Legal
Privacy Policy
Last updated: February 2025
This Privacy Policy describes how Guide42 Technologies Ltd ("Guide42", "we", "us") collects, uses, and protects personal data when you use our platform. We are committed to transparency and protecting your privacy.
1. Data We Collect
Account data: Name, email address, company name, and role when you register.
HR and candidate data: CVs, job descriptions, onboarding documents, and other content you upload to the platform.
Usage data: Session logs, feature interactions, timestamps, browser type, and IP address.
Payment data: Billing information is processed by Stripe. We do not store credit card numbers on our servers.
2. How We Use Your Data
- Provide and operate the Service, including AI-powered matching and onboarding
- Process payments and manage subscriptions
- Send transactional emails (account, billing, security alerts)
- Analyse usage patterns to improve the platform
- Comply with legal obligations
We do not sell your personal data. We do not use your data to train AI models.
3. Cookies and Analytics
We use essential cookies for authentication and session management. We may use analytics services (e.g., Vercel Analytics) to understand aggregate usage patterns. You can manage cookie preferences in your browser settings. We do not use third-party advertising trackers.
4. Data Processors
We share data with the following processors to operate the Service:
- Stripe — payment processing
- Vercel — frontend hosting and edge delivery
- Railway — backend API hosting
- OpenAI — AI inference (data is not used for model training per our agreement)
- Cloud infrastructure — encrypted storage and compute
All processors are bound by data processing agreements that meet GDPR standards.
5. Data Retention
We retain your account data for the duration of your subscription and for 90 days after account deletion to support recovery requests. Candidate and HR data you upload is deleted within 30 days of account closure or upon request. Usage logs are retained for up to 12 months for analytics and security purposes.
6. Your Rights
Under applicable data protection laws (including the GDPR and UAE PDPL), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your data
- Export your data in a portable format
- Object to or restrict certain processing activities
- Withdraw consent where processing is based on consent
To exercise any of these rights, contact privacy@guide42.ai. We will respond within 30 days.
7. Data Security
We apply encryption in transit (TLS 1.2+) and at rest. PII redaction is applied at the input layer before content reaches AI models. Access controls and audit logging are enforced across all infrastructure.
8. International Transfers
Your data may be processed in jurisdictions outside your country of residence. Where transfers occur, we ensure appropriate safeguards are in place, including standard contractual clauses and adequacy decisions.
9. Children's Privacy
The Service is not directed to individuals under 16. We do not knowingly collect data from children. If we become aware of such data, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification. Continued use of the Service after changes constitutes acceptance.
11. Contact
For privacy inquiries, contact our Data Protection Officer at privacy@guide42.ai.
