Data processing

The standing terms under which we process personal data on a customer's behalf. This page is the agreement — there is nothing separate to sign.

Last updated 29 July 2026

Status of this page

These are the data processing terms required by Article 28 of the GDPR. They form part of the Terms and take effect when you begin using the service. No separate signature is needed and none is offered: a customer buying a shortlist with a card cannot negotiate a bespoke agreement, so the agreement is published instead. It binds us in the same way a signed one would.

If you operate under a master services agreement with its own data processing annex, that annex governs and this page is subordinate to it.

Roles

You are the controller. You decide which role you are filling, which people are researched, and what happens to the result.

We are the processor. Zero One Labs LLC processes candidate personal data on your instructions in order to produce the shortlists you commission.

For data about your own account holders, we act as controller instead; that is covered by the privacy notice and not by this page.

Scope of the processing

Subject matter and duration

Researching, verifying and documenting candidates against role specifications you approve, for as long as you hold an account and for the retention period that follows.

Nature and purpose

Collecting personal data from public and licensed sources; verifying it against independent sources; assessing it against your role specification; writing it up with citations; storing it so that a delivered list stays auditable.

Categories of data subject

Candidates and potential candidates for roles you are filling — working professionals, researched in their professional capacity.

Categories of personal data

  • identity and contact: name, public profile URLs, general location;
  • professional history: employer, role, tenure, responsibilities, education, public output such as talks, articles and code;
  • assessments we generate: the evidence gathered, the sources cited, the verification status of each claim, and the score computed against your specification;
  • your own records about the person: the decision you took and the reason you gave.

A profile photograph may be displayed in the console, streamed from its origin at the moment of display. It is never stored by us.

Special category data

We do not seek special category data — health, religion, ethnicity, political opinions, trade union membership, sexual orientation — and it is not part of any assessment. You must not instruct us to research it or write it into a role specification. Where such material appears incidentally on a public page, it does not become evidence for or against a candidate.

Our obligations

  • Documented instructions. We process personal data only on your instructions. Your approved role specification and your use of the console are those instructions. If we believe an instruction breaches data protection law, we will tell you and may decline it.
  • Confidentiality. Everyone with access is bound by confidentiality obligations, and access is limited to those who need it to operate the service.
  • Security. The measures described in the next section.
  • Subprocessors. Each engaged under a written contract with obligations no weaker than these, and named to you on request.
  • Assistance. We help you respond to data subject requests, and with your obligations on security, breach notification and impact assessments, taking into account what we know and what you know.
  • Deletion and return. On termination, or on your instruction, we delete or return the personal data we hold for you.
  • Information. We make available what you need to demonstrate compliance with Article 28, and cooperate with audits you reasonably require.

Security measures

Stated specifically, because a list of adjectives is not a security measure:

  • Isolation between customers.Every record carries the practice that owns it, and all access passes through a single scoped data layer. An automated isolation test seeds two practices and checks that no query reaches the other’s rows; it runs as part of the test suite and fails the build if isolation breaks.
  • Separate identity records per controller. The records that carry contact history and Article 14 notice state are kept per practice, never shared between customers.
  • Access control. No passwords are held. Sign-in is a one-time code to a verified email address. A confirmed account without a membership can open nothing.
  • No photograph storage. Candidate images are streamed transiently with caching disabled and are never written to disk, blob storage or the database.
  • Encryption in transit for all traffic, and encryption at rest as provided by our database and hosting providers.
  • Provenance in the record. Every claim carries its source, so an inaccuracy can be traced to where it came from rather than argued about.

We hold no security certifications and make no claim to any. The measures above are what the system does.

Subprocessors

We engage subprocessors in these categories: application hosting, the database that holds account data and research artifacts, the search and profile sources the research reads, the language models that perform the reasoning and write the profiles, transactional email, and payment processing for self-serve customers. Each is engaged under a written contract carrying data protection obligations no weaker than these terms, and you consent to them by accepting these terms.

The current list is provided on request rather than published here. It names every subprocessor, what it does, where it processes and the transfer mechanism relied on. Email privacy@01.inc and we will send it within five working days, at no cost, as often as you ask.

We give notice before adding or replacing a subprocessor, and you may object on reasonable data protection grounds. If we cannot resolve your objection, you may terminate and we will refund any credits you have not spent.

Some services are consulted as public sources rather than engaged as subprocessors, and are therefore not on that list, because we send them no candidate personal data: national business registers (public authority data), a public DNS resolver used to check that a claimed company’s domain exists, and public code hosting read through an unauthenticated public API.

International transfers

Account data and research artifacts are stored in the EU. Some subprocessors process outside the EEA, and personal data is transferred to them in the course of the processing — a search query naming a person, a profile URL sent for verification, a document sent to a language model.

Every transfer outside the EEA rests on a mechanism recognised under Chapter V of the GDPR: an adequacy decision, the EU-US Data Privacy Framework where the recipient is certified, or the standard contractual clauses with the UK addendum where it is not. We verify the mechanism against the vendor’s own published terms before engaging them, and the mechanism relied on for each one is named in the list we provide on request.

Data subject requests

If a candidate contacts us directly, we do not answer on your behalf. We identify the controller and pass the request to you promptly, and we give you what you need to answer it — including the sources relied on for every claim, which are recorded in the deliverable itself.

Where you instruct us to correct, restrict or erase a person’s record, we act on it. Your own decision records are kept as an append-only audit trail of your review process; where erasure requires those to go too, say so and we will action it.

Personal data breach

If we become aware of a personal data breach affecting data we process for you, we notify you without undue delay and in any event within 48 hours of becoming aware, with what we know: what happened, which categories and roughly how many people are affected, the likely consequences, and what we are doing about it. Notifying a supervisory authority or the affected people is the controller’s decision, which means yours.

Contact

Data protection matters: privacy@01.inc. Zero One Labs LLC, a limited liability company organised in Texas, United States · 5900 Balcones Dr, STE 100, Austin, TX 78731 · Texas Taxpayer No. 32098806634.