Effective Date: 1 November 2025
Version: 1.0
Between:
(1) [Customer legal name], the Controller ("Customer"); and
(2) InterviewRelay by Instantflows B.V., a company incorporated in the Netherlands (KvK: 96160861), with registered office at Willem Hioolenstraat 3, 3065 LE Rotterdam, Netherlands, the Processor ("InterviewRelay", "Processor", "we/us").
This DPA forms part of (and is incorporated into) the agreement governing Customer's use of InterviewRelay services (the "Agreement").
1.1 Roles. For interview content (audio, transcripts, interview responses, and related metadata), Customer is the Controller and InterviewRelay is the Processor. For website, account, billing, security logs, and marketing data, InterviewRelay acts as Controller under its Privacy Policy (outside the scope of this DPA).
1.2 Purpose. InterviewRelay will process Personal Data only to provide the AI‑conducted voice interview platform (real‑time interview execution, transcription, storage, delivery, and related support), and strictly in accordance with Customer's documented instructions and this DPA.
1.3 MVP note. This DPA meets GDPR Article 28 requirements while keeping operational overhead appropriate for a startup MVP; enterprise features (e.g., SOC 2 reports, extended audit exports) may be added later as referenced alternatives.
"Data Protection Laws" means GDPR and applicable UK/EU/EEA Member State data protection laws.
"Personal Data", "processing", "Controller", "Processor", and "Data Subject" have the meanings in GDPR.
"Services" means InterviewRelay's AI voice interview SaaS, APIs, and related support.
"Sub‑processor" means a third party engaged by InterviewRelay to process Personal Data for the Services.
Subject matter: Processing of interview content within the Services.
Duration: Term of the Agreement and retention periods chosen by Customer (see §9).
Nature & Purpose: Real‑time voice interviews, transcription, storage, retrieval, export/webhooks, and translations/localization.
Categories of Data Subjects: Interview participants (candidates/respondents), Customer's staff who configure campaigns.
Types of Personal Data (non‑exhaustive): Participant identifiers (name/email if provided), voice audio recordings, transcripts, responses, timestamps, session/IP/locale metadata, and technical logs tied to sessions. Data model includes invites, sessions, messages, and stored audio/artifacts.
Special categories & biometric data:
Voice recordings constitute biometric data under GDPR Article 9 when used for identification or authentication purposes. Customer MUST NOT use the Services for biometric identification or authentication without:
For general interview purposes (candidate assessment, research, feedback collection), voice recordings may be processed under Article 6 lawful basis (typically consent or legitimate interest), but Customer must ensure their use case does not constitute biometric identification. Customer must not intentionally elicit other special category data (health, beliefs, race, etc.) unless a lawful Article 9 basis exists and is documented.
4.1 Instructions. InterviewRelay shall process Personal Data only on documented instructions from Customer, including regarding transfers to third countries, unless required by law. InterviewRelay will notify Customer if an instruction violates Data Protection Laws (where legally permitted).
4.2 Confidentiality. InterviewRelay ensures personnel with access to Personal Data are bound by confidentiality obligations.
4.3 Security (Article 32). InterviewRelay implements appropriate technical and organizational measures ("TOMs") described in Annex 3 (encryption at rest/in transit; Postgres Row‑Level Security; JWT‑based auth; RBAC; signed URLs; rate limiting; monitoring and audit trails).
4.4 Sub‑processors. Customer authorizes InterviewRelay to use Sub‑processors listed in Annex 2 for infrastructure, AI runtime, email, and payments. InterviewRelay imposes data protection obligations on Sub‑processors equivalent to this DPA and will notify Customer 30 days in advance of material changes to the list, allowing objection for reasonable, documented security grounds.
4.5 Assistance. Taking into account the nature of processing and the MVP stage, InterviewRelay will commercially reasonably assist Customer with:
(a) Data Subject requests (access, deletion, portability, objection, restriction) via product features and exports;
(b) Security, breach notifications, DPIAs, and prior consultations (see Annex 4 for DPIA assistance details);
(c) Consent records (timestamp, IP, policy version) surfaced to Customer.
Reasonable costs may apply for effort beyond self‑serve features.
4.6 Personal Data breach. InterviewRelay will notify Customer without undue delay and within 72 hours of becoming aware of a Personal Data Breach affecting Customer data. Notifications will include:
(a) The nature of the breach (categories of data, approximate number of records/subjects affected);
(b) Name and contact details of InterviewRelay's data protection contact (business@instantflows.com);
(c) Likely consequences of the breach;
(d) Measures taken or proposed to mitigate and remediate the breach;
(e) Updates as further information becomes available.
InterviewRelay will cooperate with Customer's investigation and regulatory reporting obligations.
4.7 Return/Deletion. Upon termination/expiry of the Agreement or upon Customer request, InterviewRelay shall delete or return Personal Data after the applicable retention period, except where law requires storage. Deletes cascade across transcripts, messages, audio files, and related artifacts.
5.1 Lawful basis & notices. Customer is responsible for establishing a lawful basis and providing all required notices to Data Subjects (including disclosure that an AI system conducts the interview). Customer configures scripts to avoid eliciting special category data unless legally permitted and documented.
5.2 Consent. Where required, Customer obtains valid consent; InterviewRelay provides consent capture tooling and stores consent records for evidencing.
5.3 Webhooks & sharing. Customer's configured webhooks/integrations are Customer's own data disclosures; Customer is responsible for securing endpoints and entering required downstream DPAs.
7.1 Data residency. Customer may select EU or US project residency. Where Personal Data is transferred outside the EEA/UK to a country without adequacy, InterviewRelay ensures appropriate safeguards including:
(a) Encryption in transit (TLS 1.2+) and at rest (AES-256);
(b) Strict access controls and authentication requirements;
(c) Contractual restrictions on government access in Sub-processor agreements;
(d) Standard Contractual Clauses (and, where applicable, UK IDTA/UK Addendum).
A Transfer Impact Assessment documenting supplementary measures is available upon request.
7.2 SCCs. The EU SCCs (Commission Implementing Decision (EU) 2021/914) are incorporated by reference and completed as set out in Annex 5 (Module 2: Controller→Processor; docking clause included; NL law/courts). For onward transfers to Sub‑processors, Module 3 applies as appropriate. UK transfers attach the UK Addendum/IDTA as set out in Annex 5.
8.1 Evidence. On written request, InterviewRelay will make available summary security documentation, policy excerpts, and responses to a reasonable security questionnaire. If available, third‑party assessments (e.g., penetration test summaries) may be provided as an alternative to onsite audits.
8.2 Onsite audit. Customer may conduct an onsite audit of relevant processing systems:
(a) Once annually as a matter of routine;
(b) Additional audits following: (i) a Personal Data breach affecting Customer data, (ii) regulatory request or investigation, or (iii) material change to Sub-processors or security measures.
Audits require 30 days' notice (or 5 days for cause), occur during business hours without disrupting operations, and are subject to reasonable confidentiality obligations and reimbursement of InterviewRelay's reasonable costs. Scope is limited to processing of Customer's Personal Data and relevant TOMs.
Default retention is plan‑based and configurable. Indicative defaults:
Product automatically purges sessions and cascades deletions to messages/files once retention elapses. Customer may delete data earlier via dashboard or API. Sub-processor retention: see Annex 2.
InterviewRelay will reasonably assist Customer with Data Protection Impact Assessments (where Customer's use case involves high-risk processing) by providing documentation as detailed in Annex 4. InterviewRelay will cooperate with Customer consultations with supervisory authorities under Article 36 where required.
11.1 GDPR liability. Under GDPR Article 82, each party is liable only for damages caused by its own failure to meet GDPR obligations. InterviewRelay is not liable for damages caused by Customer's instructions or failures.
11.2 Limitation. Subject to mandatory law, total liability under this DPA is limited to the lesser of: (a) amounts paid by Customer in the 12 months preceding the claim, or (b) any limitation set forth in the Agreement. This limitation does not apply to liabilities that cannot be limited under applicable law (e.g., intentional misconduct, gross negligence).
11.3 Notices. Notices under this DPA should be sent to:
Customer: Account owner email on file
InterviewRelay: business@instantflows.com (copy to: privacy@interviewrelay.com)
11.4 Amendments. InterviewRelay may update Annex 2 (Sub‑processors) with prior notice under §4.4. Material changes to other terms require mutual written agreement.
For Customer (Controller)
Name: ____________________ Title: ____________________
Signature: ____________________ Date: ____________________
For InterviewRelay (Processor)
Instantflows B.V. (d/b/a InterviewRelay)
Name: ____________________ Title: ____________________
Signature: ____________________ Date: ____________________
A. Data subjects: Interview participants (candidates/respondents), Customer staff who design or administer interviews.
B. Categories of Personal Data:
C. Processing purposes/operations: collection, recording, storage, retrieval, playback, transcription, translation/localization, structured analysis, secure transmission (dashboard/API/webhooks), export, deletion.
D. Retention: Per §9; automated cleanup (cron) and cascade deletion across messages/files.
E. Data location/residency: EU or US, selectable per project; see Annex 2 for vendor locations.
F. Special categories: Voice recordings constitute biometric data; discouraged for identification/authentication unless explicit Art. 9(2)(a) consent and DPIA completed; Customer must not elicit other Art. 9 data (health, beliefs, etc.) without documented legal basis.
| Sub‑processor | Purpose | Data | Location | Retention | Notes |
|---|---|---|---|---|---|
| Supabase | Database, auth, file storage | All interview content, profile/session data, audio/artifacts | EU/US (customer‑selectable) | Per Customer settings (§9) | Encryption at rest/in transit; RLS |
| OpenAI | Real‑time model for voice interviews; transcription/translation | Audio streams, transcripts, prompts, responses | Primarily US | 30 days (abuse monitoring), then automatic deletion; zero-retention available for enterprise | API data not used for training per OpenAI DPA |
| Stripe | Billing & payments | Billing contact info, payment tokens | Global (EU presence) | Per payment regulations | PCI DSS L1 |
| SendGrid | Email delivery | Invitee emails, invite links | US | Email logs: 30 days | Sender verification; branding |
| ipapi.co | IP geolocation (transient) | IP address | N/A | No retention (lookup only) | Used for geo‑restriction checks |
Change management: InterviewRelay will provide 30 days' prior notice of material changes to this list via email to account owner. Customer may object on reasonable, documented security grounds within 15 days.
When Customer conducts a Data Protection Impact Assessment for high-risk use cases, InterviewRelay will provide upon reasonable request:
Requests should be sent to business@instantflows.com with reasonable advance notice (typically 15 business days).
EU SCCs (2021/914) — incorporated by reference.
UK: The UK Addendum to the EU SCCs (IDTA) is incorporated for UK transfers with the same annex mappings.
Instantflows B.V.
KvK — Kamer van Koophandel: 96160861
Willem Hioolenstraat 3, 3065 LE Rotterdam, Netherlands
Email: business@instantflows.com
Privacy: privacy@interviewrelay.com
Document Version: 1.0 (Production Ready)
Prepared: 23 October 2025
Status: ✅ Ready for legal review and publication