AITACS Talent — Recruiting Calendar & CRM Suite  ·  Terms · Privacy · Informed Consent
AITACS Talent — Legal Documentation

Privacy Policy

Effective Date: 2026-07-13  ·  Last Updated: 2026-07-13  ·  Version: 0.2-draft  ·  Provider: Artem Chukov, Israel

GDPR Israeli Privacy Law EU AI Act NYC LL144
"Provider" / "We" — Artem Chukov, sole proprietor, registered in the State of Israel (עוסק פטור 345086623). Contact: talent@aitacscrm.app. Where the Recruiter/Client Employer is the data controller of Candidate data (see Section 5), the Provider acts as data processor on the Recruiter's instructions.

1. Data We Collect

The Platform collects the following categories of data. By design, the Candidate data schema does not include: date of birth, gender, marital status, education level unrelated to the role, religion, nationality/ethnicity, photo, or health information — these fields simply do not exist in the Platform's candidate record, as an anti-discrimination safeguard (see Section 3).

2. Data Flow Transparency

Candidate data entered by a Recruiter is stored in the Platform's database and is visible only to that Recruiter's account (and, where applicable, other authorized members of the same organization). Data is not shared with other Recruiters or made searchable across accounts.

The Platform's AI features are implemented as three distinct mechanisms with different data-handling profiles, described in full in Section 3. In summary: the "Elia for HR" chat assistant and the AI candidate-analysis feature are bias-safe by design (de-identified before transmission); résumé and company-document import is not, because its purpose is precisely to extract identifying data from an uploaded document. Each AI exchange that is logged is logged for bias-audit purposes as described in Section 3.

3. AI Data Processing — Three Mechanisms, Not One

The Platform uses OpenAI models in three distinct features. They are described separately here because they have materially different data-handling profiles — a single blanket statement ("the AI never sees identifying data") would be inaccurate for one of the three.

3.1 "Elia for HR" chat assistant and AI candidate analysis (bias-safe by design)

Before a request reaches the AI model for the dashboard chat assistant or for candidate-card analysis (gap analysis, screening, interview questions, scorecard summaries, red-flag review), the Platform automatically strips: full name, phone number, email address, and résumé file link, and scrubs email/phone-like patterns from free-text notes. The Candidate is represented to the AI model only by an auto-generated pseudonym plus job-relevant professional data. This is the same purpose-built mechanism that, in the Platform's companion product for healthcare professionals, implements HIPAA Safe-Harbor de-identification — here it is repurposed as an anti-discrimination control: the AI physically does not receive the categories of information (age, gender, race, disability, religion, marital status, etc.) that anti-discrimination law prohibits from being used as hiring factors. Every such call is recorded in an audit log (fields redacted, model used, human-review status) — the evidentiary basis for the bias-reporting dashboard in Section 13.

3.2 Résumé and company-document import (not de-identified)

Bulk import of CVs or client lists uses AI to extract a candidate's or company's name, contact details, and other information from an uploaded document — that extraction is the feature's purpose, so this data is not stripped before being sent to the AI model. Protection here relies instead on the AI subprocessor's zero/short data-retention terms (Section 8) and the Platform's own short-term handling of the uploaded file, not on pre-redaction. Recruiters should not upload documents containing special-category data (health information, government ID numbers, etc.) beyond what the source document already contains.

4. How We Use Data

Candidate and Vacancy data is used solely to provide the Platform's recruiting-workflow functionality: scheduling interviews, tracking pipeline stage, generating analytics for the Recruiter, and (where enabled) AI-assisted screening and interview-question preparation. Data is not used to train third-party AI models (see Section 8 for subprocessor-specific retention terms) and is not sold or shared for advertising.

5. Legal Basis for Processing (GDPR)

Processing of Candidate personal data relies on consent (GDPR Art. 6(1)(a)) as the primary legal basis, obtained by the Recruiter using the Informed Consent Template — not "legitimate interest," which is legally contested as a basis for candidate-sourcing and screening practices in several jurisdictions. Processing of Recruiter account data relies on contract performance (Art. 6(1)(b)).

The Provider is an Israeli-registered sole proprietor, so the Israeli Protection of Privacy Law, 5741-1981, and the Protection of Privacy Regulations (Data Security), 5777-2017, apply directly to the Provider's own processing of personal data, in parallel with GDPR for EU/EEA data subjects and with the Law of Ukraine "On Protection of Personal Data" for data subjects located in Ukraine. These regimes apply concurrently, not as alternatives — see Section 9 of the Terms of Service for how conflicts between them are resolved.

6. Candidate Rights (GDPR Articles 15–22)

Right of Access

Request a copy of all personal data held about you. (Art. 15)

Right to Rectification

Request correction of inaccurate or incomplete data. (Art. 16)

Right to Erasure

Request deletion of your data ("right to be forgotten"). (Art. 17)

Right to Data Portability

Receive your data in a structured, machine-readable format. (Art. 20)

Right to Restrict Processing

Request limitation of how your data is processed. (Art. 18)

Right Not to Be Subject to Automated Decision-Making

No decision materially affecting you is made solely by the AI Assistant without human review. (Art. 22)

Because Candidates are not Platform account holders, rights requests should be directed to the Recruiter (or Client Employer) who entered your data, who acts as data controller. Where the Recruiter cannot be reached, requests may be sent to talent@aitacscrm.app; we will respond within 30 days.

You have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction.

7. Technical Security Measures

7.1. Encryption in transit: TLS 1.2 or higher for all data transmitted between the Recruiter's browser, our servers, and third-party services.

7.2. Authentication: Firebase Authentication; two-factor authentication is recommended.

7.3. De-identification: automatic removal of identifying fields before any AI transmission, as described in Section 3.

7.4. Access control: each Recruiter account's data is isolated by Firebase UID; accounts cannot access another account's Candidate data.

7.5. Backups: regular database backups with encrypted storage.

8. Third-Party Data Sharing and Subprocessors

The Platform shares data with the following subprocessors, each performing a specific and limited function. This list reflects the integrations actually implemented in the Platform's backend at the time of writing.

SubprocessorCountryFunctionData Shared
OpenAI, LLC USA Chat assistant, candidate analysis, and résumé/document-import extraction (three distinct features — see Section 3) For the chat assistant and candidate analysis: pseudonym + de-identified professional data only (skills, salary expectations, notice period) — no name, contact info, or protected characteristics. For résumé/document import: the uploaded document's content as-is, including any name and contact details it contains, because extracting that data is the feature's purpose (see Section 3.2).
Google Firebase USA Recruiter authentication Email address, UID
Google LLC — Calendar API USA OAuth-based calendar synchronisation for scheduled interviews Interview date, time, and event title configured by the Recruiter. Subject to the Google API Services User Data Policy Limited Use requirements (see notice below).
Zapier, Inc. USA Webhook relay for interview-scheduling metadata when a Recruiter connects their own Zoom account via a Zapier automation ("meeting ended" trigger). Zoom itself is the Recruiter's own third-party tool, independent of the Platform — the Platform has no direct Zoom API integration or Zoom account. Meeting ID, meeting topic, host/participant email, scheduled start/end time, and (if the Recruiter's Zoom account produced one) a recording URL, forwarded to the Platform via a shared webhook secret.
Hetzner Online GmbH Germany / Finland MySQL database and application hosting All Platform data (encrypted in transit). Own, isolated database — not shared with the companion coach/therapist product.

A live video/audio interview widget ("Transcription Module") exists in the Platform's coach product and has not yet been adapted or activated for this product; its subprocessor (if and when enabled here) will be added to this table before activation, not assumed in advance.

The Recruiter will be notified at least 14 days in advance of any new subprocessor being added.

Google API Services User Data Policy — Limited Use Disclosure

The Platform's use and transfer of information received from Google APIs (including the Google Calendar API) to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used solely to create, read, and synchronise interview events for the scheduling feature described in this Policy, is never sold, and is never used for advertising.

9. International Data Transfers

Where subprocessors are located outside the Recruiter's or Candidate's jurisdiction, transfers rely on Standard Contractual Clauses (SCCs) or an equivalent adequacy mechanism, as maintained by each subprocessor.

10. Data Retention (Ongoing, Per Candidate)

This section governs how long an individual Candidate's data is kept in the Platform during the Recruiter's active use — a separate question from how long the Recruiter's account data is retained after the Recruiter's subscription itself ends (see Terms of Service §8).

Each Candidate record has a data_retention_until field that the Recruiter sets. The Platform does not apply an automatic default value to this field — if the Recruiter does not set it, the record is not automatically flagged for deletion. Recruiters are responsible for setting a retention date consistent with the GDPR storage-limitation principle and their own record-keeping obligations; a period of 6–24 months is typical depending on jurisdiction, but the Platform does not enforce any particular value. [ПЛЕЙСХОЛДЕР: автоматизована крон-задача видалення/повторного запиту згоди після спливу `data_retention_until` — на момент цього чернетки не реалізована в for-hr/api/, потребує окремої задачі. До її реалізації навіть встановлена рекрутером дата не призводить до автоматичного видалення.]

Interview recordings (where consent was given) are retained for [ПЕРІОД — TBD, узгодити з юристом залежно від юрисдикції] and may be deleted earlier at the Candidate's request.

11. Cookies and Tracking

The Platform uses only strictly necessary cookies/local storage for authentication session state and application preferences. See the Cookie Policy for details. [ПЛЕЙСХОЛДЕР: окремий `cookie-policy.html` для for-hr ще не створено — coach-версія не переноситься автоматично.]

12. Children's Privacy

The Platform is intended for use by adult professionals recruiting adult candidates. It is not directed at children, and we do not knowingly process data of individuals under the applicable age of majority in the relevant jurisdiction as a Candidate or Recruiter.

13. Jurisdiction-Specific Provisions for Hiring

NYC Local Law 144 (Automated Employment Decision Tools)

Where the Platform's AI Assistant is used to substantially assist or replace discretionary decision-making for employment decisions concerning candidates in New York City, the Recruiter (as employer or employment agency) is responsible for: independent bias audit publication, advance candidate notice (≥10 business days), and providing an alternative selection process or accommodation upon request. The Platform's AI-screening log (Section 3) supports but does not replace these obligations.

EU AI Act — High-Risk AI System (Employment, Annex III)

AI systems used in recruitment and selection of natural persons are classified as high-risk under the EU AI Act. The Platform is designed to support the corresponding obligations (human oversight, logging, bias mitigation via de-identification) but the Recruiter/Client Employer, as deployer, retains independent obligations under the Act (e.g., informing candidates, maintaining usage records) that this Policy does not substitute for.

EU Pay Transparency Directive

Where applicable, the Vacancy's salary range must be disclosed to Candidates no later than the point required by law (e.g., in the job posting or before the first interview), and Candidates must not be asked about their salary history. The Vacancy record's `must_disclose_range` flag and the Analytics "pay transparency" report support Recruiter compliance with this obligation.

Illinois Artificial Intelligence Video Interview Act (and similar statutes)

Where video interviews are recorded and analyzed using AI, applicable law may require: advance notice to the Candidate, explicit consent before the interview, an explanation of how the AI evaluates responses, and deletion of the recording within a specified period upon request. See the Informed Consent Template, Section E.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to Recruiters through the Platform or by email before taking effect.

15. Contact

Questions about this Privacy Policy may be sent to talent@aitacscrm.app.

Related Compliance Documents

Terms of Service · Privacy Policy · Informed Consent Template · Cookie Policy · Data Processing Agreement (DPA) · Recruitment Data Sharing Agreement · Subprocessor List · Security Requirements · Incident Response Policy · Security Overview · Refund Policy · Copyright Policy · Contact Us