Skip to main content
Menu

HireFlow

Privacy statement

Information for agencies and candidates about how HireFlow operates.

Version 2026-09-07 · Effective date 2026-09-07

1. Who we are

This Privacy Statement explains how personal data is processed in connection with HireFlow, recruitment software operated by Appollo Lab.

  • Legal operator: Appollo Lab
  • Address: Hoornstraat 10, 5402 HP Uden, The Netherlands
  • KVK: 96983299
  • VAT ID: NL005241718B76
  • Phone: +31 6 83428932
  • General: info@hireflowjobs.com
  • Privacy: privacy@hireflowjobs.com
  • Legal: legal@hireflowjobs.com

2. Controller and processor roles

For candidate and recruitment data processed through HireFlow on behalf of a recruitment agency (the “Customer”), the Customer is normally the controller. The Customer decides the purposes of recruitment processing, determines its own lawful basis, and is responsible for providing candidates with appropriate privacy information. This Statement is not legal advice to Customers.

Appollo Lab normally acts as a processor for that Customer-controlled candidate processing: we host and operate the platform, authentication, security controls, feature delivery, and configured integrations (including optional AI parsing and inbound email intake) according to the Customer’s instructions and the product’s design.

Appollo Lab may separately act as a controller for its own business processing, including Customer account administration, contractual administration, service security and abuse prevention, operational records, direct Customer communications, local billing/plan administration, and compliance with legal obligations. A public Data Processing Agreement and Subprocessor register are available for review. Public availability does not by itself mean a DPA has been electronically signed for a specific Customer.

3. Categories of personal data

Depending on how HireFlow is used, we may process:

  • Customer / user account data: names, emails, usernames, roles/permissions, agency/company details, authentication and security events, support communications, and registration metadata (such as IP and user agent at signup where collected).
  • Public business-contact and sales/demo enquiries submitted via HireFlow’s contact form: name, email, company, message, and optional qualification details such as company size, recruiter seats needed, country, and requested plan. These are HireFlow Sales records operated by Appollo Lab and are not candidate recruitment files.
  • Candidate identity and contact details: name, email, phone, address and related residential fields where provided, date of birth where provided, and similar profile information.
  • Application and profile content: employment history, education, skills, languages, motivation, eligibility and certificate flags (for example VCA, GPI, or driving licence, as boolean or list flags), recruiter notes, evaluations, match scores, interview records, and workflow status. HireFlow does not intentionally collect a Dutch BSN number or a BSN-possession flag for V1 recruitment AI.
  • CV, motivation, and supporting files uploaded by candidates or received via configured intake channels.
  • Inbound email content, attachment metadata, extracted CV text, and AI-suggested structured fields stored for recruiter review.
  • Messaging content where a messaging integration is enabled for the Customer (for example WhatsApp), including phone numbers, message content, and media.
  • Technical data: IP addresses and request metadata in logs where collected, cookie/preference choices, and error-monitoring telemetry.
  • Local billing/plan administration data (plan, subscription state, usage). Online payment-card processing via Stripe is not currently implemented in HireFlow.

CVs and other free-text documents may incidentally contain additional identifiers (including government ID numbers) if a person included them in the document. Truncation of CV text for AI processing is a size limit, not removal of personal data.

4. Purposes and legal bases

Where Appollo Lab acts as processor for Customer-controlled candidate data, processing supports the Customer’s recruitment purposes (receiving applications, organising candidate records, recruiter collaboration, and related workflows). The Customer is responsible for determining the lawful basis for that recruitment processing.

Where Appollo Lab acts as controller, bases may include performance of a contract with the Customer, legitimate interests in operating and securing the service (balanced against individuals’ rights), legal obligations, and consent where genuinely required (for example certain non-essential cookies via our cookie preference centre). We do not invent consent as a basis merely because data is processed.

5. Inbound email and attachments

Customers may configure email intake so applications arrive via inbound messages (production inbound handling uses Mailgun webhooks where configured). The platform stores message metadata, body text, and attachments within the Customer’s tenant space. Attachments are not published publicly; downloads require authenticated agency access.

6. AI-assisted parsing (assistive only)

When enabled for a Customer, offline processing may extract text from CV files and send a bounded portion of that plaintext to an AI provider (currently OpenAI via API) to suggest structured fields. Where technically preventable, Dutch BSN numbers detected in that CV-derived plaintext are redacted before transmission. Redaction before AI does not mean BSN content is removed from stored CV files, email attachments, or extracted plaintext retained for recruiter workflows. The sent text may still include other personal data present in the CV. Suggestions are shown to recruiters for human review and may be persisted in HireFlow for that review workflow.

The platform does not automatically merge AI output into candidate records without recruiter action. HireFlow does not autonomously hire, reject, or make final ranking decisions about candidates. Parsed fields may be wrong or incomplete; Customers and recruiters must verify information before relying on it.

Provider contractual details (for example training use, retention, or exact processing locations) depend on the OpenAI service arrangement in force and are not asserted here beyond what this Statement can verify from product behaviour. OpenAI is listed in the Subprocessor register where production-enabled.

7. Automated decision-making

HireFlow is designed so that recruitment decisions about individuals involve meaningful human involvement. AI features and match-score tooling are decision support for recruiters. Customers remain responsible for hiring outcomes and must not treat automated suggestions as the sole grounds for rejection or selection.

8. Service providers and integrations

Depending on configuration and enablement, HireFlow may use service providers such as: application hosting and database/media storage; Mailgun for inbound email/CV webhooks; OpenAI for optional AI CV structuring; Sentry for exception monitoring; and email delivery providers (for example Zoho SMTP) for transactional and operational messages. Uptime monitoring may check public health endpoints without receiving candidate ATS content by design. Optional analytics tags, if ever enabled, are consent-gated via the cookie preference centre.

WhatsApp / Meta messaging code exists in the product. Live production enablement depends on configuration and Meta account verification and is not claimed as always active in this Statement. Where enabled for a Customer, message content and phone numbers may be processed as described above.

A formal, production-accurate Subprocessor register and Data Processing Agreement are published for V1 review. Public availability does not claim that a specific Customer has already executed the DPA electronically.

9. Error monitoring (Sentry)

When Sentry is configured in production, HireFlow sends exception telemetry for reliability. Default personal-data capture is disabled, request bodies are not sent, user identity is removed in our scrubbing path, and sensitive cookies/headers/query fragments are scrubbed. Tracing and profiling sampling are set to zero, and Session Replay is not configured. Residual risk remains if personal data is embedded in exception messages or local variables. We do not claim that personal data can never reach error monitoring.

10. International transfers

Some providers used by HireFlow may process data outside the European Economic Area (for example AI API providers or email infrastructure, depending on the arrangement in force). Appollo Lab will apply transfer safeguards required by applicable law for the relevant relationship. Exact mechanisms (such as standard contractual clauses, adequacy decisions, or other lawful tools), provider regions, and hosting-vendor contract status depend on provider contracts and operational verification and are summarised conservatively in the Subprocessor register and DPA.

11. Security

Recruiter access is scoped to the signed-in agency. Standard product interfaces do not expose one agency’s candidate workspace to another agency.

We apply reasonable technical and organisational measures appropriate for a B2B SaaS product, including access control, secure sessions, and private file handling for agency-scoped content. No system is perfectly secure. We do not claim perfect security, that breach is impossible, or that data loss cannot occur. Customers must also protect their accounts and any exported data.

12. Retention and deletion

Candidate and recruitment records are retained while the Customer’s account is active and while the Customer needs the records for recruitment, subject to Customer instructions and product tooling. HireFlow provides agency retention visibility and classification tooling (for example aging/stale indicators). Automatic purge of candidate data is not implemented in the current V1 product and must not be assumed.

Agency-scoped candidate erasure is available in the product for authorised agency users: it removes the agency’s workspace link and related agency-scoped records (applications, notes, communications, inbound imports, and similar). A shared global candidate profile may be preserved if linked to other agencies; residential identity fields may be cleared when no agency link remains. Historical backups may retain data for a limited retention window after live deletion.

Account, billing/plan, security, and operational records used for Appollo Lab’s own controller purposes may be retained as needed for contract, security, and legal obligations. Full agency offboarding/deletion is not fully productized as a self-serve end-to-end flow.

13. Your rights

Depending on applicable law, individuals may have rights of access, rectification, erasure, restriction, objection, and data portability, and the right to withdraw consent where processing is based on consent. Individuals may also lodge a complaint with a supervisory authority.

If you are a candidate, contact the recruitment agency handling your application first; they normally control the recruitment relationship. HireFlow provides agency-scoped tooling that authorised Customer users can use to export a candidate data package (DSAR export) and to perform agency-scoped erasure as described above. When Appollo Lab receives a candidate request that concerns Customer-controlled data, we will cooperate with the relevant Customer and route or support the request appropriately; we do not independently decide all such requests as if we were the recruitment controller.

For platform privacy questions to Appollo Lab, contact privacy@hireflowjobs.com. For the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens (https://www.autoriteitpersoonsgegevens.nl/).

14. Security incidents

Appollo Lab assesses personal-data incidents affecting HireFlow and takes appropriate containment and remediation steps. Where Appollo Lab acts as processor, we will notify the affected Customer without undue delay after becoming aware of a personal-data breach affecting that Customer’s processing, and cooperate on required notifications. Where Appollo Lab acts as controller, we will notify the competent authority and affected individuals when required by law. This Statement does not invent fixed contractual response-time SLAs; those belong in the Data Processing Agreement or another written agreement.

15. Cookies

HireFlow uses essential cookies for secure sessions and related operation, and a consent preference centre for optional categories. Details are in our Cookie statement and cookie preferences.

16. Changes

We may update this Privacy Statement when practices or legal requirements change. The version and effective date above identify the published text. Account signup currently records acceptance timing for Terms; it does not yet store the exact Privacy document version accepted.

This Privacy Statement is an internal self-reviewed V1 production publication aligned to Appollo Lab’s approved business decisions. It is not external legal-counsel approval.