Data processing agreement
Last updated: 25 September 2026
This Data Processing Agreement (DPA) applies whenever Sasha Rec AB (“Sasha”, the processor) processes personal data on behalf of a customer (the controller) through the Sasha service. It forms part of the terms of service, or of a signed Platform Agreement where one exists. Terms not defined here have their GDPR meaning.
- Roles and instructions. The customer is the controller and Sasha the processor. Sasha processes personal data only on the customer’s documented instructions, which include these terms, unless the law requires otherwise. Sasha tells the customer if it believes an instruction breaks data protection law.
- Subject matter, purpose, duration. Providing the Sasha service: drafting role profiles with the customer, conducting AI voice screening interviews with candidates the customer invites, producing evidence-based assessments, and recording the customer’s decisions. For the term of the agreement plus the wind-down in section 12.
- Data subjects. Candidates the customer invites, and the customer’s users.
- Personal data. Candidate name, email, and a hashed PIN; the interview transcript; salary and availability where the candidate volunteers them; the assessment (per-requirement evidence, no score, no verdict); the customer’s decision and reasoning; usage data. Call audio is streamed and never stored. Special-category data (Article 9) should not be submitted; if it is, Sasha minimises its processing and does not assess it.
- Retention. Transcripts, assessments and decisions are deleted automatically after the retention period the customer sets, which cannot be shorter than six months (the log-retention minimum under Article 26(5) of the AI Act) and is two years by default, counted from each call. Candidate name and email stay until the customer deletes the candidate or the account. The customer can delete a candidate, and all data linked to them, at any time in the product.
- Security. Sasha maintains appropriate technical and organisational measures under Article 32: access controls; tenant isolation enforced by database row-level security; encryption in transit; hashed PINs; append-only audit logs for privileged operations; telemetry that excludes prompt and answer content; confidentiality obligations for personnel. Data is stored in the EU.
- Automated decisions. Sasha is configured as a decision-support tool. It produces no scores or verdicts and no decision based solely on automated processing; the customer’s people make and record every hiring decision.
- Sub-processors. The customer authorises Sasha to use the sub-processors listed on the service providers page, under written terms no less protective than this DPA. Sasha remains responsible for them. Sasha may add or replace sub-processors; it announces an intended change before it goes live by updating the service providers page and notifying customers, and the customer may object on reasonable grounds before the change takes effect. If an objection cannot be resolved, the customer may terminate the affected processing. Customers with a signed Platform Agreement or an enterprise plan follow the notice terms of that agreement.
- Transfers. Data storage and Sasha’s servers stay in the EU. AI inference runs on a mix of EU and US infrastructure: Deepgram’s speech services run in the EU, and the language models on Microsoft Azure run in the US by default and may be processed in other Azure regions. Other sub-processors outside the EU/EEA are listed on the service providers page. Enterprise customers who require EU-only processing can get it by special arrangement, at extra cost and possibly without every feature. Each transfer outside the EU/EEA relies on an adequacy decision or the EU Standard Contractual Clauses with supplementary measures where required.
- Assistance. Taking the nature of the processing into account, Sasha helps the customer respond to data-subject requests, including requests for human review and explanation of an assessment, and with security, breach and impact-assessment obligations.
- Breach. Sasha notifies the customer without undue delay, and within 48 hours, after becoming aware of a personal data breach affecting the customer’s data, with the information the customer needs to meet its own obligations.
- Deletion and return. On termination, Sasha deletes the customer’s personal data within 30 days, or returns it first if the customer asks in writing before then, unless the law requires retention. Anonymised and aggregated data may be kept.
- Audit. Sasha provides the information needed to demonstrate compliance with this DPA and allows one audit per year, on reasonable notice, under confidentiality, at the customer’s cost, or more often after a breach.
- Logs. Sasha keeps operational logs of the AI system as the AI Act requires and for as long as it requires.
- Liability. Liability under this DPA follows the liability terms of the agreement it forms part of.
- Contact. privacy@sasharec.ai. Sasha has not appointed a statutory Data Protection Officer; on the current scale none is required under Article 37, and this will be reviewed as the service grows.