679 (“GDPR”).
The Agreement forms an integral part of the Hiringly Terms of Service (the “Terms”) and is concluded together with them, by registering for or using the Service. Capitalised terms have the meaning given in the Terms. In matters of personal data protection, this Agreement prevails over the Terms.
2. Subject Matter, Purpose and Duration of Processing
The Processor processes personal data on behalf of the Controller solely to provide the Service, in particular:
- storing and managing candidate data and CVs;
- analysing CVs and assessing the match with a position using AI;
- publishing the Controller’s job postings and receiving applications, including obtaining and recording the applicants’ consent;
- sending emails to candidates and applicants on the Controller’s behalf (application confirmations, consent requests, interview invitations);
- scheduling interviews and sharing candidates with persons designated by the Controller (e.g. hiring managers);
- technical operation, security and backup of the Service.
Processing lasts for as long as the Controller uses the Service and for the time needed for erasure under clause 11.
3. Data Subjects and Categories of Personal Data
- Data subjects: candidates and applicants for employment or cooperation (including applicants from public job postings), persons with whom the Controller shares candidates (e.g. hiring managers), and other persons named in materials the Controller uploads to the Service (e.g. references).
- Personal data: identification and contact details; CV data (employment history, education, skills, languages, and a photograph where included); salary expectations and availability; evaluations, notes and AI outputs; communication and interview dates; records of consent given and withdrawn.
- Special categories of personal data (Article 9 GDPR) are not deliberately processed by the Service. The Controller does not upload them beyond what an applicant includes in their own CV.
4. The Controller’s Instructions
The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by EU or Member State law; in that case the Processor informs the Controller beforehand unless that law prohibits it. Documented instructions are this Agreement, the Terms, and the settings and actions the Controller performs in the Service.
If the Processor considers that an instruction infringes the GDPR or other data protection law, it informs the Controller immediately.
5. Obligations of the Processor
The Processor:
- ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality;
- takes the technical and organisational measures required by Article 32 GDPR, in particular: encrypted data transmission (HTTPS/TLS), passwords stored only as cryptographic hashes, role-based access control and separation of each User’s data, access links and tokens stored only as hashes, rate limiting against abuse, operation on a server in the EU, and daily encrypted backups with regular restore tests;
- does not use the Controller’s personal data for any purpose other than providing the Service, and in particular does not use it to train AI models; it uses AI services in a mode in which their provider does not use the data for training;
- taking into account the nature of the processing, assists the Controller in responding to data subject requests (Articles 12 to 22 GDPR), in particular through the Service’s functions for exporting, correcting and erasing data and managing consent; it forwards any request it receives directly to the Controller without undue delay;
- assists the Controller in complying with Articles 32 to 36 GDPR (security, breach notification, data protection impact assessment and prior consultation);
- makes available to the Controller the information needed to demonstrate compliance with Article 28 GDPR (clause 9).
6. Sub-processors
The Controller gives the Processor general authorisation to engage sub-processors. The current list is set out in the Privacy Policy (Sub-processors section): a server provider in the EU (operation, database and files), OpenAI (AI analysis, EU endpoint), Resend (email delivery) and Backblaze (storage of backups, which are encrypted before upload). The Stripe payment gateway processes only the User’s billing data, not candidate data.
The Processor informs the Controller by email at least 14 days in advance of any intended addition or replacement of a sub-processor. The Controller may object within that period; if no agreement is reached, the Controller may stop using the Service.
The Processor imposes on sub-processors the same data protection obligations as set out in this Agreement and remains liable to the Controller for their performance.
7. Transfers outside the EEA
Where a sub-processor processes personal data outside the European Economic Area or accesses it from outside the EEA, the Processor ensures that the transfer complies with Chapter V GDPR, in particular on the basis of an adequacy decision (EU–US Data Privacy Framework) or standard contractual clauses.
8. Personal Data Breaches
The Processor notifies the Controller of a personal data breach without undue delay and no later than 48 hours after becoming aware of it, by email to the Controller’s account address. The notification contains the information under Article 33(3) GDPR available to the Processor; further information is provided as it becomes available. Notification of the supervisory authority and data subjects is carried out by the Controller.
9. Information and Audits
On request, the Processor provides the Controller with the information needed to demonstrate compliance with this Agreement. The Controller, or an auditor mandated by it and bound by confidentiality, may carry out an audit, including an inspection, at most once a year (more often after a personal data breach or at the request of a supervisory authority), with at least 30 days’ notice and at its own cost. An audit must not compromise the security or confidentiality of other Users’ data.
10. Obligations of the Controller
The Controller:
- is responsible for the legal basis of processing and for informing data subjects;
- familiarises itself with the consent wording and information that the Service displays and sends to applicants from public job postings on its behalf, and is responsible for ensuring they match its processing;
- is responsible for the accuracy of the billing details (company name and Company ID) that the Service shows applicants as the identification of the controller;
- erases personal data once the retention period ends, in particular applications from public job postings whose consent has expired (the Service flags them), no later than 30 days after the consent expires, as applicants are told.
11. Duration, Erasure and Return of Data
The Agreement lasts for as long as the Service is used. After the provision of the Service ends, the Processor, at the Controller’s choice, erases the personal data or returns it and erases existing copies, unless EU or Member State law requires its storage. The Controller may export the data using the Service’s functions before termination or request that it be handed over. Unless the Controller requests return, the Processor erases the data no later than 30 days after the Service ends.
Erased data may persist in encrypted backups for up to 6 months until removed by regular rotation; backups are used solely to restore the Service.
12. Final Provisions
The parties’ liability for damage caused by an infringement of the GDPR is governed by Article 82 GDPR; otherwise, the liability provisions of the Terms apply between the parties. This Agreement is governed by the laws of the Czech Republic and is amended in the same way as the Terms. The Czech version prevails.
Data protection contact: privacy@hiringly.ai