Recruit CRM
Menu

Privacy policy

Workforce Cloud Tech, Inc. (Recruit CRM)
2026 Edition v3.2 — Aligned with the Data Privacy Framework
This Privacy Policy is consistent with and has been prepared in accordance with:
EU GDPR (Regulation EU 2016/679) · UK GDPR · Swiss nFADP (effective 1 September 2023)
EU-U.S. Data Privacy Framework, UK Extension to the EU-U.S. DPF, and Swiss-U.S. Data Privacy Framework
ePrivacy Directive · CCPA / CPRA · EDPB guidance 2025–2026
Last updated: September 2026 | Version: 3.2
Contact: support@recruitcrm.io | recruitcrm.io/legal/privacy/
Version 3.2 — Governing Law: Ireland · Aligned with DPA v3

Data Privacy Framework Adherence Statement

Workforce Cloud Tech, Inc. adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF. This adherence also extends to personal data received from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Workforce Cloud Tech, Inc. also adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF.
Workforce Cloud Tech, Inc. has completed its self-certification of adherence to the EU-U.S. DPF Principles, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF Principles with the U.S. Department of Commerce, and adheres to the EU-U.S. DPF Principles with regard to personal data transferred from the European Union and the United Kingdom, and to the Swiss-U.S. DPF Principles with regard to personal data transferred from Switzerland.
In the event of any conflict between the terms of this Privacy Policy and the EU-U.S. DPF Principles, the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) programme, or to verify Workforce Cloud Tech, Inc.'s current listing, please visit https://www.dataprivacyframework.gov/
FTC Enforcement: Workforce Cloud Tech, Inc.'s commitments under the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF are subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC).

1. About This Privacy Policy

Workforce Cloud Tech, Inc. (trading as Recruit CRM) is committed to protecting your privacy and handling your personal data responsibly and transparently. This Privacy Policy (“Policy”) applies to all individuals who visit our websites (recruitcrm.io and related domains), sign up for a free trial, subscribe to our Services, or whose personal data is processed through our platform.
We will never sell your personal data to third parties. We handle all personal data in strict compliance with the EU General Data Protection Regulation (“GDPR”) (Regulation (EU) 2016/679), the UK GDPR, the Swiss Federal Act on Data Protection (nFADP, effective 1 September 2023), the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), and all other applicable data protection laws.
This Policy was last updated in September 2026. We will notify you via email when we update this Policy. We will also display a prominent notice on our website prior to any changes taking effect, at least 14 days in advance for material changes, consistent with the amendment process set out in our Data Processing Agreement (Section 12.5).
If you have questions about this Policy or wish to exercise your data protection rights, contact us at: support@recruitcrm.io

2. Who We Are and Our Role in Data Processing

Workforce Cloud Tech, Inc. & all its subsidiaries
Contact: support@recruitcrm.io · Website: recruitcrm.io
Recruit CRM operates in two distinct capacities depending on whose data is being processed:
(a) As a Data Controller — when we collect and process personal data directly from visitors to our website, prospective customers, trial users, and our own subscribers for purposes such as marketing, account management, and service delivery. In this capacity, we determine the purposes and means of processing and are directly responsible to you under applicable Data Protection Laws.
(b) As a Data Processor — when our customers (who are Data Controllers) upload, import or otherwise submit personal data about their candidates, contacts and clients into the Recruit CRM platform. In this capacity, we process personal data strictly on our customers' instructions under the terms of our Data Processing Agreement (DPA), available at recruitcrm.io/legal/data-processing-agreement/. Our customers are responsible for ensuring they have a lawful basis to submit personal data to our platform.
Note for candidates and contacts: If you are a job candidate, contact or end-customer whose data has been uploaded to Recruit CRM by one of our customers (a recruitment agency or employer), that customer is your data controller. Please contact them directly to exercise your data rights. We will assist our customers in responding to such requests as required by law.

3. What Personal Data We Collect and Why

3.1 Data you provide directly

When you visit our website, register for a trial, or subscribe to our Services:
  • Contact information: name, email address, phone number, mailing address
  • Business information: company name, company size, industry, job title
  • Account credentials: username, password (stored in hashed form)
  • Billing information: credit/debit card number, billing address (processed via PCI-DSS compliant payment processors)
  • Communications: emails, support tickets, feedback forms, survey responses, testimonials
  • Professional profile: employment history and qualifications (where provided)

3.2 Data collected automatically

When you use our website or Services, we automatically collect:
  • Device data: device type, operating system, browser type, device identifier (UDID)
  • Log data: IP address, access timestamps, pages visited, referring URLs, clickstream data
  • Usage data: features accessed, session duration, interactions within the platform
  • Location data: approximate geographic location derived from IP address; precise location (with device-level consent) for mobile applications
  • Cookie and tracking data: as described in Section 9 below

3.3 Data submitted by our customers (processor role)

Our customers may upload personal data about their candidates, clients and contacts to the platform, including CVs/resumes, employment history, contact details, professional qualifications, and (where applicable) AI-processed outputs such as call summaries, transcripts and candidate assessments generated through our AI Features. We process this data strictly under our customers' instructions.

4. Lawful Basis for Processing (GDPR Article 6)

Under GDPR, we are required to have a documented lawful basis for each processing activity. The table below sets out the legal basis for each purpose for which we process personal data in our capacity as Data Controller:
Processing purposeType of dataLawful basis (Art. 6 GDPR)
Providing the Services and managing your accountContact, billing, account, usage dataArt. 6(1)(b) — Performance of contract
Processing payments and preventing fraudBilling, payment, device dataArt. 6(1)(b) — Contract; Art. 6(1)(f) — Legitimate interest
Responding to support requestsContact, account, usage dataArt. 6(1)(b) — Contract; Art. 6(1)(f) — Legitimate interest
Sending service-related notificationsContact, account dataArt. 6(1)(b) — Contract; Art. 6(1)(f) — Legitimate interest
Sending marketing communications (where opted in)Contact, usage dataArt. 6(1)(a) — Consent
Product analytics and service improvementUsage, device, log data (pseudonymised)Art. 6(1)(f) — Legitimate interest
Security monitoring and incident responseLog, device, usage dataArt. 6(1)(f) — Legitimate interest
Compliance with legal obligationsAll relevant categoriesArt. 6(1)(c) — Legal obligation
Processing on behalf of customers (as data processor)All customer-submitted personal dataArt. 6(1)(b) — Contract (with controller)
AI Feature processing (optional, controller-directed)As submitted by controllerArt. 6(1)(b) — Contract with controller; inherits lawful basis established by the controller
Where we rely on legitimate interests (Article 6(1)(f)), we have conducted and documented a Legitimate Interests Assessment (LIA) balancing our interests against your rights and freedoms. You may request a copy of our LIA by contacting support@recruitcrm.io.
Where we rely on consent (Article 6(1)(a)), you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, contact us at support@recruitcrm.io or use the unsubscribe link in any marketing communication.

5. How We Use Your Personal Data

5.1 Service delivery and account management

  • Providing, maintaining and improving the Recruit CRM platform and Services
  • Creating and managing your account, including authentication and access control
  • Processing payments and managing billing, invoicing and subscription renewals
  • Sending transactional communications essential to the Service (account alerts, security notices, service updates)
  • Responding to support requests, troubleshooting and resolving disputes

5.2 Marketing and communications (where you have opted in)

  • Sending newsletters, product updates, feature announcements and promotional offers
  • Conducting surveys and requesting feedback on the Services
  • Personalising content and recommendations based on your usage patterns
  • Displaying targeted advertising on our website and third-party platforms (with your consent where required)
You may opt out of marketing communications at any time by using the unsubscribe link in any email or by contacting support@recruitcrm.io. Opting out of marketing will not affect your receipt of service-related communications.

5.3 AI Features (optional — controller-directed)

Our optional AI-powered features (including call transcription, note-taking, candidate summaries, job description generation and email drafting) process personal data submitted by our customers. The following terms govern AI processing:
  • No AI training on your data: We will not use your personal data or your customers' data to train, fine-tune or improve AI models without your explicit prior written consent.
  • Ownership: You retain full ownership of all inputs and outputs generated through AI Features.
  • Shared responsibility: Recruit CRM implements appropriate safeguards for AI-processed data and maintains shared responsibility with customers under GDPR Articles 26 and 28.
  • Disclosure: AI outputs are provided for informational assistance only. You are responsible for decisions made in reliance on AI outputs.
  • Automated decision-making: Where AI Features involve automated processing that produces significant effects on individuals (Article 22 GDPR), we will disclose this upon request and ensure appropriate human review mechanisms are available.
  • Usage data: We may collect anonymised or pseudonymised technical usage data (error logs, performance metrics) to maintain service quality. No personal data is used for product improvement without your explicit consent.

6. How We Share Personal Data

We do not sell your personal data. We share personal data only as described below:

6.1 Sub-processors

We engage trusted third-party service providers (“sub-processors”) who process personal data on our behalf under written data processing agreements that provide equivalent protections to those in our customer DPA. We notify customers of any changes to our sub-processor list in advance.
The single authoritative and up-to-date list of sub-processors — including their purpose and country of establishment — is maintained in Annex III of the Recruit CRM Data Processing Agreement, available at recruitcrm.io/legal/data-processing-agreement/. The table below is provided as a convenience summary and reflects the sub-processors as of the date of this Policy. In the event of any inconsistency between this table and DPA Annex III, DPA Annex III shall prevail.
Sub-processorPurposeCountry
Amazon Web Services, Inc.Cloud infrastructure hostingUnited States (+ EU regions)
SendGrid, Inc.Transactional email deliveryUnited States
Twilio Inc.Voice, SMS and call recordingUnited States
Google, Inc.Regional data processing, APIsUnited States (+ EU regions)
Intercom, Inc.Customer chat and supportUnited States
Nylas, Inc.Email, calendar and contact syncUnited States
OpenAI, L.L.C.Generative AI featuresUnited States
Workato, Inc.Workflow automation platformUnited States
TextKernel USA LLCAI-powered resume parsingUnited States
Mixpanel, Inc.Product analyticsUnited States
Datadog, Inc.Application monitoring and securityUnited States
Singlestore, Inc.Real-time search and analyticsUnited States
BeamerIn-product announcementsUnited States
UserpilotOnboarding experienceUnited States
Metabase, Inc.Advanced reporting and analyticsUnited States
VONQ Inc.Job advertising and multipostingNetherlands (EEA)
UnipileLinkedIn messaging integrationFrance (EEA)
GeoapifyLocation servicesGermany (EEA)
ContactOut LimitedData enrichmentUnited Kingdom
Bright Data, Inc.Public data scrapingUnited States
Athina AIAI onboarding softwareUnited States
MongoDB, Inc.Audit log captureUnited States
AWS CloudWatch / Elastic SearchLog managementUnited States
All sub-processors located in the United States are covered by the EU-U.S. Data Privacy Framework (and, as applicable, the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF) and/or Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2) as appropriate transfer safeguards. Sub-processors in the EEA are covered by GDPR directly. Sub-processors in the UK are covered by the UK GDPR and UK IDTA where applicable.

6.2 Legal disclosures

We may disclose personal data to law enforcement, courts or other public authorities where required by applicable law or a binding legal order. Where legally permissible, we will notify affected customers before complying with such requests so they may seek appropriate legal remedies. We will always seek to disclose the minimum data necessary to comply with the request.

6.3 Business transfers

In the event of a merger, acquisition, sale of assets or restructuring, personal data may be transferred to the acquiring entity. We will provide advance notice of any such transfer via email and a prominent website notice, and the acquiring entity will be bound by privacy commitments equivalent to this Policy.

6.4 With your consent

We may share personal data with other third parties where you have provided your explicit prior consent for us to do so.

6.5 Onward Transfer Liability

In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF Principles, Workforce Cloud Tech, Inc. remains liable under the DPF Principles for the onward transfer of personal data to third-party sub-processors that process such data on our behalf, unless we prove that we are not responsible for the event giving rise to the relevant damage.

7. International Data Transfers

Recruit CRM is headquartered in the United States. When we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to the United States or other countries, we rely on the following transfer mechanisms:

7.1 EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (primary mechanism for EEA/UK/Switzerland → US transfers)

Workforce Cloud Tech, Inc. adheres to the EU-U.S. Data Privacy Framework (EU-U.S. DPF), as established by the European Commission's Adequacy Decision C(2023) 4745 of 10 July 2023, extending to the United Kingdom under the UK Extension to the EU-U.S. DPF, and to Switzerland under the Swiss-U.S. DPF. Workforce Cloud Tech, Inc.'s current listing can be verified at https://www.dataprivacyframework.gov/

7.2 Standard Contractual Clauses (supplementary safeguard)

We have entered into Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2: Controller-to-Processor) with our sub-processors and customers for transfers of EEA personal data to the US. The SCCs serve as a supplementary transfer mechanism alongside the DPF. The SCCs are governed by the law of Ireland, and disputes are subject to the jurisdiction of the courts of Dublin, Ireland, consistent with the governing law election in our DPA. Where applicable, the UK International Data Transfer Addendum (UK IDTA) applies to transfers subject to the UK GDPR.

7.3 Other transfer mechanisms

Transfers to sub-processors within EEA member states are governed by GDPR directly. Transfers to sub-processors in the UK are subject to UK GDPR. Transfers to sub-processors in countries with an EU adequacy decision are permitted on that basis. All other transfers are covered by SCCs or another mechanism under Chapter V GDPR.
Important note: We do not rely on bundled consent as a transfer mechanism for transfers of personal data from the EEA, UK or Switzerland to the United States. The EU-U.S. DPF and SCCs are our primary transfer mechanisms.

8. Data Retention

We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law. The table below summarises our key retention periods:
Data categoryRetention periodLegal basis for retention
Customer account data (active accounts)Duration of subscriptionArt. 6(1)(b) — contract performance
Customer account data (post-termination)14 days (export window)Art. 6(1)(f) — legitimate interest in orderly transition
System logs (active log management)30 days post-terminationArt. 6(1)(f) — security incident investigation
System logs (cold storage archive)11 months further (after active log period)Art. 6(1)(f) — legal compliance and security
Billing and financial records10 yearsArt. 6(1)(c) — legal obligation (tax/accounting law)
Marketing opt-in recordsUntil consent withdrawn + 3 yearsArt. 6(1)(a) — consent; Art. 6(1)(f) — dispute resolution
Candidate/contact data (processor role)As instructed by ControllerPer customer DPA instructions
Upon expiry of each retention period, personal data is securely and permanently deleted in accordance with NIST SP800-88 guidelines for media sanitisation. Customer data cannot be recovered once deleted. Upon written request, we will provide a written certification of deletion within 30 days.
Controllers using Recruit CRM as a processor should refer to this retention table in conjunction with Section 11 of the Recruit CRM Data Processing Agreement when completing their own Article 30 Records of Processing Activities.

9. Cookies and Tracking Technologies

We use cookies and similar technologies (web beacons, pixels, local storage) on our website and within the Services. In jurisdictions where required by the ePrivacy Directive and GDPR (including all EEA member states and the UK), we obtain your consent before placing non-essential cookies via our cookie consent banner.

9.1 Types of cookies we use

Cookie typePurposeLegal basis
Essential cookiesRequired for the platform to function. Include session management, authentication and security tokens. Cannot be disabled without disrupting the Service.Art. 6(1)(b) — contract; strictly necessary
Analytics / insight cookiesUsed to understand how users interact with our platform (e.g. Mixpanel, Datadog). Help us improve user experience. Data is pseudonymised where possible.Art. 6(1)(a) — consent
Marketing cookiesUsed to deliver targeted advertising and track campaign effectiveness (e.g. Facebook Pixel, LinkedIn Insight Tag). Set only with your consent.Art. 6(1)(a) — consent
Functional cookiesRemember your preferences and settings (e.g. language, timezone). Improve convenience but not essential.Art. 6(1)(a) — consent
You can manage or withdraw your cookie consent at any time via our cookie preference centre (accessible from the cookie banner on our website) or by adjusting your browser settings. Note that disabling certain cookies may affect the functionality of the Services. For Do Not Track (DNT) signals: we currently do not respond to DNT signals from browsers.
Third-party tracking: We partner with advertising networks (including Google, Facebook/Meta and LinkedIn) that may use cookies and web beacons to serve you interest-based advertisements. If you wish to opt out of interest-based advertising, visit https://www.youronlinechoices.eu/ (EEA), https://optout.aboutads.info/ (US), or manage preferences via each platform's privacy settings. You may also opt out of RB2B/Retention.com data practices at https://app.retention.com/optout.

10. Your Data Protection Rights

Depending on your location, you may have the following rights under applicable Data Protection Laws. These rights are available to individuals in the EU/EEA under the GDPR, to individuals in the United Kingdom under the UK GDPR, and to individuals in Switzerland under the Swiss Federal Act on Data Protection (FADP) — including with respect to the right of access and the right to limit the use and disclosure of personal data. The specific statutory basis and, in some cases, the scope of a right varies slightly by law, as set out in the “Legal basis” column below. We respond to all valid requests within 30 days (or within the timeframe required by applicable law). We will not charge a fee unless a request is manifestly unfounded or excessive.
RightWhat it meansHow to exerciseLegal basis
Right of Access (Art. 15)Obtain a copy of your personal data and information about how it is processed.Email: support@recruitcrm.ioArt. 15 GDPR / UK GDPR; Art. 25 FADP
Right to Rectification (Art. 16)Correct inaccurate or incomplete personal data we hold about you.Email or via account settingsArt. 16 GDPR / UK GDPR; Art. 32(1) FADP
Right to Erasure (Art. 17)Request deletion of your personal data where there is no legitimate reason for continued processing.Email: support@recruitcrm.ioArt. 17 GDPR / UK GDPR; Art. 32(2) FADP (destruction / blocking)
Right to Restrict Processing (Art. 18)Request that we limit how we use your data in certain circumstances.Email: support@recruitcrm.ioArt. 18 GDPR / UK GDPR; closest FADP equivalent is the right to request a prohibition on disclosure (Art. 32(2)(c) FADP) — FADP has no directly equivalent standalone right
Right to Data Portability (Art. 20)Receive your personal data in a structured, machine-readable format.Email: support@recruitcrm.ioArt. 20 GDPR / UK GDPR; Art. 28 FADP
Right to Object (Art. 21)Object to processing based on legitimate interests or for direct marketing purposes.Email or unsubscribe linksArt. 21 GDPR / UK GDPR; Art. 30(2) FADP (narrower scope — see note below)
Right re Automated Decisions (Art. 22)Not be subject to solely automated decisions that produce significant effects, including profiling.Email: support@recruitcrm.ioArt. 22 GDPR / UK GDPR; Art. 21 FADP
Right to Lodge a Complaint (Art. 77)Complain to a supervisory authority in your country of residence.Contact your national DPA, UK ICO, or Swiss FDPICArt. 77 GDPR / UK GDPR; see Section 10.2 for the Swiss FDPIC reporting channel
Note on UK and Swiss scope: The UK GDPR mirrors the EU GDPR's articles and numbering directly, so UK individuals may exercise the same rights on the same statutory basis. The Swiss FADP grants closely corresponding rights (access, rectification, erasure/destruction, and data portability under Articles 25–32 FADP; protection from automated individual decisions under Article 21 FADP), but with some differences in scope compared to the GDPR — for example, the FADP does not include a directly equivalent standalone right to “restrict processing,” and its right to object is narrower than GDPR Article 21. The exact statutory citations above should be confirmed by legal counsel before this Policy is finalized for publication.

10.1 How to exercise your rights

To exercise any of the rights above, contact us at support@recruitcrm.io with “Data Rights Request” in the subject line. We may ask you to verify your identity before processing your request to protect against unauthorised access. If you are an employee or candidate whose data is processed by one of our customers, please contact that customer directly as they are your data controller.

10.2 Right to lodge a complaint

If you are not satisfied with our response, or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with your local supervisory authority:
  • EEA residents: The supervisory authority of your EU Member State of habitual residence or place of work (a full list is available at https://edpb.europa.eu/). For matters relating to the governing law of our SCCs, the lead supervisory authority is the Data Protection Commission (DPC) of Ireland — dataprotection.ie
  • UK residents: The Information Commissioner's Office (ICO) — ico.org.uk
  • Swiss residents: The Swiss Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch
  • California residents: The California Privacy Protection Agency (CPPA) — cppa.ca.gov

10.3 DPF recourse mechanism

Independent Recourse Mechanism (DPF requirement): In compliance with the EU-US DPF and the UK Extension to the EU-U.S. DPF, Swiss-US DPF Principles, Workforce Cloud Tech, Inc. commits to resolve complaints about our collection or use of your personal data. This Policy covers personal data other than human resources (HR) data; Workforce Cloud Tech, Inc.'s DPF self-certification does not currently cover HR data. EU, UK and Swiss individuals with inquiries or complaints regarding our DPF compliance should first contact us at support@recruitcrm.io.
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our US-based independent dispute resolution provider JAMS (free of charge to you) at https://www.jamsadr.com/dpf-dispute-resolution
Under certain conditions, you may also be entitled to invoke binding arbitration before the DPF Panel. For details, see Annex I of the DPF Principles at https://www.dataprivacyframework.gov/framework-article/Annex-I-introduction

11. Security of Your Personal Data

We implement appropriate technical and organisational measures (TOMs) to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in accordance with GDPR Article 32. Our security measures include:
  • Encryption of personal data in transit (TLS 1.2 or higher) and at rest
  • Multi-factor authentication (MFA) for access to systems containing personal data
  • Role-based access controls and need-to-know access restrictions
  • Annual penetration and vulnerability testing by independent third parties
  • Annual SOC 2 Type II audits and ISO 27001:2022 alignment
  • Continuous application monitoring via monitoring tools
  • Physical data centre security controls at all AWS facilities
  • Annual privacy and security training for all personnel with access to personal data
  • Formal incident response procedures aligned with NIST and EDPB Recommendation 01/2020
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Article 33), and will notify affected individuals without undue delay where required under GDPR Article 34.
While we take all reasonable steps to protect your data, no internet transmission is completely secure. We therefore cannot guarantee absolute security of data transmitted to our website or Services.

12. Children's Personal Data

Our Services are designed for use by adults and professional organisations. We do not knowingly collect personal data from children under 13 years of age (or under 16 in EEA member states that have set the age of digital consent at 16 under GDPR Article 8). We do not permit children to access or use our Services without verified parental consent. If you believe a child has provided personal data to us without appropriate consent, please contact support@recruitcrm.io immediately and we will delete that data without undue delay.

13. California Residents — CCPA / CPRA Rights

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following additional rights:
  • Right to Know: Request disclosure of the categories and specific pieces of personal information collected, the purposes for collection, and the categories of third parties with whom we share it
  • Right to Delete: Request deletion of personal information, subject to certain exceptions
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing: We do not sell personal information. We do not share personal information for cross-context behavioural advertising without your opt-in consent
  • Right to Limit Use of Sensitive Personal Information: Limit our use of sensitive personal information to that which is necessary to perform the Services
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights
To exercise your California rights, contact us at support@recruitcrm.io or use the “Data Rights Request” subject line. We will respond within 45 days as required by CCPA/CPRA. We do not respond to Global Privacy Control (GPC) signals at this time but review this position on an ongoing basis.

14. Mobile Applications

When you use our mobile application, we collect device type, operating system version, device identifier (UDID), and usage data. We may send push notifications for service updates and promotions — you can disable these at the device level at any time. Location data is collected only with your explicit device-level consent and is used solely to provide location-based search features within the app. You may revoke location consent at any time via your device settings.

15. Google API Disclosure

Recruit CRM's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Personal data received through Google APIs is used only for the purpose of providing the requested Service feature and is not used for advertising, sold to third parties, or used to train AI models.

16. Third-Party Services, Social Media and Links

Our website includes links to third-party websites and integrations with social media platforms (including LinkedIn, Facebook and Twitter/X). We are not responsible for the privacy practices of those platforms. We encourage you to review their privacy policies before interacting with their features. Social media features embedded on our website (such as “Like” or “Share” buttons) may set cookies and collect your IP address — subject to your cookie consent choices.
Our website may include community forums or public blogs. Information you share publicly in these areas may be read or used by others. Contact support@recruitcrm.io to request removal of your personal information from public forums.

17. Amendments to This Policy

We review and update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements or regulatory guidance. If we make material changes, we will:
  • Notify you via email (to the address registered to your account) at least 14 days in advance of the change taking effect
  • Display a prominent notice on our website
  • Update the “Last updated” date at the top of this Policy
  • Where required, obtain fresh consent for any new processing activities
This 14-day advance notification period is consistent with the amendment notification process set out in the Recruit CRM Data Processing Agreement (Section 12.5). For business customers bound by both this Policy and the DPA, the DPA amendment process governs changes to processor-role obligations; this Policy governs changes to controller-role processing and individual user rights.
For DPF-related changes, we will notify the U.S. Department of Commerce in advance. Amendments to our Data Processing Agreement require written agreement by both parties in accordance with Section 12.5 of the DPA.

18. How to Contact Us

For any questions, concerns or requests regarding this Privacy Policy or your personal data:
Query typeContact
General privacy enquiriessupport@recruitcrm.io
Data rights requestssupport@recruitcrm.io (subject: “Data Rights Request”)
Data breach reportssupport@recruitcrm.io (subject: “Security Incident”)
DPF complaints (first contact)support@recruitcrm.io
DPF independent recourseJAMS — jamsadr.com/dpf-dispute-resolution
Lead supervisory authority (SCC governing law)Data Protection Commission (DPC) Ireland — dataprotection.ie
Company addressWorkforce Cloud Tech, Inc. & all its subsidiaries, 28 Mohawk Avenue, Norwood, NJ 07648, United States
Websiterecruitcrm.io