Privacy Policy
Effective date: January 1, 2025
At Hireflow, we take your privacy seriously. This policy explains what data we collect, how we use it, and the rights you have over your personal information.
1. Information We Collect
We collect information you provide directly to us and information generated as you use the Hireflow platform. This includes:
Information you provide:
- Account registration details (name, email address, password)
- Profile and application information (resume, cover letter, work history)
- Communications you send to us or through the platform
- Responses to assessments or screening questions
Information collected automatically:
- Log data (IP address, browser type, pages visited, timestamps)
- Device information (operating system, screen resolution)
- Cookie and session data (see Cookies section below)
- Usage data (features accessed, actions taken within the platform)
2. How We Use Your Data
We use the information we collect to:
- Create and maintain your account and authenticate your identity
- Match your profile with relevant job opportunities
- Process and manage your job applications
- Communicate application status updates and notifications
- Facilitate communication between candidates and hiring teams
- Improve and personalize the Hireflow platform
- Monitor for fraud, abuse, and security threats
- Comply with applicable legal obligations
- Send you relevant updates (you may opt out at any time)
We do not use your personal data to make fully automated hiring decisions. All application reviews involve human judgment.
3. Legal Basis for Processing
Where applicable under data protection law (including the GDPR), we process your personal data on the following legal bases:
- Contract performance — to provide the services you've signed up for
- Legitimate interests — for fraud prevention, security, and platform improvement
- Legal obligation — where required by law
- Consent — for marketing communications (which you may withdraw at any time)
4. Data Sharing
We do not sell your personal information. We share your data only in the following limited circumstances:
- Hiring organizations: When you apply for a role, your application details are shared with the relevant hiring team members within that organization.
- Service providers: We use trusted third-party vendors (e.g., cloud hosting, email delivery) who process data on our behalf under strict data processing agreements.
- Legal requirements: We may disclose data when required by law, court order, or government authority.
- Business transfers: In the event of a merger or acquisition, data may be transferred as part of that transaction with appropriate notice to you.
6. Data Retention
We retain your personal data for as long as necessary to provide our services and comply with legal obligations:
- Active accounts: retained for the duration of your account plus 2 years after your last activity
- Job applications: retained for 3 years from the date of submission
- Communications: retained for 2 years from the date of the last exchange
- Log and security data: retained for 12 months
When data is no longer needed, we securely delete or anonymize it. You may request earlier deletion at any time (see Your Rights).
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data (subject to legal obligations)
- Restriction: Request that we limit how we use your data
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Where processing is based on consent, withdraw it at any time
To exercise any of these rights, email us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing your request.
8. Data Security
We implement industry-standard security measures to protect your personal data, including:
- Encryption of data in transit (TLS) and at rest (AES-256)
- Hashed and salted password storage — we never store plaintext passwords
- Role-based access controls limiting who can view candidate data
- Regular security reviews and penetration testing
- Automatic session expiry and secure cookie handling
While we take every reasonable precaution, no system is completely secure. If you suspect a security incident, please contact us immediately at [email protected].
9. Children's Privacy
Hireflow is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us and we will promptly delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a prominent notice on the platform before the changes take effect. The “Effective date” at the top of this page indicates when it was last revised.
Your continued use of Hireflow after the effective date of any changes constitutes your acceptance of the updated policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact our Privacy team:
Hireflow Privacy Team
Email: [email protected]
Address: 123 Recruitment Ave, Nairobi, Kenya
Or use our contact form.
