Parties, roles, and how this addendum applies
This Data Processing Addendum (“DPA”) forms part of the agreement between Itya and the customer organisation that subscribes to the Itya service (the “Agreement”). It governs Itya's processing of personal data on the customer's behalf and applies wherever the EU General Data Protection Regulation, the UK GDPR, the Swiss Federal Act on Data Protection, or a comparable law applies to that processing.
- Customer as controller. The customer determines why and how candidate, interviewer and workspace personal data is processed in Itya. The customer decides which roles are opened, which candidates are entered, which interviews are recorded, and what the retention policy is.
- Itya as processor. Itya processes that personal data only to provide, secure and support the service, and only on the customer's documented instructions.
- Itya as controller, separately. For its own account records, billing, service security, abuse prevention and product telemetry about how the service itself is used, Itya acts as a controller. That processing is described in the privacy policy, not here.
Where this DPA conflicts with the rest of the Agreement on the processing of personal data, this DPA prevails. Where an executed order form or a negotiated data-protection agreement conflicts with this DPA, that signed document prevails.
Acceptance and counter-signature
This DPA is incorporated into the Agreement automatically. A customer that subscribes to Itya and continues to use the service is bound by it, and Itya is bound to the customer, without either party needing to sign anything. Self-serve customers therefore already have a data processing agreement in place.
If your organisation needs an executed counterpart — because procurement, a data protection officer, or a supervisory authority requires one — email legal@itya.ai with your legal entity name, registered address, and the signatory's name and title. We will return a counter-signed copy of this DPA, including the Standard Contractual Clauses, with the annexes populated for your subscription.
We will also complete a reasonable security questionnaire and answer a transfer-impact-assessment request during an evaluation. Send those to security@itya.ai.
Subject matter, duration, nature and purpose
Subject matter. Provision of the Itya interview-intelligence service: scheduling and hosting interviews, capturing consented interview audio and video, producing transcripts, generating AI-assisted debriefs and scorecards for human review, and managing the resulting hiring records.
Duration. For the term of the Agreement, plus the deletion window described under “Return and deletion” below.
Nature of the processing. Collection, recording, structuring, storage, transcription, automated analysis to produce draft evaluations for human review, retrieval, transmission to systems the customer connects, restriction, erasure and destruction.
Purpose. Solely to provide, secure, monitor, support and improve the service for the customer, and to comply with law. Itya does not use customer personal data to train general-purpose AI models, does not sell it, and does not use it for advertising.
Categories of data subjects and personal data
Data subjects. Candidates and applicants; interviewers, recruiters, hiring managers and other workspace members; administrative and billing contacts of the customer; and any third party a customer's users mention inside interview content they submit.
Personal data.
- Identity and contact data: name, email address, phone number, profile photo where supplied, job title and employer.
- Application data: resumes and attachments, application answers, stage and status, recruiter notes and internal comments.
- Interview data: scheduled times and attendance, consented audio and video, transcripts, speaker attribution, AI-drafted debriefs and scorecards, and the reviewer edits and decisions recorded against them.
- Account and security data: authentication credentials in hashed form, two-factor enrolment, session and device records, IP address, and audit-log entries.
- Billing data: billing contact, billing address and subscription records.
Special category data. Itya is not designed to process special category data under Article 9, criminal-offence data under Article 10, or children's data. A customer must not configure the service to collect it. Because interview conversation is free-form, special category data can appear incidentally in a transcript; Itya applies the same technical and organisational measures to it and does not process it for any separate purpose.
Itya’s obligations as processor (Article 28(3))
- (a) Documented instructions. Itya processes personal data only on the customer's documented instructions, including as to international transfers. The Agreement, this DPA and the customer's use of the product's features are the complete documented instructions. If Itya is required by law to process beyond them, it will tell the customer first unless that law forbids it. Itya will tell the customer if it believes an instruction infringes data protection law.
- (b) Confidentiality. Every Itya person with access to customer personal data is bound by a written confidentiality obligation that survives the end of their engagement, and access is granted only where a role requires it.
- (c) Security. Itya implements the technical and organisational measures described under “Security measures” below, appropriate to the risk under Article 32.
- (d) Sub-processing. Itya engages sub-processors only on the terms in “Sub-processors” below, and imposes on each of them data-protection obligations no less protective than these.
- (e) Data subject rights. Itya assists the customer, by appropriate technical and organisational measures and so far as possible, in responding to requests to exercise data subject rights.
- (f) Articles 32–36. Itya assists the customer in meeting its own security, breach-notification and data-protection-impact-assessment obligations, taking into account the nature of the processing and the information available to Itya.
- (g) Return or deletion. At the end of the Agreement Itya returns or deletes customer personal data as set out under “Return and deletion” below.
- (h) Information and audits. Itya makes available the information needed to demonstrate compliance with Article 28 and allows for and contributes to audits, as set out under “Audit rights” below.
Sub-processors
The customer gives Itya a general authorisation to engage sub-processors. The current list is below and is maintained on the subprocessors page.
| Subprocessor | Purpose | Data categories | Location | Transfer mechanism |
|---|---|---|---|---|
| Oracle Cloud InfrastructureOracle Corporation | Hosting, compute, and managed block storage for the database. In the reference deployment the S3-compatible object store that holds recordings, transcripts, resumes and exports also runs on this infrastructure; a deployment that points the object-store endpoint at Amazon S3 sends those objects to AWS instead (see the AWS entry below). | All workspace, candidate and interview data at rest, including recordings, transcripts, resumes and audit records. | The OCI region configured for the deployment (EU or US). | EU SCCs (Module Three) plus the UK Addendum where the region sits outside the EEA or UK. |
| AnthropicAnthropic PBC | Large-language-model generation for AI scorecards, interview debriefs and job/rubric drafting. This is the default scoring and debrief provider. | Interview transcript excerpts, job descriptions and rubrics, and any personal data those texts contain. | United States | EU SCCs (Module Three) plus the UK Addendum. |
| OpenAIOpenAI, L.L.C. | Speech-to-text transcription of interview audio (Whisper). Also serves scorecards and debriefs where a deployment sets the scoring or debrief provider to OpenAI. | Interview audio, the transcripts produced from it, and the prompts built from transcripts and rubrics. | United States | EU SCCs (Module Three) plus the UK Addendum. |
| Microsoft Azure Communication ServicesMicrosoft Corporation | Carries real-time audio and video for the embedded Itya interview room, and streams the consented audio leg to our capture endpoint. | Interview audio and video in transit, participant display names, and call-lifecycle metadata. | The Azure region of the ACS resource configured for the deployment. | Microsoft Products and Services DPA incorporating the EU SCCs, plus the UK Addendum. |
| Amazon Web Services (SES)Amazon Web Services, Inc. | Delivery of transactional email: interview invitations, verification and password mail, notifications and data-request correspondence. | Recipient name and email address, message subject and body, and delivery/bounce events. | The SES sending region configured for the deployment. | AWS DPA incorporating the EU SCCs, plus the UK Addendum. |
| StripeStripe, Inc. / Stripe Payments Europe, Ltd. | Subscription billing, hosted checkout, the customer billing portal, invoices and receipts. | Billing contact name and email, billing address, subscription and invoice records. Card details are collected by Stripe and never reach Itya. | United States and Ireland | Stripe DPA incorporating the EU SCCs, plus the UK Addendum. |
| SlackSlack Technologies, LLC (Salesforce, Inc.)Conditional | Delivers workspace notifications to a Slack channel.Only when a workspace connects Slack and enables Slack notifications. | Notification content, which can reference candidate names, roles and interview outcomes. | United States | Salesforce DPA incorporating the EU SCCs, plus the UK Addendum. |
| ZendeskZendesk, Inc.Conditional | Mirrors support requests into a ticketing system so they can be worked and answered.Only where the deployment routes support requests to Zendesk. | Requester name and email, the message body, and the page the request came from. | The region of the configured Zendesk subdomain. | Zendesk DPA incorporating the EU SCCs, plus the UK Addendum. |
| Google WorkspaceGoogle LLCConditional | Hosts the Itya notetaker identities that join Google Meet interviews, where a deployment enables external meeting capture.Only where external Google Meet capture is enabled. The embedded Itya room does not use it. | Meeting attendance, meeting audio captured under recorded consent. | United States | Google Cloud DPA incorporating the EU SCCs, plus the UK Addendum. |
| Microsoft 365Microsoft CorporationConditional | Hosts the Itya notetaker identities that join Microsoft Teams interviews, where a deployment enables external meeting capture.Only where external Microsoft Teams capture is enabled. The embedded Itya room does not use it. | Meeting attendance, meeting audio captured under recorded consent. | The Microsoft 365 tenant region. | Microsoft Products and Services DPA incorporating the EU SCCs, plus the UK Addendum. |
| ZoomZoom Communications, Inc.Conditional | Carries Zoom-hosted interviews and, where enabled, streams consented meeting audio to Itya through Zoom RTMS.Only where external Zoom capture is enabled. The embedded Itya room does not use it. | Meeting attendance, meeting audio captured under recorded consent. | United States | Zoom DPA incorporating the EU SCCs, plus the UK Addendum. |
| Amazon Web Services (S3)Amazon Web Services, Inc.Conditional | Object storage for uploaded resumes and attachments, interview audio, transcript exports, audit archives and data-request bundles, where the deployment points its object-store endpoint at Amazon S3 rather than at the self-hosted store.Only where the object-store endpoint is Amazon S3. The reference single-host deployment uses an S3-compatible store on its own infrastructure. | Resume and attachment files, interview audio, transcript and export files, and data-subject export bundles. | The bucket region the deployment configures. Absent an explicit region the SDK default is us-east-1, so a deployment that requires EU storage must set the region and the bucket deliberately. | AWS DPA incorporating the EU SCCs, plus the UK Addendum. |
| DeepgramDeepgram, Inc.Conditional | Speech-to-text with speaker diarisation, turning interview audio into the transcript the scorecard is evidenced against.Only where the deployment selects Deepgram as its transcription vendor. | Interview audio, and the transcript text derived from it, including anything a participant says. | United States | Deepgram DPA incorporating the EU SCCs, plus the UK Addendum. |
| AssemblyAIAssemblyAI, Inc.Conditional | Speech-to-text with speaker diarisation, as an alternative to Deepgram.Only where the deployment selects AssemblyAI as its transcription vendor. | Interview audio, and the transcript text derived from it, including anything a participant says. | United States | AssemblyAI DPA incorporating the EU SCCs, plus the UK Addendum. |
| Recall.aiRecall.ai, Inc.Conditional | Hosted meeting bot that joins an external Google Meet, Microsoft Teams or Zoom interview and returns its audio and transcript.Only where external meeting capture is enabled and the hosted capture lane is selected. The embedded Itya room does not use it. | Interview audio and video, participant display names, and meeting metadata. | The Recall region configured for the deployment. | Recall.ai DPA incorporating the EU SCCs, plus the UK Addendum. |
| Greenhouse, Lever, Ashby and WorkableGreenhouse Software, Inc. / Lever, Inc. / Ashby, Inc. / Workable Software Ltd.Conditional | Two-way applicant-tracking sync: importing candidates and applications, and pushing stage changes, scorecards and interview evidence back to the system of record.Only where a workspace administrator connects that ATS and enables the corresponding sync direction. | Candidate name, email, phone, resume URL, application stage, and the interview evidence a workspace chooses to push back. | The region of the customer-connected ATS account. | Governed by the customer's own agreement with the ATS vendor. What leaves the workspace is bounded by the connection's sync settings. |
Before a new sub-processor starts processing customer personal data, Itya gives at least 30 days' notice. To receive that notice, email legal@itya.ai asking to be added to the subprocessor notification list. A customer that reasonably objects on data-protection grounds within that notice period may raise the objection with Itya; if the parties cannot agree on a resolution, the customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused term.
Itya remains fully liable to the customer for the performance of each sub-processor's obligations. Each sub-processor is engaged under a written contract imposing data-protection obligations no less protective than this DPA.
Systems the customer connects itself — its own calendar, meeting, ATS and messaging accounts — are not Itya sub-processors. The customer is already the controller of those systems and directs the transfer:
- Google Calendar and Google Meet, connected by a workspace member through OAuth
- Microsoft Outlook Calendar and Microsoft Teams, connected by a workspace member through OAuth
- Zoom, connected by a workspace member
- Greenhouse, Lever and Ashby applicant tracking systems, connected by a workspace administrator
- Slack, connected by a workspace administrator
International transfers, SCCs, UK and Swiss addenda
Where Itya processes personal data that is subject to EU, UK or Swiss data protection law outside the country of origin, the following transfer mechanisms apply and are incorporated into this DPA by reference.
- EU SCCs, Module Two (controller to processor), Commission Implementing Decision (EU) 2021/914, apply to transfers of customer personal data from the customer as controller to Itya as processor. Clause 7 (docking) applies; clause 9 uses option 2 (general written authorisation) with the 30-day notice period above; clause 11 does not use the optional independent-dispute-resolution wording; clause 17 selects Irish law; clause 18(b) selects the courts of Ireland. Annex I is populated by the “Parties, roles”, “Subject matter” and “Categories” sections above; Annex II by “Security measures”; Annex III by the subprocessor table.
- EU SCCs, Module Three (processor to sub-processor) apply between Itya and each sub-processor listed above that is outside the EEA and not covered by an adequacy decision.
- UK transfers. The UK International Data Transfer Addendum to the EU SCCs (version B1.0, issued under section 119A of the Data Protection Act 2018) applies to transfers subject to UK GDPR, with the EU SCCs above as the approved transfer mechanism it amends. Where the customer prefers the standalone UK IDTA, Itya will execute it on request.
- Swiss transfers. For transfers subject to the Swiss FADP, the EU SCCs apply with the Swiss adaptations: the Federal Data Protection and Information Commissioner is the competent supervisory authority, references to the GDPR are read as references to the FADP, and the clauses also protect the data of legal entities until the FADP no longer requires it.
Transfer impact assessments. Itya has assessed the laws of the destination countries for the transfers above and is not aware of any law or practice that would prevent it from meeting its obligations under the SCCs. Itya has not received a government request for customer personal data. Itya will notify the customer if it becomes unable to comply, will challenge any request it believes is unlawful, and will disclose only the minimum required. Itya will share its transfer impact assessment and its supplementary measures on request to security@itya.ai.
Security measures (Annex II)
The measures below are the technical and organisational measures Itya applies under Article 32 and Annex II of the SCCs. The security page describes them in product terms, and states precisely which data is encrypted at the application layer and which relies on encrypted infrastructure volumes.
- Encryption in transit. TLS 1.2 or above on every external connection, with HSTS on the public origins.
- Encryption at rest. Application-layer AES-256-GCM with versioned keys for the highest-risk secrets — integration OAuth access and refresh tokens, two-factor secrets, webhook signing secrets and stored bot credentials. The database and object storage sit on encrypted block and object volumes provided by the hosting platform, and backups are encrypted before they leave the host.
- Access control. Role-based permissions enforced per request; every tenant query is scoped to one workspace; cross-workspace access is available only to a named system path that is itself audited.
- Authentication. Password hashing with an adaptive work-factor function (bcrypt, cost factor 12), breached-password checks, optional two-factor authentication, session listing and remote sign-out, and short-lived rotating refresh tokens in host-scoped cookies.
- Consent gating. Interview capture will not start without a recorded consent decision from the participants, and the deletion deadline is fixed at consent time so a later policy change cannot extend it.
- Logging and monitoring. An audit log of interview, scorecard, billing, security and administrative actions with actor context; structured application logs; alerting on error rate, queue depth and circuit breakers.
- File safety. Uploaded files are scanned before they are made available, and quarantined on a positive result.
- Resilience. Automated encrypted backups to a separate off-host store, with restore drills.
- Organisational measures. Least-privilege production access, code review, dependency and secret scanning in continuous integration, and a documented vulnerability disclosure policy.
Itya does not currently hold a SOC 2 or ISO 27001 certification and makes no such claim.
Assistance with data subject requests
Itya provides self-service tooling that lets a customer answer most requests without contacting us: candidate and workspace data export, candidate erasure, consent records, and an audit trail of what was done and by whom. A candidate can also start a verified request directly through the public data-request flow, which identifies the controlling workspace and routes the request to it.
If a data subject contacts Itya directly about data Itya processes for a customer, Itya will not respond substantively. It will tell the data subject to contact the customer, and notify the customer without undue delay unless the law forbids it.
Where a customer needs more help than the tooling gives, Itya will provide reasonable assistance at no additional charge for requests that arise from ordinary use of the service. An erasure accepted by the customer is executed against live systems within 72 hours and works through backups as they roll off.
Personal data breach notification
Itya notifies the customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting that customer's personal data. Notice goes to the workspace owner and to any security contact the customer has given us.
The notice will describe, so far as the information is available at the time:
- the nature of the breach and the categories and approximate number of records;
- the likely consequences;
- the measures taken or proposed to address it and to mitigate its effects; and
- a contact point for further information.
Where the full picture is not available within 72 hours, Itya sends what it has and follows up in phases. Itya will not delay notice to complete an investigation. Itya's notice is not an admission of fault. The customer, as controller, remains responsible for notifying its supervisory authority and, where required, affected data subjects.
Retention defaults
These are the retention periods Itya applies by default. A workspace administrator can shorten or lengthen the configurable ones. Where a class has no automatic expiry, that is stated rather than dressed up as a policy.
| Data class | Default retention | Configurable | What enforces it |
|---|---|---|---|
| Account and profile records | Retained for the life of the account. | Not configurable. | A requested account deletion runs after a 14-day cooling-off window, during which signing in cancels it. |
| Candidate profiles and application records | Retained until deletion is requested or the workspace is closed. | Deleted on request; no automatic expiry. | Candidates can request erasure through the public data-request flow; administrators can delete a candidate directly. |
| Resumes and uploaded candidate files | 30 days | 7–365 days, per workspace | The hourly retention sweep deletes expired rows and hands the stored objects to a durable deletion janitor. |
| Interview recordings and captured audio | 30 days | 7–365 days, per workspace | The deletion deadline is fixed at consent time from the retention policy then in force, so a later policy change cannot extend it. |
| Interview transcripts | 30 days | 7–365 days, per workspace | Same consent-time deadline as the recording the transcript came from. |
| AI scorecards and debriefs | Retained until deletion is requested or the workspace is closed. | Deleted on request; no automatic expiry. | A scorecard is the hiring decision record. Erasing a candidate removes their scorecards with the rest of their record. |
| Audit logs | Retained for the life of the workspace. | Not configurable; exportable by administrators. | Audit records evidence who did what. They are not expired automatically, and are removed when the workspace is deleted. |
| Product analytics snapshots | 90 days | Not configurable. | A daily sweep deletes analytics snapshots older than 90 days. |
| Application logs | 30 days | Not configurable. | Enforced by log rotation on the host. |
| Support requests | Retained until deletion is requested or the workspace is closed. | Deleted on request; no automatic expiry. | Kept so a reopened issue still has its history. |
| Billing and invoice records | Retained as long as tax and accounting law requires, typically 7 years. | Not configurable. | Billing webhook payloads, which carry billing contact details, are purged after 90 days once processed. |
| Data-export downloads | 7 days | Not configurable. | An export produced for a data request expires 7 days after it is generated. |
| Encrypted backups | At least 30 days | Deployment-configurable, with a 30-day floor. | A deletion is applied to live systems immediately and works through backups as they roll off. |
A legal hold, a live security investigation, or a legal obligation can pause a deletion. If that happens to data the customer asked us to delete, we will say so and say why.
Return and deletion on termination
For 30 days after the Agreement ends, the customer can export its data through the product's export tooling, and can ask Itya for an export in a structured, machine-readable format.
After that window, Itya deletes customer personal data from live systems. Encrypted backups are retained on their normal cycle — at least 30 days — and the data is destroyed as those backups expire. Until then it remains encrypted and is not restored except to recover the production environment.
Itya may retain personal data where the law requires it, and will keep it only for as long as that obligation lasts and only for that purpose. On request, Itya will confirm deletion in writing.
Audit rights
Itya will make available to the customer the information reasonably necessary to demonstrate compliance with Article 28 and this DPA. In the first instance that means: this DPA, the security page, the subprocessor list, the retention matrix, the disclosure policy, and a completed security questionnaire.
Where that is not sufficient for the customer's own compliance obligations, or where a supervisory authority requires it, the customer may audit Itya's processing once in any 12-month period, on 30 days' written notice, during business hours, under an appropriate confidentiality agreement, and in a way that does not disrupt Itya's operations or the confidentiality of other customers' data. The customer may use an independent auditor that is not a competitor of Itya. Each party bears its own costs, except that the customer reimburses Itya's reasonable costs for an audit beyond the first in any 12-month period. An additional audit may be carried out at any time following a personal data breach affecting the customer.
Liability, order of precedence, and changes
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where a mandatory provision of data protection law — in particular Article 82 GDPR and clause 12 of the SCCs — provides otherwise. Nothing in this DPA limits a data subject's rights against either party.
Order of precedence: (1) the Standard Contractual Clauses and any applicable UK or Swiss addendum, (2) an executed order form or negotiated data-protection agreement, (3) this DPA, (4) the terms of service.
Itya may update this DPA to reflect a change in law, in the service, or in its sub-processors. A change that materially reduces the protection of customer personal data takes effect only after 30 days' notice, during which the customer may object as described under “Sub-processors”.
Questions and signature requests: legal@itya.ai. This DPA is published in English; a translation is provided for convenience only and the English version governs.