Data Processing Addendum.

Last updated: October 2, 2026. A plain-language summary of how Scrini processes personal data on behalf of customers. The signed DPA governs.

Summary

1. Scope and roles

The DPA applies when Scrini processes personal data on a customer's behalf to provide the Service. The customer is the controller (or a processor for its own clients, for example a staffing agency) and Scrini is the processor or subprocessor. For US state privacy laws, Scrini is a service provider or contractor and will not sell or share the data, use it outside the direct business relationship or combine it with other data except as the law allows.

2. What is processed

Data subjects: candidates and potential candidates, and the customer's users. Data categories: contact details, resumes and work history, messages, call and video recordings, transcripts, assessment results, scores and their evidence, scheduling data, identity verification signals and account and usage data. Special category data is processed only if the customer instructs it and has a lawful basis. The nature and purpose: sourcing, outreach, screening, assessment, ranking, scheduling and related support. Duration: the term of the agreement plus the deletion period.

3. Instructions and confidentiality

We process personal data only on the customer's documented instructions, including those set by configuring the Service, and we tell the customer if we think an instruction breaks the law. Everyone at Scrini with access to customer data is bound by confidentiality.

4. Security

We maintain the technical and organizational measures described in our Data Security Policy, including TLS 1.3 encryption in transit, AES-256 encryption at rest, SSO and MFA, role-based access, central logging with 24/7 alerting, scans on every build and independent penetration testing at least once a year. Our security controls are mapped to SOC 2 and ISO 27001.

5. Subprocessors

The customer gives general authorization for the subprocessors on our Subprocessors page. We give at least 30 days' notice before adding or replacing one, by email to the account owner or by updating that page, and the customer can object on reasonable data protection grounds within the notice period. Each subprocessor is bound by data protection terms at least as protective as the DPA, and Scrini remains responsible for its subprocessors.

6. Helping customers

We help customers respond to data subject requests, carry out data protection impact assessments and, where relevant, fundamental rights impact assessments under the EU AI Act, and consult regulators. If a candidate contacts us directly, we pass the request to the customer and do not respond ourselves unless the customer asks us to.

7. Personal data breaches

We notify the customer without undue delay and within 72 hours of confirming a personal data breach affecting its data. We share what we know about the nature and scope of the breach, the likely consequences and the steps taken, and we update the customer as we learn more.

8. Deletion and return

Customers can export and delete data in the Service at any time. When the contract ends, or when the customer asks, we delete or anonymize customer personal data within 30 days, and backups are deleted on a 35-day cycle, unless the law requires us to keep it.

9. Audits

We make available the information needed to show compliance with the DPA. Once a year, on request, customers can review our third-party security reports, security documentation and penetration test executive summaries under NDA, and we answer reasonable security questionnaires. On-site audits take place only where the law requires them, with reasonable notice and during business hours.

10. International transfers

Data is hosted on AWS in India and Germany, and customers can choose EU-only hosting. Transfers out of the EEA, the UK or Switzerland are covered by the EU Standard Contractual Clauses (with the UK Addendum and the Swiss amendments) where required, with supplementary measures where needed.

11. Government access requests

If a public authority asks for customer personal data, we will review the request, challenge it where there are reasonable grounds to consider it unlawful, disclose only what is legally required and notify the customer unless the law forbids it.

12. AI-specific commitments

Customer personal data is used only to provide the Service to that customer. It is never used to train or fine-tune shared AI models, and it is never shared with other customers.

13. Getting the DPA

Email support@scrini.ai to request the DPA for signature. Enterprise customers can also include it in their master services agreement.

Related policies.

Privacy Policy

How Scrini collects, uses and protects personal data.

Read

Candidate Privacy Notice

For people assessed through Scrini by an employer.

Read

AI Transparency Notice

How our AI agents work and the choices candidates have.

Read

Cookie Policy

Cookies, consent and how to change your choices.

Read

Terms of Service

The agreement for using the Scrini platform.

Read

Acceptable Use Policy

What customers may and may not do with Scrini.

Read

Subprocessors

Third parties that process data for Scrini.

Read

Data Security Policy

How we protect data and respond to incidents.

Read

Refund Policy

Credits, billing disputes and refunds.

Read

Accessibility Statement

Our accessibility commitment and accommodations.

Read

Vulnerability Disclosure

How to report a security issue.

Read