1. Who we are

SmartHire is operated by HRD (“SmartHire”, “we”, “us”). We provide software that hiring teams (our customers) use to run WhatsApp-based candidate screening, scheduling, and ATS integration.

Our role: For candidate personal data, our customer — the recruiting company — is the data controller. SmartHire acts as a data processor on the customer's documented instructions, under a Data Processing Agreement (DPA).

For our own website visitors and customer account users (recruiters, admins, hiring managers), SmartHire is the data controller.

2. What data we process

Candidate data (processor role)

When a candidate interacts with a SmartHire-powered WhatsApp number, we process:

Customer account data (controller role)

Marketing site visitors

See the Cookies, local storage, and analytics section below. In short: the marketing pages under smarthire.chat do not set cookies and do not run analytics on legal pages. The signed-in dashboard at app.smarthire.chat uses first-party session cookies plus PostHog product analytics (EU region, localStorage-only, no cookies).

3. Why we process it — purposes and legal bases

When SmartHire acts as processor, the legal basis is set by the controller (our customer) and covered in the DPA. When SmartHire acts as controller, we rely on the following bases under Article 6 of the EU General Data Protection Regulation (GDPR):

PurposeLegal basis
Deliver the WhatsApp screening & scheduling service to our customerContract (Art. 6(1)(b)) — with the customer; candidate data processed on the customer's instructions
Voice-note transcription (candidate voice messages)Consent (Art. 6(1)(a)) where required by local law; captured in the WhatsApp conversation flow when the candidate chooses to send a voice note
Account authentication and access controlContract (Art. 6(1)(b))
Security monitoring, fraud prevention, service integrityLegitimate interests (Art. 6(1)(f))
Legal compliance (record-keeping, responding to lawful requests)Legal obligation (Art. 6(1)(c))
Product improvement (aggregated, non-identifying metrics)Legitimate interests (Art. 6(1)(f))

We also align our practices with applicable data-protection legislation in the customer's jurisdiction, including local privacy laws that apply to employee and candidate data.

4. How long we keep data (retention)

Default retention for candidate data is 365 days from the candidate's last activity (last message, last status change). Each customer can configure a shorter or longer retention window in their SmartHire settings, subject to the maximum allowed under their governing law.

5. Sub-processors

SmartHire uses vetted sub-processors to deliver the service. All are bound by written agreements with confidentiality and security obligations at least as strict as those we owe our customers.

A full, current list is published at /subprocessors/. We notify customers at least 30 days before adding a new sub-processor, so they can object.

6. International transfers

All customer data is stored and processed in the European Union — specifically the AWS eu-central-1 (Frankfurt) region. This includes DynamoDB storage, S3 object storage, Lambda compute, and AI model inference via Amazon Bedrock.

Two limited exceptions:

7. Your rights as a data subject

Under GDPR and equivalent legislation, individuals whose personal data we process have the right to:

How to exercise these rights

If SmartHire holds your data as a processor (candidate data), the fastest route is through the recruiting company that contacted you — they control the record. You can also email us directly and we will route your request to the appropriate controller.

To reach us: privacy@smarthire.chat. Please include enough detail for us to identify the record (for example, the phone number you used with the recruiting company, or the name of the recruiter/company you spoke with).

We respond to verified requests within 30 days. Complex requests may take up to 60 days, in which case we will let you know within the first 30.

8. Automated decision-making

SmartHire uses AI (large language models running on Amazon Bedrock, currently Anthropic Claude models) to conduct screening conversations, extract structured data, score candidate answers, and produce a recommendation for the recruiter.

By default, the recruiter or hiring manager makes the final decision on advancing or rejecting a candidate — SmartHire's scoring is a recommendation, not an automated decision with legal or similarly significant effect. Where a customer chooses to enable “autonomous mode” for advancement to interview, the system will automatically progress candidates who pass all mandatory criteria; rejections always require human review.

You have the right to request human review of any AI-produced screening decision that affects you. Contact privacy@smarthire.chat or the recruiting company directly.

9. Security

Summary of core controls:

See our full Trust & Security page for the current control set, roadmap, and incident-response policy.

10. Cookies, local storage, and analytics

The marketing site at smarthire.chat uses a minimal set of technologies:

11. Changes to this policy

We update this policy as our service evolves. Material changes are announced to account admins by email at least 30 days before they take effect. The changelog below records past updates.

12. Contact

Privacy inquiries: privacy@smarthire.chat
Security disclosures: security@smarthire.chat
Legal / DPA requests: legal@smarthire.chat
General: hi@smarthire.chat