Skip to main content
Hirify is built with GDPR by design. All candidate data stays within a controlled HR perimeter — no copy-pasting CVs into public AI tools, no data leaving France without GDPR-governed safeguards. Whether you’re a recruitment agency processing hundreds of candidate profiles per month or an internal HR team managing sensitive applications, Hirify gives you the structure to stay compliant without slowing down your workflow.

Your Obligations as a Recruiter

As the data controller, you remain responsible for how candidate data is collected and used. Hirify acts as your data processor — it handles data only on your instructions and within the boundaries you set.
You must inform candidates before recording an interview. This is a legal requirement under GDPR Article 13. Use language such as:“This interview will be recorded and processed by Hirify’s AI to enrich your candidate profile. You have the right to object to this processing at any time.”Do not begin a recorded session without explicit acknowledgement from the candidate.

Lawful Basis for Processing

You need a valid lawful basis to process candidate data under GDPR Article 6. In a recruitment context, the two most common bases are:
  • Legitimate interest — where processing is necessary to evaluate a candidate for a specific role and the candidate reasonably expects it (e.g., a structured interview as part of an active application).
  • Consent — where you proactively collect and store candidate data beyond the immediate application process, such as adding them to a talent pool for future opportunities.
Document your chosen lawful basis and ensure your privacy policy reflects how Hirify is used in your recruitment process.

Candidate Rights

Candidates whose data is held in Hirify have the following rights under GDPR:
  • Right of access — to receive a copy of all data Hirify holds about them
  • Right to rectification — to correct inaccurate or incomplete data
  • Right to erasure — to have their data permanently deleted
To exercise any of these rights, candidates or their representatives should contact rgpd@hirify.fr. Hirify’s team will coordinate with you to fulfil requests within the statutory 30-day window.

How Hirify Protects Candidate Data

Hirify’s architecture is designed to minimise risk and give you full visibility over how candidate data is handled:
  • Data hosted exclusively in France — all data is stored on Scalingo infrastructure in Paris, certified to ISO 27001.
  • No data shared with public AI services — candidate transcripts and profiles are never sent to general-purpose consumer AI tools.
  • AI analysis performed by EU-governed processors — language model processing is handled by Mistral (France); audio transcription by Gladia (France).
  • Every enriched field is traceable to its source — each data point in a candidate profile links back to the interview segment that generated it, giving you a clear audit trail.
  • Humans decide — Hirify surfaces structured information and insights, but no automated decision with legal or significant effect is made about a candidate without recruiter review.

Data Retention

You control how long candidate data is retained in Hirify. There is no fixed system-wide expiry — retention periods reflect your organisation’s own data minimisation obligations under GDPR. Configure retention periods in Settings > Data & Privacy. You can set per-pipeline or per-template retention rules, and candidates can be anonymised or fully deleted at any time from their profile page.
As a best practice, define retention periods that align with the duration of your active recruitment cycles. For talent pool contacts, ensure you have a clear consent mechanism and a re-engagement process before data ages out.

Data Processing Agreement

A Data Processing Agreement (DPA) formalises the controller–processor relationship between your organisation and Hirify and is required under GDPR Article 28.
  • Volume plan customers receive a full, countersigned DPA as part of onboarding.
  • Starter and Hub plan customers can request a standard DPA by contacting rgpd@hirify.fr.
Contact rgpd@hirify.fr for any data subject access requests, erasure requests, DPA inquiries, or questions about Hirify’s role as a data processor under your organisation’s GDPR obligations.