Privacy Policy

Last updated: June 2, 2026

1. Who We Are

HRHandle is operated by Aleksandre Merabishvili, Individual Entrepreneur, registration number 01019062001, Tbilisi, Georgia ("we", "us", "our").

We are the data controller for the personal data of our customers (account holders and their team members). For candidate data that you enter into the Service, you are the data controller and we act as a data processor on your behalf.

Contact: support@hrhandle.com

2. What Data We Collect

2.1 Account and Organization Data

  • Name and email address of account holders and team members
  • Organization name and configuration settings
  • Subscription and billing information (processed by our payment provider — we do not store card details)
  • Usage activity within the Service (e.g. actions taken, features used)
  • If you sign in with Google: your Google account name, email address, and profile picture, provided via Google OAuth. We do not store your Google password.

2.2 Integration Data

  • If you connect LinkedIn: your LinkedIn OAuth access token, used solely to post vacancies on your behalf. We do not access your LinkedIn connections or personal feed.
  • If you connect Google Calendar: your Google OAuth access token and refresh token, used solely to create and manage interview calendar events on your behalf.
  • If you connect Zoom: your Zoom OAuth access token and refresh token, used solely to create Zoom meetings when scheduling video interviews on your behalf.
  • If you connect Microsoft: your Microsoft OAuth access token and refresh token, used solely to create Teams meetings and Outlook Calendar events when scheduling video interviews on your behalf. We do not access your emails, contacts, or any other Microsoft data.

2.3 Vacancy Data

  • Job titles, descriptions, responsibilities, departments, locations, and requirements
  • Salary information and hiring timelines
  • Evaluation criteria and scores entered by your team

2.4 Candidate Data

You enter candidate data into HRHandle as part of your recruitment process, or candidates submit it themselves through your public application page. This may include:

  • Full name, email address, and phone number
  • Current company and position, years of experience
  • LinkedIn profile URL
  • CVs, resumes, cover letters, and other uploaded documents
  • Information automatically extracted from uploaded CVs (work experience, education) — see Section 5 for details on how this extraction works
  • Recruiter notes and interview records
  • Application status and history
  • For candidates who apply through the public application page: the IP address from which the application was submitted. We use this to prevent abuse (rate-limiting and duplicate-submission detection). It is stored alongside the application record and deleted together with it.

Some of this data may be imported by your recruiters directly from LinkedIn, or bulk-imported by an organisation owner or admin via the CSV import feature at /candidates/import. You are responsible for ensuring you have a lawful basis to collect and store this data under applicable law, regardless of the entry path.

2.5 Candidate status page

When a candidate applies for a role, we create a private, token-gated status page at /status/<token> on this Service that shows only that candidate's own application status. The token is an opaque 32-character random string and is the only credential to the page — there is no login. The page does not show recruiter notes, evaluation scores, internal pipeline stage names, or any other recruiter-internal data; it shows the role title, employer (the recruiting organisation's name), the date the candidate applied, the date of the last status change, and a simplified status bucket (Applied / In review / Interview / Decision / Closed). Candidates receive the link in the application-confirmation email; recruiters can also re-share it from inside HRHandle. The link can be revoked by the recruiter at any time by removing the application; the token is also deleted by our 30-day purge ([G-003](https://github.com/Merabishvili/HRHandle/blob/main/docs/issues-found.md)) if the application is soft-deleted.

In addition, recruiters can opt their organisation in to two automatic status-change emails: one when an application moves to the "Under review" stage and one when it moves to the "Interview" stage. Each email contains the role title, employer, and the candidate's status page link. These emails are off by default and only fire when an admin saves a template and toggles them on in HRHandle's settings; no other status transitions produce automatic emails (offers, hires, rejections, and withdrawals are handled by the recruiter directly).

The status page also lets the candidate withdraw their application directly. Clicking Withdraw application opens a confirmation prompt with an optional free-text reason that only the recruiter sees. On confirm, the application's status is set to "withdrawn", any active offer attached to it is automatically withdrawn so a stale accept button never reappears, and the recruiter is notified. The page does not allow a candidate to undo the withdrawal — the candidate can contact the recruiter directly to be re-added.

When the recruiter sends an offer, we create a separate token-gated offer page at /offer/<token> on this Service. Like the status page, the token is the only credential — there is no login. The page shows the role title, employer name, the structured terms the recruiter entered (compensation, currency, period, start date, respond-by date — any of which may be blank), the recruiter's plain-text offer details, and an optional personal note. The candidate can accept or decline directly from the page; declining accepts an optional free- text reason which only the recruiter sees. The offer page does not show any other candidate's data and does not show recruiter-internal notes, evaluation scores, or audit trail.

When a recruiter chooses to share a candidate's evaluation scorecard with someone outside HRHandle (typically a hiring manager or executive who does not have an account), we generate a separate token-gated page at /scorecard/<token> on this Service. The page shows only the candidate's full name, the role title, the recruiting organisation's name, the evaluation answers and per-question scores entered by the recruiter, and the name + date of the recruiter who first shared it. It does not show the candidate's email, phone, LinkedIn, application status, recruiter notes, AI-generated content, offer terms, or any other recruiter-internal data. The recruiter can revoke the link at any time, at which point the URL stops working immediately.

3. How We Use Your Data

  • To provide, operate, and improve the Service
  • To manage your subscription and process payments
  • To send transactional emails (account invitations, password resets)
  • To monitor for errors and technical issues (via Sentry)
  • To comply with legal obligations

We do not use your data or your candidates' data for advertising or marketing purposes, and we do not sell data to third parties.

4. Legal Basis for Processing

  • Contract performance: processing necessary to deliver the Service under our Terms
  • Legitimate interests: monitoring service health, preventing abuse
  • Legal obligation: complying with applicable laws
  • Consent: where you have explicitly provided it (e.g. marketing communications, if any)

5. Third-Party Services

We use the following sub-processors to provide the Service:

ProviderPurposeLocation
Supabase (AWS us-east-1)Database and file storageUSA
ResendTransactional email deliveryUSA
SentryError monitoringUSA
VercelHosting and deploymentUSA / Global CDN
Google (optional)Authentication (OAuth) and Google Calendar integrationUSA / Global
Google Generative AI (Gemini API)Automated extraction of structured fields from uploaded CVs (name, email, work experience, education) — see "AI features" belowUSA / Global
LinkedIn (optional)Vacancy posting via LinkedIn APIUSA / Global
Zoom (optional)Video meeting creation via Zoom APIUSA / Global
Microsoft (optional)Teams meeting and Outlook Calendar integration via Microsoft Graph APIUSA / Global

All sub-processors are contractually obligated to process data only as instructed and to maintain appropriate security measures.

5.1 AI-assisted features

HRHandle includes a small number of AI-assisted features that send candidate or vacancy data to Google's Gemini API to help the recruiter — never to replace their judgement. Each feature is opt-in per request: nothing is generated automatically, and the recruiter must explicitly click a button to invoke it.

Current AI-assisted features:

  • CV parsing — when a CV (PDF or Word document) is uploaded, the file is sent to Gemini to extract structured fields (name, contact details, work experience, education) so they can be pre-filled into the application form.
  • Job-description suggestions — when a recruiter clicks a "Generate" button while creating or editing a vacancy, the AI suggests one or more sections (About the job, Responsibilities, Requirements) based on the recruiter-provided role data (title, department, location, employment type, sector, and any optional context the recruiter typed). No candidate data is sent to the AI for this feature. The suggestions are not added to the vacancy unless the recruiter explicitly clicks "Apply all to form" or copies a section manually.
  • Interview question suggestions — when a recruiter clicks the "Generate questions" button on a vacancy's Interview Questions tab, the AI suggests four categories of questions (behavioural, technical, situational, closing) based on the vacancy fields (title, description, responsibilities, requirements, department, location, employment type, sector, and any optional context the recruiter typed). No candidate data is sent to the AI for this feature. The suggestions are advisory; the recruiter chooses whether to save them to the vacancy (overwriting the previously-saved set) or copy individual questions.
  • Interview-note structuring — when a recruiter pastes their free-text interview notes and clicks "Extract structure" on the candidate detail page, the AI returns a structured view (summary, strengths, concerns, skills demonstrated, follow-ups). The notes the recruiter pasted are sent to Google's Gemini API along with the candidate's name and the title of the role they are being considered for. The AI is explicitly instructed not to make any hiring recommendation, not to include the candidate's salary expectations in the structured output, and not to infer protected characteristics (age, gender, race, religion, family or marital status, disability, etc.) even if the notes hint at them. The structured output is not saved anywhere unless the recruiter clicks "Save as note", which creates a single candidate note prefixed with "AI interview notes (not reviewed by recruiter)" so it is clearly traceable.
  • Inclusive-language check — when a recruiter clicks "Run check" on a vacancy form, the AI scans the vacancy's description, responsibilities, and requirements fields for phrases that may deter underrepresented candidates (gender-coded, age-coded, culture-coded, pronoun bias, potentially discriminatory phrasing, vague cultural-fit requirements). It returns a list of flagged passages with the reason and a suggested neutral replacement. Only the vacancy text is sent to the AI for this feature; no candidate data is involved. The form is never modified by the AI; the recruiter chooses whether to apply any of the suggestions.
  • Assessment suggester — when a recruiter clicks "Generate suggestions" on a vacancy's Assessment tab, the AI proposes evaluation criteria (skill labels scored 1–5) and open-ended prompts based on the vacancy's text. Only the vacancy text is sent to the AI for this feature; no candidate data is involved. Each suggestion is added to the vacancy only when the recruiter explicitly clicks the "Add" button next to it.

The AI output is informational only. No AI feature in HRHandle makes any automated decision about a candidate — no automatic ranking, no automatic rejection, no automatic advancement. Every hiring decision (advancing, rejecting, hiring) is taken by a human recruiter on your team. Article 22 GDPR (automated decision-making with legal or similarly significant effect) therefore does not apply.

We record an internal log entry each time an AI feature is invoked (recruiter, candidate, feature name, timestamp) for traceability under the EU AI Act's high-risk-AI logging requirements. We do not log the AI output itself.

We use Google's paid Gemini API for all of these features. Under Google's paid-services terms, Google is not permitted to use customer prompt content or responses to train or improve their models. Google retains prompts and responses briefly only for abuse detection.

If an AI feature is unavailable or fails for any reason, the workflow proceeds normally and the recruiter completes the task manually.

6. International Data Transfers

Your data is stored on servers located in the United States (AWS us-east-1, North Virginia). If you are located in the European Economic Area or Georgia, this constitutes a transfer of personal data outside your jurisdiction. We rely on standard contractual clauses and the data processing agreements of our sub-processors to ensure an adequate level of protection.

7. Data Retention

We retain your account, organization, and candidate data for as long as your account is active.

After your account is terminated (by you or by us), you have 30 days to request an export of your data. During this 30-day window the data remains recoverable. After the 30-day window, your account, organization, and all associated candidate data, documents, and application records are permanently deleted, except where we are required by law to retain specific records longer (for example, invoicing records under Georgian tax law).

Within the active life of your account, when you delete a candidate or document from within the Service, the record is marked for deletion immediately and permanently removed within 30 days. Backup snapshots taken before deletion are kept under Supabase's backup-retention policy and are not used for selective restoration of deleted records.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Object to or restrict certain processing
  • Receive your data in a portable format
  • Withdraw consent where processing is based on consent

To exercise any of these rights, contact us at support@hrhandle.com. We will respond within 30 days.

9. Cookies and analytics

We use cookies and browser storage in two categories:

9.1 Essential

Cookies and storage required for authentication, session management, CSRF protection, and remembering your sign-in preference. These are set by Supabase Auth and our own application code, and cannot be disabled without breaking the Service. We do not use advertising or cross-site tracking cookies.

9.2 Product analytics

In production we use the following analytics tools to understand how the Service is used and to improve it:

  • PostHog (hosted in the EU, eu.i.posthog.com) — captures page views, clicks, and product events. Person profiles are created only for signed-in users (configured as identified_only). Anonymous visitors to the landing page and public application pages do not receive a PostHog person profile.
  • Vercel Analytics — counts page views and basic traffic signals (referrer, country, device type) on production deployments. Vercel Analytics is privacy-friendly and does not use cross-site tracking cookies.

We do not run PostHog or Vercel Analytics on the candidate apply pages in a way that captures candidate-entered content, and we do not send candidate personal data (name, email, CV content) to either tool.

9.3 Error monitoring

Sentry collects technical error details (stack traces, browser/OS, request metadata) when something fails in the Service. Before any error is sent to Sentry, we run a server-side scrubbing step that removes known personal-data fields (names, emails, phone numbers, CV content, dates of birth, and similar) from the payload, so error reports do not contain candidate personal data.

10. Security

We implement appropriate technical and organizational measures to protect your data, including encrypted data transmission (TLS), row-level security on all database tables, role-based access controls, and signed URLs for document access.

11. Children

The Service is not directed at persons under 18. We do not knowingly collect personal data from anyone under 18.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice within the Service. The "last updated" date at the top of this page reflects the most recent revision.

13. Contact

Data controller: Aleksandre Merabishvili, Individual Entrepreneur
Identification number: 01019062001
29 Tskneti Highway, Tbilisi, Georgia
support@hrhandle.com
Phone: +995 599 89 29 17