This Acceptable Use Policy ("Policy") sets out what customers, their users and anyone else who accesses the Hireall platform (the "Service") may and may not do with it. It forms part of the Terms of Service; capitalised terms have the meaning given there. Hireall Technology Ltd ("Hireall") may suspend or terminate access that breaches this Policy, as described in the Terms.
The short version. Post real jobs, treat candidates and their data lawfully and fairly, message people only with a proper basis and a working opt-out, keep humans in charge of hiring decisions, and do not attack or overload the platform. If you see abuse, tell us at legal@hireall.com.
01Lawful and fair hiring
- Use the Service only for genuine recruitment and related people processes of your organisation, or of a client you are authorised to recruit for.
- Comply with the employment, equal-opportunity, anti-discrimination and pay-transparency laws that apply where you hire, including obligations to state pay or a pay range in job posts, not to ask candidates about salary history, to use gender-neutral job titles and language, and to provide reasonable accommodation to candidates with disabilities during your process.
- Do not set requirements or screening criteria that discriminate on protected grounds (such as sex, age, race or ethnicity, nationality, religion or belief, disability, pregnancy or family status, marital status, sexual orientation, trade-union membership or, where protected, military status), or that act as proxies for them. The platform supports this: an automation rule conditioned on gender, nationality, military-service or smoking status may add a note or calculate a score on its own, but every step that would move the candidate, send a message, invitation or assessment, or make an offer waits for a person to confirm it for that candidate. A person's confirmation does not make a discriminatory criterion lawful: use these fields only where the law permits it for the role. Nationality is not a substitute for a right-to-work check; where such a check is legally required, run it as a separate, purpose-specific step and record only its outcome.
- Do not use the Service to recruit for unlawful work, unpaid work that must be paid under applicable law, or roles that require candidates to pay a fee.
02Candidate data and privacy
- Have a lawful basis for every processing activity, give candidates a privacy notice that describes it accurately, and obtain consent where the law requires, for example before keeping a candidate in a talent pool for future roles where consent is required.
- Use the sourced-candidate notice and personal privacy page the Service provides; do not re-import a candidate who has objected.
- Collect only the data you need for the role. Do not request or store special-category or otherwise sensitive data (health, biometric, religious, political, trade-union, sexual-orientation or criminal-record information) except in fields the Service provides for that purpose and only where you have a lawful basis. Candidate document verification records the type of check, its outcome and, where the Candidate supplies one, a reference; where you ask for a document, it also holds the file the Candidate uploads until the purge date you set. Ask for a criminal-record or fitness-for-work document only where the law allows it for the role, and only through the consent box the Service shows the Candidate: you must not make that consent a condition of applying, of being considered or of completing the check, and you must accept a reference number or a declaration instead. Tell Candidates to cover over anything on a document you do not need. The risk flag produced by the automatic check is a prompt to look, not a finding: you must not reject a Candidate, or treat a document as false, on that flag alone.
- Do not upload protected health information regulated by HIPAA or similar laws.
- User accounts for people acting on behalf of an employer are restricted to individuals aged 18 or over. Do not create or authorise a User account for anyone under 18. Hireall does not knowingly maintain individuals under 18 as contacts for its own marketing.
- These restrictions do not prohibit the lawful processing of personal data about Candidates under 18, including applications for internships, apprenticeships or entry-level roles. Customer must ensure that the recruitment and processing comply with applicable age and employment requirements, provide appropriate privacy information, establish a lawful basis and obtain parental or guardian consent where required. Collect only the data necessary for the lawful recruitment purpose. Hireall processes such Candidate data on Customer's documented instructions under the DPA. Youthall's separate age requirements apply to Youthall candidate accounts.
- Configure roles so that people see only what their job requires, decide how long you keep data (video-interview recordings are deleted after the retention period of your plan; other records stay until deleted), export data you no longer need and instruct us in writing to delete it; individual Candidate records and whole jobs are deleted by Hireall on your instruction (normally within five business days, at the latest within 30 days, and always within any shorter period the law or a Candidate's request requires) — there is no self-service delete button, so plan requests accordingly.
- Do not use candidate data for purposes unrelated to your recruitment process, share it with third parties without a lawful basis, or combine it with data from other sources to build profiles beyond what the role requires.
03Job posting standards
- Every posting must describe a real, currently open position with your organisation or your client, one position per posting, with an accurate title, location, work mode and, where required, pay range.
- Do not post multi-level-marketing or commission-only schemes presented as employment, "opportunities" that require the candidate to buy something, training sold as a job, or postings intended mainly to collect data or drive traffic elsewhere.
- Do not include content that is misleading, defamatory, obscene, hateful or infringing, or that impersonates another organisation.
- Job boards and aggregators apply their own standards; a posting that breaches them may be rejected by the channel without liability for Hireall. Hireall may remove or unpublish a posting that breaches this Policy, giving notice where practicable.
04Candidate communications: e-mail
- Send e-mail through the Service only to candidates who applied to you, were referred to you, were added to your talent pool with a proper basis, or otherwise consented to hear from you.
- Identify your organisation clearly in every message, do not use misleading subject lines, and keep the content related to the recruitment process. Do not use the Service to send newsletters, promotions or other marketing.
- Honour opt-outs and objections promptly; do not message a candidate who has withdrawn their application or asked not to be contacted.
- Do not upload purchased or scraped contact lists. Bulk sends are limited to candidates in your own pipelines and pools, and Hireall may impose sending limits or pause sends that generate unusual bounce or complaint rates.
05AI features
- Use AI outputs (match scores, parsed profiles, search results, drafts) as advisory input reviewed by a qualified person. Do not configure processes in which a candidate is rejected, refused or otherwise adversely affected on the basis of an AI output without human review. Automation rules that use an AI score may move candidates between stages and send the messages or invitations you attach to those steps on their own; the Service asks a person before such a rule moves a candidate to the rejected or an offer stage or creates an offer. You remain responsible for reviewing the candidates such rules do not advance, and you must not use a rule, or any workaround such as a stage or message that stands in for a rejection, to turn candidates down by score without human review.
- If you record your own employees as internal talent, tell them before you do it, keep what you record accurate and up to date, and give them a way to correct it. Do not use a readiness figure or a career-compass summary as the sole basis for a decision about a promotion, an assignment, pay or a person's continued employment, and do not treat either as a performance rating. Do not record or assess employees you are not actually considering for a role, and do not use the feature to build a performance, potential or succession ranking of your workforce.
- Where you have a message to a candidate drafted or rewritten for you, read it before you send it. You are the sender and you are responsible for what it says, including any date, commitment or reason it contains. Do not paste a candidate's personal details into the request, and never paste special-category data such as health, criminal-record or trade-union information: write the request so that the placeholders the Service fills in supply the candidate's name and the role.
- Do not use AI features to infer, estimate or filter on protected characteristics, or to circumvent the fairness rules built into them, for example by describing a protected characteristic indirectly in a search.
- Do not submit prompts designed to make the models ignore their instructions, produce discriminatory output, or reveal system instructions or other customers' data.
- Do not use AI features, inputs or outputs to develop, train or benchmark a competing product.
- Where the law requires, tell candidates that AI tools assist your process, provide the notices and assessments required in your jurisdiction, and offer human review on request. See the AI Transparency Notice.
06Security and integrity of the Service
- Keep credentials confidential; one person, one login. Enable two-step verification where available — an authenticator application in preference to e-mail codes — keep the recovery codes issued to you somewhere safe, and remove access for people who leave your organisation.
- Do not attempt to access other customers' data or areas of the Service you are not authorised to use, and do not probe, scan or test the Service for vulnerabilities without our prior written permission. Report suspected vulnerabilities to security@hireall.com; we welcome responsible disclosure and will not take action against researchers who act in good faith.
- Do not upload malware, run automated scripts that scrape the Service, or interfere with its operation, monitoring or metering.
- Do not circumvent usage limits, Credit metering, feature restrictions or the consent tools shown to candidates.
07API and automation
- Where an API is available, keep API keys confidential, respect rate limits and use the API only to move data between the Service and your own systems for your recruitment process.
- Do not use the API or automation to bulk-export candidate data for purposes unrelated to hiring, to resell or provide the Service to third parties, or to build a substitute for the Service.
- Integrations you connect must comply with the terms of the third-party service and with this Policy.
08Content standards
- Content you or your Users publish through the Service (job posts, career pages, messages, documents) must not be unlawful, defamatory, harassing, hateful or discriminatory, must not infringe intellectual property or privacy rights, and must not contain malicious code.
- Use the Hireall name and logo only as displayed by the Service or as permitted in writing; do not suggest that Hireall endorses your organisation or vets your postings.
09Enforcement
Hireall may investigate suspected violations and, depending on severity, ask you to correct the issue, remove or unpublish content, restrict a feature (such as bulk e-mail or AI features), suspend an Account or terminate the agreement, as set out in the Terms of Service. We give notice where practicable and act without notice where necessary to protect candidates, other customers or the Service. Where the law requires, we may report violations to authorities.
To report abuse of the Service by a customer, write to legal@hireall.com. Candidates who believe their data has been misused can also write to privacy@hireall.com.
10Changes to this Policy
We update this Policy when the Service, carrier requirements or the law change. Material changes are notified in the same way as changes to the Terms of Service. The date at the top shows the latest revision.