BorovaHR Logo

Privacy Policy

Last Updated: March 1, 2026

At BorovaHR ("we," "us," or "our"), we are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our HR and recruitment management platform ("Service"). Please read this policy carefully to understand our practices regarding your data.

By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.

1. Information We Collect

We collect several types of information to provide and improve our Service:

1.1 Information You Provide

When you register for an account or use our Service, we may collect:

  • Account Information: Name, email address, password, company name, phone number, and other contact details
  • Company Information: Company name, address, industry, business type, registration number, tax ID, and other business details
  • Job Posting Data: Job descriptions, requirements, salary information, and other job-related content
  • Public Job Board Data: When you opt to list jobs on the BorovaHR public job board, certain information — including job title, description, location, employment type, salary range, and your company name, logo, and industry — is made publicly accessible to all visitors of the platform, including unauthenticated users
  • Candidate Information: Resumes, cover letters, application data, and other information submitted by candidates through your job postings
  • Communication Data: Messages, emails, and other communications sent through the Service
  • Payment Information: Billing address, payment method details (processed securely through third-party payment processors)

1.2 Automatically Collected Information

When you use our Service, we automatically collect certain information:

  • Usage Data: Pages visited, features used, time spent, click patterns, and other interaction data
  • Device Information: IP address, browser type, device type, operating system, and device identifiers
  • Log Data: Access times, error logs, and system performance data
  • Location Data: General location information based on IP address (not precise location)
  • Cookies and Tracking Technologies: Information collected through cookies, web beacons, and similar technologies (see Section 7)

1.3 Information from Third Parties

We may receive information about you from third-party services, such as:

  • Authentication providers (e.g., Google OAuth)
  • Payment processors
  • Analytics services
  • Email service providers
  • Other integrated services you authorize

2. How We Use Your Information

Google user data (from Google sign-in, Google Calendar, or other Google APIs) is used only to provide and improve our application's functionality (e.g., authentication, calendar sync, profile display). We do not use Google user data for marketing, advertising, or any purpose other than providing or improving the Service.

We use other collected information for the following purposes:

  • Service Provision: To provide, maintain, and improve our Service, including processing job postings, managing applications, facilitating communications, and displaying opted-in job listings on the public BorovaHR job board
  • Account Management: To create and manage your account, authenticate users, and provide customer support
  • Communication: To send you service-related notifications, updates, security alerts, and respond to your inquiries
  • Billing and Payments: To process payments, manage subscriptions, and handle billing inquiries
  • Analytics and Improvement: To analyze usage patterns, improve our Service, develop new features, and conduct research
  • Security: To detect, prevent, and address security issues, fraud, and unauthorized access
  • Legal Compliance: To comply with legal obligations, enforce our Terms of Service, and protect our rights
  • Marketing: To send you promotional communications (with your consent, where required by law)
  • Personalization: To customize your experience and provide relevant content and features
  • AI-Powered Analysis: We use artificial intelligence (powered by OpenAI) to analyze candidate resumes and generate interview questions for employers. Resume data submitted through job applications may be processed by OpenAI's API to provide automated scoring and analysis. This processing is performed to assist employers in evaluating candidates and is based on the legitimate interest of providing core recruitment functionality. AI-generated analysis is advisory only and does not replace human decision-making in the hiring process.

3. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), we process your personal data based on the following legal grounds:

  • Contract Performance: To fulfill our contractual obligations to provide the Service
  • Legitimate Interests: To improve our Service, ensure security, and conduct business operations
  • Consent: When you have provided explicit consent for specific processing activities
  • Legal Obligation: To comply with applicable laws and regulations

4. Data Sharing and Disclosure

4.0 Google User Data — No Transfer for Prohibited Purposes

We do not transfer Google user data to third parties for any reason other than providing or improving our application's functionality. Our data handling process expressly prohibits the transfer of Google user data (data obtained through Google APIs, including OAuth and Google Calendar) to third parties for any of the following reasons:

  • Targeted advertising
  • Selling to data brokers
  • Providing to information resellers
  • Determining credit-worthiness
  • Lending purposes
  • User advertisements
  • Personalized advertisements
  • Retargeted advertisements
  • Interest-based advertisements

We have changed our data handling process to prohibit such use and transfer of Google user data. Any sharing of Google user data is limited to service providers that strictly help us operate and improve the BorovaHR service (e.g., secure hosting, calendar sync) under contract and only for those purposes. We do not sell Google user data.

We may share other information (non-Google user data) in the following circumstances:

4.1 Service Providers

We share information with third-party service providers who perform services on our behalf, including:

  • Vercel — Cloud hosting, serverless functions, and file storage (Vercel Blob)
  • Neon — PostgreSQL database hosting
  • Paddle — Payment processing and subscription billing
  • Google — Analytics (Google Analytics / Google Tag Manager), OAuth authentication, Gmail API for email sending, Google Calendar integration
  • Meta (Facebook) — Conversion tracking via Facebook Pixel (loaded only with your consent)
  • LinkedIn — Conversion tracking via LinkedIn Insight Tag (loaded only with your consent)
  • OpenAI — AI-powered resume analysis and interview question generation for recruitment features
  • Cal.com — Demo scheduling and meeting booking
  • Nodemailer — Transactional email delivery

These service providers are contractually obligated to protect your information and use it only for the purposes we specify (providing and improving our Service). We do not permit them to use your data, including any Google user data, for advertising, resale, or any purpose other than delivering the services we have contracted for.

4.2 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control. Any transfer of Google user data in such circumstances would remain subject to the same restrictions: use only for providing or improving the application's functionality, with no transfer for advertising, data brokers, or other prohibited purposes.

4.3 Legal Requirements

We may disclose your information if required by law, court order, or government regulation, or if we believe disclosure is necessary to:

  • Comply with legal obligations
  • Protect our rights, property, or safety
  • Protect the rights, property, or safety of our users or others
  • Prevent or investigate fraud or security issues

4.4 With Your Consent

We may share your information (other than Google user data) with third parties when you have provided explicit consent for such sharing. We do not share Google user data with third parties for targeted advertising, data brokers, resellers, advertising of any kind, or any purpose other than providing or improving our application's functionality, even with consent.

4.5 Aggregated and Anonymized Data

We may share aggregated, anonymized, or de-identified data that cannot be used to identify you for research, analytics, or to improve our Service. We do not include Google user data in any such data shared for purposes other than providing or improving our application's functionality, and we do not use or share such data for advertising, data broker sales, or any other prohibited purpose.

4.6 Public Job Board

BorovaHR operates a public job board that aggregates job listings from companies using our platform. When a company opts to list a job on the public job board (controlled via a per-job toggle and a company-level default setting), the following information is made publicly visible to anyone, including unauthenticated visitors:

  • Job title, description, location, and employment type
  • Salary range (if provided by the employer)
  • Company name, logo, and industry
  • Date the job was posted

This public display is based on the employer's explicit opt-in. Companies can control visibility at both the individual job level and through a company-wide default setting. Disabling the "List on BorovaHR Job Board" toggle will remove the job from public view. No candidate personal data or application information is ever displayed on the public job board.

4.7 Google User Data (Google APIs)

When you connect your Google account (e.g., for sign-in or Google Calendar integration), we access and use Google user data only to provide and improve our application's functionality—such as authenticating you, syncing your calendar with BorovaHR, or displaying your profile information within the Service. We store only what is necessary for these features. We do not transfer, sell, or disclose Google user data to third parties for targeted advertising, advertising-related purposes, data broker or reseller purposes, credit or lending purposes, or any use other than providing or improving BorovaHR. Our data handling processes prohibit such uses and transfers.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption: Data is encrypted in transit using TLS/SSL and at rest using industry-standard encryption
  • Access Controls: Strict access controls and authentication mechanisms to limit who can access your data
  • Security Monitoring: Continuous monitoring for security threats and vulnerabilities
  • Regular Audits: Regular security audits and assessments
  • Employee Training: Security training for employees who handle personal data
  • Incident Response: Procedures for responding to security incidents

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

6.1 Access and Portability

You have the right to access your personal information and receive a copy in a structured, machine-readable format.

6.2 Rectification

You have the right to correct inaccurate or incomplete personal information. You can update most information through your account settings.

6.3 Erasure (Right to be Forgotten)

You have the right to request deletion of your personal information, subject to certain legal and contractual limitations.

6.4 Restriction of Processing

You have the right to request that we limit how we process your personal information in certain circumstances.

6.5 Objection to Processing

You have the right to object to certain types of processing, including processing for direct marketing purposes.

6.6 Withdrawal of Consent

Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

6.7 Data Portability

You have the right to receive your personal information in a structured, commonly used, and machine-readable format and to transmit it to another controller.

6.8 Complaints

You have the right to lodge a complaint with a supervisory authority if you believe we have violated your data protection rights.

To exercise these rights, please contact us at: support@borovahr.com

7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our Service and store certain information. Cookies are small data files stored on your device.

7.1 Types of Cookies We Use

  • Essential Cookies: Required for the Service to function properly (e.g., authentication, security)
  • Functional Cookies: Remember your preferences and settings
  • Analytics Cookies: Help us understand how users interact with our Service
  • Marketing Cookies: Used to deliver relevant advertisements (with your consent)

7.2 Cookie Consent

When you first visit our site, you will be presented with a cookie consent banner that allows you to choose which categories of cookies to accept. Analytics and marketing cookies are not loaded until you explicitly opt in. You can change your preferences at any time through the cookie settings in your account or by clearing your browser storage and revisiting the site.

7.3 Cookie Management

You can also control cookies through your browser settings. However, disabling certain cookies may limit your ability to use some features of our Service.

8. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Our retention periods are based on:

  • The nature of the information
  • The purposes for which it was collected
  • Legal and regulatory requirements
  • Business needs and operational requirements

When we no longer need your information, we will securely delete or anonymize it in accordance with our data retention policies.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country.

When we transfer personal data from the EEA to other countries, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Other legally recognized transfer mechanisms

10. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.

If you believe we have collected information from a child, please contact us immediately at support@borovahr.com.

11. Third-Party Links and Services

Our Service may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information.

12. Data Controller Information

For the purposes of GDPR and other applicable data protection laws, BorovaHR is the data controller of your personal information.

However, when you collect candidate information through our Service, you act as the data controller for that candidate data, and we act as a data processor. You are responsible for ensuring compliance with applicable data protection laws when processing candidate information.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting the updated policy on our website
  • Sending an email notification to the address associated with your account
  • Displaying a prominent notice on our Service

The "Last Updated" date at the top of this policy indicates when it was last revised. Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Support Email: support@borovahr.com

For users in the EEA, you also have the right to contact your local data protection authority if you have concerns about how we handle your personal information.

Back to HomeTerms & Conditions