Privacy Policy

How Agentiv handles personal data · Last updated 21 September 2026

This Privacy Policy explains how Agentiv OY (“Agentiv”, “we”, “us”) collects, uses, and protects personal data when you use our website, our recruiting platform, and our browser extension (together, the “Service”).

We are committed to processing personal data lawfully, transparently, and in line with the EU General Data Protection Regulation (GDPR) and Finnish data protection law.

1. Who we are

Agentiv OY is the data controller for personal data described in this policy, except where we act as a processor on behalf of our customers (see Section 8).

Controller
Agentiv OY
Registered address
Metsäläntie 12 A 1, 00620 Helsinki, Finland
Business ID (Y-tunnus)
3620640-6
Privacy contact
privacy@agentiv.app

We have not appointed a Data Protection Officer. Data protection enquiries should be sent to the privacy contact above.

2. Scope of this policy

This policy covers:

  • Visitors to agentiv.app
  • Users — recruiters and talent acquisition professionals with an Agentiv account
  • The Agentiv browser extension, which operates on LinkedIn pages you are viewing
  • Candidate data processed within the Service

Where Agentiv processes candidate personal data on behalf of a customer, that processing is governed by our customer agreement and Data Processing Agreement (DPA), and the customer is the controller. This policy describes our own practices as a controller and gives candidates and users transparency about how the Service works.

3. Personal data we process

3.1 Account and user data

When you create or use an Agentiv account, we process: name, work email, organisation, role, authentication credentials, subscription and billing status, and account preferences.

3.2 Candidate data

When a user captures a candidate — via the browser extension on a LinkedIn profile they are viewing, by uploading a CV, or by entering details directly — we process personal data about that candidate, which may include: name, profile photo, work history, employers, job titles, skills, location, and any notes the user adds.

This data is structured, mapped to Agentiv’s skills and company taxonomies, and stored within the user’s workspace. See Section 8 for the controller/processor position on candidate data, Section 10 for how long it is kept, and Section 6 for how AI is applied to it.

3.3 Usage and technical data

Log data, device and browser information, IP address, and product interaction data used to operate, secure, and improve the Service. This includes analytics data collected through Google Analytics, and error and performance data collected through Sentry when something goes wrong in the recruiting platform — see Sections 7 and 13.

3.4 Communications

Content of outreach drafts, notes, and any correspondence you have with us.

3.5 Google account data (Calendar and Gmail)

Connecting a Google account to Agentiv is optional. When you connect, Agentiv asks Google only for the permissions (“scopes”) that the feature you are enabling needs, at the moment you enable it — never at sign-in.

Google Calendar (scopes calendar.events, calendar.freebusy and calendar.calendarlist.readonly) — used to create, update and cancel interview events in your Google Calendar from Agentiv, to keep those events in sync when they change on either side, to read your free/busy times so scheduling avoids conflicts, and to list your calendars so you can choose which ones Agentiv checks and writes to. Agentiv stores the events it created and a mirror of the events on the calendars you connect (times, titles, attendees, meeting links) so that your Agentiv calendar can show them.

Gmail (scope gmail.send only) — used to send candidate emails from your own Google address when you, or an Agentiv assistant acting on your instruction, send from the app. This permission lets Agentiv send mail; it cannot read, search or delete anything in your mailbox, and Agentiv does not access it.

Limited Use. Agentiv’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use Google user data only to provide and improve the user-facing features described above; we do not use it for advertising; we do not sell it; we do not transfer it to third parties except as necessary to provide those features (our subprocessors in Section 7), for security purposes, or to comply with law; we do not use it to develop, improve or train generalised AI or machine-learning models; and no person at Agentiv reads it except with your explicit permission, for security or abuse investigation, or where required by law.

Storage and deletion. Google access tokens and the data above are stored in our Frankfurt-region database, encrypted in transit and at rest, and are never shared with other users or workspaces. You can disconnect Google at any time from the Calendar page in Agentiv, which removes the connection and the mirrored calendar data, and you can revoke Agentiv’s access at any time at myaccount.google.com/permissions. Deleting your Agentiv account deletes your Google data with it.

4. How the browser extension works

Transparency about the extension matters, so specifically:

  • The extension reads details from a LinkedIn profile only when you open the Agentiv panel and choose to capture that profile. It does not read pages in the background, and it does not collect your browsing history.
  • Captured details are sent to your authenticated Agentiv workspace so the candidate can be created and managed there.
  • The extension does not send messages or connection requests on your behalf. Outreach drafts are copied to your clipboard for you to paste and send yourself.
  • The extension stores only your session state and preferences locally on your device.

We do not sell personal data, and we do not use candidate data for advertising.

5. Purposes and legal bases

We process personal data on the following legal bases under GDPR Article 6:

PurposeDataLegal basis (Art. 6)
Providing and operating the ServiceAccount, candidate, usage dataContract — Art. 6(1)(b)
Authenticating and securing accountsAccount, technical dataContract; Legitimate interests — Art. 6(1)(f)
Capturing and structuring candidate profilesCandidate dataLegitimate interests — Art. 6(1)(f), and/or processing on behalf of a controller customer (Section 8)
Improving and developing the ServiceUsage data (aggregated / de-identified where feasible)Legitimate interests — Art. 6(1)(f)
Website and product analytics (Google Analytics)Usage, device and technical dataConsent — Art. 6(1)(a)
Error monitoring and performance observability (Sentry)Technical, log and diagnostic dataLegitimate interests — Art. 6(1)(f)
Billing and subscription managementAccount, billing dataContract; Legal obligation — Art. 6(1)(c)
Responding to enquiriesCommunicationsLegitimate interests

Candidate data is processed on the basis of legitimate interests — specifically, to enable recruiters to identify and contact potential candidates for open roles — subject to the safeguards described in this policy, including a defined retention period, automatic deletion of candidates who are not contacted, and notification to the candidate on first contact (see Sections 8 and 10). Where Agentiv processes candidate data on a customer’s documented instructions, it does so as a processor (Section 8).

Where we rely on legitimate interests, we have assessed that our interests do not override the rights and freedoms of the individuals concerned. You can object to this processing — see Section 12.

6. AI and automated processing

AI is applied throughout the Service to structure profiles, map skills and companies to our taxonomies, score candidates against role rubrics, and draft outreach.

Agentiv does not make solely automated decisions that produce legal or similarly significant effects on candidates. All AI outputs — including match scores and rubric assessments — are assistive only. A human recruiter makes every hiring-relevant decision, including whether to progress or reject a candidate. Scores are decision support, not decisions; the recruiter’s own scorecard remains the source of truth.

This reflects both our product design and our approach to the EU AI Act: AI supports human judgement, it does not replace it.

7. Sharing and subprocessors

We share personal data only with service providers (“subprocessors”) who process it on our behalf under contract, and only as needed to run the Service. Our primary application hosting is on Agentiv’s own secure server located in Finland (EU).

SubprocessorPurposeRegion
NeonPostgres database hostingFrankfurt (EU)
Cloudflare (R2 + edge)Web/file hosting, object storage, AI routingEU
RailwayApplication deployment / hostingEU
OpenRouter (+ downstream LLM providers)AI model processingSome downstream providers outside the EU — see Section 9
AssemblyAIInterview transcription (native)EU-West endpoint
Recall.aiInterview intelligence on Google MeetFrankfurt (EU)
GoogleAuthentication / sign-in; Google Calendar and Gmail integration where you connect them (see Section 3.5)Ireland (EU), with transfers to the US
StripeSubscription billingIreland (EU), with transfers to the US
Google AnalyticsWebsite and product usage analyticsIreland (EU), with transfers to the US
SentryError monitoring and performance observability (recruiting platform)Frankfurt (EU)

We keep this list current: adding or removing a subprocessor is reflected here and, for customers, notified in line with our DPA.

We do not sell personal data to third parties.

8. Candidate data — controller and processor

Where a user captures and manages candidate data to carry out recruitment for their organisation, Agentiv processes that data on behalf of the user (or their organisation), who is the controller. This processing is governed by our customer terms and Data Processing Agreement (DPA), which all users — including those using the free browser extension — accept as part of using the Service.

Where Agentiv determines the purposes of processing itself — for example, operating and securing the platform, or improving the Service — Agentiv acts as a controller.

To support transparency toward candidates, Agentiv notifies a candidate that their data is held in the Service on first outreach, and provides an opt-out and deletion link at that point (see Section 12). Overall controller responsibility for candidate data — including the lawfulness of outreach — rests with the customer who captures and uses it.

9. International transfers

Most personal data in the Service is stored and processed within the EU/EEA — on Agentiv’s own secure server in Helsinki, in our Frankfurt-region database, and with EU-based infrastructure providers.

Some processing involves providers that operate in, or route data to, jurisdictions outside the EEA — currently our AI model routing (OpenRouter and downstream model providers), authentication and any Google Calendar or Gmail you connect (Google), subscription billing (Stripe), and website and product analytics (Google Analytics). Where personal data is transferred outside the EEA, we ensure an appropriate safeguard is in place, such as an adequacy mechanism (for example the EU–US Data Privacy Framework) or the European Commission’s Standard Contractual Clauses (SCCs).

10. Retention

We retain personal data only as long as necessary for the purposes it was collected, or as required by law.

Account data: for the life of the account and a reasonable period afterwards.

Candidate data is managed through a two-stage retention model:

  • Where a candidate has been added but has not been contacted within a defined retention period, their record is automatically deleted from the platform.
  • Where a candidate has been contacted or has responded, their data is retained to support the ongoing recruitment relationship, subject to the customer’s retention settings and the candidate’s right to opt out or request deletion. Candidates are notified that their data is held in Agentiv on first contact and are given an opt-out / deletion link at that point.

Billing records: as required by Finnish accounting and tax law.

Users can delete candidate records, and customers can request deletion of their workspace data, at any time.

11. Security

We apply technical and organisational measures appropriate to the risk, including primary storage on Agentiv’s own secure server located in Finland, EU-region storage with our infrastructure providers, tenant isolation between workspaces, encryption in transit and at rest, and access controls. No system is perfectly secure, but we work to protect personal data against unauthorised access, loss, or misuse.

12. Your rights

Under the GDPR, you have the right to: access your personal data; rectify inaccurate data; erase data; restrict or object to processing; data portability; and to withdraw consent where processing is based on consent.

Candidates whose data is held in Agentiv may exercise these rights, and can opt out or request deletion directly via the link provided on first contact. Because candidate data is often processed on behalf of a customer, we may direct such requests to, or handle them together with, the relevant customer as controller.

To exercise any right, contact privacy@agentiv.app. We will respond within the timeframes required by law.

You also have the right to lodge a complaint with your local supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi.

13. Cookies and local storage

Our public website and the recruiting Service use cookies and local storage that are strictly necessary to operate, authenticate, and secure the Service — for example to keep you signed in and maintain your session. These are set without consent because the Service cannot function without them. We do not use advertising cookies, and we do not sell or share personal data for advertising purposes.

We also use Google Analytics on the public website and in the recruiting platform to understand how they are used — which pages and features are visited, how people navigate, and where they run into friction. Google Analytics is a third-party service that sets cookies and identifiers in your browser and collects device and technical data. Our Google Analytics account is configured to collect and process this data in the EU, with Google Ireland Limited as our contracting entity; Google may still access it from the United States, under the safeguards described in Section 9. Because these are not strictly necessary cookies, we set them only where you have given your consent, and you can withdraw that consent at any time. Refusing analytics does not affect your ability to use the Service.

The public website records first-party, aggregate usage measurements— pages viewed, time on a page, which sections are read, which links are clicked, and a rough location (city and country) derived by our edge provider from the connection — so we can understand what's useful. This measurement sets no cookies and stores no IP addresses and no persistent identifiers: a random session number, kept in your browser only for the duration of a visit, ties together the pages of that one visit and identifies nothing about you. Browsers signalling Do Not Track or Global Privacy Control are excluded entirely.

The recruiting platform uses Sentry for error monitoring and performance observability. When something fails or runs slowly, Sentry records diagnostic data — the error, a stack trace, the page or action involved, browser and device information, IP address, and the account identifier of the signed-in user — so we can diagnose and fix it. This is used to keep the Service working and secure, not to profile you or to advertise, and we rely on our legitimate interests for it. Sentry processes this data in its EU region (Frankfurt), so it does not leave the EEA. Sentry is not used on the public marketing website.

Our investor portal — a separate, sign-in-only area of this website available to invited investors — records usage analytics, such as time spent on a section and which documents were opened, so we can understand how the materials are used. This does not apply to the public website or to the recruiting Service.

You can change or withdraw your cookie choices at any time through the cookie settings on our website, or by clearing cookies in your browser. If we introduce any further non-essential cookies in future, we will do so on the basis of your consent and update this policy accordingly.

14. Children

The Service is intended for professional use by adults and is not directed at children.

15. Changes to this policy

We may update this policy from time to time. Material changes will be communicated through the Service or by other appropriate means, and the “Last updated” date above will be revised.

16. Contact

Questions about this policy or your personal data:

Agentiv OY

Metsäläntie 12 A 1, 00620 Helsinki, Finland

privacy@agentiv.app

Agentiv

Hire Smarter, Stay Human.