Legal
Privacy Policy
What personal data HireOS handles, why, for how long, and what rights people have over it.
Last updated 29 July 2026
1.Two different roles
HireOS handles two kinds of personal data, and the relationship differs for each.
For your account — your name, work email and password — HireOS is the data controller.
For candidate data — CVs, contact details, screening results — the agency is the controller and HireOS is a processor acting on your instructions. What we do with candidate data is governed by our Data Processing Agreement.
2.Account data we hold
Your name, work email, hashed password, the organisation you belong to, your role within it, and session records including IP address and browser user agent.
We use it to sign you in, to show your team who did what, and to contact you about the service. We do not sell it and we do not send marketing you did not ask for.
3.Candidate data
CVs you upload, the text extracted from them, contact details found in them, the assessments produced, recruiter decisions and notes, drafted messages and interview times.
This is processed to provide screening to your agency. It is never shared between agencies, never pooled, and never used to train models.
6.How long we keep it
Candidate data is kept for as long as your workspace's retention policy allows. Owners and admins set that window in Privacy & retention, and candidates past it are deleted along with their screening, drafts and interviews.
Account data is kept while your account is open and for 30 days after closure, so an accidental cancellation can be undone.
7.Rights over your data
Anyone whose data is held has the right to access it, correct it, have it erased, restrict or object to its processing, and to receive it in a portable format.
For candidate data, the agency answers these requests — HireOS provides a full JSON export and a permanent erase on every candidate record so they can. For your own account data, contact us and we will action it.
8.Security
Passwords are hashed, never stored in plain text. Service credentials are encrypted at rest with authenticated encryption. Candidate files are served with private, no-store caching so they are never held by an intermediate cache.
Deletions, data exports and retention purges are recorded in an append-only audit trail that cannot be edited from inside the product.
Something here you need changed before you can sign? Say so on the call — we would rather agree terms you are comfortable with.
Book a call