← Security and data

Data Processing Agreement

Version 1.0 · Effective 1 October 2026

To put this in place

Write to contactus@insiderone.in with your company's legal name and a signatory, and we send a countersigned copy. If your organisation uses its own agreement, send it and we will review it.

1. Parties and what this covers

This agreement is between the organisation using insiderOne for Employers (the "Customer") and Aurist Private Limited, North Lakhimpur, Assam, India ("insiderOne"), which operates the service in India. It forms part of the Terms of Service between them and applies whenever insiderOne processes Candidate Personal Data on the Customer's behalf.

"Candidate Personal Data" means personal data about job applicants and candidates that the Customer collects, uploads or asks insiderOne to verify through the service. Under the Digital Personal Data Protection Act 2023 ("DPDP Act") the Customer is the Data Fiduciary and insiderOne its Data Processor; under the GDPR and UK GDPR, where they apply, the Customer is the controller and insiderOne the processor.

It does not cover the profiles of insiderOne members that SCOUT shows a Customer. Those belong to people who joined insiderOne themselves, and insiderOne controls them under its own privacy notice until a member applies to the Customer or agrees to be contacted.

2. Instructions

insiderOne processes Candidate Personal Data only to provide the service and on the Customer's documented instructions, which are these Terms, this agreement, and what the Customer does in the service. It will tell the Customer if it believes an instruction breaks the law, and will not process the data for any purpose of its own.

insiderOne does not sell Candidate Personal Data, and does not use it to train any language model or other machine-learning model.

3. The Customer's part

The Customer is responsible for having a lawful basis for the data it brings into the service, for the notices it gives candidates, and for every background check it requests. Each check runs only after the named candidate agrees on a page of their own; a request nobody answers lapses after 14 days and nothing is run. Regulated checks require the Customer to state its purpose, which is recorded.

4. People who handle the data

Everyone at insiderOne who can reach Candidate Personal Data is bound by confidentiality, and access is limited to the people who operate and support the service. Staff look at a Customer's data only to support the Customer when asked, or to investigate abuse or a security problem.

5. Security

insiderOne keeps the measures in Annex 2 in place for as long as it processes the data and may improve them, but will not reduce the overall protection they give. The security page describes each in plain words.

6. Sub-processors

The Customer authorises the sub-processors in Annex 3. insiderOne binds each to data protection terms no less protective than these, and remains responsible for them.

Before a new sub-processor starts receiving Candidate Personal Data, insiderOne will email the Customer's account owner at least 30 days ahead and update the security page. The Customer may object on reasonable data protection grounds; if the parties cannot resolve it, the Customer may end the affected part of the service and receive a pro-rata refund of fees paid for the remaining term.

7. Where the data is processed

The database is in Mumbai, India. Some sub-processors in Annex 3 process data in other countries, which each entry states. insiderOne will not transfer Candidate Personal Data to a country the Government of India has restricted under section 16 of the DPDP Act. Where the GDPR or UK GDPR applies to a transfer, it is made under the European Commission's Standard Contractual Clauses or the UK addendum, as the case requires.

8. Candidates' rights

insiderOne will help the Customer answer requests from candidates to access, correct or erase their data, or to withdraw consent, using the tools in the service, and will pass on to the Customer within five working days any such request it receives directly rather than answering it itself.

9. Personal data breaches

insiderOne will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a breach affecting the Customer's Candidate Personal Data. The notice will say what is known of what happened, the data and people affected, and what is being done, and insiderOne will add to it as it learns more. It will give the Customer what it needs to inform the Data Protection Board of India and the people affected, as the DPDP Act requires of a Data Fiduciary.

10. Records and audits

insiderOne will answer a Customer's written security questionnaire, and make available the information reasonably needed to show it meets this agreement. Once in any twelve months, on thirty days' notice, the Customer or an independent auditor bound by confidentiality may audit that compliance at the Customer's cost, in a way that does not expose other customers' data.

Every hiring decision step the Customer takes in the service is logged with its time and actor, and the Customer can download an audit pack for any role at any time.

11. Assessments

insiderOne will give reasonable help with any data protection impact assessment or prior consultation the Customer is required to carry out about the service.

12. At the end

The Customer can export its data at any time on every plan. When the agreement ends, insiderOne will delete or anonymise the Customer's Candidate Personal Data within 30 days, except where the law requires it to be kept, in which case it is kept only for that purpose and remains protected by this agreement.

13. Order and liability

On data protection, this agreement takes precedence over the Terms of Service. Liability under it is subject to the limits in the Terms. It lasts as long as insiderOne processes Candidate Personal Data for the Customer.

Annex 1 · What is processed

  • Purpose: running the Customer's hiring: receiving applications, ranking them against the Customer's requirements, interviews and scorecards, sourcing through SCOUT, and verification through VERA.
  • People: applicants, candidates sourced or contacted, referees a candidate names, and the Customer's own team members.
  • Data: names, contact details, employment and education history, skills and the evidence behind them, application answers, interview notes and scorecards, call recordings the Customer uploads, consent records, and, where a candidate agrees, the results of the checks they agreed to.
  • Not processed: Aadhaar numbers, which no part of the service stores. An EPFO passbook a candidate provides is read once for its employers and months, and not kept.
  • Duration: the term of the Customer's use, then section 12.

Annex 2 · Security measures

  • Encryption of all traffic in transit, with browsers told never to connect without it.
  • Every request checked on the server against the company it belongs to before any data is read.
  • Sign-in by one-time code to a work email; no passwords.
  • Applicants' contact details withheld until the Customer proves control of its email domain.
  • Interviewers see only the applications they are assigned to.
  • Shared shortlist links expire after 30 days and are treated as expired if their date cannot be read.
  • Pages cannot be embedded by other sites.
  • A logged record of each request, answer, check and status change.

Annex 3 · Sub-processors

  • Supabase — database, sign-in and file storage. Receives: everything stored in the product. Where: Mumbai, India (ap-south-1).
  • Cloudflare — hosting, network edge and bot protection on forms. Receives: requests passing through, including ip addresses. Where: Global edge network.
  • Google (Gemini) — language models that draft, search and summarise for scout and vera. Receives: the profile, role and message text a task needs, and an epfo passbook a candidate chooses to upload for vera (read for employer names and months; the file isn't kept). Where: United States and other Google regions.
  • OpenRouter — a second route to language models when the first is unavailable. Receives: the same task text as above, when used. Where: United States.
  • Resend — sending email. Receives: recipient address, name and the message itself. Where: United States.
  • AssemblyAI — transcribing call recordings you choose to upload. Receives: the recording and the transcript. Where: United States.
  • Firecrawl — reading public web pages: a company's own website, and the links an applicant chose to give when your team asks what they show. Receives: the page address, which for an applicant's link can be their personal site or portfolio, and the public page it returns. Where: United States.

Contact

Aurist Private Limited · North Lakhimpur, Assam, India
Email: contactus@insiderone.in