Current document

Privacy Policy

This policy explains the data Hiruu needs to provide workforce, hiring and business services, the strict security-only treatment of phone numbers, and the choices and rights available to each user.

Version
privacy-2026-09-16
Effective
2026-09-16

Operator and data controller

Hiruu is operated by Christos Papoukas.

For processing activities where Hiruu determines the purposes and means of processing, the data controller is:

  • Christos Papoukas
  • Trading name: Hiruu
  • Registered address: Adroutsou, 551 32 Kalamaria, Thessaloniki, Greece
  • Email for privacy, legal and support requests: [email protected]

Employer customers may act as independent controllers for workforce information they enter into Hiruu. Where Hiruu processes that information solely on their instructions, the respective responsibilities will be governed by the customer agreement and Data Processing Agreement.

1. Scope and separate choices

This Privacy Policy applies to the Hiruu mobile apps, website, business dashboard, support channels and the backend services that operate them. Hiruu is a workforce and hiring platform for adults and is not intended for anyone under 18.

At signup, one clear action may accept the Terms and acknowledge this Privacy Policy, with both documents linked. Hiruu records the Terms acceptance and Privacy acknowledgement as separate evidence, including each document version, locale and timestamp. This acknowledgement is not consent to optional marketing. Marketing remains optional, is managed separately after signup, and declining or withdrawing it does not block an account or feature. Device permissions are requested only when a feature needs them and can be changed in device settings.

2. Data we collect

Account, eligibility and security data includes name, email, password verifier or sign-in-provider identifier, language, account status, verification records, sessions and security events. Initial account registration does not collect a date of birth. Before normal account features become available, mandatory onboarding asks the user to submit a date of birth only to calculate whether the user is 18 or over. After that check, Hiruu retains the adult-eligibility confirmation, time and method, not the submitted date of birth.

Profile, work and business data includes profile photos, skills, work preferences, availability, employment and contract details, business profiles, team roles, job listings, applications, schedules, attendance, leave, overtime, shift reports, ratings, badges and rewards.

Communications and safety data includes chat messages, attachments, support conversations, call-session metadata, block relationships, reports about users or content, evidence submitted with a report, moderation decisions, notifications and appeals. Hiruu does not intentionally record call audio or video unless users receive clear notice first.

Files and generated content includes media you upload, documents, generated CV files and their temporary download or preview links. Generated CVs may include profile information that you chose for the CV.

Device, permission and diagnostic data includes app version, platform, build, IP address, security and server logs, crash or diagnostic information, push tokens and the minimum device identifiers needed for integrity checks and notifications. If you choose a relevant feature, the app may request camera, photo or file access, microphone, foreground location, notifications or Android alarm access.

Payment and subscription data includes plan and entitlement state, product identifiers, billing cycle, App Store or Google Play receipts or purchase tokens, and Stripe payment or subscription references for web billing. Hiruu does not store full payment-card numbers.

Accounting and employment records may include tax, payroll and bank fields, business legal details, accountant contact details, generated reports and records that a business must maintain for employment, tax or accounting duties.

Website usage data includes limited first-party hiring-page events such as page view, open-app, job click and store click, together with the business or listing context. Those events are sent without browser credentials and are not used for cross-site advertising. The public CV demo loads Cloudflare Turnstile only after the user asks to generate a demo CV.

3. Why we use data and our legal bases

  • To create and secure accounts, verify eligibility and prevent fraud or abuse.
  • To provide profiles, hiring, applications, workforce records, schedules, attendance, leave, chat, calls, support, files, CV generation, notifications, payments and subscriptions.
  • To moderate reports, enforce the Terms and Community Standards, notify affected users and review appeals.
  • To meet employment, tax, accounting, platform, safety and other legal obligations.
  • To maintain, debug and improve service reliability using proportionate logs and aggregate or de-identified analysis.

Where EU law applies, the legal basis is performance of the contract, compliance with legal obligations, legitimate interests in security and reliable service, or consent where consent is legally required. Hiruu asks separately for optional marketing consent and optional device permissions.

4. What is shared and what is never shared

Profile, listing, application, schedule, employment and chat information is shared only with the audience needed for the feature. Account owners control what they submit, subject to business and workplace record duties. Accounts that are deleted or pending deletion are excluded from profiles, search, business pages, job pages and other discovery or sharing endpoints.

Phone numbers, authentication secrets, security challenges, push tokens, exact dates of birth, private moderation evidence and internal security data are not public profile fields. Sensitive employment, tax and banking fields are limited to authorized workflows and must not appear in public or general search results.

Hiruu may disclose information when required by law, to protect users and the service, or as part of a corporate transaction subject to appropriate safeguards. Hiruu does not sell personal data or share it for cross-context behavioural advertising.

5. Service providers

Hiruu uses providers only for features that are actually enabled. Depending on the selected feature and deployment, those providers are:

  • Apple and Google for sign-in and native app-store purchases.
  • Firebase for app security, push notifications and Apple sign-in on the web login.
  • Google Identity Services for Google sign-in on the web login.
  • Twilio or Prelude for delivery and verification of security codes, according to the configured verification route.
  • Agora for live call sessions.
  • Cloudinary and Cloudflare R2 for media or file storage, and Cloudflare Turnstile for abuse prevention on the public CV demo.
  • Stripe for business web billing and subscription management.
  • Contracted email delivery through the configured SMTP service for transactional messages and separately consented marketing.

Providers receive only the data needed for their task and act under their own legally required notices and Hiruu’s contractual safeguards. International transfers use an applicable transfer mechanism where required.

6. Employment-related tools and human review

Ranking, reliability indicators, leaderboards, rewards and scheduling suggestions are support tools. They must not be used as the sole basis for dismissal, refusal of work, discipline, pay reduction or another significant adverse employment decision. Businesses remain responsible for lawful, explainable decisions and meaningful human review.

A user may ask for an explanation, correct inaccurate source data and contest a decision through support or the appeal path. Hiruu reviews employment-impacting automation for unjustified proxy use, disproportionate effects and data minimisation.

7. Retention and deletion

We retain only data needed for a documented legal obligation, legal claim or other continuing lawful purpose, with restricted access and a defined expiry. Business ownership alone is not an exemption from erasure. The Privacy Policy lists the category schedules; you may ask which records remain, the reason, responsible controller and expected expiry. Account deletion and erasure of independently controlled employer records are separate requests, and we assist with the latter where applicable.

CategoryNormal treatment
Account, profile and job dataHidden when a verified deletion request is accepted. Permanent erasure starts promptly, unless you choose the optional 7-day recovery period. A future shift does not require retaining your Hiruu account.
Sessions, push tokens and newsletter accessMarketing and push delivery stop on request. Other sessions are revoked. During recovery, only deletion status, identity verification, cancellation and starting erasure are available; a limited session may support these actions. All account sessions are revoked when erasure starts.
Generated CVs and user mediaRemoved from active records and queued for provider deletion when permanent erasure starts. Outside account deletion, generated CVs normally expire after 3 days on free plans or 90 days on premium plans.
Chat, support and callsWhen deletion starts, Hiruu erases the user’s authored message text, mentions, pins and attachments, and deletes read receipts, call participation and call-quality or recording references. Those items are not part of the legal-retention allowlist.
Security, access and activity logsOrdinary security, access and activity records have a 90-day retention limit. A documented legal hold may require a restricted copy for longer; it does not keep the account active.
Processor-deletion evidenceMinimum references are kept until provider deletion is verified. Failures are retried and overdue or unresolvable tasks are escalated for manual action. An unresolved case remains open and restricted; completed task evidence is removed after 90 days.
Resolved moderation reports and appealsRetained for 24 months for safety, consistency and dispute handling, then deleted or irreversibly anonymised.
Hiring-page daily aggregatesCredential-free page and action events are aggregated into daily counters when received; no raw event row is retained. Daily aggregates are deleted after 24 months.
Newsletter recordsDelivery stops on request. Subscriber contact data is removed and limited suppression or consent evidence is retained for 3 years. A suppression hash is pseudonymous data, not a guarantee of irreversible anonymisation.
Payment, tax and signed-contract recordsAccount deletion does not resign from a job, terminate a contract, cancel agreed shifts or erase an employer's independently necessary records. Account links and access are removed. Necessary workforce records remain available to the authorised business while required for the employment relationship, then follow the applicable retention schedule. Payment and signed-contract records normally have a 10-year retention limit. This is not a claim that every record must legally be kept for 10 years.
Terms, Privacy and deletion evidenceThe exact document version, locale, content hash, choice and timestamp are retained for 6 years after account deletion, then removed by the retention job. Optional marketing evidence follows the separate 3-year period above.
Protected backupsRolling backup copies expire within 35 days. Removed features are not restored; after disaster recovery, deletion records and feature purge migrations run before normal access resumes.

Choose Start deletion now, or choose an optional 7-day recovery period. During recovery you can cancel or start deletion early after confirming your identity. Once permanent deletion is requested to start, it cannot be cancelled. Older pending requests keep the cancellation deadline already shown; they do not receive another waiting period.

We begin erasure without undue delay after your chosen start time and aim to complete active-system and processor work within 28 days of the original request, including any recovery period. This is a service target, not permission to delay deletion. We respond to rights requests without undue delay and normally within one calendar month. If a lawful extension is necessary because of complexity or the number of requests, we explain the reason within that first month. A failed processor task does not automatically extend the legal deadline or count as completion.

When an email address is available, a separate encrypted copy is used only for deletion-status notices, including completion or a delay. It is removed after the final notice, or at most 45 days after the original request. A read-only status receipt also lasts up to 45 days. If an older request has already erased its contact address, we do not restore that address just to send a notice; contact [email protected] for assistance.

8. Your rights and choices

  • Ask for access to and a copy of your personal data through the privacy contact. Hiruu verifies the requester and responds through an appropriate secure channel.
  • Where the right applies, ask for personal data you provided in a structured, commonly used and machine-readable format, or for transfer to another controller where technically feasible. This request uses the same verified privacy-contact process and does not require a self-service download endpoint.
  • Correct inaccurate data and complete incomplete data.
  • Request deletion, restriction or objection where the law provides that right.
  • Withdraw optional marketing consent at any time without affecting earlier lawful processing.
  • Manage app permissions and notification choices in Hiruu and device settings.
  • Report users or content, block a user and appeal a moderation decision.
  • Complain to the competent data-protection authority.

9. Security, children and changes

Hiruu uses access controls, encrypted transport, secure session handling, least-privilege provider access and monitoring designed to protect personal data. No service can guarantee absolute security; report suspected unauthorized access promptly.

Hiruu is only for adults aged 18 or over. A newly registered account remains pending and cannot use normal Hiruu features until mandatory onboarding supplies a valid date of birth confirming adult eligibility. Invalid, future and under-18 dates do not activate the account, and the submitted date is not retained as account profile data after the decision. If an existing account is found to belong to a person under 18, Hiruu restricts the account, keeps only the minimum investigation record, verifies the situation and deletes or otherwise handles the account as legally required.

Material policy changes receive a new document ID and effective date. A user may be asked to acknowledge a new Privacy Policy separately from accepting new Terms. Earlier version-addressed documents remain available for acceptance records.

10. Contact

© 2026 Hiruu legal and privacy information