Current document
Privacy Policy
This policy explains the data Hiruu needs to provide workforce, hiring and business services, the strict security-only treatment of phone numbers, and the choices and rights available to each user.
- Version
- privacy-2026-07-31
- Effective
- 2026-07-31
Operator and data controller
Hiruu is operated by Christos Papoukas.
For processing activities where Hiruu determines the purposes and means of processing, the data controller is:
- Christos Papoukas
- Trading name: Hiruu
- Registered address: Adroutsou, 551 32 Kalamaria, Thessaloniki, Greece
- Email for privacy, legal and support requests: [email protected]
Employer customers may act as independent controllers for workforce information they enter into Hiruu. Where Hiruu processes that information solely on their instructions, the respective responsibilities will be governed by the customer agreement and Data Processing Agreement.
1. Scope and separate choices
This Privacy Policy applies to the Hiruu mobile apps, website, business dashboard, support channels and the backend services that operate them. Hiruu is a workforce and hiring platform for adults and is not intended for anyone under 18.
Acknowledging this Privacy Policy is separate from accepting the Terms. Optional marketing consent is also separate: declining marketing does not block an account or a Hiruu feature. Device permissions are requested only when a feature needs them and can be changed in device settings.
2. Data we collect
Account, eligibility and security data includes name, email, date of birth, password verifier or sign-in-provider identifier, language, account status, verification records, sessions and security events. Date of birth is used to enforce the 18+ rule.
Profile, work and business data includes profile photos, skills, work preferences, availability, employment and contract details, business profiles, team roles, job listings, applications, schedules, attendance, leave, overtime, shift reports, ratings, badges and rewards.
Communications and safety data includes chat messages, attachments, support conversations, call-session metadata, block relationships, reports about users or content, evidence submitted with a report, moderation decisions, notifications and appeals. Hiruu does not intentionally record call audio or video unless users receive clear notice first.
Files and generated content includes media you upload, documents, generated CV files and their temporary download or preview links. Generated CVs may include profile information that you chose for the CV.
Device, permission and diagnostic data includes app version, platform, build, IP address, security and server logs, crash or diagnostic information, push tokens and the minimum device identifiers needed for integrity checks and notifications. If you choose a relevant feature, the app may request camera, photo or file access, microphone, foreground location, notifications or Android alarm access.
Payment and subscription data includes plan and entitlement state, product identifiers, billing cycle, App Store or Google Play receipts or purchase tokens, and Stripe payment or subscription references for web billing. Hiruu does not store full payment-card numbers.
Accounting and employment records may include tax, payroll and bank fields, business legal details, accountant contact details, generated reports and records that a business must maintain for employment, tax or accounting duties.
Website usage data includes limited first-party hiring-page events such as page view, open-app, job click and store click, together with the business or listing context. Those events are sent without browser credentials and are not used for cross-site advertising. The public CV demo loads Cloudflare Turnstile only after the user asks to generate a demo CV.
3. Why we use data and our legal bases
- To create and secure accounts, verify eligibility and prevent fraud or abuse.
- To provide profiles, hiring, applications, workforce records, schedules, attendance, leave, chat, calls, support, files, CV generation, notifications, payments and subscriptions.
- To moderate reports, enforce the Terms and Community Standards, notify affected users and review appeals.
- To meet employment, tax, accounting, platform, safety and other legal obligations.
- To maintain, debug and improve service reliability using proportionate logs and aggregate or de-identified analysis.
Where EU law applies, the legal basis is performance of the contract, compliance with legal obligations, legitimate interests in security and reliable service, or consent where consent is legally required. Hiruu asks separately for optional marketing consent and optional device permissions.
4. What is shared and what is never shared
Profile, listing, application, schedule, employment and chat information is shared only with the audience needed for the feature. Account owners control what they submit, subject to business and workplace record duties. Accounts that are deleted or pending deletion are excluded from profiles, search, business pages, job pages and other discovery or sharing endpoints.
Phone numbers, authentication secrets, security challenges, push tokens, exact dates of birth, private moderation evidence and internal security data are not public profile fields. Sensitive employment, tax and banking fields are limited to authorized workflows and must not appear in public or general search results.
Hiruu may disclose information when required by law, to protect users and the service, or as part of a corporate transaction subject to appropriate safeguards. Hiruu does not sell personal data or share it for cross-context behavioural advertising.
5. Service providers
Hiruu uses providers only for features that are actually enabled. Depending on the selected feature and deployment, those providers are:
- Apple and Google for sign-in and native app-store purchases.
- Firebase for app security, push notifications and Apple sign-in on the web login.
- Google Identity Services for Google sign-in on the web login.
- Twilio or Prelude for delivery and verification of security codes, according to the configured verification route.
- Agora for live call sessions.
- Cloudinary and Cloudflare R2 for media or file storage, and Cloudflare Turnstile for abuse prevention on the public CV demo.
- Stripe for business web billing and subscription management.
- Contracted email delivery through the configured SMTP service for transactional messages and separately consented marketing.
Providers receive only the data needed for their task and act under their own legally required notices and Hiruu’s contractual safeguards. International transfers use an applicable transfer mechanism where required.
6. Employment-related tools and human review
Ranking, reliability indicators, leaderboards, rewards and scheduling suggestions are support tools. They must not be used as the sole basis for dismissal, refusal of work, discipline, pay reduction or another significant adverse employment decision. Businesses remain responsible for lawful, explainable decisions and meaningful human review.
A user may ask for an explanation, correct inaccurate source data and contest a decision through support or the appeal path. Hiruu reviews employment-impacting automation for unjustified proxy use, disproportionate effects and data minimisation.
7. Retention and deletion
Hiruu keeps personal data only for the feature, security period or legal duty that requires it. Deletion jobs remove expired data and processor copies, while a narrow retention allowlist covers records Hiruu or a business must keep for tax, accounting, payments, employment, fraud, safety, disputes or legal claims.
| Category | Normal treatment |
|---|---|
| Account, profile and job data | Hidden immediately when deletion is requested. Erasure starts immediately; closing a narrow future-shift record or completing a processor retry or manual reconciliation may delay confirmed completion, with a maximum 30-day pending window. |
| Sessions, push tokens and newsletter access | Sessions and push tokens are revoked and newsletter delivery is disabled immediately when deletion is requested. |
| Generated CVs and user media | Removed from active records and queued for processor deletion immediately when deletion is requested. Outside deletion, generated CVs normally expire after 3 days on free plans or 90 days on premium plans. |
| Chat, support and calls | When deletion starts, Hiruu erases the user’s authored message text, mentions, pins and attachments, and deletes read receipts, call participation and call-quality or recording references. Those items are not part of the legal-retention allowlist. |
| Security, access and activity logs | Backend and infrastructure security, access and activity records are pseudonymised and purged after 90 days unless an active legal hold requires a restricted copy. Production release is blocked until every external log sink enforces the same maximum. |
| Processor-deletion evidence | Only the minimum technical evidence needed to confirm or retry a processor deletion is retained. Completed task evidence expires after 90 days; unresolved tasks remain restricted during the maximum 30-day deletion window and are escalated for manual handling. |
| Resolved moderation reports and appeals | Retained for 24 months for safety, consistency and dispute handling, then deleted or irreversibly anonymised. |
| Hiring-page daily aggregates | Credential-free page and action events are aggregated into daily counters when received; no raw event row is retained. Daily aggregates are deleted after 24 months. |
| Newsletter records | Active while subscribed. On unsubscribe or deletion, the contact and user link are cleared; only a non-reversible suppression or consent-proof hash remains for 3 years. |
| Payment, tax and signed-contract records | Minimum legally required fields are retained for 10 years, with identifiers minimised and access restricted. |
| Terms, Privacy and deletion evidence | The exact document version, locale, content hash, choice and timestamp are retained for 6 years after account deletion, then removed by the retention job. Optional marketing evidence follows the separate 3-year period above. |
| Protected backups | Rolling backup copies expire within 35 days. Removed features are not restored; after disaster recovery, deletion records and feature purge migrations run before normal access resumes. |
Hiruu starts verified deletion immediately and keeps the account hidden. Closing a narrow future-shift record or completing a processor retry or manual reconciliation may delay confirmed completion, but never beyond 30 days. The Account Deletion page explains the deletion categories, retained-record allowlist, processor deletion and subscription steps.
8. Your rights and choices
- Ask for access to and a copy of your personal data through the privacy contact. Hiruu verifies the requester and responds through an appropriate secure channel.
- Where the right applies, ask for personal data you provided in a structured, commonly used and machine-readable format, or for transfer to another controller where technically feasible. This request uses the same verified privacy-contact process and does not require a self-service download endpoint.
- Correct inaccurate data and complete incomplete data.
- Request deletion, restriction or objection where the law provides that right.
- Withdraw optional marketing consent at any time without affecting earlier lawful processing.
- Manage app permissions and notification choices in Hiruu and device settings.
- Report users or content, block a user and appeal a moderation decision.
- Complain to the competent data-protection authority.
9. Security, children and changes
Hiruu uses access controls, encrypted transport, secure session handling, least-privilege provider access and monitoring designed to protect personal data. No service can guarantee absolute security; report suspected unauthorized access promptly.
Hiruu is for adults aged 18 or over. Invalid, future and under-18 dates of birth are rejected. If an existing account is found to belong to a person under 18, Hiruu restricts the account from profiles and work features, preserves only the minimum investigation record, verifies the situation and deletes or legally handles the account.
Material policy changes receive a new document ID and effective date. A user may be asked to acknowledge a new Privacy Policy separately from accepting new Terms. Earlier version-addressed documents remain available for acceptance records.