Legal

Privacy Policy

What personal data Recruitifly collects, why, how long we keep it, who we share it with, and the rights you have.

Last updated 11 June 2026Version 1.0
On this page

This Privacy Policy explains how Recruitifly, based in Amsterdam, the Netherlands (“Recruitifly”, “we”, “us”), handles personal data when you visit our websites, create or use a Recruitifly workspace, or contact us. For privacy questions or requests, email hello@recruitifly.com.

The short version

We collect what we need to run an applicant tracking service: account details, workspace content, usage and billing data. We host in the European Union, we do not sell personal data, and optional analytics cookies only run after you accept them. For candidate data inside customer workspaces, our customer is the controller and we act as processor; that relationship is described on our GDPR page.

Our two roles

Recruitifly processes personal data in two distinct roles, and your rights run through a different door depending on which role applies.

As a controller. We decide how and why data is processed when you visit www.recruitifly.com, create an account, use our chat widget, subscribe to updates, or contact us. This policy covers that processing.

As a processor. Candidate and recruitment data inside a customer’s workspace is controlled by that customer (the employer or agency using Recruitifly). We process it only on the customer’s instructions. If you are a candidate in a hiring process run on Recruitifly, the organization you applied to is your first point of contact for privacy requests; we support them with the tooling described on the GDPR page. If you contact us directly we will refer your request to the responsible customer and assist where we can.

Data we collect as a controller

Account and profile data. Name, work email address, password hash, role, locale, workspace membership, and settings, collected when an account is created or an invitation is accepted.

Billing data. Organization name, billing contact, plan, invoices, and payment status. Payment card details are handled by our payment provider and do not touch our servers.

Usage and log data. IP address, browser and device information, pages visited, feature events, and technical logs (including request identifiers and error traces). We use this to secure, operate, and improve the Service.

Communications. Messages you send us by email, through the contact form, or in the public chat widget on our website. Chat conversations with the website assistant are stored so we can answer follow-up questions and improve answer quality.

Cookie and consent choices. Whether you accepted or rejected optional analytics, stored locally in your browser.

  • Providing the Service you signed up for, including authentication, workspaces, support, and billing: performance of a contract (GDPR Article 6(1)(b)).
  • Securing the Service, preventing abuse, and keeping audit trails: legitimate interest (Article 6(1)(f)) in running a safe, reliable platform.
  • Product analytics via optional cookies: consent (Article 6(1)(a)), which you can withdraw at any time.
  • Sending product and marketing communications to business contacts: legitimate interest or consent, depending on the channel; every message includes an opt-out.
  • Complying with legal obligations such as tax and accounting rules: legal obligation (Article 6(1)©).

Automated assistance

Parts of the Service, including the website chat widget and the in-product assistant, use LLMs to generate answers and suggestions. We work with established providers under business terms, and this paid usage is not used to train their models. Sensitive payloads are encrypted at the application layer before storage on our side. Automated output supports human decisions; no decision producing legal or similarly significant effects is taken about you based solely on automated processing.

Cookies

We use a small number of cookies and similar browser storage:

  • Essential. Session and authentication cookies (including a secure, httpOnly refresh token), your language preference, and your consent choice. These are required for the site and product to work and do not need consent.
  • Optional analytics. Disabled by default. The consent banner on our public pages lets you accept or reject them; rejecting changes nothing about how the Service works. You can change your choice by clearing the stored consent in your browser, after which the banner is shown again.

We do not use third-party advertising cookies and we do not track you across other websites.

Sharing and sub-processors

We do not sell personal data. We share it only with:

  • Infrastructure and service providers (sub-processors). Microsoft Azure hosts our databases, storage, and transactional email from European Union regions. An LLM provider processes the content sent to the assistant and analysis features. A payment provider processes subscription payments.
  • Integrations you enable. When a workspace administrator connects a job board, calendar, messaging channel, or HRIS, the data needed for that integration is exchanged with that provider under its own terms.
  • Authorities. When required by law, after verifying the request is valid and no broader than necessary.

A current list of sub-processors, including the safeguards used for any transfer outside the EEA, is maintained on the GDPR page.

International transfers

We host the Service in the European Union. Where a provider processes data outside the European Economic Area, we rely on adequacy decisions or the European Commission’s Standard Contractual Clauses, plus additional measures such as encryption.

Retention

We keep personal data no longer than needed:

  • Account data: for the life of the account, then deleted or anonymized within 30 days of account or workspace closure.
  • Billing records: as long as required by Dutch tax law (generally 7 years).
  • Technical logs: rotated on a short schedule, typically within weeks.
  • Website chat conversations: periodically purged on an automated schedule.
  • Candidate data in customer workspaces follows the retention rules described on the GDPR page, with automated, per-workspace retention enforcement.

Your rights

Under the GDPR you can ask us for access to, correction of, deletion of, or a copy (portability) of your personal data, ask us to restrict processing, and object to processing based on legitimate interest. Where processing is based on consent you can withdraw it at any time without affecting earlier processing.

Email hello@recruitifly.com and we will respond within one month. We may ask you to verify your identity first. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or the supervisory authority in your country.

If your request concerns candidate data in a customer’s workspace, the customer is the controller; we will route your request to them and support its execution.

Sourcing and public profiles

Customers can use sourcing features that work with professional, publicly available signals. How that works, and how you can exclude your identifiers from matching with a one-way hashed opt-out, is explained on the sourcing and your data page.

Security

We protect personal data with encryption in transit (TLS) and at rest, application-layer encryption for sensitive payloads, strict tenant isolation between workspaces, role-based access control, audit logging, and EU-based managed infrastructure. No internet service can guarantee absolute security; if a breach affects your data we will notify you and the competent authority as required by law.

Children

The Service is for professional use and is not directed at children under 16. We do not knowingly collect their data.

Changes to this policy

We will update this policy when our processing changes, and the “Last updated” date above will reflect the latest version. For material changes affecting account holders we give notice by email or in the product.

Contact

Recruitifly, Amsterdam, the Netherlands. Privacy questions and requests: hello@recruitifly.com. See also the Terms of Service and the GDPR page.

Other legal documents

Questions about this page?

We answer privacy and legal questions on business days, usually within one day.

Contact us