Privacy Policy

Last updated: September 2026

This Privacy Policy explains how Another SaaS EOOD ("PeekHire", "we", "us") collects, uses, shares, and protects personal data in connection with the PeekHire platform and website. We have written this policy in plain language so that anyone — a SaaS customer, a job candidate, or a casual website visitor — can find the part that applies to them.

If you only have a minute, jump to the section that fits your situation: §3 if you have or are creating a PeekHire account; §4 if you are a job candidate who applied (or is about to apply) through a recruiter using PeekHire; §5 if you are simply browsing the website.

1. Who This Notice Covers

PeekHire is used by three groups of people, and our role under data-protection law differs for each:

You are…Our role
A SaaS customer (an account holder, recruiter, or team member working under an account)Controller of your account, billing, and usage data
A job candidate submitting an application through our Apply toolThe recruiter is the Controller of your application; we act as a Processor on the recruiter's behalf, with narrow Controller activities listed in §7
A website visitor browsing peekhire.ioController of the limited browsing, analytics, and cookie data described in §5

This single notice covers all three. Where a section is relevant only to one group, we say so at the top.

2. Controller and Contact

The data controller for the purposes of the EU and UK General Data Protection Regulation (GDPR) is:

Another SaaS EOOD Alabin Street 33, Floor 3, Office 318 1000 Sofia, Bulgaria Unified Identification Code (UIC): 207282077

For any data-protection request — access, deletion, correction, complaints, or general questions — email us at [email protected]. We have not appointed a statutory Data Protection Officer because we are not legally required to; the email above reaches the people who handle privacy requests.

3. Data We Collect From SaaS Customers

When you create or use a PeekHire account, we collect:

Account data — Your name, email address, company name, and job title at registration. We need this to create your account, authenticate you, and contact you about the service.

Sign-in data — If you sign in with Google or Microsoft, the provider sends us your name, your email address, whether it has confirmed that the address is yours, and a stable account identifier (for Microsoft accounts also the identifier of your organisation's directory). If you sign in through your employer's single sign-on (SAML), your employer's identity provider sends us your email address, your name and an account identifier; if your employer uses automatic user provisioning (SCIM), it creates, updates and deactivates your PeekHire account on its own instruction. We use this data only to create your account and sign you in, which is necessary to provide the service you asked for (Art. 6(1)(b) GDPR). We never receive your password, and we do not access your emails, contacts, files or any other data in your Google or Microsoft account. PeekHire's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Usage data — How you use the platform: campaigns you create, searches you run, idea-validation results you view, features you interact with, and session metadata. We use this to operate, debug, and improve the service.

Payment data — If you subscribe to a paid plan, our payment provider Stripe, Inc. handles your billing address and payment method on its own infrastructure. We never store full card numbers; we receive only the metadata Stripe sends us (last four digits, brand, expiry, country) to display invoices and renewal information.

Communication data — When you email us or use in-app support, we keep your messages so we can respond and so we can refer back if the issue recurs.

Technical data — IP address, browser type, operating system, and access timestamps are recorded automatically by our servers for security, abuse-prevention, and operational purposes.

4. Data We Collect From Job Candidates via Apply

If you reach a PeekHire-powered application page (a URL containing /c/<slug> or hosted by a recruiter who uses PeekHire), the recruiter — not PeekHire — decides what to ask you and what to do with your answers. PeekHire only processes the data on the recruiter's behalf, as their Processor. The categories we touch are:

Application content — Your name (always required), your email (the recruiter configures whether it is required, optional, or hidden entirely), and your response in the format the recruiter allows (video, audio, or text). For media responses we also receive technical metadata: response duration, MIME type, and the temporary upload reference. A short receipt token is generated so you can return to a confirmation page after submission.

Spam-prevention signals — When you submit, your browser may obtain a Google reCAPTCHA token, which we forward to Google together with limited technical signals (IP address, browser data) to detect automated abuse. Google's privacy policy applies to that processing.

Consent records — We keep a record that you ticked the consent boxes in the submission modal (processing of your application, the recruiter's own privacy notice where applicable, and this platform Privacy Policy). This is required so we — and the recruiter — can demonstrate the legal basis for processing.

The recruiter's own questions and any data you choose to provide in your answers — A recruiter may ask you to share things we cannot anticipate (work experience, portfolio links, opinions on a hypothetical, etc.). What you say in your answer becomes part of your submission. Whether the recruiter is allowed to ask any particular question, and how they handle your answer, is governed by the recruiter's privacy notice, not by ours. Read it before you submit.

We do not ask for, and recruiters should not solicit through PeekHire, special-category data under GDPR Article 9 (health, religion, sexual orientation, biometric or genetic data, etc.). If a recruiter's campaign appears to do so, please report it to [email protected].

5. Data We Collect From Website Visitors

When you visit peekhire.io we automatically collect:

  • IP address, user-agent, language preference, country derived from IP
  • Pages you visit, referrer, time on page
  • Cookies as described in §10

We use this for security, accessibility, troubleshooting, and — where you have given consent — aggregated analytics about how the site is used.

We process personal data for the following purposes and on the following legal bases under GDPR Article 6:

PurposeLegal basis
Providing and operating the PeekHire service to account holdersArt. 6(1)(b) — performance of a contract
Account management, authentication, and customer supportArt. 6(1)(b) — performance of a contract
Processing subscription paymentsArt. 6(1)(b) — performance of a contract
Operating the Apply submission flow (storage, playback, delivery to recruiter)Art. 6(1)(b) — performance of a contract with the recruiter (Processor activities)
Sending service-related notificationsArt. 6(1)(b) — performance of a contract
Spam, fraud, and abuse prevention (including reCAPTCHA)Art. 6(1)(f) — legitimate interests
Improving and developing the platformArt. 6(1)(f) — legitimate interests
Producing aggregated, de-identified analyticsArt. 6(1)(f) — legitimate interests
Marketing communications to existing customers about similar servicesArt. 6(1)(f) — legitimate interests (opt-out available)
Marketing to prospects and non-essential cookiesArt. 6(1)(a) — consent
Complying with court orders, lawful requests, and tax obligationsArt. 6(1)(c) — legal obligation

For candidate application content, the recruiter is responsible for selecting and documenting the legal basis (typically Art. 6(1)(b) — pre-contractual steps at the candidate's request, or Art. 6(1)(a) — consent). We process that data only on the recruiter's instructions under the contract we have with them.

7. The Recruiter–Platform Relationship for Candidate Data

This section matters most for job candidates. We separate two roles:

The recruiter is the Controller. The recruiter — the company or individual who set up the campaign you applied to — decides what to ask, who in their organisation sees your response, how long they keep it, whether they shortlist you, and whether they make a hiring decision. Their own privacy notice (which you can read before submitting; the recruiter is required to provide it for any application that collects personal data) governs those substantive choices.

PeekHire is the Processor. We process your submission strictly as the recruiter instructs us: we host the recording, deliver it to the recruiter's account, optionally transcribe or summarise it where the recruiter has enabled AI features (see §13), and apply the retention period the recruiter has set. We do not use your application content for our own purposes, do not sell it, and do not allow third parties (including our AI providers) to train their models on it. Our obligations as Processor are documented in our standard Data Processing Addendum (DPA), available on request.

PeekHire is also a (narrow) Controller for candidate data, for activities that are necessary for us to run the platform safely even though the recruiter did not specifically instruct them: securing the Apply infrastructure, preventing fraud and abuse, producing aggregated and de-identified analytics, and complying with our own legal obligations. We have a legitimate interest in these activities under Art. 6(1)(f).

If you want to exercise a data-subject right (access, deletion, correction, objection, withdrawal of consent, etc.) over your application data, please contact the recruiter first — they hold the substantive responsibility. If you cannot reach them, contact us at [email protected] and we will help route the request or, where we are independently a Controller, respond ourselves.

8. Third-Party Services (Sub-Processors)

We use the following categories of service providers, each bound by a written data-processing agreement and (where applicable) the EU Standard Contractual Clauses. The list is updated when underlying tooling stabilises; an up-to-date list is available on request.

Payment processing — Stripe, Inc. (United States) and its affiliates handle subscription billing. See stripe.com/privacy.

Cloud infrastructure and object storage — A leading cloud infrastructure provider hosts our servers, databases, and object storage (where candidate media is stored unless the recruiter uses their own bucket, in which case the recruiter selects the location and provider). Server logs and stored media live on that infrastructure.

Email and transactional messaging — A transactional email provider sends account, billing, and notification emails on our behalf.

Spam protection — Google reCAPTCHA (operated by Google Ireland Limited in the EEA and by Google LLC outside the EEA) helps us tell humans from bots on the Apply submission flow. See policies.google.com/privacy.

AI processing — Where the recruiter has enabled AI features (such as transcription, summarisation, or scoring assistance for candidate responses) we send the necessary content to AI service providers under contracts that prohibit them from training their models on customer or candidate content. Where AI features are not enabled, no such transfer occurs.

Analytics — A privacy-aware website analytics provider helps us understand aggregated usage of peekhire.io. No advertising identifiers are set without consent.

We do not sell, rent, or otherwise share your personal data with third parties for their own marketing purposes.

9. International Data Transfers

We are based in the European Union and we strongly prefer keeping personal data in the EEA. However, because some of our sub-processors and some of our customers are outside the EEA, your personal data may be transferred to and processed in countries that the European Commission has not formally found to provide an adequate level of protection — including the United States.

Where that happens, the transfer is protected by one or more of the following safeguards:

  • EU Standard Contractual Clauses (Commission Decision (EU) 2021/914) with the receiving party
  • UK International Data Transfer Addendum for transfers under the UK GDPR
  • Adequacy decisions where they exist (United Kingdom, Switzerland, Japan, EU–US Data Privacy Framework participants, etc.)
  • Supplementary measures including encryption in transit (TLS 1.2 or higher) and at rest, strict access controls, audit logging, and pseudonymisation where practical

You can request a copy of the Standard Contractual Clauses that apply to a specific transfer by emailing [email protected]. We may redact commercial terms.

10. Cookies and Similar Technologies

We use two kinds of cookies and similar technologies:

Strictly necessary — sign-in sessions, CSRF tokens, load-balancer affinity, and security cookies. These are required for the site to work; they operate under Art. 6(1)(b) (contract) or Art. 6(1)(f) (legitimate interest in providing a secure service) and do not require consent.

Optional — analytics and product-improvement cookies. These run only after you have given consent through the cookie preference control on the site. You can withdraw consent at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal.

We do not set advertising cookies and we do not allow third-party advertisers to set them through our pages.

11. Retention

We keep personal data for as long as we need it, and no longer:

  • Account data — for the lifetime of the account; deleted within 90 days after account closure, except where law requires us to retain a record longer.
  • Usage data (customers) — up to 24 months in identifiable form; thereafter only in aggregated, de-identified form.
  • Payment records — 10 years to meet Bulgarian tax and accounting obligations.
  • Server logs — 30 days, unless retained longer for a specific security investigation.
  • Email correspondence — for the duration of the business relationship plus a reasonable administrative period.
  • Candidate submissions — retained per the recruiter's instructions. Our default, unless the recruiter sets a shorter period, is up to 24 months from submission, after which the content is deleted from systems we control. If you want your submission deleted sooner, contact the recruiter first; we will assist on request.
  • Anti-fraud signals (reCAPTCHA tokens, IPs linked to security events) — up to 90 days.
  • Cookies — lifetime varies by cookie; check the cookie preference control for current durations.

12. Your Rights

The rights available to you depend on where you live. We honour the strongest applicable standard.

If you are in the EEA, the United Kingdom, or Switzerland, the GDPR (or equivalent local law) gives you:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure — request deletion, subject to legal retention obligations
  • Right to restriction — limit how we process your data in certain circumstances
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Right to withdraw consent — at any time, for processing that relies on consent
  • Right not to be subject to a solely automated decision producing legal or similarly significant effects (see §13)

If you are in California, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to know, the right to delete, the right to correct, the right to opt out of "sale" or "sharing" of personal information, and the right not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA.

If you are elsewhere — including Brazil (LGPD), Switzerland (revFADP), South Korea (PIPA), Singapore (PDPA), Australia (Privacy Act), or any other jurisdiction with a comprehensive privacy law — you have substantially the same rights of access, correction, deletion, objection, and complaint to your local authority. Contact us at [email protected] and we will treat your request under the most protective applicable standard.

For candidate application data, route your request to the recruiter (the Controller) first. We will acknowledge any request we receive within 30 days, even if the substantive response has to come from the recruiter, and we will help you find the right contact.

13. Automated Decision-Making and AI

PeekHire does not make solely automated decisions that produce legal or similarly significant effects on candidates. Where a recruiter enables AI-assisted features such as transcription, summarisation, or scoring of candidate responses, those outputs are decision-support only: a human at the recruiter is responsible for reviewing them and making the actual hiring decision.

Recruiters using AI features in PeekHire remain responsible for their compliance with Article 22 GDPR and with the EU Artificial Intelligence Act, including its obligations for high-risk AI systems used in employment contexts (recruitment, selection, evaluation). We provide controls and information to help recruiters meet those obligations, but the legal responsibility for the hiring decision sits with them.

We do not allow our AI service providers to train their models on customer or candidate content.

14. Children

PeekHire is a business tool. The service is not directed at children, and we do not knowingly collect personal data from anyone under 16 years of age (under 13 in the United States, where COPPA applies). If you believe a child has provided personal data through PeekHire, please contact us so we can delete it.

15. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, and destruction:

  • All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher
  • Stored data — including candidate media — is encrypted at rest by our cloud providers
  • Access to personal data within our organisation is restricted on a need-to-know basis and logged
  • Authentication uses industry-standard practices including password hashing and, where available, multi-factor authentication
  • We maintain audit logging, vulnerability scanning, and a documented incident-response plan
  • Where the GDPR applies, we will notify the competent supervisory authority of a personal-data breach within 72 hours of becoming aware, and notify affected individuals where required

No method of transmission over the internet or electronic storage is 100% secure. We strive to use commercially reasonable means to protect your data but cannot guarantee absolute security.

16. Supervisory Authority

You have the right to lodge a complaint with a data-protection supervisory authority. Because Another SaaS EOOD is established in Bulgaria, the lead supervisory authority under the GDPR's one-stop-shop mechanism is:

Commission for Personal Data Protection (CPDP) — Lead Supervisory Authority 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria Website: cpdp.bg

You may also lodge a complaint with the supervisory authority in your country of residence. The lead authority and the local authority cooperate under GDPR procedures. For example, users in Germany may contact:

Federal Commissioner for Data Protection and Freedom of Information (BfDI) Website: bfdi.bund.de

Candidates and customers outside the EEA may also have a right to complain to their local data-protection authority or equivalent regulator.

17. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes that affect account holders, we will notify you by email at least 30 days in advance where feasible. For candidates, the version of the policy in effect at the time of your submission governs that submission.

The date at the top of this policy indicates when it was last revised.

18. Contact

For any privacy-related question or to exercise a data-subject right:

Another SaaS EOOD Alabin Street 33, Floor 3, Office 318 1000 Sofia, Bulgaria Email: [email protected]