Deze inhoud is beschikbaar in het Engels terwijl de vertaling wordt beoordeeld. · Machine translation preview
LEGAL

Data Processing Agreement

Processor obligations for employer-directed personal data, including instructions, security, assistance, deletion and transfers.

Last updated: 1 oktober 2026 · Version 1.0

1. Parties, scope and precedence

HireValid is operated by Recordskeeper Inc, a Delaware C-Corp. Our business mailing address is 2261 Market Street STE 86483, San Francisco, CA 94114. This DPA applies when incorporated into a service agreement or order with the customer identified in that agreement. The customer is the controller, or an authorized processor acting for its controller, and Recordskeeper Inc acts as processor or subprocessor. It controls conflicting service terms on personal-data processing. Independent business-contact and billing processing remains covered by our Privacy Policy.

2. Processing description

The subject matter is provision of the contracted hiring-assessment service for the agreement’s duration and an authorized return or deletion period. Activities include receiving, storing, organizing, scoring, retrieving, transmitting, supporting and deleting assessment records. Data subjects include candidates, customer users and authorized contacts. Categories may include identity and contact details, assessment responses, work samples, scores, timestamps, technical logs and monitoring data only where expressly enabled and lawfully instructed. Special-category or biometric processing requires a specifically documented scope and safeguards.

3. Documented instructions

We process customer personal data only on documented instructions, including those in the agreement and lawful account settings, unless law requires otherwise. Where permitted, we inform the customer of a legal requirement before processing. We promptly inform the customer if an instruction appears to violate applicable data-protection law and may suspend the affected processing while it is clarified. The customer is responsible for a lawful basis, notices, permissions and the legality of its instructions.

4. Confidentiality and security

Access is limited to authorized persons bound by confidentiality. Measures must be proportionate to the nature and risk of processing and include access management, secure transmission, appropriate storage protection, logging, incident handling and restoration procedures. Specific deployment measures and any additional customer requirements must be documented in the applicable security schedule before processing requiring them begins. No certification, dedicated region or audit report is implied by this DPA.

5. Subprocessors

The customer authorizes service providers identified for its deployment, subject to written obligations offering materially equivalent protection. We remain responsible for their performance of our processing obligations. We will provide at least 30 days’ notice of an intended material addition or replacement where practicable, allowing a reasonable objection on data-protection grounds. The parties will seek an alternative or mitigation; if none is reasonably available, the customer may terminate the affected service before the change takes effect, with a proportionate refund for the unused prepaid affected service.

6. Personal-data breaches

We notify the customer without undue delay after becoming aware of a personal-data breach affecting its data. Information, as available, includes the nature of the incident, affected categories and approximate scope, likely consequences, mitigation and a contact for follow-up. We provide updates as facts develop and cooperate with remediation. The customer decides its regulatory and individual notification obligations; our assistance does not postpone statutory deadlines.

7. Rights and compliance assistance

Taking account of the processing and information available, we assist with requests from data subjects, security obligations, impact assessments and regulatory consultations. We forward requests relating to customer-controlled data and do not respond substantively without instructions unless required by law. Any reasonable charges for extraordinary assistance must be agreed in advance and cannot prevent mandatory cooperation.

8. Information and audits

We make information reasonably necessary to demonstrate these obligations available and permit proportionate audits by the customer or an independent auditor bound by confidentiality. Audits should use existing evidence where sufficient, minimize disruption and protect other customers’ data. Reasonable notice and scope may be agreed, but cannot restrict a competent authority or an urgent legally required investigation.

9. Return and deletion

At the customer’s choice after services end, we return or delete covered personal data and delete remaining copies unless law requires retention. The parties must agree the export format and deletion schedule appropriate to the deployment. Data retained under legal requirements is isolated from ordinary use and deleted when that requirement ends. Backup deletion follows the documented backup cycle; any restoration must reapply outstanding deletion instructions. We provide confirmation on request.

10. International transfers

Restricted international transfers require a valid transfer mechanism and any necessary assessments and supplementary measures before the transfer. Where needed, the parties must execute the applicable standard contractual clauses and complete their annexes and any UK addendum. This document alone does not execute transfer clauses or establish a particular hosting region. Mandatory transfer terms prevail over conflicting provisions, including governing law and forum.

11. Service-provider restrictions

Where applicable US state privacy law requires, we do not sell or share customer personal data, retain or use it outside the specified business purposes or direct business relationship, or combine it with unrelated data except as law permits. We will inform the customer if we can no longer meet applicable obligations and allow reasonable measures to stop and remediate unauthorized use.

12. Contact and governing terms

Notices concerning this DPA should be sent to [email protected]. The service agreement’s Delaware law and Delaware court provisions apply subject to non-waivable rights and controlling transfer clauses. This DPA does not replace the customer-specific order, processing scope, deployment security schedule or required transfer annexes.

Download DPA