Trust & security
Our customers' trust and the protection of candidate data are central to Hirify. This page summarizes our security measures, our GDPR compliance, and our responsible approach to artificial intelligence.
Last updated : June 18, 2026
Hosting and data residency
The application and its data are hosted in France. Files, databases, and backups reside in France, in ISO 27001-certified datacenters. Data is encrypted at rest and in transit. Backups are performed daily.
- Data residency
- France
- Data centers
- ISO 27001-certified
- Encryption
- At rest and in transit
- Backups
- Daily
Platform security
Encryption
Data encrypted in transit and at rest.
Authentication
Enterprise single sign-on via SAML 2.0, with a second factor available.
Access control
Access partitioned by organization and graded by role, following the principle of least privilege.
Monitoring and logging
Application monitoring and access logging.
Backups and recovery
Encrypted backups and a recovery plan.
Data protection and GDPR
Hirify acts as a processor within the meaning of the GDPR, while the recruiting client remains the controller. We apply data minimization and defined retention periods.
Data subjects exercise their rights of access, rectification, and erasure through their usual contact. Our data protection contact is rgpd@hirify.fr.
- Data processing agreement
- Compliant with Article 28 of the GDPR, available on request.
- Breach notification
- Notification to the controller within 48 hours.
- Retention
- Two years after the last contact with a candidate, for interview analyses.
Our sub-processors
| Function | Provider | Location |
|---|---|---|
| Meeting capture | Recall.ai | European Uniondata localized in the EU, entity outside the EU |
| Transcription | Gladia | France |
| AI analysis and text recognition | Mistral | France |
| File storage | Scaleway | France |
| Hosting | Scalingo | France |
| Semantic search | Voyage and Cohere | United States and Canadatransfer governed by Chapter V of the GDPR |
| Telephony | Telnyx | European Uniondata localized in the EU, entity outside the EU |
| Brevo | France | |
| Observability | Monocle | Switzerland |
| Support | Crisp | France |
The most sensitive data, interview audio and content, is processed within the European Union. The rare processing located outside the Union falls under Chapter V of the GDPR, with the applicable transfer mechanism specified in the data processing agreement. This list shows our main sub-processors; the complete named list is included in that agreement.
Responsible artificial intelligence
Humans decide
Hirify assists the recruiter, it does not decide in their place. No write to your ATS happens automatically; the decision and the action remain in the recruiter's hands.
Traceable analyses
Our analyses are anchored to verifiable quotations from the interview, which prevents unfounded claims.
Non-discrimination
Safeguards prevent the system from retaining protected characteristics, in accordance with Article L1132-1 of the French Labour Code and Directive 2000/78/EC.
No training on your data
Your data is not used to train the models, and the model providers apply a zero-retention policy.
Your questions
Evaluating Hirify? Request our complete compliance dossier and our data processing agreement.
The detailed compliance dossier is shared under a confidentiality agreement.
The company's legal information for HIRIFY SAS is available in the legal notice. The processing of personal data is described in the privacy policy.