Data Processing Addendum
Last updated: September 23, 2026
HURA — Aztia LLC (St. Petersburg, Florida, USA)
This Data Processing Addendum ("DPA") forms part of the HURA Terms of Service (the "Terms") between Aztia LLC ("Aztia") and the Client. It applies to Candidate Data that Aztia processes on the Client's behalf in providing the Service. Capitalized terms not defined in this DPA have the meaning given to them in the Terms. In the event of conflict between this DPA and the Terms on matters of personal data protection, this DPA prevails.
1. Definitions
- "Applicable Data Protection Law": all laws on the protection of personal data, in any jurisdiction, that apply to the processing of Candidate Data under the Terms, including the California Consumer Privacy Act, as amended ("CCPA"), and other U.S. state privacy laws.
- "Controller", "processor", "data subject", "personal data", and "processing" have the meanings given in Applicable Data Protection Law; "controller" includes "responsable", "business", and equivalent terms, and "processor" includes "encargado", "service provider", and equivalent terms.
- "Security Incident": a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Candidate Data processed by Aztia or its Subprocessors.
- "Subprocessor": any third party engaged by Aztia to process Candidate Data.
2. Roles and Scope
The Client is the controller of Candidate Data, and Aztia is its processor. The details of the processing are set out in Schedule 1. The Client is responsible for the lawfulness of the processing instructions it gives and for having a legal basis, including any required consent or authorization from Candidates, for the processing described in this DPA.
3. Processing Instructions
Aztia will process Candidate Data only on the Client's documented instructions, which consist of the Terms, this DPA, and the Client's use and configuration of the Service, unless required otherwise by applicable law, in which case Aztia will inform the Client before processing where legally permitted. Aztia will inform the Client if, in its opinion, an instruction infringes Applicable Data Protection Law.
4. Confidentiality of Personnel
Aztia will ensure that persons authorized to process Candidate Data are bound by confidentiality obligations and access Candidate Data only as necessary to provide and support the Service.
5. Security
Aztia will implement and maintain the technical and organizational measures described in Schedule 2, which are appropriate to the risk of the processing. Aztia may update these measures provided that the overall level of protection is not materially reduced.
6. Subprocessors
The Client grants Aztia general authorization to engage Subprocessors. The current list of Subprocessors is set out in Schedule 3 and published at www.huraapp.com/dpa#subprocessors. Aztia will give the Client at least fifteen (15) days' notice, by email to the Administrator or through the Service, before adding or replacing a Subprocessor. If the Client reasonably objects on data protection grounds and the parties cannot resolve the objection, the Client may terminate the affected Plan, and Aztia will refund the unused, pro-rated portion of prepaid Plan fees. Aztia will impose on each Subprocessor data protection obligations substantially equivalent to those in this DPA and remains responsible for their performance.
7. Artificial Intelligence
Aztia will not use Candidate Data to train artificial intelligence models and will engage AI Subprocessors only under terms that prohibit them from using Candidate Data to train their models. Aztia may create and use aggregated or de-identified data, which cannot reasonably be linked to the Client or any individual, to maintain and improve the Service, and will not attempt to re-identify such data.
8. International Transfers
The Client acknowledges that Candidate Data will be processed in the United States and in the other countries where Subprocessors operate, as listed in Schedule 3. For Candidate Data transmitted from Colombia, this DPA constitutes the data transmission agreement (contrato de transmisión) contemplated in Article 2.2.2.25.5.2 of Decree 1074 of 2015; Aztia undertakes to process such data in accordance with the Client's data processing policy and Colombian law, to apply the security measures in this DPA, and to keep such data confidential. Where Applicable Data Protection Law requires an additional transfer mechanism, the parties will execute it upon the Client's request.
9. Data Subject Requests
Taking into account the nature of the processing, Aztia will provide reasonable assistance to the Client, including through the Service's functionality, to respond to requests from data subjects to exercise their rights. If Aztia receives a request directly from a Candidate, it will forward it to the Client without undue delay and will not respond itself except to direct the Candidate to the Client, unless required by law.
10. Security Incidents
Aztia will notify the Client without undue delay, and in any event within seventy-two (72) hours after confirming a Security Incident. The notice will describe, to the extent known, the nature of the Security Incident, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Aztia will provide information reasonably requested by the Client to meet its own notification obligations. Aztia's notification of a Security Incident is not an acknowledgment of fault or liability.
11. Deletion and Return
While the Client's subscription is active, Aztia retains Candidate Data unless the Client deletes it or instructs its deletion earlier. When the subscription is canceled or terminated, Aztia retains Candidate Data for twelve (12) months to allow the Client to reactivate its Account and, if the Account is not reactivated, then deletes or anonymizes it, except as required by law. Backup copies are deleted in their normal rotation cycle, which does not exceed thirty-five (35) days. The Client may at any time instruct earlier deletion, and Aztia will comply within thirty (30) days.
12. Audits and Information
Upon written request, no more than once per year, Aztia will provide the Client with information reasonably necessary to demonstrate compliance with this DPA, including responses to reasonable security questionnaires. On-site audits will be conducted only where required by Applicable Data Protection Law or a competent authority, on reasonable prior notice, during business hours, subject to confidentiality obligations, and at the Client's expense.
13. CCPA Service Provider Terms
To the extent the CCPA applies, Aztia acts as a service provider and will not: (i) sell or share Candidate Data; (ii) retain, use, or disclose Candidate Data for any purpose other than the business purposes specified in the Terms and this DPA, including for any commercial purpose other than providing the Service; (iii) retain, use, or disclose Candidate Data outside the direct business relationship between Aztia and the Client; or (iv) combine Candidate Data with personal data received from or on behalf of other persons, except as permitted by the CCPA. Aztia will comply with the CCPA's obligations applicable to service providers, will notify the Client if it determines it can no longer meet those obligations, and grants the Client the right to take reasonable and appropriate steps to stop and remediate any unauthorized use of Candidate Data. Aztia certifies that it understands and will comply with these restrictions.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms.
15. Term
This DPA remains in effect for as long as Aztia processes Candidate Data on behalf of the Client and terminates automatically thereafter.
Schedule 1 — Details of Processing
Subject matter and nature: hosting, generation, delivery, and AI-assisted grading of Assessments, and production of comparative analyses and reports for the Client.
Duration: the term of the subscription, plus the retention period after cancellation set out in Section 11.
Purpose: to provide the Service to the Client in support of the Client's hiring process.
Categories of data subjects: Candidates invited by the Client.
Categories of personal data: name, email address, Submissions (code, text, files), interview transcripts where applicable, audio or video recordings of live interviews, if enabled, AI-generated scores and feedback, and technical session metadata (IP address, device type, timestamps).
Sensitive data: none intended. The Client must not submit, or require Candidates to submit, sensitive data through the Service.
Schedule 2 — Security Measures
- Encryption of data in transit using TLS.
- Role-based access controls and least-privilege access to production systems.
- Logging and monitoring of the infrastructure.
- Logical separation of each Client's data within the Service.
- Confidentiality obligations for all personnel with access to Candidate Data.
- Multi-factor authentication for administrative access to production systems.
Schedule 3 — Subprocessors
- Google LLC (Google Cloud Platform), hosting of the platform and databases, United States / Iowa.
- Anthropic, PBC — AI generation and grading of Assessments — United States.
- OpenAI, L.L.C.— AI generation and grading of Assessments — United States.