Skip to content
DeveloperHiring

Data processing agreement

This data processing agreement (DPA) applies when a customer uses developerhiring.com to process personal data of candidates and team members. It forms part of the terms of service. Team and Scale customers can save it as a PDF for their records.

Back to security

1. Parties and roles

The customer is the company that holds a DeveloperHiring workspace and accepts this DPA by using the service on a paid plan ("Customer"). The administrator of the developerhiring.com service ("we") processes personal data on behalf of the Customer. The Customer is the controller, and we are the processor.

2. Subject matter and duration

We process personal data to provide the service described in the terms: sourcing, screening, coding assessments, AI technical interviews, integrity analysis, ranking and related features. Processing lasts for the term of the Customer's subscription plus the retention and deletion periods described below.

3. Categories of data subjects and personal data

  • Candidates: name, email address, public profile links, CV content, public code, screening answers, test submissions, keystroke and paste events, interview transcripts, scores and notes, and optional webcam snapshots or identity check results when the candidate consents.
  • Customer team members: name, email address, role, sign-in and activity records.

The service is not designed to process special categories of personal data. The Customer should not ask candidates for such data.

4. Our obligations

  • We process personal data only on documented instructions of the Customer, including those given through the product settings.
  • People who process personal data for us are bound by confidentiality.
  • We apply the technical and organisational measures in section 7.
  • We help the Customer answer data subject requests, mainly through the candidate portal, where candidates export or delete their data.
  • We help the Customer with security, breach notification and data protection impact assessments, taking into account the nature of processing.
  • We notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer data.
  • We make available the information needed to show compliance with this DPA and allow reasonable audits by questionnaire.

5. Sub-processors

The Customer gives general authorisation for us to use sub-processors in these categories: infrastructure and hosting in the European Union, transactional email delivery, payment processing, an AI model provider for text processing, a code execution environment, and, on Scale, an identity verification provider. Each sub-processor is bound by written terms that offer the same level of protection. We inform Customers about new sub-processor categories in advance, and the Customer may object on reasonable grounds.

6. International transfers

Customer data is stored in the European Union. When a sub-processor needs to access data from outside the European Economic Area, the transfer is covered by appropriate safeguards such as standard contractual clauses.

7. Security measures

  • Encryption in transit with TLS and encryption at rest for databases, files and backups.
  • Candidate code runs in an isolated sandbox.
  • Access to production data is limited, logged and reviewed.
  • Blind review hides name, photo, age and gender from the scoring step.
  • Daily encrypted backups with the same retention as live data.
  • On Scale, single sign-on and an audit log of user actions.

8. Retention and deletion

The Customer sets a retention period for candidate data in its workspace. The default is 12 months. Data older than the retention period is deleted automatically. When the subscription ends, the Customer can export its data, and we delete Customer data within 30 days, with backups expiring on their normal cycle.

9. AI processing

AI is used to extract skills from role descriptions, score CVs and public code against a skill matrix, and conduct text-based technical interviews. AI outputs support the Customer's decision and never replace it. Candidates are informed before AI stages start and may request human review. Customer data is not used to train AI models.

10. Liability and order of precedence

Liability under this DPA follows the limits in the terms of service. If this DPA and the terms conflict on data protection, this DPA prevails.

11. Contact

Questions about this DPA go to [email protected].