Need a signed copy? This page is the current published DPA. If your legal or procurement team needs a countersigned PDF for their vendor-review file, email legal@smarthire.chat with your company name and we will send one within 3 business days.

1. Definitions

Capitalized terms used in this DPA have the meaning given below. Terms not defined here take their meaning from the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) or applicable data-protection legislation in the customer's jurisdiction.

2. Roles

With respect to Customer Personal Data, the Customer is the Controller and SmartHire is the Processor. Each party will comply with its own obligations under applicable data-protection legislation.

3. Subject matter and duration

Subject matter: the processing of Customer Personal Data by SmartHire strictly for the purpose of providing the SmartHire service to the Customer under the parties' underlying subscription agreement (the “Main Agreement”).

Duration: this DPA takes effect on the date the Customer accepts SmartHire's Terms of Service (or the date of a signed order form, if later) and remains in effect for as long as SmartHire processes Customer Personal Data, plus any post-termination retention period described in Section 9.

4. Nature and purpose of processing

SmartHire processes Customer Personal Data to:

5. Categories of personal data

Customer will not submit sensitive or special-category data (as defined in GDPR Art. 9) unless it has notified SmartHire in advance and has a documented lawful basis.

6. Categories of data subjects

7. SmartHire obligations as Processor

7.1 Documented instructions only

SmartHire will process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country. The Customer's use of the service's features and configuration constitutes such instructions. If SmartHire is required by Union or Member State law to process Customer Personal Data other than on Customer's instructions, SmartHire will inform the Customer before processing, unless that law prohibits notification.

7.2 Confidentiality

SmartHire will ensure that personnel authorized to process Customer Personal Data are bound by contractual or statutory duties of confidentiality.

7.3 Security

SmartHire will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. A summary of current measures is published at /trust/ and forms part of this DPA. Measures include encryption at rest and in transit, tenant isolation, role-based access controls, MFA availability, audit logging, and an incident-response playbook.

7.4 Sub-processor engagement

Customer grants SmartHire general authorization to engage the sub-processors listed at /subprocessors/. SmartHire will:

7.5 Assistance with data-subject rights

Taking into account the nature of the processing, SmartHire will assist the Customer with appropriate technical and organizational measures, insofar as possible, in responding to requests from Data Subjects exercising their rights under GDPR (access, rectification, erasure, restriction, portability, objection). Where a Data Subject contacts SmartHire directly regarding Customer Personal Data, SmartHire will promptly forward the request to the Customer.

7.6 Assistance with DPIAs and consultation

SmartHire will provide reasonable assistance to the Customer in carrying out data-protection impact assessments (Art. 35) and consulting with supervisory authorities (Art. 36), taking into account the nature of processing and the information available to SmartHire.

7.7 Breach notification

SmartHire will notify the Customer without undue delay and no later than 72 hours after becoming aware of a personal-data breach affecting Customer Personal Data. The notification will describe the nature of the breach (including categories and approximate number of Data Subjects and records affected), the likely consequences, and the measures taken or proposed to address the breach and mitigate its adverse effects.

8. International transfers

Customer Personal Data is stored and processed in the European Union (AWS eu-central-1, Frankfurt). Where processing involves a transfer of Customer Personal Data to a third country that is not covered by an adequacy decision, the parties agree that:

Where sub-processors transfer data to third countries, SmartHire relies on the sub-processor's own SCC-based transfer mechanism or an adequacy decision. See /subprocessors/ for details per vendor.

9. Deletion and return

On termination of the Main Agreement, SmartHire will, at the Customer's choice, delete or return all Customer Personal Data. SmartHire makes an export of Customer Personal Data available for 30 days after termination. After that period, SmartHire will delete all Customer Personal Data from live systems within a further 30 days, and from backups on the next full backup cycle (typically within 35 days). SmartHire may retain Customer Personal Data to the extent required by law, provided that data is protected in accordance with this DPA for as long as it is retained.

10. Audit and inspection

SmartHire will make available to the Customer all information necessary to demonstrate compliance with this DPA. On written request, and no more than once per year (or more frequently if required by a supervisory authority or following a personal-data breach), SmartHire will contribute to a reasonable audit conducted by the Customer or an independent auditor mandated by the Customer.

11. Liability

The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Main Agreement, except where such limitation is not permitted by law with respect to Data Subject claims under Article 82 GDPR.

12. Governing law

This DPA is governed by the law that governs the Main Agreement. Where the SCCs apply to a transfer, Clause 17 of the SCCs (as described in Section 8) governs that portion of the processing.

13. Order of precedence

In the event of a conflict between this DPA, the Main Agreement, and the SCCs, the following order of precedence applies (highest first): the SCCs (for transfers only) → this DPA → the Main Agreement.

14. Contact

For all DPA-related matters, including requests for a signed copy, sub-processor notifications, audit requests, and breach notifications, contact legal@smarthire.chat. Data Subject rights requests should be routed to privacy@smarthire.chat.

15. Effective date and signature

This DPA takes effect on 2026-07-20 for new customers, and on the next renewal or order form for existing customers, unless expressly agreed earlier. Customer's continued use of the service constitutes acceptance.

SmartHire (Processor)

Signed on behalf of HRD:

 

Name & title

 

Date

Customer (Controller)

Signed on behalf of the Customer:

 

Name & title

 

Date