Roles and documented instructions
For Candidate data processed on behalf of a Customer, the Customer acts as controller and AI Psychometrics acts as processor or service provider. We process that data only on documented instructions needed to provide, operate, secure, and support the Service, unless law requires otherwise.
Confidentiality and security
Authorized personnel and subprocessors must be bound by confidentiality. Measures include TLS, access controls, secret management, logging, and reasonable administrative, technical, and organizational safeguards. No method is completely secure.
Subprocessors
Subprocessor categories may include cloud hosting and infrastructure, database and authentication, cache and session storage, transactional email, and third-party large-language-model API provider(s). A final DPA should define notice of material changes and applicable objection procedures.
Rights requests and assistance
Taking account of the nature of processing, we will reasonably assist the Customer with verified individual-rights requests, security enquiries, impact assessments, regulatory consultations, and incident obligations within the agreed scope.
Security incidents
We will notify the Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer data, and provide available information reasonably needed for the Customer’s obligations. Final notice mechanics and timelines require counsel approval.
Deletion and return
At the end of service or upon a valid instruction, personal data will be returned, deleted, or de-identified within a reasonable period, subject to backups, security records, dispute needs, and legal retention obligations.
International transfers and audit
Where required, the parties will use an appropriate international-transfer safeguard. A final DPA must set the applicable transfer module, audit process, liability allocation, term, and order-of-precedence rules before signature.
