Controller and processor
You decide why applicants' data is processed; we process it only on your instructions.
This agreement is part of the Erioun for Teams terms and applies to every hiring workspace automatically — there is nothing to sign to be covered. It says what we do with the applicant data your workspace holds, on whose instructions, where, with whom, and what happens when you want it gone.
Every clause in the agreement is a behaviour the workspace actually has — the vault, the EU server, the erasure cascade, the retention warning, the dated sub-processor list.
You decide why applicants' data is processed; we process it only on your instructions.
Stored and processed in Warsaw on our own server; mail from the EU; screening in France.
We tell your admins within 48 hours of becoming aware, with what we know, then the rest.
The Controller is the company that founded the hiring workspace (the customer under the Terms for Teams). The Processor is Erioun, operated by Loukas Tzekos, sole proprietorship, Thessaloniki, Greece (details on the Company details page). For the personal data of applicants processed in the workspace, the Controller determines the purposes and means and the Processor acts on the Controller's documented instructions. Erioun is separately a controller of its own account data about the Controller's members (their sign-in identity, billing contact and usage records) and of job seekers' own accounts — those are covered by the Privacy policy, not by this agreement.
Subject matter: the personal data of people who apply to the Controller's roles, or whom the Controller adds to its pipeline. Duration: for as long as the workspace exists, plus the deletion period in section 9. Nature: collecting applications through the Controller's apply pages and imports; storing, displaying and searching them; ranking them with AI screening on the Controller's instruction; sending mail on the Controller's behalf; filing replies and bookings; producing offer letters and recording signatures; analytics; erasure. Purpose: enabling the Controller to run its recruitment.
Data subjects: applicants and candidates, including people the Controller imports. Categories:
The Controller undertakes:
The Processor undertakes (Art. 28(3) GDPR):
Screening is performed on the Controller's instruction (a member's click, or the Controller's own automation setting) by sending the CV text and the role to Mistral AI SAS, Paris, France, through Mistral's commercial API, whose terms exclude the use of API data for training. Erioun stores the score, the reasons and the model identifier as part of the application record; it never rejects, ranks people out of sight, or acts on a score. The disclosure required by Art. 50 AI Act is displayed on every screening surface. The Processor is the provider of this AI system and the Controller its deployer; each side cooperates with the other's obligations under Regulation (EU) 2024/1689 as those obligations apply in time.
The Controller authorises the sub-processors listed on the Third parties page under "Sub-processors for Erioun for Teams" (identity, location, purpose and safeguard for each). The Processor will announce any addition or replacement on that page at least 30 days before it takes effect and by notice in the workspace; the Controller may object on reasonable data-protection grounds within that period, in which case the parties will look for a solution and, failing one, the Controller may terminate the affected workspace without penalty. The Processor remains liable for its sub-processors' performance.
Applicant data is stored and processed on servers operated for Erioun by OVHcloud in Warsaw, Poland (EU). Mail is delivered by Lettermint B.V. from servers in the EU. AI screening is performed by Mistral AI in France. Network delivery for erioun.com passes through Cloudflare, Inc.'s global edge, where connections are terminated and re-encrypted; no applicant data is stored there. Product analytics (PostHog, EU cloud, Frankfurt) never run on applicant-facing pages, so no applicant data reaches them. Where a sub-processor's contracting entity is outside the EEA (Cloudflare, Inc.; PostHog, Inc.), transfers rest on the Commission's Standard Contractual Clauses and, where the entity is certified, the EU-US Data Privacy Framework.
Every path by which data leaves the workspace:
The Processor answers written information requests about this processing within 30 days and provides its current security measures and sub-processor list on request. Once per year, or after a breach affecting the Controller, the Controller may audit the Processor's compliance with this agreement by a written questionnaire or, where that is insufficient, by an on-site or remote audit on 30 days' notice, during business hours, at the Controller's cost, by an auditor bound by confidentiality. Erioun does not hold ISO 27001 or SOC 2 reports; the measures in Annex 2 are what is offered.
The Processor notifies the Controller without undue delay, and in any case within 48 hours of becoming aware, of a personal-data breach affecting the Controller's data, with what it knows at that time (nature, categories and approximate numbers, likely consequences, measures taken), and supplements as facts become known. Notification goes to the workspace's admins by mail and in the workspace.
Liability follows the Terms for Teams. This agreement lasts as long as the Terms and survives for as long as the Processor holds any of the Controller's data. Greek law applies; the courts of Thessaloniki have jurisdiction. Where this agreement and the Terms conflict on data protection, this agreement prevails.
As in sections 2 and 3. Processing activities, in the order they occur: intake (apply page, manual add, CSV import), storage in the sealed vault, display to members, screening on instruction, messaging (outbound as the Controller's identity on Erioun's domain; inbound filed to the timeline), interview scheduling through the Controller's own booking page, offers and signatures, analytics on anonymous counts, retention and erasure.
The measures in force, each one implemented in the product or its operation:
Maintained on the Third parties page, section "Sub-processors for Erioun for Teams", which is the authoritative, dated list and the place where changes are announced.
Every apply page states, in the Controller's name: who is hiring; that the application is processed in Erioun on the employer's behalf on EU servers; that an AI system may rank it with reasons that a person reviews and that no decision is automated; how long the data is kept (the Controller's policy, if set); and how to ask for access, correction or erasure — by replying to any message from the employer or writing to the employer's address shown on the page.
No. The DPA applies to every workspace as part of the Terms for Teams. If your procurement needs a signed copy, write to support@erioun.com and we return a countersigned PDF of this page.
No. Screening uses Mistral's commercial API, whose terms exclude training on API data, and Erioun itself never trains anything on workspace data.
Yes — export from the workspace at any time, and erase any applicant or the whole workspace. A signed offer letter is mailed to both sides as a last copy before an erasure takes it.
Start your free trial and keep your job search under control.