This Data Processing Agreement (the “DPA”) forms part of the Terms of Service between HireDay, Inc. (“HireDay”, the Processor) and the organization that has created a HireDay account (“you”, the Controller). It applies where you are subject to the UK GDPR, the EU GDPR, or both, and it is entered into when you accept the Terms of Service. No signature is required, though we will sign a counterpart on request — write to hello@hireday.io.
You decide what employee data goes into HireDay and why. We process it to run the service for you, and for nothing else. Where this DPA and the Terms of Service disagree about personal data, this DPA governs.
1. Subject-matter and duration
Subject-matter: provision of the HireDay employee onboarding platform — checklist templates, task assignment, progress tracking and related notifications.
Duration: from the creation of your account until it is closed, plus the deletion period in Section 8. Sections 3 (confidentiality), 8 (deletion) and 9 (audit) survive termination.
2. Nature and purpose of processing
Nature: collection through the web application and its API; storage in an encrypted database; display to authorised users within your organization; automated scheduling and sending of notification emails; generation of progress reports and exports; and deletion on your instruction.
Purpose: to let your organization plan, assign and track employee onboarding.
Boundaries. We process personal data only on your documented instructions. Your use of the service is itself an instruction; anything beyond it must be in writing. We do not sell personal data, we do not use it for advertising, and we do not use your data to train machine-learning models.
3. Our obligations
Under Article 28(3) we undertake the following.
(a) Documented instructions. We process personal data only on your documented instructions, including as to international transfers, unless required otherwise by law — in which case we will tell you before processing, unless the law forbids us from doing so on important grounds of public interest.
(b) Confidentiality. Everyone we authorise to process personal data is bound by an obligation of confidentiality.
(c) Security. We implement the technical and organisational measures required by Article 32. They are listed in Annex II, and we do not reduce them below that standard during the term.
(d) Sub-processors. We engage sub-processors only under the terms in Section 5.
(e) Data subject rights. Taking into account the nature of the processing, we assist you in responding to requests from your employees to exercise their rights under Chapter III. The product lets an administrator view, correct and delete individual records directly; where a request cannot be served that way, write to us.
(f) Compliance assistance. We assist you with your obligations under Articles 32 to 36 — security, breach notification, impact assessments and prior consultation — taking into account the nature of processing and the information available to us.
(g) Deletion or return. On termination, we delete or return personal data at your choice, as set out in Section 8.
(h) Audit. We make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, as set out in Section 9.
4. Your obligations and rights
- You may issue documented instructions about how we process personal data, within the scope of the service.
- You confirm that you have a lawful basis under Article 6 for the processing you ask us to carry out, and that you have given your employees whatever notice their local law requires.
- You are responsible for responding to your employees’ data subject requests. We assist under Section 3(e).
- You tell us if your processing instructions change materially, or if you become subject to a requirement that affects how we must handle your data.
- You keep your administrator contact details current, so that sub-processor notices and breach notifications reach the right person.
- You must not put special category data into HireDay. There is no field for it, and our security measures are not designed for it.
5. Sub-processors
You give us general written authorisation to engage sub-processors. Our current sub-processors are listed, with what each one does and what it can see, at hireday.io/legal/subprocessors.
Before we add or replace one, we email your administrator contact at least 30 days in advance. You may object on reasonable data-protection grounds within 14 days of that notice. If we cannot resolve your objection within 30 days, you may terminate the affected part of the service without penalty and receive a pro-rated refund of prepaid fees.
We impose on every sub-processor, by written contract, data protection obligations materially equivalent to those in this DPA, as Article 28(4) requires. We remain fully liable to you for their performance.
6. International transfers
We process your data in the United States. The transfer mechanism is the Standard Contractual Clauses (Implementing Decision 2021/914) together with the UK International Data Transfer Addendum, supported by a transfer impact assessment carried out under the EDPB’s Recommendations 01/2020. The detail, including the supplementary measures we apply, is on our International Data Transfers page, which forms part of this DPA.
7. Personal data breach
We notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data. The notification describes the nature of the breach, the categories and approximate number of records concerned, the likely consequences, the measures taken or proposed, and a contact point.
Where we cannot provide all of that at once, we provide it in phases without further undue delay. Notifying your supervisory authority under Article 33(1) remains your decision and your responsibility; we give you what you need to make it.
8. Deletion and return
You can export your organization’s data from the product at any time while your account is open.
On request, we delete your organization’s data within 90 days, and confirm when it is done. Deletion follows a tested procedure that covers every table holding your data. Two honest caveats: routine encrypted backups still contain the data until they age out on their normal schedule, and we retain the minimum billing records that tax law requires us to keep.
Closing a paid subscription does not delete anything — your account moves to the free plan and your data stays as it was. Deletion happens only when you ask for it.
9. Audit
We make available the information reasonably necessary to demonstrate compliance with Article 28, and respond to security questionnaires and reasonable written requests for information.
You may audit our compliance, or appoint an independent auditor to do so, no more than once in any twelve-month period unless a breach or a supervisory authority requires otherwise. Give us 30 days’ written notice; audits happen during business hours, must not unreasonably disrupt the service, and must not access other customers’ data. The auditor signs a confidentiality undertaking. You bear the cost, unless the audit finds a material failure on our part.
HireDay is a small company and does not hold SOC 2 or ISO 27001 certification today. We would rather tell you that here than have you discover it during procurement. Our infrastructure sub-processors do hold those certifications, and their reports are available through them.
10. Liability and changes
Liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR does not permit those limitations to apply.
We may update this DPA to reflect changes in law, guidance or our processing. If a change materially reduces your protections we give you 30 days’ notice by email, and you may terminate without penalty if you do not accept it. Version history is at the top of this page.
Annex I — Description of processing
A. Parties
Controller (exporter): the organization holding the HireDay account. Processor (importer): HireDay, Inc. Contact for both roles: hello@hireday.io.
B. Categories of data subjects
- Your employees who use HireDay — HR administrators, hiring managers, onboarding buddies
- Your new hires, including people who have accepted an offer but not yet started
- People you have invited who have not yet accepted
C. Categories of personal data
- Identity and contact: first and last name, work email address
- Employment: job title, department, employment type, start date, manager and buddy relationships, organizational attributes you define
- Onboarding activity: assigned tasks, completion status and timestamps, notes and acknowledgements, check-in responses, uploaded task attachments
- Account: role within HireDay, authentication identifiers, invitation status
- Billing (paid plans only): billing contact name and email. Card details go to Stripe directly and never reach us.
D. Special category data
None. HireDay provides no field for data of the kinds listed in Article 9, and you agree not to enter any.
E. Frequency and duration
Continuous, for the term of your account. Retained for the life of the account, then per Section 8.
F. Nature and purpose
As set out in Section 2.
Annex II — Technical and organisational measures
These are the Article 32 measures in place today. Where something is not in place, it is not listed.
Access control
- Tenant isolation. Every query against organization-owned data is restricted to the requesting organization. The restriction is enforced centrally in one place rather than repeated at each call site, and an automated check runs on every code change to catch any query that bypasses it.
- Role-based access within your organization: HR administrator, manager and new hire see different data, and a manager sees only their own reports.
- Authentication by short-lived single-use email links or, for enterprise customers, your own SSO identity provider. HireDay stores no passwords.
- Staff access to production is limited to those who need it, under individual credentials with multi-factor authentication.
Encryption
- TLS 1.2 or better for all data in transit, including outbound email.
- Encryption at rest for the database and for uploaded files.
Resilience and recovery
- Automated daily database backups with point-in-time recovery, and deletion protection on the production database.
- Database migrations run to completion before the application serves traffic; a failed migration aborts the deployment.
Monitoring
- Every request carries a request identifier, logged and returned in error responses, so an incident can be traced.
- Automated alerts on error-rate spikes and on unresponsive application instances.
- Error responses never expose internal detail — no stack traces, no SQL, no connection strings.
- An audit trail of onboarding activity is available to administrators for export.
Organisational
- Written data retention policy, and a tested procedure for deleting an organization’s data on request.
- Written contracts with every sub-processor imposing equivalent obligations.
- Transfer impact assessment reviewed at least annually.
Annex III — Sub-processors
Maintained at hireday.io/legal/subprocessors and incorporated into this DPA by reference. At the effective date: Amazon Web Services (hosting, database, email), Anthropic (optional AI task suggestions), and Stripe (billing, paid plans only).