Legal

Privacy Policy

Effective 10 July 2026 · Version 1.0

1. Who we are, and the two roles we play

Whizz Hire is operated by Whizz Tech, Office 218, Binghatti Azure, JVC, Dubai, UAE. Contact: support@whizztech.ai.

Because this is a recruiting product, we wear two hats under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, where it applies, the GDPR:

  • Controller — for the account data of our customers (the employers using the dashboard and API).
  • Processor — for candidate data. The employer running the hiring process is the controller of applicant data; we process it on their documented instructions. Candidates: your first point of contact for access or deletion is the employer you applied to — but you can also write to us and we will route the request and assist (see Section 7).

2. What we collect

From customers (employers):

  • Account data — email (one-time-passcode sign-in), organization name, plan and billing details.
  • Job data — job posts, screening rubrics and weights, knockout questions, company career-page configuration.
  • Usage data — API request logs, credit ledger entries, run telemetry, and standard server logs (IP address, user agent) kept for security and billing.

About candidates (processed for the employer):

  • Identity and contact — name, email, phone, location, and links the candidate provides.
  • CV files and extracted content — the uploaded document, its parsed text and structure, and the anonymized extract used for scoring.
  • Application data — answers to application and knockout questions, application source, and status history.
  • Screening outputs — criterion scores, evidence quotes drawn from the CV, rankings, and interview kits.
  • Decision records — human dispositions and the audit log entries that document them.
  • Portal and email events — status-portal visits and delivery status of candidate notifications.

We do not run third-party advertising or analytics trackers on this site. Cookies are limited to what sign-in requires.

3. How we use it

  • To operate the service: host career pages, receive applications, screen CVs, generate interview kits, deliver webhooks and notifications.
  • To support fair process: identity fields are stripped from CV extracts before scoring models run (see the AI disclosure).
  • To bill accurately: credits, refunds, and usage records.
  • To secure the platform: abuse prevention, rate limiting, audit logs.
  • To communicate: sign-in codes, service notices, and candidate status emails sent on the employer's behalf.

We do not sell personal data. We do not use CVs, applications, or screening outputs to train models — content is sent to our model providers solely to produce the customer's output, under API terms that exclude training use.

4. Retention

  • Candidate data— retained per the employer's configured retention policy. The default is 24 months from last activity, after which candidate records are deleted or anonymized; employers can shorten or extend this within legal limits, and talent-pool retention requires the candidate's consent.
  • Screening and decision records — retained for 4 years by default, matching the longest current regulatory retention requirement for automated hiring tools (California FEHA). These records are kept even where CV content has been anonymized, with identity fields minimized.
  • Account data — kept while the organization is active; deleted within 30 days of account closure except records we must keep for legal or accounting reasons.
  • Server logs — rotate within 90 days.

5. Subprocessors

We share data with these categories of subprocessor, each under a data-processing agreement:

  • Google Cloud Platform — hosting, task queues, and CV file storage (Google Cloud Storage, private buckets with signed URLs). Primary region: EU/US multi-region today; a KSA/EU data-residency option is on the enterprise roadmap and this policy will name exact regions as they ship.
  • Model providers— Google (Gemini), Anthropic (Claude), and OpenAI (embeddings) for CV parsing, scoring, evidence citation, JD generation, and interview kits. API-submitted content is excluded from training under each provider's API terms.
  • Resend (United States) — transactional email: sign-in codes, candidate acknowledgments and status notices.
  • Stripe — payment processing for paid plans; we do not store card numbers.

We will update this list before adding a subprocessor that handles personal data. International transfers rely on appropriate safeguards, including standard contractual clauses where required.

6. Security

CV files live in private storage accessed only via short-lived signed URLs; API keys are stored hashed; board and integration credentials are encrypted at rest (AES-256-GCM); webhook deliveries are signed (Standard Webhooks) so you can verify origin; access to production systems is restricted and logged.

7. Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal data — and, for candidates, specific rights around automated decision-making described in our AI disclosure, including requesting human review of a screening outcome.

Customers: email support@whizztech.ai from your account address. Candidates: contact the employer you applied to, or email us and we will forward the request to the responsible employer and assist with its completion. We respond within 30 days. If you believe a concern is unresolved, you may complain to your local supervisory authority.

8. Changes

We will post changes here and update the effective date. Material changes are announced by email to organization owners before they take effect.