1. Parties and acceptance
- This DPA is between the company that holds a NeuRazor client account (the "Client", controller) and NeuRazor Labs, New Delhi, India ("NeuRazor", processor).
- It takes effect when a person authorised to bind the Client accepts the Platform Terms and this DPA in the client portal, or signs an order form that refers to them. NeuRazor records the version accepted, who accepted it and when. That acceptance is also the parties' signature of the Standard Contractual Clauses incorporated in section 13.
2. Definitions
- GDPR: Regulation (EU) 2016/679. Where relevant, references to the GDPR include the UK GDPR and the Swiss Federal Act on Data Protection (FADP).
- Client Personal Data: personal data that NeuRazor processes for the Client under the Platform Terms, described in Annex I.
- Candidate: a person the Client invites to, or who applies through, an assessment or job posting on the Platform.
- Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Client Personal Data.
- Sub-processor: a third party NeuRazor engages to process Client Personal Data.
- SCCs: the standard contractual clauses for transfers to third countries approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- UK Addendum: the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, version B1.0, in force from 21 March 2022.
Other terms such as "controller", "processor", "data subject" and "processing" have the meaning given in the GDPR. Capitalised terms not defined here have the meaning in the Platform Terms.
3. Scope, roles, subject matter and duration
- The Client is the controller and NeuRazor is the processor of Client Personal Data.
- This DPA does not apply where NeuRazor is itself a controller: candidate portal accounts, job-board profiles (including CVs, intro videos and ID proofs), the contact details of the Client's Authorised Users, website enquiries and NeuRazor's support mailbox. NeuRazor's Privacy Notice covers those.
- Subject matter: providing the NeuRazor assessment platform to the Client.
- Duration: for as long as NeuRazor processes Client Personal Data under the Platform Terms, and until it is deleted under section 11.
- Nature and purpose: as set out in Annex I.
4. Processing on documented instructions
- NeuRazor processes Client Personal Data only on the Client's documented instructions, including for transfers to a third country, unless the law to which NeuRazor is subject requires otherwise. In that case NeuRazor will tell the Client of that legal requirement before processing, unless that law prohibits it on important grounds of public interest.
- The Client's documented instructions are: the Platform Terms and this DPA; the Client's configuration and use of the Platform, including the campaigns, assessments and skills it sets up, and its retention setting; and any other written instructions the parties agree.
- Standing instruction on Candidate requests. The Client instructs NeuRazor to:
- act on verified access (download) and erasure requests that Candidates make directly through the candidate portal, under Settings, then Your data. A request is verified when the Candidate is signed in with the email address the data belongs to. An erasure made this way removes the Candidate's data held for every client that invited them;
- record consent withdrawals and requests for human review made in the candidate portal or by email; and
- notify the Client of each such request that concerns its Candidates through the privacy requests list in the client portal (Settings, then Privacy), where the Client can see the request, its due date and its outcome.
- Retention. The Client instructs NeuRazor to delete Client Personal Data on the schedule in Annex I, using the retention period the Client sets in the client portal (30 days to 3 years after a Candidate's last activity; 12 months by default).
- Statistics. The Client authorises NeuRazor to create statistics with names and identities removed from Platform use, and to use them to improve the Platform. They do not identify the Client or any individual.
- NeuRazor will tell the Client immediately if, in its opinion, an instruction infringes the GDPR or other data protection law.
5. Confidentiality
NeuRazor ensures that every person it authorises to process Client Personal Data has committed to confidentiality or is under an appropriate legal duty of confidentiality, and has access only to the extent needed to support the Platform.
6. Security
- NeuRazor implements the technical and organisational measures in Annex II, which meet the requirements of Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to Candidates.
- NeuRazor may update those measures, provided the overall level of security does not decrease.
7. Sub-processors
- General authorisation. The Client gives NeuRazor general written authorisation to engage Sub-processors. The Sub-processors in Annex III, also listed at www.neurazor.com/subprocessors, are approved at the date of acceptance.
- Notice of changes. NeuRazor will inform the Client of any intended addition or replacement of a Sub-processor at least 30 days before it starts processing Client Personal Data, by updating the sub-processor page. Clients who ask for it at support@neurazor.com (subject "Sub-processor updates") also receive the notice by email.
- Right to object. The Client may object to the change on reasonable data protection grounds by writing to support@neurazor.com within that 30-day period. The parties will discuss the objection in good faith. If they cannot resolve it, the Client may terminate the affected part of the service by written notice before the change takes effect, and NeuRazor will refund prepaid fees for the period after termination.
- Flow-down. NeuRazor will engage each Sub-processor by a written contract that imposes data protection obligations no less protective than this DPA, in particular sufficient guarantees of appropriate technical and organisational measures.
- Responsibility. NeuRazor remains fully liable to the Client for the performance of each Sub-processor's obligations.
8. Assistance with data subject rights
- Taking into account the nature of the processing, NeuRazor assists the Client by appropriate technical and organisational measures to respond to requests from Candidates exercising their rights under Chapter III of the GDPR.
- The Platform gives the Client these tools: export of a Candidate's data (open the candidate, then Privacy, then Export data); erasure of all of a Candidate's data held for the Client (Erase all data, for owners and client admins); a retention setting; the privacy requests list; and the Candidates' consent records.
- If NeuRazor receives a request about Client Personal Data other than through the candidate portal, it will record it, pass it to the Client without undue delay, and not answer it itself except to acknowledge receipt, to act under the standing instruction in section 4.3, or as the Client instructs.
- NeuRazor will answer requests for human review only by passing them to the Client. The Client decides the outcome.
9. Other assistance
Taking into account the nature of the processing and the information available to it, NeuRazor assists the Client in meeting its obligations under Articles 32 to 36 of the GDPR: security, notification of Personal Data Breaches, data protection impact assessments and prior consultation with a supervisory authority. This includes giving the Client a summary of NeuRazor's own impact assessment of AI-scored, proctored assessments on request.
10. Personal data breaches
- NeuRazor will notify the Client of a Personal Data Breach without undue delay and in any case no later than 48 hours after becoming aware of it.
- The notice goes to the Client's account owner by email, and to any privacy contact the Client has given NeuRazor in writing.
- The notice will describe, as far as the information is available:
- the nature of the breach, including where possible the categories and approximate number of Candidates and records concerned;
- the name and contact details of NeuRazor's contact point for the breach;
- the likely consequences of the breach; and
- the measures taken or proposed to address the breach, including measures to reduce its possible adverse effects.
- Where it is not possible to give all of this at once, NeuRazor will give it in phases without undue further delay.
- NeuRazor will take reasonable steps to contain and investigate the breach, and will help the Client notify the supervisory authority and Candidates where required. NeuRazor will not notify a supervisory authority or Candidates about a breach of Client Personal Data on the Client's behalf unless the Client instructs it or the law requires it.
- Notifying a breach is not an admission of fault or liability.
11. Deletion or return at the end
- Before closing its account, the Client can export Client Personal Data from the client portal. NeuRazor will help with a reasonable request for an export.
- NeuRazor deletes Client Personal Data within 30 days after the Client's account closes, and copies in backups within 7 further days, unless Union or Member State law requires storage.
- Billing records are kept as the law requires, with Candidates' email addresses replaced by a one-way code.
- On request, NeuRazor will confirm the deletion in writing.
12. Audits and information
- NeuRazor makes available to the Client the information necessary to demonstrate compliance with Article 28 of the GDPR and this DPA. This includes this DPA and its annexes, the sub-processor list, a summary of its most recent vulnerability assessment and penetration test, and answers to reasonable security and privacy questionnaires.
- If that information is not enough to show compliance, or a supervisory authority requires it, NeuRazor allows for and contributes to audits, including inspections, by the Client or an independent auditor the Client mandates who is bound by confidentiality.
- The Client will give at least 30 days' written notice of an audit, agree its scope in advance, carry it out during business hours without unreasonably disrupting NeuRazor's business, and bear its own costs. Audits take place at most once in any 12 months, unless a Personal Data Breach or a supervisory authority requires otherwise.
- Audits must not give access to other clients' data or to information that would compromise the security of the Platform.
13. International transfers
13.1 Where the data goes
NeuRazor is established in India, and its staff access the Platform from India. Client Personal Data is stored by Supabase in Sydney, Australia (AWS ap-southeast-2). Some Sub-processors are in the USA, as listed in Annex III.
13.2 EU Standard Contractual Clauses
- To the extent the Client's transfer of Client Personal Data to NeuRazor is a transfer to a third country subject to Chapter V of the GDPR, the SCCs, Module Two (controller to processor), are incorporated into this DPA by reference. The Client is the data exporter and NeuRazor is the data importer.
- The parties make these choices:
- Clause 7 (docking clause): applies.
- Clause 9(a) (use of sub-processors): Option 2, general written authorisation. The time period for prior notice of changes is 30 days, as set out in section 7.
- Clause 11(a) (redress): the optional language does not apply.
- Clause 13 (supervision): the competent supervisory authority is determined under Clause 13(a) according to the Client's establishment, as set out in Annex I.C.
- Clause 17 (governing law): Option 2. The SCCs are governed by the law of the EU Member State in which the Client is established. Where that law does not allow for third-party beneficiary rights, they are governed by the law of Ireland.
- Clause 18(b) (choice of forum): the courts of the EU Member State whose law governs the SCCs under Clause 17.
- Annexes I, II and III of this DPA are the annexes to the SCCs.
- Onward transfers by NeuRazor to Sub-processors comply with Clause 8.8 of the SCCs, using the Sub-processor's standard contractual clauses and, where shown in Annex III, its certification under the EU-US Data Privacy Framework.
- If the SCCs conflict with this DPA or the Platform Terms, the SCCs prevail.
13.3 United Kingdom
For transfers subject to the UK GDPR, the UK Addendum is incorporated into this DPA by reference and completed as follows. Table 1: the parties and their details are as in Annex I.A, and the start date is the date of acceptance. Table 2: the Addendum EU SCCs are the SCCs, Module Two, with the choices in section 13.2. Table 3: the Appendix Information is in Annexes I, II and III. Table 4: either party may end the UK Addendum as allowed by its Section 19.
13.4 Switzerland
For transfers subject to the Swiss FADP, the SCCs apply with these adaptations: references to the GDPR are to be read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and the term "Member State" in the SCCs must not be read to exclude data subjects in Switzerland from bringing claims in their place of habitual residence under Clause 18(c).
13.5 Requests from public authorities
If NeuRazor receives a legally binding request from a public authority for Client Personal Data, it will handle it as set out in Clause 15 of the SCCs, including notifying the Client where permitted and reviewing the legality of the request.
14. Liability
Each party's liability under this DPA is subject to the limits in the Platform Terms, except where the SCCs or applicable law do not allow those limits. Nothing in this DPA limits the rights of data subjects under the SCCs.
15. Precedence, term and changes
- If documents conflict, this order applies: the SCCs (and the UK Addendum or Swiss adaptations, where they apply), then this DPA, then the Platform Terms.
- This DPA lasts for as long as NeuRazor processes Client Personal Data.
- NeuRazor may update this DPA as set out in the Platform Terms. An update will not reduce the protection given to Client Personal Data, unless the law requires it.
- Apart from the SCCs, this DPA is governed by the law that governs the Platform Terms.
Annex I. Description of the processing
A. List of parties
Data exporter (controller)
- Name
- The Client, as identified in its client account and any order form.
- Address
- As given in the client account or order form.
- Contact
- The Client's account owner, and any privacy contact it names in writing.
- Activities
- Using the NeuRazor Platform to assess and select candidates.
- Signature and date
- Electronic acceptance in the client portal, recorded with version, person and time.
- Role
- Controller
Data importer (processor)
- Name
- NeuRazor Labs
- Address
- New Delhi, India. Full registered address on request.
- Contact
- Privacy contact, support@neurazor.com
- Activities
- Providing the NeuRazor assessment platform and related support.
- Signature and date
- Accepted with the Client's electronic acceptance.
- Role
- Processor
B. Description of transfer
Categories of data subjects. Candidates invited by the Client to its assessments, or applying to its job postings.
Categories of personal data.
- Identity and contact: name and email address, provided by the Client.
- Assessment data: answers, scores, time spent on each task, task results, transcripts and reports.
- Proctoring data: webcam photos taken every few seconds while the camera is on; screen images while screen sharing is on; browser events such as switching tabs, leaving full screen and copying or pasting; browser and device details; IP address.
- Recordings: for AI interviews, role-plays, scenarios and simulations, an audio and video recording of the whole task, including the Candidate's image and voice; audio captured during some games.
- Consent and request records: when the Candidate agreed, the notice version, the purposes agreed to, age confirmation, withdrawals, and privacy and human review requests.
Sensitive data. None intended. The Client must not provide special categories of personal data or data about criminal convictions. Images and recordings of Candidates are not processed for face recognition, biometric identification, eye tracking or emotion detection. Safeguards: role-based access, access logging, short retention for images and recordings (Annex I.B, retention), and the measures in Annex II.
Frequency. Continuous, for as long as the Client runs assessments on the Platform.
Nature of the processing. Collection through online assessments; storage; proctoring; audio and video recording; speech to text and text to speech; scoring with AI models against the skills the Client chooses; running the AI interviewer and role-play; reporting to the Client; retrieval, export and erasure; and creation of statistics with names and identities removed.
Purposes. To provide the Platform to the Client: to run, proctor, record and score assessments and report the results, so that the Client can make its own hiring decisions; to support and secure the Platform; and to improve it using statistics with names and identities removed.
Retention.
| Data | Retention |
|---|---|
| Webcam photos | 10 days. 10 sample photos per Candidate kept 30 days. |
| Screen images | 10 days. Images taken when the Candidate leaves the assessment window: 90 days. |
| Gameplay audio | 30 days. |
| Interview, role-play, scenario and simulation recordings | Up to 90 days. |
| Answers, scores, transcripts, reports, proctoring event log, consent records | Erased 12 months after the Candidate's last activity by default. The Client can set 30 days to 3 years. |
| Candidates in a campaign the Client deletes | Erased 30 days after deletion. |
| Billing records | As the law requires, with the Candidate's email replaced by a one-way code on erasure. |
| After the account closes | Deleted within 30 days; backups within 7 further days. |
| Backups | Up to 7 days after deletion. |
Transfers to Sub-processors. Each Sub-processor in Annex III processes the data shown there, for the purpose shown, for as long as the Client uses the Platform and subject to the retention above. Anthropic and OpenAI may keep data sent to them for up to 30 days for abuse monitoring. Deepgram does not keep data after processing.
C. Competent supervisory authority
Under Clause 13(a) of the SCCs: where the Client is established in an EU Member State, the supervisory authority responsible for the Client's compliance with the GDPR; where the Client is not established in the EU but has appointed a representative under Article 27(1) GDPR, the supervisory authority of the Member State where that representative is established; otherwise, the supervisory authority of the Member State where the Candidates concerned are located.
Annex II. Technical and organisational measures
- Encryption. Data is encrypted at rest with AES-256 (managed by our hosting provider) and in transit with TLS 1.2 or higher.
- Tenant isolation. Row-level security is enabled on every database table. A Client's users can reach only their own company's data. Privacy functions check the caller's identity and company on the server.
- Role-based access. Client users have roles. Only owners and client admins can erase Candidate data or change retention. NeuRazor's admin functions are limited to staff with the admin role, who access Client Personal Data only when needed to support the Platform.
- Access logging. Viewing a report, playing a recording, viewing a proctoring image, CV, ID proof or intro video, exporting, and erasing are recorded in an append-only access log, kept for 2 years.
- Erasure tooling. Candidates (candidate portal), Clients (client portal) and NeuRazor admins (admin portal) can erase a Candidate's data. Erasure covers every table that holds the Candidate's data and the stored files. Files are deleted at once and a retry job runs every 10 minutes. Every erasure is recorded.
- Retention. Data is deleted automatically on the schedule in Annex I by scheduled jobs: a daily retention sweep, a daily proctoring image retention job, and an hourly recording clean-up.
- Data minimisation. Only name and email are needed to invite a Candidate. Candidate names are not sent to AI models for scoring. There is no face recognition, biometric identification, eye tracking or emotion detection.
- AI providers. AI and speech providers may not train on Client Personal Data. Deepgram's model-improvement opt-out is set on every request. Anthropic and OpenAI may keep API data up to 30 days for abuse monitoring.
- Backups and availability. Daily backups are kept for 7 days.
- Testing. NeuRazor carries out a vulnerability assessment and penetration test (VAPT) at least once a year. The most recent was in July 2026.
- Personnel. Staff who can access Client Personal Data are bound by confidentiality and have access only as their role needs.
- Incident response. NeuRazor keeps a written breach response plan, with defined roles, triage, containment, a breach register, and notice to the Client within 48 hours (section 10).
- Physical security. Servers and storage are run by our hosting providers (Supabase on Amazon Web Services in Sydney, and Vercel), whose physical security controls apply.
- Browser storage. The Platform keeps only strictly necessary items in the browser and runs no analytics, advertising or tracking scripts.
- Sub-processors. Sub-processors are engaged under written contracts with data protection terms and transfer safeguards, as listed in Annex III.
- Assisting the Client. The client portal provides export, erasure, retention settings, the privacy requests list and Candidates' consent records (section 8).
Annex III. Sub-processors
The current list, with any changes announced under section 7, is at www.neurazor.com/subprocessors. At the date of this version it is:
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Supabase Inc. | Database, sign-in, file storage, server functions. | Data in Sydney, Australia. Company in the USA. | SCCs in the Supabase DPA. |
| Vercel Inc. | Web hosting, voice proxy functions. | Global edge. Company in the USA. | SCCs and EU-US Data Privacy Framework. |
| Anthropic PBC | AI scoring, AI interviewer and role-play. | USA | SCCs in the Anthropic DPA. No training. Up to 30 days. |
| OpenAI, L.L.C. | AI conversation, scoring, speech, transcription. | USA | SCCs in the OpenAI DPA. No training. Up to 30 days. |
| Deepgram, Inc. | Speech to text, text to speech. | USA | SCCs. Model-improvement opt-out on every request. Not kept after processing. |
| Cartesia AI, Inc. | AI interviewer voice (text to speech). | USA | SCCs. |
| ElevenLabs, Inc. | Backup interviewer voice. | USA | SCCs. |
| Microsoft Corporation (Azure AI Speech) | Backup interviewer voice. | India (Central India region) | SCCs and EU-US Data Privacy Framework. |
| Resend (Plus Five Five, Inc.) | Sending emails (invitations, sign-in links). | USA | SCCs. |
| Google LLC (Google Workspace) | Support mailbox, support@neurazor.com. | USA and EU | SCCs and EU-US Data Privacy Framework. |
Razorpay Software Pvt. Ltd. (India) processes client payments only and receives no Candidate data, so it is not a Sub-processor under this DPA.
Data Processing AgreementVersion 2026-10-03Last updated 3 October 2026