# Data Processing Addendum.

> A plain-language summary of the Scrini AI Data Processing Addendum: roles, security, subprocessors, breach notice, international transfers, deletion and audits.

URL: https://landing.qa.scrini.ai/dpa  
Breadcrumb: Home > Data Processing Addendum

Last updated: October 2, 2026. A plain-language summary of how Scrini processes personal data on behalf of customers. The signed DPA governs.

## Summary

- The customer is the controller of candidate data. Scrini is the processor and acts only on the customer's documented instructions.
- Customer data is never used to train or fine-tune shared AI models.
- We notify customers of a personal data breach without undue delay and within 72 hours of confirming it.
- Data is deleted or anonymized within 30 days of a request or the end of the contract, and backups are deleted on a 35-day cycle.
- To get the DPA for signature, email support@scrini.ai.

## 1. Scope and roles

The DPA applies when Scrini processes personal data on a customer's behalf to provide the Service. The customer is the controller (or a processor for its own clients, for example a staffing agency) and Scrini is the processor or subprocessor. For US state privacy laws, Scrini is a service provider or contractor and will not sell or share the data, use it outside the direct business relationship or combine it with other data except as the law allows.

## 2. What is processed

Data subjects: candidates and potential candidates, and the customer's users. Data categories: contact details, resumes and work history, messages, call and video recordings, transcripts, assessment results, scores and their evidence, scheduling data, identity verification signals and account and usage data. Special category data is processed only if the customer instructs it and has a lawful basis. The nature and purpose: sourcing, outreach, screening, assessment, ranking, scheduling and related support. Duration: the term of the agreement plus the deletion period.

## 3. Instructions and confidentiality

We process personal data only on the customer's documented instructions, including those set by configuring the Service, and we tell the customer if we think an instruction breaks the law. Everyone at Scrini with access to customer data is bound by confidentiality.

## 4. Security

We maintain the technical and organizational measures described in our Data Security Policy, including TLS 1.3 encryption in transit, AES-256 encryption at rest, SSO and MFA, role-based access, central logging with 24/7 alerting, scans on every build and independent penetration testing at least once a year. Our security controls are mapped to SOC 2 and ISO 27001.

## 5. Subprocessors

The customer gives general authorization for the subprocessors on our Subprocessors page. We give at least 30 days' notice before adding or replacing one, by email to the account owner or by updating that page, and the customer can object on reasonable data protection grounds within the notice period. Each subprocessor is bound by data protection terms at least as protective as the DPA, and Scrini remains responsible for its subprocessors.

## 6. Helping customers

We help customers respond to data subject requests, carry out data protection impact assessments and, where relevant, fundamental rights impact assessments under the EU AI Act, and consult regulators. If a candidate contacts us directly, we pass the request to the customer and do not respond ourselves unless the customer asks us to.

## 7. Personal data breaches

We notify the customer without undue delay and within 72 hours of confirming a personal data breach affecting its data. We share what we know about the nature and scope of the breach, the likely consequences and the steps taken, and we update the customer as we learn more.

## 8. Deletion and return

Customers can export and delete data in the Service at any time. When the contract ends, or when the customer asks, we delete or anonymize customer personal data within 30 days, and backups are deleted on a 35-day cycle, unless the law requires us to keep it.

## 9. Audits

We make available the information needed to show compliance with the DPA. Once a year, on request, customers can review our third-party security reports, security documentation and penetration test executive summaries under NDA, and we answer reasonable security questionnaires. On-site audits take place only where the law requires them, with reasonable notice and during business hours.

## 10. International transfers

Data is hosted on AWS in India and Germany, and customers can choose EU-only hosting. Transfers out of the EEA, the UK or Switzerland are covered by the EU Standard Contractual Clauses (with the UK Addendum and the Swiss amendments) where required, with supplementary measures where needed.

## 11. Government access requests

If a public authority asks for customer personal data, we will review the request, challenge it where there are reasonable grounds to consider it unlawful, disclose only what is legally required and notify the customer unless the law forbids it.

## 12. AI-specific commitments

Customer personal data is used only to provide the Service to that customer. It is never used to train or fine-tune shared AI models, and it is never shared with other customers.

## 13. Getting the DPA

Email support@scrini.ai to request the DPA for signature. Enterprise customers can also include it in their master services agreement.

## Related policies.

### Privacy Policy

How Scrini collects, uses and protects personal data.

[Read](https://landing.qa.scrini.ai/privacy-policy)

### Candidate Privacy Notice

For people assessed through Scrini by an employer.

[Read](https://landing.qa.scrini.ai/candidate-privacy-notice)

### AI Transparency Notice

How our AI agents work and the choices candidates have.

[Read](https://landing.qa.scrini.ai/ai-transparency)

### Cookie Policy

Cookies, consent and how to change your choices.

[Read](https://landing.qa.scrini.ai/cookie-policy)

### Terms of Service

The agreement for using the Scrini platform.

[Read](https://landing.qa.scrini.ai/terms-of-service)

### Acceptable Use Policy

What customers may and may not do with Scrini.

[Read](https://landing.qa.scrini.ai/acceptable-use-policy)

### Subprocessors

Third parties that process data for Scrini.

[Read](https://landing.qa.scrini.ai/subprocessors)

### Data Security Policy

How we protect data and respond to incidents.

[Read](https://landing.qa.scrini.ai/data-security-policy)

### Refund Policy

Credits, billing disputes and refunds.

[Read](https://landing.qa.scrini.ai/refund-policy)

### Accessibility Statement

Our accessibility commitment and accommodations.

[Read](https://landing.qa.scrini.ai/accessibility)

### Vulnerability Disclosure

How to report a security issue.

[Read](https://landing.qa.scrini.ai/vulnerability-disclosure)
