1. Who we are
SmartHire is operated by HRD (“SmartHire”, “we”, “us”). We provide software that hiring teams (our customers) use to run WhatsApp-based candidate screening, scheduling, and ATS integration.
Our role: For candidate personal data, our customer — the recruiting company — is the data controller. SmartHire acts as a data processor on the customer's documented instructions, under a Data Processing Agreement (DPA).
For our own website visitors and customer account users (recruiters, admins, hiring managers), SmartHire is the data controller.
2. What data we process
Candidate data (processor role)
When a candidate interacts with a SmartHire-powered WhatsApp number, we process:
- Contact identifiers — WhatsApp phone number (stored as a SHA-256 hash after initial routing), display name if provided by WhatsApp.
- CV / resume — PDF, image, or document uploaded via WhatsApp; parsed text extract; storage reference.
- Message content — the full WhatsApp conversation transcript with the SmartHire bot, including text, buttons, list selections, and media.
- Voice notes — when a candidate sends a voice message, we generate and store a text transcript. Original audio is retained short-term (up to 30 days) to allow retry.
- Screening answers — structured responses to the customer's qualifying questions (experience, availability, location, salary expectations, etc.).
- Interview scheduling — slot preferences, confirmed times, calendar invite metadata.
- Application status — bot recommendation, recruiter/hiring-manager decisions, timestamps.
Customer account data (controller role)
- Account holder name, work email, Google profile (if signed in via Google), country.
- Role assignments (org admin, recruiter, interviewer, hiring manager).
- Authentication events, IP address, user-agent, session tokens.
- Billing contact (once billing is active).
Marketing site visitors
See the Cookies, local storage, and analytics section below. In short: the marketing pages under smarthire.chat do not set cookies and do not run analytics on legal pages. The signed-in dashboard at app.smarthire.chat uses first-party session cookies plus PostHog product analytics (EU region, localStorage-only, no cookies).
3. Why we process it — purposes and legal bases
When SmartHire acts as processor, the legal basis is set by the controller (our customer) and covered in the DPA. When SmartHire acts as controller, we rely on the following bases under Article 6 of the EU General Data Protection Regulation (GDPR):
| Purpose | Legal basis |
|---|---|
| Deliver the WhatsApp screening & scheduling service to our customer | Contract (Art. 6(1)(b)) — with the customer; candidate data processed on the customer's instructions |
| Voice-note transcription (candidate voice messages) | Consent (Art. 6(1)(a)) where required by local law; captured in the WhatsApp conversation flow when the candidate chooses to send a voice note |
| Account authentication and access control | Contract (Art. 6(1)(b)) |
| Security monitoring, fraud prevention, service integrity | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance (record-keeping, responding to lawful requests) | Legal obligation (Art. 6(1)(c)) |
| Product improvement (aggregated, non-identifying metrics) | Legitimate interests (Art. 6(1)(f)) |
We also align our practices with applicable data-protection legislation in the customer's jurisdiction, including local privacy laws that apply to employee and candidate data.
4. How long we keep data (retention)
Default retention for candidate data is 365 days from the candidate's last activity (last message, last status change). Each customer can configure a shorter or longer retention window in their SmartHire settings, subject to the maximum allowed under their governing law.
- Candidate erasure requests: we execute deletion within 30 days of a validated request; audit-log entries recording the erasure are retained.
- Voice-note audio (original): up to 30 days, then automatically deleted; text transcript follows the candidate retention window.
- Audit logs: retained for the life of the customer account plus 12 months for security and dispute-resolution purposes.
- Backups: encrypted; overwritten on the normal backup cycle (typically within 35 days). Erasure from live systems propagates to backups on the next full cycle.
- Marketing / account data: retained while the account is active, plus 24 months after account closure for legal and financial record-keeping.
5. Sub-processors
SmartHire uses vetted sub-processors to deliver the service. All are bound by written agreements with confidentiality and security obligations at least as strict as those we owe our customers.
A full, current list is published at /subprocessors/. We notify customers at least 30 days before adding a new sub-processor, so they can object.
6. International transfers
All customer data is stored and processed in the European Union — specifically the AWS
eu-central-1 (Frankfurt) region. This includes DynamoDB storage, S3 object storage,
Lambda compute, and AI model inference via Amazon Bedrock.
Two limited exceptions:
- WhatsApp delivery: messages transit the Meta / WhatsApp Business platform, which may route through Meta infrastructure outside the EU. This transfer is governed by Meta's own Data Processing Terms and Standard Contractual Clauses.
- Support access: if a customer opens a support ticket, their authorized account name and issue description may be viewed by SmartHire personnel; personnel outside the EU access data only under a Standard Contractual Clauses (SCC)-based transfer mechanism.
7. Your rights as a data subject
Under GDPR and equivalent legislation, individuals whose personal data we process have the right to:
- Access — get a copy of your personal data.
- Rectification — correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — ask us to delete your data.
- Portability — receive your data in a structured, machine-readable format.
- Restriction — ask us to pause processing while a concern is resolved.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
- Complain — lodge a complaint with your local data-protection authority.
How to exercise these rights
If SmartHire holds your data as a processor (candidate data), the fastest route is through the recruiting company that contacted you — they control the record. You can also email us directly and we will route your request to the appropriate controller.
To reach us: privacy@smarthire.chat. Please include enough detail for us to identify the record (for example, the phone number you used with the recruiting company, or the name of the recruiter/company you spoke with).
We respond to verified requests within 30 days. Complex requests may take up to 60 days, in which case we will let you know within the first 30.
8. Automated decision-making
SmartHire uses AI (large language models running on Amazon Bedrock, currently Anthropic Claude models) to conduct screening conversations, extract structured data, score candidate answers, and produce a recommendation for the recruiter.
By default, the recruiter or hiring manager makes the final decision on advancing or rejecting a candidate — SmartHire's scoring is a recommendation, not an automated decision with legal or similarly significant effect. Where a customer chooses to enable “autonomous mode” for advancement to interview, the system will automatically progress candidates who pass all mandatory criteria; rejections always require human review.
You have the right to request human review of any AI-produced screening decision that affects you. Contact privacy@smarthire.chat or the recruiting company directly.
9. Security
Summary of core controls:
- Encryption at rest (AWS-managed KMS) and in transit (TLS 1.2+).
- Strict tenant isolation: every database query is scoped to the customer's tenant ID at the data-access layer.
- Role-based access controls with MFA available for account users.
- Webhook signature verification on all inbound WhatsApp events.
- Append-only audit log for admin actions, erasures, and hiring-manager decisions.
See our full Trust & Security page for the current control set, roadmap, and incident-response policy.
10. Cookies, local storage, and analytics
The marketing site at smarthire.chat uses a minimal set of technologies:
- Google Fonts: we load the Heebo webfont from Google's CDN. Google may log the request. No cookies are set by this call.
- No analytics on legal pages:
/privacy/,/terms/,/subprocessors/,/trust/, and/dpa/do not run any analytics, tag manager, or advertising scripts. - Application session cookies: when you sign in at
app.smarthire.chat, we set first-party session cookies (Amazon Cognito) necessary to keep you logged in and to remember your locale preference. These are strictly necessary and are the only cookies set by the dashboard. - Product analytics on the dashboard (PostHog): once you are signed in to
app.smarthire.chat, we use PostHog (EU region,eu.i.posthog.com) for product analytics and session replay. PostHog is served same-origin via/ingest/*and is configured withlocalStoragepersistence — it sets no cookies; an anonymous identifier is kept in your browser's local storage. Session recordings mask every input field by default and are disabled entirely on login and credential pages. Analytics capture is limited to signed-in users; we do not share this data with advertisers. Legal basis: legitimate interests under GDPR Article 6(1)(f). You can clear local storage at any time via your browser to reset the anonymous identifier.
11. Changes to this policy
We update this policy as our service evolves. Material changes are announced to account admins by email at least 30 days before they take effect. The changelog below records past updates.
- 2026-10-04 Section 10 updated to disclose PostHog product analytics and session replay on the signed-in dashboard (EU region,
localStorage-only, no cookies). No changes to candidate-side processing. - 2026-07-20 Initial published version.
12. Contact
Privacy inquiries: privacy@smarthire.chat
Security disclosures: security@smarthire.chat
Legal / DPA requests: legal@smarthire.chat
General: hi@smarthire.chat