Privacy Policy
How Hirevoice processes personal data, including data reached through integrations and connected applications
Last updated: August 2026
1. Responsible party and data processor
HIREVOICE, S.L. (C/ Travessera de Gracia, 15, Sobreático 3, 08021, Barcelona, Spain; Tax ID: B-23903230; gdpr@hirevoice.com) operates in two capacities:
- Data Controller for business clients, corporate users, contacts, and billing data related to contractual relationships.
- Data Processor for candidate data in selection processes managed on behalf of client companies, pursuant to GDPR Article 28 and Spanish Organic Law 3/2018.
2. Processing purposes
Business client management and platform access: names, professional contact details, company information, IP addresses, encrypted credentials, and billing data. Legal basis: contract execution. Data retained during contract term and per legal prescription periods.
Voice interview services via AI: candidate names, contact information, CVs, voice recordings, interview transcripts, AI-generated scores, and interaction data. The company is the controller; Hirevoice processes only following documented instructions per GDPR Article 28. Scores measure response alignment with client-defined competencies. They do not determine hiring decisions. Data is retained per client instructions.
Customer support: contact and communication data for resolving technical issues. Legal basis: legitimate interest in quality service delivery.
Commercial communications: professional email addresses for platform updates and industry resources, with withdrawal option. Legal basis: consent or legitimate interest for existing clients.
Platform improvement: aggregated, anonymized usage data for analytics and development. Candidate data is not utilized for training, tuning, or enhancing artificial intelligence models.
3. Artificial intelligence
Hirevoice transcribes responses and generates competency scores based exclusively on client-defined parameters. Clients must ensure final hiring decisions include human supervision and validation, without relying exclusively on automated scores.
Candidates may request human intervention and explanations from the responsible company (their prospective employer).
Transparency notices appear before interviews, in automated call announcements, and in instant messaging communications, complying with EU AI Regulation Article 50.
4. Recipients
Hirevoice does not sell personal data. Data may be disclosed to:
- Government agencies (legal obligations)
- Law enforcement and courts (investigations and proceedings)
- AI model providers (with Standard Contractual Clauses and Article 28 contracts)
- Authorized subprocessors (with prior written approval)
Non-EEA transfers include appropriate safeguards per GDPR standards.
5. Integrations and connected applications
Client companies may connect third-party applications to their Hirevoice workspace: recruitment software through our integration API, and AI assistants through our MCP connector. Connecting is always an act of the client company, performed by one of its administrators, and never enabled by Hirevoice on a client's behalf.
A connected application can reach only the data of the workspace that authorised it. Access is scoped to a single client company and enforced on every request; it does not extend to any other client's data.
Data read by a connected application is transmitted to the provider of that application. Where a client connects an AI assistant, that assistant's provider receives the candidate data the assistant reads, and processes it under the client's own agreement with that provider. Hirevoice is not a party to that relationship and does not control the provider's subsequent handling of the data. Clients are responsible for satisfying themselves, before connecting, that the provider's terms are compatible with their obligations as controller — including any transfer outside the EEA.
Candidate data reached through an integration is not used by Hirevoice to train, tune or improve artificial intelligence models.
A company administrator may revoke any connection in their workspace at any time, from the Hirevoice application. Revocation takes effect immediately: the application's access ends on its next request. Grants and revocations are recorded in an audit log that is retained independently of the accounts involved, so the record of who authorised which access, and when it ended, survives changes of personnel.
6. Rights
Data subjects may exercise access, correction, deletion, processing limitation, data portability, and opposition rights by contacting gdpr@hirevoice.com or the Barcelona address.
Candidates should contact their prospective employer (the responsible controller). Complaints may be filed with Spain's Data Protection Authority (www.aepd.es) or AI Supervision Agency (www.aesia.digital.gob.es).
7. Security measures
Technical and organizational measures per GDPR Article 32 protect data integrity and prevent unauthorized access. Logical data segregation between clients prevents cross-access.
8. Processor obligations
Hirevoice commits to following documented instructions, maintaining confidentiality, implementing appropriate safeguards, limiting subcontracting, assisting with data subject rights requests, conducting impact assessments, and deleting or returning data post-service (except legally required retention).
9. Minors
Services target professional recruitment only. Hirevoice does not knowingly process data of minors under 18. Detected minor data is immediately deleted.
10. Policy updates
Hirevoice reserves modification rights for legislative or judicial changes, with reasonable advance notice.
11. Cookies
This marketing site does not set any cookies required for it to function. With your consent we use analytics cookies to understand site usage and improve the product. The Hirevoice application (used after sign-in) is on a separate subdomain and has its own cookie policy.
You can change your choice at any time on the cookie preferences page.