Skip to content

Data Processing Agreement

How BeCareers processes candidate personal data on your behalf. We name every sub-processor, say where data is held, and list the security measures that are actually in place - not a wish list.

Version 1.0 · 23 September 2026 · Applies to BeCareers AI screening and GetMeHired.uk employer services

1. Parties and scope

1.1 This Data Processing Agreement ("DPA") forms part of the agreement between BeCareers Ltd (company number 16983211, registered office 22 Queens Road, Doncaster, South Yorkshire, DN1 2NQ) ("BeCareers", "we") and the employer, agency or partner using our services ("Customer", "you").

1.2 It applies whenever we process personal data on your behalf in providing AI screening, the careers-site widget, the employer dashboard and GetMeHired.uk employer services (the "Services").

1.3 "Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and, where it applies to you, the EU GDPR. Terms such as controller, processor, personal data and processing have the meanings given in that law.

2. Roles

2.1 You are the controller of the personal data of your applicants and your users. We are your processor.

2.2 You decide which roles to screen, the criteria and questions used, whether any automatic knock-out rules apply, and every hiring decision. You are responsible for having a lawful basis and giving applicants the information Data Protection Law requires, including that AI is used in screening.

2.3 GetMeHired.uk is operated by BeCareers. Where a candidate creates their own account on GetMeHired.uk to search and apply for jobs, BeCareers is the controller of that account data and our Privacy Policy applies. Once an application is made to you, the application data is processed on your behalf under this DPA.

3. Your instructions

3.1 We process personal data only on your documented instructions - this DPA, your configuration of the Services and your written requests - unless the law requires otherwise, in which case we will tell you first unless the law prohibits it.

3.2 We will tell you promptly if we believe an instruction breaks Data Protection Law.

4. Confidentiality

4.1 Everyone we authorise to process your personal data is bound by confidentiality, and access is limited to those who need it to provide or support the Services.

5. Security

5.1 We implement the technical and organisational measures in Annex 2, appropriate to the risks of processing applicant data. We may improve them over time but will not reduce the overall level of protection.

5.2 Some measures are controls you choose to use - for example requiring multi-factor authentication for your users, and your retention settings. We will help you configure them.

6. Sub-processors

6.1 You authorise the sub-processors listed in Annex 3. We name each one, what it does and where it processes data.

6.2 We will give you at least 30 days' notice of a new or replacement sub-processor. You may object on reasonable data protection grounds; if we cannot resolve the objection, you may end the affected Services without penalty.

6.3 We impose data protection terms on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance.

7. International transfers

7.1 The Services are hosted in the United Kingdom, on Amazon Web Services in London (eu-west-2).

7.2 Where a sub-processor processes data outside the UK, we rely on UK adequacy regulations (including the UK-US data bridge where the recipient is certified) or the ICO's International Data Transfer Agreement or Addendum, with a transfer risk assessment.

7.3 AI screening runs on BeCareers' own models, hosted in the UK. Applicant data is not sent outside the UK for screening.

7.4 The only sub-processors that may process data outside the UK are optional messaging channels (Annex 3), used only if you choose to enable them.

8. Data subject rights

8.1 We will help you respond to requests from applicants to exercise their rights. The Services include tools to export an individual's data, erase it, and place records on legal hold; applicants can withdraw an application.

8.2 If an applicant contacts us directly about data we process for you, we will pass the request to you without undue delay and will not respond ourselves except to acknowledge it, unless you ask us to.

9. AI screening safeguards

9.1 People decide. AI screening produces transcripts, summaries and scores to support your review. It is decision-support: the Services do not use AI output alone to reject an applicant.

9.2 Knock-out rules are yours. If you configure knock-out questions (for example, "Do you hold a valid HGV licence?"), the Services can move an applicant who gives a disqualifying answer to a disqualified stage automatically. That is a decision rule you set and control. You are responsible for making sure such rules are necessary for the role, for telling applicants about them, and for giving them a way to ask for a person to review the outcome. Any applicant can be reviewed and reinstated by your team.

9.3 Our own models, in the UK. Screening is conducted by BeCareers' own AI models, hosted in the UK. We do not use your applicants' personal data to train AI models.

9.4 Anonymised improvement data. You authorise us to create anonymised data from screenings - with names, contact details and anything else that could identify an applicant removed - and to use it to evaluate and improve the quality of our screening. Anonymised data is not personal data. We will not attempt to re-identify anyone, and we will not use or disclose anonymised data in a way that identifies you as the customer. You can withdraw this authorisation at any time by telling us in writing.

9.4 Provenance. Each screening result records which AI model and provider produced it, the rubric version and whether it is advisory, so results can be explained and audited. If the model is not identified, the result is flagged for human review.

9.5 Scope of data. Screening uses the application, the CV and the screening conversation. We do not collect or analyse applicants' social media or other public profiles.

10. Personal data breaches

10.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data.

10.2 We will give you the information you reasonably need to meet your own obligations, update you as we learn more, and take reasonable steps to contain and remedy the breach.

11. DPIAs and consultation

11.1 We will provide reasonable assistance with your data protection impact assessments and any prior consultation with the ICO. Our own DPIA for the Services is available on request - see the DPIA summary.

12. Return and deletion

12.1 During the agreement you control retention through your settings, and the Services delete personal data automatically at the end of the retention period you set (by default, 180 days). Screening records held by our screening service are deleted once their audit retention period ends.

12.2 Within 30 days of the end of the agreement we will, at your choice, return your personal data in a common format or delete it, and confirm deletion in writing on request - unless the law requires us to keep it.

13. Audits and information

13.1 We will make available the information reasonably necessary to demonstrate compliance with this DPA, including our DPIA, this Annex 2 and answers to security questionnaires.

13.2 Where that is not enough, you may carry out an audit (or have an independent auditor do so) once a year, on 30 days' notice, during business hours and subject to confidentiality.

14. General

14.1 If this DPA conflicts with the rest of our agreement on data protection, this DPA prevails.

14.2 This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Annex 1 - Details of processing

Subject matterReceiving and managing job applications, and AI-assisted first-stage screening of applicants.
DurationThe term of the agreement, plus the retention period you set and the return/deletion period in clause 12.
Nature of processingCollection, storage, structuring, CV analysis against your criteria, conducting a screening conversation, producing transcripts, summaries and scores, sending interview invitations and updates, and deletion.
Data subjectsApplicants and candidates for your roles; your users of the Services.
Personal dataName and contact details; CV and employment and education history; skills and qualifications; answers to application and screening questions; screening transcripts, summaries and scores; interview scheduling details; application status and history; consent records; communication records; for users, account and login details.
Special category dataNot requested by the Services. Applicants may include it in a CV or answer. You should not configure criteria or questions that ask for it, including health questions before a job offer.
Criminal offence dataNot requested. If you ask applicants about willingness to undergo a DBS check, the check itself is carried out by you, not us.

Annex 2 - Security measures

These measures are in place in the platform today.

Hosting and infrastructure

  • Hosted on Amazon Web Services in London (eu-west-2): managed Aurora PostgreSQL database, ElastiCache with TLS, and Amazon S3 file storage.
  • Files, including CVs, are stored in Amazon S3, which encrypts objects at rest (AES-256).
  • The database is encrypted at rest (AES-256, AWS KMS) and backed up automatically.
  • Public traffic is encrypted in transit with TLS at the load balancer, with HTTP Strict Transport Security on the core API.
  • Secrets and credentials are held in AWS Systems Manager Parameter Store and AWS Secrets Manager. Integration credentials are encrypted with AES-256-GCM.

Access control

  • Every API route requires authentication by default; access is governed by a single permission engine using role-based permissions.
  • Separation between customers: every record is scoped to its customer account, with enforcement in the application and automated tests for isolation.
  • Multi-factor authentication (authenticator app or passkey) is available and can be required for your users.
  • Administrative sessions use 15-minute access tokens; all of a user's sessions are revoked when their role or permissions change.
  • Passwords are hashed with PBKDF2-SHA512 (100,000 iterations, unique salt); login attempts are rate-limited with automatic lockout.
  • Public pages return only the fields a per-field exposure policy allows; records are never exposed wholesale.

Audit, provenance and accountability

  • A tamper-evident audit log: audit records are insert-only and sealed hourly in a SHA-256 hash chain that can be verified for tampering.
  • Every change to an application's stage records the previous and new stage, the reason, who made it and when, in UTC.
  • Each AI screening result records the model, provider and rubric version that produced it and whether it is advisory; results with no identified model are flagged for human review.
  • AI agent actions in the platform pass through a policy gate, are logged individually, and higher-risk actions need approval from a second person.
  • Screening results from the BeCareers screening service are delivered by webhooks authenticated with HMAC-SHA256 signatures.
  • Where applicable, the source of an application (the job it was made to and the channel) is recorded with it.

Data protection by design

  • Consent is recorded in an append-only ledger with the wording shown and its version; marketing and tracking consent are separate from the application.
  • Built-in tools to export and erase an individual's data, place legal holds and record withdrawal.
  • Automated daily deletion of personal data at the end of its retention period.
  • AI summarisation of records cannot be switched on for recruitment data until a DPIA reference has been recorded, and its output needs human review by default.
  • Marketing emails carry one-click unsubscribe.

Secure development

  • Automated architecture tests in continuous integration fail the build if code bypasses the audit, activity, workflow, access-control, field-exposure or timestamp controls.
  • Weekly automated dependency updates.

Annex 3 - Sub-processors

Sub-processorPurposeLocation
Amazon Web Services EMEA SARLHosting, database, file storage, email delivery (SES), and hosting of BeCareers' AI screening modelsUnited Kingdom (London)
Human Advertising (UK)Platform operation and support for GetMeHired.uk and the employer dashboardUnited Kingdom
Meta Platforms (optional)WhatsApp messaging to applicants - only if you enable itGlobal
LY Corporation (optional)LINE messaging to applicants - only if you enable itJapan

We will update this list, and notify you under clause 6.2, before adding a sub-processor.

Need this signed, or our DPIA?

We can countersign this DPA and share our Data Protection Impact Assessment with your DPO or procurement team.