Privacy Policy
How Agentiv handles personal data · Last updated 21 September 2026
This Privacy Policy explains how Agentiv OY (“Agentiv”, “we”, “us”) collects, uses, and protects personal data when you use our website, our recruiting platform, and our browser extension (together, the “Service”).
We are committed to processing personal data lawfully, transparently, and in line with the EU General Data Protection Regulation (GDPR) and Finnish data protection law.
1. Who we are
Agentiv OY is the data controller for personal data described in this policy, except where we act as a processor on behalf of our customers (see Section 8).
- Controller
- Agentiv OY
- Registered address
- Metsäläntie 12 A 1, 00620 Helsinki, Finland
- Business ID (Y-tunnus)
- 3620640-6
- Privacy contact
- privacy@agentiv.app
We have not appointed a Data Protection Officer. Data protection enquiries should be sent to the privacy contact above.
2. Scope of this policy
This policy covers:
- Visitors to agentiv.app
- Users — recruiters and talent acquisition professionals with an Agentiv account
- The Agentiv browser extension, which operates on LinkedIn pages you are viewing
- Candidate data processed within the Service
Where Agentiv processes candidate personal data on behalf of a customer, that processing is governed by our customer agreement and Data Processing Agreement (DPA), and the customer is the controller. This policy describes our own practices as a controller and gives candidates and users transparency about how the Service works.
3. Personal data we process
3.1 Account and user data
When you create or use an Agentiv account, we process: name, work email, organisation, role, authentication credentials, subscription and billing status, and account preferences.
3.2 Candidate data
When a user captures a candidate — via the browser extension on a LinkedIn profile they are viewing, by uploading a CV, or by entering details directly — we process personal data about that candidate, which may include: name, profile photo, work history, employers, job titles, skills, location, and any notes the user adds.
This data is structured, mapped to Agentiv’s skills and company taxonomies, and stored within the user’s workspace. See Section 8 for the controller/processor position on candidate data, Section 10 for how long it is kept, and Section 6 for how AI is applied to it.
3.3 Usage and technical data
Log data, device and browser information, IP address, and product interaction data used to operate, secure, and improve the Service. This includes analytics data collected through Google Analytics, and error and performance data collected through Sentry when something goes wrong in the recruiting platform — see Sections 7 and 13.
3.4 Communications
Content of outreach drafts, notes, and any correspondence you have with us.
3.5 Google account data (Calendar and Gmail)
Connecting a Google account to Agentiv is optional. When you connect, Agentiv asks Google only for the permissions (“scopes”) that the feature you are enabling needs, at the moment you enable it — never at sign-in.
Google Calendar (scopes calendar.events, calendar.freebusy and calendar.calendarlist.readonly) — used to create, update and cancel interview events in your Google Calendar from Agentiv, to keep those events in sync when they change on either side, to read your free/busy times so scheduling avoids conflicts, and to list your calendars so you can choose which ones Agentiv checks and writes to. Agentiv stores the events it created and a mirror of the events on the calendars you connect (times, titles, attendees, meeting links) so that your Agentiv calendar can show them.
Gmail (scope gmail.send only) — used to send candidate emails from your own Google address when you, or an Agentiv assistant acting on your instruction, send from the app. This permission lets Agentiv send mail; it cannot read, search or delete anything in your mailbox, and Agentiv does not access it.
Limited Use. Agentiv’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use Google user data only to provide and improve the user-facing features described above; we do not use it for advertising; we do not sell it; we do not transfer it to third parties except as necessary to provide those features (our subprocessors in Section 7), for security purposes, or to comply with law; we do not use it to develop, improve or train generalised AI or machine-learning models; and no person at Agentiv reads it except with your explicit permission, for security or abuse investigation, or where required by law.
Storage and deletion. Google access tokens and the data above are stored in our Frankfurt-region database, encrypted in transit and at rest, and are never shared with other users or workspaces. You can disconnect Google at any time from the Calendar page in Agentiv, which removes the connection and the mirrored calendar data, and you can revoke Agentiv’s access at any time at myaccount.google.com/permissions. Deleting your Agentiv account deletes your Google data with it.
4. How the browser extension works
Transparency about the extension matters, so specifically:
- The extension reads details from a LinkedIn profile only when you open the Agentiv panel and choose to capture that profile. It does not read pages in the background, and it does not collect your browsing history.
- Captured details are sent to your authenticated Agentiv workspace so the candidate can be created and managed there.
- The extension does not send messages or connection requests on your behalf. Outreach drafts are copied to your clipboard for you to paste and send yourself.
- The extension stores only your session state and preferences locally on your device.
We do not sell personal data, and we do not use candidate data for advertising.
5. Purposes and legal bases
We process personal data on the following legal bases under GDPR Article 6:
| Purpose | Data | Legal basis (Art. 6) |
|---|---|---|
| Providing and operating the Service | Account, candidate, usage data | Contract — Art. 6(1)(b) |
| Authenticating and securing accounts | Account, technical data | Contract; Legitimate interests — Art. 6(1)(f) |
| Capturing and structuring candidate profiles | Candidate data | Legitimate interests — Art. 6(1)(f), and/or processing on behalf of a controller customer (Section 8) |
| Improving and developing the Service | Usage data (aggregated / de-identified where feasible) | Legitimate interests — Art. 6(1)(f) |
| Website and product analytics (Google Analytics) | Usage, device and technical data | Consent — Art. 6(1)(a) |
| Error monitoring and performance observability (Sentry) | Technical, log and diagnostic data | Legitimate interests — Art. 6(1)(f) |
| Billing and subscription management | Account, billing data | Contract; Legal obligation — Art. 6(1)(c) |
| Responding to enquiries | Communications | Legitimate interests |
Candidate data is processed on the basis of legitimate interests — specifically, to enable recruiters to identify and contact potential candidates for open roles — subject to the safeguards described in this policy, including a defined retention period, automatic deletion of candidates who are not contacted, and notification to the candidate on first contact (see Sections 8 and 10). Where Agentiv processes candidate data on a customer’s documented instructions, it does so as a processor (Section 8).
Where we rely on legitimate interests, we have assessed that our interests do not override the rights and freedoms of the individuals concerned. You can object to this processing — see Section 12.
6. AI and automated processing
AI is applied throughout the Service to structure profiles, map skills and companies to our taxonomies, score candidates against role rubrics, and draft outreach.
Agentiv does not make solely automated decisions that produce legal or similarly significant effects on candidates. All AI outputs — including match scores and rubric assessments — are assistive only. A human recruiter makes every hiring-relevant decision, including whether to progress or reject a candidate. Scores are decision support, not decisions; the recruiter’s own scorecard remains the source of truth.
This reflects both our product design and our approach to the EU AI Act: AI supports human judgement, it does not replace it.
8. Candidate data — controller and processor
Where a user captures and manages candidate data to carry out recruitment for their organisation, Agentiv processes that data on behalf of the user (or their organisation), who is the controller. This processing is governed by our customer terms and Data Processing Agreement (DPA), which all users — including those using the free browser extension — accept as part of using the Service.
Where Agentiv determines the purposes of processing itself — for example, operating and securing the platform, or improving the Service — Agentiv acts as a controller.
To support transparency toward candidates, Agentiv notifies a candidate that their data is held in the Service on first outreach, and provides an opt-out and deletion link at that point (see Section 12). Overall controller responsibility for candidate data — including the lawfulness of outreach — rests with the customer who captures and uses it.
9. International transfers
Most personal data in the Service is stored and processed within the EU/EEA — on Agentiv’s own secure server in Helsinki, in our Frankfurt-region database, and with EU-based infrastructure providers.
Some processing involves providers that operate in, or route data to, jurisdictions outside the EEA — currently our AI model routing (OpenRouter and downstream model providers), authentication and any Google Calendar or Gmail you connect (Google), subscription billing (Stripe), and website and product analytics (Google Analytics). Where personal data is transferred outside the EEA, we ensure an appropriate safeguard is in place, such as an adequacy mechanism (for example the EU–US Data Privacy Framework) or the European Commission’s Standard Contractual Clauses (SCCs).
10. Retention
We retain personal data only as long as necessary for the purposes it was collected, or as required by law.
Account data: for the life of the account and a reasonable period afterwards.
Candidate data is managed through a two-stage retention model:
- Where a candidate has been added but has not been contacted within a defined retention period, their record is automatically deleted from the platform.
- Where a candidate has been contacted or has responded, their data is retained to support the ongoing recruitment relationship, subject to the customer’s retention settings and the candidate’s right to opt out or request deletion. Candidates are notified that their data is held in Agentiv on first contact and are given an opt-out / deletion link at that point.
Billing records: as required by Finnish accounting and tax law.
Users can delete candidate records, and customers can request deletion of their workspace data, at any time.
11. Security
We apply technical and organisational measures appropriate to the risk, including primary storage on Agentiv’s own secure server located in Finland, EU-region storage with our infrastructure providers, tenant isolation between workspaces, encryption in transit and at rest, and access controls. No system is perfectly secure, but we work to protect personal data against unauthorised access, loss, or misuse.
12. Your rights
Under the GDPR, you have the right to: access your personal data; rectify inaccurate data; erase data; restrict or object to processing; data portability; and to withdraw consent where processing is based on consent.
Candidates whose data is held in Agentiv may exercise these rights, and can opt out or request deletion directly via the link provided on first contact. Because candidate data is often processed on behalf of a customer, we may direct such requests to, or handle them together with, the relevant customer as controller.
To exercise any right, contact privacy@agentiv.app. We will respond within the timeframes required by law.
You also have the right to lodge a complaint with your local supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi.
14. Children
The Service is intended for professional use by adults and is not directed at children.
15. Changes to this policy
We may update this policy from time to time. Material changes will be communicated through the Service or by other appropriate means, and the “Last updated” date above will be revised.
16. Contact
Questions about this policy or your personal data:
Hire Smarter, Stay Human.