Employer information

Privacy Policy Design Draft

This local design draft maps the topics a future approved Hirello privacy policy would need to address. It does not describe current data practices, create obligations, or provide legal advice.

Local design draft. No privacy practice, right, or obligation described on this page is approved or operative.

1. Who are we?

An approved Hirello privacy policy would need to identify the responsible legal entity, the services in scope, the operating regions, the covered interactions, and the policy boundaries.

2. Who is responsible for your personal information?

An approved policy would need to identify each party responsible for personal information at every stage of an application and explain where an advertiser or another organisation has separate responsibilities.

3. What personal information do we collect?

An approved policy would need to list the personal information Hirello actually collects, the source of each category, why it is needed, and any requirements for information supplied about another person.

4. Do we collect sensitive information?

An approved policy would need to state whether Hirello collects sensitive information, the permitted circumstances, the safeguards required, and the consequences of making information public.

5. How do we collect personal information?

An approved policy would need to document every authorised collection method, including direct collection, automated collection, service providers, linked services, advertisers, and other lawful sources.

6. How do we use your personal information?

An approved policy would need to identify every use purpose, legal basis, automated process, notice requirement, consent requirement, security purpose, service purpose, and compliance purpose.

7. What happens if we cannot collect your personal information?

An approved policy would need to explain which information is optional, which information is required, and what service consequences follow when required information is not provided.

8. Who do we share your personal information with?

An approved policy would need to identify approved recipient categories, disclosure purposes, responsibility boundaries, consent requirements, legal requirements, and the consequences of public access.

9. When do we share personal information overseas?

An approved policy would need to identify any overseas recipients and locations, the reason for each transfer, and every safeguard required by applicable law.

10. How do we keep your information secure?

An approved policy would need to describe the authorised technical, organisational, and physical safeguards, their limitations, account security expectations, and the approved incident contact process.

11. How do we use cookies and usage and device data?

An approved policy would need to identify every cookie, device signal, measurement, provider, purpose, user control, and service effect that has been reviewed and authorised.

12. Retention of your personal information

An approved policy would need to define retention criteria, deletion or de-identification procedures, legal exceptions, backup treatment, and the responsibilities of advertisers and other recipients.

13. Personal information requests

An approved policy would need to list available rights, eligibility requirements, request channels, identity verification, legal exceptions, response handling, marketing controls, and profile consequences.

14. Updates to this Privacy Policy

An approved policy would need to explain how changes are reviewed, published, dated, and made effective, plus when additional notice or consent would be required.

15. Contact us

An approved policy would need to provide verified privacy contact details, accessible format options, complaint handling steps, response expectations, and external escalation routes.

16. Languages

An approved policy would need to state which languages are available, how translations are maintained, and which approved version governs if translations differ.

17. Definitions

An approved policy would need to define its key roles, information categories, technologies, processing activities, service relationships, and other legal terms consistently.

18. Region specific information

An approved policy would need to identify each applicable region, governing legislation, additional rights, organisational obligations, regulator contacts, and conflict rules.