Privacy Policy
Hire HRAI Oy
Last updated: December 13, 2024
1 Introduction
This Privacy Policy explains how Hire HRAI Oy ("Hire HRAI", "we", "us", or "our") collects, uses, stores, and protects personal data in connection with the use of our platform and related services ("Service").
We are committed to processing personal data responsibly, transparently, and in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act.
This Policy applies to:
- Visitors to our website;
- Registered users and customers (employers and recruiters); and
- Job applicants ("Candidates") whose information is processed through the platform.
Separate agreements, such as our Data Processing Agreement (DPA), govern how we process data on behalf of our business customers.
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2 Data Controller and Contact Information
For personal data collected directly by Hire HRAI (e.g., user accounts, billing, analytics, communication), the data controller is:
- Hire HRAI Oy
- Business ID: 3576626-8
- Registered address: Takomotie 14 C 36 00380 Helsinki, Finland
- Email: support@hirehrai.com
- Website: www.hirehrai.com
For personal data processed on behalf of customers (such as candidate data uploaded to the platform), the customer acts as the data controller, and Hire HRAI Oy acts as the data processor under the applicable Data Processing Agreement (DPA).
If you have questions or wish to exercise your data protection rights, you can contact us at the address above.
3 What Personal Data We Collect
Depending on how you interact with the Service, we may collect and process the following categories of personal data:
Customer and User Data
- Name, email address, and contact details;
- Company name, department, and role;
- Account login credentials (hashed passwords);
- Billing and payment information;
- Communication history and support requests.
Candidate Data (uploaded by customers)
- Application documents (CV, cover letter, portfolio);
- Professional history, education, and skills;
- Assessment results and scores generated by the Service;
- Feedback or notes added by employer users.
Technical and Usage Data
- IP address, browser type, operating system, and device identifiers;
- Log files, analytics data, and usage statistics;
- Cookies or similar tracking technologies (see Cookie Policy).
We do not intentionally collect sensitive personal data (such as health information or political opinions).
4 How We Collect Data
We collect personal data through the following methods:
- Directly from you – when you create an account, fill in forms, contact us, or use features of the Service;
- From Customers – when employer organizations upload candidate information or evaluation data to the platform;
- Automatically – when you interact with our website or platform, via cookies, analytics, and system logs;
- From third-party service providers – for payment processing, email delivery, or analytics, always in accordance with this Policy and applicable law.
All data is collected for specific and lawful purposes and is never sold or shared for advertising use.
5 Legal Basis for Processing
Hire HRAI processes personal data based on one or more of the following legal grounds under Article 6 of the GDPR:
- Performance of a contract – to provide the Service, manage user accounts, and deliver features in accordance with the Terms and Conditions;
- Legitimate interest – to maintain and improve the Service, ensure security, prevent misuse, and communicate relevant updates to users;
- Legal obligation – to comply with accounting, tax, or regulatory requirements;
- Consent – for specific optional features (e.g., newsletters, cookies, or marketing communication). Consent may be withdrawn at any time;
- Processing on behalf of customers – when acting as a data processor under a Data Processing Agreement.
6 How We Use Personal Data
We use personal data only for clearly defined and lawful purposes. Depending on your relationship with Hire HRAI, your data may be used for:
Service Delivery
- Creating and managing user accounts;
- Enabling access to platform features and tools;
- Processing candidate data for recruitment analytics on behalf of Customers;
- Providing customer support and technical assistance.
Service Improvement and Communication
- Monitoring platform performance and usage patterns;
- Improving product functionality and user experience;
- Communicating important updates, service changes, or policy revisions;
- Sending optional marketing messages (only with consent).
Security and Compliance
- Detecting, preventing, and addressing fraud or abuse;
- Ensuring compliance with applicable laws and contractual obligations;
- Fulfilling accounting and legal recordkeeping requirements.
We do not use personal data for automated decision-making that produces legal or similarly significant effects without human involvement.
7 Data Sharing and Transfers
We share personal data only when necessary to provide and operate the Service:
Service Providers
We may share limited data with trusted third-party vendors who assist in hosting, analytics, payment processing, or email delivery. Each provider processes data only under our instruction and is bound by strict confidentiality and data protection obligations.
Legal and Compliance Obligations
We may disclose data when required by law, court order, or governmental authority, but only to the extent necessary and with prior notice to the affected party when legally permissible.
International Data Transfers
If personal data is transferred outside the European Economic Area (EEA), such transfers are protected by appropriate safeguards — including Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent mechanisms ensuring GDPR-level protection.
Hire HRAI does not sell or rent personal data to third parties under any circumstances.
8 Cookies and Analytics
Our website and platform use cookies and similar technologies to ensure proper functionality, improve performance, and analyze usage trends.
Types of cookies used:
- Essential Cookies: Required for the core functionality of the website, including secure login, session management, and accessibility. These cookies cannot be disabled in our systems.
- Analytics Cookies: Help us understand how visitors interact with our website by collecting and reporting information anonymously. These cookies allow us to count visits and traffic sources so we can measure and improve site performance.
- Personalization Cookies: Enable the website to remember user choices and preferences (such as language, interface settings, or saved filters) to provide a more personalized experience.
- Marketing Cookies: Used to track visitors across websites to display relevant advertisements and build a profile of user interests. These cookies may be set by our advertising partners.
Users can manage or disable cookies via their browser settings. Certain features of the Service may not function properly if cookies are disabled.
We may use privacy-focused analytics tools (e.g., Plausible, Matomo, or equivalent GDPR-compliant providers). No data is shared with external advertising networks.
9 Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this Policy or to comply with legal obligations.
Retention periods:
- User account data: retained while the account is active and up to 12 months after termination, unless deletion is requested earlier;
- Candidate data (uploaded by customers): retained according to the Customer's instructions under the Data Processing Agreement;
- Billing and contractual records: retained for up to six (6) years in accordance with accounting laws;
- Technical logs and analytics data: retained for a limited operational period (typically up to 12 months).
After the retention period expires, data is securely deleted or anonymized.
10 Data Security
Hire HRAI implements appropriate technical and organizational measures (TOMs) to protect personal data against unauthorized access, loss, alteration, or destruction.
These include:
- Encryption of data in transit and at rest;
- Secure authentication and access controls;
- Regular backups and integrity monitoring;
- Role-based permissions for employees;
- Staff confidentiality obligations and data protection training;
- Ongoing security testing and vulnerability management.
Access to personal data is strictly limited to authorized personnel who need it to perform their duties.
In the event of a personal data breach, we will notify affected Customers and relevant supervisory authorities in accordance with Articles 33 and 34 of the GDPR.
11 Your Rights as a Data Subject
Under the EU General Data Protection Regulation (GDPR), individuals have specific rights regarding their personal data. Depending on your relationship with Hire HRAI and applicable law, you have the right to:
- Access – Request confirmation of whether we process your personal data and obtain a copy of such data;
- Rectification – Request correction of inaccurate or incomplete information;
- Erasure ("Right to be Forgotten") – Request deletion of your data where it is no longer needed or where consent is withdrawn;
- Restriction of Processing – Request that we limit the use of your data under certain circumstances;
- Data Portability – Receive your personal data in a structured, commonly used format and transmit it to another controller;
- Objection – Object to the processing of your data based on legitimate interests or for direct marketing purposes;
- Withdraw Consent – Withdraw previously given consent at any time without affecting the lawfulness of processing prior to withdrawal.
Requests can be made by contacting privacy@hirehrai.com. We may need to verify your identity before responding to a request.
If you believe that your rights have been violated, you have the right to lodge a complaint with your local supervisory authority. In Finland, this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto).
12 Children's Privacy
Hire HRAI is a business-to-business (B2B) service designed for professional recruitment use and is not intended for individuals under the age of 16.
We do not knowingly collect or process personal data from minors. If we become aware that personal data from a child has been collected inadvertently, we will delete such data promptly.
Parents or guardians who believe that a child's data has been provided to us are encouraged to contact privacy@hirehrai.com.
13 Updates to this Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, legal obligations, or the functionality of our Service.
When significant updates are made, we will post a clear notice on our website and update the "Last Updated" date at the top of this document. If required by law, we will also notify affected users directly or seek renewed consent when necessary.
We encourage all users to review this Policy regularly to stay informed about how we protect personal data.
14 Contact Information
If you have questions about this Privacy Policy, our data protection practices, or your rights, you may contact us at:
- Hire HRAI Oy
- Business ID: 3576626-8
- Registered address: Takomotie 14 C 36 00380 Helsinki, Finland
- Email: support@hirehrai.com
- Website: www.hirehrai.com