Version 2026-10-02Nederlandse tekst

Annex 1: Data Processing Agreement

This data processing agreement (the "Data Processing Agreement") is an annex to, and forms an integral part of, the main agreement between Hyre B.V. and the Customer (the "Main Agreement"). It is not signed separately: by signing the Main Agreement, the Parties also agree to this Data Processing Agreement.

Acceptance in the app

This text is Annex 1 to the pilot agreement of Hyre B.V. (Brouwersgracht 238, Amsterdam, Chamber of Commerce 88732037). A Customer who does not sign the pilot agreement enters into this Data Processing Agreement with Hyre B.V. by accepting it in the Hyre app. For that Customer:

  • "Main Agreement" means the terms of use at https://hyre.io/terms, which the Customer accepts at the same time.
  • The acceptance in the app, recorded with the date, the time and the user who gave it, counts as signature.
  • This English text is a translation. If it conflicts with the Dutch text, the Dutch text prevails.

Article 1. Definitions and order of precedence

1.1 Capitalised terms in this Data Processing Agreement that are not defined here have the meaning given to them in the General Data Protection Regulation (GDPR) or in the Main Agreement.

1.2 "Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Sub-processor" and "Personal Data Breach" have the meaning that the GDPR gives them. Where this Data Processing Agreement refers to a "Data Breach", it means a personal data breach within the meaning of the GDPR.

1.3 If this Data Processing Agreement and the other provisions of the Main Agreement conflict, this Data Processing Agreement prevails as far as the Processing of Personal Data is concerned. In all other respects, the provisions of the Main Agreement remain in full force.

Article 2. Subject matter, nature and duration of the Processing

2.1 Hyre processes Personal Data solely to perform the Main Agreement. Annex A describes the nature and purpose of the Processing, the categories of Data Subjects and the categories of Personal Data.

2.2 This Data Processing Agreement applies for the duration of the Main Agreement. Obligations that by their nature are intended to continue after it ends, including the obligations on confidentiality, return and deletion, remain in force after the end of the Main Agreement.

Article 3. Instructions

3.1 Hyre processes the Personal Data solely on the basis of, and in accordance with, the documented instructions of the Customer, unless a statutory provision that applies to Hyre requires it to process. In that case Hyre informs the Customer of that legal requirement before the Processing, unless that law prohibits such information on important grounds of public interest.

3.2 The Main Agreement and this Data Processing Agreement, including Annex A, are the documented instructions of the Customer. Additional or different instructions are recorded in writing or by email.

3.3 Hyre informs the Customer without delay if, in Hyre's opinion, an instruction infringes the GDPR or other applicable data protection law.

3.4 The Customer instructs Hyre to verify the connection with the ATS or CRM that the Customer connects to Hyre, by writing test data into it. Hyre complies with the following:

a. Hyre creates, updates and deletes only records that Hyre itself creates for the verification and that are clearly marked as a Hyre test record, and notes on the record of a Hyre employee.

b. Hyre never updates or deletes any other record of the Customer.

c. A test record contains no Personal Data of the Customer's Data Subjects, only fictitious data or data of Hyre employees.

d. Hyre keeps the number of test records as small as possible, and runs the verification at most once a day.

e. Hyre deletes every test record directly after the verification. If that fails, Hyre deletes it as soon as possible afterwards.

The Customer can withdraw or limit this instruction at any time, in the manner of Article 3.2.

Article 4. Confidentiality

4.1 Hyre ensures that the persons it involves in the Processing, including its staff and third parties it engages, are bound to keep the Personal Data confidential, either by a statutory duty of confidentiality or by a contractual confidentiality obligation.

4.2 Hyre gives access to the Personal Data only to persons for whom that access is necessary to perform the Main Agreement.

Article 5. Security

5.1 Hyre takes appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing. Annex B describes the measures.

5.2 Hyre evaluates these measures periodically and adjusts them where necessary to keep the level of security.

Article 6. Sub-processors

6.1 The Customer gives Hyre general authorisation to engage Sub-processors in the Processing. The current list of Sub-processors, with their role, the categories of data involved, the country where the processing entity is established and the country of data storage, is available at https://hyre.io/subverwerkers.

6.2 Hyre announces an intended change in the Sub-processors, including the addition or replacement of a Sub-processor, at least thirty (30) days before the intended effective date, by email to the address the Customer has given for that purpose.

6.3 Within that period, the Customer may object to a change on reasonable grounds. The Parties then consult each other. If the Parties do not reach agreement, the Customer may terminate the Main Agreement as of the intended effective date of the change, without observing a notice period and without owing any costs other than those already invoiced and those of the current period.

6.4 By agreement, Hyre imposes on every Sub-processor the same data protection obligations as those in this Data Processing Agreement, as far as they apply to the Processing the Sub-processor performs. Hyre remains fully liable to the Customer for the Sub-processor's performance of its obligations.

Article 7. Data Breaches

7.1 Hyre informs the Customer within forty-eight (48) hours after it discovers a Data Breach that concerns the Personal Data Hyre processes for the Customer. The notification is made in writing or by email to the address the Customer has given for that purpose.

7.2 The notification contains at least the information the Customer needs to meet its obligations under Articles 33 and 34 GDPR, including a description of the nature of the Data Breach, the categories and numbers of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed.

7.3 If not all the information referred to in Article 7.2 is available within the period of forty-eight (48) hours, Hyre reports within that period what is known at that moment, and completes the notification afterwards without undue delay.

Article 8. Rights of Data Subjects

8.1 Hyre gives the Customer reasonable cooperation in fulfilling its duty to respond to requests from Data Subjects, including requests for access, rectification, erasure, restriction of Processing, objection and data portability.

8.2 If a request from a Data Subject reaches Hyre directly, Hyre forwards it to the Customer without delay and does not answer the request itself, unless the Customer instructs it to do so in writing.

Article 9. Assistance with a DPIA and prior consultation

9.1 Taking into account the nature of the Processing and the information available to it, Hyre gives the Customer reasonable assistance in carrying out a data protection impact assessment (DPIA) and in any prior consultation of the supervisory authority, as far as they concern the Processing by Hyre.

Article 10. Processing in Europe and transfers outside the EEA

10.1 Hyre aims to engage only Sub-processors that process and store the Personal Data within the European Economic Area (EEA). Where a Sub-processor offers a European region, Hyre chooses that region. In doing so, Hyre takes into account that its customers, including customers established in the Netherlands, require processing and storage in Europe.

10.2 As far as Personal Data is nevertheless processed outside the EEA, this happens only if there is a valid transfer basis for it, namely an adequacy decision of the European Commission, the EU-US Data Privacy Framework, or the standard contractual clauses (SCCs) adopted by the European Commission.

10.3 Where necessary, Hyre takes supplementary measures to ensure an appropriate level of protection for the transferred Personal Data. The country of establishment, the country of storage and the transfer basis per Sub-processor are included in the list at https://hyre.io/subverwerkers.

Article 11. Audit

11.1 The Customer may verify compliance with this Data Processing Agreement at most once every twelve (12) months, at its own cost, after at least thirty (30) days' notice. The Customer itself may carry out a verification, or an independent auditor who is not a competitor of Hyre and who is bound to confidentiality.

11.2 Hyre may first answer a request for verification by providing the reports, statements and certifications available to it. An on-site verification takes place only as far as those reports do not give sufficient clarity.

11.3 A verification is carried out so that it disturbs Hyre's operations and the interests of its other customers as little as possible.

11.4 If the verification reveals a shortcoming attributable to Hyre, Hyre bears the reasonable costs of that verification and remedies the shortcoming within a reasonable period.

Article 12. Return and deletion

12.1 At the Customer's first request, and in any case within ten (10) working days after the end of the Main Agreement, Hyre makes the Customer's Personal Data available to the Customer in a common, machine-readable format.

12.2 After making it available, Hyre deletes the Personal Data from its production systems and confirms this deletion in writing or by email, unless a statutory retention obligation prevents it.

12.3 Personal Data that remains only in regular backups is not actively accessed and is overwritten according to Hyre's regular retention schedule. Until then, the obligations of this Data Processing Agreement continue to apply to those backups.

Article 13. Liability

13.1 The liability of the Parties under this Data Processing Agreement follows, and is governed by, the liability provisions of the Main Agreement. The mandatory regime of Article 82 GDPR remains unaffected.

Article 14. Amendment

14.1 Hyre may amend this Data Processing Agreement unilaterally, only as far as mandatory law, a decision of a supervisory authority or a court judgment requires it, with at least thirty (30) days' notice.

14.2 Substantive relaxations of Hyre's obligations under this Data Processing Agreement are expressly excluded from the unilateral right of amendment in Article 14.1, and are agreed only by mutual consent.

Article 15. Governing law and disputes

15.1 This Data Processing Agreement is governed by Dutch law. Disputes are submitted to the competent court in Amsterdam.

Annex A: Nature and purpose of the Processing

Purpose of the Processing

Hyre processes Personal Data to provide its agentic AI platform for recruitment intelligence, which works as a data layer on top of the Customer's existing ATS. The Processing covers recording, enriching and analysing communication and activity data and automating recruiter workflows, as the Main Agreement describes in more detail.

Nature of the Processing

Collecting, recording, organising, structuring, storing, consulting, transcribing, enriching, analysing and transmitting Personal Data to the Customer's ATS, and erasing or destroying it.

Categories of Data Subjects

  • candidates;
  • contact persons at the Customer's clients;
  • employees of the Customer who use the platform.

Categories of Personal Data

  • name, address and place of residence;
  • contact details, including email addresses and telephone numbers;
  • CV and career data;
  • communication content from email, LinkedIn, telephony, meetings and WhatsApp;
  • transcripts of calls and meetings;
  • enriched contact details from enrichment sources engaged by Hyre.

Special categories of Personal Data

Hyre does not deliberately process special categories of Personal Data within the meaning of Article 9 GDPR. As far as such data occurs incidentally in free-text fields supplied by Data Subjects, for example in CVs, it is not processed for special purposes, and the same security measures apply as for other Personal Data. The Customer, as Controller, is responsible for having a valid legal basis for supplying such data.

Annex B: Technical and organisational measures

The measures below describe Hyre's security framework.

1. Encryption

Personal Data is encrypted in transit with TLS 1.2 or higher, and at rest with AES-256 or an equivalent standard. Key management runs through the managed key services of the cloud infrastructure in use.

2. Access management

Access to Personal Data follows the principle of least privilege: staff get access only to the data they need for their task. Two-factor authentication is enforced on systems with access to customer data. Access rights are reviewed periodically and revoked immediately when someone leaves.

3. Logging and monitoring

Access to and actions on Personal Data are logged, and systems are monitored for unauthorised access and anomalous behaviour. Logs are kept for a set period and protected against tampering.

4. Separation of customer data

The data of different customers is kept logically separate on the basis of a customer identifier, so that a customer has access only to its own data.

5. Backup and recovery

Encrypted backups are made periodically to allow recovery after incidents, with a set retention schedule. Recovery procedures are tested periodically.

6. Personnel policy and confidentiality

Staff and engaged third parties are contractually bound to confidentiality. They get access to customer data only as far as their role requires it, and are instructed on how to handle personal data.

7. Incident procedure

Hyre has a procedure for detecting, assessing and handling security incidents and Data Breaches, in line with the notification duty in Article 7 of this Data Processing Agreement.

8. Sub-processors

Sub-processors are assessed beforehand on their level of security, and with every Sub-processor, processing terms apply that contain at least equivalent obligations, in accordance with Article 6. The status per Sub-processor is included at https://hyre.io/subverwerkers.