This Data Processing Agreement (the “DPA”) forms part of the Terms of Service between HireDay, Inc. (“HireDay”, the Processor) and the organization that has created a HireDay account (“you”, the Controller). It applies where you are subject to the UK GDPR, the EU GDPR, or both, and it is entered into when you accept the Terms of Service. No signature is required, though we will sign a counterpart on request — write to hello@hireday.io.

You decide what employee data goes into HireDay and why. We process it to run the service for you, and for nothing else. Where this DPA and the Terms of Service disagree about personal data, this DPA governs.

1. Subject-matter and duration

Subject-matter: provision of the HireDay employee onboarding platform — checklist templates, task assignment, progress tracking and related notifications.

Duration: from the creation of your account until it is closed, plus the deletion period in Section 8. Sections 3 (confidentiality), 8 (deletion) and 9 (audit) survive termination.

2. Nature and purpose of processing

Nature: collection through the web application and its API; storage in an encrypted database; display to authorised users within your organization; automated scheduling and sending of notification emails; generation of progress reports and exports; and deletion on your instruction.

Purpose: to let your organization plan, assign and track employee onboarding.

Boundaries. We process personal data only on your documented instructions. Your use of the service is itself an instruction; anything beyond it must be in writing. We do not sell personal data, we do not use it for advertising, and we do not use your data to train machine-learning models.

3. Our obligations

Under Article 28(3) we undertake the following.

(a) Documented instructions. We process personal data only on your documented instructions, including as to international transfers, unless required otherwise by law — in which case we will tell you before processing, unless the law forbids us from doing so on important grounds of public interest.

(b) Confidentiality. Everyone we authorise to process personal data is bound by an obligation of confidentiality.

(c) Security. We implement the technical and organisational measures required by Article 32. They are listed in Annex II, and we do not reduce them below that standard during the term.

(d) Sub-processors. We engage sub-processors only under the terms in Section 5.

(e) Data subject rights. Taking into account the nature of the processing, we assist you in responding to requests from your employees to exercise their rights under Chapter III. The product lets an administrator view, correct and delete individual records directly; where a request cannot be served that way, write to us.

(f) Compliance assistance. We assist you with your obligations under Articles 32 to 36 — security, breach notification, impact assessments and prior consultation — taking into account the nature of processing and the information available to us.

(g) Deletion or return. On termination, we delete or return personal data at your choice, as set out in Section 8.

(h) Audit. We make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, as set out in Section 9.

4. Your obligations and rights

5. Sub-processors

You give us general written authorisation to engage sub-processors. Our current sub-processors are listed, with what each one does and what it can see, at hireday.io/legal/subprocessors.

Before we add or replace one, we email your administrator contact at least 30 days in advance. You may object on reasonable data-protection grounds within 14 days of that notice. If we cannot resolve your objection within 30 days, you may terminate the affected part of the service without penalty and receive a pro-rated refund of prepaid fees.

We impose on every sub-processor, by written contract, data protection obligations materially equivalent to those in this DPA, as Article 28(4) requires. We remain fully liable to you for their performance.

6. International transfers

We process your data in the United States. The transfer mechanism is the Standard Contractual Clauses (Implementing Decision 2021/914) together with the UK International Data Transfer Addendum, supported by a transfer impact assessment carried out under the EDPB’s Recommendations 01/2020. The detail, including the supplementary measures we apply, is on our International Data Transfers page, which forms part of this DPA.

7. Personal data breach

We notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data. The notification describes the nature of the breach, the categories and approximate number of records concerned, the likely consequences, the measures taken or proposed, and a contact point.

Where we cannot provide all of that at once, we provide it in phases without further undue delay. Notifying your supervisory authority under Article 33(1) remains your decision and your responsibility; we give you what you need to make it.

8. Deletion and return

You can export your organization’s data from the product at any time while your account is open.

On request, we delete your organization’s data within 90 days, and confirm when it is done. Deletion follows a tested procedure that covers every table holding your data. Two honest caveats: routine encrypted backups still contain the data until they age out on their normal schedule, and we retain the minimum billing records that tax law requires us to keep.

Closing a paid subscription does not delete anything — your account moves to the free plan and your data stays as it was. Deletion happens only when you ask for it.

9. Audit

We make available the information reasonably necessary to demonstrate compliance with Article 28, and respond to security questionnaires and reasonable written requests for information.

You may audit our compliance, or appoint an independent auditor to do so, no more than once in any twelve-month period unless a breach or a supervisory authority requires otherwise. Give us 30 days’ written notice; audits happen during business hours, must not unreasonably disrupt the service, and must not access other customers’ data. The auditor signs a confidentiality undertaking. You bear the cost, unless the audit finds a material failure on our part.

HireDay is a small company and does not hold SOC 2 or ISO 27001 certification today. We would rather tell you that here than have you discover it during procurement. Our infrastructure sub-processors do hold those certifications, and their reports are available through them.

10. Liability and changes

Liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR does not permit those limitations to apply.

We may update this DPA to reflect changes in law, guidance or our processing. If a change materially reduces your protections we give you 30 days’ notice by email, and you may terminate without penalty if you do not accept it. Version history is at the top of this page.


Annex I — Description of processing

A. Parties

Controller (exporter): the organization holding the HireDay account. Processor (importer): HireDay, Inc. Contact for both roles: hello@hireday.io.

B. Categories of data subjects

C. Categories of personal data

D. Special category data

None. HireDay provides no field for data of the kinds listed in Article 9, and you agree not to enter any.

E. Frequency and duration

Continuous, for the term of your account. Retained for the life of the account, then per Section 8.

F. Nature and purpose

As set out in Section 2.

Annex II — Technical and organisational measures

These are the Article 32 measures in place today. Where something is not in place, it is not listed.

Access control

Encryption

Resilience and recovery

Monitoring

Organisational

Annex III — Sub-processors

Maintained at hireday.io/legal/subprocessors and incorporated into this DPA by reference. At the effective date: Amazon Web Services (hosting, database, email), Anthropic (optional AI task suggestions), and Stripe (billing, paid plans only).