plainhire.app

Data processing agreement

Last updated 29 September 2026

This agreement covers the candidates' personal data that [Business name, e.g. Your Name EI or PlainHire SAS] (“we”, the processor) processes for you (the customer and controller) when you use PlainHire. It meets Article 28 of the UK GDPR and the EU GDPR, and forms part of our terms of service, so there's nothing to sign. If you need a countersigned copy, email privacy@plainhire.app.

1. The processing

Subject and purposeReceiving, storing and assessing job applications against your criteria; helping you review, shortlist and correspond with candidates; keeping records of the process.
DurationWhile you use PlainHire. Candidate data is deleted automatically the number of days after each hiring process closes that you set (30 to 365; 90 by default), or earlier if you delete it or your organisation.
Data subjectsJob applicants (and anyone named in what they send, such as referees).
Personal dataContact details; CVs, cover letters and application emails; assessments and evidence; notes; decisions; correspondence; data-protection requests.
Special category dataNot sought. Common fields (such as date of birth, marital status, nationality, health) are removed before assessment, but CVs can contain it. You shouldn't ask candidates for it through PlainHire.

2. What we commit to

  1. Instructions. We process candidate data only on your documented instructions: these terms, and what you do in PlainHire. If we believe an instruction breaks data protection law, we'll tell you.
  2. Confidentiality. Everyone who can access the data is bound to keep it confidential, and access is limited to those who need it to run and support the service.
  3. Security. We maintain the measures in section 5, and review them as risks and technology change.
  4. Sub-processors. You authorise the sub-processors in section 6. We'll give at least 30 days' notice (on this page and by email to owners) before adding or replacing one. You can object on reasonable data protection grounds; if we can't address the objection, you can end the agreement and we'll refund any hiring process that is still open. Each sub-processor is bound by data protection terms at least as protective as these, and we remain responsible for them.
  5. Candidates' rights. PlainHire helps you respond: requests in candidates' replies are flagged with a deadline, each candidate's data and an explanation of the assessment can be downloaded, and candidates can be deleted in one step. If a candidate contacts us directly, we'll pass the request to you.
  6. Assistance. We'll help you with security, breach notifications, data protection impact assessments (a pre-filled template is in your account) and consultations with regulators, as far as they concern our processing.
  7. Breaches. We'll tell you without undue delay, and within 48 hours, after becoming aware of a personal data breach affecting your data, with the information we have and updates as we learn more.
  8. End of processing. Candidate data is deleted on the retention schedule you set, or when you delete it. You can download everything first. Deleted data leaves backups within 35 days. Anonymous records with no personal data (such as totals, and how assessments compared with decisions) may be kept.
  9. Demonstrating compliance. We'll provide the information you reasonably need to show we meet this agreement, and allow an audit by you or an independent auditor once a year, on 30 days' notice, at your cost, subject to confidentiality.

3. International transfers

Candidate data is stored in the EU. Some sub-processors process it in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum for UK data), with the measures in section 5. The AI models receive text with protected details and the candidate's name removed.

4. Your side

You're responsible for having a lawful basis for the processing, for the instructions you give, for telling candidates about it (we provide the wording and send them a notice), and for your hiring decisions. See section 6 of the terms.

5. Security measures

  • Encryption in transit (TLS) and at rest; uploaded documents are also encrypted with our own key before storage.
  • Each organisation's data is separated, and every request is checked against the signed-in user's organisation and role.
  • Role-based permissions inside each organisation; only owners, hiring managers and recruiters can reject or email candidates, or export data.
  • Sign-in by single-use email links or strong passwords, optional two-factor authentication, and rate limiting against guessing.
  • Uploaded files are checked by their real file type and for active content such as macros and scripts, and rejected if they contain it.
  • Append-only activity log of who did what, and when.
  • Protected details and candidates' names are removed before any model assesses an application; model providers are configured not to retain or train on prompts.
  • Daily backups of the database, in the EU; automated deletion on schedule.

6. Sub-processors

Sub-processorPurposeDataLocation
TypeSafe (Jev), via OpenRouterAssesses redacted application text against the employer's criteriaRedacted CV, cover letter and application email text; criteriaUSA (SCCs)
Anthropic (Claude), via OpenRouterReads contact details from CVs; drafts candidate emails and interview questions from the assessmentCV text (contact details); criteria outcomes and evidence quotesUSA (SCCs)
OpenRouterRoutes requests to the two models above, with prompt logging offAs above, in transitUSA (SCCs)
SupabaseDatabase and encrypted file storageAll candidate and account dataEU region
RenderApplication hostingAll data, in transit and in processingEU region
PostmarkReceiving applications and sending candidate and team emailEmails and attachmentsUSA (SCCs)

Stripe processes only your billing details, not candidate data, so it isn't a sub-processor for this agreement.

7. General

Liability under this agreement is subject to the limits in the terms, except where the law doesn't allow it. If this agreement conflicts with the terms about candidate data, this agreement wins. It is governed by the law of France.