Skip to content
Atheer
Home/GDPR

Legal

GDPR Compliance

How Atheer complies with the EU General Data Protection Regulation and protects the rights of EEA data subjects.

Effective dateJanuary 1, 2026
Last updatedJune 1, 2026

Summary

Atheer complies with GDPR when processing EEA personal data. We offer Data Processing Agreements to all customers, implement Standard Contractual Clauses for international transfers, and support all seven GDPR data subject rights. Our AI outputs always involve human review — no significant decisions are made solely by automated systems.

Your GDPR Rights at a Glance

AccessArt. 15
Get a copy of your data
RectificationArt. 16
Correct inaccurate data
ErasureArt. 17
Request deletion
RestrictionArt. 18
Limit how we use your data
PortabilityArt. 20
Receive data in machine-readable format
ObjectArt. 21
Object to certain processing
Human ReviewArt. 22
Review of automated decisions

To exercise any right, email privacy@aiatheer.com. We respond within 30 days.

1. Introduction

This page explains how Atheer Technologies ("Atheer", "we", "our", or "us") complies with the General Data Protection Regulation (GDPR) — the European Union's data protection law — when processing the personal data of individuals located in the European Economic Area (EEA), United Kingdom, or Switzerland.

While Atheer is primarily built for organizations in the GCC region, we recognize that our customers may process the data of candidates or employees who are EEA residents, or that EEA-based organizations may use our Services. In these cases, GDPR requirements apply.

If you are an EEA resident and have questions about how your data is handled, this page and our Privacy Policy provide a complete picture of your rights and our obligations.

2. Data Controller and Processor

Atheer as Data Processor

When organizations ("Customers") use Atheer to process candidate or employee data, Atheer acts as a data processor. The Customer is the data controller — they determine the purposes and means of processing, and they are responsible for ensuring a lawful basis exists for that processing.

Atheer as Data Controller

Atheer acts as a data controller for data we collect directly, including account registration data, usage analytics, and communications with our team.

Data Processing Agreements

We offer Data Processing Agreements (DPAs) to all Customers processing EEA personal data through our platform. These agreements comply with Article 28 of the GDPR and include the required contractual clauses governing processor obligations. To request a DPA, contact privacy@aiatheer.com.

3. Lawful Bases for Processing

Under GDPR, personal data may only be processed where a lawful basis exists. Atheer relies on the following bases:

Contractual Necessity (Article 6(1)(b))

Processing necessary to fulfill our contractual obligations — providing the platform, managing your account, and delivering the Services you have subscribed to.

Legitimate Interests (Article 6(1)(f))

Processing for purposes such as improving our Services, fraud prevention, and security monitoring, where those interests are not overridden by individual rights. We conduct Legitimate Interests Assessments (LIAs) for processing activities based on this ground.

Consent (Article 6(1)(a))

Where required — for example, marketing communications and non-essential cookies — we obtain explicit, freely given, specific, and informed consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.

Legal Obligation (Article 6(1)(c))

Processing required to comply with applicable laws, court orders, or regulatory requirements.

Special Categories of Data

We do not intentionally collect special category data (Article 9) such as health, biometric, or ethnicity data through our platform. If such data is incidentally included in candidate CVs or interview content, it is processed only to the extent necessary and on the basis of explicit consent or legal obligation where required.

4. Your Rights Under GDPR

As an EEA resident, you have the following rights under the GDPR. To exercise any of these rights, contact us at privacy@aiatheer.com. We will respond within 30 days (extendable to 3 months for complex requests with notice).

Right of Access (Article 15)

You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data along with information about how it is used.

Right to Rectification (Article 16)

You have the right to have inaccurate personal data corrected and incomplete data completed without undue delay.

Right to Erasure (Article 17)

You have the right to request deletion of your personal data where it is no longer necessary for the purpose it was collected, where you withdraw consent, or where processing is unlawful. This right is subject to certain exceptions, including legal obligation and public interest.

Right to Restriction of Processing (Article 18)

You have the right to request that we restrict processing of your data in certain circumstances, such as while accuracy is contested or while an objection is being assessed.

Right to Data Portability (Article 20)

Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.

Right to Object (Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will cease processing immediately.

Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing that produce significant effects on you. Atheer's AI outputs are always reviewed by human hiring professionals. You may request human review of any AI-generated assessment by contacting privacy@aiatheer.com.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

5. International Data Transfers

Atheer operates primarily in the GCC region. When personal data of EEA residents is transferred outside the EEA — including to Saudi Arabia or the UAE — we ensure appropriate safeguards are in place in accordance with Chapter V of the GDPR.

Transfer Mechanisms

We rely on the following mechanisms for international transfers:

  • Standard Contractual Clauses (SCCs) as adopted by the European Commission
  • Data Processing Agreements incorporating SCCs with all sub-processors
  • Transfer Impact Assessments (TIAs) where required

Sub-processors

We maintain an up-to-date list of sub-processors involved in processing EEA personal data. Customers may request this list by contacting privacy@aiatheer.com. We notify Customers of material sub-processor changes with at least 30 days' notice, providing the opportunity to object.

6. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in our Privacy Policy or as required by applicable law.

For EEA data subjects, our standard retention periods are:

  • Account data: Retained for the duration of the customer relationship plus 2 years
  • Candidate data: Retained for 24 months following the completion of a hiring process, unless the Customer specifies a shorter period
  • Usage and analytics data: Retained for 12 months in identifiable form, then aggregated anonymously
  • Communication records: Retained for 3 years for legal and compliance purposes
  • Backup data: Purged within 90 days of deletion from primary systems

Upon expiry of the applicable retention period, data is securely deleted or anonymized in accordance with our data destruction procedures.

7. Security Measures

In accordance with Article 32 of the GDPR, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These include:

  • AES-256 encryption for all data at rest
  • TLS 1.3 encryption for all data in transit
  • Role-based access controls with least-privilege principles
  • Multi-factor authentication for all staff accessing personal data
  • Regular penetration testing and vulnerability assessments
  • Pseudonymization of analytics data where feasible
  • Data minimization practices — we collect only what is necessary
  • Staff training on data protection and confidentiality obligations
  • Incident response procedures with defined breach notification timelines

8. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of EEA individuals, Atheer will:

  • Notify affected Customers without undue delay and within 72 hours of becoming aware, in accordance with Article 33 GDPR (where Atheer is the controller) or within a timeframe agreed in the DPA (where Atheer is the processor)
  • Provide sufficient information to enable the Customer (as controller) to fulfill their own notification obligations to supervisory authorities
  • Cooperate fully with affected Customers and supervisory authorities in the event of an investigation

Notifications will include the nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken or proposed to address the breach.

9. Data Protection Officer

Atheer has appointed a Data Protection contact responsible for overseeing our GDPR compliance program. While we are currently assessing the formal requirement to appoint a Data Protection Officer (DPO) under Article 37 GDPR, our privacy team handles all data protection inquiries and exercises the functions of a DPO in practice.

To contact our Data Protection team:

Email: privacy@aiatheer.com Response time: Within 30 days for rights requests; within 72 hours for breach notifications

10. Supervisory Authority

If you are an EEA resident and believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with your local data protection supervisory authority.

You may find your local supervisory authority through the European Data Protection Board's website at edpb.europa.eu.

We encourage you to contact us first at privacy@aiatheer.com so we have the opportunity to address your concern directly before escalating to a supervisory authority.

11. Updates to This Page

We review and update this GDPR compliance page regularly to reflect changes in our practices, legal requirements, and guidance from supervisory authorities. The "Last updated" date at the top of this page indicates when the most recent review took place.

For questions about our GDPR compliance program or to request a Data Processing Agreement, contact privacy@aiatheer.com.

Need a Data Processing Agreement?

If your organization processes EEA personal data through Atheer, you may require a DPA under Article 28 GDPR. Contact us to request one.

Request a DPA

GDPR or privacy questions?

Contact our Data Protection team at privacy@aiatheer.com

Privacy PolicyTerms of Service