Informação legal
Política de Privacidade
Última atualização: 5 de outubro de 2026
Esta Política de Privacidade explica como a RecrutFlo trata dados para automatizar caixas de CV, organizar registos de candidatos, administrar contas, medir anonimamente a utilização do site e realizar contactos empresariais limitados. O serviço foi concebido segundo os princípios de proteção de dados da UE e assinala o alinhamento com o Reino Unido quando relevante.
A quem se aplica esta política e como nos contactar
RecrutFlo is operated by an individual entrepreneur (self-employed sole trader) registered in the Slovak Republic, trading as "RecrutFlo".
For most candidate data processed through a customer's workspace, RecrutFlo acts as a processor and the customer is the controller - see "Purpose and lawful use" below. For questions about this policy, or to exercise a data protection right described below, contact privacy@recrutflo.com (or support@recrutflo.com for general support).
Dados que tratamos
RecrutFlo may process account data, tenant and user settings, session data, mailbox configuration, email metadata, email content relevant to candidate intake, CV attachments, extracted candidate fields, review notes, processing logs, audit events and export metadata.
Candidate data may include name, email address, phone number, location, professional summary, employment history, education, skills, languages, role context, source mailbox and other information contained in a CV or candidate email.
For privacy-minimised public-site measurement, RecrutFlo records a random browser-tab identifier held only in memory, public page paths, page-view counts, first and last activity times and allowlisted UTM campaign parameters. It does not record an IP address, location, browser or device details, account ID or persistent cross-visit identifier in this measurement dataset.
RecrutFlo does not collect, transmit, access or store payment card numbers, card security codes, bank account credentials or payment authentication data at any point, for customers or candidates. Paid subscription payment data is entered directly into Stripe's own systems and never passes through RecrutFlo.
Finalidade e utilização lícita
RecrutFlo processes data only for the purpose of providing the service: mailbox intake, CV detection, structured extraction, candidate organization, duplicate handling, search, review, export, audit, security, billing administration and support.
The customer decides which mailboxes are connected and which candidate data is processed. The customer is normally the controller of candidate data and is responsible for having a lawful basis to process it. RecrutFlo acts as a processor when it hosts and processes candidate data on the customer's behalf, except where it processes limited data for its own legal, security, billing or service administration purposes as an independent controller.
Contactos empresariais e comunicação comercial
RecrutFlo may use a business contact's name, work email address, job title, employer, publicly available professional information, outreach history and replies to introduce the service to relevant businesses. This information may come from company websites, public professional profiles, official company registers, direct referrals or a business-to-business contact-data provider. For this limited activity RecrutFlo acts as a controller and relies on its legitimate interests in responsibly promoting and improving the service, subject to applicable direct-marketing rules.
Outreach is limited to contacts whose professional role appears relevant. Messages identify RecrutFlo and the sender and provide a simple way to opt out. RecrutFlo does not knowingly send unsolicited marketing to sole traders or other individual subscribers where prior consent is required. Anyone may object to direct marketing at any time by replying to the message or contacting the privacy address in this policy; RecrutFlo will stop the outreach and retain only the minimum suppression information needed to avoid contacting that person again.
Prospect information is kept only for as long as reasonably needed for the outreach or an ongoing business discussion and is ordinarily deleted or anonymized within 12 months of the last meaningful interaction. Minimal suppression records may be retained for longer to respect an opt-out.
Dados de caixas de correio Google e Microsoft
When a customer explicitly connects a supported mailbox, RecrutFlo requests only the OAuth permissions needed to provide mailbox intake and candidate-organization features. For Gmail, the application searches for newly arrived messages that contain attachments. For each matching message, it accesses the Gmail message identifier, received time, From and Subject headers, and attachment filename, media type, size and attachment identifier. Its Gmail API request deliberately excludes ordinary message-body content. It downloads only supported PDF, DOC or DOCX attachments identified as possible CVs.
RecrutFlo uses this Google user data only to identify incoming candidate documents, protect against duplicate imports, extract objective CV fields, and display the resulting candidate record, source information and processing status to authorized users in the customer's workspace. It stores the source message identifier, sender, subject, received time, supported CV attachment, extracted text and derived candidate fields for those user-facing features. It does not store unrelated Gmail messages or ordinary Gmail message bodies.
For Gmail, RecrutFlo requests https://www.googleapis.com/auth/gmail.readonly through Google OAuth. This scope is required because Gmail attachment bytes cannot be retrieved with gmail.metadata. RecrutFlo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
For Microsoft 365 and Outlook, RecrutFlo uses Microsoft OAuth and Microsoft Graph with Mail.Read and offline_access permissions. Mail.Read permits read-only access to messages and attachments; offline_access permits RecrutFlo to maintain the connection until the customer or their organization revokes it.
RecrutFlo does not use Google or Microsoft mailbox access to send, modify or delete messages. Mailbox data is not used for advertising, profiling unrelated to recruitment administration, or sale to third parties. Access is limited to the user-facing features described in this policy.
RecrutFlo personnel do not routinely read Google message or attachment content. Human access is limited to cases where the customer affirmatively requests support involving specific data, where access is necessary to investigate a security incident or abuse, or where required by law. Personnel and service providers with authorized access are bound to use the data only for those purposes and to protect its confidentiality.
A customer can stop future mailbox access by removing the connected mailbox in RecrutFlo or revoking RecrutFlo's permission from their Google Account. Removing a mailbox immediately revokes the credential within RecrutFlo and erases the stored OAuth refresh-token ciphertext. Previously imported candidate records remain available until the customer deletes them or requests workspace erasure. Deleting a candidate permanently removes that candidate's active database record, related imported email records, extracted results and stored CV attachment. Residual disaster-recovery copies are isolated from normal application access and expire through the hosting provider's protected backup-rotation process.
Workspace administrators can remove a connected mailbox from CV sources, disable automatic collection without removing it, and delete an imported candidate from that candidate's record. Candidates and other data subjects can request deletion through the customer that controls the recruitment workspace or through the privacy contact below.
Mecanismos de proteção e segurança dos dados
RecrutFlo protects data in transit with HTTPS/TLS between users, RecrutFlo, Google, Microsoft, storage services and subprocessors. Google and Microsoft OAuth refresh tokens are encrypted at rest using authenticated AES-256-GCM encryption with encryption keys held separately in protected server configuration. Tokens are decrypted only by the backend when it must obtain a short-lived provider access token.
Account passwords are protected with unique salts and the scrypt password-hashing function. Session tokens are cryptographically signed, their server-side identifiers are stored as hashes, and browser session cookies use Secure, HttpOnly and SameSite protections. Sessions have absolute expiration, server-side revocation and an inactivity timeout.
The application enforces tenant-scoped authorization and role-based permissions so workspace data is available only to authenticated members of the relevant customer workspace. Destructive candidate deletion is restricted to owners and administrators. CV attachments are kept in non-public storage and downloads are proxied through an authenticated, tenant-authorized application route rather than exposed as public file links.
Production credentials and encryption keys are kept outside client-side code and source control. RecrutFlo records security-relevant and administrative events in audit logs, limits routine application logging of message content and credentials, maintains access-controlled disaster-recovery backups, applies security updates, and reviews operational errors and suspected incidents. If a personal-data breach requires notice under applicable law, RecrutFlo will notify affected customers or authorities as legally required. No security mechanism can eliminate all risk, but these controls are designed to prevent unauthorized access, alteration, disclosure and loss.
Tratamento por IA e treino de modelos
To provide the visible CV-extraction feature, RecrutFlo may send OpenAI's API a limited prompt containing the source sender, subject, attachment filename and a bounded portion of text extracted from the CV attachment. RecrutFlo does not send the user's ordinary Gmail message body to OpenAI. OpenAI returns structured candidate fields that RecrutFlo automatically stores in a generated candidate record. High-confidence records may be activated automatically, while lower-confidence results are presented to authorized recruiters for verification. OpenAI is not permitted to use the data for advertising or unrelated purposes.
RecrutFlo does not use Google user data, Gmail data, CV content, prompts, API outputs or derived candidate data to train or improve any generalized or shared artificial-intelligence or machine-learning model. RecrutFlo does not opt in to OpenAI API data sharing for model training and sends Responses API requests with storage disabled. Under OpenAI's API data controls, API inputs and outputs are not used for model training by default; OpenAI may retain limited API content for up to 30 days in abuse-monitoring logs unless a shorter approved retention control applies, or longer where legally required.
AI processing is limited to automatic extraction and organization. It does not require human input to create a candidate record; recruiter verification is required by the product workflow only for lower-confidence results. RecrutFlo does not use AI to rank candidates, recommend hiring decisions, determine suitability or make legal or similarly significant decisions.
Exatidão dos dados extraídos e enviados pelos candidatos
Automated extraction may produce incomplete, outdated or inaccurate results because CVs and emails vary in format, language, quality and context. RecrutFlo does not guarantee the validity, completeness or current accuracy of extracted data, and disclaims liability for decisions made in reliance on it.
Separately, RecrutFlo has no means of independently verifying the truthfulness of information a candidate chooses to submit in a CV or email - identity, qualifications, employment history and similar claims are third-party content outside RecrutFlo's control. RecrutFlo accepts no responsibility for false, misleading or fraudulent candidate-submitted information.
Candidate records are created automatically. Lower-confidence results are held for recruiter verification, while high-confidence records may enter the active candidate pool automatically. Customers remain responsible for checking extracted information before relying on it for recruitment or other consequential decisions. The service is intended to organize information, not to validate credentials, verify employment history, assess suitability, rank candidates or make hiring decisions. No output of the service is used to make a decision producing legal or similarly significant effects about a candidate without human review.
Partilha e subcontratantes
RecrutFlo shares data only with service providers needed to operate the product and its limited business communications. As of the date above, these are: Hostinger (hosting, database, protected backups and transactional email delivery), OpenAI (API-based CV field extraction as described above), Stripe (subscription billing and payment processing), Google Analytics (basic cookieless website measurement and, with consent, optional analytics storage and detailed product usage events), Instantly (B2B contact research and outreach management), and Namecheap Private Email (the dedicated outreach mailbox). Customer workspace data, candidate CVs and Google user data are not shared with Instantly or Namecheap for sales outreach, and Google user data is not shared with Stripe.
Each subprocessor is contractually or by its own terms restricted to processing data only as needed to provide its service to RecrutFlo, and only for the purposes described in this policy.
Transferências internacionais
Where a subprocessor is located outside the EEA or UK, or processes data outside the EEA or UK, RecrutFlo relies on an adequacy decision, Standard Contractual Clauses, or another valid transfer mechanism recognized under GDPR or UK GDPR for that transfer.
Conservação, eliminação e direitos
Customer workspaces should retain candidate data only for as long as needed for the recruitment administration purpose or as required by law. Customers are responsible for defining their own recruitment retention rules and deleting or exporting records when appropriate. RecrutFlo does not currently run automatic time-based deletion of workspace data; a deletion request will be actioned within a reasonable period, subject to data RecrutFlo is legally required to retain (e.g. billing records).
Anonymous public-site presence and campaign records are automatically removed after 90 days. The temporary tab identifier is lost when the tab closes and cannot be used by RecrutFlo to recognize that browser on a later visit.
Individuals may have rights to access, rectify, erase, restrict, object to processing, data portability and to lodge a complaint with a supervisory authority. Requests relating to candidate records should normally be directed first to the customer that controls the recruitment mailbox, since the customer is typically the controller; RecrutFlo will assist customers with such requests where technically possible. Requests directed to RecrutFlo can be sent to privacy@recrutflo.com.
Alinhamento com a UE e o Reino Unido
RecrutFlo is designed with GDPR principles in mind: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability. As a Slovak-registered business, RecrutFlo's lead supervisory authority is the Slovak Office for Personal Data Protection (Úrad na ochranu osobných údajov Slovenskej republiky), without prejudice to a data subject's right to lodge a complaint with the supervisory authority of their own EU member state of residence.
For UK processing, equivalent UK GDPR and Data Protection Act 2018 obligations may apply. UK-specific controller notices, transfer wording and regulatory references should be reviewed before UK-focused launch materials are finalized.
Encarregado da Proteção de Dados
RecrutFlo has not appointed a Data Protection Officer. Based on the nature and current scale of processing, RecrutFlo does not consider itself subject to a mandatory DPO requirement under GDPR Article 37, and will reassess this as the business and its processing activities grow. This does not affect a customer's own, independent assessment of whether it requires a DPO as controller of the candidate data it processes.