RecruiterBrief
GDPR & UK GDPR Aligned

Compliance & Data Protection

Everything your compliance team needs — DPA, sub-processor list, data retention schedules, and your rights as a data controller. Built for recruiters who handle candidate data every day.

UK GDPR aligned

ICO registered framework

No CV storage

Unsaved content discarded immediately

EU SCCs in place

All third-country transfers covered

DPA available

On request for enterprise clients

Last reviewed: 25 July 2026 · For DPA requests or compliance queries: recruiterbrief12@gmail.com

Your role under UK GDPR

You are the data controller.
We are the data processor.

When you submit candidate CVs, screening notes or application data into RecruiterBrief, you do so as the data controller — the organisation that determines the purpose and means of processing. RecruiterBrief acts as a data processor, processing that data on your behalf solely to generate the outputs you request.

This means you are responsible for ensuring you have a lawful basis to process candidate data — typically legitimate interest in the context of an active recruitment process, or consent where required.

You must also ensure candidates are informed that their data may be processed by AI tools as part of your recruitment workflow, either through your own privacy notice or your privacy policy.

What RecruiterBrief commits to as data processor

  • Process data only on your documented instructions
  • Never use submitted candidate data to train AI models
  • Discard unsaved submitted content immediately — it is never stored on our servers
  • Maintain technical and organisational measures to protect data
  • Notify you of any personal data breach affecting your data without undue delay
  • Delete or return your data on termination of service
  • Maintain records of all processing activities (Article 30)
  • Co-operate with any ICO investigation or audit upon request

Your responsibilities as data controller

  • Maintain a lawful basis for processing candidate data
  • Inform candidates that AI tools are used in your process
  • Respond to candidate Subject Access Requests within 30 days
  • Ensure you are registered with the ICO (if UK-based)
Data Processing Agreement

Data Processing Agreement (DPA)

Under Article 28 of the UK GDPR and EU GDPR, you as data controller are required to have a written contract in place with any data processor you use. RecruiterBrief's standard DPA is available on request and covers all processing activities described in this page.

Standard DPA

All plans

Available on request for all users. Covers all processing activities described on this page. Based on ICO model clauses.

Custom DPA

Enterprise

For enterprise accounts or agencies with specific contractual requirements. Contact us to discuss.

Request your DPA

Email us and we will send you a signed DPA within 2 business days.

Request DPA

The DPA incorporates the ICO's standard contractual clauses for UK transfers and the European Commission's Standard Contractual Clauses (SCCs) for EEA data transfers, where applicable.

Sub-Processor List

Current sub-processors

Last updated: 25 July 2026

RecruiterBrief uses the following sub-processors in the delivery of the platform. Each has been assessed for GDPR compliance and has a Data Processing Agreement in place with us. Where data is transferred outside the UK or EEA, Standard Contractual Clauses (SCCs) or UK IDTA are in place.

Google LLC

DPA in place

Purpose

AI content generation (Gemini)

Data processed

Text content you submit (CVs, notes, job specs)

Location

USA — EU SCC in place

Retention

Not retained after response; data is not used to train models

Neon Inc.

DPA in place

Purpose

Database storage (PostgreSQL)

Data processed

Account data, saved outputs, usage logs

Location

USA (AWS) — EU SCC in place

Retention

Retained until account deletion

Stripe Inc.

DPA in place

Purpose

Payment processing & subscription management

Data processed

Billing name, email, payment method metadata

Location

USA — EU SCC in place

Retention

Retained per Stripe legal and financial obligations (typically 7 years)

Vercel Inc.

DPA in place

Purpose

Application hosting & content delivery

Data processed

IP addresses, request logs, session data

Location

USA/EU edge nodes — EU SCC in place

Retention

Log data retained for 30 days

Uploadcare Inc.

DPA in place

Purpose

File upload processing (CV and document handling)

Data processed

Files uploaded by users for processing

Location

USA — EU SCC in place

Retention

Files deleted after processing; not stored long term

Sub-processor change notification: We will provide at least 14 days' notice before adding or replacing any sub-processor that handles personal data. If you have a DPA in place with us, we will notify you directly by email.

Data Retention

Data retention schedule

RecruiterBrief retains different categories of data for different periods, based on legal requirement or legitimate interest. The schedule below applies to all users. Data is deleted securely at the end of the applicable retention period.

The most important thing to know

Content you submit to RecruiterBrief tools (CVs, screening notes, job specs) and do not save is never stored on our servers. It is passed directly to the AI API, a response is generated, and it is discarded immediately. We have no record of it.

Category

Account data

Data

Name, email address, account settings

Retention

Duration of active account + 30 days post-deletion request

Legal basis

Contract performance

Category

Saved outputs

Data

Generated briefs, CVs, emails, question packs saved to your dashboard

Retention

Until you delete them, or account closure. Auto-deleted 12 months after account inactivity.

Legal basis

Contract performance / legitimate interest

Category

Submitted content (unsaved)

Data

CVs, notes, job specs submitted to tools but not saved

Retention

Not stored. Content is passed to the AI API and discarded immediately. Not retained on our servers.

Legal basis

Not applicable — no retention

Category

Usage logs

Data

Tool usage count, timestamps, feature access

Retention

12 months rolling

Legal basis

Legitimate interest (fraud prevention, usage enforcement)

Category

Billing records

Data

Subscription status, payment history (held by Stripe)

Retention

7 years (legal financial obligation)

Legal basis

Legal obligation

Category

Security & access logs

Data

IP addresses, login attempts, session tokens

Retention

30 days

Legal basis

Legitimate interest (security)

Category

AI cost and audit logs

Data

Anonymised token usage, response lengths (no content)

Retention

90 days

Legal basis

Legitimate interest (platform monitoring)

Upon account deletion, all associated personal data is removed within 30 days unless retention is required by law (e.g. billing records). Anonymised aggregated usage data may be retained for platform analytics.

Your rights

Data subject rights

Under the UK GDPR (and EU GDPR where applicable), you and your candidates have the following rights. We will respond to any rights request within 30 calendar days of receipt.

Right of access

Request a copy of all personal data we hold about you. We will respond within 30 days.

Right to rectification

Correct inaccurate or incomplete data held in your account at any time.

Right to erasure

Request full deletion of your account and associated data. We will action within 30 days.

Right to restrict processing

Pause how we process your data while we investigate a concern.

Right to data portability

Receive your saved outputs and account data in a machine-readable format.

Right to object

Object to processing based on legitimate interest, including marketing.

How to submit a rights request

Email recruiterbrief12@gmail.com with the subject line "Rights Request" and include your name, email address, and a description of your request. We may ask for identity verification before processing.

If you are a candidate whose data was submitted by a recruiter, you should contact that recruiter directly in the first instance, as they are the data controller responsible for your data. If you cannot reach them, contact us and we will assist.

Technical & Organisational Measures

How we protect your data

Encryption in transit

All data transmitted between your browser and RecruiterBrief is encrypted using TLS 1.2+. All API calls to sub-processors use HTTPS.

Encryption at rest

Data stored in our database (Neon PostgreSQL) is encrypted at rest using AES-256.

Access controls

Production database access is restricted to authorised personnel only. Role-based access controls limit what each system can see.

No CV storage (by default)

Content submitted to tools and not explicitly saved is never written to disk. It exists only in memory for the duration of the API call.

Breach notification

In the event of a personal data breach, we will notify affected users without undue delay and in any case within 72 hours of becoming aware.

Dependency & vulnerability monitoring

We monitor platform dependencies for known vulnerabilities and apply security patches promptly.

Recruiter guidance

Using RecruiterBrief with candidate data

Recruiters process candidate personal data every day — CVs, contact details, screening call notes, salary expectations. When you use RecruiterBrief as part of that process, here is what good practice looks like.

01

Only submit data for active candidates

Only paste CV or application data into RecruiterBrief for candidates who are actively in a recruitment process you're managing. Don't use it to process data held in an archive without a current purpose.

02

Update your privacy notice

Add a note to your candidate privacy notice or fair processing statement explaining that AI tools are used in your workflow for tasks like CV analysis, candidate summary generation, and interview preparation. This satisfies Article 13/14 transparency obligations.

03

Don't save unnecessary data

If you generate a brief or email but don't intend to keep it, don't save it to your dashboard. Unsaved outputs are never stored — only save what you need to refer back to.

04

Handle candidate rights requests promptly

If a candidate requests deletion of their data, check your RecruiterBrief dashboard and delete any saved outputs relating to them. Email us and we will confirm deletion from our system.

05

Don't submit special category data

Avoid submitting special category personal data (health conditions, religious beliefs, ethnic origin, etc.) unless strictly necessary. RecruiterBrief tools are not designed or tested for processing this category of data.

Supervisory authority

RecruiterBrief's supervisory authority is the Information Commissioner's Office (ICO) in the United Kingdom.

ico.org.uk

Applicable law

UK GDPR (as retained in UK law by the European Union (Withdrawal) Act 2018), the Data Protection Act 2018, and where applicable, the EU GDPR for EEA data subjects.

Data protection contact

For all data protection queries, DPA requests, breach notifications or rights requests:

recruiterbrief12@gmail.com

Questions about compliance?

Whether you need a signed DPA, have questions about candidate data handling, or want to discuss how RecruiterBrief fits your organisation's GDPR obligations — get in touch. We respond to all compliance queries within 2 business days.