Privacy policy
Who we are
OleeHire is an AI hiring platform operated by Oleon (Private) Limited at hire.oleon.io. In this policy "we" and "us" mean Oleon (Private) Limited, and "you" means whoever is reading it, whether you are a recruiter using the platform or a candidate applying through it.
For anything about this policy, write to privacy@oleon.io and we will answer within 30 days.
Two different relationships
Who controls your data depends on how you reached us. The distinction matters, because it decides who you ask when you want a copy or a deletion.
- Recruiters and employers. We are the controller of your account data: your name, email, the organisation you belong to, your billing details and how you use the product.
- Candidates. The employer that published the apply link is the controller of your application. We are their processor, acting on their instructions. We only handle your CV, interview and scores to run the hiring process for them.
What we collect
We collect only what the hiring process needs, plus basic analytics about how the site is used. There is no advertising network here, nothing is sold on, and no profile is built for any purpose other than the role you applied to or the account you run.
- Account details: name, work email, role in the organisation, and the password hash or Google account identifier used to sign in.
- Organisation details: company name, team members you invite, plan and billing information.
- Content you create: job descriptions, screening criteria, interview questions, notes, messages to candidates.
- Usage and diagnostic data: pages visited inside the app, actions taken, IP address, browser and device type, error logs.
- Application data: your CV or resume file and everything inside it, plus any answers you give on the apply form.
- Contact details: name, email address, phone number if you provide one.
- Interview data: audio of your answers, the transcript generated from that audio, and timing information for the session.
- Assessment data: scores, rankings, evidence citations and the written reasoning the AI produced against the employer's criteria.
- Technical data: IP address, browser and device type, and the Google account identifier if the employer requires a Google sign-in to reach the interview.
How we use it
- To run the hiring process: collect applications, score CVs against the employer's criteria, conduct voice interviews, and produce the ranked report.
- To operate accounts: authentication, permissions, billing, support, and service notices about outages or changes.
- To keep the platform safe: rate limiting, abuse and fraud detection, and the insert-only audit log that records every state change on an application.
- To improve the product: aggregated and de-identified usage statistics that cannot be traced back to a person.
- To meet legal obligations: tax records, and equal opportunity or anti-discrimination records where an employer is required to keep them.
AI processing and automated decisions
OleeHire uses Google Vertex AI to read CVs, generate interview questions, transcribe and grade answers, and write the reasoning behind each score. This is a substantial use of automated processing and we want you to understand its limits.
- A human always decides. The AI produces a recommendation and a score. Selecting or rejecting a candidate is an action taken by a named person in the employer's team, recorded against that person in the audit log, never against the model.
- Every score cites evidence. Scores reference the line in the CV or the moment in the interview that produced them, so a decision can be reviewed and challenged.
- AI can be wrong. Models misread documents, mishear audio and miss context. Treat output as a first pass, not a verdict.
- You can ask for a review. Candidates may request human review of any assessment, contest the result, and give their point of view. Ask the employer first, or write to privacy@oleon.io.
Legal bases for processing
Where the GDPR or a similar law applies, we rely on the following bases.
- Contract: to provide the platform to a recruiter who has signed up, and to run an application a candidate has submitted.
- Legitimate interests: to secure the service, prevent abuse, keep audit records, and improve the product using aggregated data.
- Consent: for optional things such as keeping a candidate record in an employer's talent pool after the role closes, or marketing email. Consent can be withdrawn at any time.
- Legal obligation: where we must keep records for tax, accounting or employment law.
International transfers
Data is stored in the region an organisation selects, EU by default. Some providers process data outside that region. Where personal data leaves the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, the UK Addendum, or an adequacy decision, together with encryption in transit and at rest.
How long we keep it
Employers set retention windows for their own organisation, within the limits below. When a window ends, the record is deleted automatically rather than archived.
| Data | Rule | Default |
|---|---|---|
| CVs and applications | Deleted automatically at the end of the period | 12 months |
| Interview recordings | Audio and transcript, deleted together | 6 months |
| Talent pool records | Kept only with the candidate agreeing | 24 months |
| Audit events | Cannot be shortened below the legal minimum | 7 years |
| Recruiter accounts | Deleted 30 days after the account is closed | 30 days |
Backups roll off on their own schedule and are fully replaced within 35 days of a deletion.
How we protect it
- Row Level Security in Postgres denies access by default. Every table has a policy, so one organisation can never read another's data.
- CVs and recordings live in private storage buckets and are served only through short-lived signed URLs.
- Candidates never receive an account password. Access to a status page or an interview uses an opaque, single-purpose, expiring token.
- Service credentials for the database and the AI provider exist only in server-side code and are never sent to a browser.
- Data is encrypted in transit with TLS and at rest by our infrastructure providers.
- Every state change on an application is appended to an insert-only audit log.
Your rights
Depending on where you live you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, receive it in a portable format, withdraw consent, and complain to your data protection authority.
- Recruiters: most of this is self-service in Settings. Anything else, write to privacy@oleon.io.
- Candidates: ask the employer that published the role first, since they control your application. Copy us at privacy@oleon.io and we will make sure the request is actioned.
We do not charge for these requests and we will not treat you differently for making one.
Children
OleeHire is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has submitted data through the platform, write to privacy@oleon.io and we will delete it.
Changes to this policy
We update this policy when the product or the law changes. The date at the top always reflects the current version. For material changes we will email account holders and show a notice in the app at least 14 days before the change takes effect.
Contact us
Privacy questions, data requests and complaints: privacy@oleon.io.
Postal address: Oleon (Private) Limited, hire.oleon.io. If you are in the EEA or the UK and are unhappy with our response, you may complain to your local supervisory authority.
See also our terms of service.