HireForge

Data Processing Addendum

Last updated: July 28, 2026

This Data Processing Addendum (“DPA”) forms part of the HireForge Terms of Service or other agreement between HireForge and a business customer (“Customer”). It applies automatically when HireForge processes personal data on Customer’s behalf, including candidate, employee, applicant, or coaching-client data. Capitalized terms not defined here have the meaning in the agreement.

1. Scope and roles

Customer is the controller or business, and HireForge is the processor or service provider, for Customer Personal Data. Each party will comply with applicable data-protection law. Customer’s use of the Service and configured features are documented processing instructions.

Customer determines the lawfulness, purpose, means, data minimization, notices, permissions, and retention period for Customer Personal Data. HireForge will process it only on documented instructions, to provide and secure the Service, or as required by law. If law requires processing outside Customer’s instructions, HireForge will notify Customer unless prohibited.

2. Processing details

Subject matter and purpose: providing AI-assisted resume, coaching, hiring-evidence, interview-analysis, storage, support, security, and billing administration. Duration: the agreement term plus the limited deletion and backup period described below.

Data subjects may include applicants, candidates, employees, contractors, coaching clients, Customer users, and people identified in submitted materials. Data may include identifiers, contact details, professional and education history, resume content, interview notes, role criteria, evidence excerpts, reviewer notes, generated inferences, technical data, and other information Customer chooses to submit.

Customer will not submit special-category data, government identifiers, medical data, background reports, or criminal-history data unless the parties authorize it in writing and implement legally required safeguards.

3. Confidentiality and security

HireForge ensures that people authorized to process Customer Personal Data are bound by confidentiality and receive appropriate security and privacy instructions. HireForge maintains reasonable administrative, technical, and organizational measures appropriate to risk.

  • Encrypted network transport and managed encryption at rest where supported by the hosting provider.
  • Authentication, least-privilege service access, row-level database policies, and production secrets controls.
  • Logging, vulnerability and dependency management, backups, recovery procedures, and incident-response processes.
  • Data minimization and production AI processing that fails closed unless Zero Data Retention has been confirmed for the xAI account.

4. Subprocessors

Customer authorizes HireForge to use subprocessors needed to provide the Service. Core categories currently include Supabase for authentication and database services, xAI for AI inference, Helcim for payment processing, email delivery providers, infrastructure and monitoring providers, and job-content retrieval services.

HireForge will impose data-protection duties materially consistent with this DPA and remains responsible for subprocessors to the extent required by law. Customer may request the current subprocessor list at support@ithubs.org. We will provide reasonable advance notice of a material new subprocessor where required. Customer may object on reasonable data-protection grounds; the parties will work in good faith on a commercially reasonable solution, which may include stopping the affected feature.

5. Data-subject requests and compliance assistance

Taking into account the nature of processing, HireForge will reasonably assist Customer with verified access, correction, deletion, portability, restriction, objection, and automated-decision requests. If HireForge receives a request relating to Customer Personal Data, it will direct the requester to Customer unless law permits HireForge to respond directly.

HireForge will reasonably assist with security, breach notification, data-protection impact assessments, and regulator consultations, considering available information and the nature of the Service. Customer is responsible for employment-law notices, accommodations, bias audits, impact assessments, and decision records.

6. Personal data incidents

HireForge will notify Customer without undue delay after confirming unauthorized access to, acquisition of, or disclosure of Customer Personal Data in HireForge’s control. Notice will include available information reasonably needed for Customer’s legal obligations. HireForge’s notice is not an admission of fault or liability. Customer is responsible for notices to individuals and regulators unless law assigns that duty to HireForge.

7. Return, deletion, and retention

During the term, Customer users may delete supported saved content through the Service. On termination or a verified request, HireForge will delete or return Customer Personal Data within a reasonable period, unless law requires retention. Residual backups remain protected, are not used for other purposes, and expire under normal backup schedules.

Billing, security, consent, dispute, and transaction records may be retained independently where legally required or necessary to establish or defend claims. Customer remains responsible for retaining employment records for the period required by applicable law before directing deletion.

8. Information and audits

On reasonable written request, HireForge will provide information needed to demonstrate compliance with this DPA. If that information is insufficient, Customer may conduct one audit per year through an independent auditor bound by confidentiality, during business hours and without disrupting operations. Customer bears audit costs unless an audit identifies a material HireForge breach. The parties may use current third-party security reports or certifications to avoid duplicative audits.

9. International transfers

For transfers of EEA personal data to a country without an adequacy decision, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two, are incorporated: Customer is data exporter, HireForge is data importer, Clause 7 applies, Option 2 in Clause 9 applies with 30 days’ notice, Ireland is the Clause 17 law, and Irish courts apply under Clause 18. Annexes are completed by Sections 2, 3, and 4 of this DPA.

For UK transfers, the then-current UK International Data Transfer Addendum modifies those Clauses. For Swiss transfers, references are adapted to the Swiss FADP and the competent Swiss authority. If another valid transfer mechanism replaces these terms, that mechanism applies to the extent necessary.

10. U.S. state privacy terms

For laws including the CCPA, HireForge acts as Customer’s service provider or contractor. HireForge will not sell or share Customer Personal Data; retain, use, or disclose it outside the business purposes in the agreement; combine it with personal information received from another person except as legally permitted to provide the Service; or use it for cross-context behavioral advertising.

HireForge will notify Customer if it determines it can no longer meet applicable obligations. Customer may take reasonable steps to stop and remediate unauthorized use. The parties acknowledge that Customer provides Customer Personal Data only for the limited and specified purposes described in this DPA.

11. Order of precedence and contact

If this DPA conflicts with the agreement on processing Customer Personal Data, this DPA controls. Liability under this DPA is subject to the agreement’s liability terms except where law prohibits that limitation.

Questions, audit requests, and incident contacts should be sent to support@ithubs.org.

See also: Privacy Policy