Legal

Data Processing Agreement

Last updated 2026-08-21

Draft — awaiting legal review

This document is being finalised before launch and has not yet been reviewed by a lawyer. Passages in double brackets are still to be completed. Do not rely on it.

1. The parties and what this covers

This Data Processing Agreement ("DPA") is between:

DIGITSOLUTIONS, a société par actions simplifiée registered with the RCS of Rennes under number 977 519 586, whose registered office is at [[REGISTERED ADDRESS]], trading as HireCall ("HireCall", the Processor); and

the Customer identified in the order form or account ("Customer", the Controller).

It forms part of the HireCall Terms of Service and applies whenever HireCall processes personal data on the Customer's behalf. Where it conflicts with the Terms of Service on the subject of personal data, this DPA prevails.

"Data Protection Law" means Regulation (EU) 2016/679 (GDPR), the French loi n° 78-17 du 6 janvier 1978 as amended, and any other data protection law applicable to the processing — including, where the Customer processes data about candidates in the United States, applicable US federal and state law.

Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in the GDPR.


2. Who is what

The Customer is the controller. It decides which candidates are interviewed, for which roles, against which criteria, and what happens to them afterwards.

HireCall is the processor. It processes candidate personal data only to provide the service, on the Customer's instructions.

HireCall is a controller in its own right for a limited and separate set of data: the Customer's account and billing records, and its own security and service logs. That processing is not governed by this DPA but by HireCall's own privacy notice.

For review. Keep this distinction clean. Blurring it is the most common drafting fault in vendor DPAs, and here it has teeth: HireCall makes public commitments (90-day audio deletion, EU storage, no model training) about data it holds as a processor, which means those commitments must be capable of being given as instructions from the controller — which is what clauses 4, 8 and 12 do. If HireCall were to treat candidate data as its own, the entire public position would change.


3. Processing on documented instructions

HireCall processes candidate personal data only on the Customer's documented instructions, including as to transfers to a third country, unless required to do otherwise by EU or member state law — in which case HireCall will tell the Customer before processing, unless that law prohibits it.

The Customer's instructions are:

  1. this DPA;
  2. the Terms of Service;
  3. the configuration the Customer chooses in the product — including the region, the roles, the criteria, the questions and the retention period; and
  4. any further written instruction the parties agree.

HireCall will tell the Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend the affected processing until it is resolved (Article 28(3), final paragraph, GDPR).

HireCall will not:

  • use candidate personal data for its own purposes;
  • use candidate personal data to train, fine-tune or evaluate any AI model, whether its own or a third party's;
  • sell, rent or share candidate personal data;
  • combine candidate personal data with data from other customers, except to produce genuinely anonymous aggregate statistics from which no individual and no customer can be identified.

4. Instructions specific to this service

Because of what the service does, the following are recorded as standing instructions from the Customer and commitments by HireCall.

4.1 Data residency

Candidate recordings, transcripts and briefs are stored in the European Union, and HireCall will not move them outside it without the Customer's written instruction.

⚠️ Changed at review — do not restore the "EU or US" version. An earlier draft let the Customer "select a region at setup — the EU or the US", mirroring the marketing site. Verified against the product source on 19 August 2026: that capability does not exist. There is no residency field in the data model, the in-product consent copy shown to every candidate hardcodes "stored in the EU", and the object store is not pinned per customer. A DPA is a warranty; this clause now warrants only what is true. The marketing site's "Pick EU or US at setup" claim must be withdrawn or the capability built — and if it is built, the consent copy, the candidate notice and this clause change before the first US-hosted interview.

⚠️ Still verify before signature. Even the EU-only clause is a warranty about the whole pipeline: audio transport, model inference, any speech synthesis or fallback, storage (confirm the object-store region is pinned to an EU location, not left on its "auto" default), backups, disaster recovery, logging, and support access. Support access from outside the EU is a transfer even if the data never moves. If any leg cannot be guaranteed, narrow this clause — "stored in the EU" rather than "stored and processed" — and disclose the exception here rather than leaving a warranty HireCall cannot honour. See README.

4.2 Retention and deletion

Unless the Customer instructs otherwise in writing:

  • HireCall deletes candidate audio recordings 90 days after the interview, automatically, by a scheduled purge job that writes a deletion record distinguishing a scheduled purge from an erasure request;
  • HireCall deletes candidate transcripts and briefs 12 months after the interview.

HireCall also deletes a candidate's data promptly — and in any event within [[ERASURE SLA]] days — where the Customer instructs it, or where the candidate asks HireCall directly and the Customer does not object within [[OBJECTION WINDOW]] days of being told.

The Customer may agree different retention periods in an order form. Where it does, the periods are recorded in Annex I and are shown to candidates in the candidate privacy notice.

Verified, in part. The 90-day automatic purge of audio is implemented and enforced in the product (verified in source, 19 August 2026: a scheduled reconciler erases the audio object and writes a tombstone), and the period is configurable per customer — which is what makes the order-form route above real. The 12-month figure for transcripts and briefs comes from the product's own consent copy; confirm that deletion at 12 months is actually enforced by code, not merely stated.

⚠️ Two problems to settle before this is used.

First, deletion must actually be deletion. Backups, replicas, message queues and provider-side logs are where "deleted" quietly becomes "deleted from the main table". State the position honestly: if backups roll off on a cycle, say what the cycle is and commit that the data is not restored to live use in the meantime. [[BACKUP DELETION POSITION]]

Second, the candidate-initiated route needs the Customer's agreement. A processor acting on a data subject's request without the controller's instruction is itself a breach of Article 28. The mechanism above solves it by making it a standing instruction with an objection window — but the Customer must understand it is agreeing to that, because it may cut against the Customer's own need to retain evidence of a fair process. Some customers will refuse, and that must not be treated as a compliance failure on their part.

Note the public-claim gap: the landing page says only "deleted after ninety days", with no mention of the 12-month transcript and brief period — a material omission — while the pricing page sells "custom retention". The fix is on the landing page: state the defaults and the configurability. See README.

4.3 No scoring, no ranking, no automated decisions

HireCall will not produce, and will not make available to the Customer:

  • a score, rating or index representing a candidate's overall suitability;
  • a ranking or ordering of candidates against one another;
  • a recommendation, classification or label that determines or is intended to determine a candidate's outcome;
  • any inference about a candidate's emotional state, personality, accent or tone;
  • any inference about a characteristic protected under applicable non-discrimination law.

The Customer undertakes that every decision about a candidate is taken by an identified natural person who has the competence and authority to reach a different conclusion from the one the brief suggests, and who takes other information into account. The Customer will not configure its process, or instruct its staff, so that a HireCall brief determines an outcome without genuine human assessment.

⚠️ The single most important clause in this document, and the one most likely to be tested.

In SCHUFA (CJEU, C-634/21, 7 December 2023) the Court held that an automated output produced by one party can itself be a decision within Article 22 GDPR where the party receiving it draws strongly upon it. A brief that a recruiter follows without real scrutiny falls within that reasoning — and the exposure would land on the Customer as controller, and on HireCall through the public claim that "no automated decisions" are made.

The undertaking above is the contractual half of the answer. The product half is missing and should be built: require the named decision-maker and a reason to be recorded before an outcome is set, and make that record exportable, so that both parties can evidence meaningful human involvement if challenged. Confirm whether the product does this today. If it does, say so here — it is a genuine differentiator. If it does not, this clause is a promise resting on the customer's goodwill.

Note also the CNIL made recruitment a priority inspection theme for 2026, with automated decision-making, candidate information and retention periods named as focus areas. This is not a distant risk.

4.4 The Customer's own obligations

The Customer confirms that it will:

  • have a lawful basis for the processing, and be able to demonstrate it;
  • inform candidates before the interview, and make the candidate privacy notice available to them in a language they understand;
  • offer any candidate who does not wish to take an AI interview an alternative route, without disadvantage;
  • carry out a data protection impact assessment where required, and consult employee representatives where required — in France, the comité social et économique;
  • meet any local requirement applying to it as an employer, including bias auditing and advance notice where an automated employment decision tool is regulated, and biometric consent requirements where voice is treated as a biometric identifier;
  • not submit special category data, and not set criteria that seek or proxy for protected characteristics.

5. Confidentiality

HireCall ensures that everyone authorised to process candidate personal data is bound by an appropriate duty of confidentiality, whether by contract or by statute, and that the duty survives the end of their engagement. Access is limited to those who need it to provide the service.


6. Security

HireCall implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as Article 32 GDPR requires. Those measures are described in Annex II, and HireCall will not reduce them materially during the term.

HireCall takes into account, in particular, the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to candidate personal data — including voice recordings, which are more revealing than the text of what was said.


7. Sub-processors

The Customer gives general written authorisation for HireCall to engage sub-processors. Those engaged at the date of this DPA are listed in Annex III.

Before adding or replacing a sub-processor, HireCall will give the Customer at least [[SUBPROCESSOR NOTICE PERIOD]] days' notice — 30 days is suggested — by email and on [[SUBPROCESSOR PAGE URL]], which the Customer may subscribe to.

The Customer may object on reasonable data protection grounds within that period. The parties will discuss it in good faith. If it cannot be resolved, the Customer may terminate the affected service without penalty and receive a pro rata refund of unused, unexpired credits.

HireCall imposes on each sub-processor, by contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for a sub-processor's performance (Article 28(4) GDPR).


8. Helping the Customer with data subject requests

Candidates exercise their rights against the Customer, as controller. HireCall will:

  • promptly pass on any request it receives directly from a candidate, and not respond to it substantively itself, except to acknowledge and redirect — subject to the standing erasure instruction in clause 4.2;
  • provide, within [[DSR ASSISTANCE SLA]] days, the technical means for the Customer to answer a request for access, rectification, erasure, restriction, portability or objection;
  • where the product does not expose the necessary function, act on the Customer's written instruction to do so.

This assistance is included in the fees. HireCall will not charge for it.

For review. Charging for rights assistance is common in vendor DPAs and is a frequent negotiation point. Given HireCall's public positioning on candidate rights, offering it free is both consistent and cheap to honour at this scale. If that changes, change it deliberately.


9. Helping with security, breaches and impact assessments

Taking into account the nature of the processing and the information available to it, HireCall will assist the Customer in meeting its obligations under Articles 32 to 36 GDPR — security, breach notification, data protection impact assessment and prior consultation.

HireCall will make available the information the Customer needs to complete an impact assessment for the use of the service, including the information required of it as the provider of the AI system.


10. Personal data breaches

HireCall will notify the Customer without undue delay, and in any event within [[BREACH NOTICE PERIOD]] hours — 48 hours is suggested — after becoming aware of a personal data breach affecting candidate personal data.

The notification will describe, as far as known: what happened, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Where the information is not all available at once, HireCall will provide it in phases without undue delay.

HireCall will not notify a supervisory authority or any data subject on the Customer's behalf unless instructed to, and will not make any public statement identifying the Customer without its consent, except where legally required.


11. Deletion or return at the end

On termination, and at the Customer's choice, HireCall will delete or return all candidate personal data and delete existing copies, unless EU or member state law requires it to be kept.

Unless the Customer instructs otherwise, HireCall will:

  • make the data available for export for [[EXPORT WINDOW]] days after termination; and
  • delete it within [[POST TERMINATION DELETION]] days after that.

HireCall will certify deletion in writing if asked.


12. Audits

HireCall will make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

In practice, and to keep this workable for both sides:

  • HireCall will provide [[CERTIFICATIONS AND REPORTS]] on request — see the note below;
  • HireCall will answer a written security questionnaire once a year;
  • the Customer may conduct an on-site or remote audit once a year, on 30 days' notice, during business hours, subject to confidentiality, and more often where a supervisory authority requires it or following a personal data breach;
  • each party bears its own costs, save that the Customer bears HireCall's reasonable costs for audits beyond the annual one, unless the audit reveals material non-compliance.

To confirm. State what HireCall actually has. If there is no SOC 2 report, no ISO 27001 certificate and no penetration test, say so rather than implying otherwise — enterprise buyers will ask for the artefact, and a placeholder that resolves to nothing is worse than an honest "not yet, planned for X". A recent third-party penetration test report is the cheapest credible artefact to obtain first. See README.


13. International transfers

HireCall will not transfer candidate personal data outside the European Union except as permitted by this DPA and Data Protection Law.

Where candidate personal data originating in the EEA is transferred to a country without an adequacy decision, the transfer is made under:

  • the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, which are incorporated into this DPA by reference and completed by the annexes below; or
  • the EU–US Data Privacy Framework, where the recipient is certified under it and the certification covers the data in question.

Where the Data Privacy Framework is relied on and it ceases to be valid, or the recipient's certification lapses, the standard contractual clauses apply automatically without further action, and HireCall will tell the Customer.

Where the standard contractual clauses apply, HireCall will carry out and document a transfer impact assessment and make it available to the Customer.

For review. The automatic fallback above is deliberate. The Data Privacy Framework is currently valid — the General Court dismissed the challenge to it in Latombe (T-553/23) on 3 September 2025 — but the appeal filed on 31 October 2025 is pending before the Court of Justice (Case C-703/25 P), and the Court of Justice struck down both predecessor frameworks. A DPA that relies on the Framework alone would have to be renegotiated across the whole customer base if the appeal succeeds. This clause means it would not.

Note also that the UK and Swiss positions differ and need their own addenda if HireCall sells into either. [[UK AND SWISS ADDENDA]]


14. Liability, term and law

This DPA takes effect when the Terms of Service do and continues for as long as HireCall processes candidate personal data for the Customer.

Liability under this DPA is subject to the limitations in the Terms of Service, except where Data Protection Law does not permit it. Nothing here limits a data subject's rights under Article 82 GDPR.

This DPA is governed by French law, and disputes fall to the exclusive jurisdiction of the courts of Paris — save that, where the standard contractual clauses apply, the governing law and forum they specify prevail for matters within their scope.


Annex I — Details of the processing

Subject matter. Provision of AI-conducted first-screen interviews for the Customer's job applicants.

Duration. The term of the Terms of Service, plus the retention period in clause 4.2.

Nature and purpose. Inviting candidates; conducting a structured interview by AI — by voice, or in the text-only mode in writing; capturing and transcribing speech (in the text-only mode, speech is transcribed in real time and no audio recording is retained); producing a written brief of evidence against the Customer's criteria; making that brief, and where configured the transcript and recording, available to the Customer; deleting the data at the end of the retention period.

Categories of data subject. Job applicants of the Customer. Users of the Customer's account (recruiters, hiring managers).

Categories of personal data.

Category Detail
Identity and contact Name, email address, telephone number [[CONFIRM FIELDS]]
Application data The role applied for; data the Customer supplies from its ATS [[CONFIRM]]
Voice recording Audio of the candidate's answers (voice mode only; none in text-only mode)
Transcript Text of the candidate's answers
Brief Evidence extracted from the transcript against the Customer's criteria
Consent record Time of consent, version of the consent text shown, and the language it was rendered in (written by the server that rendered it). No IP address is captured.
Technical Connection metadata, timestamps, device and network information [[CONFIRM]]

On the consent record — verified, deliberate, and not to be "fixed". Verified in the product source (20 August 2026): the consent record stores the time of consent, the consent-copy version, and the language the copy was rendered in — the language field written by the server that rendered it and never backfilled. No IP address is captured, and none should be added. This is stronger Article 7(1) evidence than an IP log: it proves which text, in which language, the candidate was shown and when — which is what a consent dispute is actually about — while an IP proves only where a connection originated. Attribution is already established because the record is bound to the invited candidate's own interview session. Adding an IP would add personal data for no evidentiary gain, contrary to Article 5(1)(c) minimisation. If anyone proposes logging IPs "for consent proof", the answer is no.

Special category data. None is requested and none is required. The service does not ask about protected characteristics.

⚠️ But note. An open-ended spoken interview can produce special category data unprompted — a candidate may mention a health condition, a pregnancy, a religious observance or a trade union role in the course of an ordinary answer. The service cannot prevent this, and pretending otherwise would be false.

State what actually happens: is such content filtered or redacted from the brief? Is the transcript retained in full? The honest answer belongs here, and HireCall should have a considered position on it before a works council asks. [[INCIDENTAL SPECIAL CATEGORY DATA POSITION]]

On biometric data: recording and transcribing a voice is not biometric data under Article 4(14) GDPR, because that requires processing by specific technical means allowing or confirming unique identification. This remains true only for as long as no component of the pipeline performs speaker recognition, voice-based identity or liveness checking, or produces persistent voice embeddings. This must be verified across every sub-processor, and re-verified when any of them changes. If it is ever untrue, this row becomes Article 9 data requiring explicit consent, and separately triggers Illinois BIPA in the United States. See README.

Frequency. Continuous, as candidates take interviews.

Retention. By default: audio recordings, 90 days from the interview; transcripts and briefs, 12 months from the interview. Or as agreed in the order form: [[CUSTOM RETENTION PERIOD]].

Region. European Union — see the note at clause 4.1.


Annex II — Technical and organisational measures

⚠️ This annex is a template. Every line must be confirmed as a fact before this DPA is sent to a customer. Annex II is the part a security reviewer reads line by line, and a measure claimed but not implemented is a misrepresentation in a signed contract, not an aspiration.

Area Measure Status
Encryption in transit TLS 1.2 or above for all connections, including audio transport [[CONFIRM]]
Encryption at rest AES-256 for recordings, transcripts and database contents [[CONFIRM]]
Access control Role-based access; least privilege; MFA enforced on all staff accounts [[CONFIRM]]
Customer separation Logical separation of each customer's data [[CONFIRM]]
Regional isolation Storage pinned to the European Union (no per-customer region selection exists) [[CONFIRM — see clause 4.1: object-store region must be pinned, not "auto"]]
Key management [[DESCRIBE]] [[CONFIRM]]
Logging and monitoring Access to candidate data logged and retained for [[PERIOD]] [[CONFIRM]]
Backups Encrypted, [[FREQUENCY]], retained [[PERIOD]], restore tested [[FREQUENCY]] [[CONFIRM]]
Deletion Automated purge of audio at 90 days is implemented (scheduled job, logged tombstone); deletion of transcripts and briefs at 12 months, and deletion from backups, per clause 4.2 [[CONFIRM — audio verified 19 Aug 2026; rest open]]
Vulnerability management Dependency scanning; patching within [[SLA]] by severity [[CONFIRM]]
Penetration testing Independent test [[FREQUENCY]]; summary available under NDA [[CONFIRM]]
Staff Confidentiality undertakings; data protection training; access removed on departure [[CONFIRM]]
Business continuity RPO [[X]], RTO [[X]]; documented and tested [[CONFIRM]]
Incident response Documented plan; breach notification per clause 10 [[CONFIRM]]
Secure development Code review; separated environments; no production data in development [[CONFIRM]]
Sub-processor management Due diligence before engagement; contractual flow-down; periodic review [[CONFIRM]]

Annex III — Sub-processors

⚠️ THIS LIST IS UNVERIFIED AND MUST NOT BE PUBLISHED AS IT STANDS

The entries below reflect HireCall's stated expectation of the architecture. None has been confirmed against a signed contract. For each one, before this annex goes to any customer, confirm:

  1. the exact contracting entity and its country of establishment;
  2. what it actually processes — candidate personal data, or only metadata;
  3. the region where it processes and stores, and whether that can be pinned to the European Union;
  4. the transfer mechanism (adequacy, Data Privacy Framework certification — checked live on the official list — or standard contractual clauses);
  5. that a data processing agreement is signed and flows down obligations no less protective than this DPA;
  6. for AI providers, that zero-retention and no-training terms are enabled on the account, not merely available;
  7. whether the provider uses its own sub-processors in a way that affects the residency commitment.

HireCall's marketing states that "a signed DPA names every sub-processor". That promise is only kept when this table is complete and true.

Sub-processors for the interview service

Provider Purpose Candidate data? Entity and region Transfer mechanism DPA signed?
LiveKit Realtime audio transport Yes — live audio [[CONFIRM]] [[CONFIRM]] [[CONFIRM]]
OpenAI Realtime model conducting the interview Yes — audio and transcript [[CONFIRM]] [[CONFIRM]] [[CONFIRM]]
ElevenLabs Speech fallback Yes — audio [[CONFIRM]] [[CONFIRM]] [[CONFIRM]]
Cloudflare R2 Storage of audio recordings Yes — recordings [[CONFIRM]] [[CONFIRM]] [[CONFIRM]]
[[POSTGRES PROVIDER]] Managed database — transcripts, briefs, account data Yes [[CONFIRM]] [[CONFIRM]] [[CONFIRM]]
Clerk Authentication and billing Customer users, not candidates [[CONFIRM]] [[CONFIRM]] [[CONFIRM]] [[CONFIRM]]
Stripe Payment processing No candidate data [[CONFIRM]] [[CONFIRM]] [[CONFIRM]]
Vercel Application hosting [[CONFIRM]] [[CONFIRM]] [[CONFIRM]] [[CONFIRM]]
Resend Transactional email — candidate invitations [[CONFIRM — likely yes: name and email]] [[CONFIRM]] [[CONFIRM]] [[CONFIRM]]

Note. The managed Postgres provider has not been named. It cannot ship as "a managed Postgres provider" — customers need the entity and the region.

Note on the residency promise. Several of these are the places where an EU-storage warranty is most likely to fail in practice: realtime model inference, speech synthesis, and email delivery. If a provider cannot pin to the EU, either the architecture changes or clause 4.1 narrows further. (The marketing site's broader "never leave your region" claim is addressed in the README — it must be withdrawn or the capability built.)

Sub-processors for the marketing website only

Vercel (hosting), Resend (demo-request email and newsletter) and — on the /demo page only, and only once the anti-bot challenge is switched on — Cloudflare (Turnstile). These are described in the website privacy policy and are a separate, shorter list — do not conflate the two.

Cloudflare is listed here for completeness. It processes no candidate data and plays no part in the interview service this DPA governs: it sees only a visitor of the public marketing site who asks to try the demo.


Annex IV — Contacts

HireCall privacy contact: privacy@hirecall.ai HireCall security contact: [[SECURITY CONTACT EMAIL]] Sub-processor notifications: [[SUBPROCESSOR PAGE URL]] Customer contact: as given in the order form.


Version [[DPA VERSION]][[PUBLICATION DATE]]