Privacy Policy
Last updated: 20 April 2026
This policy explains how Hirleo collects, uses, and protects your personal data when you use our platform. We are committed to transparency and to upholding your rights under the UK GDPR and EU GDPR.
1. Data Controller
Hirleo ("we", "us", "our") is the data controller responsible for your personal data. If you have questions about this policy or wish to exercise your rights, contact us at privacy@hirleo.com. Company details: Hirleo Ltd, United Kingdom.
2. What Data We Collect
- Account data: Name, email address, phone number, and password hash when you register.
- Profile data: Job titles, CV text, location, subscription status, and preferences you provide.
- Application data: CV files, answers to screening questions, salary expectations, and availability submitted when applying for jobs.
- Usage data: Pages visited, features used, time spent, and device/browser information collected via analytics cookies (with your consent).
- Communications: Emails and messages you send us for support or enquiries.
- Payment data: Payment is processed by Stripe. We do not store card numbers — only a subscription status and Stripe customer ID.
3. Legal Basis for Processing (GDPR)
- Contract (Art. 6(1)(b)): Processing your account, application, and payment data is necessary to provide the service you signed up for.
- Legitimate interests (Art. 6(1)(f)): Security, fraud prevention, product improvement, and direct marketing to existing customers.
- Consent (Art. 6(1)(a)): Analytics cookies (Google Analytics). You may withdraw consent at any time via the cookie banner or by contacting us.
- Legal obligation (Art. 6(1)(c)): Retaining financial records as required by law.
4. How We Use Your Data
- Providing the service: Creating your account, processing job applications, running AI match analysis, and managing your subscription.
- Communications: Sending transactional emails (OTP codes, application status updates) and, where you have opted in, product updates.
- AI features: CV text is sent to OpenAI's API to extract contact details and calculate a job-match score. No data is used to train OpenAI models per our data processing agreement.
- Analytics: With your consent, Google Analytics is used to understand page usage and improve the product. IP addresses are anonymised.
- Security: Detecting and preventing fraud, abuse, and unauthorised access.
6. Data Retention
- Active accounts: Data is retained for as long as your account is active.
- Deleted accounts: Account data is deleted within 30 days of account deletion, except where retention is required by law.
- Job applications: Application data (including CVs) is retained for up to 2 years to allow hiring teams to revisit candidates, unless you request earlier deletion.
- Financial records: Retained for 7 years as required by UK tax law.
- Analytics data: Aggregated and anonymised — no individual retention limit.
7. International Data Transfers
Some of our service providers (e.g. OpenAI) are based in the United States. We ensure such transfers comply with UK/EU data protection law through Standard Contractual Clauses (SCCs) or equivalent safeguards. You can request details of the specific safeguards by contacting privacy@hirleo.com.
8. Your Rights Under GDPR
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct inaccurate or incomplete data.
- Erasure: Request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
- Restriction: Ask us to restrict processing of your data in certain circumstances.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests, including direct marketing.
- Withdraw consent: Withdraw cookie consent at any time. This does not affect the lawfulness of processing before withdrawal.
To exercise any right, email privacy@hirleo.com. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or your local EU supervisory authority.
10. Children's Privacy
Hirleo is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us immediately.
11. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes by email or by displaying a prominent notice on the site. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact Us
For any privacy-related queries, data subject requests, or complaints: Email: privacy@hirleo.com Address: Hirleo Ltd, United Kingdom
Questions about your data?
Our team will respond to all data requests within 30 days.
Contact privacy@hirleo.com