Privacy Policy
How Agentiv handles personal data · Last updated [date on publish]
This Privacy Policy explains how Agentiv OY (“Agentiv”, “we”, “us”) collects, uses, and protects personal data when you use our website, our recruiting platform, and our browser extension (together, the “Service”).
We are committed to processing personal data lawfully, transparently, and in line with the EU General Data Protection Regulation (GDPR) and Finnish data protection law.
1. Who we are
Agentiv OY is the data controller for personal data described in this policy, except where we act as a processor on behalf of our customers (see Section 8).
- Controller
- Agentiv OY
- Registered address
- [registered address, Helsinki, Finland]
- Business ID (Y-tunnus)
- [to be confirmed]
- Privacy contact
- privacy@agentiv.app
We have not appointed a Data Protection Officer. Data protection enquiries should be sent to the privacy contact above.
2. Scope of this policy
This policy covers:
- Visitors to agentiv.app
- Users — recruiters and talent acquisition professionals with an Agentiv account
- The Agentiv browser extension, which operates on LinkedIn pages you are viewing
- Candidate data processed within the Service
Where Agentiv processes candidate personal data on behalf of a customer, that processing is governed by our customer agreement and Data Processing Agreement (DPA), and the customer is the controller. This policy describes our own practices as a controller and gives candidates and users transparency about how the Service works.
3. Personal data we process
3.1 Account and user data
When you create or use an Agentiv account, we process: name, work email, organisation, role, authentication credentials, subscription and billing status, and account preferences.
3.2 Candidate data
When a user captures a candidate — via the browser extension on a LinkedIn profile they are viewing, by uploading a CV, or by entering details directly — we process personal data about that candidate, which may include: name, profile photo, work history, employers, job titles, skills, location, and any notes the user adds.
This data is structured, mapped to Agentiv’s skills and company taxonomies, and stored within the user’s workspace. See Section 8 for the controller/processor position on candidate data, and Section 6 for how AI is applied to it.
3.3 Usage and technical data
Log data, device and browser information, IP address, and product interaction data used to operate, secure, and improve the Service.
3.4 Communications
Content of outreach drafts, notes, and any correspondence you have with us.
4. How the browser extension works
Transparency about the extension matters, so specifically:
- The extension reads details from a LinkedIn profile only when you open the Agentiv panel and choose to capture that profile. It does not read pages in the background, and it does not collect your browsing history.
- Captured details are sent to your authenticated Agentiv workspace so the candidate can be created and managed there.
- The extension does not send messages or connection requests on your behalf. Outreach drafts are copied to your clipboard for you to paste and send yourself.
- The extension stores only your session state and preferences locally on your device.
We do not sell personal data, and we do not use candidate data for advertising.
5. Purposes and legal bases
We process personal data on the following legal bases under GDPR Article 6:
| Purpose | Data | Legal basis (Art. 6) |
|---|---|---|
| Providing and operating the Service | Account, candidate, usage data | Contract — Art. 6(1)(b) |
| Authenticating and securing accounts | Account, technical data | Contract; Legitimate interests — Art. 6(1)(f) |
| Capturing and structuring candidate profiles | Candidate data | Legitimate interests, and/or processing on behalf of a controller customer (Section 8) |
| Improving and developing the Service | Usage data (aggregated / de-identified where feasible) | Legitimate interests — Art. 6(1)(f) |
| Billing and subscription management | Account, billing data | Contract; Legal obligation — Art. 6(1)(c) |
| Responding to enquiries | Communications | Legitimate interests |
Where we rely on legitimate interests, we have assessed that our interests do not override the rights and freedoms of the individuals concerned. You can object to this processing — see Section 12.
6. AI and automated processing
AI is applied throughout the Service to structure profiles, map skills and companies to our taxonomies, score candidates against role rubrics, and draft outreach.
Agentiv does not make solely automated decisions that produce legal or similarly significant effects on candidates. All AI outputs — including match scores and rubric assessments — are assistive only. A human recruiter makes every hiring-relevant decision, including whether to progress or reject a candidate. Scores are decision support, not decisions; the recruiter’s own scorecard remains the source of truth.
This reflects both our product design and our approach to the EU AI Act: AI supports human judgement, it does not replace it.
8. Candidate data — controller and processor
Where a user captures and manages candidate data to carry out recruitment for their organisation, Agentiv processes that data on behalf of the customer, who is the controller. That processing is governed by the customer agreement and DPA.
Where Agentiv determines the purposes of processing itself — for example, operating and securing the platform or improving the Service — Agentiv acts as a controller.
9. International transfers
Where personal data is transferred outside the European Economic Area — for example to AI or infrastructure providers operating in other jurisdictions — we ensure an appropriate safeguard is in place, such as an adequacy decision or the European Commission’s Standard Contractual Clauses (SCCs).
10. Retention
We retain personal data only as long as necessary for the purposes it was collected, or as required by law.
- Account data: for the life of the account and a reasonable period afterwards.
- Candidate data: for as long as the user/customer maintains it in their workspace, subject to the customer’s own retention settings and instructions, then deleted or de-identified.
- Billing records: as required by Finnish accounting and tax law.
Users can delete candidate records, and customers can request deletion of their workspace data, at any time.
11. Security
We apply technical and organisational measures appropriate to the risk, including tenant isolation between workspaces, encryption in transit, access controls, and EU-region storage for stored personal data. No system is perfectly secure, but we work to protect personal data against unauthorised access, loss, or misuse.
12. Your rights
Under the GDPR, you have the right to: access your personal data; rectify inaccurate data; erase data; restrict or object to processing; data portability; and to withdraw consent where processing is based on consent.
Candidates whose data is held in Agentiv may exercise these rights. Because candidate data is often processed on behalf of a customer, we may direct such requests to, or handle them together with, the relevant customer as controller.
To exercise any right, contact privacy@agentiv.app. We will respond within the timeframes required by law.
You also have the right to lodge a complaint with your local supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi.
14. Children
The Service is intended for professional use by adults and is not directed at children.
15. Changes to this policy
We may update this policy from time to time. Material changes will be communicated through the Service or by other appropriate means, and the “Last updated” date above will be revised.
16. Contact
Questions about this policy or your personal data:
