Effective Date: [Insert Date]
- Introduction
2. Information We Collect
The information we gather generally falls into two categories: information you intentionally provide to us and information automatically collected through your use of our services.1. Voluntarily Provided Information
This includes any personal data you willingly submit when using or interacting with ComplyHire’s services, such as:- Contact forms (name, email, company details)
- Service requests
- Job application submissions
- Communication with our team or through customer support
2. Automatically Collected Information
When you visit or interact with our website or digital platforms, we may automatically collect certain technical and usage data, such as:- Your IP address and device information
- Browser type and version
- Pages visited, time spent, and referral URLs
- Cookies and similar tracking technologies
3. Log Data
When you access our website, our servers may automatically record technical information provided by your browser. This may include:- Your device’s IP address
- Browser type and version
- Visited pages and time stamps
- Time spent on each page
- Referring website addresses or links
- What you were doing at the time of the error
- Details about your device and software
- Error messages or system logs (where applicable)
4. Device Data
When you access our website or use our services, we may collect specific information about the device you are using. This may include:- Device type (e.g., mobile, desktop, tablet)
- Operating system and version
- Approximate geolocation (based on IP address or device settings)
- Personal Information
- Email address
- Phone number or mobile number
- Social media profiles (if voluntarily shared with us)
- Full name, date of birth, and gender
- Nationality and residential address
- Marital status
- Financial or payroll information (e.g., banking details)
- Health-related data (where legally required or consented)
- Official government identification numbers (e.g., ID card, tax number, social security, health ID)
6. Legal Basis for Processing Your Personal Information
We only collect and process your personal data when we have a valid legal basis to do so. This ensures that your information is used in a fair, lawful, and transparent manner. Contractual Necessity: We process your personal data when it is necessary for fulfilling our contractual obligations to you or for taking steps at your request before entering into a contract. For example, if you engage ComplyHire for EOR or HR outsourcing services, we require certain personal data to provide those services and manage the ongoing business relationship. Compliance with Legal Obligations: We may process your data to meet our legal and regulatory obligations under Serbian law or other applicable jurisdictions. This includes obligations such as employment law compliance, tax reporting, anti-money laundering checks, or responding to lawful requests from public authorities. Legitimate Interests: In certain cases, we process your personal information for our legitimate business interests—such as improving our services, ensuring the security of our systems, conducting internal analytics, or communicating with existing customers. Before relying on this basis, we balance our interests against your rights and freedoms to ensure they are not overridden. Legitimate Interests of Third Parties: If ComplyHire acts as a data processor on behalf of a client (e.g., in an outsourcing arrangement), we may process data to support the client’s legitimate business objectives—such as HR administration or compliance. We ensure this processing is conducted responsibly and in accordance with applicable data protection laws. Consent: Where required, especially in the case of collecting sensitive personal data or for sending you marketing communications, we will ask for your explicit consent. You may withdraw this consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.7. Collection and Use of Information
ComplyHire may collect your personal data both directly—from your interactions with us—and indirectly—through your usage of our website and services. We collect data in a variety of contexts, including (but not limited to) when:- You register for an account on our website
- You subscribe to receive email or social media updates
- You access our services via a mobile device or web browser
- You contact us by email, social media, or other communication channels
- You mention or tag ComplyHire on social media platforms
- You opt into marketing communications or attend a promotional event
- You become a platform user or client
- You are employed by or collaborate with ComplyHire
- To provide access to our platform and core services as required by law or contract
- To personalize your experience on our website or platform
- To establish contact and maintain communication with you
- To process employment applications
- For internal research, product testing, and service improvement
- To operate effectively with partners, clients, and vendors
- To develop new services based on your needs and feedback
- For marketing, event participation, or promotional campaigns
- For billing, payroll management, and processing payments
- To administer taxes and regulatory compliance activities
- For risk and fraud prevention, including anti-money laundering procedures
- To investigate and respond to user complaints or legal inquiries
- Identity and Contact Information: We will identify ComplyHire as the data controller and provide appropriate contact details, including that of a representative, where relevant.
- Data Protection Officer (DPO): Where applicable, we will share the contact information of our DPO.
- Purpose and Legal Basis: You will be informed of why we are processing your personal data and under which lawful basis.
- Categories of Personal Data: We will specify which types of personal data are involved.
- Recipients of Data: Where necessary, we disclose who may receive or have access to the data.
- Data Transfers: If personal data is transferred internationally (outside the EU/EEA), we will inform you about the destination, the safeguards in place, and your right to request further information or a copy of those safeguards.
8. Security of Your Personal Information
At ComplyHire, the security of your personal information is a top priority. We implement appropriate administrative, technical, and organizational measures to protect your data against unauthorized access, disclosure, loss, misuse, or alteration. These safeguards are designed based on the nature of the data we collect, its sensitivity, and the latest industry best practices. We follow internationally recognized standards to maintain the confidentiality and integrity of your data and continuously work to enhance our security practices. These include:- Secure data transmission protocols (e.g., HTTPS/SSL)
- Access control and authentication procedures
- Regular audits and security monitoring
- Data encryption, both in transit and at rest
9. How Long We Keep Your Personal Information
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, or as required by applicable laws and regulatory obligations. The specific retention period depends on the nature of the data and how it is used. We implement secure deletion protocols to manage your personal information responsibly. Where feasible, we permanently delete or anonymize your data once it is no longer needed. While we strive to remove information promptly, please note that there may be short delays between your deletion request and the removal of data from all active and backup systems. For example, if you created an account with us or engaged in our services, we may retain your personal data as long as your account is active or as long as necessary to fulfill our service agreement. Once your information is no longer required, we ensure it is securely erased or anonymized. In certain circumstances, we may retain personal data beyond the termination of services, including:- To comply with legal, tax, or accounting requirements
- To meet archiving, research, or statistical needs (where permitted by law)
- To resolve disputes or enforce our agreements
- To ensure the integrity, security, and prevention of fraud or misuse of our services
10. Children’s Privacy
ComplyHire does not target its services or content to children under the age of 16, nor do we knowingly collect personal data from anyone under this age. Our services are intended for use by adults and business professionals. If you become aware that a child under 16 has provided us with personal information without parental consent, please contact us immediately. Upon verification, we will take prompt action to delete the data from our systems in accordance with applicable data protection laws.11. Disclosure of Personal Information to Third Parties
ComplyHire may share your personal data with trusted third parties in the following circumstances:- With our parent company, subsidiaries, or affiliated entities to support our business operations.
- With third-party service providers who assist us in delivering services, including but not limited to IT support, data hosting and storage, server management, analytics, error tracking, debt collection, maintenance, professional advice, and payment processing.
- With our employees, contractors, and related business units who need access to your data to perform their job functions.
- With current or prospective business partners, agents, or collaborators to facilitate joint services or business activities.
- With credit reporting agencies, courts, tribunals, regulatory bodies, and law enforcement authorities in cases such as non-payment for goods or services or to comply with legal obligations.
- With third-party agents or subcontractors who support us in providing products, services, or marketing communications.
- With third parties involved in data collection and processing on our behalf.
- With any entity that acquires or takes over all or a significant portion of our assets or business, ensuring your data remains protected during such transitions.
12. International Data Transfer
By using ComplyHire’s services and providing your personal data, you acknowledge and consent that your information may be transferred, stored, and processed in countries other than your country of residence, including Serbia and other jurisdictions where our affiliates or service providers operate. Some of these countries may have data protection laws that differ from those in your home country and may not offer the same level of protection. If you are located in the European Economic Area (EEA) or the United Kingdom, and your personal data is transferred to a country outside of Europe or a country that does not have an adequacy decision from the European Commission, we ensure appropriate safeguards are in place. Such safeguards include entering into agreements with data recipients that incorporate standard contractual clauses (also known as EU Model Clauses or SCCs) and the UK International Data Transfer Addendum. These legal tools ensure that your personal data continues to receive an adequate level of protection even when processed internationally.13. Your Rights and Controlling Your Personal Information
Individuals located in the European Economic Area (EEA), the United Kingdom, California, Singapore, the UAE, Canada, and other regions worldwide have certain statutory rights regarding their personal data under applicable data protection laws. These rights include, but are not limited to:- Right to be Informed: You have the right to know how and why your personal data is processed, including the purposes, recipients, and legal basis.
- Right of Access: You can request confirmation on whether we are processing your personal data and, if so, access a copy of that data.
- Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format and transfer it to another data controller.
- Right to Rectification: You may request correction or amendment of inaccurate or incomplete personal data.
- Right to Erasure (“Right to be Forgotten”): Under certain conditions, you may request deletion or removal of your personal data.
- Right to Restrict Processing: You can request that we limit the processing of your personal data in specific circumstances.
- Right to Object: You have the right to object to processing based on legitimate interests or for direct marketing purposes.
- Right to Non-Discrimination: You should not be subject to discrimination for exercising any of your data protection rights.
- Right to Additional Information: You may request further details about the processing of your data beyond standard disclosures.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Right to Lodge a Complaint: You can file a complaint with a relevant data protection authority if you believe your rights have been violated.
- Right to Opt-Out of Sale: In certain jurisdictions, you have the right to opt out of the sale or disclosure of your personal data to third parties for commercial purposes.
- Right to Object to Automated Decision-Making: You can object to decisions based solely on automated processing, including profiling, that significantly affect you.