Hireall Technology ("Hireall", "we", "us", "our") provides applicant tracking software that employers use to publish jobs, receive and review applications, run interviews and assessments, and extend offers. This Privacy Policy explains what personal data we collect, why we process it, who we share it with, how long we keep it and the rights you have. It applies when you visit hireall.com, use the Hireall application as a member of a customer's hiring team, contact our sales or support teams, attend our events, or apply for a job at Hireall.
Applied for a job through Hireall? The employer you applied to decides how your application data is used and is the data controller. Hireall processes that data only on the employer's instructions. Please direct questions and requests about your application to the employer first. Our Candidate Privacy Notice explains how this works and how we help route your request.
01Who we are
For the personal data described in this Policy, Hireall is the data controller under the UK General Data Protection Regulation and the Data Protection Act 2018 ("UK GDPR"), the EU General Data Protection Regulation ("EU GDPR"), the Turkish Personal Data Protection Law No. 6698 ("KVKK") and, where applicable, the California Consumer Privacy Act ("CCPA").
Hireall is affiliated with Youthall, the talent network operated by STJ İnsan Kaynakları Bilişim ve Danışmanlık A.Ş. (Istanbul, Türkiye). Candidates can apply to jobs on Hireall with a Youthall profile and employers can publish jobs to Youthall; the two companies also work together on support, security and product development. Where this Policy refers to sharing with Youthall, it means that company; where Youthall uses data for its own purposes, it does so as a separate controller under its own privacy policy at youthall.com. The integration has a fixed limit, the same one set out in section 13.7 of our Terms of Service: the Candidate records, interview notes, scorecards, internal comments and offers that an employer keeps in Hireall are not used for Youthall's own marketing, are not added to Youthall's talent pool or to any public Youthall profile, and are not made available to other employers.
Our privacy team can be reached at privacy@hireall.com or by post at the address above, marked "Privacy".
02When this Policy applies, and when it does not
Hireall processes personal data in several roles. This Policy covers the situations in which we decide how and why data is processed.
| Situation | Our role | Which document applies |
|---|---|---|
| You visit hireall.com, request a demo, contact sales or support, attend an event or subscribe to our content | Controller | This Privacy Policy and our Cookie Policy |
| You use the Hireall application as a member of a customer's hiring team (a "User") | Controller for your account, security and usage data; processor for the content you and your colleagues place in the Service | This Privacy Policy for account data; the customer's own notices and our Data Processing Agreement for Service content |
| You apply to a job, record a video interview, receive an offer or are added to a talent pool by an employer using Hireall (a "Candidate") | Processor acting on the employer's instructions | The employer's privacy notice and our Candidate Privacy Notice |
| You apply for a job at Hireall | Controller | This Privacy Policy (see the section on recruitment at Hireall) |
Hireall is not a data broker. We do not sell personal data, we do not use Candidate data processed for an employer for our own purposes, and we do not build profiles of Candidates across employers. Where an employer is the controller, our contract with that employer requires us to redirect requests about Candidate data to the employer and to assist the employer in answering them. The rest of this Policy describes the processing for which Hireall itself is the controller; everything we do with Candidate data and other Service content on an employer's behalf (hosting job posts and applications, running hiring pipelines, sending the messages an employer configures, AI analysis the employer requests, exports and deletion) is governed by the employer's instructions, the employer's own legal basis and our Data Processing Agreement.
03Personal data we collect
Data you give us
- Account and profile data — name, work e-mail address, phone number, job title, organisation, profile photo, password (stored as a salted hash) and the role assigned to you by your organisation's administrator.
- Organisation and billing data — company name, registration and tax identifiers, billing address, headcount band, subscription and invoice history. Card details are entered directly with our payment processor, Stripe; we store only Stripe's customer and payment references, never the card number.
- Sales, support and marketing interactions — the content of demo requests, support tickets, survey answers, event registrations and e-mail correspondence.
- Content you place in the Service — job descriptions, pipeline stages, scorecards, interview notes, e-mail templates, automation rules and other material you create. Where this content contains personal data about Candidates, we process it as a processor for your organisation.
Data we collect automatically
- Technical data — IP address, browser type and version, operating system, device identifiers, language and time-zone settings. Inside the application we do not derive a location from the IP address; only the analytics on the public marketing pages does, as described below.
- Usage data — the pages and features you use, recorded in our server logs and in the account audit log (action, time and IP address), the searches you run, referring URLs and error reports. We do not use click-tracking or session-recording tools inside the application.
- Security and audit data — sign-in events, two-step verification events, password changes, exports, permission changes, stage moves and other administrative actions recorded in the audit log that your organisation's administrators can review.
- Contract acceptance records — when you register, start a checkout or activate a paid plan on behalf of your organisation, we record which version of our Terms of Service was accepted, when, by which user account, from which IP address and browser, and whether the annual commitment and early-exit terms were shown; if your organisation enables automatic AI-credit top-ups, we also record which user account gave that authorisation, when, and which version of the authorisation text was accepted. We keep these records for the life of the customer relationship and for six years afterwards as evidence of the contract.
- Cookies and similar technologies — as described in our Cookie Policy.
Data we receive from others
- Your organisation — when an administrator invites you, assigns you a role or updates your details.
- Connected services — when you or your organisation connect Google Workspace or Microsoft 365 calendars, Zoom, Google Meet, Microsoft Teams, Slack, assessment partners or job boards, we receive the data those services return to us under your instruction.
- Youthall — as our affiliate, Youthall may pass us account details of organisations and users who sign up to Hireall through Youthall (a disclosure from STJ in Türkiye, distinct from transfers Hireall makes to Youthall), job posts and applications exchanged between the two platforms when an employer enables that channel, and support or billing information relating to a shared customer.
- Payment and fraud-prevention providers — payment confirmations, chargeback notices and risk signals from Stripe.
- Publicly available business information — company websites and professional profiles that we consult when researching prospective customers, limited to business contact details.
04How we use personal data and our legal bases
Under the UK GDPR and EU GDPR we must have a legal basis for each use of personal data. The table below sets out the purposes for which Hireall is the controller and the bases we rely on. Under KVKK the corresponding processing conditions in Article 5 apply. Our contract is with your organisation, not with you personally, so for your own personal data as a User, billing contact or security contact we rely on our legitimate interest in providing the Service to your organisation and in dealing with the people it has authorised to act for it, rather than on "performance of a contract"; where you contract with us personally as a sole trader, performance of our contract with you applies instead. Processing of Candidate data and other Service content on an employer's instructions is not listed here: the employer determines its legal basis and our Data Processing Agreement governs.
| Purpose | Examples | Legal basis |
|---|---|---|
| Providing the Service to your organisation | Creating and administering User accounts, authenticating Users, applying the roles and permissions your administrator sets, sending account and workflow notifications to Users, providing support to Users | Legitimate interest in providing the Service to the organisation you act for and in serving its authorised Users; performance of a contract where you are our customer personally |
| Billing | Issuing invoices, collecting payment, handling disputes and refunds, keeping accounting records, corresponding with the billing contact your organisation names | Legitimate interest in administering the customer relationship; legal obligation (tax and company law); performance of a contract where you are our customer personally |
| Security and integrity | Detecting and preventing fraud, abuse and unauthorised access; maintaining the audit log; investigating incidents; enforcing our Terms | Legitimate interest in keeping the Service and its data secure; legal obligation |
| Improving the Service | Analysing how features are used, diagnosing errors, testing changes, producing aggregated statistics | Legitimate interest in developing our product; where cookies are involved, your consent |
| Communicating with you | Service announcements, security notices, changes to terms, responses to your requests | Legitimate interest in keeping Users and customer contacts informed; legal obligation where a notice is required by law |
| Marketing | Newsletters, product updates, event invitations, demo follow-ups | Consent where required (including under PECR and KVKK); otherwise our legitimate interest in promoting our Service to business contacts, always with the right to opt out |
| Operating together with Youthall | Receiving applications that Candidates choose to make with a Youthall profile; exchanging job posts and applications between the platforms when an employer chooses to publish to Youthall; joint customer support, security and fraud prevention; product development across both platforms using anonymous, aggregated statistics and, where a lawful basis applies, User account and usage data; and, subject to your separate marketing choices, telling Users about related Youthall services. Candidate records, interview notes and evaluations that an employer keeps in Hireall are processed for these purposes only as far as an enabled feature, support request or security investigation requires, and never for independent marketing or to build Youthall's talent pool | Legitimate interest in operating the two affiliated platforms efficiently and securely; the employer's instructions under the Data Processing Agreement for Candidate data exchanged through a feature it enables; consent for marketing where required |
| Legal compliance and protection of rights | Responding to lawful requests, exercising or defending legal claims, complying with regulatory obligations | Legal obligation; legitimate interest |
| Corporate transactions | Due diligence in a merger, financing or acquisition | Legitimate interest, subject to confidentiality |
Where we rely on legitimate interests we have assessed that our interests are not overridden by your rights. You can ask us for more information about these assessments at any time.
05AI features
Hireall includes optional AI features that employers can enable, such as CV parsing, match scores against a job description, bulk matching, plain-language search across a talent pool and AI-assisted drafting of job posts. These features are designed to support recruiters; they do not make hiring decisions on their own, and an employer can switch them off.
- AI features process only the data needed for the specific task, typically the job description and the application material the employer chooses to analyse. Where a feature produces a score or ranking, the result is shown with the explanation the model returned, so that a reviewer can see the reasoning rather than a bare number.
- The instructions given to the models require them to assess only job-related criteria and never to consider, infer or mention protected characteristics or their proxies. We do not include the structured fields for a candidate's name, gender, date of birth or nationality in what we send to the model. Talent-pool search is instructed not to turn a request about gender, age or a similar characteristic into a filter, and the platform drops those structured filters if a model still returns them. The same information can still appear in free text such as a CV or a search keyword; the model is instructed to disregard it, which reduces but does not eliminate the possibility that it influences an output. For that reason AI outputs are advisory: our Terms of Service require employers to have a suitably trained person review an output before relying on it for a decision that affects a Candidate and prohibit rejecting a Candidate, or taking any other decision that materially affects a Candidate, solely on an AI output. Hireall provides the controls for that review (explanations, the ability to disregard or override a result, and the option to disable AI features) and enforces a technical limit: an automation rule that uses the AI score cannot move a candidate to the rejected or an offer stage or create an offer without a team member's confirmation for that candidate; a rule conditioned on gender, nationality, military-service or smoking status cannot move a candidate, send a message or create an offer without such a confirmation. Otherwise, automation rules the employer sets up may move a candidate to another stage and send the message attached to that step on their own, unless the employer has chosen to have each step confirmed. Hireall does not itself verify the content of each review; the employer is responsible for it, and Hireall remains responsible for the design of the features and its own data-protection obligations.
- Requests are processed through large-language-model providers (currently Google and OpenAI) under contracts that prohibit those providers from using the data to train their models.
- We do not use Candidate data or customer content to train or fine-tune foundation models or any other machine-learning model, whether our own or a third party's. Processing needed to generate a requested output or to maintain a customer's own search index is not training. Any training arrangement would require a separate written agreement with the customer and an appropriate lawful basis.
- The credit cost of an AI action is shown before it runs, and AI actions are recorded so that reviewers can see what was analysed, when and by whom, to the extent described for each feature in the AI Transparency Notice.
Our AI Transparency Notice describes these features, the human oversight around them and how Candidates can ask an employer for a human review.
06Cookies and similar technologies
hireall.com and the Hireall application use cookies and similar technologies for the purposes described in our Cookie Policy. Cookies that are not strictly necessary are set only after you give consent through the banner, and you can change your choice at any time using the "Cookie preferences" or "Your Privacy Choices" link in the footer of every page. Inside the Hireall application and on the career pages, application forms, personal privacy pages and video-interview pages we host for employers we use only strictly necessary cookies (your session, form protection and, when you open the purchase dialog, Stripe's fraud-prevention cookies); no analytics, advertising, retargeting or chat tag is loaded there, so no consent banner is shown on those pages. The only third-party code that can run on those pages is Stripe.js, loaded when you open the purchase dialog, together with the static files and script libraries (icons, fonts, a date picker, a text editor, a map and small utility libraries) served from the content-delivery networks listed in the Cookie Policy, which set no cookies of their own. "Apply with Youthall" on job pages that offer it opens a window on youthall.com when you click the button; no Youthall script is loaded on the Hireall page. Both are described in the Cookie Policy.
07How we share personal data
We share personal data only as described here. We do not sell it, and we do not share it for cross-context behavioural advertising.
- Sub-processors for customer data — companies that process Service content and Candidate data on our behalf and only on our documented instructions: infrastructure hosting (Amazon Web Services, Frankfurt), transactional e-mail delivery, AI model providers (Google, OpenAI) and Youthall where an employer enables the Youthall channel or a Candidate applies with a Youthall profile. Each is bound by a written contract with data-protection, confidentiality and security obligations, and the current list with purposes and locations is published at hireall.com/legal/sub-processors.
- Service providers for our own operations — companies that process the account, billing and marketing data for which Hireall is controller: Cookiebot by Usercentrics (consent management on our marketing pages) and Stripe (payment processing). Cookiebot acts as our processor. Stripe processes payment data as our processor for taking payment and, for its own fraud prevention, sanctions screening and regulatory obligations, as an independent controller under the Stripe Privacy Policy. Support requests are handled in Hireall's own systems and by e-mail; we do not use a third-party chat or CRM tool inside the application.
- Website analytics — Google Analytics 4 runs only on the public marketing pages of hireall.com, and only after you accept statistics cookies in the banner; Global Privacy Control is honoured where the law requires. It does not run inside the Hireall application, on sign-in and account pages, or on the career pages, application forms, personal privacy pages and video-interview pages we host for employers, so no page title, URL or event from a recruitment process reaches Google. When active it receives a cookie identifier, the URL and title of the marketing page, referrer, device and browser information, approximate location derived from the IP address (which Google Analytics 4 does not store) and events such as a demo request. Google processes this data as our processor under the Google Analytics data-processing terms; we do not use Google Ads or Meta advertising tags on any Hireall page. Details, cookie names and opt-outs are in the Cookie Policy.
- Youthall, our affiliate — we share account, organisation, usage and support data with Youthall to operate the two platforms together (applications made with a Youthall profile, job distribution and application exchange when an employer publishes to Youthall, joint support, security and fraud prevention, and product development based on anonymous statistics and User data). Sharing that is needed to run a feature you or your organisation use rests on our legitimate interest in operating the affiliated platforms and, for Candidate data, on the employer's instructions under the Data Processing Agreement; it does not depend on your consent and is limited to what the feature requires. Where Youthall processes this data for Hireall it does so as our sub-processor under a written data-processing agreement; where it provides its own candidate account or talent-network services it is a separate controller under its own privacy policy. Employer Candidate records, interview notes, scorecards and offers are not passed to Youthall for its own marketing or talent pool. Marketing messages about Youthall services are sent only with the separate consent the law requires or, where the applicable law permits such messages without consent, only if its conditions are met for the sender, the recipient and the message concerned (for example the rules for corporate subscribers and the existing-customer exemption in the UK, which does not extend automatically to another group company); you can opt out at any time.
- Services you connect — job boards and aggregators (including Google for Jobs, LinkedIn, Indeed, Talent.com, Jooble and Adzuna), calendar and meeting providers, Slack and assessment partners receive the data required to perform the integration you or your organisation enabled. Their use of that data is governed by their own terms and privacy notices.
- Your organisation — administrators of the customer account you belong to can see your profile, role, activity and audit-log entries.
- Professional advisers — lawyers, auditors, accountants and insurers where necessary for the services they provide to us.
- Authorities and legal process — courts, regulators and law-enforcement bodies where disclosure is required by law, or where reasonably necessary to protect the rights, property or safety of Hireall, our customers, Candidates or the public.
- Corporate transactions — a prospective or actual buyer, investor or successor in a merger, acquisition, financing or reorganisation, under confidentiality obligations and subject to this Policy.
- At your direction or with your consent — for example when you ask us to share an export with a third party.
08Security
We protect personal data with technical and organisational measures appropriate to the risk, including:
- encryption of data in transit (TLS) and at rest;
- logical separation of each customer's data (multi-tenant isolation) and role-based access control, so Users see only what their role requires;
- optional two-step verification for User sign-in — either a one-time code sent to the User's e-mail address or a time-based code from the User's own authenticator application, together with single-use recovery codes — and administrators managing seats and roles;
- an audit log of hiring and administrative events that administrators can review and, depending on the subscription, export;
- encrypted backups, tested restore procedures and monitoring for unusual activity;
- confidentiality obligations and security training for our personnel, and least-privilege access to production systems;
- a logging standard under which application logs carry record identifiers rather than names, e-mail addresses or identity numbers, enforced through code review; security and access logs are kept for 12 months with restricted access.
We do not currently hold ISO 27001 or SOC 2 certification and we do not display badges we have not earned; our security page describes our controls in the language of a security questionnaire. If you believe you have found a vulnerability, please write to security@hireall.com. If a personal data breach affects you, we will notify you and the relevant authority where the law requires it.
09How long we keep personal data
We keep personal data only for as long as we need it for the purposes described above, and then delete or anonymise it. The table sets out the periods for the data for which Hireall is controller and, for information, the schedule that applies to Service content at the end of a customer's subscription; during a subscription the customer decides how long Candidate data is kept.
| Data | Retention |
|---|---|
| User account and organisation data | For the life of the subscription and a 30-day retrieval period after it ends; then deleted or anonymised from active systems, normally within a further 30 days and at the latest 60 days after the retrieval period ends — that is, at most 90 days after the subscription ends |
| Service content, including Candidate data processed for a customer | As instructed by the customer during the subscription; after the 30-day retrieval period, deleted or anonymised from active systems on the same schedule (normally 30 days, at the latest 60 days after the retrieval period, so at most 90 days after the subscription ends), unless a specific legal ground described below requires a particular record to be kept |
| Unconverted trial accounts | Kept for 30 days after the trial ends so that you can resume or export; then the same deletion sequence applies |
| Documents uploaded for a verification item | Erased on the purge date the customer sets for the item - 180 days from the request by default and 365 at the most - and immediately if the request is cancelled or the customer deletes the file; a daily scheduled job carries this out |
| Video interview recordings | 60, 90 or 365 days after recording depending on the customer's subscription, then deleted |
| Audit and security logs | Audit log entries for 3 years from the event, then purged by a scheduled job (or earlier with the customer's content at the end of the subscription); security and access logs for 12 months |
| Contract acceptance records | Life of the customer relationship plus 6 years |
| Invoices, payments and tax records | 6 years after the end of the financial year, as required by UK law |
| Support tickets and correspondence | 3 years after the matter is closed |
| Marketing contacts | Until you unsubscribe or object, or after 24 months without engagement |
| Website analytics | As set out in the Cookie Policy; reports are aggregated |
| Applications for jobs at Hireall | 12 months after the decision, unless you agree to be kept in our talent pool for longer |
What happens when data is deleted
- Records a User deletes in the Service (scorecard evaluations, saved filters, support conversations, templates, company-page items and similar) are hidden immediately from every User, from search, reports, exports and AI features. There is no undo period: the record cannot be restored by Users. Until it is permanently deleted it is only stored, with access restricted to the engineers who operate the platform, and is not used for any other purpose. A scheduled job that runs every day permanently deletes such records from active systems no later than 30 days after the deletion; its runs and any failures are logged and monitored. A configuration record that past records still depend on (for example a rejection reason used by earlier applications, or a scorecard template on which evaluations were made) is kept only as a hidden reference so that those records stay intact.
- Candidate withdrawal, objection and erasure are three different things. When a Candidate asks to withdraw an application, the employer decides under its own retention rules and applicable law (a withdrawal does not by itself require erasure of every related record) and can instruct Hireall to delete or anonymise the record. When a sourced Candidate objects through the personal privacy page, the record is anonymised immediately and automatically, and a minimal suppression record prevents re-import. An erasure request from a Candidate is forwarded to the employer without undue delay, normally within two business days, together with the information the employer needs to decide; the employer's own statutory deadline (one month under the GDPR) runs from the Candidate's request, not from its instruction to us. When the employer instructs deletion, or the Candidate's request must be honoured under applicable law, Hireall permanently deletes or anonymises the record from active systems promptly, normally within five business days and in any event within 30 days, and confirms completion so that the employer can respond to the Candidate in time. These service periods are a ceiling, not an entitlement: they never extend the employer's remaining statutory deadline, and where applicable law, the employer's remaining deadline or our Data Processing Agreement requires a shorter period, the shorter period applies — if an instruction reaches us late, we act within the time that is left. Deletion is never postponed to the end of the employer's subscription because a second request has not been made.
- Content with its own retention rule (video-interview recordings; document-verification records, which hold only the outcome of a check and never the document itself) is purged automatically by a daily job when that rule expires.
- Employer deletion instructions for individual Candidate records or whole jobs are carried out by Hireall on the employer's written instruction on the same timeline (normally five business days, at the latest 30 days); at the end of a subscription all Service content is deleted on the schedule in the table above.
- Backups. Encrypted backups are kept for a limited rolling period, are isolated from ordinary processing and are overwritten within the maximum period set out in our Data Processing Agreement. If a backup is restored for disaster recovery in the meantime, the deletion is applied again before the data returns to ordinary processing.
- Records kept for a specific legal reason. Only the specific records that a legal obligation or a live legal matter requires are kept longer: invoices and tax records, contract acceptance records, security logs, records that are the subject of a pending legal claim, regulatory request or dispute, and a minimal suppression record where it is needed to honour an objection. These are kept for that purpose alone, with restricted access, and are deleted when the reason ends. A retention obligation for one type of record, such as an invoice, never means that Candidate files or other Service content are kept for the same period; a Candidate record is retained beyond the schedule above only if it is itself the subject of such a matter.
10Your rights
Depending on where you live, you have the following rights in relation to personal data for which Hireall is the controller:
- Access — to obtain a copy of your data and information about how we use it.
- Rectification — to have inaccurate or incomplete data corrected. Users can edit most profile details in Settings.
- Erasure — to have data deleted where there is no overriding reason to keep it.
- Restriction — to limit how we use your data in certain circumstances.
- Portability — to receive data you gave us in a structured, machine-readable format.
- Objection — to object to processing based on legitimate interests, and at any time to direct marketing.
- Withdrawal of consent — where processing is based on consent, without affecting processing that took place before withdrawal.
- Automated decisions — not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Hireall does not make such decisions about Users or website visitors.
To exercise a right, write to privacy@hireall.com from the e-mail address associated with your account, or by post. We may ask for information to verify your identity. Under the UK GDPR and EU GDPR we respond within one month, extendable by up to two further months for complex or numerous requests; under KVKK within 30 days. Under the CCPA we respond to requests to know, delete or correct within 45 calendar days, extendable once by a further 45 days with notice, and we act on requests to opt out of sale or sharing or to limit the use of sensitive personal information as soon as feasibly possible and no later than 15 business days. We do not charge a fee unless a request is manifestly unfounded or excessive. Authorised agents may submit requests on your behalf with proof of authority.
If your request concerns data an employer processes about you as a Candidate, we will forward it to the employer and tell you we have done so.
You may also lodge a complaint with a supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the authority of the country where you live or work; in Türkiye, the Personal Data Protection Authority (kvkk.gov.tr). We would appreciate the chance to address your concern first.
11How to complain to us
If you think we have handled your personal data in a way that infringes data-protection law, you can complain to us directly. Send your complaint by e-mail to privacy@hireall.com, use the online form at hireall.com/resources/ticket (choose "Privacy or data-protection complaint"), or write to the postal address below. Tell us what happened, when, and what outcome you are seeking.
We acknowledge every complaint within 30 days of receiving it, look into it, keep you informed of progress and tell you the outcome without undue delay. This procedure follows section 164A of the UK Data Protection Act 2018. Using it does not affect your right to complain to a supervisory authority at any time.
12Regional information
United Kingdom and European Economic Area
Hireall is the controller for personal data covered by this Policy. Requests from any region can be sent to privacy@hireall.com; we respond in English. In the UK, the rules on automated decision-making in Articles 22A to 22D of the UK GDPR apply; Hireall does not take decisions about Users or website visitors based solely on automated processing.
Türkiye
For processing subject to KVKK, Hireall Technology Ltd is the data controller (veri sorumlusu) and this Policy also serves as our information notice under Article 10. You may exercise the rights in Article 11 by writing to privacy@hireall.com; we respond within 30 days as required by the Communiqué on the Procedures and Principles of Application to the Data Controller. Employers using Hireall to process Candidate data in Türkiye are the data controllers for that data and are responsible for their own information notices and, where they use our talent-pool features, for obtaining explicit consent where required.
California
If you are a California resident, the CCPA gives you the right to know what personal information we collect and how we use and disclose it, to delete it, to correct it, to opt out of "sale" or "sharing" and to limit the use of sensitive personal information, all without discrimination. In the last twelve months we have collected the categories listed in the section on personal data we collect (identifiers, commercial information, internet activity, geolocation derived from IP address, professional information and inferences about product interest) for the purposes listed above, and disclosed them to the service providers described in the section on sharing. We do not sell personal information, we do not use advertising tags on our pages and we do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA. Statistics cookies on our marketing pages are set only with your consent; you can withdraw it through the "Your Privacy Choices" and "Cookie preferences" links in the footer of every page, or by enabling Global Privacy Control in your browser, which we honour as an opt-out of any sale or sharing. Submit requests to know, delete or correct to privacy@hireall.com; for those requests we verify identity using the information associated with your account or interaction. We do not require verification for a request to opt out of sale or sharing or to limit the use of sensitive personal information; we ask only for the information needed to carry it out and act on it within 15 business days. Hireall does not use automated decision-making technology to make significant decisions about website visitors or Users.
Global Privacy Control and Do Not Track
Our consent tool detects the Global Privacy Control (GPC) browser signal and, for visitors from jurisdictions where the signal must be treated as an opt-out (including California, Colorado and Connecticut), does not set statistics or marketing cookies and confirms that the opt-out has been honoured. We do not respond to the older "Do Not Track" header, for which there is no agreed standard; the cookie banner and the "Cookie preferences" link remain available to everyone.
13Recruitment at Hireall
If you apply for a role with Hireall, we process the information in your application, your interview and assessment results, references you authorise us to contact and, where the law permits and you volunteer it, information needed for right-to-work checks. We use it to assess your application, communicate with you and comply with employment law. Applications are kept for 12 months after a decision; with your consent we keep them longer to consider you for other roles. Hireall does not use AI features to make or recommend decisions about its own applicants.
14Children
Hireall is a business service. hireall.com and the Hireall application are directed to adults acting for an employer; we do not knowingly create User accounts or marketing contacts for anyone under 18, and where we learn that we have done so we close the account and delete the data unless a legal obligation requires otherwise. This is different from Candidate data: employers may lawfully receive applications from young people, for example for internships and entry-level roles, and Hireall processes those applications only as the employer's processor. The employer is responsible for the age rules and any parental consent that apply to its recruitment; Youthall's own age requirements for candidate accounts are set out in its privacy policy. If you believe we hold personal data about a child for which Hireall is the controller without a lawful basis, contact privacy@hireall.com and we will investigate and, where appropriate, delete it; if the data belongs to an employer's recruitment process we will pass your report to that employer and tell you we have done so.
15Links to other sites
Our websites and the Service link to third-party sites and services, such as job boards, integration partners, social networks and, on employer career pages, the employer's own website. Those sites have their own privacy notices and we are not responsible for their practices.
16Changes to this Policy
We update this Policy when our practices, our providers or the law change. The date at the top shows when it was last revised. For material changes we give Users at least 30 days' notice by e-mail or an in-app message before the change takes effect, and we obtain consent where the law requires it. Previous versions are available on request from legal@hireall.com.
17Contact us
Privacy questions and data-subject requests: privacy@hireall.com
Contracts, DPA signatures and legal notices: legal@hireall.com
Security reports: security@hireall.com