Legal

Data Processing Agreement

The terms that apply when SuprHiro processes personal data on your behalf as a customer.

Last updated: 30 September 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the customer (“you”) and Zuvomo, which operates SuprHiro (“we”). It applies automatically when you use SuprHiro to process personal data of candidates, new hires, employees or your own users. If it conflicts with the Terms on a data-protection point, this DPA wins. If you need a countersigned copy, email hiring@supahiro.co.

1. Definitions

“Data Protection Law” means the laws that apply to the processing, including India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and its rules, the Information Technology Act, 2000, and — where they apply — the EU and UK GDPR. “Personal data”, “processing”, “controller”, “processor”, “data fiduciary”, “data principal” and “personal data breach” have the meanings given in that law. “Customer Personal Data” means personal data within Customer Data, as defined in the Terms.

2. Roles

  • You are the controller / data fiduciary for Customer Personal Data: you decide which roles to hire for, which candidates to consider, what to collect and how to use it.
  • We are your processor. We process Customer Personal Data only to provide the Service and on your documented instructions — which are these Terms, this DPA, and the settings and actions you and your users take in SuprHiro.
  • We are a controller only for our own account, billing, security and website data, as described in the Privacy Policy.

If we believe an instruction breaks Data Protection Law, we will tell you and may decline to carry it out.

3. Details of the processing

  • Subject matter and purpose: providing the SuprHiro hiring and onboarding platform — applications, screening, AI calls and summaries, scheduling, messaging, offers, onboarding, background-check tracking and reporting.
  • Duration: the term of your subscription, plus the export and deletion period in section 10.
  • Data principals: job applicants and sourced candidates; new hires and employees; your users (recruiters, hiring managers, interviewers, admins); referees and other people named in the data you upload.
  • Categories of data: identity and contact details; resumes, work history, education and skills; current and expected pay; interview notes, feedback, scorecards and assessments; messages; call recordings and transcripts; interview transcripts; offer details.
  • Sensitive categories, where you choose to collect them: government identifiers (PAN, Aadhaar, passport), bank account details, date of birth, gender, blood group, and background-check results, which may include criminal-record and credit checks.

4. Our obligations

  • Process Customer Personal Data only on your instructions, as described in section 2.
  • Make sure everyone we authorise to access it is bound by confidentiality, and give access only to those who need it to run or support the Service.
  • Apply the security measures in section 8.
  • Help you respond to requests from data principals — to access, correct, erase or port their data — and pass on promptly any request we receive directly, rather than answering it ourselves unless you ask us to.
  • Give you reasonable help with data-protection impact assessments and consultations with regulators, where they relate to the Service.
  • Not sell Customer Personal Data, use it for advertising, or use it to train AI models.

5. Your obligations

  • Have a lawful basis for the data you put into SuprHiro and give data principals the notices the law requires — including candidates you import, upload or source, who did not apply through your careers page.
  • Obtain any consent the law requires before using AI phone screening, recording calls or interviews, switching on the AI notetaker, or messaging candidates on WhatsApp or other channels, and honour requests to stop.
  • Collect government identifiers, bank details and background-check information only where you are entitled to, and only what you need.
  • Configure automations responsibly and review AI output before relying on it (see Responsible AI).
  • Keep your users’ accounts secure and remove access for people who leave.

6. Sub-processors

You authorise us to use the sub-processors listed on our Sub-processors page. Several are used only when you switch on the related feature. We impose data-protection terms on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance.

We will update that page before adding or replacing a sub-processor and, for a new sub-processor of Customer Personal Data, tell workspace admins by email at least 14 days in advance. If you have a reasonable data-protection objection, tell us within that period; we will try to find an alternative, and if we cannot, you may stop using the affected feature or end the affected part of the Service.

7. AI processing

To provide AI features we send the minimum data needed — such as resume text, transcripts and interview notes — to the AI providers listed as sub-processors, only to produce the result you asked for. We do not use Customer Personal Data to train our own or any third party’s AI models.

8. Security

We maintain technical and organisational measures appropriate to the risk, which currently include:

  • HTTPS for all traffic between browsers, our servers and our providers.
  • AES-256-GCM encryption at rest for government identifiers, bank account numbers, call and interview transcripts, email and chat messages, and connected-account credentials.
  • Passwords stored only as salted bcrypt hashes.
  • Logical separation of every customer’s data, enforced on every query, with automated tests for cross-workspace access.
  • Role-based access control inside each workspace, with recruiters limited to candidates on their own jobs; our platform staff have read-only access for support.
  • Rate limiting, account lockout after repeated failed sign-ins, CAPTCHA on public forms, and single-use, time-limited links for candidates.
  • An audit log of important actions, and of access to call records and messages.

More detail is on our Security page. We may change these measures over time, but not in a way that lowers the overall level of protection.

9. Personal data breaches

If we become aware of a personal data breach affecting Customer Personal Data, we will notify the workspace admins without undue delay, and in any case within 72 hours. We will tell you what happened, what data and people are likely to be affected, and what we are doing about it, and we will update you as we learn more. We will help you meet your own obligations to notify the Data Protection Board of India, other regulators and affected people.

10. Return and deletion

During the subscription you can export candidate, background-verification and analytics data from the Exports page, archive candidates, and ask us to erase a candidate permanently. When your subscription ends you have 30 days to ask for a copy of your Customer Data; after that we delete or anonymise it, except where the law requires us to keep it. Copies in backups are overwritten over time and are not restored except to recover the Service.

11. International transfers

Some sub-processors process data outside India, mainly in the United States and the European Union. We transfer data only to countries not restricted under the DPDP Act and, where the GDPR applies, using the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism.

12. Information and audits

On written request, and no more than once a year unless a regulator requires it or there has been a breach, we will answer reasonable security questionnaires and give you the information you need to show compliance with this DPA. Any on-site audit must be agreed in advance, at your cost, during business hours, and subject to confidentiality.

13. Liability

Each party’s liability under this DPA is subject to the limitations in the Terms of Service, except where Data Protection Law does not allow them to be limited.

14. Term and changes

This DPA lasts as long as we process Customer Personal Data for you. We may update it to reflect changes in the law or the Service; we will not reduce the protection it gives you without notice, and material changes follow the notice process in the Terms.

15. Contact

Data-protection questions, sub-processor objections and breach contacts: hiring@supahiro.co.