Privacy Policy

Last updated 5 September 2026

Applyyy is an applicant tracking system. This policy explains what we do with personal data, both for people who use Applyyy to hire and for people who apply to a job through it.

Who is responsible for your data

This distinction decides who you should contact about your data.

If you applied to a job: the organization you applied to decides what to collect, why, and how long to keep it. They are the data controller. Applyyy stores and processes that data on their instructions only — we are a processor, and we do not use applicant data for our own purposes, sell it, or use it to train models. Requests to access or delete your application should go to the organization you applied to. If you contact us instead, we will pass the request on to them.

If you use Applyyy to hire: we are the controller for your account data — your name, work email, profile details, and billing records.

What we collect

From applicants: the name, email address, phone number, and résumé you submit through an application form, plus the record of your progress through that organization's hiring process — interview times, interviewer feedback and scores, and internal notes written about your application.

From account holders: your name, email address, profile photo, timezone, and the Google account identifier you sign in with. If your organization connects a calendar, we store the connection's access credentials in encrypted form and the details of interview events we create.

Automatically: server logs containing IP address, request path, and timestamp, kept for security and debugging.

Why we can process it

Processing a job application rests on the steps necessary before entering a contract, and on the hiring organization's legitimate interest in evaluating candidates — not on consent, so you are not asked to tick a box to apply. Account data is processed to perform our contract with your organization. Security logging rests on our legitimate interest in keeping the service safe.

Who else sees it

We use a small number of service providers, each contractually limited to processing data on our instructions: a cloud hosting and database provider, an object storage provider for résumé files, Mailjet for transactional email, Google for sign-in and optional calendar integration, Stripe for billing, and — on our public pages only, and only with your consent — Google Analytics. We do not sell personal data or share it for advertising.

Cookies and analytics

Signing in sets a session cookie. It is required for the service to work and is not used for tracking, so it is not something you are asked to agree to.

Our public pages — this site and the public job boards — can also use Google Analytics to count visits and see which pages are read. Google's code is not loaded until you choose "Accept" on the banner: if you choose "Reject", or never answer, your browser makes no request to Google at all, so no cookie is set and no pageview, IP address, or device detail reaches them. Google's advertising signals stay switched off whatever you choose. Your choice is remembered in your browser's local storage, and "Cookie settings" at the bottom of the page reopens the banner if you want to change it. The signed-in application carries no analytics at all.

How long we keep it

Account data is kept while your organization has an active account. Applicant data is kept for as long as the hiring organization's own retention policy requires; because they are the controller, they set that period, and records may be retained where employment law requires it. When data is erased we overwrite the identifying fields rather than dropping the record, so aggregate hiring statistics survive without the person remaining identifiable.

Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, object to or restrict how it is used, receive a portable copy, and complain to your local data protection authority. We will respond within one month. As above: if the data relates to a job application, direct the request to the organization you applied to, and we will assist them in fulfilling it.

Security

Data is encrypted in transit. Calendar credentials are encrypted at rest. Access within a customer's account is limited by role, and every record is scoped to the organization that owns it. No system is perfectly secure. Should a breach affect your data, we will notify the affected organization without undue delay, and regulators where the law requires it.

Changes

If we change this policy materially we will update the date above and notify account holders by email.

Contact

Questions about this policy, or about data we hold, can be sent through our contact form.