Privacy Policy
Effective Date: May 1, 2026
Last Updated: May 1, 2026
JivaHire ("we," "us," "our," or "Company") operates the JivaHire Candidate Hub platform (the "Service"). We are committed to protecting your privacy.
By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Recruiter Account Information
- Email address, name, profile picture, job title
- Authentication data (encrypted passwords, JWT tokens, session IDs)
- Account status (verification, admin role, login history)
1.2 Organization Information
- Company name, website, location, logo, employee headcount, industry
- Organizational content (about us, benefits, mission statements, EEO policy)
1.3 Candidate Data
- Name, email, phone number, location
- Resume content, work history, skills, education
- Interview responses, video recordings, assessment results, recruiter notes
- Application status and activity history
1.4 Usage & Logs
- API calls, login attempts, feature usage, timestamps
- Error logs, IP addresses, browser information
- Activity related to job postings, interviews, and candidate interactions
1.5 Cookies & Tracking
- Session cookies (essential for authentication)
- CSRF tokens (security)
- Cloudflare Turnstile tokens (bot protection)
- We do NOT use advertising, analytics, or persistent tracking cookies
2. How We Use Your Information
We use personal data to:
- Provide and operate the Service (authentication, job posting, interviews, candidate evaluation)
- Communicate with you (verification emails, password resets, service notifications)
- Generate interview questions using AI/LLM models
- Analyze candidate-job fit using embeddings and similarity matching
- Maintain security, detect fraud, and prevent abuse
- Comply with laws and respond to legal requests
- Improve and optimize the Service (aggregate, de-identified analytics only)
We do not sell or rent your personal data.
3. Data Retention
We retain personal data as follows:
| Data Type | Retention Period |
|---|---|
| Active recruiter accounts | While account is active + 2 years after deletion/inactivity |
| Organization data | While organization has active recruiters + 2 years after |
| Candidate data | 2 years from last recruiter interaction (interview, evaluation, or application status change) |
| Interview videos | 2 years from interview date |
| Activity logs & audit trails | 2 years for compliance and security |
| Session cookies | Until browser session ends or logout |
We may retain data longer when required by law (legal holds, litigation, tax/employment records, regulatory requirements).
4. Data Sharing & Subprocessors
4.1 We Share Data With
| Service | Purpose | Your Data |
|---|---|---|
| AWS | Infrastructure, storage, backup, CDN | All personal data (accounts, candidates, videos, logs) |
| SendGrid | Transactional email | Email addresses, names, interview details |
| OpenRouter & LLM Providers | AI question generation, scoring, matching | Job descriptions, candidate profiles, resume content |
| Cloudflare Turnstile | Bot protection | IP address, device fingerprint |
| Candidate Hub | Candidate profiles, resumes, talent search | Candidate emails, resume, work history, skills |
All subprocessors are contractually required to protect data and process only as instructed.
4.2 We Notify You of Subprocessor Changes
When we add or replace a subprocessor, we will notify users 30 days in advance and allow objections if concerns exist.
4.3 Legal Requests
We may disclose personal data when required by law (court order, subpoena, warrant, law enforcement). We will notify you of legal requests when legally permissible.
5. Security
We implement industry-standard security measures:
- HTTPS/TLS encryption for all data in transit
- AES-256 encryption for sensitive data at rest
- JWT-based authentication with token expiration
- Role-based access controls and organization-level data isolation
- Audit logging and real-time monitoring
- Annual security testing and vulnerability scanning
- AWS managed infrastructure with security best practices
No system is 100% secure. We cannot guarantee protection against sophisticated attacks, zero-day exploits, or insider threats.
6. Your Rights
6.1 GDPR Rights (EU/EEA users)
If you are in the EU/EEA, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion (subject to legal holds)
- Portability: Receive your data in a portable format (JSON, CSV)
- Restriction: Limit how we process your data
- Withdraw Consent: Stop processing based on consent
6.2 CCPA Rights (California residents)
If you are in California, you have the right to:
- Know: What personal information we have and how we use it
- Delete: Request deletion of your personal information
- Correct: Request correction of inaccurate information
- Opt-out: Opt out of the sale or sharing of personal information (we do not sell data)
6.3 GDPR/CCPA/India Rights — How to Exercise
To exercise any of these rights, contact us at:
Email: support@jivahire.com
Include in your request:
- Your full name and email address
- The specific right you are exercising
- Description of the data or account
- Any proof of identity we may need
We will respond within 30 days (GDPR), 45 days (CCPA), or a reasonable timeframe (other jurisdictions).
7. Cookies
We use minimal cookies:
- Session cookies: Maintain authentication between requests (expires on logout or 24–48 hours)
- CSRF tokens: Prevent cross-site request forgery
- Turnstile tokens: Bot protection (30 minutes)
All cookies are HttpOnly (no JavaScript access), Secure (HTTPS only), and SameSite (prevent leakage).
You can disable cookies in your browser, but this may impair login and other features.
8. Children & Minors
The Service is not intended for persons under 18 years of age. We do not knowingly collect personal information from minors. If we become aware of a minor's information, we will delete it promptly.
9. International Data Transfers
If you are in the EU/EEA, UK, or India, your personal data may be transferred to the United States or other countries for processing. Such transfers are governed by:
- EU Standard Contractual Clauses (SCCs) (see our Data Processing Agreement)
- Supplementary safeguards: encryption, access controls, monitoring
We monitor US government access risks and escalate concerns to you if safeguards fail.
10. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will:
1. Update the "Last Updated" date
2. Notify you via email or in-app notice
3. Obtain consent if required by law
Your continued use of the Service after updates constitutes acceptance.
11. Contact Us
Privacy inquiries:
Email: support@jivahire.com
Website: https://jivahire.com
Response time: 5 business days acknowledgment; substantive response within 30 days.
12. Data Protection Authority Complaints
If you believe your privacy rights have been violated, you have the right to file a complaint with:
- GDPR (EU/EEA): Your national data protection authority
- CCPA (California): California Attorney General
- India: Data Protection Board of India