Skip to content
Hirify
Trust center

Trust & security

Our customers' trust and the protection of candidate data are central to Hirify. This page summarizes our security measures, our GDPR compliance, and our responsible approach to artificial intelligence.

Last updated : June 18, 2026

Infrastructure

Hosting and data residency

The application and its data are hosted in France. Files, databases, and backups reside in France, in ISO 27001-certified datacenters. Data is encrypted at rest and in transit. Backups are performed daily.

Data residency
France
Data centers
ISO 27001-certified
Encryption
At rest and in transit
Backups
Daily
Platform

Platform security

  • Encryption

    Data encrypted in transit and at rest.

  • Authentication

    Enterprise single sign-on via SAML 2.0, with a second factor available.

  • Access control

    Access partitioned by organization and graded by role, following the principle of least privilege.

  • Monitoring and logging

    Application monitoring and access logging.

  • Backups and recovery

    Encrypted backups and a recovery plan.

Compliance

Data protection and GDPR

Hirify acts as a processor within the meaning of the GDPR, while the recruiting client remains the controller. We apply data minimization and defined retention periods.

Data subjects exercise their rights of access, rectification, and erasure through their usual contact. Our data protection contact is rgpd@hirify.fr.

Data processing agreement
Compliant with Article 28 of the GDPR, available on request.
Breach notification
Notification to the controller within 48 hours.
Retention
Two years after the last contact with a candidate, for interview analyses.
Transparency

Our sub-processors

Hirify sub-processors: function, provider, and location.
FunctionProviderLocation
Meeting captureRecall.aiEuropean Uniondata localized in the EU, entity outside the EU
TranscriptionGladiaFrance
AI analysis and text recognitionMistralFrance
File storageScalewayFrance
HostingScalingoFrance
Semantic searchVoyage and CohereUnited States and Canadatransfer governed by Chapter V of the GDPR
TelephonyTelnyxEuropean Uniondata localized in the EU, entity outside the EU
EmailBrevoFrance
ObservabilityMonocleSwitzerland
SupportCrispFrance

The most sensitive data, interview audio and content, is processed within the European Union. The rare processing located outside the Union falls under Chapter V of the GDPR, with the applicable transfer mechanism specified in the data processing agreement. This list shows our main sub-processors; the complete named list is included in that agreement.

Responsible AI

Responsible artificial intelligence

  • Humans decide

    Hirify assists the recruiter, it does not decide in their place. No write to your ATS happens automatically; the decision and the action remain in the recruiter's hands.

  • Traceable analyses

    Our analyses are anchored to verifiable quotations from the interview, which prevents unfounded claims.

  • Non-discrimination

    Safeguards prevent the system from retaining protected characteristics, in accordance with Article L1132-1 of the French Labour Code and Directive 2000/78/EC.

  • No training on your data

    Your data is not used to train the models, and the model providers apply a zero-retention policy.

Contact

Your questions

Evaluating Hirify? Request our complete compliance dossier and our data processing agreement.

The detailed compliance dossier is shared under a confidentiality agreement.

Email rgpd@hirify.fr

The company's legal information for HIRIFY SAS is available in the legal notice. The processing of personal data is described in the privacy policy.