Legal
Privacy Policy
Last updated: August 12, 2026
This Privacy Policy explains how RecrutFlo processes personal data for CV inbox automation, candidate record organization, account administration and limited business-to-business outreach. The service is designed around EU data protection principles and notes UK alignment where relevant.
Who this policy covers and how to reach us
RecrutFlo is operated by an individual entrepreneur (self-employed sole trader) registered in the Slovak Republic, trading as "RecrutFlo".
For most candidate data processed through a customer's workspace, RecrutFlo acts as a processor and the customer is the controller - see "Purpose and lawful use" below. For questions about this policy, or to exercise a data protection right described below, contact privacy@recrutflo.com (or support@recrutflo.com for general support).
Data we process
RecrutFlo may process account data, tenant and user settings, session data, mailbox configuration, email metadata, email content relevant to candidate intake, CV attachments, extracted candidate fields, review notes, processing logs, audit events and export metadata.
Candidate data may include name, email address, phone number, location, professional summary, employment history, education, skills, languages, role context, source mailbox and other information contained in a CV or candidate email.
RecrutFlo does not collect, transmit, access or store payment card numbers, card security codes, bank account credentials or payment authentication data at any point, for customers or candidates. Paid subscription payment data is entered directly into Stripe's own systems and never passes through RecrutFlo.
Purpose and lawful use
RecrutFlo processes data only for the purpose of providing the service: mailbox intake, CV detection, structured extraction, candidate organization, duplicate handling, search, review, export, audit, security, billing administration and support.
The customer decides which mailboxes are connected and which candidate data is processed. The customer is normally the controller of candidate data and is responsible for having a lawful basis to process it. RecrutFlo acts as a processor when it hosts and processes candidate data on the customer's behalf, except where it processes limited data for its own legal, security, billing or service administration purposes as an independent controller.
Business contacts and sales outreach
RecrutFlo may use a business contact's name, work email address, job title, employer, publicly available professional information, outreach history and replies to introduce the service to relevant businesses. This information may come from company websites, public professional profiles, official company registers, direct referrals or a business-to-business contact-data provider. For this limited activity RecrutFlo acts as a controller and relies on its legitimate interests in responsibly promoting and improving the service, subject to applicable direct-marketing rules.
Outreach is limited to contacts whose professional role appears relevant. Messages identify RecrutFlo and the sender and provide a simple way to opt out. RecrutFlo does not knowingly send unsolicited marketing to sole traders or other individual subscribers where prior consent is required. Anyone may object to direct marketing at any time by replying to the message or contacting the privacy address in this policy; RecrutFlo will stop the outreach and retain only the minimum suppression information needed to avoid contacting that person again.
Prospect information is kept only for as long as reasonably needed for the outreach or an ongoing business discussion and is ordinarily deleted or anonymized within 12 months of the last meaningful interaction. Minimal suppression records may be retained for longer to respect an opt-out.
Google and Microsoft mailbox data
When a customer explicitly connects a supported mailbox, RecrutFlo requests only the OAuth permissions needed to provide mailbox intake and candidate-organization features. For Gmail, the application searches for newly arrived messages that contain attachments. For each matching message, it accesses the Gmail message identifier, received time, From and Subject headers, and attachment filename, media type, size and attachment identifier. Its Gmail API request deliberately excludes ordinary message-body content. It downloads only supported PDF, DOC or DOCX attachments identified as possible CVs.
RecrutFlo uses this Google user data only to identify incoming candidate documents, protect against duplicate imports, extract objective CV fields, and display the resulting candidate record, source information and processing status to authorized users in the customer's workspace. It stores the source message identifier, sender, subject, received time, supported CV attachment, extracted text and derived candidate fields for those user-facing features. It does not store unrelated Gmail messages or ordinary Gmail message bodies.
For Gmail, RecrutFlo requests https://www.googleapis.com/auth/gmail.readonly through Google OAuth. This scope is required because Gmail attachment bytes cannot be retrieved with gmail.metadata. RecrutFlo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
For Microsoft 365 and Outlook, RecrutFlo uses Microsoft OAuth and Microsoft Graph with Mail.Read and offline_access permissions. Mail.Read permits read-only access to messages and attachments; offline_access permits RecrutFlo to maintain the connection until the customer or their organization revokes it.
RecrutFlo does not use Google or Microsoft mailbox access to send, modify or delete messages. Mailbox data is not used for advertising, profiling unrelated to recruitment administration, or sale to third parties. Access is limited to the user-facing features described in this policy.
RecrutFlo personnel do not routinely read Google message or attachment content. Human access is limited to cases where the customer affirmatively requests support involving specific data, where access is necessary to investigate a security incident or abuse, or where required by law. Personnel and service providers with authorized access are bound to use the data only for those purposes and to protect its confidentiality.
A customer can stop future mailbox access by removing the connected mailbox in RecrutFlo or revoking RecrutFlo's permission from their Google Account. Removing a mailbox immediately revokes the credential within RecrutFlo and erases the stored OAuth refresh-token ciphertext. Previously imported candidate records remain available until the customer deletes them or requests workspace erasure. Deleting a candidate permanently removes that candidate's active database record, related imported email records, extracted results and stored CV attachment. Residual disaster-recovery copies are isolated from normal application access and expire through the hosting provider's protected backup-rotation process.
Workspace administrators can remove a connected mailbox from CV sources, disable automatic collection without removing it, and delete an imported candidate from that candidate's record. Candidates and other data subjects can request deletion through the customer that controls the recruitment workspace or through the privacy contact below.
Data protection and security mechanisms
RecrutFlo protects data in transit with HTTPS/TLS between users, RecrutFlo, Google, Microsoft, storage services and subprocessors. Google and Microsoft OAuth refresh tokens are encrypted at rest using authenticated AES-256-GCM encryption with encryption keys held separately in protected server configuration. Tokens are decrypted only by the backend when it must obtain a short-lived provider access token.
Account passwords are protected with unique salts and the scrypt password-hashing function. Session tokens are cryptographically signed, their server-side identifiers are stored as hashes, and browser session cookies use Secure, HttpOnly and SameSite protections. Sessions have absolute expiration, server-side revocation and an inactivity timeout.
The application enforces tenant-scoped authorization and role-based permissions so workspace data is available only to authenticated members of the relevant customer workspace. Destructive candidate deletion is restricted to owners and administrators. CV attachments are kept in non-public storage and downloads are proxied through an authenticated, tenant-authorized application route rather than exposed as public file links.
Production credentials and encryption keys are kept outside client-side code and source control. RecrutFlo records security-relevant and administrative events in audit logs, limits routine application logging of message content and credentials, maintains access-controlled disaster-recovery backups, applies security updates, and reviews operational errors and suspected incidents. If a personal-data breach requires notice under applicable law, RecrutFlo will notify affected customers or authorities as legally required. No security mechanism can eliminate all risk, but these controls are designed to prevent unauthorized access, alteration, disclosure and loss.
AI processing and model training
To provide the visible CV-extraction feature, RecrutFlo may send OpenAI's API a limited prompt containing the source sender, subject, attachment filename and a bounded portion of text extracted from the CV attachment. RecrutFlo does not send the user's ordinary Gmail message body to OpenAI. OpenAI returns structured candidate fields that RecrutFlo automatically stores in a generated candidate record. High-confidence records may be activated automatically, while lower-confidence results are presented to authorized recruiters for verification. OpenAI is not permitted to use the data for advertising or unrelated purposes.
RecrutFlo does not use Google user data, Gmail data, CV content, prompts, API outputs or derived candidate data to train or improve any generalized or shared artificial-intelligence or machine-learning model. RecrutFlo does not opt in to OpenAI API data sharing for model training and sends Responses API requests with storage disabled. Under OpenAI's API data controls, API inputs and outputs are not used for model training by default; OpenAI may retain limited API content for up to 30 days in abuse-monitoring logs unless a shorter approved retention control applies, or longer where legally required.
AI processing is limited to automatic extraction and organization. It does not require human input to create a candidate record; recruiter verification is required by the product workflow only for lower-confidence results. RecrutFlo does not use AI to rank candidates, recommend hiring decisions, determine suitability or make legal or similarly significant decisions.
Accuracy of extracted and candidate-submitted data
Automated extraction may produce incomplete, outdated or inaccurate results because CVs and emails vary in format, language, quality and context. RecrutFlo does not guarantee the validity, completeness or current accuracy of extracted data, and disclaims liability for decisions made in reliance on it.
Separately, RecrutFlo has no means of independently verifying the truthfulness of information a candidate chooses to submit in a CV or email - identity, qualifications, employment history and similar claims are third-party content outside RecrutFlo's control. RecrutFlo accepts no responsibility for false, misleading or fraudulent candidate-submitted information.
Candidate records are created automatically. Lower-confidence results are held for recruiter verification, while high-confidence records may enter the active candidate pool automatically. Customers remain responsible for checking extracted information before relying on it for recruitment or other consequential decisions. The service is intended to organize information, not to validate credentials, verify employment history, assess suitability, rank candidates or make hiring decisions. No output of the service is used to make a decision producing legal or similarly significant effects about a candidate without human review.
Sharing and subprocessors
RecrutFlo shares data only with service providers needed to operate the product and its limited business communications. As of the date above, these are: Hostinger (hosting, database, protected backups and transactional email delivery), OpenAI (API-based CV field extraction as described above), Stripe (subscription billing and payment processing), Google Analytics (basic cookieless website measurement and, with consent, optional analytics storage and detailed product usage events), Instantly (B2B contact research and outreach management), and Namecheap Private Email (the dedicated outreach mailbox). Customer workspace data, candidate CVs and Google user data are not shared with Instantly or Namecheap for sales outreach, and Google user data is not shared with Stripe.
Each subprocessor is contractually or by its own terms restricted to processing data only as needed to provide its service to RecrutFlo, and only for the purposes described in this policy.
International transfers
Where a subprocessor is located outside the EEA or UK, or processes data outside the EEA or UK, RecrutFlo relies on an adequacy decision, Standard Contractual Clauses, or another valid transfer mechanism recognized under GDPR or UK GDPR for that transfer.
Retention, deletion and rights
Customer workspaces should retain candidate data only for as long as needed for the recruitment administration purpose or as required by law. Customers are responsible for defining their own recruitment retention rules and deleting or exporting records when appropriate. RecrutFlo does not currently run automatic time-based deletion of workspace data; a deletion request will be actioned within a reasonable period, subject to data RecrutFlo is legally required to retain (e.g. billing records).
Individuals may have rights to access, rectify, erase, restrict, object to processing, data portability and to lodge a complaint with a supervisory authority. Requests relating to candidate records should normally be directed first to the customer that controls the recruitment mailbox, since the customer is typically the controller; RecrutFlo will assist customers with such requests where technically possible. Requests directed to RecrutFlo can be sent to privacy@recrutflo.com.
EU and UK alignment
RecrutFlo is designed with GDPR principles in mind: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability. As a Slovak-registered business, RecrutFlo's lead supervisory authority is the Slovak Office for Personal Data Protection (Úrad na ochranu osobných údajov Slovenskej republiky), without prejudice to a data subject's right to lodge a complaint with the supervisory authority of their own EU member state of residence.
For UK processing, equivalent UK GDPR and Data Protection Act 2018 obligations may apply. UK-specific controller notices, transfer wording and regulatory references should be reviewed before UK-focused launch materials are finalized.
Data Protection Officer
RecrutFlo has not appointed a Data Protection Officer. Based on the nature and current scale of processing, RecrutFlo does not consider itself subject to a mandatory DPO requirement under GDPR Article 37, and will reassess this as the business and its processing activities grow. This does not affect a customer's own, independent assessment of whether it requires a DPO as controller of the candidate data it processes.