GDPR Compliant

Privacy Policy

Last updated: 20 April 2026

This policy explains how Hirleo collects, uses, and protects your personal data when you use our platform. We are committed to transparency and to upholding your rights under the UK GDPR and EU GDPR.

1. Data Controller

Hirleo ("we", "us", "our") is the data controller responsible for your personal data. If you have questions about this policy or wish to exercise your rights, contact us at privacy@hirleo.com. Company details: Hirleo Ltd, United Kingdom.

2. What Data We Collect

  • Account data: Name, email address, phone number, and password hash when you register.
  • Profile data: Job titles, CV text, location, subscription status, and preferences you provide.
  • Application data: CV files, answers to screening questions, salary expectations, and availability submitted when applying for jobs.
  • Usage data: Pages visited, features used, time spent, and device/browser information collected via analytics cookies (with your consent).
  • Communications: Emails and messages you send us for support or enquiries.
  • Payment data: Payment is processed by Stripe. We do not store card numbers — only a subscription status and Stripe customer ID.

4. How We Use Your Data

  • Providing the service: Creating your account, processing job applications, running AI match analysis, and managing your subscription.
  • Communications: Sending transactional emails (OTP codes, application status updates) and, where you have opted in, product updates.
  • AI features: CV text is sent to OpenAI's API to extract contact details and calculate a job-match score. No data is used to train OpenAI models per our data processing agreement.
  • Analytics: With your consent, Google Analytics is used to understand page usage and improve the product. IP addresses are anonymised.
  • Security: Detecting and preventing fraud, abuse, and unauthorised access.

5. Who We Share Data With

  • OpenAI: CV text is processed to provide AI parsing and match scoring. Processed under a data processing agreement with no model training.
  • Google Analytics: Anonymised usage data, with your consent only.
  • Stripe: Payment processing for Pro subscriptions.
  • Cloud infrastructure: Hosting providers (servers, databases) under EU or UK standard contractual clauses where applicable.
  • Legal authorities: Only when required by law or to protect our legal rights.

We do not sell your personal data to third parties.

6. Data Retention

  • Active accounts: Data is retained for as long as your account is active.
  • Deleted accounts: Account data is deleted within 30 days of account deletion, except where retention is required by law.
  • Job applications: Application data (including CVs) is retained for up to 2 years to allow hiring teams to revisit candidates, unless you request earlier deletion.
  • Financial records: Retained for 7 years as required by UK tax law.
  • Analytics data: Aggregated and anonymised — no individual retention limit.

7. International Data Transfers

Some of our service providers (e.g. OpenAI) are based in the United States. We ensure such transfers comply with UK/EU data protection law through Standard Contractual Clauses (SCCs) or equivalent safeguards. You can request details of the specific safeguards by contacting privacy@hirleo.com.

8. Your Rights Under GDPR

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Ask us to correct inaccurate or incomplete data.
  • Erasure: Request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
  • Restriction: Ask us to restrict processing of your data in certain circumstances.
  • Portability: Receive your data in a structured, machine-readable format.
  • Objection: Object to processing based on legitimate interests, including direct marketing.
  • Withdraw consent: Withdraw cookie consent at any time. This does not affect the lawfulness of processing before withdrawal.

To exercise any right, email privacy@hirleo.com. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or your local EU supervisory authority.

9. Cookies

  • Essential cookies: Session tokens and authentication cookies necessary for the service to function. No consent required.
  • Analytics cookies (_ga, _gid): Set by Google Analytics to measure page views and user journeys. Only active after you click "Accept all" in our cookie banner.

You can change your cookie preferences at any time by clearing the banner choice in your browser's local storage, or by contacting us.

10. Children's Privacy

Hirleo is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us immediately.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes by email or by displaying a prominent notice on the site. The "Last updated" date at the top of this page reflects the most recent revision.

12. Contact Us

For any privacy-related queries, data subject requests, or complaints: Email: privacy@hirleo.com Address: Hirleo Ltd, United Kingdom

Questions about your data?

Our team will respond to all data requests within 30 days.

Contact privacy@hirleo.com