Data Processing
Data Processing
Last Updated, 21 August 2026
Last Updated, 21 August 2026
Data Processing and Data Sharing Addendum
Last Updated: 21 August 2026
1. Purpose
This Data Processing and Data Sharing Addendum (“Addendum”) forms part of the agreement between HIER APPLICATIONS LIMITED (“Hier”) and each Business using the Hier Platform (“Customer”).
This Addendum governs:
personal data processed by Hier on behalf of a Customer where Hier acts as a Processor;
personal data independently controlled by Hier;
Candidate personal data disclosed by Hier to Customers for recruitment purposes; and
the respective data protection responsibilities of Hier and Customers.
This Addendum should be read with the Hier Terms of Use and Privacy Policy.
2. Definitions
For the purposes of this Addendum:
Applicable Data Protection Law means all applicable UK privacy and data protection legislation, including the UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025, Privacy and Electronic Communications Regulations 2003 where applicable, and legislation that replaces or amends them.
Candidate Data means personal data relating to a Candidate made available to a Customer through Hier.
Controller, Processor, Personal Data, Processing, Data Subject, Personal Data Breach and Special Category Personal Data have the meanings given to them under Applicable Data Protection Law.
Customer Data means Personal Data supplied to Hier by or on behalf of Customer for Processing solely on Customer's documented instructions, excluding Candidate Data independently controlled by Hier.
Subprocessor means another Processor engaged by Hier to process Customer Data on behalf of Customer.
3. Roles of the Parties
The parties acknowledge that their respective data protection roles depend on the relevant Processing activity.
3.1 Hier as Controller
Hier acts as a Controller for Personal Data it determines the purposes and means of Processing, including generally:
Candidate accounts;
Candidate profiles;
account authentication;
platform security;
Hier's own fraud prevention;
service analytics;
Hier customer support;
referral programme administration;
Business account administration;
billing administration;
legal compliance;
platform moderation; and
operation and improvement of Hier.
3.2 Customers as Separate Controllers
Where Hier makes Candidate Data available to Customer and Customer determines whether and how to use that information for recruitment, employment or talent-management purposes, Customer acts as a separate Controller of the Candidate Data it receives.
Nothing in this Addendum permits Customer to use Candidate Data for unrestricted purposes.
3.3 Hier as Processor
Where Customer provides Personal Data to Hier and Hier Processes that information solely for the purpose of providing a hosted service to Customer on Customer's documented instructions, Hier will act as Processor.
Examples may include:
information uploaded by Customer about individuals not independently sourced by Hier;
Customer recruitment notes;
Customer-configured workflow information;
data imported by Customer;
Customer-controlled records; and
other Personal Data processed solely to provide functionality requested by Customer.
3.4 No Assumed Joint Controllership
The parties do not intend to become joint controllers merely by using or providing Hier.
If an activity results in the parties jointly determining the purposes and means of Processing, they will cooperate in good faith to put an appropriate arrangement in place as required by law.
4. Customer Obligations as Controller
Customer warrants that it will comply with Applicable Data Protection Law.
Customer is responsible for:
identifying an appropriate lawful basis;
providing required privacy information;
complying with transparency requirements;
ensuring Personal Data is accurate where required;
limiting Personal Data to what is necessary;
maintaining appropriate security;
complying with Data Subject rights;
complying with retention requirements;
conducting required impact assessments;
maintaining required records;
complying with rules concerning Special Category Personal Data;
complying with rules concerning criminal offence data; and
ensuring its instructions to Hier are lawful.
Customer must not instruct Hier to process Personal Data unlawfully.
5. Use of Candidate Data
Customer may use Candidate Data only where reasonably necessary for legitimate recruitment-related activities.
Permitted purposes may include:
reviewing applications;
identifying potentially relevant Candidates;
assessing Candidate suitability;
communicating with Candidates;
arranging interviews;
managing a recruitment process; and
maintaining appropriate recruitment records.
Customer must not use Candidate Data to:
sell Candidate information;
create unrelated marketing databases;
send unrelated unsolicited marketing;
unlawfully discriminate;
build competing data products;
scrape or systematically copy the Hier Candidate database;
infer sensitive characteristics unlawfully;
profile Candidates for unrelated purposes;
conduct fraud;
harass Candidates;
disclose Candidate Data to unrelated third parties without lawful justification; or
use Candidate Data in a manner incompatible with the purpose for which it was made available.
6. Candidate Transparency
Customer is responsible for ensuring Candidates receive any privacy information that Customer is legally required to provide concerning Customer's independent Processing.
Where Customer obtains Candidate Data through Hier, Customer must consider its transparency obligations under Applicable Data Protection Law, including where information has not been obtained directly from the Candidate.
Customer should clearly identify itself as the relevant employer, recruiter or Controller where required.
7. Automated Recruitment Decisions
Where Customer uses automated tools, algorithms or AI in connection with Candidate Data, Customer is solely responsible for ensuring such use complies with Applicable Data Protection Law and applicable equality and employment law.
Customer must not treat a Hier AI score, ranking, recommendation or automated output as a substitute for meaningful recruitment judgement.
Where Customer makes a significant decision based solely on automated Processing, Customer must implement all safeguards required by Applicable Data Protection Law.
This may include requirements to:
inform the affected individual;
enable representations;
provide appropriate human intervention;
enable the decision to be contested;
assess fairness and bias; and
conduct a Data Protection Impact Assessment where required.
Customer must take particular care when Special Category Personal Data is involved.
8. Processing Instructions
Where Hier acts as Processor, Customer instructs Hier to Process Customer Data:
to provide the Platform;
to provide functionality selected by Customer;
to maintain and secure the service;
to troubleshoot;
to provide support;
to back up Customer Data;
to prevent technical abuse;
to comply with Customer's lawful written instructions; and
as otherwise necessary to perform the agreement.
The Terms, Customer's configuration and use of the Platform, this Addendum and any agreed written instructions constitute Customer's documented instructions.
Hier will not Process Customer Data outside those instructions unless required by applicable law.
If legally permitted, Hier will notify Customer before Processing required by law.
If Hier reasonably considers an instruction to infringe Applicable Data Protection Law, Hier may suspend execution of the instruction and notify Customer.
9. Confidentiality
Hier will ensure that persons authorised to Process Customer Data are subject to appropriate confidentiality obligations.
Access will be limited to persons who reasonably require it to perform their responsibilities.
10. Security
Taking account of:
available technology;
implementation cost;
the nature, scope, context and purpose of Processing; and
the risk to individuals,
Hier will maintain appropriate technical and organisational measures designed to protect Customer Data.
Measures may include, as appropriate:
role-based access controls;
authentication controls;
least-privilege access;
encryption in transit;
appropriate protection for stored data;
secure hosting;
logging and monitoring;
vulnerability management;
backups and resilience;
incident management;
staff confidentiality;
access reviews;
supplier security controls; and
processes for restoring availability following relevant incidents.
No Customer should use Hier to store Personal Data that requires a level of security materially beyond the service as described without first agreeing specific requirements with Hier.
11. Personal Data Breaches
Where Hier acts as Processor and becomes aware of a Personal Data Breach affecting Customer Data, Hier will notify Customer without undue delay.
The notification will contain information reasonably available to Hier that Customer may require to comply with its breach-notification obligations, which may include:
the nature of the incident;
categories of affected individuals;
categories of affected data;
likely consequences;
steps taken or proposed; and
relevant contact information.
Information may be provided in stages where it is not available at the same time.
Hier's notification of a security incident is not an admission of fault or liability.
Customer remains responsible for determining whether notification to individuals, regulators or other parties is legally required where Customer is Controller.
12. Subprocessors
Customer gives Hier general authorisation to engage Subprocessors where necessary to provide the Platform.
Hier will:
carry out reasonable due diligence;
impose appropriate data protection obligations;
require substantially equivalent protection for relevant Customer Data;
remain responsible for its Subprocessors to the extent required by Applicable Data Protection Law; and
provide information about material Subprocessors on reasonable request.
Where legally required, Hier will notify Customer of intended material changes to Subprocessors and allow Customer a reasonable opportunity to raise legitimate data-protection objections.
An objection must relate to genuine data-protection concerns rather than ordinary commercial preference.
The parties will work in good faith to resolve a legitimate objection.
13. International Transfers
Hier will not make a restricted international transfer of Customer Data as Processor unless a lawful transfer mechanism applies.
Where required, this may include:
UK adequacy regulations;
the International Data Transfer Agreement;
an approved UK Addendum;
binding corporate rules; or
another valid mechanism recognised under Applicable Data Protection Law.
Hier may implement additional contractual, organisational or technical safeguards where reasonably appropriate.
Customer authorises international Processing carried out in accordance with this section.
14. Data Subject Rights
Taking account of the nature of the Processing, Hier will provide reasonable assistance to Customer where necessary for Customer to respond to requests relating to:
access;
rectification;
deletion;
restriction;
objection;
portability; and
applicable automated decision rights.
If Hier receives a request relating solely to Customer Data for which Customer is Controller, Hier may direct the requester to Customer unless law requires otherwise.
Customer is responsible for assessing and responding to the request.
Where Hier is independently the Controller of relevant information, Hier will handle the request in its own capacity.
15. Regulatory Assistance and DPIAs
Taking account of the nature of Processing and information available to Hier, Hier will provide reasonable assistance to Customer with obligations relating to:
security;
breach assessment;
Data Protection Impact Assessments;
regulator consultations; and
demonstration of compliance,
where the matter directly concerns Hier's Processing of Customer Data as Processor.
Customer remains responsible for its own compliance decisions.
Hier may charge reasonable fees for substantial assistance that falls outside normal service provision, unless the assistance is required because of Hier's breach.
16. Audits and Compliance Information
Hier will make available information reasonably necessary to demonstrate compliance with its Processor obligations.
Where reasonably necessary and proportionate, Customer may request an audit relating to Hier's Processing of Customer Data.
Audits must:
normally be requested in writing;
provide reasonable notice;
occur no more than once in any 12-month period unless required by a regulator or following a material incident;
avoid unreasonable disruption;
protect the confidentiality and security of other customers;
be carried out by suitably qualified persons; and
comply with reasonable security requirements.
Hier may satisfy audit requests through relevant independent audit reports, certifications, security documentation or questionnaires where these reasonably demonstrate compliance.
Customer bears its own audit costs unless an audit identifies a material breach by Hier.
17. Deletion and Return
Upon termination of services involving Hier acting as Processor, Hier will, at Customer's choice and subject to available Platform functionality:
return relevant Customer Data; or
delete relevant Customer Data,
unless applicable law requires continued retention.
Customer is responsible for exporting information it requires before account closure.
Customer acknowledges that securely deleted information may remain temporarily in backup systems until normal backup rotation occurs.
While retained only in backups, such information will remain protected and will not be actively processed except where necessary for restoration, security or legal compliance.
18. Data Minimisation
Customer must not upload Personal Data that is unnecessary for use of Hier.
In particular, Customer should not upload:
excessive identity documents;
unnecessary financial information;
medical records;
biometric data;
criminal records;
passwords belonging to individuals;
unrelated private communications; or
other high-risk information
unless Hier expressly supports that use and Customer has established the lawful basis and safeguards required.
19. Special Category Personal Data
Hier's standard Business service is not designed to require unnecessary Special Category Personal Data.
If Customer chooses to process Special Category Personal Data using Hier, Customer is responsible for:
identifying an Article 6 lawful basis;
identifying an applicable Article 9 condition;
satisfying any Data Protection Act 2018 requirements;
providing appropriate transparency;
completing any required impact assessment; and
implementing appropriate safeguards.
Customer must not instruct Hier to infer sensitive characteristics about Candidates unless expressly supported by Hier and lawful.
20. Criminal Offence Data
Customer must not use Hier to process criminal conviction or offence information unless:
the Processing is lawful;
an appropriate condition applies;
necessary policies and safeguards are in place; and
the Platform expressly supports the relevant activity.
21. Direct Marketing
Access to Candidate Data through Hier does not constitute consent for unrelated direct marketing.
Customer is responsible for complying with applicable marketing and privacy rules before using Candidate information for marketing purposes.
Candidate data obtained for recruitment must not be repurposed for unrelated advertising merely because Customer has access to the Candidate's email address or telephone number.
22. Customer Security Obligations
Customer must:
protect its Hier credentials;
use appropriate access controls;
restrict access to authorised users;
promptly disable former employees or contractors;
use secure devices;
promptly notify Hier of suspected compromise;
avoid exporting Personal Data unnecessarily; and
maintain appropriate protection for exported information.
Hier is not responsible for an unauthorised disclosure caused solely by Customer failing to secure its own account or systems.
23. Data Accuracy
Each party is responsible for taking reasonable steps to ensure the Personal Data it controls is accurate where required.
Customer must not knowingly maintain materially inaccurate information about a Candidate where that information could adversely affect the Candidate.
Where Hier provides functionality enabling a Candidate to correct their information, Customer should take appropriate account of corrected information where relevant.
24. Retention by Customers
Customer must establish and follow an appropriate retention policy for Candidate Data.
Candidate Data must not be retained indefinitely merely because it was available through Hier.
Customer should consider:
whether recruitment remains active;
legal claims;
statutory requirements;
Candidate expectations;
future-opportunity consent where relevant;
data minimisation; and
security risk.
Where Customer no longer has a lawful reason to retain Candidate Data, it must delete or anonymise it as appropriate.
25. Data Protection Complaints
Each party is responsible for handling data protection complaints concerning Processing for which that party is Controller.
If a complaint principally concerns the other party's Processing, the receiving party may direct the complainant appropriately or cooperate with the other party where lawful.
Nothing in this Addendum prevents an individual from exercising rights against the relevant Controller.
26. Giftcloud and Referral Data
For clarity, where Hier sends Hier-user names and email addresses to Giftcloud Limited solely to fulfil a Hier referral reward:
Hier acts as Controller;
Giftcloud acts as Hier's Processor for the Processing performed on Hier's instructions; and
that Processing is governed by the contractual data-processing arrangements between Hier and Giftcloud.
Giftcloud is not a Customer Subprocessor merely because a Business uses Hier.
Giftcloud may separately act as Controller for information it independently collects or Processes for its own purposes.
27. Liability
Liability under this Addendum is subject to the liability provisions in the Hier Terms of Use or any separately signed agreement between the parties.
Nothing in this Addendum excludes or limits liability where such exclusion or limitation is prohibited by Applicable Data Protection Law.
Each party remains responsible for fines, claims, losses and regulatory action to the extent arising from its own breach of Applicable Data Protection Law.
28. Order of Precedence
If there is a conflict concerning Processing of Personal Data:
any mandatory requirement of Applicable Data Protection Law applies first;
this Addendum applies next;
any separately signed data-processing agreement applies where it expressly supersedes this Addendum;
the applicable Hier Terms apply thereafter.
Schedule 1 — Processor Processing Details
Subject Matter
Provision of the Hier recruitment, recruitment-management, communication and related technology services to Customer.
Duration
For the duration of Customer's use of the relevant Hier services and any limited post-termination period necessary for secure deletion, backup rotation or legal compliance.
Nature of Processing
Processing may include:
collection;
receipt;
recording;
organisation;
structuring;
hosting;
storage;
retrieval;
consultation;
display;
transmission;
matching;
communication;
support;
backup;
security monitoring;
restriction;
export at Customer's instruction;
deletion; and
anonymisation.
Purpose
To provide, secure, maintain and support functionality requested by Customer through the Hier Platform.
Categories of Data Subjects
Depending on Customer's use, Data Subjects may include:
Candidates;
applicants;
prospective Candidates;
employees;
contractors;
Customer staff;
Customer authorised users; and
other individuals whose Personal Data Customer lawfully uploads.
Types of Personal Data
Depending on Customer's use:
names;
email addresses;
telephone numbers;
professional information;
employment history;
education;
qualifications;
skills;
CV information;
application information;
interview information;
recruitment notes;
communication information;
workflow information;
identifiers; and
account-related data.
Special Category Data
Not required for standard use.
May be incidentally processed where included by Customer or a Data Subject, subject to Customer satisfying applicable legal requirements.
Criminal Offence Data
Not intended for standard use unless expressly supported and lawfully processed.
Documented Instructions
Customer's documented instructions consist of:
this Addendum;
the Hier Terms;
Customer's use and configuration of Hier;
requests made through authorised Platform functionality; and
additional lawful instructions agreed in writing.
Schedule 2 — Minimum Security Principles
Hier will maintain security measures proportionate to the risk, which may include:
controlled access to production systems;
authentication mechanisms;
access based on job responsibilities;
confidentiality requirements;
secure communications;
protected data storage;
environment separation where appropriate;
monitoring and logging;
vulnerability and dependency management;
data backup and recovery processes;
incident response;
supplier oversight;
software development controls;
access revocation procedures; and
periodic review of security measures.
Security measures may evolve as technology and risk change, provided the overall level of protection is not materially reduced without reasonable justification.
Schedule 3 — Contact
HIER APPLICATIONS LIMITED
167–169 Great Portland Street
London
England
W1W 5PF
Company Number: 17102004
Email: hello@hierapp.co.uk
Data Processing and Data Sharing Addendum
Last Updated: 21 August 2026
1. Purpose
This Data Processing and Data Sharing Addendum (“Addendum”) forms part of the agreement between HIER APPLICATIONS LIMITED (“Hier”) and each Business using the Hier Platform (“Customer”).
This Addendum governs:
personal data processed by Hier on behalf of a Customer where Hier acts as a Processor;
personal data independently controlled by Hier;
Candidate personal data disclosed by Hier to Customers for recruitment purposes; and
the respective data protection responsibilities of Hier and Customers.
This Addendum should be read with the Hier Terms of Use and Privacy Policy.
2. Definitions
For the purposes of this Addendum:
Applicable Data Protection Law means all applicable UK privacy and data protection legislation, including the UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025, Privacy and Electronic Communications Regulations 2003 where applicable, and legislation that replaces or amends them.
Candidate Data means personal data relating to a Candidate made available to a Customer through Hier.
Controller, Processor, Personal Data, Processing, Data Subject, Personal Data Breach and Special Category Personal Data have the meanings given to them under Applicable Data Protection Law.
Customer Data means Personal Data supplied to Hier by or on behalf of Customer for Processing solely on Customer's documented instructions, excluding Candidate Data independently controlled by Hier.
Subprocessor means another Processor engaged by Hier to process Customer Data on behalf of Customer.
3. Roles of the Parties
The parties acknowledge that their respective data protection roles depend on the relevant Processing activity.
3.1 Hier as Controller
Hier acts as a Controller for Personal Data it determines the purposes and means of Processing, including generally:
Candidate accounts;
Candidate profiles;
account authentication;
platform security;
Hier's own fraud prevention;
service analytics;
Hier customer support;
referral programme administration;
Business account administration;
billing administration;
legal compliance;
platform moderation; and
operation and improvement of Hier.
3.2 Customers as Separate Controllers
Where Hier makes Candidate Data available to Customer and Customer determines whether and how to use that information for recruitment, employment or talent-management purposes, Customer acts as a separate Controller of the Candidate Data it receives.
Nothing in this Addendum permits Customer to use Candidate Data for unrestricted purposes.
3.3 Hier as Processor
Where Customer provides Personal Data to Hier and Hier Processes that information solely for the purpose of providing a hosted service to Customer on Customer's documented instructions, Hier will act as Processor.
Examples may include:
information uploaded by Customer about individuals not independently sourced by Hier;
Customer recruitment notes;
Customer-configured workflow information;
data imported by Customer;
Customer-controlled records; and
other Personal Data processed solely to provide functionality requested by Customer.
3.4 No Assumed Joint Controllership
The parties do not intend to become joint controllers merely by using or providing Hier.
If an activity results in the parties jointly determining the purposes and means of Processing, they will cooperate in good faith to put an appropriate arrangement in place as required by law.
4. Customer Obligations as Controller
Customer warrants that it will comply with Applicable Data Protection Law.
Customer is responsible for:
identifying an appropriate lawful basis;
providing required privacy information;
complying with transparency requirements;
ensuring Personal Data is accurate where required;
limiting Personal Data to what is necessary;
maintaining appropriate security;
complying with Data Subject rights;
complying with retention requirements;
conducting required impact assessments;
maintaining required records;
complying with rules concerning Special Category Personal Data;
complying with rules concerning criminal offence data; and
ensuring its instructions to Hier are lawful.
Customer must not instruct Hier to process Personal Data unlawfully.
5. Use of Candidate Data
Customer may use Candidate Data only where reasonably necessary for legitimate recruitment-related activities.
Permitted purposes may include:
reviewing applications;
identifying potentially relevant Candidates;
assessing Candidate suitability;
communicating with Candidates;
arranging interviews;
managing a recruitment process; and
maintaining appropriate recruitment records.
Customer must not use Candidate Data to:
sell Candidate information;
create unrelated marketing databases;
send unrelated unsolicited marketing;
unlawfully discriminate;
build competing data products;
scrape or systematically copy the Hier Candidate database;
infer sensitive characteristics unlawfully;
profile Candidates for unrelated purposes;
conduct fraud;
harass Candidates;
disclose Candidate Data to unrelated third parties without lawful justification; or
use Candidate Data in a manner incompatible with the purpose for which it was made available.
6. Candidate Transparency
Customer is responsible for ensuring Candidates receive any privacy information that Customer is legally required to provide concerning Customer's independent Processing.
Where Customer obtains Candidate Data through Hier, Customer must consider its transparency obligations under Applicable Data Protection Law, including where information has not been obtained directly from the Candidate.
Customer should clearly identify itself as the relevant employer, recruiter or Controller where required.
7. Automated Recruitment Decisions
Where Customer uses automated tools, algorithms or AI in connection with Candidate Data, Customer is solely responsible for ensuring such use complies with Applicable Data Protection Law and applicable equality and employment law.
Customer must not treat a Hier AI score, ranking, recommendation or automated output as a substitute for meaningful recruitment judgement.
Where Customer makes a significant decision based solely on automated Processing, Customer must implement all safeguards required by Applicable Data Protection Law.
This may include requirements to:
inform the affected individual;
enable representations;
provide appropriate human intervention;
enable the decision to be contested;
assess fairness and bias; and
conduct a Data Protection Impact Assessment where required.
Customer must take particular care when Special Category Personal Data is involved.
8. Processing Instructions
Where Hier acts as Processor, Customer instructs Hier to Process Customer Data:
to provide the Platform;
to provide functionality selected by Customer;
to maintain and secure the service;
to troubleshoot;
to provide support;
to back up Customer Data;
to prevent technical abuse;
to comply with Customer's lawful written instructions; and
as otherwise necessary to perform the agreement.
The Terms, Customer's configuration and use of the Platform, this Addendum and any agreed written instructions constitute Customer's documented instructions.
Hier will not Process Customer Data outside those instructions unless required by applicable law.
If legally permitted, Hier will notify Customer before Processing required by law.
If Hier reasonably considers an instruction to infringe Applicable Data Protection Law, Hier may suspend execution of the instruction and notify Customer.
9. Confidentiality
Hier will ensure that persons authorised to Process Customer Data are subject to appropriate confidentiality obligations.
Access will be limited to persons who reasonably require it to perform their responsibilities.
10. Security
Taking account of:
available technology;
implementation cost;
the nature, scope, context and purpose of Processing; and
the risk to individuals,
Hier will maintain appropriate technical and organisational measures designed to protect Customer Data.
Measures may include, as appropriate:
role-based access controls;
authentication controls;
least-privilege access;
encryption in transit;
appropriate protection for stored data;
secure hosting;
logging and monitoring;
vulnerability management;
backups and resilience;
incident management;
staff confidentiality;
access reviews;
supplier security controls; and
processes for restoring availability following relevant incidents.
No Customer should use Hier to store Personal Data that requires a level of security materially beyond the service as described without first agreeing specific requirements with Hier.
11. Personal Data Breaches
Where Hier acts as Processor and becomes aware of a Personal Data Breach affecting Customer Data, Hier will notify Customer without undue delay.
The notification will contain information reasonably available to Hier that Customer may require to comply with its breach-notification obligations, which may include:
the nature of the incident;
categories of affected individuals;
categories of affected data;
likely consequences;
steps taken or proposed; and
relevant contact information.
Information may be provided in stages where it is not available at the same time.
Hier's notification of a security incident is not an admission of fault or liability.
Customer remains responsible for determining whether notification to individuals, regulators or other parties is legally required where Customer is Controller.
12. Subprocessors
Customer gives Hier general authorisation to engage Subprocessors where necessary to provide the Platform.
Hier will:
carry out reasonable due diligence;
impose appropriate data protection obligations;
require substantially equivalent protection for relevant Customer Data;
remain responsible for its Subprocessors to the extent required by Applicable Data Protection Law; and
provide information about material Subprocessors on reasonable request.
Where legally required, Hier will notify Customer of intended material changes to Subprocessors and allow Customer a reasonable opportunity to raise legitimate data-protection objections.
An objection must relate to genuine data-protection concerns rather than ordinary commercial preference.
The parties will work in good faith to resolve a legitimate objection.
13. International Transfers
Hier will not make a restricted international transfer of Customer Data as Processor unless a lawful transfer mechanism applies.
Where required, this may include:
UK adequacy regulations;
the International Data Transfer Agreement;
an approved UK Addendum;
binding corporate rules; or
another valid mechanism recognised under Applicable Data Protection Law.
Hier may implement additional contractual, organisational or technical safeguards where reasonably appropriate.
Customer authorises international Processing carried out in accordance with this section.
14. Data Subject Rights
Taking account of the nature of the Processing, Hier will provide reasonable assistance to Customer where necessary for Customer to respond to requests relating to:
access;
rectification;
deletion;
restriction;
objection;
portability; and
applicable automated decision rights.
If Hier receives a request relating solely to Customer Data for which Customer is Controller, Hier may direct the requester to Customer unless law requires otherwise.
Customer is responsible for assessing and responding to the request.
Where Hier is independently the Controller of relevant information, Hier will handle the request in its own capacity.
15. Regulatory Assistance and DPIAs
Taking account of the nature of Processing and information available to Hier, Hier will provide reasonable assistance to Customer with obligations relating to:
security;
breach assessment;
Data Protection Impact Assessments;
regulator consultations; and
demonstration of compliance,
where the matter directly concerns Hier's Processing of Customer Data as Processor.
Customer remains responsible for its own compliance decisions.
Hier may charge reasonable fees for substantial assistance that falls outside normal service provision, unless the assistance is required because of Hier's breach.
16. Audits and Compliance Information
Hier will make available information reasonably necessary to demonstrate compliance with its Processor obligations.
Where reasonably necessary and proportionate, Customer may request an audit relating to Hier's Processing of Customer Data.
Audits must:
normally be requested in writing;
provide reasonable notice;
occur no more than once in any 12-month period unless required by a regulator or following a material incident;
avoid unreasonable disruption;
protect the confidentiality and security of other customers;
be carried out by suitably qualified persons; and
comply with reasonable security requirements.
Hier may satisfy audit requests through relevant independent audit reports, certifications, security documentation or questionnaires where these reasonably demonstrate compliance.
Customer bears its own audit costs unless an audit identifies a material breach by Hier.
17. Deletion and Return
Upon termination of services involving Hier acting as Processor, Hier will, at Customer's choice and subject to available Platform functionality:
return relevant Customer Data; or
delete relevant Customer Data,
unless applicable law requires continued retention.
Customer is responsible for exporting information it requires before account closure.
Customer acknowledges that securely deleted information may remain temporarily in backup systems until normal backup rotation occurs.
While retained only in backups, such information will remain protected and will not be actively processed except where necessary for restoration, security or legal compliance.
18. Data Minimisation
Customer must not upload Personal Data that is unnecessary for use of Hier.
In particular, Customer should not upload:
excessive identity documents;
unnecessary financial information;
medical records;
biometric data;
criminal records;
passwords belonging to individuals;
unrelated private communications; or
other high-risk information
unless Hier expressly supports that use and Customer has established the lawful basis and safeguards required.
19. Special Category Personal Data
Hier's standard Business service is not designed to require unnecessary Special Category Personal Data.
If Customer chooses to process Special Category Personal Data using Hier, Customer is responsible for:
identifying an Article 6 lawful basis;
identifying an applicable Article 9 condition;
satisfying any Data Protection Act 2018 requirements;
providing appropriate transparency;
completing any required impact assessment; and
implementing appropriate safeguards.
Customer must not instruct Hier to infer sensitive characteristics about Candidates unless expressly supported by Hier and lawful.
20. Criminal Offence Data
Customer must not use Hier to process criminal conviction or offence information unless:
the Processing is lawful;
an appropriate condition applies;
necessary policies and safeguards are in place; and
the Platform expressly supports the relevant activity.
21. Direct Marketing
Access to Candidate Data through Hier does not constitute consent for unrelated direct marketing.
Customer is responsible for complying with applicable marketing and privacy rules before using Candidate information for marketing purposes.
Candidate data obtained for recruitment must not be repurposed for unrelated advertising merely because Customer has access to the Candidate's email address or telephone number.
22. Customer Security Obligations
Customer must:
protect its Hier credentials;
use appropriate access controls;
restrict access to authorised users;
promptly disable former employees or contractors;
use secure devices;
promptly notify Hier of suspected compromise;
avoid exporting Personal Data unnecessarily; and
maintain appropriate protection for exported information.
Hier is not responsible for an unauthorised disclosure caused solely by Customer failing to secure its own account or systems.
23. Data Accuracy
Each party is responsible for taking reasonable steps to ensure the Personal Data it controls is accurate where required.
Customer must not knowingly maintain materially inaccurate information about a Candidate where that information could adversely affect the Candidate.
Where Hier provides functionality enabling a Candidate to correct their information, Customer should take appropriate account of corrected information where relevant.
24. Retention by Customers
Customer must establish and follow an appropriate retention policy for Candidate Data.
Candidate Data must not be retained indefinitely merely because it was available through Hier.
Customer should consider:
whether recruitment remains active;
legal claims;
statutory requirements;
Candidate expectations;
future-opportunity consent where relevant;
data minimisation; and
security risk.
Where Customer no longer has a lawful reason to retain Candidate Data, it must delete or anonymise it as appropriate.
25. Data Protection Complaints
Each party is responsible for handling data protection complaints concerning Processing for which that party is Controller.
If a complaint principally concerns the other party's Processing, the receiving party may direct the complainant appropriately or cooperate with the other party where lawful.
Nothing in this Addendum prevents an individual from exercising rights against the relevant Controller.
26. Giftcloud and Referral Data
For clarity, where Hier sends Hier-user names and email addresses to Giftcloud Limited solely to fulfil a Hier referral reward:
Hier acts as Controller;
Giftcloud acts as Hier's Processor for the Processing performed on Hier's instructions; and
that Processing is governed by the contractual data-processing arrangements between Hier and Giftcloud.
Giftcloud is not a Customer Subprocessor merely because a Business uses Hier.
Giftcloud may separately act as Controller for information it independently collects or Processes for its own purposes.
27. Liability
Liability under this Addendum is subject to the liability provisions in the Hier Terms of Use or any separately signed agreement between the parties.
Nothing in this Addendum excludes or limits liability where such exclusion or limitation is prohibited by Applicable Data Protection Law.
Each party remains responsible for fines, claims, losses and regulatory action to the extent arising from its own breach of Applicable Data Protection Law.
28. Order of Precedence
If there is a conflict concerning Processing of Personal Data:
any mandatory requirement of Applicable Data Protection Law applies first;
this Addendum applies next;
any separately signed data-processing agreement applies where it expressly supersedes this Addendum;
the applicable Hier Terms apply thereafter.
Schedule 1 — Processor Processing Details
Subject Matter
Provision of the Hier recruitment, recruitment-management, communication and related technology services to Customer.
Duration
For the duration of Customer's use of the relevant Hier services and any limited post-termination period necessary for secure deletion, backup rotation or legal compliance.
Nature of Processing
Processing may include:
collection;
receipt;
recording;
organisation;
structuring;
hosting;
storage;
retrieval;
consultation;
display;
transmission;
matching;
communication;
support;
backup;
security monitoring;
restriction;
export at Customer's instruction;
deletion; and
anonymisation.
Purpose
To provide, secure, maintain and support functionality requested by Customer through the Hier Platform.
Categories of Data Subjects
Depending on Customer's use, Data Subjects may include:
Candidates;
applicants;
prospective Candidates;
employees;
contractors;
Customer staff;
Customer authorised users; and
other individuals whose Personal Data Customer lawfully uploads.
Types of Personal Data
Depending on Customer's use:
names;
email addresses;
telephone numbers;
professional information;
employment history;
education;
qualifications;
skills;
CV information;
application information;
interview information;
recruitment notes;
communication information;
workflow information;
identifiers; and
account-related data.
Special Category Data
Not required for standard use.
May be incidentally processed where included by Customer or a Data Subject, subject to Customer satisfying applicable legal requirements.
Criminal Offence Data
Not intended for standard use unless expressly supported and lawfully processed.
Documented Instructions
Customer's documented instructions consist of:
this Addendum;
the Hier Terms;
Customer's use and configuration of Hier;
requests made through authorised Platform functionality; and
additional lawful instructions agreed in writing.
Schedule 2 — Minimum Security Principles
Hier will maintain security measures proportionate to the risk, which may include:
controlled access to production systems;
authentication mechanisms;
access based on job responsibilities;
confidentiality requirements;
secure communications;
protected data storage;
environment separation where appropriate;
monitoring and logging;
vulnerability and dependency management;
data backup and recovery processes;
incident response;
supplier oversight;
software development controls;
access revocation procedures; and
periodic review of security measures.
Security measures may evolve as technology and risk change, provided the overall level of protection is not materially reduced without reasonable justification.
Schedule 3 — Contact
HIER APPLICATIONS LIMITED
167–169 Great Portland Street
London
England
W1W 5PF
Company Number: 17102004
Email: hello@hierapp.co.uk