Version 1.3 – Last Updated: 06/08/2024
RecruitPilot AI Privacy Notice
Welcome to RecruitPilot AI! This Privacy Notice outlines how we collect, use, and protect your personal information when you interact with our products and services, including Custom GPTs available in the GPT store, our Chrome extension, and our Web app. By using our services, you consent to the collection and use of your information as described in this Privacy Notice.
- 1. Scope of this Privacy Notice
- - RecruitPilot AI Limited ("RecruitPilot AI," "RP AI," "we," "us," and "our") respects your privacy.
- - This privacy notice applies to personal information collected when you interact with our 'RecruitPilot AI GPTs' available in the GPT store ('GPT Interactions'); use our products, including our 'chrome extension' and our 'web app' and any of our computer or mobile software applications (collectively, 'Apps'); visit or use our website (the 'Website') https://recruitpilot.ai; participate in our business relationships as a client or supplier contact of ours ('Business Relationships'); interact with our social media accounts and pages ('Social Media Pages'); access any services accessible through the Website or Apps, including GPT Interactions (collectively, the 'Services'); participate in offline sales and marketing activities.
- - This Privacy Notice, together with our Data Processing Agreement (DPA), outlines how RP AI Limited collects, uses, and protects personal information. The DPA provides further detail on the specific terms under which we process personal data on behalf of our clients and users. For the purposes of this privacy notice, all references to the Website shall include a reference to the Apps.
- 2. What Personal Information Do We Collect?
- - Your usage details, interaction data, and feedback.
- - Your full name, email address, telephone number, transaction details, usage details, interaction data, and feedback.
- - Your full name, email address, postal address, telephone number, and transaction details.
- - Information provided by completing forms on our Apps or Website, such as signing up for communications or events, searching for products or services, and creating accounts (log-in and password details).
- - Information from messages or posts on our Social Media Pages.
- - Information in communications sent to us, such as reporting problems or submitting queries.
- - Data from surveys conducted for research purposes if you choose to participate.
- - Information collected automatically when you use our Apps and Website, such as usage details, geo-location data, IP addresses, and information through cookies and other tracking technologies. Users may manage their consent preferences, including opting out of marketing communications, via their account settings or by contacting us directly at privacy@recruitpilot.ai.
- 3. How Do We Use Personal Information Relating to You?
- - To provide and improve our services, including delivering our products and services to your employer or potential employer.
- - To fulfill our contractual obligations and provide requested information, products, and services.
- - To provide information about products and services that may interest you, with your consent.
- - To ensure content from our Apps and Website is presented effectively.
- - For internal operations including troubleshooting, data analysis, testing, research, statistical, and survey purposes.
- - To keep our Apps and Website safe and secure.
- - To measure and understand the effectiveness of advertising and deliver relevant ads to you.
- - To conduct our internal business processes, such as accounting and auditing.
- - To further develop our products and services.
- - For any other purposes required by law.
- 4. Legal Basis for Processing Personal Information
- - Where you have given consent for specific purposes.
- - Where processing is necessary for a contract with you or to take steps before entering into a contract.
- - Where processing is necessary to comply with legal obligations.
- - Where processing is in our legitimate interests or those of a third party, provided your interests or rights do not override them.
- 5. Compliance with Global Data Protection Regulations
- - We comply with the GDPR ((EU) 2016/679) for users in the European Economic Area (EEA).
- - We comply with the CCPA for users in California, USA, granting additional rights regarding their personal information.
- - We comply with relevant regulations under the AI Act concerning the use of artificial intelligence technologies.
- - We adhere to SOC 2 standards for the security, availability, processing integrity, confidentiality, and privacy of customer data.
- - RP AI also complies with the Brazilian General Data Protection Law (LGPD), the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada, and other applicable data protection laws. We ensure that personal data is processed in accordance with the highest standards of data protection across all jurisdictions. For a detailed understanding of our data processing practices and compliance with these regulations, please refer to our Data Processing Agreement (DPA). The DPA outlines the specific measures we take to ensure compliance, including our obligations and those of our users.
- 6. Do We Share Your Personal Information with Any Third Parties?
- - We may share personal information with other companies within our group involved in providing products and services to you or your employer or potential employer and who may use personal information in accordance with this notice.
- - We may share personal information with third-party service providers who assist us with running our business, including customer support, payment processing, contractors, and IT services. These providers are bound by contractual obligations to keep personal information confidential and use it only for the purposes for which we disclose it to them.
- - We may share personal information with companies that assist with improving and optimizing our Apps and Website, including analyzing user behavior and trends.
- - We may share personal information with lawyers, accountants, tax advisors, and auditors who need access to personal information to provide their services.
- - We may share personal information with law enforcement bodies, courts of law, or as otherwise required or authorized by law, for compliance with legal obligations or to protect our rights, property, or safety, or that of our users, clients, or others.
- - We may disclose personal information in the event that we sell or buy any business or assets, in which case we may disclose personal information to the prospective seller or buyer of such business or assets.
- - If we are acquired by a third party, personal information held by us about our users will be one of the transferred assets.
- - We may disclose personal information to comply with legal obligations or to enforce or apply our terms of use or other agreements, or to protect the rights, property, or safety of RP AI, our customers, or others.
- - All sharing of personal information with third parties, including service providers and group companies, is governed by the terms specified in our Data Processing Agreement (DPA). This agreement details the roles and responsibilities of third parties in handling and protecting your personal information. Before sharing personal information with third parties, we take steps to ensure that the third party will protect the personal information in accordance with applicable privacy laws and in a manner consistent with this notice. Third parties are required to restrict their use of this information to the purpose for which the information was provided.
- - For international data transfers, we implement safeguards such as standard contractual clauses, adequacy decisions, or other lawful mechanisms to ensure the protection of personal data.
- 7. LinkedIn API Data Integration
- - RecruitPilot integrates with LinkedIn APIs to facilitate recruitment, employer branding, job advertising, and platform functionality. As part of this integration, RecruitPilot may automatically access and process certain LinkedIn data related to users’ organizational activities and publicly available LinkedIn content.
Types of LinkedIn data we may collect include, but are not limited to:
Organization (Company) data (such as name, industry, size, logo, description, website URL)
Job posting data (such as titles, descriptions, locations, application methods)
Recruitment-related metadata (such as posting status updates or application events)
Public LinkedIn profile attributes as authorized by LinkedIn policies
Purpose of Processing: RecruitPilot uses LinkedIn data to:
Enable job posting, job management, and candidate engagement features
Enhance job listings with accurate company branding and organizational context
Facilitate content sharing and platform interactions with LinkedIn
Lawful Basis for Processing: RecruitPilot processes LinkedIn data based on legitimate interest (for recruitment service provision) and contractual necessity (to provide services requested by our users or organizational clients), in compliance with applicable data protection laws including the GDPR and CCPA.
Data Protection and User Rights: RecruitPilot processes LinkedIn data in accordance with LinkedIn’s API Terms of Use, Developer Policies, and relevant data protection regulations.
Individuals have the right to:
Access the personal data RecruitPilot holds about them
Request correction of inaccurate data
Request deletion of their personal data
Object to certain processing activities
Request data portability where applicable
Requests regarding LinkedIn-sourced data can be submitted by contacting us at [insert your contact email].
We only retain LinkedIn data for as long as necessary to fulfill the purposes outlined above or as required by applicable law. Users may revoke RecruitPilot’s access to LinkedIn data at any time via LinkedIn settings or by contacting us directly.
For further information about LinkedIn’s own data processing practices, please refer to the LinkedIn Privacy Policy.
- 8. Third-Party Policies
- - Our services are integrated with third-party platforms and services, and we adhere to their privacy and usage policies: Google: Our React web app uses Firebase for user authentication, and our services comply with Google's privacy, security, and usage policies. This includes data handling as specified by Google API Services User Data Policy, including the Limited Use requirements, Apple: Our Apps available on Apple platforms comply with Apple's privacy policies and guidelines, OpenAI: Our products, including Custom GPTs and the Wingman Chrome extension, comply with OpenAI's privacy and usage policies. This includes adhering to OpenAI’s standards for data handling, security, and user privacy.
- 9. How Do We Protect Your Personal Information?
- - Information in transit is encrypted using Secure Sockets Layer (SSL) / Transport Layer Security (TLS) and stored using 256-bit AES encryption.
- - Access to personal information is restricted to authorized personnel who need it for their duties.
- - We conduct regular audits of our information security practices.
- - Employees receive training on data protection best practices.
- - For comprehensive details on our security measures, including how we manage data breaches and safeguard personal data, please consult our Data Processing Agreement (DPA). The DPA provides a complete overview of our information security practices and the protocols we follow to protect your data. In case of a data breach, we have procedures to take necessary actions promptly and notify affected individuals as required by law.
- 10. Where Do We Store Personal Information?
- - Personal information may be transferred to, stored, and processed outside the European Economic Area (EEA). We ensure appropriate safeguards are in place for such transfers, including: Transfers to countries deemed to provide adequate protection by the European Commission, Contracts that ensure personal information has the same protection as in Europe, Approved binding corporate rules for data protection within our group.
- 11. Cookies and Tracking Technologies
- - Our Apps and Website use cookies to distinguish users and improve user experience. We use cookies that: Are necessary for the operation of our website, Help us understand how our website is used and improve functionality, Remember your preferences and personalize content, Track your visit and interests to display relevant ads.
- - You can block cookies via your browser settings, but doing so may limit access to some services.
- 12. Your Rights
- - You have the right to request access to personal information we hold about you.
- - You have the right to request correction of any inaccurate or incomplete personal information.
- - You have the right to request the deletion of your personal information, subject to certain exceptions.
- - You have the right to request the restriction of processing of your personal information in certain circumstances.
- - You have the right to object to the processing of your personal information where we are relying on legitimate interests as the legal basis.
- - You have the right to request the transfer of your personal information to another organization, or directly to you, in a structured, commonly used, and machine-readable format.
- - Where we rely on your consent to process your personal information, you have the right to withdraw your consent at any time.
- - To exercise these rights, please contact us at privacy@recruitpilot.ai. We will respond to your request within 7 days, in accordance with applicable data protection laws. In certain circumstances, we may request additional information to verify your identity before processing your request. If you have a concern about the way we are collecting or using your personal information, we request that you raise your concern with us first. You can also contact the Information Commissioner’s Office (ICO) at https://ico.org.uk/concerns/.
- 13. Third-Party Links
- - Our Apps and Website may contain links to external sites. We are not responsible for the privacy policies of these external sites. Please review their policies before submitting personal information.
- 14. Social Media Platforms
- - Engagement on social media platforms is subject to the terms and privacy policies of those platforms. We are not responsible for their policies. Review these policies before submitting personal information.
- 15. Data Retention
- - We retain personal information only as long as necessary for the purposes for which it was collected, including legal, regulatory, tax, accounting, or reporting requirements. Retention periods are determined based on the nature and sensitivity of the information and potential risk of harm from unauthorized use or disclosure. For example, we may retain contact details for marketing purposes until consent is withdrawn. Specific retention periods are determined based on the type of data and the purpose for which it was collected. Our data retention practices, including the methods used for data deletion or return at the end of the retention period, are fully outlined in our Data Processing Agreement (DPA). The DPA specifies the conditions under which personal data is retained and the procedures for securely disposing of it.
- 16. Fair Usage Policy
- - To ensure fair use of our services, including our chrome extension and web app, we implement token limits and monitor for abuse. Usage beyond specified limits or abusive behavior may result in suspension or termination of access.
- 17. Changes to this Notice
- - We review and update this privacy notice regularly. Changes will be posted on this page, and significant updates may be communicated via email. Please review this page periodically for updates.
- 18. Version Control and Document History
- - We maintain version control to ensure the most current version of our Terms is always available to our users. Each update to the Terms will include a new version number and date to indicate when the changes took effect. Users are responsible for reviewing the Terms periodically to stay informed about any changes. Continued use of the Services following the posting of a new version indicates your acceptance of the modified Terms.
- - Version 1.0: Initial version published on [17/03/2024]. Version 1.1: Updated on [03/05/2024] to include legal basis for processing, data portability, and additional security measures. Version 1.2: Updated on [22/07/2024] to enhance cookie policy and information on automated decision-making. Version 1.3: Updated on [06/08/2024] to enhance scope and personal information we collect.
- 19. Contacting Us
- - If you have any questions regarding this privacy notice, please contact us at: RecruitPilot AI Limited, 85 Great Portland Street, First Floor, London, W1W 7LT, Email: privacy@recruitpilot.ai.