Data Processing Agreement

Effective Date

Sep 30, 2026

Version 1.3 WireApps Limited, Sri Lanka

In Short

  • You're the Controller, HireVia AI is the Processor for candidate and user personal data.

  • We process your data for CV parsing, candidate matching, screening recommendations against a JD, and interview analysis; we keep it confidential and secure it (TLS 1.2+ in transit, AES-256 at rest, least privilege).

  • Five subprocessors on file (AWS, Anthropic, OpenAI, Resend, Microsoft), each under its own DPA; 14 days' notice before adding new ones, with a right to object.

  • No candidate data — identifiable or anonymised — is used to train or improve AI models.

  • Confirmed breaches are reported without undue delay, and we help you meet the 72-hour GDPR notification window.

  • Active data is retained for as long as your account remains active and deleted on request; post-termination data is deleted within 90 days. You can audit compliance annually.

  1. What We Process

Element

Details

Data Subjects

Job candidates, hiring managers, interviewers, Authorised Users

Personal Data

Names, contact details, employment history, education, skills, CV content, assessment responses, interview records, AI-generated outputs (match scores, screening recommendations, interview analysis results)

Purpose

CV parsing, candidate matching, screening recommendations against a JD, and interview analysis

Duration

Term of the Agreement + 90-day post-termination deletion period

  1. Our Obligations

  • Process Personal Data for the purpose of CV parsing, candidate matching, screening recommendations against a JD, and interview analysis

  • Ensure staff with access are bound by confidentiality

  • Maintain appropriate technical and organisational security measures (§5)

  • Assist with Data Subject rights requests

  • Assist with DPIAs where required

  • Delete or return all Personal Data on termination (§7)

  • Not use Personal Data for any purpose beyond providing the Services

  1. Your Obligations

  • Ensure a lawful basis exists for all processing

  • Provide candidates with appropriate privacy notices

  • Obtain necessary consents before uploading candidate data

  • Do not upload special category data (health, biometric, political) unless expressly authorised in writing by HireVia AI

  1. Subprocessors

Element

Purpose

Location

Safeguard

AWS

Infrastructure & storage

Singapore

SCCs / AWS DPA

Anthropic

AI processing (primary)

United States

SCCs / Anthropic DPA

OpenAI

AI processing (secondary/legacy)

United States

SCCs / OpenAI DPA

Resend

Email delivery

United States

SCCs

Microsoft

Calendar integration

United States

SCCs / MS DPA

Element

Purpose

Location

Safeguard

AWS

Infrastructure & storage

Singapore

SCCs / AWS DPA

Anthropic

AI processing (primary)

United States

SCCs / Anthropic DPA

OpenAI

AI processing (secondary/legacy)

United States

SCCs / OpenAI DPA

Resend

Email delivery

United States

SCCs

Microsoft

Calendar integration

United States

SCCs / MS DPA

Each subprocessor is bound by its own data processing agreement (all five executed and on file). Current list available on request. Change notification and objection rights per §5.7 of the Agreement (14 days' notice, right to object, terminate if unresolved).

  1. 5. Security

  • Encryption: TLS 1.2+ in transit, AES-256 at rest

  • Access: role-based controls, least privilege

  • Network: AWS WAF, private subnets, security group isolation

  • Monitoring: CloudWatch, application logging (no PII in logs)

  • Vulnerability management: Dependabot, dependency updates, container scanning

  • Incident response: documented procedure with triage, containment, recovery, and post-incident review

  1. AI Processing

HireVia AI does not use candidate Personal Data — identifiable or anonymised/aggregated — to train, fine-tune, or otherwise improve AI models. AI processing is performed by the subprocessors listed in §4, per the primary/secondary designation there.

HireVia AI does not use candidate Personal Data — identifiable or anonymised/aggregated — to train, fine-tune, or otherwise improve AI models. AI processing is performed by the subprocessors listed in §4, per the primary/secondary designation there.

  1. Breach Notification

We will notify you of a confirmed Personal Data breach without undue delay, including:

  • Nature of the breach and approximate records affected

  • Likely consequences and measures taken to mitigate

We will cooperate to help you meet your 72-hour GDPR notification obligation to Supervisory Authorities.

We will notify you of a confirmed Personal Data breach without undue delay, including:

  • Nature of the breach and approximate records affected

  • Likely consequences and measures taken to mitigate

We will cooperate to help you meet your 72-hour GDPR notification obligation to Supervisory Authorities.

  1. Retention & Deletion

Data

Retention

Deletion

Active candidate data (including AI-generated outputs — match scores, screening recommendations, interview analysis)

For as long as your account remains active

Deleted manually on request

Post-termination

30-day export window

Deleted within 90 days after

Data

Retention

Deletion

Active candidate data (including AI-generated outputs — match scores, screening recommendations, interview analysis)

For as long as your account remains active

Deleted manually on request

Post-termination

30-day export window

Deleted within 90 days after

Written deletion confirmation provided on request. Longer retention only where required by law.

  1. International Transfers

Primary storage: AWS Singapore (ap-southeast-1). AI processing via Anthropic and OpenAI (US). Emails via Resend (US). Calendar via Microsoft (US).

Safeguards for cross-border transfers:

  • EU/EEA transfers: Standard Contractual Clauses (Module 2: Controller to Processor)

  • UK transfers: UK IDTA or UK Addendum to EU SCCs

  • Supplementary measures: encryption in transit and at rest, access controls

Primary storage: AWS Singapore (ap-southeast-1). AI processing via Anthropic and OpenAI (US). Emails via Resend (US). Calendar via Microsoft (US).

Safeguards for cross-border transfers:

  • EU/EEA transfers: Standard Contractual Clauses (Module 2: Controller to Processor)

  • UK transfers: UK IDTA or UK Addendum to EU SCCs

  • Supplementary measures: encryption in transit and at rest, access controls

  1. Audits

You may audit our compliance with this DPA once per year with 30 days' written notice. We may satisfy audit requests by providing our ISO 27001 certificate (certification in progress), a security questionnaire, or equivalent evidence. On-site audits available if alternative evidence is insufficient.

You may audit our compliance with this DPA once per year with 30 days' written notice. We may satisfy audit requests by providing our ISO 27001 certificate (certification in progress), a security questionnaire, or equivalent evidence. On-site audits available if alternative evidence is insufficient.

  1. Sri Lanka PDPA

HireVia AI is operated by WireApps Limited, registered in Sri Lanka. The Personal Data Protection Act No. 9 of 2022 (PDPA) applies to our processing of personal data. We are working to comply with the PDPA obligations applicable to our role as processor, alongside the GDPR/UK GDPR safeguards described in this DPA. Where the PDPA imposes requirements additional to those safeguards, those requirements apply.

HireVia AI is operated by WireApps Limited, registered in Sri Lanka. The Personal Data Protection Act No. 9 of 2022 (PDPA) applies to our processing of personal data. We are working to comply with the PDPA obligations applicable to our role as processor, alongside the GDPR/UK GDPR safeguards described in this DPA. Where the PDPA imposes requirements additional to those safeguards, those requirements apply.

  1. Liability & Governing Law

Data protection liability cap per ToS §12. Governing law follows the Agreement (§15, tiered by Customer jurisdiction). Mandatory local data protection law applies regardless.

Data protection liability cap per ToS §12. Governing law follows the Agreement (§15, tiered by Customer jurisdiction). Mandatory local data protection law applies regardless.

  1. Term

This DPA is effective from the Agreement date until all Personal Data is deleted. Breach notification, deletion, and audit obligations survive termination.

By executing the Agreement, both parties agree to be bound by this Data Processing Agreement.

This DPA is effective from the Agreement date until all Personal Data is deleted. Breach notification, deletion, and audit obligations survive termination.

By executing the Agreement, both parties agree to be bound by this Data Processing Agreement.

AI-native hiring for teams tired of spreadsheets, inboxes, and 45 minutes of manual work per CV. Upload a candidate and HireVia AI parses, scores, and ranks them in seconds.

© 2026 WireApps Limited · Built in Sri Lanka, hosted in Singapore