Legal
Privacy Policy
Effective date: 1 May 2025 · HireIQ · Fajikunda, The Gambia
This Privacy Policy explains how HireIQ ("HireIQ", "we", "us") collects, uses, stores, and discloses personal data when you use our platform at hireiq.app (the "Service"). By using the Service, you agree to the practices described in this Policy.
1. Who We Are
HireIQ operates HireIQ, a hiring platform that helps employers conduct structured screening interviews, evaluate applicants, and make hiring decisions. The Service is used by two distinct groups: employers (companies that post jobs and review candidates) and candidates (individuals who apply to those jobs).
For the purposes of applicable data protection law, HireIQ acts as a data controller in respect of employer account data and as a data processor on behalf of employers in respect of candidate data. Employers are responsible for their own compliance obligations as data controllers for candidate data.
2. Data We Collect
2.1 Employer Account Data
When a company creates an account, we collect:
- ▸Company name, email address, and password (hashed, never stored in plaintext)
- ▸Company profile details: industry, size, website URL, logo URL
- ▸Billing contact information if you upgrade to a paid plan
- ▸IP address, browser type, and session data for security and abuse prevention
- ▸Platform usage data: pages visited, features used, timestamps of actions
2.2 Candidate Data
When candidates apply to jobs posted on HireIQ, we collect data on behalf of the hiring employer. This may include:
- ▸Full name, email address, phone number, and other contact details
- ▸Date of birth, nationality, current location (if requested by the employer)
- ▸Employment history, education history, and professional background
- ▸Uploaded documents: CV/résumé, cover letter, certificates, portfolio files
- ▸Profile links: LinkedIn, GitHub, Dribbble, personal website
- ▸AI interview transcript, the complete verbatim record of the candidate's responses to AI-generated screening questions
- ▸Derived assessments: overall score, per-dimension score breakdown, hiring recommendation, red flags analysis, and engagement metrics
- ▸Voluntary diversity data (ethnicity, gender identity, disability status, veteran status), only if the employer has enabled this and only where permitted by law
2.3 Technical and Usage Data
- ▸Authentication tokens and session identifiers
- ▸Server access logs (IP address, request timestamps, HTTP status codes)
- ▸Error logs for debugging and platform stability
3. How We Use Your Data
| Data Type | Purpose | Retention |
|---|---|---|
| Employer account data | Authenticate your account, deliver the platform, send notifications, and provide support | For the life of the account, plus 90 days after deletion |
| Candidate interview data | Power the AI interview, generate scores and reports, deliver results to the hiring employer | As configured by the employer (default 365 days from completion) |
| Uploaded documents | Display to the hiring employer, extract text for AI analysis | Same retention period as interview data |
| Voluntary DEI data | Provide aggregate diversity reporting to the employer; never used in scoring | Same retention period as interview data |
| Usage analytics | Improve the platform, detect abuse, inform product decisions | 24 months, then aggregated/anonymised |
| Security/access logs | Detect and investigate security incidents | 90 days |
We do not sell personal data to third parties. We do not use candidate data to train our own AI models without explicit consent.
4. AI Processing of Candidate Data
HireIQ uses AI language models (currently Groq-hosted LLaMA 3) to conduct candidate screening conversations and generate assessment reports. When a candidate interacts with the platform:
- ▸Their responses are transmitted to Groq's API for real-time inference. Groq's data processing terms apply. Groq does not train models on API payloads.
- ▸AI-generated scores, recommendations, and red-flag analyses are stored in our database and made available to the hiring employer only.
- ▸Candidates may be flagged if the system detects patterns consistent with AI-generated responses. This forms part of the Red Flags Report visible to the employer.
- ▸No automated hiring decision is made solely by the AI. All final hiring decisions remain with the employer.
5. Data Storage and Security
All data is stored on Supabase-managed PostgreSQL databases hosted in the European Union (eu-central-1 region). Uploaded files are stored in Supabase Storage (same region). We implement the following security measures:
- ▸All data in transit is encrypted using TLS 1.2 or higher
- ▸All data at rest is encrypted using AES-256
- ▸Access to production databases is restricted by role and IP allowlist
- ▸Passwords are hashed using bcrypt via Supabase Auth, plaintext passwords are never stored
- ▸Authentication tokens are short-lived JWTs; refresh tokens are stored securely
- ▸Row-level security policies enforce company-level data isolation
Despite these measures, no system is perfectly secure. We will notify affected parties of material data breaches in accordance with applicable law.
6. Third-Party Data Sharing
We share data only in the following limited circumstances:
- ▸Supabase (database, authentication, file storage), EU-hosted, GDPR-compliant
- ▸Groq (AI inference API), candidate responses are sent for real-time processing; Groq does not retain inputs after inference
- ▸Render (backend hosting), receives encrypted traffic to our API; no direct database access
- ▸Vercel (frontend hosting), serves the web application; does not receive personal data beyond anonymised request logs
- ▸Legal and regulatory bodies, when required by law, court order, or to protect our legal rights
We do not share personal data with advertisers, data brokers, or other employers on the platform.
7. Data Retention
- ▸Employer accounts: Data is retained for the life of the account. After account deletion, data is purged within 90 days.
- ▸Candidate data: Retained for the period configured by the employer (default: 365 days from application completion). At the end of this period, data is automatically deleted from our systems.
- ▸Uploaded files: Retained for the same period as the interview record. When the interview is deleted, associated files are removed from storage.
- ▸AI assessments: Retained as part of the interview record; deleted when the interview record is deleted.
- ▸Anonymised analytics: May be retained indefinitely in aggregated form.
8. Candidate Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- ▸Right of access: Request a copy of the data held about you
- ▸Right to rectification: Request correction of inaccurate data
- ▸Right to erasure: Request deletion of your data, subject to the employer's legal obligations
- ▸Right to restriction: Request that processing be limited in certain circumstances
- ▸Right to data portability: Receive your data in a structured, machine-readable format
- ▸Right to object: Object to processing based on legitimate interests
To exercise any of these rights, contact us at privacy@hireiq.app. We will respond within 30 days. Note that because HireIQ acts as a processor for candidate data on behalf of employers, some requests may need to be directed to the hiring company.
10. Children's Data
The HireIQ platform is intended for use by adults aged 18 and over. We do not knowingly collect personal data from individuals under 18. If you believe a minor has submitted data through the platform, contact us immediately at privacy@hireiq.app and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by posting a notice on the platform or sending an email to registered account holders at least 14 days before the change takes effect. Your continued use of the Service after that date constitutes acceptance of the revised Policy.
12. Contact Us
For privacy-related questions, data subject requests, or to report a concern: