Legal

Data Processing Agreement

This DPA forms part of the agreement between AIPL Hire (processor) and the customer (controller) for the processing of personal data through the platform.

Last updated: 6 July 2026

Operated by Ayansh Institute Private Limited

AIPL Hire is a product of Ayansh Institute Private Limited · CIN U85499BR2025PTC080635 · Reg. No. 080635 · ISO 9001:2015 · MCA Registered Company · NSDC Partner

01.Roles of the parties

For candidate and applicant data processed through the platform, the customer is the controller and AIPL Hire is the processor. AIPL Hire processes personal data only on documented instructions from the controller, including as set out in the agreement and this DPA.

02.Definitions

Terms such as “personal data”, “processing”, “controller”, “processor”, and “data subject” have the meanings given in applicable data protection law, including the GDPR where it applies.

03.Scope and purpose of processing

  • Subject matter — provision of the AIPL Hire hiring platform.
  • Duration — the term of the agreement plus any legally required retention.
  • Nature and purpose — screening, interviewing, scoring, and reporting on candidates.
  • Categories of data — identifiers, application materials, interview responses, and recordings.
  • Data subjects — the controller's candidates and applicants.

04.Processor obligations

  • Process personal data only on the controller's documented instructions.
  • Ensure personnel are bound by confidentiality.
  • Implement appropriate technical and organizational security measures.
  • Assist the controller with data subject requests and compliance obligations.

05.Sub-processors

The controller authorizes AIPL Hire to engage sub-processors (for hosting, AI, email, and payments) under written contracts imposing equivalent data protection obligations. We maintain a current list of sub-processors and provide notice of material changes.

06.Security measures

We maintain encryption in transit and at rest, access controls, monitoring, and backup and recovery processes. See our Security page for details.

07.Data subject requests

Taking into account the nature of processing, we assist the controller with appropriate technical and organizational measures to respond to requests from data subjects exercising their rights.

08.Personal data breach

We notify the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, and provide information reasonably needed to meet notification obligations.

09.International transfers

Where personal data is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses.

10.Audits

We make available information necessary to demonstrate compliance and allow for audits, subject to reasonable confidentiality and security conditions.

11.Return and deletion of data

Upon termination, we delete or return personal data at the controller's choice, except where retention is required by law.

12.Contact

To request a signed DPA or ask questions, email privacy@aipl.online.

Questions about this document? Contact support@aipl.online.