Data Processing Agreement
How SynergicHire handles the personal data our customers entrust to us, above all their candidates’, as their processor. It covers the GDPR, the UK GDPR and the other data protection laws in section 2, and includes the Standard Contractual Clauses for transfers.
1. Parties and scope
This Data Processing Agreement (“DPA”) is between MiaRay Ventures Private Limited (“SynergicHire”, “we”) and the customer that holds a SynergicHire workspace (“Customer”). It forms part of the Terms of Service and applies whenever we process Customer Personal Data in providing the service. It takes effect when the Customer accepts the Terms, with no signature needed; a Customer that wants a countersigned copy can ask at synergichire@raymish.com.
If this DPA and the Terms conflict on the processing of personal data, this DPA wins. If this DPA and the Standard Contractual Clauses conflict, the Clauses win.
2. Definitions
- Data Protection Law: every law on personal data that applies to the processing, including the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, India’s Digital Personal Data Protection Act 2023 (“DPDP Act”), and US state privacy laws such as the California Consumer Privacy Act.
- Customer Personal Data: personal data we process on the Customer’s behalf in providing the service, chiefly about its candidates, applicants and team members.
- Controller, processor, data subject, processing and personal data breach mean what the GDPR says they mean. Under the DPDP Act, “controller” means Data Fiduciary and “processor” means Data Processor; under US state laws, “controller” includes “business” and “processor” includes “service provider”.
- Standard Contractual Clauses or SCCs: the clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
- Subprocessor: a third party we engage that processes Customer Personal Data.
3. Roles and instructions
The Customer is the controller of Customer Personal Data and we are its processor. Where the Customer is itself a processor for someone else, we are its subprocessor, and the Customer confirms that its own controller has authorised this DPA.
We process Customer Personal Data only on the Customer’s documented instructions. Those instructions are the Terms, this DPA, and how the Customer’s team configures and uses the service: the roles and screening plans it approves, the candidates it invites, whether voice is offered and audio kept, the proctoring level, the retention period, and deletions it asks for. We tell the Customer if we think an instruction breaks Data Protection Law, unless the law forbids us to.
We do not sell Customer Personal Data, share it for advertising, use it for any purpose of our own, combine it with data from other customers, or use it, or let our AI providers use it, to train AI models.
4. The Customer's responsibilities
- Having a lawful basis for the processing, and giving candidates and team members the notices that Data Protection Law and employment law require. The service shows candidates an AI notice and asks for their consent before an application, a screen or a round begins; the Customer remains responsible for its content being enough where it hires.
- Making hiring decisions through a person, as the service requires, and meeting obligations that fall on it as an employer or deployer of AI, such as bias audits and notices under New York City Local Law 144, the Illinois Artificial Intelligence Video Interview Act, and the EU AI Act.
- Answering requests from its candidates and team members about their data, with our help (section 9).
- Not asking candidates for special categories of personal data (such as health, religion or ethnicity) that the role does not need.
5. Our people
Only people who need access to provide, secure or support the service have it, each bound by confidentiality. Access to a workspace’s data by the people who run SynergicHire is limited to named platform administrators and is recorded in an audit log.
6. Subprocessors
The Customer authorises us to use the subprocessors listed on our Subprocessors page, which is Annex 3. We bind each one by a written agreement to protections no weaker than this DPA’s, and remain responsible for what they do.
We give at least 30 days’ notice before a new subprocessor starts processing Customer Personal Data, by updating that page and emailing the workspace’s admins. The Customer may object in writing, on reasonable data protection grounds, within that time. We will then try in good faith to resolve the objection; if we cannot, the Customer may stop using the part of the service concerned and end the Terms for it, and we refund the unused part of any fees paid in advance for it.
7. Security
We maintain the technical and organisational measures in Annex 2, appropriate to the risk. We may improve them over time, but will not make them materially weaker.
8. Personal data breaches
We notify the Customer without undue delay, and within 48 hours, of becoming aware of a personal data breach affecting Customer Personal Data. The notice goes to the workspace’s admins by email and says, as far as we then know: what happened, the categories and rough number of people and records involved, the likely consequences, what we have done and will do about it, and who to talk to. We add what we learn as we learn it.
We take reasonable steps to contain the breach and limit its harm, and help the Customer meet its own duties to notify authorities and the people affected. Notifying the Customer is not an admission of fault.
9. Helping the Customer
Requests from data subjects. The service gives the Customer the tools to answer most requests itself: a candidate’s full record is read in one place, on their profile, and a candidate can be erased, with their profile, application, every round and every recording. Where a request needs a copy of the data in a portable form, we provide it to the Customer on request. If a request reaches us directly, we pass it to the Customer without answering it ourselves, unless the law requires us to.
Assessments and authorities. We give the Customer the information it reasonably needs for a data protection impact assessment, a consultation with an authority, or an AI Act or bias-audit obligation, including how the AI assessment works, the evidence each score cites, and the exports of selection rates and decisions the service provides.
10. International transfers
We operate from India, Customer Personal Data is stored in Japan, and some subprocessors process it in the United States (Annex 3). We transfer Customer Personal Data out of a country only as Data Protection Law allows.
Where the GDPR applies to a transfer to us or from us to a subprocessor, and no adequacy decision covers it, the SCCs apply and are incorporated into this DPA: Module 2 where the Customer is a controller, Module 3 where it is a processor. In them: Clause 7 is included; in Clause 9, option 2 applies with the notice period in section 6; the optional wording in Clause 11 is not included; in Clause 13, the supervisory authority is the one competent for the Customer; in Clauses 17 and 18, the law and courts are those of Ireland. Annexes I to III of the SCCs are filled in by Annexes 1 to 3 of this DPA.
For transfers from the UK, the International Data Transfer Addendum issued by the UK Information Commissioner applies to the SCCs, with either party able to end it as its section 19 allows. For transfers from Switzerland, the SCCs apply with references to the GDPR read as the Swiss Act, and the Swiss Federal Data Protection and Information Commissioner as the competent authority.
11. Retention, return and deletion
While the Terms are in force, the Customer controls how long Customer Personal Data is kept: its retention period erases recordings and declined applications automatically, and it can erase a candidate at any time.
When the Terms end, the Customer can use the service’s exports, and ask us for a copy of other Customer Personal Data, before its workspace is closed. Within 30 days of the workspace being deleted, we delete Customer Personal Data, unless a law requires us to keep some of it, in which case we keep only that, protected by this DPA, and only for as long as the law requires. Copies in backups are overwritten in their normal cycle.
One copy is outside our control: when a Customer keeps interview audio, OpenAI stores each voice session’s recording so that we can copy it, and keeps its copy for 30 days after the call. OpenAI offers no way to delete it sooner. Erasing a recording in SynergicHire removes our copy at once; OpenAI’s lapses at the end of those 30 days. With audio off, which is the default, no recording is stored.
12. Information and audits
We make available the information needed to show we meet this DPA, and answer reasonable security questionnaires. If that is not enough, or an authority requires it, the Customer may audit our compliance, itself or through an independent auditor bound by confidentiality, once in any 12 months, on at least 30 days’ written notice, during business hours, at its own cost, and without access to other customers’ data. Audits of subprocessors are met by the reports and certifications they publish.
13. Liability, term and law
Each party’s liability under this DPA is subject to the limits in the Terms, except where Data Protection Law or the SCCs do not allow a limit. This DPA lasts as long as we process Customer Personal Data. Apart from the SCCs, which are governed as section 10 says, it is governed by the same law, and disputes go to the same courts, as the Terms.
We may update this DPA to reflect changes in law or in the service, giving 30 days’ notice of a change that is material. An update will not reduce the protection Customer Personal Data has.
14. Annex 1: Description of the processing
| Data exporter | The Customer, as controller (or processor), whose contact details are those of its workspace admins. Activities: recruiting and hiring. |
| Data importer | MiaRay Ventures Private Limited, at the address in the Terms, synergichire@raymish.com, as processor. Activities: providing SynergicHire. |
| Data subjects | The Customer’s job applicants and candidates; its recruiters, interviewers and admins. |
| Categories of data | Candidates: name, email, and if given, phone, location, links and a note; resume and what is read from it; screen transcripts, drawings, code and test runs; voice transcripts, and audio if the Customer keeps it; coding-round code history, prompts and responses, accepted and dismissed completions, agent steps, runs, commands, plan and review; focus changes and pastes (unless switched off); AI assessments; notes, feedback, scorecards and decisions. Team members: work email, role, sign-in, and the actions recorded in the audit log. |
| Sensitive data | None is asked for. A resume or an answer may contain some incidentally; it is protected as all Customer Personal Data is, and access to it is limited to the Customer’s team. |
| Frequency | Continuous, while the Customer uses the service. |
| Nature and purpose | Collecting, storing, reading with AI models, displaying, exporting and erasing, to let the Customer screen, interview and assess candidates and record a person’s decision. |
| Duration | The term of the Terms, and until deletion under section 11; within that, the Customer’s retention period. |
| Subprocessors | As Annex 3, for the same nature, purpose and duration. |
15. Annex 2: Technical and organisational measures
- Encryption: TLS for all traffic; data encrypted at rest in the database and file storage.
- Separation of customers: every record belongs to one workspace, and every request is checked against the workspace of the verified signed-in user; database row-level security for access made with a user’s own token.
- Access within a workspace: roles (admin, recruiter, interviewer) that limit who can see and do what; exports and the audit log limited to the roles that need them.
- Authentication: one-time email links or a sign-in provider; no passwords stored by us. Identity comes from a verified token on every request.
- Candidates: signed invite links that work only for the address they were sent to; no personal details in any URL; consent recorded before anything starts.
- Secrets: keys for the database and AI providers held only on the server, never sent to a browser.
- Code execution: candidates’ code runs in isolated, network-restricted sandboxes, torn down when the work ends, with rate limits on how much can be started.
- Abuse prevention: rate limits shared by every server instance, keyed by a one-way hash rather than an address; bot checks on public forms.
- AI: what candidates write is treated as evidence, never as instructions to the model; screening plans and scoring stay on the server; every score must cite a record or it is not shown.
- Accountability: an audit log of sign-offs, decisions, plan approvals, evaluations, exports, deletions and administration, kept after the records it describes are erased.
- Retention and erasure: a configurable retention period, erasure on request, and deletion of a workspace’s files when the workspace is deleted.
- Resilience: managed database with backups; hosting on providers with their own security programmes and certifications.
- People: access limited to those who need it, bound by confidentiality; platform administration limited to named people and recorded.
16. Annex 3: Subprocessors
The subprocessors, what each does with Customer Personal Data and where, are listed on the Subprocessors page, which forms this Annex.