Compliance & Data Protection
Everything your compliance team needs — DPA, sub-processor list, data retention schedules, and your rights as a data controller. Built for recruiters who handle candidate data every day.
UK GDPR aligned
ICO registered framework
No CV storage
Unsaved content discarded immediately
EU SCCs in place
All third-country transfers covered
DPA available
On request for enterprise clients
Last reviewed: 25 July 2026 · For DPA requests or compliance queries: recruiterbrief12@gmail.com
You are the data controller.
We are the data processor.
When you submit candidate CVs, screening notes or application data into RecruiterBrief, you do so as the data controller — the organisation that determines the purpose and means of processing. RecruiterBrief acts as a data processor, processing that data on your behalf solely to generate the outputs you request.
This means you are responsible for ensuring you have a lawful basis to process candidate data — typically legitimate interest in the context of an active recruitment process, or consent where required.
You must also ensure candidates are informed that their data may be processed by AI tools as part of your recruitment workflow, either through your own privacy notice or your privacy policy.
What RecruiterBrief commits to as data processor
- Process data only on your documented instructions
- Never use submitted candidate data to train AI models
- Discard unsaved submitted content immediately — it is never stored on our servers
- Maintain technical and organisational measures to protect data
- Notify you of any personal data breach affecting your data without undue delay
- Delete or return your data on termination of service
- Maintain records of all processing activities (Article 30)
- Co-operate with any ICO investigation or audit upon request
Your responsibilities as data controller
- →Maintain a lawful basis for processing candidate data
- →Inform candidates that AI tools are used in your process
- →Respond to candidate Subject Access Requests within 30 days
- →Ensure you are registered with the ICO (if UK-based)
Data Processing Agreement (DPA)
Under Article 28 of the UK GDPR and EU GDPR, you as data controller are required to have a written contract in place with any data processor you use. RecruiterBrief's standard DPA is available on request and covers all processing activities described in this page.
Standard DPA
All plansAvailable on request for all users. Covers all processing activities described on this page. Based on ICO model clauses.
Custom DPA
EnterpriseFor enterprise accounts or agencies with specific contractual requirements. Contact us to discuss.
Request your DPA
Email us and we will send you a signed DPA within 2 business days.
The DPA incorporates the ICO's standard contractual clauses for UK transfers and the European Commission's Standard Contractual Clauses (SCCs) for EEA data transfers, where applicable.
Current sub-processors
Last updated: 25 July 2026
RecruiterBrief uses the following sub-processors in the delivery of the platform. Each has been assessed for GDPR compliance and has a Data Processing Agreement in place with us. Where data is transferred outside the UK or EEA, Standard Contractual Clauses (SCCs) or UK IDTA are in place.
Google LLC
DPA in placePurpose
AI content generation (Gemini)
Data processed
Text content you submit (CVs, notes, job specs)
Location
USA — EU SCC in place
Retention
Not retained after response; data is not used to train models
Neon Inc.
DPA in placePurpose
Database storage (PostgreSQL)
Data processed
Account data, saved outputs, usage logs
Location
USA (AWS) — EU SCC in place
Retention
Retained until account deletion
Stripe Inc.
DPA in placePurpose
Payment processing & subscription management
Data processed
Billing name, email, payment method metadata
Location
USA — EU SCC in place
Retention
Retained per Stripe legal and financial obligations (typically 7 years)
Vercel Inc.
DPA in placePurpose
Application hosting & content delivery
Data processed
IP addresses, request logs, session data
Location
USA/EU edge nodes — EU SCC in place
Retention
Log data retained for 30 days
Uploadcare Inc.
DPA in placePurpose
File upload processing (CV and document handling)
Data processed
Files uploaded by users for processing
Location
USA — EU SCC in place
Retention
Files deleted after processing; not stored long term
Sub-processor change notification: We will provide at least 14 days' notice before adding or replacing any sub-processor that handles personal data. If you have a DPA in place with us, we will notify you directly by email.
Data retention schedule
RecruiterBrief retains different categories of data for different periods, based on legal requirement or legitimate interest. The schedule below applies to all users. Data is deleted securely at the end of the applicable retention period.
The most important thing to know
Content you submit to RecruiterBrief tools (CVs, screening notes, job specs) and do not save is never stored on our servers. It is passed directly to the AI API, a response is generated, and it is discarded immediately. We have no record of it.
Category
Account data
Data
Name, email address, account settings
Retention
Duration of active account + 30 days post-deletion request
Legal basis
Contract performanceCategory
Saved outputs
Data
Generated briefs, CVs, emails, question packs saved to your dashboard
Retention
Until you delete them, or account closure. Auto-deleted 12 months after account inactivity.
Legal basis
Contract performance / legitimate interestCategory
Submitted content (unsaved)
Data
CVs, notes, job specs submitted to tools but not saved
Retention
Not stored. Content is passed to the AI API and discarded immediately. Not retained on our servers.
Legal basis
Not applicable — no retentionCategory
Usage logs
Data
Tool usage count, timestamps, feature access
Retention
12 months rolling
Legal basis
Legitimate interest (fraud prevention, usage enforcement)Category
Billing records
Data
Subscription status, payment history (held by Stripe)
Retention
7 years (legal financial obligation)
Legal basis
Legal obligationCategory
Security & access logs
Data
IP addresses, login attempts, session tokens
Retention
30 days
Legal basis
Legitimate interest (security)Category
AI cost and audit logs
Data
Anonymised token usage, response lengths (no content)
Retention
90 days
Legal basis
Legitimate interest (platform monitoring)Upon account deletion, all associated personal data is removed within 30 days unless retention is required by law (e.g. billing records). Anonymised aggregated usage data may be retained for platform analytics.
Data subject rights
Under the UK GDPR (and EU GDPR where applicable), you and your candidates have the following rights. We will respond to any rights request within 30 calendar days of receipt.
Right of access
Request a copy of all personal data we hold about you. We will respond within 30 days.
Right to rectification
Correct inaccurate or incomplete data held in your account at any time.
Right to erasure
Request full deletion of your account and associated data. We will action within 30 days.
Right to restrict processing
Pause how we process your data while we investigate a concern.
Right to data portability
Receive your saved outputs and account data in a machine-readable format.
Right to object
Object to processing based on legitimate interest, including marketing.
How to submit a rights request
Email recruiterbrief12@gmail.com with the subject line "Rights Request" and include your name, email address, and a description of your request. We may ask for identity verification before processing.
If you are a candidate whose data was submitted by a recruiter, you should contact that recruiter directly in the first instance, as they are the data controller responsible for your data. If you cannot reach them, contact us and we will assist.
How we protect your data
Encryption in transit
All data transmitted between your browser and RecruiterBrief is encrypted using TLS 1.2+. All API calls to sub-processors use HTTPS.
Encryption at rest
Data stored in our database (Neon PostgreSQL) is encrypted at rest using AES-256.
Access controls
Production database access is restricted to authorised personnel only. Role-based access controls limit what each system can see.
No CV storage (by default)
Content submitted to tools and not explicitly saved is never written to disk. It exists only in memory for the duration of the API call.
Breach notification
In the event of a personal data breach, we will notify affected users without undue delay and in any case within 72 hours of becoming aware.
Dependency & vulnerability monitoring
We monitor platform dependencies for known vulnerabilities and apply security patches promptly.
Using RecruiterBrief with candidate data
Recruiters process candidate personal data every day — CVs, contact details, screening call notes, salary expectations. When you use RecruiterBrief as part of that process, here is what good practice looks like.
Only submit data for active candidates
Only paste CV or application data into RecruiterBrief for candidates who are actively in a recruitment process you're managing. Don't use it to process data held in an archive without a current purpose.
Update your privacy notice
Add a note to your candidate privacy notice or fair processing statement explaining that AI tools are used in your workflow for tasks like CV analysis, candidate summary generation, and interview preparation. This satisfies Article 13/14 transparency obligations.
Don't save unnecessary data
If you generate a brief or email but don't intend to keep it, don't save it to your dashboard. Unsaved outputs are never stored — only save what you need to refer back to.
Handle candidate rights requests promptly
If a candidate requests deletion of their data, check your RecruiterBrief dashboard and delete any saved outputs relating to them. Email us and we will confirm deletion from our system.
Don't submit special category data
Avoid submitting special category personal data (health conditions, religious beliefs, ethnic origin, etc.) unless strictly necessary. RecruiterBrief tools are not designed or tested for processing this category of data.
Supervisory authority
RecruiterBrief's supervisory authority is the Information Commissioner's Office (ICO) in the United Kingdom.
ico.org.ukApplicable law
UK GDPR (as retained in UK law by the European Union (Withdrawal) Act 2018), the Data Protection Act 2018, and where applicable, the EU GDPR for EEA data subjects.
Data protection contact
For all data protection queries, DPA requests, breach notifications or rights requests:
recruiterbrief12@gmail.comQuestions about compliance?
Whether you need a signed DPA, have questions about candidate data handling, or want to discuss how RecruiterBrief fits your organisation's GDPR obligations — get in touch. We respond to all compliance queries within 2 business days.