Your next great hire is waiting.
Let AI find them.
Join engineering teams who replaced week-long hiring cycles with hours. No credit card required.
Join engineering teams who replaced week-long hiring cycles with hours. No credit card required.
Effective 31 August 2026. Version 1.0. This DPA is incorporated into, and forms part of, the Terms of Service. It applies automatically to every customer who processes personal data through AIHire. No signature is required, though we will sign a countersigned copy on request to privacy@aihire.io.
For Candidate Data the Customer is the controller and AIHire is the processor. AIHire processes Candidate Data only on the Customer's documented instructions, which consist of these terms, the Terms of Service, and the Customer's use of the product's configuration. Where AIHire is a controller in its own right, see the Privacy Policy, section 1.
The Customer grants general authorisation for AIHire to engage sub-processors. Each is bound by written terms imposing data protection obligations no less protective than this DPA, and AIHire remains fully liable to the Customer for their performance. The current list is:
| Sub-processor | Purpose | Data reached | Region |
|---|---|---|---|
| Supabase | Managed Postgres, authentication, realtime | All structured data | US / EU |
| Amazon Web Services (S3) | Object storage | Recordings, CVs, uploaded media | US / EU |
| Vercel | Application hosting and edge delivery | Data in transit, request logs | Global edge |
| Google (Gemini API) | AI conversation, transcription, translation, grading, generation | Session audio and video frames, transcripts, answers, prompts | US |
| Resend | Transactional email | Name, email, message content | US / EU |
Changes. We will give at least thirty days' notice before adding or replacing a sub-processor, by email to the account owner and by updating this page. A Customer with a reasonable data protection objection may raise it within that period; if we cannot resolve it, the Customer may terminate the affected service and receive a pro-rata refund of prepaid, unused fees for it. To receive notices, email privacy@aihire.io and ask to be added to the sub-processor notification list.
Model training. Our AI sub-processor is engaged under API terms that prohibit the use of Customer content to train or improve their generally available models.
Taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing, AIHire implements measures including:
Measures may be updated as the service evolves, provided the level of security is not reduced.
AIHire will notify the Customer without undue delay, and in any event within seventy-two hours of becoming aware of a personal data breach affecting Candidate Data, with the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and the measures taken or proposed. The Customer, as controller, is responsible for notifying its supervisory authority and its data subjects. Notification is not an admission of fault or liability.
On written request, no more than once in any twelve-month period unless a supervisory authority requires otherwise or a breach has occurred, AIHire will provide the information reasonably necessary to demonstrate compliance with this DPA, including our security documentation and any third-party attestation we hold. Where that is insufficient for a specific, documented concern, the Customer may conduct an audit at its own cost, on thirty days' notice, during business hours, subject to confidentiality, without access to other customers' data, and in a manner that does not disrupt the service.
Where Candidate Data originating in the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), which are incorporated into this DPA by reference and which the parties are deemed to have entered into, together with the UK International Data Transfer Addendum where the UK GDPR applies, and the Swiss addendum where Swiss law applies. Where a conflict arises, the Clauses prevail.
AIHire will not respond directly to a data subject request concerning Candidate Data except to confirm receipt and to direct the individual to the Customer, unless legally required to do otherwise or instructed by the Customer. We will notify the Customer without undue delay of any such request, and will provide reasonable assistance in responding to it.
On termination, AIHire deletes Candidate Data in accordance with the Data Retention Policy. Before deletion, the Customer may export its data through the dashboard and the ATS API. AIHire may retain data where required by law, in which case this DPA continues to apply to it. The Customer is responsible for exporting anything it needs. Deletion is permanent and cannot be reversed.
The liability provisions of the Terms of Service, including the exclusions and the cap, apply to this DPA and to any claim arising under it, to the maximum extent permitted by applicable law. Nothing in this DPA limits liability that Article 82 GDPR or other mandatory law does not permit to be limited, nor the rights of a data subject to compensation.
Where this DPA conflicts with the Terms of Service on a matter of personal data processing, this DPA prevails. Where the Standard Contractual Clauses conflict with either, the Clauses prevail.