Last updated: 27 September 2026 · Effective: 27 September 2026
Este anexo se ofrece en inglés, y prevalece la versión en inglés.
This Data Processing Addendum (“DPA”) forms part of the HireSide Terms of Service (the “Terms”) between Verge Inc. (“HireSide”, “we”, “us”) and the customer that has agreed to the Terms or signed an Order Form that refers to them (“Customer”, “you”). It applies whenever we process Customer Personal Data on your behalf. If this DPA conflicts with the Terms, this DPA governs as to the processing of Customer Personal Data.
1. Definitions
Capitalized terms not defined here have the meaning given in the Terms.
“Customer Personal Data” means personal information in Customer Data that we process on your behalf in providing the Service, including information about candidates who apply to your jobs and about your Authorized Users acting in your account.
“Data Protection Laws” means all laws on privacy and personal information that apply to the processing of Customer Personal Data under the Terms, which may include the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations (“CCPA”), other United States state privacy laws, Pakistan’s Prevention of Electronic Crimes Act, 2016 and, where they apply, the EU General Data Protection Regulation (“GDPR”), the UK GDPR and the Swiss Federal Act on Data Protection.
“Data Subject” means the individual to whom Customer Personal Data relates.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data that we process.
“Process” (and related words) means any operation performed on personal information, such as collection, storage, use, disclosure or deletion.
“Sub-processor” means a third party we engage to process Customer Personal Data.
“Controller”, “processor”, “business” and “service provider” have the meanings given in the applicable Data Protection Laws.
2. Roles and scope
You are the controller (business) of Customer Personal Data. You decide why and how candidates’ information is used in your hiring, and every hiring decision is yours.
We are your processor (service provider). We process Customer Personal Data only to provide the Service to you, as described in Annex I.
Where we act for ourselves. This DPA does not cover information for which we are a controller, as described in section 2.2 of our Privacy Policy: account and billing information, the candidate portal sign-in, job seekers’ own profiles, security and audit records, website visitors and the aggregated use of voluntary demographics answers to check our own AI for fairness.
Your responsibilities. You are responsible for having a lawful basis for your processing and for the instructions you give, for giving candidates any notice your law requires (the Service shows HireSide’s AI disclosure and collects consent where the Service design requires it, but your own notice obligations remain yours), and for the accuracy of the information you add.
3. Your instructions
We process Customer Personal Data only on your documented instructions. The Terms, this DPA, your configuration and use of the Service (for example the jobs you publish, the requirements and questions you set, the features you turn on and the stages you move candidates to) are your complete instructions at the time you agree to the Terms. Additional instructions must be agreed in writing. We will tell you if we believe an instruction breaks Data Protection Laws, and we may suspend the affected processing until it is clarified. We may also process Customer Personal Data where a law we are subject to requires it; in that case we will tell you first unless the law forbids it.
4. Service provider terms (California and other US states)
Where the CCPA or a similar US state law applies, we will not:
sell or share Customer Personal Data (as those terms are defined in the CCPA);
retain, use or disclose Customer Personal Data for any purpose other than the business purposes set out in the Terms and this DPA, including for any commercial purpose other than providing the Service, or outside our direct business relationship with you;
combine Customer Personal Data with personal information we receive from or on behalf of another person, or collect ourselves, except as the CCPA permits for a service provider (for example to detect security incidents or protect against fraud); or
use Customer Personal Data to train or improve AI models, other than in de-identified or aggregated form that cannot reasonably be linked to a person, and never to train a model for any other customer.
We will comply with the obligations the CCPA places on service providers, provide the same level of privacy protection the CCPA requires of you, and tell you if we can no longer meet those obligations. You may take reasonable and appropriate steps to ensure we use Customer Personal Data consistently with your CCPA obligations, and to stop and remediate unauthorized use. We certify that we understand and will comply with the restrictions in this section.
5. Our personnel
We give access to Customer Personal Data only to personnel who need it to provide, secure and support the Service. They are bound by confidentiality obligations. Support access to your account (“impersonation”) is available only to authorized HireSide staff, is limited to two hours at a time and is recorded in the audit log.
6. Security
We implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against Personal Data Breaches, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing and the risks to individuals. The measures in place are described in Annex II. We may update them over time, provided the overall level of protection is not reduced.
7. Sub-processors
General authorization. You authorize us to engage Sub-processors. Our current Sub-processors are listed at hireside.com/subprocessors (Annex III).
Our obligations. We impose on each Sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA, to the extent applicable to the service it provides. We remain responsible to you for our Sub-processors’ performance.
Changes. We will give at least 30 days’ notice before a new Sub-processor starts processing Customer Personal Data, by updating the list and notifying the account owner by email. In an emergency (for example to keep the Service secure or available) the notice may be shorter, and we will explain why.
Objections. You may object on reasonable data-protection grounds within the notice period by writing to [email protected]. We will work with you in good faith to address the objection. If we cannot, you may terminate the affected part of the Service by written notice, and we will refund any prepaid fees for the unused period.
8. Data subject requests and assistance
Requests. If we receive a request from a Data Subject about Customer Personal Data, we will pass it to you promptly and will not respond ourselves except to direct the person to you, unless the law requires otherwise. The Service lets you find, export, correct and delete candidates’ information, and lets candidates withdraw applications, leave talent pools and delete their candidate profile themselves.
Assistance. Taking into account the nature of the processing and the information available to us, we will give reasonable help with your obligations to respond to Data Subject requests, to carry out data-protection or risk assessments (including assessments of automated decision-making technology) and to consult regulators. We may charge for help that goes beyond the Service’s own tools, at our then-current rates.
Automated decisions. The Service does not make decisions about candidates without human involvement: AI outputs are suggestions, and a person on your team confirms every adverse decision. You remain responsible for any notices, explanations, human-review and appeal processes your law requires, and the Service provides tools (explanations with quoted evidence, a human-review request and an interview with a person) to support them.
9. Personal data breaches
We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe, as far as we know them, the nature of the breach, the categories and approximate number of individuals and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot give all of this at once, we will give it in phases. We will take reasonable steps to contain, investigate and remedy the breach, and give reasonable help with any notices you must give to regulators or individuals. Notice of a breach is not an admission of fault or liability.
10. AI processing
We send Customer Personal Data to AI model providers only to perform the Service’s features you use (for example reading CVs, judging requirements, running and scoring AI interviews and drafting messages), through providers listed in Annex III.
We select providers and settings intended to stop the data we send from being used to train their models, where such options are offered. We do not use Customer Personal Data to train AI models, and never to train a model for another customer.
Scoring uses a masked version of each candidate’s profile: names, contact details, photos and similar identifiers are removed, and protected characteristics are kept out of scoring. The Service never analyzes faces, emotions, voice tone or accents, and does not collect biometric data.
For every AI task we record the model and prompt version used, the number of tokens, the time taken and the outcome, without the text sent or returned, so that AI outputs can be accounted for.
11. International transfers
We host and store Customer Personal Data in the United States. Sub-processors may process it in the countries listed in Annex III. Where Data Protection Laws restrict a transfer of Customer Personal Data out of a country, we will make the transfer only with a valid safeguard. Where the GDPR, the UK GDPR or the Swiss law applies, the parties agree that the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), with the UK International Data Transfer Addendum or the Swiss amendments where relevant, are incorporated into this DPA by reference, with this DPA supplying the information their annexes require. HireSide does not currently target the European Union or the United Kingdom; this section applies if and when those laws apply to your use of the Service.
12. Return and deletion
During the subscription you can export and delete Customer Personal Data using the Service’s tools.
When your account is deleted, it is scheduled for erasure and permanently erased after a 30-day grace period (signing back in before then cancels the deletion). This removes your jobs, applications, CVs, interview recordings, test answers, scorecards and other Customer Personal Data.
Copies in backups are overwritten in the ordinary backup cycle. Until then they are kept secure and are not used.
We may keep Customer Personal Data where the law requires it, and we keep audit records, which contain identifiers and actions but not the content of applications, for at least four years to support record-keeping duties for hiring decisions. This DPA continues to protect anything we keep.
13. Information and audits
We will make available information reasonably necessary to demonstrate compliance with this DPA, including written answers to reasonable security questionnaires (no more than once a year unless there is a Personal Data Breach or a regulator requires it) and any independent audit reports we hold. If that information is not enough to demonstrate compliance, or a regulator requires it, you may carry out an audit, at your cost, once a year, with at least 30 days’ written notice, during business hours, without unreasonably disrupting our operations, and subject to confidentiality. The audit may not give access to other customers’ data.
14. Liability, term and precedence
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms. This DPA lasts as long as we process Customer Personal Data on your behalf. If there is a conflict, the following order applies: the Standard Contractual Clauses (where they apply), then this DPA, then the Terms. Questions about this DPA: [email protected].
Annex I: Details of the processing
Subject matter
Providing the HireSide recruiting Service to Customer under the Terms.
Duration
The term of the Terms, plus the deletion periods in section 12.
Nature and purpose
Hosting job posts and careers pages; receiving and storing applications; reading CVs and suggesting match scores with quoted evidence; running AI and human interviews and their scheduling; tests, evaluation forms and scorecards; talent pools; sending application, interview and outcome emails written or approved by Customer; analytics and fairness statistics for Customer; support, security and audit.
Data subjects
Candidates and job applicants of Customer; Customer’s Authorized Users (team members) and interviewers.
Categories of personal data
Identity and contact details; CVs and their contents (work history, education, skills, certifications, languages, links); answers to screening and custom questions; masked profiles, match scores and flags; AI interview transcripts, evaluations and, only where enabled and consented, audio recordings; interview integrity signals (numbers only); test answers and marks; scorecards, notes, tags and pipeline decisions with reasons; booking times and time zones; consent records; talent-pool membership; sign-in and security records.
Special categories
Not requested in applications. Only if a candidate chooses to answer the voluntary demographics survey: gender, age band, ethnicity (not in every country), disability and, in the United States, protected-veteran status, used only for aggregate fairness statistics and never for scoring or shown against a named candidate. Candidates may include other sensitive details in a CV on their own initiative.
Frequency
Continuous, for the duration of the Service.
Annex II: Technical and organizational measures
Encryption in transit: the Service is served over HTTPS (TLS), with HTTP Strict Transport Security on the live site.
Encryption at rest: files such as CVs and recordings are stored in private cloud storage that is encrypted at rest by our storage provider, never served from a public address, and streamed only after an access check. Two-factor secrets are encrypted in the database.
Authentication: passwords are stored only as bcrypt hashes; optional two-factor authentication (authenticator app or email code); candidates sign in with single-use links or codes that expire after 15 minutes; sessions are random tokens stored only as hashes and expire after 30 days; a password change ends the person’s other sessions.
Access control: every request is scoped to the signed-in account and its current company; team roles (owner, HR manager, recruiter, contributor, reviewer) limit what each person can see and do, and contributors and reviewers see only the jobs they are assigned to; public addresses use opaque codes, not sequential numbers.
Application security: parameterized database queries; cross-site request forgery protection on every form; security headers; file-type checks and limits on every upload; rate limits on sign-in, codes, forms, uploads and AI features; the private API is not reachable from the internet.
Accountability: a tamper-evident, hash-chained audit log of significant actions (for example stage changes, CV downloads and consents) that holds identifiers and actions, not content; a record of every AI task with its model and prompt version.
Data minimization: masked profiles for scoring; interview integrity signals recorded as numbers only; no emotion, face, voice-tone or accent analysis; recordings only where the employer enables them and the candidate consents.
Personnel: access on a need-to-know basis under confidentiality obligations; support access time-limited and logged.
Resilience and monitoring: managed cloud infrastructure, error alerting to our team, and an incident response process with breach notification under section 9.
Deletion: self-service deletion for candidates; scheduled erasure of deleted accounts after 30 days; automatic expiry of sign-in links, sessions and interview recordings (90 days after the job closes and never more than 365 days after the interview).
Verge Inc. 39111 Paseo Padre Pkwy, Fremont, California 94538, United States [email protected]
Cookies en HireSide
Usamos cookies esenciales para mantener tu sesión iniciada y segura. Con tu permiso, también usamos Google Analytics para ver cómo se usa el sitio. Los datos de empleos y candidatos nunca forman parte de esto.
Política de privacidad