DATA PROCESSING ADDENDUM
1. INTRODUCTION AND PRECEDENCE
This Data Processing Addendum ("DPA") applies to personal data that HyreMynd AI Inc. ("HyreMynd") processes on behalf of an Employer ("Customer") for the Customer's employer-directed hiring. It forms part of the Customer Agreement: the order form, online subscription terms or signed agreement under which the Customer subscribes to HyreMynd. The Platform Terms of Service govern the conduct of the Customer's individual authorized users and do not replace the Customer Agreement. The HyreMynd Privacy Policy describes the processing, including the retention schedule in Privacy Policy section 9.
This DPA prevails over the Customer Agreement on the processing of personal data, unless a Customer Agreement signed by both parties expressly names the clause of this DPA that it replaces. Mandatory law prevails over both.
2. DEFINITIONS
Capitalized terms not defined here have the meanings given in the Customer Agreement.
- Affiliate – Any entity under common control with a party
- Candidate – Any individual considered for a role through the Service, whether they applied, were invited or were found by sourcing
- Candidate Data – Personal Data relating to Candidates, including assessment answers and the results derived from them
- Controller – Entity determining purposes and means of Processing
- Customer Agreement – The order form, online subscription terms or signed agreement under which the Customer subscribes to HyreMynd
- Customer Data – Personal Data submitted to or generated by the Service for the Customer's employer-directed purposes
- Data Protection Laws – PIPEDA, provincial laws, GDPR (if applicable), and successors
- Data Subject – Identifiable natural person
- Non-Identifiable Data – Aggregated or anonymized data
- Personal Data – Any information relating to an identifiable individual
- Processing – Any operation performed on Personal Data
- Processor – Entity Processing Personal Data on behalf of Controller
- Security Incident – Unauthorized access, disclosure, loss, or breach
- Sensitive Personal Data – Special category data (health, biometrics, etc.)
- Sub-processor – Third party Processing Personal Data on behalf of HyreMynd
3. ROLES AND RESPONSIBILITIES
3.1 Controller and Processor Roles
The Customer is the Controller of the hiring records it directs: applications, contact records, the assessments of candidates and team members it invites, interview content, references, correspondence, notes and sourcing results. HyreMynd processes those records as Processor under the Customer's documented, lawful instructions. Hiring, rejecting or archiving a candidate, or the end of an individual's employment, does not change who controls a record. HyreMynd is the Controller of account administration, security, and an applicant's independent account and self-service assessment. When an applicant's self-service sitting is used in an application to the Customer, that use is an employer-directed purpose controlled by the Customer.
3.2 Customer Responsibilities
Customer shall:
- Ensure lawful data collection and transfer
- Give required notices and obtain required consents
- Provide lawful Processing instructions
- Secure Customer-controlled systems
- Decide Data Subject requests about the records it controls
3.3 HyreMynd Responsibilities
HyreMynd shall:
- Process data per documented instructions
- Ensure confidentiality of personnel
- Maintain the security measures in section 10
- Assist with Data Subject and regulator requests
- Notify of Security Incidents
- Delete or return data at the end of the Customer Agreement as section 11.3 describes
4. SCOPE OF PROCESSING
4.1 Purpose
HyreMynd processes Customer Data to provide the Service for the Customer's hiring: applications and contact records, résumé review, the Workplace Fit Assessment, interview scheduling and transcripts, reference requests, correspondence, open-web sourcing and browser-extension capture, the in-product assistant, and related support. Privacy Policy section 1.1 describes where the Service uses fixed rules and where it uses AI; in particular, assessment positions and comparisons are computed by fixed rules, and an AI model writes explanations of them without changing them.
4.2 Categories of Data Subjects
- Applicants and invited Candidates
- People found through sourcing or imported as contacts
- Referees and other people named in hiring correspondence
- Customer employees completing a team assessment, and Authorized Users
- Other individuals submitted by Customer
4.3 Types of Personal Data
- Identification and contact data
- Professional data, including résumés and work history
- Assessment answers, derived positions, comparisons and generated explanations
- Calendar and meeting data (connected-account email address, free/busy intervals, details of interview events created through the Service, and for native invitations the guest addresses and meeting description)
- Interview content (transcripts of interview meetings where a participant enabled transcription on the meeting platform, and the advisory drafts derived from them)
- Correspondence, references and hire-outcome feedback
- Technical data
- Other submitted Personal Data
4.4 Sensitive Personal Data
Processed only with explicit consent, lawful basis, or legal authorization. Customer bears responsibility for legal basis.
4.5 Duration
Processing continues for the term of the Customer Agreement and afterwards only as section 11 describes.
5. PROCESSING INSTRUCTIONS
The Customer Agreement, this DPA and the Customer's documented lawful instructions, including its configuration of the Service, govern employer-directed processing. Additional instructions must be within the supported purpose and authority; HyreMynd may suspend an instruction it considers unlawful. Legal holds and lawful instructions about retention use the recorded process in section 11.2.
6. CANDIDATE CONSENT
6.1 Consent Mechanism
The account gate requests acknowledgement of the current Privacy Policy and Candidate Terms for applicants, or of the Privacy Policy and Platform Terms of Service for staff. Internal Team Terms are requested immediately before a staff assessment. This DPA, the Responsible AI Statement and the Data Access Consent Form are public disclosures; publishing them does not mean that each user signed them. Assessment participation and optional provider permissions have their own purpose-specific consent. Acknowledging a legal document is not a separate opt-in to model training or marketing. Material changes require new acceptance of the exact version and content shown.
6.2 Consent Records
HyreMynd records each legal-document acceptance against the exact version and content hash shown, and records assessment consent with the sitting it covers.
6.3 Withdrawal
When a Candidate withdraws consent to an assessment or to a hiring process:
- Processing for that purpose stops, and a sitting in progress is not used
- A request to erase the Candidate's data follows the staged process in Privacy Policy section 10.3: recording, identity verification, the Customer's authorization for the records it controls, execution, and confirmation of each effect
- The request appears in the Customer's controller queue for the records it controls
7. DATA SUBJECT RIGHTS
7.1 Assistance
HyreMynd assists with access, rectification, erasure, restriction, portability, objection, and automated decision-making rights.
7.2 Timeframes
HyreMynd places each request about Customer Data in the Customer's controller queue without undue delay after recording it, and tracks each request against the 30-day response deadline measured from its arrival, so that the Customer can decide within the time the law allows.
7.3 Direct Requests
HyreMynd routes a request about employer-directed records to the Customer as Controller and carries out the Customer's decision in the Service. HyreMynd decides requests about account, security and independent self-service data itself, as Controller of that data.
7.4 Automated Decision-Making
AI outputs are decision support only; humans make final decisions.
8. SUB-PROCESSORS
8.1 Authorization
General authorization granted.
8.2 Sub-processor List
Maintained at the HyreMynd Sub-processor List, which names each Sub-processor's legal entity, purpose, categories of Personal Data received, processing location, and the date it was first disclosed: www.hyremynd.com/legal/sub-processors
8.3 Changes
30 days' advance notice for new Sub-processors.
8.4 Objections
Customer may object within 15 days; unresolved objections permit termination of affected Service.
8.5 Obligations
- Written agreements required
- HyreMynd remains liable
- Security measures enforced
9. SECURITY INCIDENTS
9.1 Notification
Notification within 72 hours of awareness.
9.2 Incident Details
Includes scope, impact, mitigation, and contact details.
9.3 Cooperation
Ongoing updates and remediation support.
9.4 Regulatory Notices
Customer determines notification obligations.
9.5 No Admission
No admission of fault implied.
10. SECURITY MEASURES
10.1 Measures
Encryption in transit, encryption of stored provider credentials, storage with a hosting provider that encrypts data at rest, tenant isolation enforced in the application and in the database, role-based access controls, multi-factor authentication for privileged administrative actions, and audit logging.
10.2 Standards
Security standards and assurance materials may inform the control program. This DPA does not assert an ISO or SOC certification, a completed independent audit or a vendor assurance report; any such evidence is supplied, dated, under the Customer Agreement.
10.3 Documentation
Provided upon reasonable request.
11. DATA RETENTION AND DELETION
11.1 Retention Schedule
Customer Data follows the category schedule in Privacy Policy section 9, which is the single statement of each ordinary retention period and the event that starts it. Expired content is withdrawn from use and then destroyed; interrupted destruction resumes and is not reported as complete. An applicant's independent account and self-service sitting are not destroyed by the Customer's retention periods.
11.2 Legal Holds and Lawful Instructions
A Customer administrator may record a legal hold or a lawful instruction for a role, covering its live applications, or for named applications, with a reason, a review date and an end date. Content under an active hold is not expired. A hold ends on its end date or when it is released, and a released hold stays on record. An erasure request that reaches held content goes to the Customer for review instead of destroying it. A hold cannot restore content already withdrawn.
11.3 End of the Customer Agreement
When the Customer Agreement ends, Customer Data continues to follow the schedule in section 11.1 unless the Customer instructs earlier deletion or return under section 5 or the Customer Agreement provides otherwise. Non-Identifiable Data may be retained.
11.4 Legal Retention
Data retained as required by law.
11.5 Connected Accounts and Interview Content
Connecting a Google or Microsoft account is optional and individual to an Authorized User. Reading a connected calendar's availability returns busy intervals only. For an interview, HyreMynd creates the event and its online meeting on the organizer's calendar. When the Candidate can be reached by email and the organizer has acknowledged HyreMynd's current disclosure for that provider, the invitation is native: the Candidate's and interviewers' email addresses and a short meeting description, including a transcription notice, go to the provider, which sends the invitations. Otherwise the provider event carries no guest list and HyreMynd emails the invitation with a calendar attachment. HyreMynd never starts transcription; where transcript access was granted, it retrieves a transcript a participant created.
A separate send-only permission (Google gmail.send or Microsoft Mail.Send) lets an Authorized User send offers, reference requests and requests for referees from their own mailbox; each send gives the provider the recipient's address and the confirmed message, and the permission cannot read or search the mailbox. Withdrawing it in the Service stops further sends but does not remove the permission at the provider or recall a message already handed over.
Disconnecting an account, switching provider accounts or erasing an Authorized User's account retires the connection through one departure process: HyreMynd finishes or settles the work bound to it and deletes the stored credentials, while non-secret connection records and operation evidence can remain. HyreMynd then asks Google to revoke its grant, which can fail; Microsoft offers this integration no revocation, so access is removed in the Microsoft account or organization settings.
11.6 Erasure Requests
An erasure request follows the staged process in Privacy Policy section 10.3. For Customer Data, the Customer authorizes and starts the work in its controller queue; HyreMynd executes it, retries a failed step and sends repeated failures to human review, and marks the request complete only once each effect is confirmed.
12. INTERNATIONAL DATA TRANSFERS
12.1 Safeguards
Adequacy decisions, SCCs, BCRs, certifications, or lawful mechanisms.
12.2 GDPR Transfers
EU SCCs (Module Two) incorporated by reference.
12.3 PIPEDA
HyreMynd uses contractual means to provide a comparable level of protection when Customer Data is processed by a Sub-processor.
13. AUDIT RIGHTS
The Customer may request compliance information and exercise the audit rights of the Customer Agreement. A current independent assurance report may support that review only if one is actually available and relevant to the processing scope; this DPA does not assert a completed SOC 2 audit or treat an unavailable report as a substitute.
14. REGULATORY COOPERATION
HyreMynd assists with regulator inquiries, remediation, and DPIAs.
15. LIABILITY
Liability and indemnification are governed by the Customer Agreement.
16. TERM AND TERMINATION
This DPA applies for the term of the Customer Agreement and afterwards for as long as HyreMynd processes Customer Data; sections 7, 9 and 11 survive.
17. GENERAL PROVISIONS
- Governing law: Ontario, Canada
- Amendments with notice
- Severability
- Order of precedence: as stated in section 1
18. CONTACT INFORMATION
HYREMYND AI INC.
Privacy Officer: Marleigh Robertson
559 Sammon Ave, East York, Ontario, M4C 2E1, Canada
SCHEDULE A — DETAILS OF PROCESSING
- Subject matter and purpose: employer-directed recruitment, sourcing, correspondence, references, assessment support and interview workflows.
- Data subjects: applicants, invited candidates, sourced and imported contacts, employees completing a team assessment, Authorized Users, referees and other contacts entered by the Customer.
- Data: identity and contact details, professional and résumé information, assessment answers and derived results, native-invitation guest addresses and meeting descriptions, transcripts, correspondence, references, hire outcomes and technical operation evidence.
- Activities: collection, rule-based derivation, AI-written explanations and drafts, storage, authorized disclosure, calendar and meeting creation, optional mailbox sending and destruction.
- Recipients and grants: the current Sub-processor List and section 11.5; separately acknowledged native invitations and separately granted mailbox and transcript permissions.
- Duration and exceptions: the category schedule in Privacy Policy section 9; legal holds and lawful instructions under section 11.2.