Data processing

Data processing

What a data processing agreement with us would cover, and the unusual part: for the data your compliance team is actually worried about, there is nothing for us to process.

A signable data processing agreement is available on request. Email [email protected] with your template or ask for ours. This page is a plain summary so you can tell in five minutes whether the shape of it works for you.

The short version

Interview content — the transcript, the quotes, the candidate's name, the submittal — is written to your recruiter's own computer and never reaches us. For that data you are the controller and we are not a processor at all, because we never receive it.

For the small amount of data we do hold, we are a processor and you are the controller, and the usual terms apply.

What we process on your behalf

CategoryData subjectsPurpose
Account data — email address, name, role Your recruiters and admins Sign-in, seat management, support
Interview metadata — how long the interview ran, how many questions and how many must-asks were covered, how many follow-ups were shown and used, how many scorecard areas were filled, one fit score, and the consent decision with its jurisdiction label Your recruiters (never candidates) Coverage reporting and the weekly coaching note
Diagnostic events — error type, app version, operating system Your recruiters Finding and fixing faults

No category above contains candidate personal data. The full field list is on the security page and in the privacy notice, and it is the same list in all three places on purpose.

Transient processing during an interview

While an interview runs, short chunks of audio, extracts of the transcript, and extracts of any CV the recruiter has attached pass through speech and model providers so the app can transcribe, suggest and score. Nothing is retained by them or by us, and no audio file is ever created. Those providers are sub-processors for the duration of the call and are listed in full on the security page.

Our commitments

Transfers

Our providers are in the United States. Where data moves from the UK or the EEA we rely on the standard contractual clauses with each. The transfer question is narrower here than usual: the content most transfer analysis is concerned with never leaves the device it was created on.

Security measures

Set out in full on the security page, which is written to be specific enough to check rather than reassuring enough to file.

Last updated 10 September 2026. For the signed agreement: [email protected].