HIVEMIND
PricingIntegrationsReleases
Log InBook a Guided Demo
Log InBook a Guided Demo

Data Processing Addendum

The terms on which Hivemind processes personal data for its customers. Part of the Terms of Service for every account, Free included.

  • Up to date
  • Part of the Terms of Service
  • 18 sub-processors in Annex 3
TermsPrivacyDPASub-processorsCandidate privacy

Data Processing AddendumIntroduction

  1. Introduction
  2. 1Roles
  3. 2Instructions
  4. 3Confidentiality and personnel
  5. 4Security
  6. 5Sub-processors
  7. 6Assistance
  8. 7Audit
  9. 8International transfers
  10. 9Deletion and return
  11. 10Liability and precedence
  12. Annex 1Description of processing
  13. Annex 2Technical and organizational measures
  14. Annex 3Sub-processors

Introduction

This Data Processing Addendum (the "DPA") is part of the Hivemind Terms of Service (the "Terms") and applies to every Customer account, including Free accounts, from the moment the account is created. It governs personal data that RocketDevs, LLC, a Delaware limited liability company operating the Hivemind platform ("Hivemind"), processes on behalf of the Customer through the Services. Capitalized terms not defined here have the meaning in the Terms.

A Customer that has signed a Hivemind Customer Agreement is covered by the Data Processing Addendum attached to that agreement as Exhibit A, which governs instead of this one; a later published version of this DPA does not amend it.

1Roles

1.1 For , including , the Customer is the controller (or business) and Hivemind is the processor (or service provider). Where the Customer is itself a processor for its own clients (a staffing or recruitment agency), Hivemind is a sub-processor and the Customer warrants that its client's instructions permit this DPA.

1.2 Hivemind is an independent controller, as described in the Privacy Policy, for:

(a) account, billing, security, support, and business-contact data;

(b) de-identified usage data; and

(c) its contact database (Privacy Policy section 5A).

"Privacy Policy" means the Hivemind privacy policy published at hivemind.hr/privacy-policy. This DPA does not cover that processing except as 1.2A and 8.7 provide.

1.2A For (Terms section B9) each party is an independent controller. Hivemind is responsible for the lawfulness of its supply and the Customer for its own use, lawful basis, notices, and responses to the people concerned; the restrictions attach to the Delivered Fields as the Terms define them. Anything a Candidate later gives the Customer directly is Customer Data under 1.1. Section 8.7 governs transfers of Sourced Records.

1.3 Annex 1 describes the subject matter, duration, nature, purpose, data categories, and data subjects.

2Instructions

2.1 Hivemind processes only on the Customer's documented instructions, which are:

(a) the Terms;

(b) this DPA;

(c) the Customer's configuration and use of the Services; and

(d) any further written instruction the parties agree.

Hivemind tells the Customer if an instruction appears to infringe data protection law, and may pause that processing.

2.2 Hivemind does not:

(a) sell Customer Data;

(b) share Customer Data for cross-context behavioral advertising;

(c) retain, use, or disclose Customer Data outside the direct business relationship or for any purpose other than the Services; or

(d) combine Customer Data with data from other sources except as the Services explicitly require.

Hivemind certifies that it understands and will comply with these restrictions, and will notify the Customer if it can no longer do so. No advertising tag loads on application, candidate, or assessment pages.

2.3 Hivemind does not use identifiable Customer Data to train any model that serves other customers, and does not license any recording of a call, interview, or meeting for training, unless the Customer opts in under section B10 of the Terms. Annex 3 states, for each model provider, its training and retention position. Hivemind's OpenAI account operates with zero data retention and its Google account on the paid tier, under which Google does not use the data to improve its products. Vapi, which runs AI phone screens, keeps recordings and transcripts under its own terms, which permit it to use them to improve its models, and Hivemind has no zero-retention arrangement with Vapi.

3Confidentiality and personnel

Hivemind ensures that everyone it authorizes to process is bound by confidentiality, trained, and limited to what their role requires.

4Security

Hivemind implements and maintains the technical and organizational measures in Annex 2, which are appropriate to the risk of processing recruitment data, and will not reduce their overall level of protection during the term of the Customer's plan.

5Sub-processors

5.1 The Customer authorizes Hivemind to use the sub-processors in Annex 3, published at https://hivemind.hr/legal/subprocessors, and to appoint new ones. Hivemind gives at least 30 days' notice of a new sub-processor by email to the account owner and to anyone subscribed at that page.

5.2 The Customer may object within that period on reasonable data-protection grounds. The parties will try to resolve the objection; if they cannot within 30 days, the Customer may terminate the affected Service with a pro-rata refund of prepaid fees.

5.3 Hivemind binds every sub-processor to obligations no less protective than this DPA and remains liable for their performance.

5.4 For each model provider, Annex 3 states whether the account is configured for zero retention of prompts and no training on .

6Assistance

6.1 Data subject requests. Hivemind forwards to the Customer within 5 Business Days any request it receives that concerns , and provides the help the Customer reasonably needs to respond, including an export and a deletion carried out by Hivemind under section 9. Hivemind does not answer such a request itself unless the Customer asks or the law requires.

6.2 Impact assessments and audits. Hivemind provides the technical information the Customer reasonably needs for a data protection impact assessment, an algorithmic impact assessment, a bias audit, or a prior consultation with a supervisory authority, including the inventory, the stored in the Services, and the selection-rate and scoring-rate data the Services hold.

6.3 Security incidents. Hivemind notifies the Customer without undue delay and within 48 hours of becoming aware of a personal data breach affecting Customer Data, with the information then available, such as:

(a) the nature of the breach;

(b) the categories and approximate numbers concerned;

(c) its likely consequences;

(d) the measures taken and proposed; and

(e) a contact point.

Hivemind updates the Customer as it learns more. Hivemind does not notify data subjects or authorities on the Customer's behalf unless asked or required.

7Audit

On written request no more than once a year (or after a breach), Hivemind provides its current security overview and the summary of its most recent security assessment described in Annex 2, under confidentiality. Where those do not reasonably answer the Customer's question, the Customer or an independent auditor it appoints may audit Hivemind's relevant controls:

(a) on 30 days' notice;

(b) during Business Hours;

(c) without disrupting the Services;

(d) at the Customer's cost; and

(e) subject to Hivemind's security and confidentiality rules.

8International transfers

8.1 Hivemind processes in the United States (Amazon Web Services us-west-2, Oregon) and through the sub-processors in Annex 3 in the locations published for each of them at https://hivemind.hr/legal/subprocessors.

8.2 For transfers of personal data from the EU or EEA to a country without an adequacy decision, the parties enter into the Standard Contractual Clauses adopted by Commission Decision 2021/914:

(a) Module Two (controller to processor) where the Customer is a controller; and

(b) Module Three (processor to processor) where the Customer is a processor,

with these selections:

(i) Clause 7 (docking) included;

(ii) Clause 9(a) option 2 (general authorization, 30 days);

(iii) Clause 11 optional language not included;

(iv) Clause 13 as applicable to the Customer;

(v) Clause 17 option 1, the law of Ireland; and

(vi) Clause 18 the courts of Ireland.

Annex I is completed by Annex 1 of this DPA, Annex II by Annex 2, and Annex III by Annex 3.

8.3 For transfers from the UK, the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner (version B1.0) applies, with Table 4 allowing either party to end it as set out there.

8.4 For transfers from Switzerland, the SCCs apply with the FDPIC's required adaptations.

8.5 If Hivemind certifies to the EU-US Data Privacy Framework and its UK and Swiss extensions, that certification applies to covered transfers and the SCCs remain in place.

8.6 Hivemind has assessed the laws of the destination countries and implements the supplementary measures in Annex 2. If it receives a government request for Customer Data it will, where legally permitted, tell the Customer, challenge an unlawful or overbroad request, and disclose only the minimum required.

8.7 Where Hivemind has confirmed in writing under the Terms section B9 that profiles of people in the EU, EEA, or UK are available through sourcing, transfers of from Hivemind to the Customer are made under Module One (controller to controller) of the same Standard Contractual Clauses, with the selections in 8.2 applied as far as Module One allows, and under the UK Addendum in 8.3. Until that confirmation no Sourced Record concerns a person in those territories and this section does not operate.

9Deletion and return

9.1 During the term of its plan the Customer can delete Candidates in the product. A deletion in the product removes the Candidate's:

(a) stage answers;

(b) AI evaluations;

(c) chats;

(d) recruiter comments;

(e) workflow logs; and

(f) shortlist entries.

It does not remove:

(a) call transcripts and summaries;

(b) email, SMS, LinkedIn, and WhatsApp messages;

(c) email tracking events;

(d) calendar entries; or

(e) files, namely:

(i) CVs;

(ii) video answers;

(iii) recordings; and

(iv) signed offers.

On the Customer's written request Hivemind deletes those as well within 30 days, together with the copies held by Vapi, Twilio, PostHog, SessionRewind, and Crisp so far as each offers deletion, and confirms the deletion in writing.

9.2 After termination or expiry and the 30-day export window in section B22 of the Terms, Hivemind deletes or irreversibly de-identifies all within a further 30 days on the same basis, except what the law requires it to keep, which stays protected under this DPA and is deleted when that requirement ends. On request Hivemind confirms deletion in writing.

9.3 Database backups roll over within seven days of a deletion. Customer files are not held in a separate backup.

10Liability and precedence

Liability under this DPA is subject to section B19 of the Terms, except that nothing in this DPA or the Terms limits or excludes a liability to a data subject or a supervisory authority that data protection law does not allow to be limited or excluded, and the SCCs govern liability for the transfers they cover. Where the SCCs conflict with this DPA, the SCCs prevail for the transfers they govern. Where this DPA conflicts with the Terms about personal data, this DPA prevails. This DPA is governed by the law that governs the Terms, except where the SCCs or the law of the Customer's country require otherwise.


Annexes

Annex 1Description of processing

Subject matter Recruitment, selection, assessment, interview, offer, and related workforce processes run by the Customer through the Services
Duration The term of the Customer's plan plus the export and deletion periods in section 9
Nature Hosting, storage, transmission, parsing, transcription, summarization, scoring, ranking, matching, messaging, scheduling, e-signature, analytics, backup, support, and deletion
Purpose Providing the Services to the Customer as configured by it
Data subjects Candidates (applicants, employees, contractors, and sourced prospects once the Customer has contacted them or added them to a pipeline); the Customer's users, hiring managers, interviewers, and referees; the Customer's clients' personnel where the Customer is an agency
Categories of data Identity and contact; application and professional history; screening, assessment, and interview data including recordings and transcripts; AI-generated scores, rankings, summaries, and inferences; notes and hiring status; offer and signature records; communications; technical and usage data
Special categories Not requested by the Services. May occur where a Candidate volunteers it, an accommodation is requested, or the Customer lawfully runs equal-opportunity monitoring or bias testing. Never used as a selection criterion
Frequency Continuous
Competent supervisory authority (SCCs) Determined by Clause 13; where the Customer has no EU establishment and no representative, the authority of the Member State where the data subjects are located

Annex 2Technical and organizational measures

Hosting. is hosted on Amazon Web Services in us-west-2 (Oregon).

Access control. Role-based permissions within the Customer's account. Customer users sign in with a password or Google sign-in. Multi-factor authentication, single sign-on, SAML, and SCIM are not currently offered.

Encryption. Encryption in transit (TLS). Encryption at rest through AWS storage encryption on the database and on file storage. Integration tokens, API keys, and SMTP passwords are additionally encrypted by the application.

Logging and monitoring. Application monitoring and alerting through New Relic and Datadog. Application logs can contain Customer Data, including call transcripts and grading output. The Services do not currently keep a Customer-visible access log.

Security assessment. A Google Cloud Application Security Assessment (CASA) Tier 2, completed in November 2025 by TAC Security, which included a penetration test. Its summary is provided under confidentiality on request.

Incident response. Notification to the Customer's account owner and notice email within 48 hours of awareness under section 6.3, with updates as Hivemind learns more.

Resilience. Automatic database backups with point-in-time recovery over a rolling seven-day window. Customer files are not held in a separate backup.

Data lifecycle. Deletion under section 9. The Services delete nothing on a schedule; Customer Data stays until the Customer, or Hivemind on the Customer's request, deletes it.

Supplementary measures for transfers. Encryption in transit and at rest, and the government-request procedure in section 8.6.

Annex 3Sub-processors

Published and maintained at https://hivemind.hr/legal/subprocessors, which lists each sub-processor's processing location and governs where it and this table differ. The table below is the current list.

Provider Role Data Location Model training and retention
Amazon Web Services (S3, database, Transcribe) Hosting; storage of CVs and recorded video answers; backups; speech to text for interview answers and meeting recordings All United States (us-west-2, Oregon) Hivemind applies the AWS AI services opt-out policy to its account
OpenAI (gpt-3.5-turbo, gpt-4o-mini, gpt-4o, gpt-4, gpt-realtime) CV scoring and parsing; coding answer grading; personality evaluation; live AI voice interviews and their feedback; meeting summaries; question and assessment generation; candidate search; pipeline generation CVs, answers, transcripts, live interview audio United States Zero data retention, no training
Google (Gemini API, gemini-2.5-pro) Grading written open-ended answers and video and audio interview answers Answer text and transcripts As published Paid tier: Google does not use the data to improve its products; prompts may be logged for a limited period for abuse monitoring
Vapi AI voice phone screens: call handling, recording, transcription, evaluation Audio, recordings, transcripts, phone numbers United States Records calls by default and keeps recordings and transcripts under Vapi's own terms, which permit use to improve its models; no zero-retention arrangement on Hivemind's plan
Cartesia Synthetic voices for AI phone screens Agent speech text only, no Customer Data As published Not applicable
Deepgram (Nova 3), engaged through Vapi Speech to text on phone screens Audio As published Under Vapi's terms; no zero-retention arrangement
Twilio SMS; phone numbers for AI and recruiter calls; call recordings; phone number verification Phone numbers, message content, call audio United States Not applicable
SendGrid Candidate email sending Email addresses, message content United States Not applicable
Unipile LinkedIn and WhatsApp messages Profile identifiers, message content France Not applicable
PostHog (US cloud) Screen recording of assessment sessions; product analytics On-screen activity on assessment pages United States Not applicable
SessionRewind Screen recording of assessment sessions On-screen activity on assessment pages As published Not applicable
Crisp Support chat in the app and on candidate pages Chat content, contact details European Union (Netherlands, Germany) Not applicable
Goody Gift sending, when a Customer sends a gift Candidate name and delivery details United States Not applicable
People Data Labs, Apollo.io Enrichment of candidate profiles Names, employers, contact details United States Not applicable
cal.com Interview scheduling Name, email, availability United States Not applicable
New Relic, Datadog Logging, monitoring, and alerting Technical logs, which include Customer Data such as call transcripts and grading output As published Not applicable
Google reCAPTCHA Spam protection on application forms Device and interaction data United States Not applicable
Stripe Customer subscriptions and credits Customer billing data only, no United States Not applicable

Integrations the Customer activates are not Hivemind sub-processors and act under the Customer's own agreements: the Customer's mailbox (Gmail, Microsoft Graph, SMTP or IMAP), Zoom, Google Meet, and Microsoft Teams recordings, Ashby, Greenhouse, Slack, Zapier, customer webhooks, and a Customer's own OpenAI account.

Hivemind's own sales tooling (Lemlist, Smartlead, MillionVerifier, the Apollo dialer) processes Hivemind's business-contact data as described in the Privacy Policy section 5 and does not touch Customer Data.

Questions about this DPA.

accounts@gethivemind.ai
HIVEMIND

Where hiring flows

Company

  • About
  • Hivemind AI
  • Modules
  • Blog
  • Docs
  • Releases
  • Reviews
  • Pricing
  • Careers

Community

  • LinkedIn
  • Twitter
  • Email

Legal

  • Terms
  • Privacy
  • DPA
  • Sub-processors
  • Candidate privacy

Reviews

  • G2
  • Capterra
  • Trustpilot
  • Product Hunt
  • Google

Comparisons

  • Hivemind vs HireVue
  • Hivemind vs Ashby
  • Hivemind vs Lever
  • Hivemind vs hireEZ
  • Hivemind vs TestGorilla
LinkedInTwitter
Copyright © 2026 Hivemind. All Rights Reserved.