Version: 2026.2 · Effective Date: 21 AUGUST 2026
This Privacy & Data Policy ("Policy") sets out how Exenai Limited ("Exenai", "we", "our") collects, uses, stores, and protects personal data in the course of providing our services. It also includes our role as a data processor for our customers, and our compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable laws. This Policy forms part of the contractual agreement between Exenai and our customers and should be read in conjunction with the Master Services Agreement. The Data Processing Addendum referred to in the Master Services Agreement is set out in Annex 1 to this Policy.
1. Scope
This Policy applies to:
All personal data we collect from users, customers, or visitors through our website, applications, platforms, or in the course of our business activities;
Personal data processed on behalf of our customers as part of providing services including the Exenai Platform, Candidate Experience Platform, Exenai Connect (including the Connect App Host), and Automation-as-a-Service offerings.
This Policy applies to Exenai as both a data controller (when we collect personal data for our own purposes, e.g. website analytics, support contact) and a data processor (when we process personal data on behalf of our customers, e.g. candidate records, CRM data, or data transiting the Exenai Connect gateway).
2. Definitions
"Personal data" means any information that relates to an identified or identifiable individual. "Customer Data" means the data input, uploaded, or shared by our customers or their users, including Community Users (e.g. candidates and client representatives). "Services" refers to our software, platforms, APIs, applications, integrations, portals, support, and any associated professional or automation services provided to customers. "Community Users" means individuals who are authorised by our customers to access Exenai portals or interfaces, including candidates, clients, or other CRM-related users.
"AI Client" means a third-party AI application or model interface (e.g. Claude, ChatGPT, Microsoft Copilot) connected to send requests through Exenai Connect. An AI Client may be connected by a customer, in which case it is the customer's own tool and not part of our Services, or by Exenai, as described in Section 3.2. "Exenai AI Features" means AI functionality we provide within our Services using Model Providers, such as AI-generated summaries of candidate experience. "Model Providers" means the third-party large language model providers whose APIs we use to deliver Exenai AI Features, as listed in the Subprocessor List (Schedule A). "Usage Data" means logs, telemetry, and metadata generated by the use and operation of our Services, including audit log records and request metadata.
"Data Protection Law" means UK GDPR, the Data Protection Act 2018, and any applicable privacy regulations in the jurisdictions where we operate. "Processor", "Controller", "Data Subject", "Supervisory Authority" and other relevant terms shall have the meanings given in UK GDPR.
3. How We Process Personal Data
3.1 As a Data Controller
We collect and process personal data for our own legitimate business purposes, including: managing customer accounts and subscriptions; responding to support enquiries or demo requests; sending updates about our services and policies; monitoring website usage and improving user experience; and maintaining system security and preventing fraud.
The legal bases for processing include: performance of a contract (e.g. user registration and account access); legitimate interests (e.g. business analytics, service improvement); legal obligation (e.g. complying with regulatory or tax requirements); and consent, where required for marketing or cookies (see Section 10).
3.2 As a Data Processor
When our customers use our services, they may upload or input personal data (e.g. candidate records, CRM or ATS data) into the Exenai Platform. In such cases the customer acts as the controller and Exenai acts as the processor, processing such data strictly on the customer's written instructions.
We process Customer Data to:
Provide and operate the Exenai Platform, including Community User portals;
Support user access, permissions, and record updates;
Enable automation, analytics, and integrations with other systems;
Operate the Exenai Connect gateway, including evaluating requests against the customer's configured policy controls (allow-listing, interception, rate and cost caps, approvals) and maintaining audit log records of requests and actions;
Deliver Exenai AI Features (see Section 11);
Serve customer-created applications and dashboards on the Connect App Host with the customer's configured authentication and permissions;
Build, configure, support and troubleshoot applications, dashboards, reports and automations for the customer, including where we do so using an AI Client we operate;
Maintain backups, monitor performance, and ensure data integrity.
Where a customer connects its own AI Client through Exenai Connect, our processing is limited to the gateway itself: transporting the request, applying the customer's configured controls, and recording the audit log. Once data has passed through the gateway to the customer's AI Client, it is processed by that provider under the customer's own agreement with them; the customer is responsible for its arrangements with its AI Client providers.
Where Exenai connects its own AI Client through Exenai Connect in order to build, configure, support or troubleshoot for a customer, our processing is not limited to the gateway. In that case we are directing the processing and the AI Client provider is one of our subprocessors, listed in Schedule A. Most work of this kind is carried out by customers themselves using their own AI Client; we do it on request. Because Exenai Connect provides a live view of connected systems, this work is carried out against live Customer Data rather than a copy. It is confined to what is necessary for the task, subject to the customer's configured permissions and policy controls, and recorded in the customer's audit log. We maintain our AI Client subscriptions with model training disabled.
Where we act as a processor, we do not: access or use Customer Data for our own purposes; share Customer Data with third parties, except as necessary for service provision and under contractual safeguards; or retain Customer Data beyond the term of service (see Section 8: Retention).
4. Categories of Personal Data
4.1 Data We Collect as Controller
Contact details: name, job title, company, email address, phone number
Account information: usernames, access logs, support tickets
Marketing preferences and communication history
Website usage data (e.g. IP address, browser, device type, location data)
Financial and billing details (e.g. invoicing contact, bank/payment information)
4.2 Data Processed on Behalf of Customers (as Processor)
Candidate data: CV/resume, contact details, work history, interview notes
Client contact data: names, emails, communication history, job order details
CRM data: status, tags, notes, compliance documentation, and interaction logs
Community User portal activity: login timestamps, form submissions, data updates
Exenai Connect gateway data: prompts and responses in transit, request metadata, and audit log records (user or agent identity, action, timestamp, outcome)
Optional integrations: LinkedIn data, job board interactions, or third-party service data (as configured by the customer)
We do not intentionally collect or process special categories of personal data (e.g. health, political views, biometric data) unless explicitly instructed by the customer and subject to appropriate safeguards under the customer's responsibility.
5. Data Sharing and Subprocessors
We do not sell personal data. However, we may share personal data with third parties as follows:
5.1 Subprocessors and Service Providers
We use trusted third-party providers (subprocessors) to help us deliver and support our services. These include providers of: hosting infrastructure (e.g. Hetzner, Microsoft Azure); platform software licensed to us and operated by us (e.g. Tocalabs); large language model APIs used to deliver Exenai AI Features, and the AI Client we operate through Exenai Connect (our Model Providers — see below); communication, email and messaging platforms; analytics, monitoring, and security tools; identity and access management systems; and integrations, plug-ins, and automation services.
Model Providers. Exenai AI Features are delivered using large language model APIs drawn from a pool of providers currently comprising OpenAI, Google (Gemini API), and Anthropic (Claude API). We select, combine, and may change the Model Provider used for any given feature at our discretion and do not publish a per-feature mapping. Customer data processed by Model Providers is not used to train any public models; processing is limited to instance-based API processing to deliver the relevant feature. The same applies to the AI Client we operate through Exenai Connect.
For clarity: a customer's own AI Client (e.g. its Claude, ChatGPT, or Copilot subscription connected through Exenai Connect) is not an Exenai subprocessor. The customer's agreement with its AI Client provider governs that processing. An AI Client operated by Exenai is a different case and is treated as a subprocessor, as described in Section 3.2.
Data residency. Customer environments are provisioned in the region matching the customer. Data belonging to EU and UK customers is hosted in the EU and the UK. Data belonging to US customers is hosted in the United States. A customer's environment is not moved between regions without agreement.
Each subprocessor is contractually bound to only process data in accordance with Exenai's written instructions, and subject to appropriate confidentiality, security, and data protection obligations. A current list of subprocessors is provided in Schedule A to this Privacy & Data Policy and is also available upon request. We will provide notice of changes to our subprocessors (including changes within the Model Provider pool) in accordance with our agreements with customers, and customers may object on reasonable data protection grounds in accordance with the Master Services Agreement and Section A5.5 of Annex 1.
5.2 Legal and Regulatory Disclosures
We may disclose personal data to courts, regulators, law enforcement, or other authorities: when required by applicable law or regulation; to comply with legal process or respond to valid requests; or to enforce our legal rights or investigate potential violations of our terms.
5.3 Business Transfers
If we are involved in a merger, acquisition, restructuring or sale of assets, personal data may be transferred as part of that transaction, subject to confidentiality and continued protection under this Policy.
6. Security Measures
We are committed to protecting the confidentiality, integrity, and availability of personal data. We implement appropriate technical and organisational measures, including: data encryption in transit and at rest; role-based access controls and user authentication; regular vulnerability scans and security patching; independent security audits and penetration testing; use of secure, certified data centres; and staff training and internal access governance.
Access to personal data is strictly limited to authorised personnel and subprocessors with a legitimate operational need. All access is logged and monitored for suspicious activity. Where required under applicable law, we will notify customers of any personal data breach without undue delay, and in accordance with Section A7 of Annex 1. A fuller description of these measures is set out in Appendix 2 to Annex 1.
7. International Data Transfers
We may process and store personal data outside of the country in which it was collected, including outside the UK or European Economic Area (EEA), particularly when using trusted hosting providers or subprocessors. In particular, delivery of Exenai AI Features may involve the transfer of personal data to Model Providers processing in the United States, and outbound messaging involves transfer to our messaging provider in the United States. Customer environments themselves are provisioned by region, as described in Section 5.1 and Section A10 of Annex 1.
Whenever we transfer personal data internationally, we ensure that appropriate safeguards are in place in compliance with Data Protection Law, such as: transfers to countries deemed to have adequate protection by the UK government or European Commission; use of Standard Contractual Clauses (SCCs) approved by the UK ICO or EU Commission, or the UK International Data Transfer Agreement or Addendum, or the Swiss addendum to the EU SCCs where Swiss law applies; reliance on the UK–US Data Bridge / EU–US Data Privacy Framework where the recipient is certified; and additional contractual, technical, or organisational measures as necessary. Details of specific international transfers and the safeguards applied can be requested via Section 12.
8. Data Retention
8.1 Data We Control
Data collected by Exenai as a controller (e.g. contact, account, billing, or support data) is retained: for the duration of the customer relationship; for up to 7 years thereafter, where required for legal, regulatory, or contractual reasons; or until a valid request for erasure is received, subject to our legal obligations.
8.2 Customer Data (Processed on Behalf of Customers)
Where we act as a processor, we retain Customer Data: only for the duration of the agreement with the customer; for up to 60 days following termination, to allow for secure export and recovery (unless otherwise agreed) — this window also applies to audit log records and customer-created application definitions; after which, Customer Data is securely deleted from all systems and backups. Prompts and responses transiting the Exenai Connect gateway are retained only as reflected in audit log records and operational logs, in accordance with the retention settings described in our documentation. Retention periods may vary depending on the nature of the data and our contractual commitments to customers.
9. Data Subject Rights
We respect the rights of individuals over their personal data. Where we act as a controller, individuals may exercise the following rights under UK GDPR: access; rectification — to correct inaccurate or incomplete data, including AI-generated content about them such as candidate experience summaries (see Section 11); erasure; restriction; objection; and portability.
Requests may be submitted to privacy@exenai.com or using our contact details in Section 12. We will respond within the timeframes required by applicable law. Where we act as a processor, data subjects should direct their requests to the relevant customer (the data controller). Exenai will support its customers in responding to such requests as required under our agreement and applicable law, and as set out in Section A6 of Annex 1.
10. Cookies and Website Tracking
We use cookies and similar tracking technologies on our websites and applications to improve user experience, analyse site traffic, and deliver relevant marketing. We use: essential cookies (core website functionality); analytics cookies (e.g. Google Analytics and the analytics built into our website platform; we also use Plausible, which is cookieless and does not store raw IP addresses or generate persistent identifiers); functionality cookies (saved preferences); and marketing cookies (targeted advertising, including through our CRM and marketing platform). Where required by law, we seek user consent before placing non-essential cookies. Users can manage or withdraw consent at any time using our cookie consent tool or browser settings. We honour Do Not Track signals where technically feasible. More detailed information is available in our Cookie Policy.
11. AI Usage and Automated Processing
Some of our Services include features powered by artificial intelligence (AI), and our Exenai Connect product provides a governed gateway through which customers connect their own AI tools to their systems. This section explains both.
11.1 Exenai AI Features (AI we provide)
Exenai AI Features are AI capabilities we build into our Services — for example, AI-generated summaries of a candidate's experience within the Candidate Experience Platform. These features are delivered using our Model Providers (see Section 5.1). Our commitments:
Customer data is not used to train any public models. Processing by Model Providers is limited to instance-based API processing to deliver the feature;
AI-generated content (including candidate summaries) is produced by statistical inference and may contain errors or omissions. It is an aid to human assessment, not a substitute for it;
Customers are responsible for reviewing and validating AI-generated content before using it in any hiring, outreach, or business decision;
Where an individual (such as a candidate) believes AI-generated content about them is inaccurate, it can be corrected or regenerated — individuals should contact the customer (controller) who manages their data, or us at privacy@exenai.com where we are the controller;
Any training, tuning or fine-tuning of Exenai's own models is limited to anonymised and aggregated data where legally permissible.
11.2 Exenai Connect (AI tools our customers bring)
Where a customer connects its own AI Client through Exenai Connect, we operate the governed gateway: enforcing the customer's configured controls and recording audit logs. The AI Client itself is the customer's tool, governed by the customer's own agreement with that provider. Exenai Connect is designed to support responsible AI use, including policy controls that can block bulk data extraction, require human approval for consequential actions, and prevent AI-driven automated decision-making about individuals.
11.3 AI Clients we operate
Where we connect our own AI Client through Exenai Connect to build, configure, support or troubleshoot for a customer, the commitments in Section 11.1 apply equally, the AI Client provider is a subprocessor, and the work is confined to what is necessary for the task and recorded in the customer's audit log. See Section 3.2 and Section A11.7 of Annex 1.
11.4 Automated Decision-Making
Customers must not use Exenai's Services to make solely automated decisions that produce legal or similarly significant effects on individuals unless compliant with Article 22 of UK GDPR or equivalent laws. Our Services are designed on the principle that AI outputs inform human decisions — in recruitment contexts, a human decides. Customers remain responsible for their use of AI features and AI Clients within our platform and must ensure that such use complies with applicable laws (including the EU AI Act where applicable), ethics, and fairness obligations.
12. Contact and Complaints
If you have any questions about this Privacy & Data Policy, or if you would like to make a request or raise a concern about how your data is being handled, you can contact us at: Email: privacy@exenai.com · Post: Data Protection Officer, Exenai Limited, 167–169 Great Portland Street, London, W1W 5PF, United Kingdom.
We aim to respond to all requests within the timeframes required by law. If you are not satisfied with our response or believe that your data has not been processed in accordance with applicable data protection laws, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the UK or your local supervisory authority.
ANNEX 1: DATA PROCESSING ADDENDUM
A1. Status and scope
A1.1 This Annex is the Data Processing Addendum ("DPA") referred to in the Exenai Master Services Agreement. It forms part of this Privacy & Data Policy and, through it, part of the agreement between Exenai Limited ("Exenai") and the customer ("Customer").
A1.2 This DPA applies where Exenai processes personal data on behalf of the Customer in the course of providing the Services. In that processing the Customer is the controller and Exenai is the processor. Where Exenai processes personal data for its own purposes, as described in Section 3.1, Exenai is the controller and this DPA does not apply.
A1.3 This DPA is written to meet the requirements of Article 28 of the UK GDPR and the EU GDPR, the Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), and the California Consumer Privacy Act as amended by the California Privacy Rights Act, in each case to the extent applicable to the processing.
A1.4 Where this DPA conflicts with the body of this Policy, this DPA prevails in respect of processing carried out by Exenai as processor. Where it conflicts with the Master Services Agreement, the Master Services Agreement prevails except on matters of data protection, where this DPA prevails.
A1.5 No separate signature is required. This DPA takes effect on the effective date of the Customer's Order Form and continues for as long as Exenai processes personal data on the Customer's behalf. Exenai will provide a separately executed copy on request.
A2. Processing on documented instructions
A2.1 Exenai processes personal data only on the Customer's documented instructions, including in relation to transfers to a third country, unless required to do otherwise by law to which Exenai is subject. Where such a legal requirement applies, Exenai will inform the Customer before processing unless the law prohibits it on important grounds of public interest.
A2.2 The Order Form, this Policy, the Master Services Agreement, the Customer's configuration of the Services, and the Customer's use of the Services together constitute the Customer's documented instructions.
A2.3 Exenai will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
A2.4 The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Appendix 1.
A3. Confidentiality
A3.1 Exenai ensures that persons authorised to process personal data are bound by confidentiality obligations, whether contractual or statutory, and are subject to appropriate training and access governance.
A3.2 Access to personal data is limited to personnel with a legitimate operational need, and all access is logged and monitored, as described in Section 6.
A4. Security
A4.1 Exenai implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing.
A4.2 Those measures are described in Section 6 and set out in Appendix 2.
A4.3 Exenai regularly tests, assesses and evaluates the effectiveness of those measures. Exenai may change specific measures provided the overall level of security is not reduced.
A5. Sub-processors
A5.1 The Customer grants Exenai general written authorisation to engage sub-processors to process personal data on the Customer's behalf, subject to this Section A5.
A5.2 The current list of sub-processors is published at exenai.com/legal/subprocessor-list and forms Schedule A to this Policy.
A5.3 Exenai imposes on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
A5.4 Exenai will give the Customer at least 30 days' notice before adding or replacing a sub-processor. Notice is given by updating the published sub-processor list and notifying the Customer's registered contact.
A5.5 The Customer may object to a proposed change on reasonable data protection grounds within that 30 day period. Exenai and the Customer will discuss the objection in good faith. If it cannot be resolved, and Exenai is unable to provide the affected Service without the sub-processor, the Customer may terminate the affected Service on written notice without penalty, with a pro rata refund of any prepaid fees for the unused period.
A5.6 A Customer's own AI Client connected through Exenai Connect is not an Exenai sub-processor. Processing by that provider is governed by the Customer's own agreement with it.
A5.7 Where Exenai connects its own AI Client through Exenai Connect in order to build, configure, support or troubleshoot applications, dashboards, reports or automations for the Customer, Exenai directs that processing and the AI Client provider is an Exenai sub-processor, listed in the published sub-processor list. Such work is carried out under the Customer's instructions, within the Customer's configured permissions and policy controls, and is recorded in the Customer's audit log.
A6. Assisting the Customer
A6.1 Data subject rights. Taking account of the nature of the processing, Exenai will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise data subject rights. Where Exenai receives such a request directly, it will not respond to it other than to acknowledge receipt, and will inform the Customer without undue delay.
A6.2 Wider obligations. Exenai will assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR, taking into account the nature of the processing and the information available to Exenai. This includes reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority.
A7. Personal data breach
A7.1 Exenai will notify the Customer without undue delay, and in any event within 48 hours of becoming aware, of a personal data breach affecting personal data processed on the Customer's behalf. For these purposes Exenai becomes aware when a member of its personnel has a reasonable degree of certainty that a security incident has occurred that led to personal data being compromised. Initial detection of an anomaly, alert or suspected incident does not by itself constitute awareness, and Exenai may take a short and reasonable period to establish whether a breach has in fact occurred.
A7.2 The notification will describe, to the extent known at the time and updated as further information becomes available: the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and to mitigate its effects; and a contact point for further information.
A7.3 Exenai will take reasonable steps to investigate and mitigate the breach, and will cooperate with the Customer in the Customer's own notification obligations to supervisory authorities and data subjects.
A7.4 Notification under this Section is not an acknowledgement of fault or liability.
A8. Return or deletion
A8.1 On termination or expiry of the agreement, Exenai will, at the Customer's choice, return the personal data to the Customer or securely delete it, and delete existing copies, unless retention is required by law.
A8.2 The Customer has 60 days from termination to export data and to make its choice, as described in Section 8.2. If the Customer has made no election by the end of that period, Exenai will securely delete the data.
A8.3 Data held in backups is deleted on the ordinary backup expiry cycle. Until deleted it remains protected by the measures in Appendix 2 and is not accessed for any purpose.
A9. Audit and information
A9.1 Exenai will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA.
A9.2 In the first instance Exenai will satisfy a request under A9.1 by providing its current security documentation, third-party audit reports, penetration test summaries and certifications, subject to confidentiality obligations.
A9.3 Where that documentation is not sufficient to demonstrate compliance, the Customer may, on at least 30 days' written notice and no more than once in any 12 month period, conduct an audit of Exenai's processing. The Customer may appoint an independent third-party auditor, who must not be a competitor of Exenai and must be bound by confidentiality.
A9.4 Audits take place during business hours, must not unreasonably disrupt Exenai's operations, and are limited to systems and records relevant to the processing of the Customer's personal data. Exenai will not be required to disclose information relating to other customers or information subject to legal privilege.
A9.5 The Customer bears its own costs and Exenai's reasonable costs of an audit under A9.3, except where the audit reveals a material breach of this DPA, in which case Exenai bears its own costs.
A9.6 The frequency limit in A9.3 does not apply where an audit is required by a supervisory authority or follows a confirmed personal data breach affecting the Customer's personal data.
A10. International transfers
A10.1 Customer environments are provisioned in the region matching the Customer. Personal data belonging to a Customer established in the United Kingdom or the European Economic Area is hosted within the United Kingdom or the EEA and is not moved to another region without the Customer's agreement. Personal data belonging to a Customer established in the United States is hosted in the United States.
A10.2 Exenai will not transfer personal data that is subject to UK or EU Data Protection Law outside the United Kingdom or the European Economic Area unless an appropriate safeguard under that law is in place. Transfers to Model Providers, and to our messaging provider for outbound email, are the transfers that arise in practice.
A10.3 Safeguards relied on include: transfer to a country subject to a UK adequacy regulation or an EU adequacy decision; the EU Standard Contractual Clauses; the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; the Swiss addendum to the EU Standard Contractual Clauses where Swiss law applies; and the UK-US Data Bridge or EU-US Data Privacy Framework where the recipient is certified.
A10.4 The Customer authorises Exenai to enter into the transfer mechanisms in A10.3 with sub-processors on the Customer's behalf.
A10.5 Where the Customer requires them, Exenai will enter into the Standard Contractual Clauses directly with the Customer. In that case Module Two (controller to processor) applies, the governing law and forum are those of England and Wales for UK transfers and of Ireland for EU transfers, the optional docking clause applies, and the appendices are completed by Appendix 1 and Appendix 2 of this DPA.
A11. Artificial intelligence
A11.1 No training on Customer personal data. Exenai does not use personal data processed on the Customer's behalf to train, tune or fine-tune any model, and its Model Providers do not use it to train any public model. This applies equally where personal data is processed through an AI Client operated by Exenai under A5.7, and Exenai maintains its AI Client subscriptions with model training disabled. Processing by Model Providers is limited to instance-based API processing to deliver the relevant feature. Training of Exenai's own models uses only anonymised and aggregated data where legally permissible.
A11.2 No solely automated decisions. Exenai AI Features are designed to inform human assessment. Exenai does not make, and its Services are not designed to make, decisions producing legal or similarly significant effects on individuals without human involvement. The Customer is responsible for ensuring meaningful human review, as set out in Section 11.4.
A11.3 Purpose limitation. Exenai uses AI models only for the purposes identified in this Policy and the Master Services Agreement. Any materially new use of AI affecting the Customer's personal data requires prior notice to the Customer.
A11.4 Explainability. Exenai will provide reasonable assistance to the Customer in explaining to a data subject the logic and outputs of Exenai AI Features applied to that data subject's personal data.
A11.5 Accuracy. Where AI-generated content about an individual is inaccurate, it can be corrected or regenerated, as described in Section 11.1.
A11.6 Gateway processing. Where the Customer connects its own AI Client through Exenai Connect, Exenai's processing is limited to transporting the request, applying the Customer's configured controls, and recording the audit log, as described in Section 3.2.
A11.7 Exenai's own use of an AI Client. Where Exenai connects its own AI Client to build, configure, support or troubleshoot for the Customer, as described in A5.7, Exenai's processing is not limited to the gateway. Because Exenai Connect provides a live view of the Customer's connected systems, this work is carried out against live Customer Data rather than a copy. It is confined to what is necessary for the task, remains subject to the Customer's configured permissions and policy controls, is recorded in the Customer's audit log, and is subject to the commitments in A11.1 to A11.5.
A12. Liability and term
A12.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Master Services Agreement.
A12.2 This DPA takes effect on the effective date of the Order Form and terminates automatically when Exenai ceases to process personal data on the Customer's behalf, save that Sections A8 and A9 survive termination.
A12.3 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, without prejudice to any mandatory jurisdiction under Data Protection Law or to A10.5.
APPENDIX 1: DETAILS OF THE PROCESSING
Controller. The Customer identified in the Order Form.
Processor. Exenai Limited, 167–169 Great Portland Street, London, W1W 5PF, United Kingdom. Registered in England and Wales, company number 14571809.
Subject matter. Provision of the Services described in the Order Form, comprising the Exenai Platform, the Candidate Experience Platform, Exenai Connect including the Connect App Host, and Automation as a Service.
Duration. For the term of the agreement, plus the retention window in Section 8.2.
Frequency. Continuous, for the duration of the agreement.
Nature and purpose of the processing.
Hosting, storage, backup and transmission of Customer Data
Creating, reading, updating and synchronising records in the Customer's connected ATS, CRM and other systems
Parsing CVs and application materials and mapping the extracted data onto the Customer's taxonomies
Generating AI summaries of candidate experience where the Customer uses that feature
Operating the Exenai Connect gateway: evaluating requests against the Customer's configured policy controls, transporting requests and responses, and recording audit log entries
Serving customer-created applications and dashboards on the Connect App Host under the Customer's configured authentication and permissions
Building, configuring, supporting and troubleshooting applications, dashboards, reports and automations for the Customer, including where Exenai does so using its own AI Client connected through Exenai Connect
Operating automations configured for the Customer, including scheduled and event-driven processing
Providing Community User portals, including candidate and client interfaces
Support, monitoring, performance management and data integrity
Categories of data subjects.
Candidates and applicants of the Customer
Client and prospect contacts of the Customer
The Customer's own personnel and authorised users
Community Users authorised by the Customer, including candidates and client representatives
Referees, emergency contacts and other third parties whose data the Customer records
Types of personal data. As set out in Section 4.2, comprising in particular:
Identity and contact data: name, email address, telephone number, postal address, LinkedIn or other profile URL
Candidate data: CV or resume content, work history, education, qualifications, certifications, skills, languages, salary and availability, interview notes
Where the Customer records them: date of birth, nationality and sex
Client contact data: name, role, employer, communication history, job order details
CRM and workflow data: status, tags, notes, compliance documentation, interaction logs
Portal activity: login timestamps, form submissions, record updates
Exenai Connect gateway data: prompts and responses in transit, request metadata, and audit log records comprising user or agent identity, action, timestamp and outcome
AI-generated content about a data subject, including candidate experience summaries
Special categories of personal data. Exenai does not intentionally process special category data. Where the Customer configures the Services to record such data, the Customer is responsible for establishing a lawful basis and an Article 9 condition, and for applying appropriate safeguards. The Acceptable Use Policy prohibits using prompts, Agents or applications to infer, derive or surface special category data or protected characteristics.
Criminal offence data. Processed only where the Customer records it as part of its own compliance or vetting processes, on the same basis as the paragraph above.
APPENDIX 2: TECHNICAL AND ORGANISATIONAL MEASURES
Measures in force as at the effective date of this Policy. Exenai may vary specific measures provided the overall level of security is not reduced.
Encryption. Personal data encrypted in transit using TLS. Personal data encrypted at rest. Encryption keys managed separately from the data they protect.
Access control. Role-based access control and least privilege. Individual named accounts, no shared credentials. Multi-factor authentication on administrative access. Access reviewed periodically and revoked promptly on role change or leaving. Customer-configurable role-based permissions within the Services.
Segregation. Customer environments logically separated. Automation environments provisioned per customer. Production separated from development and test environments; personal data is not used in development or test.
Resilience and availability. Regular automated backups. Restore procedures tested. Monitoring and alerting on availability and integrity.
Vulnerability management. Regular vulnerability scanning. Security patching of infrastructure and dependencies. Independent penetration testing.
Logging and monitoring. Access to personal data logged and monitored. Full queryable audit log of requests and actions through the Exenai Connect gateway. Alerting on anomalous activity.
Governance. Staff confidentiality obligations and data protection training. Documented incident response procedure. Sub-processor due diligence and contractual data protection terms. Certified data centres.
Deletion. Documented secure deletion procedure covering primary systems and backups. Deletion on the timescales in Section 8.
SCHEDULE A: SUB-PROCESSORS
Schedule A is the sub-processor list published at exenai.com/legal/subprocessor-list. It is not reproduced here, so that there is one list to maintain rather than two. Changes to it are notified under Section A5.4 and may be objected to under Section A5.5.
