Data processing agreement
Version 0.1. This agreement applies to every workspace under the terms of service; a countersigned copy is available on request from privacy@interviewstack.io. at legal@interviewstack.io.
Last updated 8 September 2026.
1. Parties and roles
This agreement is between the customer (the Controller: the employer using InterviewStack to screen its job candidates) and [LEGAL ENTITY NAME], [REGISTERED ADDRESS] (the Processor, "InterviewStack"). It forms part of the customer's terms of service and applies whenever InterviewStack processes personal data on the customer's behalf.
2. Subject matter, duration, nature and purpose
Processing needed to conduct AI screening interviews the customer configures, to record them where the customer enables it, to produce written assessments for the customer's review, and to detect misuse. Duration: the period the customer holds a workspace plus the retention period the customer sets, after which data is deleted as described in section 8.
3. Data subjects and categories
Data subjects: job candidates the customer invites. Categories: name and email; spoken and typed interview answers and their transcript; screen, audio and camera recordings where enabled; session events (tab switches, time away, camera state, whether the connection or browser changed during the interview); technical data (IP address, browser, and a salted hash of the IP address kept only to detect a change within one interview). InterviewStack does not intentionally process special categories of data and does not perform biometric identification or emotion inference.
4. Processor obligations
- Process personal data only on the customer's documented instructions, which include the configuration the customer sets in the product; inform the customer if an instruction appears to infringe applicable law.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures (Annex 2).
- Assist the customer, taking into account the nature of processing, in responding to data subject requests (access, correction, deletion, objection, human review) within the timeframes the law requires; deletion requests received directly by InterviewStack are completed within 30 days and the customer is informed.
- Assist the customer with data protection impact assessments and prior consultation, including by providing the information in the monitoring page and the trust page.
- Make available the information necessary to demonstrate compliance, and allow for and contribute to audits, including by completing security questionnaires and, where the customer reasonably requires, an audit conducted by the customer or an auditor it mandates, on reasonable notice and no more than once a year unless a breach has occurred.
5. Subprocessors
The customer gives general authorisation to the subprocessors listed at /hire/legal/subprocessors. InterviewStack notifies the customer at least 30 days before adding or replacing a subprocessor; the customer may object on reasonable data protection grounds, in which case the parties work in good faith to resolve the objection and, failing that, the customer may terminate the affected service. InterviewStack imposes data protection obligations on each subprocessor equivalent to this agreement and remains liable for their performance.
6. Security
Measures include encryption in transit and at rest, workspace-scoped access control, per-candidate hashed invitation credentials that expire and cannot start or re-take an interview once it is submitted, read-only expiring review links, server-side ownership of interview state, product analytics switched off on candidate pages, and scheduled deletion. Details are maintained on the trust page, which forms Annex 2.
7. Personal data breach
InterviewStack notifies the customer without undue delay after becoming aware of a personal data breach affecting the customer's data, providing the information reasonably available (nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken or proposed), and updates it as more becomes known, so the customer can meet its own 72-hour notification duty.
8. Return and deletion
At the end of the retention period the customer sets, and on termination, InterviewStack deletes candidate personal data (names, emails, recordings, transcripts, written assessments); an anonymous numeric score may be retained in the customer's records. Before deletion the customer may export screening results (CSV) and review recordings and transcripts in the product. Copies required by law are retained only as long as the law requires.
9. International transfers
Processing takes place in North America: application and database in the United States, recordings in Cloudflare's Western North America storage region. For personal data subject to the GDPR or UK GDPR, transfers rely on the EU-US Data Privacy Framework and its UK extension where InterviewStack is certified, and otherwise on the European Commission's Standard Contractual Clauses (2021/914, Module Two, and Module Three for onward transfers to subprocessors) with the UK International Data Transfer Addendum, which are incorporated by reference and executed with this agreement.
10. Liability and precedence
Liability is governed by the terms of service. In the event of conflict between this agreement and those terms concerning the processing of personal data, this agreement prevails; the Standard Contractual Clauses prevail over both where they apply.
Annex 1. Processing details
As set out in sections 2 and 3. Frequency: continuous while the customer holds a workspace. Retention: the customer's configured period, 180 days by default.
Annex 2. Technical and organisational measures
As published at /hire/trust on the date of signature.