Data Processing Agreement

Effective date: upon customer acceptance

Note: Key data processing information — including sub-processors, data retention, breach notification, and data subject rights — is now summarized on our Security page. This full DPA remains available for organizations that require a formally executed agreement.

This Data Processing Agreement ("DPA") forms part of the agreement between the customer identified in the Relio subscription ("Customer," "Controller") and Relio LLC ("Relio," "Processor") for the provision of the Relio service.

This DPA applies when Relio processes Personal Data on behalf of the Customer in connection with the Relio service.

1. Definitions

Personal Data means any information relating to an identified or identifiable natural person that is processed by Relio in connection with the service.

Processing means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.

Sub-processor means any third party engaged by Relio to process Personal Data on behalf of the Customer.

Data Subject means the identified or identifiable natural person to whom Personal Data relates.

Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

Applicable Data Protection Law means all applicable laws and regulations relating to the processing of Personal Data, including GDPR (EU General Data Protection Regulation 2016/679), CCPA (California Consumer Privacy Act), and any other applicable US state privacy laws.

2. Scope and Purpose of Processing

Relio processes Personal Data solely for the purpose of providing the Relio service as described in the applicable subscription agreement. Specifically:

Purpose of processing: Relio processes data submitted by the Customer to generate capacity decision briefs, financial analyses of hiring decisions, scenario comparisons, cost calculations, dashboards, and exportable reports. Relio also processes data to improve the Customer's organization-specific defaults through the accumulated context feature (when enabled by the Customer).

Nature of processing: automated calculation, AI-assisted conversation and formatting, storage, retrieval, aggregation, and export of hiring decision data.

Duration of processing: for the term of the Customer's subscription, plus the retention period described in Section 7.

3. Types of Personal Data Processed

Role and hiring data: Role titles, levels, functions, departments. Compensation figures (salary, total compensation, bonus, equity). Hiring timelines, search method and source information, agency fee structures, business justification text, interview process details.

Account and user data: Email addresses, names, organization name and company profile information, authentication credentials (stored as hashed values, never in plain text).

Usage data: Pages visited, features used, session duration (via Google Analytics 4). Calculation history and saved scenarios. Export and sharing activity.

Pasted or uploaded content: Job descriptions, requisitions, emails, Slack messages, recruiter intake notes, hiring plans, and spreadsheets that the Customer submits for analysis.

Data Relio does NOT process: Candidate personal data (names, resumes, contact information, demographic data). Social security numbers, government IDs. Health or medical data. Credit card numbers (payment processing is handled entirely by Stripe). Biometric data.

4. Categories of Data Subjects

Data subjects whose Personal Data may be processed include: the Customer's employees who use the Relio service (account holders), individuals whose role or hiring data is submitted by the Customer, and individuals referenced indirectly in pasted or uploaded content.

5. Obligations of the Processor

Relio will:

  1. Process Personal Data only on documented instructions from the Customer, unless required by applicable law.
  2. Ensure that authorized persons have committed to confidentiality.
  3. Implement and maintain appropriate technical and organizational security measures as described in Section 8.
  4. Comply with the conditions for engaging Sub-processors as described in Section 6.
  5. Assist the Customer in responding to Data Subject requests.
  6. Assist the Customer in ensuring compliance with security, breach notification, and impact assessment obligations.
  7. At the Customer's choice, delete or return all Personal Data after the end of services.
  8. Make available information necessary to demonstrate compliance, and allow for audits as described in Section 11.
  9. Immediately inform the Customer if an instruction infringes Applicable Data Protection Law.

6. Sub-processors

Sub-processorPurposeData ProcessedLocation
DigitalOcean Server and database hosting All data stored and processed by the Relio service. New York, United States
Resend Transactional and lifecycle email delivery Recipient email addresses and email content, including monitoring access links and summary reports. United States
Stripe Payment processing Customer email and payment method details. Relio does not store card numbers. United States
Google Analytics 4 Usage analytics Pages visited, features used, and product events. No names, emails, role data, or posting content. Advertising personalization is not enabled. United States
Cloudflare DNS and content delivery Standard DNS and network request metadata. Global

Sub-processor changes: Relio will notify the Customer at least 30 days before adding or replacing a Sub-processor by updating the list in Section 6 of this page and sending email notification. The Customer may object within 30 days. If Relio cannot reasonably accommodate the objection, the Customer may terminate the affected service.

7. Data Retention and Deletion

During active subscription: all Customer data is retained and accessible.

After cancellation: read-only for 90 days (export window), then permanently deleted within 30 days (120 days total).

On-demand deletion: completed within 30 days of request via support@relioengine.com or account settings.

Deletion scope: all analyses, uploaded files, learned defaults, hiring outcomes, company defaults, user accounts, email schedules, and organization records.

Backup retention: backups are retained for 30 days in access-controlled off-site object storage and are transferred over encrypted connections. Deleted data may persist in a backup for up to 30 days after production deletion.

Anonymized aggregate data: if opted in to benchmarks, anonymized data points may persist after deletion. Contains no company names, role titles, or identifying information. Opt-out available in Settings.

8. Security Measures

Encryption: TLS 1.2+ in transit for all traffic, HTTPS with HSTS. Sensitive access tokens, including monitoring access links and API keys, are stored as one-way hashes rather than reversible plaintext.

Access control: Role-based access, API keys stored as SHA-256 hashes, session management with idle timeout and secure cookies.

Application security: Input sanitization, parameterized queries, CSP headers, CORS restrictions, rate limiting.

Infrastructure: DigitalOcean (New York, United States). Containerized services on a single managed host, with the application database reachable only over a private internal network and never exposed to the internet. Environment separation and credential rotation are in place.

Organizational: Access limited to authorized personnel, confidentiality obligations, regular permission review.

9. Data Subject Rights

Access: view and export all data through the interface.

Rectification: edit data at any time.

Erasure: request deletion as described in Section 7.

Portability: export as CSV, PDF, or structured text.

Restriction: toggle off benchmark contribution.

Object: contact support@relioengine.com.

Relio responds to forwarded Data Subject requests within 15 business days.

10. Data Breach Notification

Relio will notify the Customer within 72 hours of becoming aware of a Data Breach, by email and in-app notification. The notification will include: nature of the breach, contact details, likely consequences, and remedial measures. Relio documents all breaches and cooperates with investigation and remediation.

11. Audits

The Customer may audit Relio's compliance once per 12 months (30 days written notice, at Customer's expense). Relio may alternatively provide an independent audit report less than 12 months old, where one is available.

12. International Data Transfers

All data is processed in the United States. For EEA/UK/Swiss customers, transfers are governed by Standard Contractual Clauses (Module Two: Controller to Processor) per Commission Implementing Decision (EU) 2021/914.

13. Liability

Each party's liability is subject to the limitations in the applicable subscription agreement.

14. Term

This DPA remains in effect for as long as Relio processes Personal Data on behalf of the Customer.

15. Governing Law

Governed by the laws of the State of Delaware. For EEA customers, GDPR and applicable member state laws apply to the extent they govern Personal Data processing.

16. Contact

DPA and privacy inquiries: kate@relioengine.com

General support: support@relioengine.com

17. Acceptance

By subscribing to a paid Relio plan, the Customer accepts this DPA. For customers who require a separately executed DPA, contact kate@relioengine.com.

An unhandled error has occurred. Reload 🗙