Enterprise privacy
Data Processing Addendum
HireEGG's public data-processing framework for enterprise candidate and workforce data.
- Applies to
- Enterprise customers, privacy counsel, security teams, and procurement teams.
- Effective
- July 17, 2026
- Document
- Enterprise term · 2026.07
Browse all policies
01
Status of this page
This page is an overview of HireEGG's intended data-processing terms; it is not a countersigned agreement by itself. A signed data processing addendum, order form, or enterprise agreement controls the parties' binding commitments and must identify the legal entities, contacts, governing terms, and any required transfer mechanism.
02
Roles
For candidate or workforce data submitted under an enterprise account, the customer generally acts as controller or data fiduciary and HireEGG acts as processor or data processor on the customer's documented instructions. HireEGG may act independently for account administration, billing, service security, fraud prevention, and its own legal obligations.
03
Processing details
- Subject matter: providing, securing, supporting, and maintaining the contracted HireEGG services.
- Duration: the service term plus the agreed return, deletion, backup, dispute, and legal-retention periods.
- People: candidates, applicants, employees, recruiters, reviewers, administrators, customer contacts, and authorized users.
- Data: contact and account details, CV and application content, interview answers, audio or video, transcripts, reports, consent records, integrity signals, device and request data, support records, and other data submitted under the service.
- Operations: collection, organization, hosting, access, transmission, model inference, transcription, analysis, retrieval, support, restriction, deletion, and return as needed for the service.
04
Customer instructions and duties
HireEGG processes customer data to provide the service, follow documented settings and support requests, and meet law. The customer is responsible for lawful instructions, notices, legal basis or consent, candidate rights, assessment criteria, user permissions, accommodations, retention choices, and the legality of recording or proctoring features.
05
Confidentiality and security
People authorized to process customer data must be subject to appropriate confidentiality obligations. HireEGG maintains technical and organizational measures proportionate to the service and risk, as summarized on the Security page. The signed DPA should specify any customer-required measures or audit evidence.
06
Subprocessors
HireEGG may use subprocessors to deliver the service and remains responsible for imposing appropriate data-protection obligations on them. Current providers and purposes appear on the Subprocessors page. Notice, objection, and replacement rights are governed by the signed customer agreement.
07
Rights requests and assistance
Taking account of the processing and information available, HireEGG will reasonably assist the customer with data-subject requests, security assessments, impact assessments, regulator enquiries, and compliance duties required by applicable law and the signed agreement. HireEGG will not independently answer a customer-controlled request unless authorized or legally required.
08
Security incidents
HireEGG will notify the customer of a confirmed personal-data breach affecting customer data without undue delay and as required by the signed agreement. Notice should include available information about the nature, likely consequences, affected data, containment, and remediation, without admitting fault before investigation is complete.
09
Return, deletion, and transfers
At the end of service, HireEGG will return or delete customer data as agreed, subject to backups, legal holds, security evidence, and records required by law. International transfers must use any safeguard required by applicable law and the signed agreement.
10
Execute enterprise terms
To request a reviewable DPA, security materials, or procurement documentation, contact info@hireegg.com. Do not rely on this public overview as a substitute for a signed agreement.
Questions about this document?
Enterprise customers can also request a signed DPA, security review, or procurement materials.