Legal
Legal, privacy and compliance, in plain English
Plain-English explanations of the Surhires agreement, privacy position, data processing addendum, subprocessor register, cookies and compliance postures. None of them is legal advice or an assertion of certification.
Agreements and data handling
What you sign, what we do with the data you hold in the product, and who else touches it.
The terms you are agreeing to, written out in ordinary language
This page walks through what the Surhires customer agreement actually says, in ordinary language, so you know its shape before your counsel reads the executed copy.
Read moreTwo sets of people, two different roles, one privacy position
Recruitment software processes personal data about the people who log in and about the candidates they hold, and those two things sit under completely different roles.
Read moreWhat the processor agreement commits us to, clause by clause
A data processing addendum is the document that says what a vendor may do with your candidate data, and this walks through each commitment it makes in ordinary language.
Read moreThe subprocessor register, and why recruitment needs one
Recruitment software sends candidate text to other companies to do its job, and a buyer is entitled to know which categories of company those are before signing.
Read moreWhat is stored in your browser, and what you can switch off
The marketing site and the signed-in application store different things for different reasons, and only one of them asks for your consent before doing it.
Read moreWhere Surhires stands on accessibility, stated honestly
A candidate blocked by an inaccessible application form does not get another route into the job, which is why those screens come first and why the work is never quite finished.
Read more
Compliance explainers
What the product supports under each regime, and what remains your obligation as the employer or sender.
The compliance matrix, walked posture by posture
Procurement wants to know who is responsible for what, so every regime here carries an explicit posture rather than a reassuring sentence that answers nothing.
Read moreHolding candidate data lawfully under UK and EU GDPR
Most candidates in a recruitment database never applied for anything, which is exactly why lawful basis, transparency and retention are harder here than in other software.
Read moreWhat California consumers can ask of a recruitment database
California treats job applicants as consumers with rights over their records, and a recruitment database is exactly the kind of collection those rights were written for.
Read moreNotice, consent and purpose limits under India's DPDP Act
India's data protection law is built around notice and consent, which lands directly on a recruitment database full of people who were never asked.
Read moreControls that support your equal-opportunity obligations
Data collected to measure a hiring decision must never be visible to the people making it, and that is an architecture question before it is a policy question.
Read moreWhat the product supports, and what the sender still owns
US calling and messaging rules land on the sender, not on the software, so the useful question is which controls exist and which decisions stay with your desk.
Read more