HireDay stores your data in the United States. Specifically, in Amazon Web Services’ us-east-1 region in Northern Virginia. If your organization is in the UK or the EEA, that is a restricted international transfer under Chapter V of the UK GDPR and EU GDPR, and this page explains the legal basis for it.

We say this plainly rather than burying it, because it is the first question a UK or EU HR buyer’s own compliance review will ask.

1. What is transferred

Everything your organization stores in HireDay: employee and new-hire names, work email addresses, job titles, start dates, manager relationships, and the content and completion status of onboarding tasks.

We do not collect or store special category data — health information, biometric data, trade-union membership or the other categories listed in Article 9. There is no field for it in the product.

2. The legal basis

We rely on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision 2021/914), Module 3, together with the UK International Data Transfer Addendum issued by the Information Commissioner’s Office. These are incorporated into our agreement with each of the companies that processes data on our behalf.

Where one of those companies is also certified under the EU-US Data Privacy Framework and its UK Extension, the corresponding adequacy decision applies as well. We keep the Standard Contractual Clauses underneath as a fallback rather than relying on a certification alone — a certification can lapse, and a transfer that depends only on it stops having a legal basis the day it does.

3. The Schrems II assessment

A transfer mechanism is not enough on its own. Following the Court of Justice’s decision in Schrems II, we have also assessed whether US law lets those clauses work in practice, using the six-step method in the European Data Protection Board’s Recommendations 01/2020.

The assessment looked at FISA Section 702, Executive Order 12333, the CLOUD Act and National Security Letters, against the four European Essential Guarantees. Its conclusion is that transfers may proceed with supplementary measures, which are listed below.

We note two things honestly. First, the redress mechanism created by Executive Order 14086 is an executive-branch body, and its independence is the subject of live legal challenge; if the adequacy decision falls, we will re-run this assessment and tell you what changes. Second, onboarding checklists for HR departments are an unlikely target for foreign-intelligence collection — but we treat that as a mitigating factor, not as a reason to skip the analysis.

4. Supplementary measures

5. Who the data reaches

Three companies process your data on our behalf, all in the United States or with US parent entities. Each is named, with what it does and what it can see, on our Sub-processors page. We give 30 days’ notice before adding another, and you can object.

6. Review

We re-run this assessment at least once a year, and sooner if any of these happen: an adequacy decision is annulled or suspended, a sub-processor’s certification lapses, a government access request reaches us, or the nature of the data we transfer changes materially.

7. Questions, and your own assessment

If your organization needs to complete its own transfer risk assessment, write to hello@hireday.io and we will share what you need — including the detail behind this summary. If EU or UK data residency is a hard requirement for you, tell us; it is not something we offer today and we would rather say so than let you find out during procurement.