1. Scope and roles
The DPA applies when Scrini processes personal data on a customer's behalf to provide the Service. The customer is the controller (or a processor for its own clients, for example a staffing agency) and Scrini is the processor or subprocessor. For US state privacy laws, Scrini is a service provider or contractor and will not sell or share the data, use it outside the direct business relationship or combine it with other data except as the law allows.
2. What is processed
Data subjects: candidates and potential candidates, and the customer's users. Data categories: contact details, resumes and work history, messages, call and video recordings, transcripts, assessment results, scores and their evidence, scheduling data, identity verification signals and account and usage data. Special category data is processed only if the customer instructs it and has a lawful basis. The nature and purpose: sourcing, outreach, screening, assessment, ranking, scheduling and related support. Duration: the term of the agreement plus the deletion period.
3. Instructions and confidentiality
We process personal data only on the customer's documented instructions, including those set by configuring the Service, and we tell the customer if we think an instruction breaks the law. Everyone at Scrini with access to customer data is bound by confidentiality.
4. Security
We maintain the technical and organizational measures described in our Data Security Policy, including TLS 1.3 encryption in transit, AES-256 encryption at rest, SSO and MFA, role-based access, central logging with 24/7 alerting, scans on every build and independent penetration testing at least once a year. Our security controls are mapped to SOC 2 and ISO 27001.
5. Subprocessors
The customer gives general authorization for the subprocessors on our Subprocessors page. We give at least 30 days' notice before adding or replacing one, by email to the account owner or by updating that page, and the customer can object on reasonable data protection grounds within the notice period. Each subprocessor is bound by data protection terms at least as protective as the DPA, and Scrini remains responsible for its subprocessors.
6. Helping customers
We help customers respond to data subject requests, carry out data protection impact assessments and, where relevant, fundamental rights impact assessments under the EU AI Act, and consult regulators. If a candidate contacts us directly, we pass the request to the customer and do not respond ourselves unless the customer asks us to.
7. Personal data breaches
We notify the customer without undue delay and within 72 hours of confirming a personal data breach affecting its data. We share what we know about the nature and scope of the breach, the likely consequences and the steps taken, and we update the customer as we learn more.
8. Deletion and return
Customers can export and delete data in the Service at any time. When the contract ends, or when the customer asks, we delete or anonymize customer personal data within 30 days, and backups are deleted on a 35-day cycle, unless the law requires us to keep it.
9. Audits
We make available the information needed to show compliance with the DPA. Once a year, on request, customers can review our third-party security reports, security documentation and penetration test executive summaries under NDA, and we answer reasonable security questionnaires. On-site audits take place only where the law requires them, with reasonable notice and during business hours.
10. International transfers
Data is hosted on AWS in India and Germany, and customers can choose EU-only hosting. Transfers out of the EEA, the UK or Switzerland are covered by the EU Standard Contractual Clauses (with the UK Addendum and the Swiss amendments) where required, with supplementary measures where needed.
11. Government access requests
If a public authority asks for customer personal data, we will review the request, challenge it where there are reasonable grounds to consider it unlawful, disclose only what is legally required and notify the customer unless the law forbids it.
12. AI-specific commitments
Customer personal data is used only to provide the Service to that customer. It is never used to train or fine-tune shared AI models, and it is never shared with other customers.
13. Getting the DPA
Email support@scrini.ai to request the DPA for signature. Enterprise customers can also include it in their master services agreement.

