Data Processing Agreement

Last updated: April 2026 · GDPR Article 28 compliant

1. Parties

This Data Processing Agreement ("DPA") governs data processing between Hirelytic ("Processor") and you, the User ("Controller"). By using our service, you agree to the terms below. For enterprise or team accounts requiring a signed DPA, contact our support team.

2. Scope & Purpose

Hirelytic processes the personal data you submit (email, CV contents, job descriptions) solely to provide the CV optimization service. We do not use your CV content to train AI models. We do not sell data to third parties.

3. Data Categories Processed

  • Identifiers: Email address (for authentication)
  • CV content: Uploaded resume text (retained 30 days maximum)
  • Job descriptions: Optional context you provide
  • Technical data: Hashed IP (SHA-256 with salt) for fraud prevention — raw IP never stored
  • Usage metadata: Timestamps, analysis counts

4. Sub-Processors

We use these data sub-processors:

  • Abacus.AI (US) — LLM inference for CV rewriting. No persistence of user CV content.
  • Abacus.AI Postgres (US) — encrypted database hosting.
  • AWS S3 (US-West-2) — encrypted file storage with 30-day lifecycle.

5. Security Measures

  • TLS 1.2+ in transit
  • Encryption at rest for all data stores
  • IP hashing with server-side salt (SHA-256)
  • JWT-based session tokens (HTTP-only cookies)
  • Access controls: only authorized personnel can access aggregated metadata
  • No engineer or admin can read user CV content in plaintext via any dashboard

6. Data Retention

  • CV analyses: 30 days after creation (automatic deletion)
  • Account email: Until account deletion request
  • Hashed IPs: 180 days for fraud signals, then purged

7. Your Rights (GDPR Articles 15–22)

  • Access: Export all your data via Dashboard → Privacy → Export
  • Rectification: Update your email/account via Dashboard
  • Erasure: Delete your account via Dashboard → Privacy → Delete
  • Restriction / Portability / Objection: Contact support
  • Complaint: You may lodge a complaint with your local supervisory authority

8. Breach Notification

In the event of a personal data breach, we will notify affected users within 72 hours as required by GDPR Article 33.

9. International Transfers

Our sub-processors are located in the US. Transfers rely on Standard Contractual Clauses (SCCs) where applicable.

10. Contact

Privacy requests or DPA inquiries: use the GDPR tools in your Dashboard. For urgent legal matters, these are routed to our operations team.