Need a signed copy? This page is the current published DPA. If your legal or procurement team needs a countersigned PDF for their vendor-review file, email legal@smarthire.chat with your company name and we will send one within 3 business days.
1. Definitions
Capitalized terms used in this DPA have the meaning given below. Terms not defined here take their meaning from the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) or applicable data-protection legislation in the customer's jurisdiction.
- “Customer” means the entity that has entered into an agreement with SmartHire for the use of the SmartHire service and that acts as the Controller of Customer Personal Data.
- “SmartHire” or “Processor” means the entity providing the SmartHire service (HRD).
- “Customer Personal Data” means personal data submitted to, or generated by, the SmartHire service on behalf of the Customer.
- “Data Subjects” means the individuals to whom Customer Personal Data relates — typically candidates interacting with the Customer via WhatsApp, plus Customer's own account users.
- “Sub-processor” means any third party engaged by SmartHire to process Customer Personal Data.
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses adopted by the European Commission on 4 June 2021 (Commission Implementing Decision (EU) 2021/914), Module 2.
2. Roles
With respect to Customer Personal Data, the Customer is the Controller and SmartHire is the Processor. Each party will comply with its own obligations under applicable data-protection legislation.
3. Subject matter and duration
Subject matter: the processing of Customer Personal Data by SmartHire strictly for the purpose of providing the SmartHire service to the Customer under the parties' underlying subscription agreement (the “Main Agreement”).
Duration: this DPA takes effect on the date the Customer accepts SmartHire's Terms of Service (or the date of a signed order form, if later) and remains in effect for as long as SmartHire processes Customer Personal Data, plus any post-termination retention period described in Section 9.
4. Nature and purpose of processing
SmartHire processes Customer Personal Data to:
- Deliver inbound and outbound WhatsApp messages between candidates and the Customer's screening bot.
- Run automated screening conversations, extract structured data, score candidates against Customer-defined criteria, and produce recommendations.
- Transcribe candidate voice notes to text.
- Schedule interviews, send calendar invitations, and sync with Customer's calendar and ATS.
- Provide the Customer's account users (recruiters, admins, hiring managers, interviewers) with dashboards and reports.
- Detect and respond to security events, prevent abuse, and maintain the integrity of the service.
5. Categories of personal data
- Candidate identifiers (WhatsApp phone number, display name).
- CV and resume content (text, uploaded documents).
- WhatsApp message content (text, media, buttons, list selections).
- Voice-note audio and its text transcript.
- Screening answers (experience, availability, location, salary expectations, etc.).
- Interview scheduling data (proposed slots, confirmations, calendar metadata).
- Application status, scoring, recruiter and hiring-manager decisions.
- Customer account user data (name, work email, role, authentication events).
Customer will not submit sensitive or special-category data (as defined in GDPR Art. 9) unless it has notified SmartHire in advance and has a documented lawful basis.
6. Categories of data subjects
- Candidates and prospective candidates who contact the Customer via WhatsApp using a SmartHire-managed number.
- Customer's own personnel with access to the SmartHire dashboard.
7. SmartHire obligations as Processor
7.1 Documented instructions only
SmartHire will process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country. The Customer's use of the service's features and configuration constitutes such instructions. If SmartHire is required by Union or Member State law to process Customer Personal Data other than on Customer's instructions, SmartHire will inform the Customer before processing, unless that law prohibits notification.
7.2 Confidentiality
SmartHire will ensure that personnel authorized to process Customer Personal Data are bound by contractual or statutory duties of confidentiality.
7.3 Security
SmartHire will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. A summary of current measures is published at /trust/ and forms part of this DPA. Measures include encryption at rest and in transit, tenant isolation, role-based access controls, MFA availability, audit logging, and an incident-response playbook.
7.4 Sub-processor engagement
Customer grants SmartHire general authorization to engage the sub-processors listed at /subprocessors/. SmartHire will:
- Give Customer at least 30 days' prior written notice of any new sub-processor.
- Impose on each sub-processor written obligations that are, in substance, no less protective than those in this DPA.
- Remain fully liable to Customer for the performance of each sub-processor's obligations.
- Allow Customer to object to a new sub-processor on reasonable data-protection grounds during the notice period. If SmartHire cannot accommodate the objection, the Customer may terminate the affected scope of service and receive a pro-rata refund for any prepaid, unused fees.
7.5 Assistance with data-subject rights
Taking into account the nature of the processing, SmartHire will assist the Customer with appropriate technical and organizational measures, insofar as possible, in responding to requests from Data Subjects exercising their rights under GDPR (access, rectification, erasure, restriction, portability, objection). Where a Data Subject contacts SmartHire directly regarding Customer Personal Data, SmartHire will promptly forward the request to the Customer.
7.6 Assistance with DPIAs and consultation
SmartHire will provide reasonable assistance to the Customer in carrying out data-protection impact assessments (Art. 35) and consulting with supervisory authorities (Art. 36), taking into account the nature of processing and the information available to SmartHire.
7.7 Breach notification
SmartHire will notify the Customer without undue delay and no later than 72 hours after becoming aware of a personal-data breach affecting Customer Personal Data. The notification will describe the nature of the breach (including categories and approximate number of Data Subjects and records affected), the likely consequences, and the measures taken or proposed to address the breach and mitigate its adverse effects.
8. International transfers
Customer Personal Data is stored and processed in the European Union (AWS eu-central-1,
Frankfurt). Where processing involves a transfer of Customer Personal Data to a third country that
is not covered by an adequacy decision, the parties agree that:
- The Standard Contractual Clauses, Module 2 (Controller-to-Processor), are incorporated into this DPA by reference.
- For the purpose of Clause 7 of the SCCs (docking), the parties agree that new parties may accede to this DPA on the same terms.
- For the purpose of Clause 9 of the SCCs, Option 2 (general written authorization) applies, with the 30-day notice period specified in Section 7.4.
- For the purpose of Clause 11 of the SCCs, the optional independent-dispute-resolution language is not adopted.
- For the purpose of Clause 17 (governing law) and Clause 18 (choice of forum), the SCCs are governed by the law of Ireland and disputes go to the courts of Ireland, without prejudice to Data Subjects' rights to bring proceedings in their Member State of habitual residence.
Where sub-processors transfer data to third countries, SmartHire relies on the sub-processor's own SCC-based transfer mechanism or an adequacy decision. See /subprocessors/ for details per vendor.
9. Deletion and return
On termination of the Main Agreement, SmartHire will, at the Customer's choice, delete or return all Customer Personal Data. SmartHire makes an export of Customer Personal Data available for 30 days after termination. After that period, SmartHire will delete all Customer Personal Data from live systems within a further 30 days, and from backups on the next full backup cycle (typically within 35 days). SmartHire may retain Customer Personal Data to the extent required by law, provided that data is protected in accordance with this DPA for as long as it is retained.
10. Audit and inspection
SmartHire will make available to the Customer all information necessary to demonstrate compliance with this DPA. On written request, and no more than once per year (or more frequently if required by a supervisory authority or following a personal-data breach), SmartHire will contribute to a reasonable audit conducted by the Customer or an independent auditor mandated by the Customer.
- Audits will be scheduled at least 30 days in advance, conducted during normal business hours, and carried out in a way that does not disrupt SmartHire's operations.
- Auditors must sign a non-disclosure agreement in a form reasonably acceptable to SmartHire.
- Audits are conducted at the Customer's cost, except where the audit reveals material non-compliance by SmartHire, in which case SmartHire will bear reasonable audit fees.
- SmartHire may satisfy audit requests by providing recent third-party audit reports or attestations of its sub-processors (e.g. AWS SOC 2 reports) where those cover the relevant controls.
11. Liability
The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Main Agreement, except where such limitation is not permitted by law with respect to Data Subject claims under Article 82 GDPR.
12. Governing law
This DPA is governed by the law that governs the Main Agreement. Where the SCCs apply to a transfer, Clause 17 of the SCCs (as described in Section 8) governs that portion of the processing.
13. Order of precedence
In the event of a conflict between this DPA, the Main Agreement, and the SCCs, the following order of precedence applies (highest first): the SCCs (for transfers only) → this DPA → the Main Agreement.
14. Contact
For all DPA-related matters, including requests for a signed copy, sub-processor notifications, audit requests, and breach notifications, contact legal@smarthire.chat. Data Subject rights requests should be routed to privacy@smarthire.chat.
15. Effective date and signature
This DPA takes effect on 2026-07-20 for new customers, and on the next renewal or order form for existing customers, unless expressly agreed earlier. Customer's continued use of the service constitutes acceptance.
SmartHire (Processor)
Signed on behalf of HRD:
Name & title
Date
Customer (Controller)
Signed on behalf of the Customer:
Name & title
Date
- 2026-07-20 Initial published version.