heyreeheyree
ProductFeaturesPricingAbout us
Log in
Legal information

Privacy Policy

for the use of the heyree website and platform (GDPR)

Effective from 1 April 2026 · Document version 1.0

At HeyHire we build everything on trust, transparency and the highest standard of data security. This document explains how we collect, use and protect personal data in compliance with Regulation (EU) 2016/679 (the GDPR) and applicable law.

These rules apply to the use of the HeyHire website and the cloud platform (referred to as „heyree").

Controller / operator
Company
HeyHire s.r.o.
Registered seat
Příčná 1892/4, Nové Město, 110 00 Prague 1, Czechia
Identification
Company ID 24441163 (registered with the Municipal Court in Prague, file C 440236)
Data protection contact
legal@heyree.com
This is an English translation provided for convenience. In the event of any discrepancy between language versions, the Czech version prevails.
Contents
  1. 1.Our role: when we act as controller and when as processor
  2. 2.What data we process as controller, and why
  3. 3.What data we process as processor, and why
  4. 4.Artificial Intelligence (AI) on the heyree platform
  5. 5.International data transfers
  6. 6.Analytics and tracking technologies (PostHog)
  7. 7.Where data are stored (data at rest)
  8. 8.Data recipients and sub-processors
  9. 9.Data retention
  10. 10.Personal data security
  11. 11.Your rights under the GDPR

1.Our role: when we act as controller and when as processor

From the perspective of data-protection law, our legal status changes depending on whose data we process and for what purpose. This distinction is crucial for the exercise of your rights:

A.HeyHire as CONTROLLER

Acting as controller, we process personal data of natural persons (data subjects), in particular visitors to our website, contact persons and users of our corporate customers, as well as billing and contractual data. In these cases we determine the purposes and means of the processing.

B.HeyHire as PROCESSOR

If you are our customer (an employer or agency) and use the heyree platform for recruitment, you upload personal data of applicants (Candidates) and other so-called Client Data. In this relationship, you (the customer) are always the Controller. We act exclusively as your processor and follow your instructions and the executed Data Processing Agreement (DPA).

Note for Candidates: If your data are held in heyree by a specific company you are applying to, please address requests to exercise your rights primarily to that company.

2.What data we process as controller, and why

If you are a customer representative, a service prospect or a website visitor, we process the following data about you:

2.1Contact, business and contractual data

  • What we process: First name, surname, business e-mail, phone, position, company, the content of our communication, company identification data, billing and payment data.
  • Why: For pre-contract negotiations, performance of the contract (onboarding, support delivery) and bookkeeping.
  • Legal basis: Processing is necessary for the performance of a contract or to take steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR), and processing is necessary for compliance with a legal obligation, e.g. in the area of tax law (Art. 6(1)(c) GDPR).

2.2Technical website and security data

  • What we process: IP address, device/browser identifiers, access logs.
  • Why: To secure our systems, prevent abuse and detect errors.
  • Legal basis: Processing is necessary for the purposes of our legitimate interests in ensuring cyber and information security (Art. 6(1)(f) GDPR in conjunction with recital 49).

2.3Marketing and website analytics

  • What we process: Data on your interaction with the website (e.g. on-page behaviour, technical identifiers) and your e-mail address if you subscribe to commercial communications.
  • Why: For traffic analysis, improving the website and sending commercial communications (B2B).
  • Legal basis: For advanced analytics, we process data on the basis of your free and informed consent (Art. 6(1)(a) GDPR).

Commercial communications are sent on the basis of your consent or within an existing business relationship with customers in compliance with Section 7 of Act No. 480/2004 Coll. To a limited extent we may also process data based on our legitimate interest (e.g. basic traffic measurement or protection against abuse of the service).

3.What data we process as processor, and why

If you are our corporate customer and use the heyree platform for recruitment, you upload personal data of applicants. We process these data exclusively on your behalf, on your instructions, and we are not responsible for determining the purposes and means of the processing.

3.1Client recruitment data (Candidate data)

  • What we process: Identification and contact data of Candidates, professional information (experience, education, skills), uploaded documents (CVs, portfolios, cover letters), internal communications, notes and evaluations from the selection process, and AI outputs generated from these data (e.g. automatic profile summaries).
  • Why: To enable us to provide you (our customer) with the features of the heyree ATS platform, allow you to manage selection processes effectively and use our AI assistance.
  • Legal basis: On our side (the Processor), processing takes place primarily on the basis of the Controller's instructions under the executed Data Processing Agreement (DPA) pursuant to Art. 28 GDPR.

To a limited extent, however, we may also process personal data for our own purposes, in particular to ensure the security, operation and improvement of the Service (e.g. technical logging, abuse prevention, error fixing), based on our legitimate interest under Art. 6(1)(f) GDPR.

Securing a valid legal basis vis-à-vis the Candidates themselves (e.g. their consent, legitimate interest or pre-contract steps) is fully your responsibility as the Controller. The exact access rights and retention periods are determined and managed by you directly in the heyree settings.

4.Artificial Intelligence (AI) on the heyree platform

HeyHire is a modern platform leveraging artificial intelligence. When using AI features (e.g. CV summarisation), we strictly observe security, ethics and the principles of Data protection by design and by default (Art. 25 GDPR).

AI principles in heyree that we strictly observe:

  • No automated decision-making: AI is only an assistive tool on our platform. The final decision (e.g. to hire/reject a candidate) is always made by a human.
  • Zero Retention: We exclusively use enterprise providers and configurations under which the content of prompts is not stored on their side.
  • No Training: It is contractually and technically guaranteed that global AI models are not trained on Client Data.

5.International data transfers

Although our primary data are stored and processed within the European Union, certain specific services (e.g. a secure AI gateway providing access to advanced models) may involve the transfer of part of the data to our sub-processors in third countries, in particular the United States.

Any transfer of data to third countries is always covered by appropriate safeguards within the meaning of Chapter V of the GDPR. This typically involves Standard Contractual Clauses (SCCs) approved by the European Commission and verification of the recipient's certification under the EU–US Data Privacy Framework (DPF). The detailed rules and the precise list of third-country sub-processors are set out in our Data Processing Agreement (DPA).

6.Analytics and tracking technologies (PostHog)

We use the PostHog platform for product and marketing analytics.

  • Localisation: To protect your data, we use PostHog exclusively in its EU cloud region (servers located in Frankfurt, Germany).
  • Consent management: Settings for analytics cookies are entirely in your hands. You can manage them and change or withdraw your consent at any time via the Cookie Settings link in the footer of our website. Functional cookies are required for the site to operate and cannot be turned off.

7.Where data are stored (data at rest)

All primary Client Data (including CVs, candidate profiles and any attachments) are physically stored on servers within the European Union (EU).

The website and application may make use of distributed infrastructure for performance and security. By their technical nature, certain technology layers (such as content delivery networks – CDNs) may process transient operational data on a global network. This is always done only to the extent strictly necessary for fast delivery and cyber security of the Service.

8.Data recipients and sub-processors

We do not sell your data. However, we may share them with vetted third parties (sub-processors), but only to the extent strictly necessary for the operation, development and security of the Service.

These recipients are in particular providers of:

  • cloud hosting and database infrastructure,
  • AI infrastructure and models (under the conditions in section 4),
  • analytics and communication tools.

The current and accurate list of sub-processors involved in the processing of Client Data is an integral part of the Data Processing Agreement (DPA).

9.Data retention

We process and retain data only for as long as necessary:

  • Where we act as Controller (customers, website): We retain data for the duration of the contractual relationship and subsequently for as long as necessary to protect our legal claims (typically for the limitation periods, 3 to 10 years) and to fulfil legal obligations (e.g. archiving accounting records).
  • Where we act as Processor (Client Data in heyree): We retain such data exclusively as agreed with the customer. Upon termination of the contractual relationship the Client has 30 days to export its data; thereafter the data are irreversibly deleted from production systems within a further 60 days at the latest (i.e. up to 90 days in total after termination), in accordance with the export and deletion period specified in our Terms of Service and DPA.

10.Personal data security

We apply strict and appropriate technical and organisational measures to protect data. Standard practices on the heyree platform include in particular:

  • encrypted data transmission (HTTPS/TLS) and encryption of data at rest,
  • strict access control and identity verification,
  • logging of security events and regular backups,
  • proactive incident response processes.

A detailed technical overview of our security measures is provided to corporate customers on request as part of our GDPR compliance documentation.

11.Your rights under the GDPR

The European GDPR gives you broad control over your personal data. To be maximally transparent, we set out a detailed overview of your rights below.

11.1Your rights vis-à-vis HeyHire (when we act as Controller)

If we process your data as controller (you are our B2B customer, customer representative or website visitor), you have the right to request at any time:

  • Right of access (Art. 15 GDPR): You have the right to know what data we process about you, for what purpose, how long we will retain them and to whom we transfer them. You have the right to obtain a free copy of these data.
  • Right to rectification (Art. 16 GDPR): If you find that the personal data we hold about you are inaccurate, out of date or incomplete, you have the right to have them rectified or completed without undue delay.
  • Right to erasure / „to be forgotten" (Art. 17 GDPR): You may ask us to permanently delete your data, in particular where the purpose of processing has ceased, you have withdrawn your consent, or you have legitimately objected to the processing.
  • Right to restriction of processing (Art. 18 GDPR): In certain cases (e.g. while we verify the accuracy of the data or resolve your objection), you may ask us to temporarily stop actively processing your data and merely retain them.
  • Right to data portability (Art. 20 GDPR): You have the right to receive your data, which we process by automated means based on your consent or a contract, in a structured and machine-readable format and to transmit them to another controller.
  • Right to object (Art. 21 GDPR): Where we process your data based on a legitimate interest (which includes B2B direct marketing), you may object to such processing. In the case of marketing, we will stop such processing immediately upon receiving your objection.
  • Right to withdraw consent (Art. 7 GDPR): Where the processing is based on your consent (e.g. for advanced analytics cookies), you may withdraw it at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

How to exercise these rights? Please send your requests to our e-mail address legal@heyree.com. We will respond to your request without undue delay and in any case within 30 days of receipt. In more complex cases we reserve the right to extend this period by a further two months, of which we will inform you. Handling a request is in principle free of charge.

11.2Specific rules for Candidates (when we act as Processor)

If you are a job applicant (Candidate) and your data are processed inside the heyree platform by our customer (e.g. a prospective employer or recruitment agency), please exercise your rights (in particular the right to erasure of your CV or access to it) primarily directly with that customer, who acts as Controller of your personal data. Any complaint to the data protection supervisory authority should also be primarily directed at this Controller.

Important notice: In this relationship HeyHire is solely the software provider (a technology processor). From a legal point of view, we are not entitled to delete, modify or export recruitment data on our own initiative without the express instruction of the employer (Controller). If we receive a request directly from a Candidate, our clients have the tools to handle your request inside the platform without undue delay. Alternatively, we will forward your request to the relevant controller and provide them with the necessary technical assistance.

11.3Right to lodge a complaint with a supervisory authority

If you believe that we are not handling your data in accordance with applicable law, you have the right to lodge a complaint with a supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (ÚOOÚ), with its seat at Pplk. Sochora 27, 170 00 Prague 7 (website: www.uoou.cz).

This Privacy Policy takes effect on 1 April 2026. We reserve the right to update it where necessary (e.g. due to changes in legislation or our services). We will inform our customers of any material changes in good time.

Backed by startup grants from
Googlefor StartupsSentryElevenLabsPostHogNVIDIAInception
heyreeheyree
hey@heyree.app
HeyHire s.r.o.
Příčná 1892/4, Nové Město
110 00 Praha 1
IČ: 24441163
heyree
ProductFeaturesPricingChangelog
Approach
About usCareersFor mediaBlog
Compare
× Sloneek× Teamio× Recruitis× Datacruit× Ashby× Recruitee× HiBob× Gem× Recruiterflow× Greenhouse× Workable× RecruHR
Legal
Terms of servicePrivacy policyGDPR complianceCookie settings
Made with love for recruiters · © 2026 heyree. All rights reserved.Made in Prague, Brno and Bratislava. Three cities, one team, one heyree.