Ask Aria. ← Back to askaria.co.za
Legal · Effective 8 October 2026

Privacy Policy

How personal information is processed on Ask Aria, in compliance with the Protection of Personal Information Act 4 of 2013 (POPIA), the EU/UK General Data Protection Regulation (GDPR), and applicable law.

Terms of Service

AiR Talent Group Ltd
Company number 15462267
5 Alderdale Road, Stockport, SK8 5PP, United Kingdom
Information Officer: Joseph Entwisle — [email protected]

1. Who is responsible

AiR Talent Group Ltd is the responsible party (POPIA) / controller (GDPR) for platform data — your account, billing, usage metering, and the operation of the Service. For candidate and hiring-manager information processed inside a customer workspace, the customer is the responsible party/controller and AiR processes it as their operator/processor on their instructions.

2. Whose data, and what data

Data subjectsWhat we process
Platform usersName, work email, organisation, account type, sign-in events, settings (signature, brand assets), support messages, billing records, usage balance and usage ledger, and your acceptance of these terms (time and version).
CandidatesName, professional profile information (title, employer, work history, skills, location, public profile URLs), contact details where revealed (personal email for candidate outreach), outreach history, replies, availability, interview records, screening and reference responses, recruiter ratings.
Hiring managersName, title, company, public profile URL, work contact details where revealed, outreach history.
Talent pool membersThe details a job seeker gives us when they join the Ask Aria talent pool (see §9, “Joining the Ask Aria talent pool”): name, email, phone, city, salary expectation, notice period, roles wanted, CV and an optional LinkedIn profile, plus the record of their consent.
RefereesName, contact details, reference responses they submit.

We do not intentionally collect special-category / special personal information, and the Service must not be used to process it as search or ranking criteria.

3. Where candidate data comes from

Candidate and hiring-manager information is collected from: (a) information the customer uploads (CVs, lists); (b) publicly available professional sources (public profiles on LinkedIn and GitHub); (c) licensed B2B data providers (currently Apollo and ContactOut) used to verify professional details and, on explicit request, reveal contact details; and (d) the individuals themselves (replies, forms, availability submissions).

Where data is collected from sources other than the individual, POPIA section 18(1) and GDPR Article 14 notice is given at the point of first outreach: our emails identify the sender and the Service, explain why the person is being contacted, and every message allows the person to object, correct their information or ask to be deleted.

4. Purposes and lawful bases

PurposeGDPR basisPOPIA justification
Operating your account, plans, usage and billingContract (Art 6(1)(b))s11(1)(b) contract
Candidate sourcing, ranking and recruitment workflow for a genuine roleLegitimate interests (Art 6(1)(f)) of the recruiting organisation and candidate interest in relevant opportunitiess11(1)(f) legitimate interests
Revealing contact details on user requestLegitimate interests, balanced per requests11(1)(f)
Metering, security, fraud and abuse preventionLegitimate interestss11(1)(f)
Legal compliance (tax, records, requests from regulators)Legal obligation (Art 6(1)(c))s11(1)(c)
Service improvement using aggregated, de-identified usageLegitimate interestss11(1)(f); de-identified data falls outside POPIA

5. AI processing, automated decision-making and fairness

The Service uses AI models to parse briefs, search and rank candidates, verify profile information, draft documents and emails, and transcribe meetings. Three commitments:

(a) Human in the loop. No solely automated decision producing legal or similarly significant effects is made about any person (GDPR Art 22; POPIA s71). Ranking is a shortlist for a human; outreach requires human approval; booking a time the candidate chose is automatic (see §8); hiring decisions are made by the recruiting organisation.

(b) Fairness. Ranking uses professional evidence only. B-BBEE status, employment-equity status and other protected characteristics (race, gender, disability) are never a search term, filter or ranking criterion. When a brief asks for one, Aria takes it out of the search, tells the recruiter once (“Aria can't search on B-BBEE or employment-equity status, so I left it out of the search. Check it with candidates directly.”) and runs the rest of the search. A job title is left as written: a brief for a B-BBEE Verification Analyst is searched as that job. More on our trust page. Search ratings are tested on every code change by a name test, which checks that swapping or removing a candidate’s name does not change them.

(c) Model providers. AI processing uses Anthropic (language models), OpenAI (embeddings; audio transcription), Deepgram (dictation) and Perplexity (professional-evidence verification). Personal information sent to these processors is used to provide the Service and is not used by them to train their models under our agreements. Untrusted content (for example inbound emails and CV text) is processed with technical safeguards that prevent it acting as instructions to the AI.

6. Sharing and sub-processors

We don’t sell candidate data to third parties. Recruiters who use Ask Aria pay to reveal contact details that a candidate chose to share with them. For anyone else, a reveal looks the email address or phone number up from ContactOut or Apollo for that recruiter. Apart from a reveal and an agency engagement (§7), personal information is shared only with the sub-processors needed to run the Service:

Sub-processorPurposeLocation
SupabaseDatabase, authentication, functions hostingEU / US
CloudflareWeb hosting and deliveryGlobal edge, EU/US
AnthropicAI language modelsUS
OpenAIEmbeddings, transcriptionUS
DeepgramVoice dictationUS
PerplexityProfessional-evidence verificationUS
Tavily, BraveWeb search used for public professional evidenceUS
ApolloB2B professional data and contact revealUS
ContactOutProfessional data and contact revealUS
SendGrid (Twilio)Email sending and inbound parsingUS
Google / MicrosoftCalendar, email sending for connected mailboxesPer user’s own tenant
StripePaymentsUS / EU
SkribbyMeeting bot/recording where usedEU

Cross-border transfers rely on POPIA section 72 (adequate protection via contract) and GDPR Chapter V safeguards (adequacy or Standard Contractual Clauses) with each sub-processor.

7. Agency consultants and shared access

A customer can bring in a recruitment agency to work inside their own workspace. While that engagement is active, the one consultant the agency assigns to it can read part of the customer’s workspace from the agency’s own account, so that they can recruit on the customer’s behalf. What they can read is: the candidates they add to that workspace and the CVs they upload with them; the applications they create there; the job records and JD drafts held in the workspace; and every bulk CV upload in the workspace, including the name, email address and phone number read from each uploaded CV. Candidate records the customer created themselves stay with the customer, together with the CVs attached to those records, the customer’s own applications, and their meeting records and transcripts.

The customer decides whether any of this happens. An engagement begins only when someone at the customer accepts it, and the acceptance screen sets out what it grants before they do. The customer can pause or end the engagement at any time. Access is tied to an active engagement and to that one assigned consultant, and it is enforced in the database on every read, so ending the engagement ends the consultant’s access to the workspace at once. Work the agency holds in its own workspace, such as a candidate it sourced, stays with the agency.

The customer remains the responsible party (POPIA) / controller (GDPR) for the personal information in their workspace. For that engagement the agency and its assigned consultant act as an operator/processor on the customer’s instructions, in the same role AiR holds under §1, with the duties that follow from it: use the information only to recruit for that customer, keep it secure, do not process it for another customer or for their own purposes, and pass on any request for access, correction, objection or deletion so that the customer can honour it under §11. This is a disclosure to another organisation using the Service rather than to one of the sub-processors in §6, and it happens only where the customer has an engagement in place.

8. Google user data

Connecting a Google account is optional and the Service works without it. If you do connect one, this section is the detail behind the Google account access summary on our homepage. It describes every permission we request, why we request it, and what we do and do not do with what we receive. The scopes below are the complete set — we request nothing else.

Permission (OAuth scope)What it gives usWhy we need it
userinfo.email
userinfo.profile
The email address and basic profile of the account you connect.To show you which account is connected and to send calendar invitations and email from the correct identity.
calendar.eventsYour calendar’s busy times, and the ability to create and update the interview events we book for you. This is the events-only permission: it does not allow creating, deleting or managing calendars themselves.To offer candidates times you are genuinely free, and to place the booking in your calendar. We write only events we are booking on your behalf.
meetings.space.createdCreation of a Google Meet link for a meeting we created.So a booked interview carries a working video link.
gmail.sendSending email as you. It confers no ability to read, search, download or delete anything in your mailbox.So candidate outreach comes from your own address rather than a system sender. Outreach is sent only after you have reviewed and approved it. Booking emails are the exception: when a candidate replies with times that suit them, we email the candidate a confirmation of the booking from this address without a further step from you. This is requested on a separate consent screen, so connecting a calendar alone never asks for it.

Limited Use. Ask Aria’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we do not use Google user data to develop, improve or train generalised artificial-intelligence or machine-learning models; we do not transfer it except as necessary to provide or improve the Service, to comply with applicable law, or as part of a merger or acquisition with notice; we do not sell it; and we do not use it for advertising, ad targeting, credit assessment or lending purposes. We allow humans to read Google user data only where you have given us explicit permission for a specific purpose, where it is necessary for security or to comply with applicable law, or where the data has been aggregated and de-identified.

What we never do. We do not request Gmail read access, so we cannot open, search or store the mail already in your mailbox. Calendar availability is processed only to select a time and compose the invitation — where that processing involves our AI sub-processor (see §6), it is to perform the scheduling you asked for and never to train any model.

What Aria sends without a further step from you. Candidate outreach is sent only after a person on your team has reviewed and approved it. Booking is automatic. When a candidate replies with times that suit them, Aria books the slot in your calendar, your calendar sends the candidate the calendar invite, and Aria emails the candidate a confirmation. The confirmation comes from your connected mailbox, or from our system address ([email protected]) if your mailbox can’t send. If a reply to the times you offered is unclear, Aria emails the candidate from your connected mailbox to check which one they meant, and books only once they confirm.

Storage, retention and revocation. Google access and refresh tokens are held encrypted in a secrets vault, never in application tables (see §10). We retain the minimum needed to operate the connection: the connected account’s address, the timezone your browser reports when you connect (we no longer read your Google calendar settings), and identifiers for the events we created, kept for the life of the connection. You can revoke access at any time by disconnecting Google in Settings, or from your Google account permissions. Disconnecting deletes the stored tokens immediately; meetings already in your calendar remain yours and are unaffected. Google user data is deleted when the connection is removed or the workspace is deleted, whichever comes first, subject to the export window in §9.

9. Retention

Account and billing data: for the life of the account plus statutory retention periods. Voice dictation billing records (when you dictated and for how long): 13 months, then deleted. Sourced candidate records: subject to a defined retention period with automated purge; verification refreshes extend retention only while the record remains in active recruitment use. Outreach history: retained to honour contact-frequency protections (we warn before re-contacting anyone approached in the previous 60 days). Deleted workspaces are erased after the 30-day export window.

Being kept on file

When a candidate picks interview times, the time picker may offer an unticked box: “Keep me on file at [the recruiting organisation] for similar roles. You can withdraw any time.” Nothing changes unless the candidate ticks it. Ticking it is consent (POPIA s11(1)(a); GDPR Art 6(1)(a)) for that one organisation to keep the candidate’s professional profile for up to 12 months and contact them about roles like the one in front of them. No other organisation using the Service can see it. The same screen says where the profile came from, for example a public professional profile found through ContactOut or Apollo, or the Ask Aria talent pool.

We record when the box was ticked, on which page, and the exact words shown with their version, because the recruiting organisation has to be able to prove the consent. Being on file never changes how a person is rated or ranked. To withdraw, the candidate opens the personal rights link (our candidate-sar page) that comes with our emails to candidates about a role (outreach, interview invitations, availability requests, booking confirmations, cancellations and recruiter messages) and with the time picker. Withdrawing takes effect at once, including on the recruiting organisation’s candidate cards, and does not change talent pool membership. After withdrawal the profile goes back to the ordinary retention period above and is deleted when that ends, and the candidate can ask for deletion straight away instead. When the candidate withdraws, we delete the record of the consent at once. If the consent runs out, we delete the record at our next daily clean-up.

Joining the Ask Aria talent pool

Job seekers can join the Ask Aria talent pool on our join page. For the pool, AiR Talent Group Ltd is the responsible party (POPIA) / controller (GDPR): we collect the details on our own page, for our own purpose. We ask for your name, email address, phone number, city, salary expectation, notice period, the roles you want, your CV and, if you choose, your LinkedIn profile. The form never asks for race, gender, disability, B-BBEE or employment-equity status, an ID number or your age, and if the free text mentions B-BBEE or equity status we take it out before it can be searched.

Joining is consent (POPIA s11(1)(a); GDPR Art 6(1)(a)), given by ticking an unticked box that says recruitment agencies and employers using Ask Aria can search your profile and see a preview of your CV with your contact details hidden, and that a recruiter who pays to reveal your contact details can also see your full CV and may contact you about roles. People who joined under the first version of the box, which said only that your profile and CV would be searchable, get the preview but not the full CV until they renew or join again. We record the exact words and their version, when you ticked it, on which page, and a keyed hash of your IP address (not the address itself). When we delete your profile, we keep that record without your email address. It holds only a fingerprint of the address made with a secret key, so we can find and delete it if you ask. Nothing is searchable until you click the link we email you to confirm; a sign-up nobody confirms is deleted, with its CV, after 7 days.

Once you confirm, our AI model provider reads your CV once to list your job titles, employers, skills, dates, qualifications and languages, and those details are searched and rated by the same rules as every other candidate, with no boost or penalty for joining. Every organisation using Ask Aria can find you. A card shows your name, current role, city, the roles you want, your salary expectation and notice period, and the date you joined. Your email address and phone number are shown only when a recruiter pays for a reveal, which is the same paid reveal used for every candidate on Ask Aria; we never show them before that, on any screen, in Slack or in an export. Before a reveal, a recruiter whose search found you can read your CV with your email address, phone number and street address taken out, along with any ID or passport number, date of birth, and lines about gender, race, marital status, health or disability; your LinkedIn link stays. If we can’t take those details out with confidence, we show no preview. Your CV file stays in private storage: after a recruiter pays for the email reveal, only the organisation that paid can open the original file, through a link that works for five minutes. We log each time an organisation looks at your CV, and your access request lists which organisations did.

We keep your profile for 12 months from the day you confirm. Then we take it out of search and email you a link to renew; if you don’t renew within 30 days, we delete your profile and your CV. Every email we send you carries your personal rights link: from it you can see what we hold, withdraw (you leave every search at once, and we delete your profile and CV at our next daily clean-up) or ask us to delete everything straight away. The rights link in an email from a recruiter who uses Ask Aria also lets you leave the pool. A recruiter who revealed your details before you left keeps the copy in their own workspace, under their own retention and your rights against them.

10. Security

Safeguards (POPIA s19) include: encryption in transit; row-level security isolating every workspace at the database layer; OAuth tokens held in a secrets vault, never in application tables; least-privilege service access; audit logging of AI tool actions; automated dependency health monitoring; and documented breach response. In the event of a notifiable breach we will notify the Information Regulator / relevant supervisory authority and affected parties as required by POPIA s22 and GDPR Arts 33–34.

11. Your rights

Any data subject (user, candidate, hiring manager, referee) may: request access to their information (we provide a structured subject-access export); request correction; object to processing, including to any further recruitment contact; request deletion (erasure cascades through search records, including merged duplicates); and lodge a complaint with the Information Regulator (South Africa) — inforeg.org.za — or, for GDPR matters, their supervisory authority (in the UK, the ICO). Requests: [email protected], or the unsubscribe/object mechanism in any email we send. Our emails to candidates about a role carry a personal rights link that opens the request page for that person and that organisation, so there is nothing to look up first. We respond within 30 days.

12. Cookies, children, changes

The Service uses only strictly necessary cookies/storage for authentication and session state; there is no advertising or cross-site tracking. The Service is not directed at children and we do not knowingly process children’s information. Material changes to this policy will be notified in-product and take effect no sooner than 30 days after notice.

Version 1.4 · effective 8 October 2026 (describes paid use as usage, with the same meaning; version 1.3 was effective 7 October 2026 and corrected sections 5(a) and 8 to say that Aria books a time a candidate chose, and emails them the confirmation, without a further step from the recruiter; version 1.2 was effective 7 October 2026, corrected section 5(b) to say what Aria does with a brief that mentions B-BBEE, employment equity or another protected characteristic, said plainly in section 6 what a paid reveal is, and added “Being kept on file” and “Joining the Ask Aria talent pool” to section 9; version 1.1 was effective 22 September 2026 and added section 7 on agency consultants and shared access; version 1.0 was effective 3 August 2026). See also the Terms of Service.