Privacy Policy
Effective date: September 24, 2026 · Hirovia Inc.
This Privacy Policy explains how Hirovia Inc. ("Hirovia," "we," "us") collects, uses, shares, and protects personal information in connection with the Hirovia platform, websites, and services (the "Service"). It applies to employer users ("Customers"), their teammates, and job applicants who complete assessments ("Candidates").
1. Our role
For Customer account information, we act as the data controller. We are also the controller for information we collect from visitors to this website for analytics and marketing purposes, described in Section 2A. For Candidate information submitted through assessments, we process data as a service provider/processor on behalf of the Customer that invited the Candidate — that Customer is the controller of Candidate data and is responsible for having a lawful basis to collect it. Candidates with questions about how their data is used in hiring decisions should contact the employer that invited them.
2. Information we collect
Account data (Customers): company name, user names and email addresses, hashed passwords, plan and billing records. Candidate data: name, email address, resume/CV files and their extracted text, assessment responses (questionnaire answers, scenario choices, written answers), computed scores and reports, and completion metadata (timestamps, progress). Identity-verification data (only where the inviting employer has enabled identity verification and the Candidate consents): see Section 4A. Technical data: IP addresses, browser information, and server logs collected automatically for security and operations. We use essential cookies (session authentication) and, subject to your choices in Section 2A, first-party analytics and advertising cookies.
2A. Website analytics and business contact
What we collect. We run our own first-party analytics on hirovia.com rather than relying on a third-party advertising network. It records how the site is used: pages viewed, the referring source and any campaign parameters in the link you arrived on, approximate engagement time, scroll depth, and clicks on links and buttons. It stores an identifier in a first-party cookie and in your browser's local storage for up to twelve months so that repeat visits can be recognised as the same browser.
Form fields. When a form on this website is submitted, the analytics service also records the email address, name, company name, and job title entered in that form, where those fields are present. It does not record passwords or hidden fields. We use this to understand which of our marketing works and, where the enquiry is from a business, to follow up with that organisation about Hirovia's services. We do not sell this information.
Candidates. This analytics runs only on our public marketing pages. It does not run on the pages where Candidates complete assessments, on shared report pages, or on employer-branded application portals. Assessment responses, scores, reports and résumés are never collected by analytics, and no Candidate information is used for marketing.
Your choices. In the EEA, the UK and Switzerland, no analytics or advertising cookie is set until you accept in the banner shown on your first visit; declining prevents them and clears any identifier already stored. Elsewhere they are set on arrival, and the same banner lets you decline at any time. We honour the Global Privacy Control signal where your browser sends one. We also use Google Ads conversion measurement and remarketing tags on our public marketing pages, governed by the same banner and the same consent settings.
3. How we use information
We use personal information to: provide the Service (deliver assessments, compute scores, generate reports for the inviting Customer); operate accounts and billing; secure the Service, prevent fraud and abuse, and detect careless or falsified responding; communicate about the Service; comply with legal obligations; and improve the Service, including creating de-identified and aggregated data (which no longer identifies anyone) used to refine scoring models and benchmarks.
4. AI processing
Resumes and written assessment answers are analyzed with artificial-intelligence models, which may include third-party AI providers acting as our sub-processors under contractual confidentiality. AI evaluation is used to generate advisory scores for the inviting employer. We do not permit our AI sub-processors to use your personal data to train their generally available models.
4A. Identity verification and biometric data
Some employers require Candidates to verify their identity before starting an assessment. When this is enabled and the Candidate consents, the Candidate is taken to a verification flow operated by Stripe, Inc. ("Stripe"). Stripe collects images of the Candidate's government-issued identity document and a live selfie, extracts information from the document, and uses facial biometric data (a mathematical representation of facial geometry) to compare the selfie with the document photo and to confirm liveness. Stripe processes this data as our service provider under contractual confidentiality and data-protection obligations, and additionally under its own Privacy Policy; Stripe may also use certain data as described there, including to comply with law and to improve its fraud-detection services.
What Hirovia receives and stores: the verification outcome (verified / not verified / error code), whether the name on the document matched the name the Candidate entered, the date and time, and a Stripe session reference. What Hirovia does not receive or store: document or selfie images, biometric templates, document numbers, dates of birth, or addresses. The outcome and name-match indication are shared with the employer that invited the Candidate as part of the assessment record.
Purpose and consent. This processing is performed solely to confirm that the person taking the assessment is the person named in the application, at the request of the inviting employer, and only with the Candidate's explicit consent, which is collected on-screen before the check begins. Candidates may decline; they will then be unable to complete that employer's assessment and should contact the employer about alternatives.
Retention and deletion. Stripe retains verification data in accordance with its retention schedule and legal obligations. Hirovia retains the outcome fields for as long as the associated candidate record exists (see Section 6). When a candidate record is deleted from Hirovia, we instruct Stripe to redact the images and extracted data for that verification session. Where biometric-privacy laws (such as the Illinois BIPA) require a written retention schedule, it is this Section: biometric identifiers are not retained by Hirovia at all, and we request their destruction at Stripe when the candidate record is deleted, and in any event within three years of the Candidate's last interaction with the Service, whichever occurs first. We do not sell, lease, trade, or otherwise profit from biometric data.
5. How we share information
We share personal information only with: (a) the Customer that invited the Candidate (assessment results, reports, resumes); (b) parties the Customer chooses to share reports with via the Service's sharing links; (c) service providers that host and support the Service (e.g., cloud infrastructure, AI processing, payment processing, and identity verification by Stripe as described in Section 4A), bound by confidentiality and data-protection obligations; (d) authorities or parties where required by law, legal process, or to protect rights, safety, or the integrity of the Service; and (e) a successor entity in connection with a merger, acquisition, financing, or sale of assets. We do not sell personal information. Our public marketing pages carry Google advertising tags that may constitute “sharing” for cross-context behavioral advertising under some U.S. state privacy laws; you can decline these at any time using the cookie banner, and we honour the Global Privacy Control signal. Candidate assessment data is never used or shared for advertising.
6. Retention
We retain Candidate data for as long as the inviting Customer's account remains active or as needed to provide the Service, after which it is deleted or de-identified within a reasonable period. Customers can delete individual candidate records at any time, which removes them from active systems. We may retain limited records as required for legal, billing, or security purposes, and de-identified data indefinitely.
When a Customer closes their account. An account owner can close their account from the account's settings. Doing so permanently deletes the account and every Candidate record it holds — résumés, responses, results, and reports — and asks Stripe, Inc. to erase any identity-verification records held for that account. Deletion is immediate and cannot be undone. We keep only what we must: transaction records required for tax, accounting, and anti-fraud purposes, and, where the Customer chose to answer, the optional exit-interview response described below.
Exit-interview responses. When an account is closed we may ask why. Answering is entirely optional and is never a condition of closing an account or of receiving a refund. What we keep is the plan the account was on, how long it had been open, how many assessments it ran, the reason selected, and any comment written. This record is kept without the account name, company name, email address, or any other identifier, and is used only to understand why customers leave. It is not used to contact anyone and is not sold or shared.
7. Security
We use reasonable technical and organizational safeguards: encryption in transit (TLS), hashed passwords, tenant isolation, access controls, and monitoring. No system is perfectly secure; you use the Service at your own risk, and Customers are responsible for safeguarding their credentials and shared-report links.
8. Your rights
Depending on your jurisdiction (e.g., GDPR in the EEA/UK, CCPA/CPRA in California), you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to non-discrimination for exercising rights. Candidates: because we process assessment data on behalf of the employer that invited you, we will refer your request to that employer or act on their documented instructions, as applicable law requires. To make a request, email privacy@hirovia.com; we will verify your identity and respond within the time required by law. You may also lodge a complaint with your local data-protection authority.
9. Automated decision-making notice
Hirovia produces automated scores that employers use as one input in their hiring process. Hirovia itself makes no employment decisions. Employers are responsible for any legally required notices, consents, human review, or alternatives regarding the use of automated tools in their hiring process in their jurisdictions.
10. International transfers
The Service is operated from the United States. If you access it from other jurisdictions, your information will be transferred to and processed in the United States and other countries where our providers operate, under appropriate safeguards where required.
11. Children
The Service is intended for working-age adults and is not directed to children under 16. We do not knowingly collect data from children; if you believe a child has provided data, contact us and we will delete it.
12. Changes and contact
We may update this Policy by posting a revised version with a new effective date; material changes will be reasonably highlighted in the Service. Continued use after changes constitutes acceptance. Questions or requests: privacy@hirovia.com · Hirovia Inc.