Skip to content

Legal

Privacy policy

Effective May 19, 2026. Last updated August 18, 2026.

The short version

Candidate data belongs to the client who collected it. We process it on that client’s documented instructions and nothing else. We do not sell personal data, do not use candidate data for advertising, and do not share talent-pool submissions across unrelated clients. Human recruiters retain final hiring authority.

1. Who we are

This Privacy Policy describes how HyreTech Pte. Ltd., operating as HyreTech (“we”, “us”), handles personal data through our platform at hyretech.ai. We are a Singapore-registered company at 77 High Street, #10-12B, High Street Plaza, Singapore 179433. You can use HyreTech as your applicant tracking system, or keep your existing stack and import candidates for AI evaluation.

Our primary privacy regime is Singapore’s Personal Data Protection Act (PDPA). We also honour EU/UK GDPR rights and US state-law rights (including CCPA/CPRA and NY SHIELD) for people in those jurisdictions, to the extent they apply.

When our clients (“Clients”) use HyreTech to manage hiring, they are the data controller for candidate data and we act as the data processor, processing candidate data solely on the client’s documented instructions. For data we collect directly — such as account information and website analytics — we are the data controller.

Contact: privacy@hyretech.ai

2. Talent pool submissions on HyreTech pages

When a candidate submits their information directly through a HyreTech-hosted talent-pool page (for example, hyretech.ai/companies/<client>/join), HyreTech acts as a joint controllerwith the named client for that submission. This differs from our role on a client’s own integrated site, where the client remains the sole controller and we act only as their processor.

What we collect on these pages. Contact details (name, email, phone), location, links (LinkedIn, portfolio, GitHub, etc.), an uploaded CV, and a record of the consent version, IP address, and user agent at the time of submission.

Recipients. The named client whose page the candidate submitted through. If that client is a recruitment agency, the agency may forward the submission to its own end clients — the candidate is told this on the submission page before they submit. We do not share talent-pool submissions across unrelated clients.

Purpose.AI-assisted matching of the candidate against the named client’s current and future open roles, both as a passive talent pool and as an applicant pipeline when matching roles open.

Legal basis.The candidate’s consent, captured at submission time and stamped with a consentVersion identifier so we can later demonstrate which version of this disclosure was shown. Candidates may withdraw consent at any time.

Retention.Twelve (12) months from the candidate’s last activity (submission, role match acknowledgement, or admin action), after which the record is deleted or anonymised. A client may set a shorter retention.

Your rights as a talent-pool candidate. Access, correction, withdrawal of consent, and deletion. Email privacy@hyretech.aiand identify which client’s page you submitted through. Because we share controllership for these submissions, we act on these requests directly rather than forwarding to the client.

3. What we collect

We process personal data provided by clients and candidates through the platform — such as contact details, professional background, qualifications, and application data — as well as account and billing information from clients. We also automatically collect device information, usage analytics, and cookies.

4. How we use it

We process personal data to operate the platform, run AI-powered resume parsing and candidate matching, manage accounts and billing, communicate with you, improve our services, comply with legal obligations, and maintain security.

Each AI operation on the platform consumes one AI credit. Credit usage is logged against client accounts, not individual candidates.

Depending on your jurisdiction, we process data based on consent, contractual necessity, legitimate interest, or legal obligation — in accordance with applicable data protection laws.

6. AI and automated decisions

HyreTech uses AI for resume parsing, candidate matching, skill assessment, and screening. These are decision-support tools — human recruiters retain final hiring authority. No candidate is automatically rejected or accepted by AI alone unless a client explicitly configures this.

HyreTech does not guarantee that AI outputs are free from error, bias, or inaccuracy. Clients are solely responsible for reviewing AI-generated results and ensuring that their use of the platform complies with all applicable anti-discrimination and employment laws.

You may have the right to request human review of AI-driven decisions, receive an explanation of how AI processing works, and contest automated outcomes. Contact your prospective employer or email us at privacy@hyretech.ai.

7. Who we share data with

We share data with clients and their authorised team members, cloud infrastructure providers, payment processors, analytics providers, and legal authorities when required by law. In the event of a merger or acquisition, data may transfer to the successor entity.

We do not sell personal data. We do not use candidate data for advertising.

PurposeWhat they receive
Cloud infrastructure (Google Cloud Platform)Compute, storage, secrets and logs — all categories of platform data
Database hosting (Supabase)The primary datastore, including candidate data
AI inference (OpenRouter, routing to the upstream model provider)Resume text and candidate-derived prompt content
Embeddings (Google Vertex AI)Resume text, converted to numeric vectors
LLM observability (Langfuse)Prompt and response traces, which may include resume text
Payments (Stripe)Billing contact and payment identifiers. We never store card numbers
Transactional email (Mailjet)Recipient name and email address
Error and product analytics (Sentry, PostHog)Diagnostic and event telemetry. Request bodies, cookies and authorization headers are not sent

The current list, with locations and purposes, is available on request and forms part of the Data Processing Agreement for Enterprise clients. We give notice before adding a sub-processor that handles candidate data.

8. Google API Services

HyreTech’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We only use data obtained through Google APIs for the purposes described in this Privacy Policy and do not use it for serving advertisements or transfer it to third parties for unrelated purposes.

9. International transfers

We are based in Singapore and our production infrastructure runs in the asia-southeast1 (Singapore) region. Some vendors process data elsewhere — error tracking is hosted in the United States and product analytics in the EU. For transfers out of Singapore we rely on the receiving organisation being bound to PDPA-comparable protection; for EU/UK transfers, on Standard Contractual Clauses or an adequacy decision. Contact privacy@hyretech.ai for details.

10. Retention

We keep candidate data for the period set by the client (default 12 months), account data for the duration of the contract plus 5 years, billing records for 7 years, and usage logs for 24 months before anonymisation. Data is securely deleted or anonymised when no longer needed.

Deletion requests are actioned within 30 days. Deleting your account takes effect immediately — subsequent authenticated requests fail — and queues an irreversible purge of personal data that runs after a 30-day grace window. The grace period is deliberate: an account deleted in error can be recovered by contacting support before the purge runs, while erasure still completes inside the 30-day SLA. Data can be exported for 30 days after termination.

11. Your rights

Depending on where you are, you may have the right to access, correct, delete, or port your data, restrict or object to processing, withdraw consent, and lodge a complaint with a supervisory authority.

Candidates:Direct your request to the employer who manages your data through HyreTech. We process candidate data on behalf of our clients and cannot independently fulfil requests without the client’s instruction. If you contact us at privacy@hyretech.ai, we’ll forward it to the relevant client.

Clients and users: Contact us directly at privacy@hyretech.ai.

We respond within 30 days, and within any shorter period applicable law requires.

12. Cookies

We use cookies essential for platform functionality (authentication, security) and analytics cookies to understand how the platform is used. Non-essential cookies require your consent where applicable — if you are in the EEA, the UK or Switzerland we ask before analytics cookies are set. You can change your choice here at any time, or manage cookies through your browser settings.

Analytics cookies follow the default for your region.

If you arrive through a referral link, we store the referral code in a functional cookie for 30 days so the referral is still credited if you browse the site before signing up. It holds only the code — no name, email, or other identifying information about you or the person who referred you.

13. Security

We protect data with encryption in transit and at rest, role-based access controls, regular security assessments, audit logging, and incident response procedures. In the event of a data breach, we notify the relevant authorities and affected individuals as required by law.

14. Changes

We may update this policy. Material changes will be communicated on our website and, where appropriate, by email.

15. Contact

Privacy requestsprivacy@hyretech.ai
General enquirieshello@hyretech.ai

HyreTech Pte. Ltd.
77 High Street, #10-12B, High Street Plaza, Singapore 179433
hyretech.ai