Your Obligations as a Recruiter
As the data controller, you remain responsible for how candidate data is collected and used. Hirify acts as your data processor — it handles data only on your instructions and within the boundaries you set.Lawful Basis for Processing
You need a valid lawful basis to process candidate data under GDPR Article 6. In a recruitment context, the two most common bases are:- Legitimate interest — where processing is necessary to evaluate a candidate for a specific role and the candidate reasonably expects it (e.g., a structured interview as part of an active application).
- Consent — where you proactively collect and store candidate data beyond the immediate application process, such as adding them to a talent pool for future opportunities.
Candidate Rights
Candidates whose data is held in Hirify have the following rights under GDPR:- Right of access — to receive a copy of all data Hirify holds about them
- Right to rectification — to correct inaccurate or incomplete data
- Right to erasure — to have their data permanently deleted
How Hirify Protects Candidate Data
Hirify’s architecture is designed to minimise risk and give you full visibility over how candidate data is handled:- Data hosted exclusively in France — all data is stored on Scalingo infrastructure in Paris, certified to ISO 27001.
- No data shared with public AI services — candidate transcripts and profiles are never sent to general-purpose consumer AI tools.
- AI analysis performed by EU-governed processors — language model processing is handled by Mistral (France); audio transcription by Gladia (France).
- Every enriched field is traceable to its source — each data point in a candidate profile links back to the interview segment that generated it, giving you a clear audit trail.
- Humans decide — Hirify surfaces structured information and insights, but no automated decision with legal or significant effect is made about a candidate without recruiter review.
Data Retention
You control how long candidate data is retained in Hirify. There is no fixed system-wide expiry — retention periods reflect your organisation’s own data minimisation obligations under GDPR. Configure retention periods in Settings > Data & Privacy. You can set per-pipeline or per-template retention rules, and candidates can be anonymised or fully deleted at any time from their profile page.Data Processing Agreement
A Data Processing Agreement (DPA) formalises the controller–processor relationship between your organisation and Hirify and is required under GDPR Article 28.- Volume plan customers receive a full, countersigned DPA as part of onboarding.
- Starter and Hub plan customers can request a standard DPA by contacting rgpd@hirify.fr.
Contact rgpd@hirify.fr for any data subject access requests, erasure requests, DPA inquiries, or questions about Hirify’s role as a data processor under your organisation’s GDPR obligations.