Legal
Privacy Policy
What we hold, why we hold it, where it lives and how long it stays — for the people who use Hirevo and for the candidates whose résumés pass through it.
Last updated 4 August 2026.
1. Who is responsible for what
[registered entity — to be confirmed] operates Hirevo.
For account data — the people who sign in — we are the controller and this policy describes what we do.
For candidate data — the résumés uploaded into a workspace — the customer organization is the controller and we are their processor. We process that data on their instructions to provide the service, and for nothing else. If you are a candidate and want your data removed, the fastest route is the organization that holds it; we will also help directly, see clause 8.
2. What we collect
From people with an account:
- Name, work email and password credentials (passwords are stored hashed, never in readable form).
- The organization you belong to and your role within it.
- Records of what you did in the product — roles created, candidates reviewed, decisions taken — which is what makes the decision ledger useful.
- Billing details where you subscribe. Card numbers are handled by our payment processor and never reach our servers.
From résumés uploaded by a customer:
- Whatever the résumé contains — typically name, contact details, employment history, education and skills.
- The analysis we derive from it: scores, extracted skills, gaps and the evidence spans supporting each claim.
- The original file, so a recruiter can open what the candidate actually sent.
We do not ask for special-category data and the service is not designed to hold it. Customers are contractually required not to upload it.
3. Why we process it
- To provide the service — analysing a résumé against a role is the product.
- To authenticate you and keep the account secure.
- To bill you, where you are on a paid plan.
- To support you when you contact us.
- To meet legal obligations, including keeping invoices for the statutory period.
For account data our basis is performance of a contract, and legitimate interest in securing the service. For candidate data the customer organization determines the basis; under our terms they confirm they have one.
4. What we do not do
- We do not use your résumés, notes or decisions to train models that serve any other organization.
- We do not sell personal data, and we do not share it with advertisers.
- We run no advertising or third-party tracking pixels on any signed-in page.
- We do not enrich candidate profiles from external sources, and we do not scrape.
5. Where it lives, and who else touches it
Your data is stored in Singapore. We do not currently offer a choice of region, and any page or person telling you otherwise is wrong.
Résumé text is sent to a large-language-model provider in the United States to produce the analysis. That transfer is what makes the product work, and it is covered by standard contractual clauses with that provider.
These are every third party that processes data on our behalf:
| Processor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication and file storage | Singapore (ap-southeast-1) |
| Groq | Large-language-model inference for résumé analysis | United States |
| Vercel | Application hosting and delivery | Global edge network |
| Razorpay | Payment processing (subscriptions and invoices) | India |
6. Security
Data is encrypted in transit and at rest. Access within a customer’s workspace is enforced at the database with row-level security, so one organization cannot read another’s data even if the application is wrong. Administrative access to production is restricted to the people who need it.
We hold no security certification at this time. We are not SOC 2 or ISO 27001 audited, and we would rather tell you that than imply otherwise. If a certification is obtained it will be stated here with its date and scope.
7. How long we keep it
- Account data: for as long as the account exists, then 30 days.
- Candidate data: until the customer deletes it, or 30 days after their account closes.
- Invoices and payment records: for the period tax law requires, which is longer than the rest and cannot be shortened on request.
- Security and audit logs: retained so an account can be investigated after an incident.
8. Your rights
Whether or not you have an account, you can ask us to give you a copy of your personal data, correct it, delete it, or restrict how it is used. You can also object to processing and complain to your data protection authority.
If you are a candidate, tell us the organization that holds your résumé if you know it — it lets us find you without searching every workspace, which is itself a privacy improvement. Where we are acting as a processor we will pass your request to that organization and support them in answering it.
We answer within 30 days. There is no charge unless a request is repetitive or excessive.
9. Automated processing
Hirevo scores and ranks candidates, and that is automated. It does not make hiring decisions. Our terms require a human to review any decision with a legal or similarly significant effect, and the product records who made each decision and on what evidence.
If you are a candidate and want to know how an analysis reached its conclusion, ask — every claim the system makes is linked to the passage of your résumé it came from, and we can show you that.
10. Contacting us, and complaining
Privacy questions and rights requests: support@hirevo.in.
Grievance Officer: [officer name — to be confirmed] · support@hirevo.in. If you are unhappy with how we handled a request, this is the person to escalate to.
11. Changes
We will post changes here and update the date at the top. Where a change materially affects how we use personal data, account holders will be emailed before it takes effect.