Privacy Policy

Your privacy, our commitment

Last updated: February 17, 2026Effective: February 17, 2026GDPR Compliant

At HireFlow, operated by FoundryX ("we," "us," or "our"), we take your privacy seriously. This Privacy Policy explains in detail how we collect, use, store, share, and protect your personal information when you use our AI-powered interview preparation platform. By accessing or using HireFlow, you acknowledge that you have read and understood this policy.

This policy applies to all users of HireFlow, including visitors to our website, registered users, and subscribers to any of our plans. It covers data collected through our web application, API services, and any related communications.

1. Information We Collect

We collect information necessary to provide, maintain, and improve our services. The types of data we collect fall into the following categories:

Account Information

When you create an account, we collect:

  • Full name and email address
  • Encrypted password (using bcrypt hashing — we never store plaintext passwords)
  • Profile preferences including preferred language, interview difficulty level, and target job roles
  • Subscription tier and billing status
  • Account creation date and last login timestamp

Interview & Practice Data

When you use our interview features, we process:

  • Voice recordings captured during practice interview sessions
  • Real-time and post-session transcriptions of your spoken responses
  • AI-generated performance scores, feedback, and coaching recommendations
  • Uploaded CVs, resumes, cover letters, and job descriptions
  • Interview session metadata (duration, question count, language used, session type)
  • Your text-based responses in non-voice interview modes

Payment & Billing Information

All payment processing is handled exclusively by Stripe, our PCI DSS-compliant payment processor. We do not store, process, or have access to your full credit card numbers, CVV codes, or bank account details. The only payment-related data we retain includes:

  • Last four digits of your payment card (for display purposes only)
  • Card brand and expiration date
  • Billing address (if provided)
  • Transaction history and invoice records
  • Stripe customer ID (an anonymized identifier)

Technical & Usage Information

We automatically collect certain technical data when you interact with our platform:

  • IP address, browser type, and version
  • Device type, operating system, and screen resolution
  • Pages visited, features used, and session duration
  • Referral source (how you found HireFlow)
  • Error logs and crash reports for debugging
  • Cookies and local storage identifiers

2. Legal Basis for Processing

Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:

Contractual Necessity

Processing required to deliver the services you signed up for — including running AI interviews, generating reports, and managing your subscription.

Legitimate Interest

Processing necessary for our legitimate business interests, such as improving our AI models through aggregated and anonymized data analysis, preventing fraud, and ensuring platform security.

Consent

Where required, we obtain your explicit consent before processing — for example, when sending marketing communications or using optional analytics cookies.

Legal Obligation

Processing required to comply with applicable laws, regulations, tax requirements, or legal proceedings.

3. How We Use Your Data

We use the information we collect for the following specific purposes:

Core Service Delivery

  • Conducting AI-powered interview practice sessions with adaptive questioning
  • Generating detailed performance reports, scores, and analytics
  • Delivering personalized coaching feedback based on your responses
  • Processing voice recordings through speech-to-text and AI analysis
  • Managing your account, subscription, and payment processing

Personalization & Improvement

  • Adapting interview questions to your experience level, target role, and identified weaknesses
  • Customizing the platform interface to your language and accessibility preferences
  • Analyzing aggregated, anonymized usage patterns to improve our AI models and platform features
  • Conducting A/B testing to optimize user experience (using anonymized data only)

Communication & Support

  • Sending transactional emails (account confirmations, password resets, subscription receipts)
  • Providing customer support and responding to your inquiries
  • Notifying you of important service updates, security alerts, or policy changes
  • Sending optional marketing communications (only with your explicit consent, with easy unsubscribe)

Security & Compliance

  • Detecting and preventing fraudulent activity, abuse, and unauthorized access
  • Monitoring for security threats and system vulnerabilities
  • Complying with legal obligations, tax regulations, and responding to lawful data requests
  • Enforcing our Terms of Service and Acceptable Use Policy

4. Data Sharing & Third Parties

We do not sell, rent, or trade your personal data to third parties for their marketing purposes. We share data only in the following limited circumstances:

ProviderPurposeData SharedLocation
StripePayment processingBilling information and transaction dataUSA (EU-US Data Privacy Framework certified)
SupabaseDatabase and authentication infrastructureAccount data, session data, and application dataEU (Frankfurt region)
GroqAI language model inferenceInterview transcriptions and prompts (processed in real-time, not stored)USA (data processing agreement in place)
ElevenLabsVoice synthesis for AI interviewerText prompts for voice generation (no user voice data shared)USA/EU (data processing agreement in place)
VercelApplication hosting and CDNTechnical request data (IP addresses, request logs)Global CDN with EU presence
Legal Requirements

We may disclose data when required by law, court order, subpoena, or governmental regulation. We will notify you of such requests unless legally prohibited from doing so.

Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your data may be transferred as part of the transaction. We will provide at least 30 days' notice and the option to delete your account before any such transfer.

With Your Consent

We may share data for purposes not described here only with your explicit, informed consent.

5. Data Retention

We retain your data only for as long as necessary to fulfill the purposes described in this policy. Specific retention periods are as follows:

Data TypeRetention Period
Account profile dataRetained while your account is active, deleted within 30 days of account deletion
Interview recordings (audio)Automatically deleted after 90 days, or immediately upon your manual deletion
Interview transcripts & reportsRetained for 12 months after creation, or until you manually delete them
Uploaded CVs and job descriptionsRetained while your account is active, deleted within 30 days of account deletion
Payment and billing recordsRetained for 7 years as required by German tax law (AO §147)
Technical logs and analyticsAnonymized after 90 days, fully deleted after 12 months
Support correspondenceRetained for 24 months after ticket resolution

When you delete your account, we initiate a permanent deletion process. All personal data is purged from our active systems within 30 days. Data may persist in encrypted backups for up to 90 additional days before being overwritten.

6. Your Rights Under GDPR

As a data subject under the General Data Protection Regulation (GDPR) and other applicable data protection laws, you have the following rights:

Right of Access (Art. 15)

You may request a complete copy of all personal data we hold about you. We will provide this in a structured, commonly used, machine-readable format within 30 days.

Right to Rectification (Art. 16)

You may request that we correct any inaccurate or incomplete personal data. You can also update most information directly in your account settings.

Right to Erasure (Art. 17)

You may request deletion of your personal data at any time. You can delete your account through Settings, or contact us for a full data purge. Certain data may be retained where legally required.

Right to Data Portability (Art. 20)

You may request that we export your data in a machine-readable format (JSON or CSV) so you can transfer it to another service.

Right to Restrict Processing (Art. 18)

You may request that we limit how we process your data while a dispute or request is being resolved.

Right to Object (Art. 21)

You may object to processing based on legitimate interest. You can opt out of marketing communications at any time via the unsubscribe link in any email.

Right to Withdraw Consent (Art. 7)

Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.

Right to Lodge a Complaint

You have the right to file a complaint with your local data protection authority. For users in Germany, this is the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW).

To exercise any of these rights, email us at support@hireflow.pro with the subject line "Data Rights Request." Please include your account email for verification. We will acknowledge your request within 48 hours and fulfill it within 30 calendar days.

There is no fee for exercising your data rights. We may request additional verification for sensitive requests to protect your account security.

7. Data Security

We implement comprehensive technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

Encryption

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for all data at rest
  • Bcrypt hashing for passwords with per-user salts
  • End-to-end encryption for sensitive API communications

Infrastructure

  • Hosted on SOC 2 Type II compliant cloud infrastructure
  • EU-based primary data storage (Frankfurt, Germany)
  • Automated backups with encrypted off-site storage
  • DDoS protection and Web Application Firewall (WAF)

Access Controls

  • Role-based access control (RBAC) for all internal systems
  • Multi-factor authentication required for all team members
  • Principle of least privilege enforced across all services
  • Regular access reviews and audit trail logging

Monitoring & Testing

  • 24/7 automated security monitoring and alerting
  • Regular penetration testing by independent third parties
  • Vulnerability scanning and dependency auditing
  • Incident response plan with defined escalation procedures

Data Breach Protocol: In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority within 72 hours as required by GDPR Article 33.

8. Cookies & Tracking Technologies

We use cookies and similar technologies to ensure our platform functions correctly and to improve your experience.

Required

Essential Cookies

Required for core functionality including authentication, session management, security tokens, and language preferences. These cannot be disabled as they are necessary for the platform to function.

Optional

Analytics Cookies

Help us understand how users interact with HireFlow so we can improve features and performance. These collect anonymized, aggregated data only. You may opt out at any time.

Optional

Preference Cookies

Remember your settings and preferences (theme, layout, dashboard configuration) to provide a personalized experience across sessions.

You can manage cookie preferences through your browser settings or by contacting us. Disabling essential cookies may prevent you from using certain platform features. We do not use advertising or third-party tracking cookies.

We respect Do Not Track (DNT) browser signals. When DNT is enabled, we disable all non-essential cookies and analytics tracking.

9. International Data Transfers

HireFlow is operated by FoundryX from Germany. Your primary data is stored in the European Union (Frankfurt, Germany). Some of our service providers are located outside the EU. When data is transferred internationally, we ensure appropriate safeguards are in place:

  • EU-US Data Privacy Framework certification (for US-based providers including Stripe)
  • Standard Contractual Clauses (SCCs) as approved by the European Commission
  • Data Processing Agreements (DPAs) with all sub-processors
  • Transfer Impact Assessments conducted for each international data flow

10. AI & Automated Decision-Making

HireFlow uses artificial intelligence to power interview simulations and generate performance feedback. We want to be transparent about how AI interacts with your data:

Voice Processing

Your voice recordings are processed in real-time by our speech-to-text service to generate transcriptions. Audio is processed transiently and is not used to train third-party AI models.

Interview Analysis

AI models analyze your transcribed responses to generate scores, identify strengths and weaknesses, and provide coaching recommendations. This analysis is based on patterns, not deterministic rules.

No Profiling

We do not use AI to create profiles that produce legal or similarly significant effects on you. Interview scores are for practice purposes only and do not affect your access to services, employment prospects, or any other rights.

Human Review

You may request human review of any AI-generated assessment by contacting our support team.

Model Training

We may use anonymized, aggregated data to improve our AI models. Your individual interview data is never used to train models without explicit anonymization. You may opt out of aggregated data usage by contacting us.

11. Children's Privacy

HireFlow is designed for users aged 16 and older. We do not knowingly collect personal data from children under 16. If we become aware that a user is under 16, we will promptly delete their account and all associated data. If you believe a minor has created an account, please contact us immediately at support@hireflow.pro.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. For material changes, we will notify you at least 30 days in advance via email and/or a prominent in-app notification. Non-material changes (such as formatting or clarifications) may be made without prior notice. We encourage you to review this policy periodically. Your continued use of HireFlow after changes take effect constitutes acceptance of the updated policy.

13. Contact & Data Protection Officer

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Company

FoundryX

Address

Schmidener Str. 37, 71332 Waiblingen, Germany

Email

support@hireflow.pro

For data protection inquiries, you may also reach our Data Protection Officer at support@hireflow.pro.

If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.