Privacy Policy
Last updated: July 10, 2026
Recruiter1 has not yet engaged legal counsel for review of this document. When counsel is retained, this page will be revised and the review notice removed.
Recruiter1 is the data controller for personal data collected directly from candidates and visitors. For Candidate Data submitted by agencies or enterprise customers, the Customer acts as data controller and Recruiter1 acts as data processor. See our Data Processing Agreement for processor obligations.
Contact: [email protected]
[Legal entity name, registration number, and registered address to be confirmed by legal counsel.]
Account information: Email, name, company name, role, and authentication credentials (hashed passwords, passkey public keys).
Candidate data: Resumes, profiles, skills, employment history, contact information, application history, and assessment results generated by AI systems.
Job data: Job titles, descriptions, requirements, locations, and compensation details posted by agencies or enterprises.
Communications: Messages between agencies, hiring managers, and candidates, including real-time chat and email notifications.
Usage and analytics: Portal views, candidate views, click events, chat activity, AI queries, device type, referrer, UTM parameters, time on page, scroll depth, and visitor identifiers. See Section 08 (Platform Analytics) for details.
Technical data: IP addresses (for rate limiting and security), browser type, session tokens, and push notification endpoints.
Billing data: Payment method details (processed by Stripe), billing address, invoices, and transaction history.
- Provide, maintain, and improve the Service and its features
- Process candidate resumes and generate AI-powered scores, match analysis, and insights
- Generate job recommendations and intelligence reports
- Enable real-time chat and communication between agencies, hiring managers, and candidates
- Process payments and manage subscriptions
- Send transactional emails (invitations, authentication, notifications)
- Send push notifications for new messages and updates
- Track portal analytics and hiring manager engagement
- Detect, prevent, and respond to security threats, fraud, and abuse
- Comply with legal obligations and respond to lawful requests
- Aggregate, de-identified analytics for product improvement
Under GDPR Article 6, we process personal data on the following lawful bases:
- Contract (Art. 6(1)(b)): Processing necessary to provide the Service under our Terms of Service, including account management, candidate scoring, and job matching.
- Legal obligation (Art. 6(1)(c)): Compliance with tax laws, employment regulations, and data protection requirements.
- Legitimate interests (Art. 6(1)(f)): Platform security, fraud prevention, analytics, and service improvement, balanced against your privacy rights.
- Consent (Art. 6(1)(a)): Marketing communications and push notifications, where applicable. You may withdraw consent at any time.
What we don't store. We do not store user prompt or content data in the model/usage system. Your actual prompts, responses, and content are not retained for model training or analysis.
What we do store. We store only billing, routing, and audit metadata necessary to operate the service. This includes usage metrics for quota management, routing information for service delivery, and audit trails for compliance and security.
How we handle identifiers. Any user identifiers are minimized and hashed where possible. They are stored only as nullable internal references when strictly required for quota, billing, or admin attribution. We do not link your account to the content of your prompts unless required for billing disputes, quota enforcement, or account administration.
Metadata retention. Audit logs and metadata are retained for a limited period necessary for operational purposes, security incident investigation, and compliance requirements. Access is restricted to authorized personnel for legitimate administrative purposes only.
No model training. Recruiter1 does not use User Content or Candidate Data to train foundation models. AI inference is performed via third-party LLM providers (OpenRouter, OpenAI) under zero-retention or limited-retention agreements. See Section 09 for sub-processor details.
AI systems in use. Recruiter1 uses AI systems for: candidate resume parsing and analysis, candidate scoring against job requirements, job-to-candidate matching and recommendations, and intelligence report generation. These systems process Candidate Data to produce scores, rankings, and insights that may influence hiring decisions.
EU AI Act classification. These AI systems are intended to be classified as "high-risk" under EU AI Act Annex III, Point 4 (AI systems used for recruitment or selection, in particular for the analysis and filtering of job applications and to evaluate candidates). The final classification depends on Recruiter1's specific role (provider, deployer, or both) and whether the system materially influences human decisions, and is subject to ongoing legal review. Article 50 transparency obligations apply from August 2, 2026. High-risk system obligations under Articles 9–15 apply from December 2, 2027, following the EU Digital Omnibus amendment. Recruiter1 is working to complete its compliance obligations, including risk management documentation, human oversight mechanisms, and bias testing. Until full compliance is achieved, human review of AI-assisted assessments is available on a case-by-case basis by contacting [email protected].
GDPR Article 22 rights. Candidates have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. If an AI score materially determines a hiring outcome, you have the right to:
- Obtain human review of the decision
- Express your point of view about the decision
- Contest the decision and request a re-evaluation
- Receive meaningful information about the logic involved in the AI assessment
CCPA/CPRA ADMT rights. California residents will have the right to opt out of the use of Automated Decision-Making Technology for significant decisions, and to request human review and an appeal process, once ADMT compliance obligations take effect on January 1, 2027. Until then, human review of AI-assisted assessments is available on request. To exercise these rights, contact [email protected].
Human review process. Upon request, a qualified human reviewer will re-evaluate the AI-assisted assessment within a reasonable timeframe. The reviewer has the authority and competence to override the AI output. You will be notified of the outcome and the reasoning behind the human review decision.
Bias testing commitment. Recruiter1 is committed to conducting and documenting bias testing of its AI systems in accordance with EU AI Act Article 9(2)(d) and Article 15. Bias testing results and methodology will be made available to competent authorities upon request.
Recruiter1 operates a first-party analytics system that tracks engagement on candidate portals shared with hiring managers. This system collects:
- Portal views, candidate views, and candidate clicks
- Chat activity (opened, messages sent, AI queries)
- Visitor identifiers and session identifiers
- Device type (desktop, mobile, tablet)
- Referrer URL and UTM campaign parameters (source, medium, campaign)
- Time on page and scroll depth
- Hiring manager lead capture data (name, email, company, role) when voluntarily provided
- Chat SLA metrics (connection status, response times)
This data is stored in our caching layer and used to provide agencies with portal engagement metrics, hiring manager lead scoring, and aggregate analytics. It is not shared with third parties or used for cross-site tracking.
No third-party analytics. We do not use Google Analytics, Meta Pixel, or any third-party analytics or tracking SDKs. All analytics are processed in-house.
We retain personal data only as long as necessary for the purposes described in this policy, or as required by law. Specific retention periods:
- Active accounts: Duration of the customer relationship + 90 days post-termination
- Candidate resumes and profiles: 2 years after last activity
- Chat messages and communications: 1 year after last message
- AI usage metadata and audit logs: 3 years (compliance and security)
- Billing and payment records: 3–7 years depending on applicable tax law requirements
- Platform analytics data: 12 months
- Push notification tokens: Until subscription is cancelled or device unregistered
- Security incident logs: 3 years
After the retention period, data is deleted or anonymized. You may request earlier deletion by exercising your rights under Section 14 or 15.
Your personal data may be transferred to and processed in countries outside your jurisdiction, including the United States (where OpenRouter, OpenAI, Stripe, Resend, and hosting providers are located). These transfers are made under appropriate safeguards:
- Standard Contractual Clauses (SCCs) — Module 2 (Controller-to-Processor) for EU-to-US transfers
- UK International Data Transfer Addendum for UK-to-US transfers
- Sub-processor-specific DPAs where available (e.g., Stripe DPA, OpenAI DPA)
We monitor regulatory developments regarding international data transfers (including the EU-US Data Privacy Framework) and update our transfer mechanisms as required.
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:
- Encryption in transit (TLS 1.2+) for all network communications
- Encryption at rest for sensitive data including messages, credentials, and recovery materials
- HttpOnly, SameSite cookies for authentication
- CSRF protection on selected authenticated state-changing requests
- End-to-end encryption (E2EE) for candidate signal messages
- Passkey-based authentication (WebAuthn) available alongside traditional password authentication
- Role-based access control with least-privilege principles
- Rate limiting on selected sensitive API endpoints
- Audit logging for administrative actions
For security vulnerability reports, see our security.txt.
In the event of a personal data breach, we will notify the relevant supervisory authority without undue delay, and where feasible within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will communicate the breach to affected data subjects without undue delay, in accordance with GDPR Article 34. Notification will include the nature of the breach, the likely consequences, and the measures taken or proposed.
We will also notify affected customers and the relevant supervisory authority where required by law.
If you are in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under GDPR:
- Right of access (Art. 15): Request a copy of your personal data.
- Right to rectification (Art. 16): Correct inaccurate or incomplete data.
- Right to erasure (Art. 17): Request deletion of your personal data, subject to legal exceptions.
- Right to restrict processing (Art. 18): Limit how we process your data.
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interests.
- Right regarding automated decisions (Art. 22): See Section 07 for details on human review and contest rights.
- Right to withdraw consent: Withdraw consent for marketing or push notifications at any time.
To exercise these rights, contact [email protected]. We respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know: Request disclosure of the categories and specific pieces of personal data we collect, the purpose of collection, and the third parties with whom we share it.
- Right to delete: Request deletion of your personal data, subject to legal exceptions.
- Right to correct: Request correction of inaccurate personal data.
- Right to opt-out of sale or sharing: We do not sell personal data. We do not share personal data for cross-context behavioral advertising. No opt-out is necessary.
- Right to limit use of sensitive data: Request that we limit use of sensitive personal information to what is necessary for providing the Service.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
- ADMT rights: See Section 07 for automated decision-making opt-out and human review rights.
To exercise these rights, contact [email protected]. We respond within 45 days, which may be extended by an additional 45 days where permitted by CCPA. You may also designate an authorized agent to submit requests on your behalf.
Global Privacy Control (GPC): We honor GPC signals as a request to opt out of sale or sharing. Since we do not sell or share personal data, GPC has no effect on your Service experience.
The Service is not directed to children under 18, and we do not knowingly collect personal data from individuals under 18. If you believe we have collected personal data from a minor, please contact [email protected] and we will promptly delete it.
We may update this Privacy Policy from time to time. We will notify users of material changes by posting the updated policy on this page and, where feasible, sending an email notification and displaying an in-app banner at least 30 days before the changes take effect.
Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy, please contact us at [email protected].
For AI Act and automated decision-making requests: [email protected]
For data subject access requests: [email protected]
This page was last updated on July 10, 2026 and is currently under review by Recruiter1 and pending engagement of outside counsel. The terms below apply to your use of the Service. If you have questions about a specific provision, contact [email protected].