This Data Processing Addendum ("DPA") forms part of the Terms of Service between Answerflix Ltd, trading as Career1 ("Career1"), and the company that uses Career1 to hire ("you"). It applies whenever Career1 processes personal data on your behalf, and it sets out the terms Article 28(3) of the UK GDPR and the EU GDPR require. Words such as controller, processor, personal data, data subject and personal data breach have the meanings those laws give them.
You accept this DPA by accepting the Terms, and it needs no signature to take effect. If you would like a copy signed by both parties, a countersigned copy is available on request at hello@career1.ai.
1. Parties and scope
"Customer Personal Data" means the personal data of your applicants and candidates that Career1 processes on your behalf in providing the Service, as described in Annex 1. "Data protection law" means the UK GDPR, the Data Protection Act 2018, the EU GDPR and any other data protection law that applies to that processing.
2. Roles
- For Customer Personal Data you are the controller and Career1 is your processor. If you are yourself processing it for a client, such as a recruitment agency hiring for another company, Career1 is your sub-processor, and you confirm your client has authorised it.
- Career1 is a controller in its own right, not your processor, for: the accounts of your own users and your billing details; the Career1 account it creates for each applicant, in their name and email address, so they can take the interview and follow the application; job seekers' profiles, vetting interviews and reports in the talent pool; and what it needs to keep the Service secure, prevent abuse and meet its legal obligations. The Privacy Policy covers that processing.
- When you view, unlock or receive a job seeker's profile from the talent pool, you receive it as an independent controller, not under this DPA. You may use it only to consider that person for work, in line with data protection law and the Terms.
3. Processing on your instructions
Career1 processes Customer Personal Data only on your documented instructions, including with regard to transfers to a third country. Your instructions are the Terms, this DPA, and the way you set up and use the Service. If the law requires Career1 to process it otherwise, Career1 will tell you before it does, unless that law forbids telling you. Career1 will tell you straight away if it believes an instruction infringes data protection law.
4. Confidentiality
Career1 ensures that everyone it authorises to process Customer Personal Data is bound by a duty of confidentiality, and gives access only to people who need it to run and support the Service.
5. Security
Career1 implements the technical and organisational measures in Annex 2 to protect Customer Personal Data, as Article 32 requires. It may change them over time, but not in a way that lowers the overall level of protection.
6. Sub-processors
- You give Career1 general written authorisation to use the sub-processors listed in Annex 3 and kept up to date at /subprocessors.
- Career1 will tell you of any intended addition or replacement of a sub-processor that processes Customer Personal Data at least 30 days before it starts, by email to your workspace owner and on that page.
- You may object on reasonable data protection grounds within that period. We will then discuss your concern in good faith. If we cannot resolve it, you may stop using the affected part of the Service, or close your workspace.
- Career1 imposes on each sub-processor, by contract, data protection obligations that are in substance the same as those in this DPA, and remains responsible to you for the sub-processor's performance of them.
7. Helping you meet your obligations
- Requests from data subjects: taking into account the nature of the processing, Career1 will help you, by appropriate technical and organisational measures and as far as possible, to answer requests from applicants exercising their rights. The product has no export or delete button yet, so Career1 carries out access, copy, correction and deletion requests for you by hand. If an applicant sends a request about your application to Career1, Career1 will pass it to you without undue delay and will not answer it itself, except to tell the applicant it has done so, unless the law requires otherwise.
- Security, impact assessments and consultations: Career1 will give you the information you reasonably need, given the nature of the processing and what is available to it, to meet your obligations under Articles 32 to 36, including data protection impact assessments and prior consultation with a supervisory authority.
8. Personal data breaches
Career1 will notify you of a personal data breach affecting Customer Personal Data without undue delay, and in any event within 48 hours of becoming aware of it. The notice will describe, as far as Career1 then knows, the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences, and the measures taken or proposed, and Career1 will add to it as it learns more. Career1 will take reasonable steps to contain the breach and limit its effects. Notifying you is not an admission of fault.
9. International transfers
Career1 is established in the United Kingdom, and the Service is hosted in the EU (Annex 2). Career1 transfers Customer Personal Data outside the UK and the European Economic Area only to the sub-processors in Annex 3, and only with a transfer mechanism that data protection law recognises.
Where your transfer of Customer Personal Data to Career1 is a restricted transfer under the EU GDPR that no adequacy decision covers, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference: Module Two where you are a controller, and Module Three where you are a processor. For them, Clause 7 applies; under Clause 9(a), Option 2 applies, with the notice period in section 6; the option in Clause 11 does not apply; under Clause 17, Option 1 applies and the law is that of Ireland; under Clause 18(b), the courts are those of Ireland; the competent supervisory authority is determined under Clause 13; you are the data exporter and Career1 the data importer; and the clauses' Annexes I, II and III are Annex 1, Annex 2 and Annex 3 of this DPA.
Where the transfer is a restricted transfer under the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0) is incorporated by reference, completed with the information above, and either party may end it as its Section 19 allows. If the clauses incorporated here conflict with the rest of this DPA, the clauses prevail.
10. Information and audits
Career1 will make available to you the information necessary to demonstrate compliance with Article 28: this DPA, the Security page, the sub-processor list, and answers to your reasonable written questions. If that is not enough, you, or an independent auditor bound by confidentiality who is not a competitor of Career1, may audit Career1's compliance with this DPA once a year, at your own cost, on at least 30 days' written notice, during business hours and without unreasonably disrupting the Service. An additional audit is allowed where a supervisory authority requires it or after a personal data breach affecting your data. Career1 will contribute to audits and inspections as Article 28(3)(h) requires.
11. Deletion or return
When your use of the Service ends, Career1 will, at your choice, delete Customer Personal Data or return a copy of it to you in a commonly used format, within 30 days of your written request after termination, unless the law requires Career1 to keep it. Two things are true of deletion today, and you should know them before you rely on it:
- Stored files, the resumes and recordings on Amazon S3, are deleted in a separate step, by hand, because the application itself deliberately has no permission to delete stored files.
- Career1 does not yet delete database backups on a schedule, so a copy of Customer Personal Data can remain in a backup after it has been deleted from the live Service. Any copy that remains stays protected by this DPA and is not used for any other purpose.
12. Your obligations
You are responsible for having a lawful basis for the processing you instruct, for giving applicants the information the law requires (including that you use Career1 and AI assessment), for the lawfulness of your instructions, and for not asking applicants for special category data through your screening questions unless the law allows it. The duties the law places on employers that use AI or automated tools in hiring remain yours, as the Terms explain.
13. Liability
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms, except where the Standard Contractual Clauses or data protection law do not allow liability to data subjects to be limited.
14. Order of precedence
If there is a conflict, the Standard Contractual Clauses and the UK Addendum, where they apply, prevail over this DPA, and this DPA prevails over the Terms.
15. Governing law
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over it, except that the Standard Contractual Clauses are governed by the law and courts they specify.
16. Annex 1: Details of the processing
| Subject matter | Providing the Service to you: hosting your careers page, job posts and application forms, receiving applications, conducting and recording AI interviews, transcribing them, writing reports, scheduling calls, and emailing applicants. |
| Duration | For as long as you use the Service, and afterwards until the data is deleted or returned under section 11. |
| Nature of the processing | Collection, storage, organisation, retrieval and display; recording of video and audio; transcription; analysis by AI to produce scores, recommendations and reports; transmission to the sub-processors in Annex 3; and deletion. |
| Purpose | To let you assess applicants and candidates for roles you are hiring for. |
| Data subjects | People who apply to your jobs or whom you invite to an interview or a call. |
| Categories of personal data | Name, email address, and, where your form asks for them, phone number and city; resumes and the text read from them; answers to your screening questions; live interview audio, processed as it happens; interview recordings (video with audio); transcripts; AI assessments (match percentage, overall and dimension scores, recommendation, skill evidence with quotes, strengths and risks); application stages and their history; calendar invitations; and technical data, such as IP address and browser, from the requests applicants make. |
| Special categories | None are sought. They may appear incidentally in what an applicant says in an interview or writes in a resume. |
| Frequency | Continuous, while you use the Service. |
| Retention | While the data is in your workspace, then as section 11 sets out. |
17. Annex 2: Security measures
These are the measures in place. The Security page also lists the ones that are not.
- Hosting: the application, database and cache run on servers operated by Contabo in France; files and database backups are stored in Amazon S3 in Stockholm (eu-north-1).
- Encryption in transit: every connection to the Service uses TLS, with HTTP Strict Transport Security for one year; stored files are fetched through short-lived signed links.
- Encryption at rest: Google Calendar access tokens are encrypted in the database. No other data is encrypted by the application itself.
- Passwords and sessions: passwords are hashed with Argon2; sign-in sessions are held on the server and can be revoked; session and account tokens are 256-bit random values stored only as SHA-256 hashes; the session cookie is HttpOnly and SameSite=Lax, and every sign-in cookie is Secure; a token that is part of a page address is replaced by a placeholder before analytics, session-replay journeys or application logs store it.
- Access within a workspace: roles from hiring manager through recruiter and admin to owner, with the more sensitive actions reserved to higher roles.
- Isolation between companies: each company's data is separated at three levels: the data-access layer, a filter applied to every database query, and a check that refuses to write a row belonging to another company.
- Administrator access: limited to an allow-list of addresses, each sign-in needing a six-digit code sent by email that expires after ten minutes and allows five attempts; the admin area answers anyone else with "not found", and admin sign-ins are recorded.
- Least privilege for storage: the credentials the application uses for Amazon S3 cannot delete or list stored files.
- Abuse controls: rate limits on password sign-in, administrator sign-in codes, password-reset requests, sign-ups, the free tools, the help assistant and session-replay uploads; sign-ups and practice interviews from Tor exit nodes are refused; company sign-up is confirmed by email and does not reveal whether an account already exists.
- Audit trail: sign-ins, stage changes, resume downloads, recording views, profile visibility changes and workspace deletions are logged, as is every administrator's viewing of an interview, recording, session replay or person's profile, and every administrative action.
- Backups: a full copy of the database every night, stored on Amazon S3.
- Payments: card details are entered on Stripe's hosted checkout and never reach Career1.
- Browser protections: pages may not be framed by other sites, content types are not sniffed, referrers are trimmed, and access to location, payment and USB features is switched off.
18. Annex 3: Sub-processors
Every provider that processes personal data for Career1 is below. Those that process Customer Personal Data, and so act as your sub-processors, are: Contabo, Amazon Web Services (Amazon S3), OpenAI, Resend and Google. The others process only data for which Career1 is the controller.
| Provider | What for | Data it receives | Where | Transfer safeguard |
|---|---|---|---|---|
| Contabo | Hosts the application servers and the database. Always in use. | All data held by Career1. | France (EU) | Within the EU. |
| Amazon Web Services (Amazon S3) | Stores resumes, interview recordings, company logos and database backups. Always in use. | Resume files, interview video with audio, backups of the database. | EU (Stockholm, eu-north-1) | Within the EU. |
| OpenAI | Runs the voice interviewer and transcription, writes interview reports and feedback, reads resumes into profiles, powers talent search, the free tools and the help assistant. Always in use. | Live interview audio, candidate name and resume text, job details, transcripts, help-chat messages, text pasted into the free tools. | United States | EU Standard Contractual Clauses and the UK Addendum. OpenAI does not train its models on data sent through its API. |
| Resend | Sends account, sign-in and interview emails. Always in use. | Email address, name and the content of the email. | United States | EU Standard Contractual Clauses and the UK Addendum. |
| Stripe | Takes payment for company subscriptions. Only when a company subscribes to a paid plan. | Billing email and company reference. Card details go to Stripe directly and never reach Career1. | Ireland and United States | EU Standard Contractual Clauses and the UK Addendum. |
| Google sign-in, Google Calendar scheduling, Google Analytics, and the connection helper (STUN) that lets the interview's voice link reach you. Only when you sign in with Google, a company connects its calendar, you accept analytics cookies, or you join a voice interview. | Sign-in: name and email. Calendar: event details and attendee emails. Analytics: pages visited, device and approximate location. STUN: your IP address. | United States | EU–US Data Privacy Framework, EU Standard Contractual Clauses and the UK Addendum. | |
| GitHub | Optional GitHub sign-in and the public-repository summary shown on a talent profile. Only when a job seeker connects GitHub. | GitHub username, name, email and public profile and repository details. | United States | EU Standard Contractual Clauses and the UK Addendum. |
| ip-api.com | Looks up the approximate country and city of website visitors for our own visit statistics. Always in use. | IP address. | Not published by the provider | The provider states it keeps the queried address in memory for up to one minute. |