1. Scope & Incorporation
This Data Processing Agreement (“DPA”) is incorporated into, and is subject to, the Hiretea Terms of Service. It applies where a workspace customer (“Customer”) uses the Hiretea platform to process personal data of data subjects (including job applicants, candidates, and guest interviewers) and Hiretea (“Processor”) processes that personal data on behalf of the Customer.
This DPA is intended to satisfy the requirements for a binding agreement between a controller and a processor under Article 28 of the General Data Protection Regulation (GDPR) and, for processing subject to Turkish law, the corresponding provisions of the Turkish Personal Data Protection Law (KVKK) and its regulations on data processing by proxy.
2. Roles of the Parties
The Customer acts as the controller (veri sorumlusu) for all candidate and recruitment data managed within its workspace. Hiretea acts as the processor (veri işleyen) and processes personal data only on the Customer’s documented instructions. Where Hiretea processes personal data for its own purposes (for example, account registration, billing, and website operation), Hiretea acts as an independent controller and that processing is governed by the Hiretea Privacy Policy, not this DPA.
3. Details of Processing
- Subject matter: Recruitment and hiring workflows provided by the Hiretea platform, including application handling, candidate pipelines, repository challenges, assessments, and live video interviews.
- Duration: The term of the Customer’s subscription, plus the retention period configured by the Customer and any period required by applicable law.
- Nature and purpose: Storage, hosting, transmission, and analysis of candidate and recruitment data in order to provide the Service.
- Categories of data subjects: Job applicants, candidates, workspace users, and guest interviewers.
- Categories of data: Identification and contact data (name, email, phone, location), application materials (CVs, cover letters, portfolio links, screening answers), challenge data (source code, commits, diffs), assessment data (scores, ratings, rubrics), consent evidence, and account data of workspace users.
4. Processor Obligations
- Process personal data only on documented instructions from the Customer, unless required by applicable law, in which case Hiretea will inform the Customer of that legal requirement before processing, where permitted.
- Ensure that persons authorized to process personal data are bound by confidentiality obligations and access it only as necessary to provide the Service.
- Implement the technical and organizational security measures described in the Privacy Policy, including TLS 1.3 in transit, AES-256 at rest, per-workspace data partitioning, least-privilege API token scopes, and sandboxed execution of candidate code.
- Assist the Customer in responding to data subject requests (access, rectification, erasure, export) through the platform’s built-in compliance tooling.
- Assist the Customer in ensuring compliance with its obligations relating to security, breach notification, and data protection impact assessments, taking into account the nature of the processing.
- Never sell, rent, or monetize personal data processed on behalf of the Customer, and never process it for advertising purposes.
5. Subprocessors
The Customer acknowledges that Hiretea engages the subprocessors listed in the Privacy Policy (cloud hosting and storage, transactional email delivery, payment processing, and AI evaluation providers where AI summaries or code reviews are requested). Hiretea will update the Privacy Policy to reflect any additions or replacements of subprocessors. If the Customer objects to a new subprocessor on reasonable data protection grounds, the parties will discuss the objection in good faith; where the objection cannot be resolved, the Customer may terminate its subscription before the new subprocessor begins processing.
Hiretea remains fully liable to the Customer for the performance of each subprocessor’s data protection obligations and imposes data protection terms on every subprocessor that are no less protective than this DPA.
6. AI-Assisted Processing
Where the Customer requests AI-assisted candidate summaries or code review proposals, Hiretea may transmit the relevant candidate data to its AI service providers solely to generate the requested output. These providers are contractually prohibited from using submitted data to train their models. AI outputs are advisory only; the Customer remains solely responsible for all hiring decisions made on the basis of its instructions.
7. International Transfers
Where personal data is transferred to a country that does not provide an adequate level of data protection, Hiretea will ensure that appropriate safeguards are in place, such as standard contractual clauses approved by the relevant supervisory authority, and will document those safeguards on the Customer’s request.
8. Personal Data Breach Notification
Hiretea will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data processed on the Customer’s behalf, providing the information reasonably available to enable the Customer to meet its own breach notification obligations, and will take reasonable steps to mitigate the breach.
9. Return & Deletion
Upon termination of the Customer’s subscription, and subject to the retention settings configured by the Customer, Hiretea will delete or return all personal data processed on the Customer’s behalf and delete existing copies, unless applicable law requires storage of the data. Data export tooling within the platform allows the Customer to retrieve its candidate data at any time during the subscription term.
10. Audit & Evidence
The platform maintains immutable audit trails of sensitive hiring actions and consent snapshots captured at the moment of application submission. Hiretea will make available, on reasonable request, the information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or another examiner mandated by it.
11. Order of Precedence
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to the subject matter of data processing. Nothing in this DPA limits or excludes either party’s liability as provided in the Terms of Service, except as required by applicable data protection law.
12. Contact
Questions or data protection inquiries relating to this DPA may be directed to: