Terms of Service

1. Parties and scope

These Terms of Service ("Terms") form a binding agreement between:

SIA Victory Vector , registration number [40203609071], registered address: Riga, Latvia, LV-1000 ("Victory Vector", "we", "us", "our"), and

the organisation or individual who registers for, subscribes to, or uses the Helen AI platform ("Customer", "you").

These Terms govern access to and use of the Helen AI platform, including its web application, dashboard, interview delivery system, APIs and supporting documentation (together, the "Service").

By creating an account, starting a free trial, or using the Service, you agree to these Terms. If you are agreeing on behalf of an organisation, you confirm you have authority to bind that organisation.

The following documents form part of this agreement and are incorporated by reference:

  • the Data Processing Agreement (the "DPA"), available on request

  • the Data Processing & Security documentation, published in our Legal Center

  • the Privacy Notice for Candidates, published in our Legal Center

  • the Sub-processor List, published in our Legal Center

  • the applicable Order Form or online plan selection

Where a signed Order Form conflicts with these Terms, the Order Form prevails. Where the DPA conflicts with these Terms on matters of personal data processing, the DPA prevails.

2. Definitions

"AI Act" means Regulation (EU) 2024/1689 as amended, including by the Digital Omnibus on AI.

"Candidate" means an individual invited by the Customer to complete a screening process through the Service.

"Candidate Data" means all personal data relating to a Candidate that is processed through the Service.

"Criminal Offence Data" means personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR.

"Deployer" has the meaning given in Article 3(4) of the AI Act. The Customer is the Deployer of the Service.

"GDPR" means Regulation (EU) 2016/679 and, where applicable, equivalent national implementing law, including the Latvian Personal Data Processing Law.

"Provider" has the meaning given in Article 3(3) of the AI Act. Victory Vector is the Provider of the Service.

"Qualifying Questions" means the closed-form questions defined by the Customer that a Candidate answers before the interview stage.

"Regulated Role Screening" means a screening configuration, described in clause 9, in which the Customer's questions lawfully cover Special Category Data or Criminal Offence Data because the role is subject to statutory vetting, licensing, fitness or background requirements (for example, licensed security personnel, maritime security roles, or other positions where such vetting is required or authorised by law).

"Screening Output" means the material the Service makes available to the Customer in respect of a Candidate: the CV, the Qualifying Question answers, the interview recording, the transcript, any assessment results, and the Candidate's stage status.

"Special Category Data" means the categories of personal data listed in Article 9(1) GDPR, including data concerning health, and, for the purposes of these Terms, data concerning drug or substance use to the extent it reveals health information.

3. What the Service does

Helen AI is a structured first-round screening system. Its operation is as follows:

  • CV intake. The Candidate uploads a CV or equivalent document.

  • Qualifying Questions. The Candidate answers the closed-form questions the Customer has defined for the role.

  • Rule-based advancement. The Service applies the advancement rule the Customer has configured. Candidates whose answers match the Customer's stated requirements are automatically invited to complete an AI interview. Candidates whose answers do not match are not invited to the interview stage. This step is deterministic rule evaluation against the Customer's stated criteria — not a model inference.

  • AI interview. Invited Candidates complete a structured interview conducted by Helen, using a fixed sequence of questions defined in advance by the Customer. Helen follows the defined order, may ask at most one clarifying follow-up per question where an answer is unclear, and then moves on. Interviews are available on demand and do not require scheduling.

  • Voice processing modes. Depending on configuration, the interview voice interaction is processed either (a) natively in the Candidate's browser, in which case voice audio is not transmitted to a third-party voice provider for speech processing, or (b) by a cloud voice provider operating under contractual zero-retention terms as described in the Data Processing & Security documentation and the Sub-processor List.

  • Recording. Where recording is enabled for a role, interview audio and video are captured and stored on our infrastructure, and made available to the Customer in the dashboard.

  • Review dashboard. All Candidates — both those who advanced and those who did not — appear in the Customer's dashboard with their CV, their Qualifying Question answers, their stage status, and, where applicable, their interview recording and transcript.

Candidates are presented in the dashboard in a defined order. They are not scored, rated, or ranked by suitability by the Service. Ordering is a display convention, not an assessment. Where optional assessments are enabled, results are produced by fixed, documented scoring keys as described in clause 8, and are informational outputs only.

4. What the Service does not do

Victory Vector confirms that the Service does not:

  • perform emotion recognition or infer emotional state, mood, confidence, enthusiasm, sincerity or personality traits from voice, tone, speech patterns, facial expression, gaze or body language;

  • perform biometric categorisation or biometric identification of any kind;

  • assign a suitability score, fitness rating, or comparative ranking to Candidates;

  • make, recommend, or communicate a hiring decision;

  • generate interview questions autonomously outside the structure the Customer has defined;

  • use Candidate Data to train, fine-tune, or improve any machine learning model, whether ours or a third party's.

Article 5(1)(f) of the AI Act prohibits AI systems that infer emotions in the workplace, and that prohibition has applied since 2 February 2025. The Service is designed so that this prohibition is not engaged, and the Customer must not attempt to configure or use it in a way that would engage it (see clause 12).

5. Regulatory classification and the Customer's position

5.1 The Service is a high-risk AI system

The Service is used to filter job applications and to conduct interviews as part of a selection process. Victory Vector therefore treats the Service as a high-risk AI system within the meaning of Annex III, point 4(a) of the AI Act.

We do not rely on the Article 6(3) derogation for narrow procedural or preparatory tasks, because the Service processes information about individual Candidates in a manner that may constitute profiling.

We state this openly because vendors who deny the classification create risk for their customers rather than removing it.

5.2 Applicable dates

Obligation

Applies from

Article 5 prohibited practices (incl. emotion inference at work)

2 February 2025 — in force

Article 4 AI literacy obligations

2 February 2025 — in force

Article 50 transparency obligations (incl. AI interaction disclosure)

2 August 2026

Article 50(2) marking of synthetic output, systems already on market

2 December 2026

New Article 5 prohibitions introduced by the Omnibus

2 December 2026

Chapter III high-risk obligations, Annex III stand-alone systems

2 December 2027

Victory Vector's conformity programme is described in the Data Processing & Security documentation.

5.3 Division of roles

Framework

Victory Vector

Customer

AI Act

Provider

Deployer

GDPR

Processor (for Candidate Data); Controller (for Customer account and billing data)

Controller (for Candidate Data)

If the Customer places its own name or trademark on the Service, materially modifies its intended purpose, or substantially modifies the system, the Customer may itself become a Provider under Article 25 of the AI Act and assume the corresponding obligations. The Customer must notify us in writing before doing any of these things.

6. Customer obligations as Deployer

The Customer is responsible for:

Configuration and content

  • the content, relevance, lawfulness and non-discriminatory character of all Qualifying Questions, interview questions and advancement rules;

  • ensuring that the criteria it configures are job-related and consistent with business necessity;

  • ensuring input data is relevant and sufficiently representative for the intended purpose (AI Act Article 26(4)).

Human oversight

  • assigning the review of Screening Output to natural persons who have the necessary competence, training and authority (AI Act Article 26(2));

  • ensuring those persons actually review Screening Output before any decision affecting a Candidate is taken;

  • ensuring those persons have the authority to disregard, override or reverse the outcome of the advancement rule.

Transparency and consultation

  • informing Candidates, before they begin, that a high-risk AI system will be used in respect of them (AI Act Article 26(7)), and that they are interacting with an AI system (AI Act Article 50);

  • where required by national law or collective agreement, informing and consulting workers' representatives before deployment;

  • providing the Privacy Notice for Candidates, or an equivalent notice, to every Candidate.

Data protection

  • establishing and documenting a lawful basis for processing Candidate Data, and — where Regulated Role Screening is used — a valid condition under Article 9(2) GDPR and, for Criminal Offence Data, authorisation under Article 10 GDPR and applicable national law;

  • carrying out a Data Protection Impact Assessment where required (Article 35 GDPR); a DPIA will generally be required for recruitment screening using AI, and will always be required where Regulated Role Screening is enabled. We provide supporting technical material on request;

  • setting an appropriate retention period within the Service;

  • responding to Candidate rights requests as Controller.

AI literacy

  • ensuring that staff who operate or rely on the Service have a sufficient level of AI literacy (AI Act Article 4). We make training material available to support this.

7. Automated filtering and the right to human involvement

The advancement rule described in clause 3 is automated processing. We describe it as such rather than characterising it otherwise.

The Service is designed so that this processing does not amount to a decision based solely on automated processing producing legal or similarly significant effects, because:

  • Candidates who are not advanced are not rejected by the Service. They remain fully visible in the Customer's dashboard, with their CV and answers, and remain available for the Customer to progress at its discretion;

  • no rejection, communication or adverse action is issued by the Service;

  • every outcome affecting a Candidate is taken by the Customer, by a human, using the Screening Output as one input.

The Customer must not configure the Service, or connect it to other systems, so that non-advancement automatically produces a rejection, an automated rejection message, or removal from consideration without human involvement. Doing so may bring the Customer within Article 22 of the GDPR and is a breach of these Terms.

Human review. Any Candidate may request human review of their screening. Requests received by us are forwarded to the Customer within 5 business days. The Customer must operate a process for handling such requests and must respond within the period required by applicable law.

8. Assessments

The Service may make available optional structured assessments, including cognitive ability and personality instruments.

Our commitments. For every instrument we make available, we make available in the dashboard and on request: the construct it measures, its scoring method, available reliability and validity evidence, known limitations, the populations on which it has been evaluated, and the languages in which it has been validated.

Scoring. Assessment responses are processed using fixed, documented scoring keys. Results are returned as structured outputs. The Service does not convert assessment results into a hiring recommendation, a suitability score, or a ranking of Candidates.

Customer obligations. The Customer is responsible for:

  • establishing that any assessment it enables is job-related and justified by business necessity for the specific role;

  • interpreting results, and not treating them as the sole or determining basis for any decision;

  • providing reasonable accommodations to Candidates with disabilities, including alternative assessment formats;

  • confirming that its intended use is lawful in every jurisdiction where it recruits.

Jurisdictional restrictions. Assessment and AI interview features are subject to additional local law. The Customer is responsible for compliance with, among others: New York City Local Law 144 (annual independent bias audit and published results, plus advance candidate notice); the Illinois Artificial Intelligence Video Interview Act (notice, explanation and consent before AI analysis of video interviews); Maryland's facial recognition consent requirement (not engaged by this system, which performs no facial analysis); and the Colorado AI Act. The Customer remains responsible for any audit obligation that falls on it as employer or employment agency; we support Customers with the documentation they need for their own audits.

9. Special category and criminal offence data — Regulated Role Screening

9.1 The default rule

By default, the Customer must not configure Qualifying Questions, interview questions or assessments intended to elicit Special Category Data — including health, disability, religion, ethnicity, trade union membership, sexual orientation or political opinion — or Criminal Offence Data, or data relating to pregnancy or family status.

Because interviews are open-response, Candidates may volunteer such information unprompted. Where this occurs, the Customer as Controller is responsible for identifying an appropriate condition for any further use, or for disregarding and, where appropriate, deleting it.

9.2 When Regulated Role Screening is permitted

Certain roles — including licensed security personnel and comparable positions — are subject to statutory fitness, background or vetting requirements. For such roles the Customer may enable Regulated Role Screening, under which questions may lawfully cover, to the extent necessary for the role:

  • health information relevant to fitness for the role (for example, medications, chronic conditions, injuries or physical limitations) — Special Category Data under Article 9 GDPR;

  • drug and substance use history — treated as Special Category Data;

  • criminal history — Criminal Offence Data under Article 10 GDPR, which is a distinct legal category with its own conditions and is not Article 9 data;

  • prior police, military, security or maritime service history — ordinary personal data, but of elevated sensitivity.

9.3 Conditions for Regulated Role Screening

Regulated Role Screening may be used only where all of the following are met, and the Customer warrants each of them for every role where it is enabled:

  1. collection of each such category is necessary and proportionate for the specific role, and the Customer has documented why;

  2. the Customer has identified and documented a valid Article 9(2) condition for the Special Category Data (in most cases explicit consent under Article 9(2)(a), or employment-law necessity under Article 9(2)(b) where national law so provides);

  3. for Criminal Offence Data, processing is authorised by Union or Member State law as required by Article 10 GDPR (for example, statutory vetting requirements applicable to licensed security work), and the Customer has verified this for each jurisdiction in which it recruits — noting that many jurisdictions restrict or prohibit employers from asking about criminal history;

  4. the Candidate receives, before any such question is asked, a clear notice identifying the sensitive categories to be collected and the legal basis, and — where consent is the condition — gives explicit consent that is recorded, and is informed of the right to withdraw it;

  5. the Customer has completed a Data Protection Impact Assessment covering this processing;

  6. access to such data within the Customer's organisation is restricted to persons with a vetting-related need;

  7. the Customer applies the shortest retention period compatible with the vetting purpose.

9.4 Our safeguards

Where Regulated Role Screening is enabled, we apply heightened safeguards: EU data residency for records and media, zero-retention AI processing, access restricted to named personnel with a documented operational need, and priority handling of deletion requests. These are described further in the Data Processing & Security documentation.

We may require the Customer to evidence the conditions in clause 9.3 before or after enabling Regulated Role Screening, and may suspend the configuration where we reasonably believe those conditions are not met.

10. Data protection

Victory Vector processes Candidate Data solely as Processor, on documented instructions from the Customer, under the DPA.

We do not sell Candidate Data. We do not use it for marketing. We do not disclose it to any party other than the Customer and the sub-processors listed in the Sub-processor List. We do not use it to train, fine-tune or evaluate machine learning models.

Our sub-processors, their functions, their processing locations and our transfer mechanisms are published in the Sub-processor List in our Legal Center. Our current core sub-processors are: Amazon Web Services (cloud infrastructure, database hosting and media storage, European Union); Anthropic (large language model processing of interview text, United States, under a data processing agreement incorporating Standard Contractual Clauses, with zero data retention and a contractual prohibition on training on our inputs); and speech processing on the cloud voice route, EU data residency, Zero Retention Mode. We will give the Customer at least 30 days' notice before adding or replacing a sub-processor, and the Customer may object on reasonable data protection grounds as set out in the DPA.

Where AI processing is performed by a third-party model provider, that processing is carried out under contractual terms requiring zero retention of Candidate Data and prohibiting use of Candidate Data for model training. The current terms in force for each provider are stated in the Sub-processor List.

11. Accessibility

The Service is designed to be usable by Candidates with disabilities. Our accessibility statement, including our current conformance level and known gaps, is available on request.

The Customer must provide an accessible alternative route through first-round screening for any Candidate who requests one, and must not treat a request for an alternative format as a withdrawal or as an adverse indicator.

12. Acceptable use

The Customer must not use the Service:

  • to configure questions, criteria or advancement rules that discriminate on the basis of a protected characteristic, whether directly or indirectly;

  • to elicit Special Category Data or Criminal Offence Data outside a properly enabled Regulated Role Screening configuration meeting all conditions in clause 9;

  • to attempt to infer emotional state, personality, sincerity, or any protected characteristic from a Candidate's voice, face, appearance, accent or speech patterns, whether within the Service or by processing exported material;

  • to conduct biometric identification or categorisation of Candidates;

  • to screen Candidates in a jurisdiction where the Customer has not met applicable notice, consent or bias audit requirements;

  • to export Screening Output into any system that issues automated rejections without human involvement;

  • to circumvent usage limits, reverse engineer the Service, or use it to build a competing product;

  • for any purpose other than a genuine recruitment process for a genuine open role.

We may suspend access immediately where we reasonably believe use falls within the first five bullets above.

13. Fees, trials and term

Fees, billing frequency and included volumes are as set out on the pricing page or in the applicable Order Form.

Free trials are provided for evaluation for the period stated on the pricing page. Trial data is subject to the same protections as paid data and is deleted within 30 days after trial expiry unless the account converts.

Subscriptions renew automatically for successive periods equal to the initial term unless cancelled before the renewal date. Fees are exclusive of VAT and other applicable taxes.

14. Intellectual property

The Customer retains all rights in Candidate Data, its questions, criteria and configurations. The Customer grants us a limited licence to process this material solely to provide the Service.

Victory Vector retains all rights in the Service, its software, interfaces and documentation. Underlying AI models are provided by third parties under their own terms; nothing in these Terms transfers ownership of the Service or of any third-party model.

15. Warranties and disclaimers

We warrant that we will provide the Service with reasonable skill and care, in accordance with the documentation, and in compliance with applicable data protection and AI law as it applies to us as Provider and Processor.

We do not warrant:

  • any hiring outcome, quality of hire, time to fill, or commercial result;

  • the accuracy, truthfulness or completeness of information provided by a Candidate;

  • that the Service will identify misrepresentation, impersonation or fraud by a Candidate;

  • uninterrupted or error-free availability, except as set out in any agreed service level.

Automatic speech recognition and transcription are imperfect and may perform differently across accents, dialects, speech impairments and background conditions. Transcripts are an aid to review, not an authoritative record. The interview recording is the primary record.

16. Indemnities

By the Customer. The Customer will indemnify us against claims arising from: the content or lawfulness of its questions, criteria or advancement rules; its hiring decisions; its failure to provide required notices or obtain required consents; its use of Regulated Role Screening without meeting the conditions in clause 9; its failure to complete a bias audit or DPIA where one is required of it; and its breach of clause 12.

By Victory Vector. We will indemnify the Customer against claims that the Service, used in accordance with these Terms, infringes a third party's intellectual property rights, and against direct losses arising from our breach of the DPA.

17. Limitation of liability

Subject to the exclusions below, each party's total aggregate liability arising out of or in connection with this agreement is limited to the fees paid or payable by the Customer in the 12 months preceding the event giving rise to the claim.

This cap does not apply to:

  • either party's liability for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation;

  • the Customer's payment obligations;

  • either party's breach of confidentiality obligations;

  • our indemnity under clause 16;

  • either party's liability arising from breach of the DPA, or administrative fines or compensation under Article 82 GDPR or the AI Act, to the extent attributable to that party's own breach. Liability for these matters is capped at three times the fees paid or payable in the preceding 12 months.

Neither party is liable for indirect or consequential loss, loss of profits, revenue, goodwill or anticipated savings.

Nothing in this clause limits liability that cannot be limited under applicable law.

18. Confidentiality

Each party will keep the other's confidential information confidential, use it only to perform this agreement, and protect it with at least the care it applies to its own confidential information. This obligation survives termination for 3 years and, for Candidate Data, indefinitely.

19. Suspension and termination

The Customer may cancel at any time, effective at the end of the current billing period.

We may suspend or terminate access where the Customer materially breaches these Terms and fails to remedy within 14 days of written notice, or immediately in the circumstances described in clauses 9 and 12.

On termination: the Customer may export Candidate Data for 30 days. After that period we will delete or return Candidate Data in accordance with the DPA, save where retention is required by law. Deletion is confirmed in writing on request.

20. Changes

We may modify the Service, provided we do not materially reduce its core functionality during a paid term.

We may amend these Terms on 30 days' notice. If an amendment materially and adversely affects the Customer, the Customer may terminate without penalty before it takes effect, with a pro-rata refund of prepaid fees. Amendments required by law may take effect on shorter notice.

Material changes to the Service that affect its regulatory classification, its processing of Candidate Data, or the matters stated in clause 4 will be notified in advance and reflected in an updated version of this document.

21. General

Governing law. These Terms are governed by the laws of the Republic of Latvia, excluding its conflict of law rules and the UN Convention on Contracts for the International Sale of Goods.

Jurisdiction. The courts of Riga, Latvia have exclusive jurisdiction, save that either party may seek injunctive relief in any competent court.

Entire agreement. These Terms, together with the incorporated documents, constitute the entire agreement between the parties on this subject.

Assignment. Neither party may assign without the other's consent, except to a successor in a merger or sale of substantially all assets.

Severance. If any provision is held unenforceable, the remainder continues in force.

Force majeure. Neither party is liable for failure caused by events beyond its reasonable control, excluding payment obligations.

Notices. Notices to us: [email protected] and our registered address. Notices to the Customer: the administrator email on the account.

22. Contact

General and contractual: [email protected] Data protection: [email protected] Security disclosure: [email protected]

SIA Victory Vector, reg. no. 40203609071 Riga, Latvia, LV-1000