General Terms and Conditions
HeyHire s.r.o. has developed and operates the cloud platform heyree, a dedicated Applicant Tracking System (ATS) designed for efficient management of recruitment processes, candidate administration and corporate communication, using modern technologies including advanced artificial-intelligence assistant features.
These General Terms and Conditions constitute a comprehensive and binding legal framework governing all relationships between the platform provider and its corporate customers. Their aim is to provide maximum legal certainty to both parties, transparently define the rules for handling sensitive data (in particular data of job applicants) and precisely delimit the scope of the services provided, the licence rights granted and the liabilities assumed.
Acceptance of this document by the customer is a mandatory formal prerequisite for the lawful and secure use of the service.
1.Introductory provisions and contractual basis
1.1Identification of the Provider
These General Terms and Conditions (the "Terms") are issued by HeyHire s.r.o., Company ID (IČO): 24441163, with its registered office at Příčná 1892/4, Nové Město, 110 00 Prague 1, Czech Republic, registered in the Commercial Register maintained by the Municipal Court in Prague, file No. C 440236 (the "Provider").
1.2Subject matter
These Terms regulate, within the meaning of Section 1751(1) of Act No. 89/2012 Coll., the Civil Code, as amended (the "Civil Code"), the mutual rights and obligations between the Provider and the customer (the "Client") relating to the provision and use of the cloud service heyree (together, the "Agreement").
1.3B2B-only nature
The Service is developed and provided exclusively for the needs of businesses, companies and other legal entities (B2B). By entering into the Agreement the Client expressly represents that it uses the Service in the course of its business activity or in the independent pursuit of its profession. Consumer-protection legislation does not apply to this contractual relationship.
1.4Hierarchy of contractual documents
The contractual relationship is governed by the following documents in the order of precedence set out below (in the event of conflict the document listed higher prevails):
- the individual written contract or the accepted Order (including the Price List),
- the Data Processing Agreement (DPA),
- these General Terms and Conditions,
- the technical and user Documentation of the Service.
2.Definitions
For the purposes of these Terms and the Agreement the following capitalised terms have the following meaning:
- Service
- means the heyree software solution provided under a Software-as-a-Service (SaaS) model, primarily serving as an Applicant Tracking System (ATS), including all available modules, integrations, API interfaces, updates and the web environment.
- Client
- means the natural or legal person that has entered into the Agreement with the Provider.
- User
- means a natural person authorised by the Client to access and use the Service under an individual user account.
- Administrator
- means a User with the highest level of permissions who manages the configuration of the Service, the user accounts and billing on behalf of the Client.
- Candidate
- means a natural person applying for a position with the Client whose data are processed within the Service.
- Client Data
- means all information, texts, files, CVs, personal data of Candidates and Users and any other content entered into the Service by the Client or automatically collected from integrated platforms.
- AI Features
- means the integrated tools and modules using artificial-intelligence technologies (including machine-learning, LLM and NLP models) to support, automate and optimise processes inside the Service.
- Order
- means a proposal to conclude the Agreement, typically made through the registration form on the Provider's website, in the Service interface, or signed in paper or electronic form.
3.Conclusion of the Agreement and account administration
3.1Formation of the Agreement
The Agreement is concluded at the moment the Provider confirms acceptance of the Order to the Client, or at the moment the Client (or a person authorised by the Client) successfully creates an account in the Service and accepts these Terms.
3.2Account creation and administration
Upon conclusion of the Agreement the Client is provided with a master Client account. The Client (via its Administrator) is entitled to create accounts for additional Users within the limits of its subscribed tariff.
3.3Security and login credentials
The Client is responsible for ensuring that Users protect their login credentials against disclosure. Access credentials are non-transferable and may not be shared between multiple natural persons (each User must have their own account). Should the Client suspect that an account has been compromised, it must notify the Provider without undue delay. All actions performed under the accounts of the Client's Users are attributed to the Client.
3.4Authority of acting persons
The natural person creating an account in the name of the Client expressly represents that they are fully authorised to act on behalf of the Client and to bind the Client to the performance of this Agreement.
4.Scope of the Service and SLA
4.1SaaS model and "As Is"
The Provider delivers the Service remotely over the Internet (cloud). The Service is provided on an "as is" and "as available" basis. The Provider does not warrant that the Service will fully meet specific and individual process requirements of the Client that go beyond the standard functionality of the Service.
4.2Service availability (Uptime)
The Provider guarantees Service availability of 99.5 % in each calendar month (SLA). The following periods of unavailability are not counted towards the availability calculation:
- scheduled maintenance and updates (downtime),
- failures on the side of the Client's end-user device, network or Internet service provider,
- outages of third-party cloud infrastructure (e.g. AWS, Google Cloud, LLM model providers),
- force-majeure events.
4.3Scheduled maintenance
The Provider undertakes to carry out maintenance downtime primarily during periods of historically lowest load (typically at weekends or during night hours CET). The Provider will give notice of maintenance exceeding 60 minutes at least 48 hours in advance via an in-app notification.
4.4Technical support
The Provider provides technical support (Helpdesk) by e-mail at hey@heyree.com. Support is available on business days from 9:00 to 17:00 (CET/CEST), excluding public holidays in the Czech Republic. The response time for standard enquiries is up to 2 business days; for critical defects preventing the Service from running the Provider commences resolution without undue delay.
4.5Service changes and updates
The Provider is entitled to modify the Service on an ongoing basis, add new features and retire obsolete modules. Such modifications must not lead to a material deterioration of the key features of the Service agreed at the time of conclusion of the Agreement.
5.Licence grant and intellectual property rights
5.1Grant of licence
Subject to proper payment of all fees, the Provider grants the Client a limited, non-transferable, non-exclusive licence (right of use) to the Service, solely for the Client's internal business purposes and for recruitment of the Client's own employees or contractors (or, where the Client is a recruitment agency operating under a specific tariff, for recruitment of the Client's customers).
5.2Reservation of ownership
All intellectual property rights in the Service, its source code, user interface (UI/UX), database structure, algorithms, know-how and any Documentation belong exclusively to the Provider or its licensors. The Client acquires no ownership rights in the Service.
5.3Feedback
If the Client provides the Provider with suggestions, ideas or comments concerning the Service (Feedback), the Provider is entitled to use such Feedback free of charge, permanently and without limitation for the development of the Service, without any claim by the Client to any consideration.
6.Conditions of use and Acceptable Use Policy
6.1Prohibited conduct
The Client and its Users undertake not to use the Service in a manner that threatens its stability or security. In particular it is expressly prohibited to:
- reverse-engineer, decompile or attempt to obtain the source code,
- use automated systems (bots, scrapers, spiders) to extract data from the Service, except via the permitted official API interfaces,
- conduct penetration or load tests of the Service without the Provider's prior written consent,
- circumvent licence restrictions or tariff limits (e.g. by artificially reducing the number of active users through account sharing),
- rent out, sublicense, resell or provide the Service by way of white-labelling without an express agreement.
6.2Unlawful content and sensitive data
The Client must not upload to the Service any Client Data that contain malicious code (viruses, trojans, ransomware) or that are in breach of law, good morals or that infringe the rights of third parties (e.g. copyright, personality rights). The Client further undertakes not to process special categories of personal data (sensitive data) through the Service unless it has a corresponding legal basis under GDPR.
6.3Fair use of API and system resources
For tariffs labelled "unlimited" the principles of fair use apply. The Provider reserves the right to limit or throttle access to the API (Rate Limiting) if the Client generates extreme load disproportionate to standard operation that threatens the availability of the Service for other customers.
7.Specific provisions for AI Features
7.1Nature of AI outputs
The artificial-intelligence tools in the Service (AI Features) serve as an assistive system supporting the work of Users. The Provider expressly warns that generative AI may produce outputs that are inaccurate, incomplete or misleading. AI outputs do not constitute legal or professional advice and serve solely as a supporting tool. The Provider assumes no liability for decisions made by the Client on the basis of AI outputs.
7.2Prohibition of solely automated decision-making
In light of the requirements of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data ("GDPR") and the forthcoming provisions of Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence, the Client bears full and exclusive responsibility for how it handles AI outputs. The Client's Users must critically review each AI output before using it. The Service must not be used for automated decision-making that produces legal or similarly significant effects for a Candidate (e.g. automatic rejection from a selection procedure) without material human review.
7.3Data protection during AI processing
Client Data passing through AI Features are processed over a secured channel. The Provider guarantees (and contractually binds its LLM-model sub-processors such as OpenAI via API to the same) that Client Data and personal data are not and will not be used for the training of any artificial-intelligence models, whether of the Provider or of third parties.
8.Client Data and their protection
8.1Ownership of Client Data
The Client is and remains the exclusive owner of all rights in the Client Data. The Client grants the Provider a limited right, in time and place, to store, process and display the Client Data solely for the purpose of providing and optimising the Service under this Agreement.
8.2Data responsibility and indemnification
The Client bears full legal responsibility for the origin, legality and accuracy of the Client Data. If a third party (including supervisory authorities) raises a claim, fine or action against the Provider on the grounds that the Client Data infringed the law, the Client undertakes to fully indemnify the Provider, including reasonably incurred legal-representation costs.
8.3Security and infrastructure
The Provider implements appropriate technical and organisational measures to protect the data, in particular:
- encryption of data in transit,
- encryption of data at rest,
- access control,
- restriction of access to data to authorised persons only,
- ongoing security updates and monitoring.
The Provider continuously develops its security and monitoring mechanisms, including expanding audit and logging functions.
8.4Infrastructure sub-processors and backups
The Provider uses third-party infrastructure and services (e.g. cloud or AI providers). When selecting them the Provider takes care to use trustworthy providers who typically declare compliance with common security standards (e.g. ISO 27001, SOC 2). The Provider, however, does not warrant the performance of such standards by those third parties.
The Provider performs regular system backups. The backups serve to restore the whole Service in the event of a disaster (Disaster Recovery); they do not serve to restore data deleted by a Client's User in error.
9.Protection of personal data (GDPR)
9.1Roles of the parties
The provision of the Service involves the processing of personal data (in particular of Candidates). In such cases the Client always acts as the Controller and the Provider as the Processor within the meaning of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data ("GDPR").
9.2Data Processing Agreement (DPA)
All rights, obligations and parameters of the processing of personal data are governed by a separate Data Processing Agreement (DPA). By concluding this Agreement and accepting these Terms the Client expressly consents also to the wording of the DPA, which forms an integral annex to these Terms.
9.3Sub-processors
The Provider is entitled to engage sub-processors (additional processors). The Provider is responsible for ensuring that such sub-processors meet adequate data-protection standards.
10.Financial terms, payments and sanctions
10.1Prices and tariffs
The use of the Service is charged on a subscription basis ("SaaS fee") depending on the selected tariff and the parameters of the Order. All prices stated in the Price List or in offers are exclusive of value added tax (VAT), which will be added to the price at the statutory rate.
10.2Invoicing and due dates
The subscription is invoiced in advance (typically monthly or annually). The Provider issues the Client an electronic invoice (tax document). The standard payment term is 14 calendar days from the date of issue, unless expressly agreed otherwise in the Order.
10.3Sanctions for default and Hard Lock
If the Client is in default of payment, the Provider is entitled to:
- charge contractual default interest of 0.05 % of the outstanding amount for each day of default,
- in the case of default exceeding 15 days, restrict the Client's access to the Service to read-only mode,
- in the case of default exceeding 30 days, fully block access to the Service (Hard Lock) until the outstanding amount is paid in full.
The restriction or suspension of access does not relieve the Client of the obligation to pay the fees for the given subscription period.
10.4Price changes
The Provider reserves the right to adjust tariff prices (the Price List). The Provider must notify the Client of any planned price change at least 30 days before the end of the current billing period. If the Client does not agree with the change, the Agreement terminates upon the expiry of the period already paid for. If the Client does not terminate the Agreement, the new price is deemed accepted for the following period.
11.Confidentiality (NDA)
11.1Duty of confidentiality
Both contracting parties undertake to keep confidential and not to disclose to any third party any information concerning the business strategy, finances, technologies, know-how or customers of the other party (the "Confidential Information"), both during the term of this Agreement and for a further 3 years after its termination.
11.2Exceptions from confidentiality
Confidential Information does not include information that:
- has become publicly known without the fault of the receiving party,
- the receiving party independently developed or can demonstrably prove it knew prior to its receipt,
- must be disclosed on the basis of a binding decision of a court, law or public authority (the other party must be informed in advance, if legally permitted).
12.Liability and its limitation
12.1Nature of liability
The Provider is liable to the Client for damage demonstrably and exclusively caused by the Provider's culpable breach of its obligations under this Agreement.
12.2Exclusion of indirect damages
To the maximum extent permitted by law, any obligation of the Provider to compensate any indirect, consequential or incidental damage is excluded, including (but not limited to) lost profit, loss of revenue, loss of business opportunities, costs of substitute solutions, damage to goodwill or damage caused by irreversible loss or corruption of Client Data.
12.3Financial liability cap
The Provider's total, maximum and cumulative liability for all claims arising in connection with this Agreement (whether in contract, tort or otherwise) is limited to the amount equal to the total fees actually paid by the Client to the Provider for the Service in the twelve (12) months preceding the event that gave rise to the claim.
12.4Force majeure
Neither party shall be liable for non-performance of its obligations (save for the obligation to duly pay the fees) where such non-performance was caused by an objectively unforeseeable and unavoidable event beyond its control. This includes in particular natural disasters, armed conflicts, strikes, major outages of backbone Internet and telecommunications networks, outages of sub-processors, or sophisticated cyber-attacks (e.g. massive DDoS) that cannot reasonably be prevented even with the highest security standards in place.
13.Term, termination and data export
13.1Term
The Agreement is concluded for the fixed term agreed in the Order (e.g. 1 month, 1 year).
13.2Termination for breach
The Provider is entitled to terminate the Agreement immediately by written notice (effective upon delivery) if the Client materially breaches the Agreement and fails to remedy such breach within fifteen (15) days of receipt of a written notice to cure. A material breach by the Client includes in particular default in payment of fees for more than 30 days, breach of the AUP, or breach of the licence terms.
13.3Data export upon termination (Off-boarding)
Following effective termination of the Agreement the Client is entitled to limited access to the Service for a period of thirty (30) calendar days, solely for the purpose of exporting and downloading its Client Data (via system export or the API). No new data may be entered into the Service during this period.
13.4Data deletion
After the expiry of the 30-day export period the Client loses access to the Service. The Provider is entitled, and under the DPA obliged, to irreversibly delete the Client Data from all production systems without undue delay, and at the latest within a further sixty (60) days, except for data for which a longer retention period is required by law (e.g. invoicing and accounting records).
14.Final provisions
14.1Amendments to the Terms (unilateral modification)
Given the long-term nature of the Service and ongoing technological development, the Provider is entitled to amend these Terms unilaterally. The Provider will notify the Client of any amendment by e-mail or by a message in the Service interface at least 30 calendar days before such amendment becomes effective. If the Client does not agree with the new wording, it is entitled to terminate the Agreement in writing as of the effective date of the amendment. If the Client does not terminate the Agreement, it is deemed to have accepted the amendment.
14.2Assignment
The Client is not entitled to assign any rights or obligations under the Agreement to any third party (including affiliated companies) without the Provider's prior written consent.
14.3Severability
Should any provision of these Terms prove to be invalid, ineffective or unenforceable, this shall not affect the validity of the remaining provisions. The parties undertake to replace such provision with a new one that is as close as possible to the original intent in terms of both content and economic effect.
14.4Governing law and dispute resolution (Jurisdiction)
This Agreement and the contractual relationships arising from it (including any tort claims) are governed exclusively by the laws of the Czech Republic, in particular the Civil Code. The parties have agreed that the courts of the Czech Republic have exclusive jurisdiction over all disputes arising from or in connection with the Agreement. The local jurisdiction of the court of first instance is determined by the registered office of the Provider at the time the action is filed.
14.5Validity and effect
These Terms become valid and effective on 1 April 2026 and supersede all previous versions.
14.6Marketing reference
The Provider is entitled to list the Client as a reference (e.g. by its logo or company name), unless the Client expressly requests exclusion (opt-out).
14.7Language versions
The Agreement and these Terms may be drawn up in several language versions. In the event of any discrepancy between the language versions, the Czech version always prevails.
IČO: 24441163 · sp. zn. C 440236, Městský soud v Praze
hey@heyree.com

