Edgeryt Hire
  • Pricing
  • Contact
  • Support
Sign inRequest a demo
  • Pricing
  • Contact
  • Support

Legal / Data Processing Agreement

Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the agreement between Eroforze Systems Private Limited (“Processor”) and the customer organisation that uses Edgeryt Hire (“Controller”). It applies when the Processor processes personal data on behalf of the Controller. Request a signed copy at privacy@edgeryt.com. Last updated 5 October 2026.

Product-accurate draft pending external counsel review. Entity details and liability clauses may change before launch.

On this page

  1. 1. Purpose and Scope
  2. 2. Definitions
  3. 3. Roles of the Parties
  4. 4. Processing Instructions
  5. 5. Categories of Personal Data
  6. 6. Categories of Data Subjects
  7. 7. Processing Activities
  8. 8. Customer Responsibilities
  9. 9. Eroforze Systems / Edgeryt Responsibilities
  10. 10. Confidentiality
  11. 11. Security Measures
  12. 12. Subprocessors
  13. 13. International Data Transfers
  14. 14. Data Subject Requests
  15. 15. Personal Data Breach
  16. 16. Data Retention and Deletion
  17. 17. Audits and Compliance
  18. 18. Return or Deletion of Data
  19. 19. Liability
  20. 20. Term and Termination
  21. 21. Annex: Processing Details
  22. 22. Annex: Technical and Organizational Security Measures
  23. 23. Annex: Subprocessor List
  24. 24. Annex: International Transfer Mechanism

1. Purpose and Scope

This DPA governs processing of personal data that the Controller uploads to or collects through the Platform in connection with hiring and assessments. It does not cover processing where Eroforze Systems Private Limited acts as an independent controller (for example account security logs for Platform users).

2. Definitions

“Personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings in the GDPR (and UK GDPR where applicable). “Services” means Edgeryt Hire and related assessment hosting.

3. Roles of the Parties

Controller determines the purposes and means of processing candidate and hiring data. Processor processes that data only to provide the Services and on documented instructions from Controller (including configuration in the product).

4. Processing Instructions

Controller instructs Processor to process personal data to host applications, assessments, interviews, files, emails and reports as configured in the workspace. Processor will not process personal data for its own marketing. If Processor believes an instruction infringes law, it will inform Controller.

5. Categories of Personal Data

Identity and contact data; application answers; resumes and files; assessment answers and scores; device and network metadata; integrity events; optional camera/microphone/screen media and identity documents; interview metadata; and related support content — as configured by Controller.

6. Categories of Data Subjects

Candidates and applicants; interviewers and workspace members whose data appears in hiring workflows.

7. Processing Activities

Collection via apply/assess/book flows; storage in database and object storage; scoring and optional AI grading; proctoring evidence storage; email delivery; retention enforcement; export and erasure tools; meeting scheduling via connected providers.

8. Customer Responsibilities

Controller warrants it has a lawful basis, provides notices to candidates, configures retention appropriately, and does not instruct Processor to process data unlawfully (including unlawful biometric monitoring).

9. Eroforze Systems / Edgeryt Responsibilities

Processor will process only on instructions; ensure confidentiality of authorised persons; implement security measures in Annex II; assist with data subject requests, DPIAs and breaches as reasonably required; and delete or return data per §18.

10. Confidentiality

Personnel authorised to process personal data are bound by confidentiality obligations.

11. Security Measures

See Annex: Technical and Organizational Security Measures below and the Trust Center.

12. Subprocessors

Controller authorises the subprocessors listed at /legal/subprocessors (Annex III). Processor will impose data protection terms on subprocessors and remain responsible for their performance. Material additions will be reflected on that list; Controller may object on reasonable data-protection grounds as agreed in a signed DPA.

13. International Data Transfers

See Annex: International Transfer Mechanism.

14. Data Subject Requests

Processor will, taking into account the nature of processing, assist Controller by providing product tools (lookup, export, erase) and reasonable cooperation so Controller can respond to data subject requests.

15. Personal Data Breach

Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller personal data, with information reasonably available to assist Controller with its notification duties.

16. Data Retention and Deletion

Processor deletes or anonymises candidate data according to retention rules Controller configures and product defaults for assessment media, plus nightly enforcement jobs.

17. Audits and Compliance

Upon reasonable written request, Processor will make available information necessary to demonstrate compliance with this DPA. On-site audits require reasonable notice, confidentiality and are limited to once per year unless a breach or regulator requires more.

18. Return or Deletion of Data

Upon termination of Services, Controller may export data using product tools while the account remains accessible. Thereafter Processor will delete or anonymise Controller personal data from active systems within a reasonable period, except where law requires retention or data is archived in encrypted backups until rotated.

19. Liability

Liability under this DPA is subject to the limitations in the Terms of Use, except where prohibited by applicable data protection law.

20. Term and Termination

This DPA lasts as long as Processor processes personal data for Controller under the Services.

21. Annex: Processing Details

  • Subject matter: hosting hiring and assessment workflows.
  • Duration: term of the subscription / account plus deletion period.
  • Nature/purpose: provide Services described in product documentation.
  • Data/subjects: as in §§5–6.

22. Annex: Technical and Organizational Security Measures

  • TLS encryption in transit; access control via authenticated sessions and role checks.
  • Integration OAuth tokens encrypted at rest with a dedicated key.
  • Object storage for files with signed/proxied access; database stores keys only.
  • Rate limiting on sensitive actions; optional malware scanning of uploads.
  • Two-factor authentication available for workspace users.
  • Nightly retention enforcement and admin export/erase tools.

23. Annex: Subprocessor List

The live list is published at /legal/subprocessors. Current entries:

  • Convex, Inc. (active) — Application database and serverless backend
  • Cloudflare, Inc. (R2) (active) — Object storage for files and assessment media
  • Cloudflare, Inc. (edge hosting / Workers) (optional) — Optional edge hosting and request geo for Assess / Hire
  • Vercel Inc. (optional) — Optional Hire app hosting
  • Resend (active) — Transactional email delivery
  • Razorpay (active) — Subscription billing and payment processing
  • Google LLC (Sign-in) (optional) — Optional OAuth sign-in for workspace users
  • Google LLC (Calendar / Meet) (optional) — Interview scheduling and Meet links when connected
  • Microsoft Corporation (optional) — Teams / Graph meeting scheduling when connected
  • Zoom Video Communications, Inc. (gated) — Zoom meeting scheduling when Marketplace app is live and connected
  • OpenAI (optional) — Optional LLM for question generation and AI grading
  • Google LLC (Gemini API) (optional) — Optional LLM for question generation and AI grading
  • DeepSeek (optional) — Optional LLM for question generation and AI grading
  • Code execution sandbox (customer-configured host) (optional) — Runs candidate coding submissions for automated tests
  • Upload malware scanner (customer-configured host) (optional) — Optional scan of assessment file uploads

24. Annex: International Transfer Mechanism

Where personal data is transferred from the EEA/UK to a country without an adequacy decision, the parties will rely on Standard Contractual Clauses (and UK addendum where required) or another lawful mechanism agreed in a signed DPA. Until countersigned, Controller should contact privacy@edgeryt.com to complete transfer documentation.

All legal documents · Privacy Policy · Terms of Use · Candidate Assessment Terms · Cookie Policy · Support

Edgeryt Hire

Select the best in a million.

High-quality. High-quantity. Hiring at scale.

Product

  • Pricing
  • Hiring platform
  • Assessment platform

Company

  • Contact
  • Support
  • Sales

Legal

  • Legal overview
  • Privacy Policy
  • Terms of Use
  • Candidate Assessment Terms
  • Cookie Policy
  • AI & Automated Decision-Making
  • Data Processing Agreement
  • Subprocessor List
  • Security / Trust Center

© 2026 Edgeryt. All rights reserved.