This Data Processing Agreement ("DPA") forms part of the agreement between Artashes Stepanyan Individual Entrepreneur (trading as Hyranse) ("Hyranse", "we", "us") and the business customer ("Customer", "you") that uses the Hyranse platform ("Service").
It applies when you are a Customer with a registered account and we process certain personal data on your behalf. It supplements our Terms of Service, Privacy Policy, and Acceptable Use Policy. If there is a conflict, this DPA prevails for processor obligations relating to Customer Personal Data (defined below); otherwise the Terms prevail.
1. Roles and scope — what this DPA covers
1.1 Customer Personal Data (this DPA applies)
For the categories below, Customer is the controller and Hyranse is the processor, processing only on Customer's documented instructions as set out in the Service, Terms, and this DPA:
- Customer account and user profile data (name, email, company, job title);
- Authentication and account settings;
- Service usage data tied to the account (search history, projects, API logs, credit usage);
- Support and communications you send to us about the Service;
- Demo booking details submitted through our website scheduling tools.
1.2 Candidate data (separate controller roles — not processor processing)
This DPA does not make Hyranse a processor of candidate database personal data on Customer's behalf.
Hyranse acts as an independent controller for collecting, organising, and maintaining the candidate database, as described in our Privacy Policy and Transparency Notice.
Customer acts as an independent controller for its own recruitment activities, including outreach to candidates accessed through the Service. Customer must establish its own lawful basis and comply with applicable law, including providing privacy information to candidates where required.
Access to candidate profiles through the Service is a controller-to-controller provision of data under our Terms, not a subprocessing arrangement for Customer Personal Data.
1.3 Website visitors
Cookie and website analytics data are described in our Cookie Policy and Privacy Policy. This DPA does not apply to anonymous website visitors who do not hold a Customer account.
2. Instructions and permitted processing
Hyranse will process Customer Personal Data only:
- To provide and support the Service under the subscription;
- As documented in the Terms, Privacy Policy, and Customer's use of account features;
- As required by applicable law (in which case we will inform Customer where permitted).
Customer instructs us to process Customer Personal Data by registering for and using the Service. Customer is responsible for ensuring its instructions comply with applicable data protection law.
3. Confidentiality and personnel
We ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations and receive appropriate training for their role.
4. Security
We implement appropriate technical and organisational measures to protect Customer Personal Data against unauthorised access, loss, or alteration, including access controls, encryption in transit where supported, and logical separation of customer environments. Measures are described at a high level in our Privacy Policy and may be updated as the Service evolves.
5. Subprocessors
Customer authorises Hyranse to use subprocessors to provide the Service. Current categories include:
- Cloud infrastructure and hosting providers;
- Paddle.com (payment processing and Merchant of Record);
- Calendly, LLC (demo scheduling);
- Email and customer support tools;
- Technical service providers that support AI-assisted search, parsing, and scoring features (where used to operate the Service);
- Analytics providers (only where the Customer or site visitor has consented to analytics cookies, where applicable).
Further detail is in our Privacy Policy. We impose data protection terms on subprocessors that process Customer Personal Data comparable to those in this DPA. We will notify Customer of material changes to subprocessors by updating the Privacy Policy or this page. Customer may object on reasonable grounds relating to data protection; if we cannot accommodate the objection, Customer may terminate the affected Service in accordance with the Terms.
6. International transfers
Customer Personal Data may be processed in the Republic of Armenia and in countries where our subprocessors operate. Where transfers from the UK or EEA require safeguards, we rely on appropriate mechanisms such as Standard Contractual Clauses (SCCs) or equivalent mechanisms recognised under applicable law, as described in our Privacy Policy.
7. Assistance with data subject requests
Taking into account the nature of processing, we will assist Customer with reasonable efforts to fulfil Customer's obligations to respond to data subject requests relating to Customer Personal Data we process as processor, where Customer cannot fulfil the request without our help.
Requests relating to candidate database data should be directed to Hyranse via the Candidate Privacy Center or our Privacy Policy contact details, because Hyranse is controller for that data.
8. Personal data breaches
We will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data we process as processor, and provide information reasonably available to help Customer meet its breach notification obligations.
9. Deletion and return
Upon termination or expiry of the Customer subscription, we will delete or anonymise Customer Personal Data within a reasonable period in accordance with our Privacy Policy and retention practices, except where retention is required by law or legitimate backup/archive cycles (after which data is deleted or anonymised).
10. Audits and information
Upon reasonable written request, we will provide information necessary to demonstrate compliance with this DPA. Customer may audit compliance no more than once per year on reasonable notice, subject to confidentiality and security restrictions, or accept third-party certifications or summaries where available.
11. US customers
US-resident Customer users may also have rights under state privacy laws. See our US Privacy Notice, which supplements the Privacy Policy for US residents.
12. Term
This DPA remains in effect for as long as Hyranse processes Customer Personal Data on Customer's behalf under an active account or as needed to comply with law.
13. Contact
Questions about this DPA: support@hyranse.com
Artashes Stepanyan Individual Entrepreneur (trading as Hyranse)
Country of establishment: Republic of Armenia
Email: support@hyranse.com
Website: https://hyranse.com