Legal · Effective 3 August 2026

Privacy Policy

How personal information is processed on Ask Aria, in compliance with the Protection of Personal Information Act 4 of 2013 (POPIA), the EU/UK General Data Protection Regulation (GDPR), and applicable law.

Terms of Service

AiR Talent Group Ltd
Company number 15462267
5 Alderdale Road, Stockport, SK8 5PP, United Kingdom
Information Officer: Joseph Entwisle — [email protected]

1. Who is responsible

AiR Talent Group Ltd is the responsible party (POPIA) / controller (GDPR) for platform data — your account, billing, usage metering, and the operation of the Service. For candidate and hiring-manager information processed inside a customer workspace, the customer is the responsible party/controller and AiR processes it as their operator/processor on their instructions.

2. Whose data, and what data

Data subjectsWhat we process
Platform usersName, work email, organisation, account type, sign-in events, settings (signature, brand assets), support messages, billing records, credit balance and usage ledger, and your acceptance of these terms (time and version).
CandidatesName, professional profile information (title, employer, work history, skills, location, public profile URLs), contact details where revealed (personal email for candidate outreach), outreach history, replies, availability, interview records, screening and reference responses, recruiter ratings.
Hiring managersName, title, company, public profile URL, work contact details where revealed, outreach history.
RefereesName, contact details, reference responses they submit.

We do not intentionally collect special-category / special personal information, and the Service must not be used to process it as search or ranking criteria.

3. Where candidate data comes from

Candidate and hiring-manager information is collected from: (a) information the customer uploads (CVs, lists); (b) publicly available professional sources (public profiles on LinkedIn, GitHub, Stack Overflow); (c) licensed B2B data providers (currently Apollo and ContactOut) used to verify professional details and, on explicit request, reveal contact details; and (d) the individuals themselves (replies, forms, availability submissions).

Where data is collected from sources other than the individual, POPIA section 18(1) and GDPR Article 14 notice is given at the point of first outreach: our emails identify the sender and the Service, explain why the person is being contacted, and every message allows the person to object, correct their information or ask to be deleted.

4. Purposes and lawful bases

PurposeGDPR basisPOPIA justification
Operating your account, plans, credits and billingContract (Art 6(1)(b))s11(1)(b) contract
Candidate sourcing, ranking and recruitment workflow for a genuine roleLegitimate interests (Art 6(1)(f)) of the recruiting organisation and candidate interest in relevant opportunitiess11(1)(f) legitimate interests
Revealing contact details on user requestLegitimate interests, balanced per requests11(1)(f)
Metering, security, fraud and abuse preventionLegitimate interestss11(1)(f)
Legal compliance (tax, records, requests from regulators)Legal obligation (Art 6(1)(c))s11(1)(c)
Service improvement using aggregated, de-identified usageLegitimate interestss11(1)(f); de-identified data falls outside POPIA

5. AI processing, automated decision-making and fairness

The Service uses AI models to parse briefs, search and rank candidates, verify profile information, draft documents and emails, and transcribe meetings. Three commitments:

(a) Human in the loop. No solely automated decision producing legal or similarly significant effects is made about any person (GDPR Art 22; POPIA s71). Ranking is a shortlist for a human; outreach requires human approval; hiring decisions are made by the recruiting organisation.

(b) Fairness. Ranking uses professional evidence only. Protected characteristics are not used as criteria, and briefs attempting to use them are refused. Ranking outcomes are monitored against a fixed evaluation baseline.

(c) Model providers. AI processing uses Anthropic (language models), OpenAI (embeddings; audio transcription), Deepgram (dictation) and Perplexity (professional-evidence verification). Personal information sent to these processors is used to provide the Service and is not used by them to train their models under our agreements. Untrusted content (for example inbound emails and CV text) is processed with technical safeguards that prevent it acting as instructions to the AI.

6. Sharing and sub-processors

We do not sell personal information. It is shared only with the sub-processors needed to run the Service:

Sub-processorPurposeLocation
SupabaseDatabase, authentication, functions hostingEU / US
CloudflareWeb hosting and deliveryGlobal edge, EU/US
AnthropicAI language modelsUS
OpenAIEmbeddings, transcriptionUS
DeepgramVoice dictationUS
PerplexityProfessional-evidence verificationUS
Tavily, BraveWeb search used for public professional evidenceUS
ApolloB2B professional data and contact revealUS
ContactOutProfessional data and contact revealUS
SendGrid (Twilio)Email sending and inbound parsingUS
Google / MicrosoftCalendar, email sending for connected mailboxesPer user’s own tenant
StripePaymentsUS / EU
SkribbyMeeting bot/recording where usedEU

Cross-border transfers rely on POPIA section 72 (adequate protection via contract) and GDPR Chapter V safeguards (adequacy or Standard Contractual Clauses) with each sub-processor.

7. Google user data

Connecting a Google account is optional and the Service works without it. If you do connect one, this section is the detail behind the Google account access summary on our homepage. It describes every permission we request, why we request it, and what we do and do not do with what we receive. The scopes below are the complete set — we request nothing else.

Permission (OAuth scope)What it gives usWhy we need it
userinfo.email
userinfo.profile
The email address and basic profile of the account you connect.To show you which account is connected and to send calendar invitations and email from the correct identity.
calendar
calendar.events
Your calendar’s busy times, and the ability to create and update the interview events we book for you.To offer candidates times you are genuinely free, and to place the booking in your calendar. We write only events we are booking on your behalf.
meetings.space.createdCreation of a Google Meet link for a meeting we created.So a booked interview carries a working video link.
gmail.sendSending email as you. It confers no ability to read, search, download or delete anything in your mailbox.So candidate outreach comes from your own address rather than a system sender. We send only messages you have reviewed and approved. This is requested on a separate consent screen, so connecting a calendar alone never asks for it.

Limited Use. Ask Aria’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we do not use Google user data to develop, improve or train generalised artificial-intelligence or machine-learning models; we do not transfer it except as necessary to provide or improve the Service, to comply with applicable law, or as part of a merger or acquisition with notice; we do not sell it; and we do not use it for advertising, ad targeting, credit assessment or lending purposes. We allow humans to read Google user data only where you have given us explicit permission for a specific purpose, where it is necessary for security or to comply with applicable law, or where the data has been aggregated and de-identified.

What we never do. We do not request Gmail read access, so we cannot open, search or store the mail already in your mailbox. Calendar availability is processed only to select a time and compose the invitation — where that processing involves our AI sub-processor (see §6), it is to perform the scheduling you asked for and never to train any model. No email is sent and no meeting is booked without a person confirming it first.

Storage, retention and revocation. Google access and refresh tokens are held encrypted in a secrets vault, never in application tables (see §9). We retain the minimum needed to operate the connection: the connected account’s address, its calendar timezone, and identifiers for the events we created, kept for the life of the connection. You can revoke access at any time by disconnecting Google in Settings, or from your Google account permissions. Disconnecting deletes the stored tokens immediately; meetings already in your calendar remain yours and are unaffected. Google user data is deleted when the connection is removed or the workspace is deleted, whichever comes first, subject to the export window in §8.

8. Retention

Account and billing data: for the life of the account plus statutory retention periods. Sourced candidate records: subject to a defined retention period with automated purge; verification refreshes extend retention only while the record remains in active recruitment use. Outreach history: retained to honour contact-frequency protections (we warn before re-contacting anyone approached in the previous 60 days). Deleted workspaces are erased after the 30-day export window.

9. Security

Safeguards (POPIA s19) include: encryption in transit; row-level security isolating every workspace at the database layer; OAuth tokens held in a secrets vault, never in application tables; least-privilege service access; audit logging of AI tool actions; automated dependency health monitoring; and documented breach response. In the event of a notifiable breach we will notify the Information Regulator / relevant supervisory authority and affected parties as required by POPIA s22 and GDPR Arts 33–34.

10. Your rights

Any data subject (user, candidate, hiring manager, referee) may: request access to their information (we provide a structured subject-access export); request correction; object to processing, including to any further recruitment contact; request deletion (erasure cascades through search records, including merged duplicates); and lodge a complaint with the Information Regulator (South Africa) — inforeg.org.za — or, for GDPR matters, their supervisory authority (in the UK, the ICO). Requests: [email protected], or the unsubscribe/object mechanism in any email we send. We respond within 30 days.

11. Cookies, children, changes

The Service uses only strictly necessary cookies/storage for authentication and session state; there is no advertising or cross-site tracking. The Service is not directed at children and we do not knowingly process children’s information. Material changes to this policy will be notified in-product and take effect no sooner than 30 days after notice.

Version 1.0 · effective 3 August 2026. See also the Terms of Service.