Privacy Statement – PolpoHire
1. Who We Are
PolpoHire B.V. | Grunerielaan 5 | kvk: 99910748 | support@polpohire.com | www.polpohire.com
PolpoHire provides an Applicant Tracking System (ATS) for organizations.
2. Roles Under GDPR
PolpoHire operates in two roles:
2.1 As a Data Processor
For customer accounts (tenants), PolpoHire processes personal data on behalf of customers. The customer is the data controller. We only process personal data according to the customer’s documented instructions and our Data Processing Agreement (DPA).
2.2 As a Data Controller
For our own website and business operations (e.g., demo requests, contact forms, billing), PolpoHire acts as the data controller.
3. What Personal Data We Process
3.1 When You Use PolpoHire (Customer Tenants)
Depending on how our customers use the platform, we may process:
- Candidate names
- Contact details (email, phone)
- CV/resume data
- Application information
- Interview notes
- Account login information
- IP address and audit logs
We do not determine the purpose of this processing. Our customers do.
3.2 When You Visit Our Website
If you submit a contact or demo form, we may collect:
- Name
- Email address
- Company name
- Message content
We do not use third-party analytics tools such as Google Analytics. We do not use tracking or marketing cookies from third parties.
4. Legal Basis (Controller Activities Only)
When we act as data controller, we rely on:
- Performance of a contract (e.g., providing the service)
- Legitimate interest (e.g., improving service security)
- Legal obligation (e.g., tax records)
- Consent (where explicitly requested)
5. Hosting and Data Location
All production data is hosted within the European Union using infrastructure provided by Google Cloud Platform in the europe-west4 region (Amsterdam, The Netherlands).
We do not transfer personal data outside the European Union unless explicitly agreed with the customer and safeguarded under appropriate GDPR mechanisms.
6. Subprocessors
PolpoHire uses infrastructure providers strictly necessary to deliver the service, including:
- Google Cloud Platform (hosting and infrastructure)
We do not sell personal data. We do not share personal data with marketing or advertising partners.
A current list of subprocessors is available upon request or via our Data Processing Agreement.
7. Security Measures
We implement appropriate technical and organizational measures, including:
- Encryption in transit (HTTPS/TLS)
- Encrypted storage at rest
- Role-based access control
- Tenant isolation
- Audit logging
- Regular backups
- Kubernetes-based infrastructure with CI/CD controls
8. Data Retention
- Customer data is retained for the duration of the contract.
- Upon termination, data is deleted or returned according to the Data Processing Agreement.
- Legal and financial records are retained according to statutory obligations.
9. Cookies
PolpoHire uses only essential cookies required for:
- Authentication
- Security
- Session management
We do not use tracking cookies or third-party advertising cookies.
10. Your Rights (GDPR)
Under the GDPR, individuals may have the right to:
- Access personal data
- Rectify incorrect data
- Erase data
- Restrict processing
- Data portability
- Object to processing
If your data is processed within a customer tenant, please contact the organization to which you submitted your application first. PolpoHire will assist our customers in fulfilling such requests.
11. Data Breach Policy
In case of a data breach affecting customer data, we:
- Notify the customer without undue delay
- Provide relevant information for regulatory reporting
- Cooperate in mitigation and investigation
12. Changes to This Statement
We may update this Privacy Statement from time to time. The latest version is always available on our website.
