← Home

HONE — DATA PROCESSING AGREEMENT

(UK GDPR Article 28 — Customer as Controller, Provider as Processor)

Lives at: https://hone.detecktiv.io/legal/dpa Version 1.1 — effective on publication

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Hone Terms of Service (the "Agreement") between Virtual Data Integration Ltd (trading as "Hone"), company number 16747738, registered office 22 Walbank Grove, Shenley Brook End, Milton Keynes, England, MK5 7WB (the "Provider", "Processor"), and the customer that has entered into the Agreement (the "Customer", "Controller"). Each a "party".

Where the Customer processes personal data of data subjects in the course of using the Services, the parties agree this DPA governs that processing. It is intended to satisfy the requirements of Article 28(3) of the UK GDPR.

1. Definitions

1.1 Terms defined in the Agreement have the same meaning here. In addition:

"Data Protection Laws" means all laws relating to data protection and privacy applicable to the processing under this DPA, including the UK GDPR (as defined in section 3(10) of the Data Protection Act 2018), the Data Protection Act 2018 ("DPA 2018"), and the Privacy and Electronic Communications (EC Directive) Regulations 2003, in each case as amended or replaced.

"UK GDPR", "controller", "processor", "data subject", "personal data", "personal data breach", "processing", "special category data" and "supervisory authority" have the meanings given in the Data Protection Laws.

"Customer Personal Data" means the personal data within the Customer Data that the Provider processes on behalf of the Customer under the Agreement, as described in Annex 1.

"Restricted Transfer" means a transfer of Customer Personal Data to, or access from, a country outside the United Kingdom that is not the subject of UK adequacy regulations.

"Sub-processor" means any processor engaged by the Provider to process Customer Personal Data.

"UK Transfer Mechanism" means the International Data Transfer Agreement issued by the Information Commissioner ("IDTA"), or the EU Standard Contractual Clauses (Commission Decision 2021/914) as supplemented by the ICO's International Data Transfer Addendum ("UK Addendum"), or any other mechanism that lawfully permits a Restricted Transfer.

2. Roles and scope

2.1 The parties acknowledge that, for the Customer Personal Data, the Customer is the controller and the Provider is the processor. Where the Customer is itself a processor acting on behalf of a third-party controller, the Customer warrants that it is authorised to instruct the Provider as a sub-processor and that this DPA reflects the third-party controller's requirements.

2.2 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.

2.3 The Provider processes Customer Personal Data in its own capacity as an independent controller only where required to do so by law, or in respect of limited data it processes as controller for its own business administration (for example account and billing contact details), which is governed by the Provider's Privacy Policy rather than this DPA.

3. Provider (processor) obligations

3.1 The Provider will process Customer Personal Data only:

(a) on the Customer's documented instructions, including as set out in the Agreement, this DPA and the Customer's use and configuration of the Services, and as necessary to provide and support the Services; and

(b) as required by applicable law, in which case the Provider will (unless legally prohibited) inform the Customer of that legal requirement before processing.

3.2 The Provider will immediately inform the Customer if, in its opinion, an instruction infringes the Data Protection Laws (without obligation to give legal advice).

3.3 Confidentiality. The Provider will ensure that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and are trained on their data protection obligations.

3.4 Security. The Provider will implement and maintain the technical and organisational measures set out in Annex 2, appropriate to the risk under Article 32 of the UK GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing (including that the Customer Personal Data may include special category and criminal offence data).

3.5 Assistance with data subject rights. Taking into account the nature of the processing, the Provider will assist the Customer, by appropriate technical and organisational measures and insofar as possible, to fulfil the Customer's obligation to respond to requests to exercise data subject rights (Chapter III UK GDPR). The Services provide in-product tools to support this, including self-service structured export and per-data-subject Subject Access packages that include the underlying CV documents. If the Provider receives a request directly from a data subject relating to Customer Personal Data, it will not respond other than to acknowledge and redirect, and will promptly notify the Customer.

3.6 Assistance with wider obligations. The Provider will assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to the Provider.

3.7 No AI training. The Provider will not use Customer Personal Data, and will contractually require that its AI sub-processors do not use Customer Personal Data, to train, fine-tune or develop AI or machine-learning models. AI sub-processors process Customer Personal Data only to return results for the Customer's requested actions.

4. Personal data breach

4.1 The Provider will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

4.2 The notification will, to the extent known, describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Where the information is not all available at once, it may be provided in phases without undue further delay.

4.3 The Provider will not make any public statement identifying the Customer in relation to a breach without the Customer's prior written consent, unless required by law. Notification of a breach is not an admission of fault or liability.

5. Sub-processors

5.1 The Customer gives general written authorisation for the Provider to engage Sub-processors to process Customer Personal Data. The current Sub-processors are listed in Annex 3 and on the Sub-processors page, which is the authoritative current list.

5.2 The Provider will impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures under Article 28(4) UK GDPR.

5.3 Changes. The Provider will give the Customer prior notice (by updating the Sub-processors page and, where the Customer has subscribed to notifications or has a signed Order Form, by notice) before a new Sub-processor starts processing Customer Personal Data. The Customer may object on reasonable, documented data protection grounds within 14 days of notice. The parties will work in good faith to resolve the objection; if they cannot, the Customer may, as its sole remedy, terminate the affected subscription and receive a pro-rata refund of prepaid Fees for the terminated, unused period.

5.4 The Provider remains liable to the Customer for the performance of each Sub-processor's data protection obligations to the same extent as if performed by the Provider.

6. International transfers

6.1 The Provider will not make a Restricted Transfer of Customer Personal Data (including via a Sub-processor) unless it has put in place an appropriate UK Transfer Mechanism or another lawful basis for the transfer, together with any supplementary measures required following a transfer risk assessment.

6.2 Where the EU SCCs plus UK Addendum are used, they are incorporated by reference and the parties will be treated as having signed them; the relevant details in Annex 1 populate the SCC/IDTA tables. Where a Sub-processor is certified under the UK Extension to the EU–US Data Privacy Framework, that certification may be relied upon for transfers to that Sub-processor.

7. Return and deletion

7.1 On termination or expiry of the Agreement, and following the 30-day post-termination export window described in the Agreement, the Provider will delete Customer Personal Data (including copies) within a further reasonable period, except to the extent retention is required by applicable law.

7.2 The Services provide a workspace deletion path with a 30-day recovery window followed by permanent erasure. Backups containing Customer Personal Data are overwritten on the Provider's routine backup cycle; during that period they are protected by the measures in Annex 2 and are not restored except for disaster recovery.

7.3 On the Customer's written request made within the export window, the Provider will confirm deletion in writing.

8. Audit and information

8.1 The Provider will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 UK GDPR and this DPA, including relevant third-party certifications, penetration-test summaries and its security documentation, where available.

8.2 The Customer may audit compliance no more than once per 12 months (and following a personal data breach affecting the Customer), on at least 30 days' written notice, during business hours, without unreasonably disrupting the Provider's operations and subject to confidentiality. The Provider may satisfy an audit request by providing the documentation in clause 8.1 where that reasonably addresses the Customer's concern. Each party bears its own audit costs.

9. Liability

9.1 Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement, and any reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together.

10. General

10.1 This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, consistent with the Agreement.

10.2 In the event of a conflict between this DPA and the Agreement on the subject of data protection, this DPA prevails. In the event of a conflict between this DPA and the EU SCCs/IDTA, the SCCs/IDTA prevail to the extent of a Restricted Transfer.

10.3 This DPA takes effect on the effective date of the Agreement and continues for as long as the Provider processes Customer Personal Data.


Annex 1 — Details of the processing

ControllerThe Customer (the recruitment agency or other business that has accepted the Agreement)
ProcessorVirtual Data Integration Ltd trading as Hone
Subject matterProvision of the Hone AI recruitment platform (CV ingestion and parsing, natural-language candidate search, shortlisting, outreach, compliance tracking and CRM)
DurationFor the term of the Agreement, plus the post-termination export and deletion periods
Nature and purposeHosting, storage, structuring (AI parsing), searching, organising, transmitting and otherwise processing candidate and related personal data to enable the Customer to carry out its recruitment activities
FrequencyContinuous, for the duration of the Agreement

Categories of data subjects: candidates (job seekers), the Customer's Authorised Users (recruiters/staff), and individuals referenced within CVs or candidate records (e.g. referees).

Types of personal data:

  • Identity and contact details (name, email, phone, address)
  • Employment and education history; qualifications
  • Professional registrations (e.g. NMC, GMC, HCPC) and card schemes (e.g. CSCS)
  • Right-to-work information
  • Free-text CV content (which may include special category data, e.g. health information, under Article 9 UK GDPR)
  • Criminal offence and safeguarding data (DBS / criminal-record / barred-list information) under Article 10 UK GDPR / section 10 and Schedule 1 DPA 2018

Special category / criminal offence data: Yes — see above. The Customer, as controller, is responsible for identifying the applicable Article 9 / Article 10 condition and the corresponding DPA 2018 Schedule 1 condition, and for maintaining any Appropriate Policy Document required.

Annex 2 — Technical and organisational security measures (Article 32)

The Provider maintains the following measures (mirroring the security clause of the Agreement):

  • Row-level security and per-workspace tenancy isolation
  • Least-privilege access controls
  • Multi-factor authentication (available and enforceable)
  • Encryption of personal data in transit (TLS) and at rest
  • Storage of secrets in a dedicated secrets manager (never in source code)
  • Cloudflare edge protection with WAF and bot mitigation
  • Per-workspace AI kill-switch and usage/spend ceilings
  • Routing of all AI-provider calls through a single audited control point
  • Append-only audit-event log covering access, export, deletion and role changes
  • Managed PostgreSQL with automated backups
  • Dependency and secret scanning in the CI pipeline
  • Logical separation of the Hone production database from other Provider systems

These measures are reviewed periodically and may be updated provided the level of protection is not materially reduced.

Annex 3 — Sub-processors

As set out on https://hone.detecktiv.io/legal/sub-processors (authoritative current list), at the date of this DPA:

Sub-processorPurpose
Lovable (Lovable Labs, Inc.)Application hosting, build/deploy and managed cloud layer (provisions Supabase/Cloudflare)
Supabase (via Lovable Cloud)Database, file/object storage and authentication — EU (Ireland)
CloudflareCDN, edge network, DNS, WAF and bot protection
AnthropicAI model provider (CV parsing, natural-language search, generation)
Voyage AIAI embeddings for semantic candidate search
Google (Drive, Gmail, Calendar APIs)User-initiated CV import / optional inbox and calendar connection
StripePayment processing and billing
TwilioSMS delivery to candidates
ResendTransactional and service email
SentryError and performance monitoring
PostHogProduct analytics (consent-gated; EU)
PlausibleCookieless marketing-site analytics (EU)