Data Processing Agreement
Last updated: March 20, 2026
1. Introduction
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between TuraHire (“Processor,” “we,” “us”) and you (“Controller,” “you,” “your”) and governs the processing of personal data by TuraHire on your behalf.
This DPA applies where and only to the extent that TuraHire processes personal data on your behalf in the course of providing the Service, and such personal data is subject to data protection laws of the European Union, the European Economic Area, the United Kingdom, Switzerland, or the California Consumer Privacy Act.
2. Definitions
- “Controller” means the entity that determines the purposes and means of the processing of personal data.
- “Processor” means the entity that processes personal data on behalf of the Controller.
- “Data Subject” means an identified or identifiable natural person whose personal data is processed.
- “Personal Data” means any information relating to a Data Subject that can be used to directly or indirectly identify that person.
- “Processing” means any operation performed on personal data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.
- “Sub-processor” means any third party engaged by the Processor to process personal data on behalf of the Controller.
- “Standard Contractual Clauses (SCCs)” means the contractual clauses approved by the European Commission for the transfer of personal data to countries outside the EEA.
- “Supervisory Authority” means an independent public authority established by an EU Member State to monitor the application of data protection regulations.
3. Scope and Purpose of Processing
TuraHire processes Candidate Data (resumes, professional profiles, interview notes) uploaded or connected by the Controller. The processing is carried out for the following purposes:
- Resume parsing and structured data extraction
- Candidate matching and ranking against job requirements
- Semantic search across candidate profiles
- Interview management and feedback collection
Categories of Data Subjects: Job candidates and applicants whose information is uploaded or connected to the Service by the Controller.
Types of Personal Data: Names, contact information (email addresses, phone numbers, physical addresses), employment history, education history, professional skills, certifications, and any other information contained in resumes or professional profiles.
4. Obligations of the Processor
TuraHire, as the Processor, shall:
- Process personal data only on documented instructions from the Controller, unless required to do so by applicable law.
- Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organizational security measures to ensure a level of security appropriate to the risk of processing.
- Assist the Controller in responding to requests from Data Subjects exercising their rights under applicable data protection law.
- Assist the Controller in ensuring compliance with obligations related to security of processing, notification of data breaches, data protection impact assessments, and prior consultation with supervisory authorities.
- At the choice of the Controller, delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies unless applicable law requires storage of the personal data.
- Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
5. Sub-processors
TuraHire uses the following sub-processors to deliver the Service. We will notify you at least thirty (30) days before adding or replacing a sub-processor.
| Sub-processor | Purpose | Location | Security Certifications |
|---|---|---|---|
| Google (Gemini API) | AI resume parsing and candidate analysis | United States | SOC 2 Type II, ISO 27001 |
| Voyage AI | Vector embedding generation | United States | SOC 2 Type II |
| Pinecone | Vector database for semantic search | United States | SOC 2 Type II, ISO 27001 |
| Supabase | Database hosting and authentication | United States | SOC 2 Type II, ISO 27001 |
| Clerk | User authentication and session management | United States | SOC 2 Type II |
| Composio | Third-party account integration (OAuth) | United States | SOC 2 Type II |
| Redis (Upstash) | Caching and task queue | United States | SOC 2 Type II |
6. Data Security Measures
TuraHire implements and maintains appropriate technical and organizational measures to protect personal data, including but not limited to:
- Encryption: All data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 encryption.
- Access Controls: Role-based access controls with multi-tenancy isolation ensure that only authorized personnel can access personal data.
- Security Assessments: Regular security assessments and vulnerability scanning are conducted to identify and remediate potential threats.
- Employee Training: All employees with access to personal data undergo security training and are bound by confidentiality agreements.
- Incident Response: Documented incident response procedures are maintained and tested to ensure rapid detection, containment, and resolution of security incidents.
- Network Security: Network security monitoring, intrusion detection, and firewall protections are in place to safeguard infrastructure.
7. Data Subject Rights
TuraHire will assist the Controller in fulfilling its obligations to respond to Data Subject requests exercising their rights under applicable data protection law, including the rights of:
- Access to their personal data
- Rectification of inaccurate personal data
- Erasure of personal data (“right to be forgotten”)
- Data portability
- Restriction of processing
- Objection to processing
TuraHire will respond to the Controller's instructions regarding Data Subject requests within thirty (30) days of receiving the instruction.
Reasonable assistance will be provided at no additional cost for standard requests. For requests that are manifestly unfounded, excessive, or require extraordinary effort, TuraHire may charge a reasonable fee based on administrative costs.
8. Data Breach Notification
TuraHire will notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting the Controller's data.
The notification will include, to the extent available:
- The nature of the personal data breach
- The categories and approximate number of Data Subjects affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects
9. Data Return and Deletion
Upon termination of the Service, the Controller may request the return of all personal data in JSON or CSV format. Such requests must be made within thirty (30) days of termination.
After the 30-day retrieval period, TuraHire will delete all personal data from production systems within 30 days and from backup systems within 90 days.
Anonymized, aggregated data that cannot be used to identify individuals may be retained for service improvement and analytics purposes.
10. Audit Rights
The Controller may audit TuraHire's compliance with this DPA once per year with thirty (30) days written notice.
- Audits will be conducted during normal business hours and will not unreasonably interfere with TuraHire's operations.
- TuraHire will provide reasonable cooperation and access to relevant documentation.
- The Controller bears the cost of any audit unless the audit reveals material non-compliance by TuraHire.
11. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA) or the United Kingdom, TuraHire relies on the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum as the legal mechanism for such transfers.
TuraHire will ensure that all sub-processors engaged in the processing of personal data provide equivalent data protection safeguards and are bound by appropriate contractual obligations.
12. Liability
Each party's liability under this DPA is subject to the limitations of liability set forth in the Terms of Service.
Nothing in this DPA limits either party's liability for breaches of data protection obligations that cannot be limited under applicable law.
13. Term and Termination
This DPA remains in effect for the duration of TuraHire's processing of personal data on behalf of the Controller.
This DPA automatically terminates when the Terms of Service terminate.
Obligations relating to data deletion, confidentiality, and audit rights survive termination of this DPA.
14. Contact
If you have any questions about this Data Processing Agreement, please contact us:
Data Protection inquiries: privacy [at] turahire.com
General inquiries: admin [at] turahire.com

