Sync Recruiting CRM Privacy Policy
Provider: Vadym Klius — sole trader registered in the Polish CEIDG business register. NIP (tax ID): 5223057985, REGON: 522352462, e-Delivery address: AE:PL-94907-58696-CJJRC-23. Registered and postal address: ul. Erazma Ciołka 25 lok. 50, 01-445 Warsaw, Poland.
§1. General
- This Privacy Policy (the "Policy") explains how personal data is processed in connection with the website https://syncrecruiting.app and the Sync Recruiting CRM application at https://app.syncrecruiting.app (the "Site" and the "App").
- The App is provided by Vadym Klius, a sole trader entered in the Polish Central Register of Business Activity (CEIDG), principal place of business ul. Erazma Ciołka 25 lok. 50, 01-445 Warsaw, Poland; NIP 5223057985, REGON 522352462 ("Sync", "we", "us").
- Data protection contact: vadym.klius@gmail.com, or by post to ul. Erazma Ciołka 25 lok. 50, 01-445 Warsaw, Poland.
- "GDPR" means Regulation (EU) 2016/679. "Controller", "processor", "personal data", "processing", "recipient" and "data subject" carry the meanings given in Article 4 GDPR.
- This Policy is publicly accessible over HTTPS, requires no login, and is not geo-blocked.
§2. Sync has two roles — this is the key distinction
Sync Recruiting CRM is a multi-tenant SaaS platform for recruitment and temporary-work agencies. Which role we are in depends on whose data it is, and that determines who you should contact.
A. Sync as PROCESSOR — candidate data
For the personal data of candidates, applicants, workers, employer and partner contacts, and anyone else whose data an agency enters into the App or who reaches it through a connected channel:
- the Customer — the recruitment agency using the App — is the controller, not Sync;
- Sync processes that data only on the Customer's documented instructions, on its behalf, under a data processing agreement (Article 28 GDPR);
- Sync does not independently determine the purposes or essential means of processing that data;
- the Customer is responsible for having a lawful basis, for giving candidates the required privacy information (Articles 13–14 GDPR), for setting retention periods, and for handling data subject requests.
B. Sync as CONTROLLER
Sync determines the purposes and means of processing for:
- people representing Customers and user accounts in the App (agency staff): sign-in details, contact details, role, account activity;
- billing and accounting records;
- security logs and audit records relating to how the App runs;
- visitors to the Site and anyone contacting Sync about sales, support or complaints.
Section §5 covers this role. The processor role is covered in §2A and in the separate Data Processing Agreement (DPA).
§3. What data we process
This list reflects the fields and files the App actually handles. Not every agency uses every module, so the data actually processed depends on the Customer's configuration.
3.1. Candidate and applicant data
- Identity and contact: first and last name, email, phone (including international format), gender, date of birth, citizenship, country, city.
- Professional: position, specialisation, years of experience, skills, languages, education, salary expectation and currency, availability, process status, tags, notes.
- Documents and right to work: passport number, visa status, work permit, document validity dates, fields read from the document (MRZ).
- Agency-configured fields (country field sets): including PESEL (the Polish national identification number), account numbers, identification numbers and other fields defined by the Customer.
- Files and media: CVs, documents, scans and photographs of documents, profile photos, recordings.
- Consents: the text and version of the consent, when it was given, the IP address it was given from, a snapshot of the policy URLs in force at that moment, and when it was withdrawn.
The App is not intended for special categories of data under Article 9 GDPR (such as health, origin, beliefs or trade union membership) or criminal conviction data under Article 10 GDPR. Entering such data requires a prior, separate instruction and a risk assessment by the Customer as controller.
3.2. Employer, partner and contact data
- company name, tax and VAT numbers, registration number, address and registered address, industry, size;
- contact person's name, email, phone and role;
- bank details (IBAN, SWIFT, bank name), cooperation terms, rates, commissions, payment terms.
3.3. Communications data
- the content of inbound and outbound messages in connected channels, including attachments;
- channel identifiers for the other party (account ID, username, display name), message IDs, timestamps;
- telephony (if enabled): phone numbers, call direction and status, duration, the call recording, its transcript and summary.
3.4. App user data (agency staff)
- name, work email, role and permissions, avatar, SIP extension, account status, last activity;
- account setup tokens and session data.
3.5. Technical data and logs
- IP address, session and device data, system logs;
- an audit log recording who did what and when, including a snapshot of values before and after each change — that snapshot can contain any field on the record, including higher-risk fields;
- in-app notifications.
§4. Where the data comes from — every intake channel
Data enters the App only through the channels below. Channels marked optional receive data only once an agency has deliberately connected and configured them.
- Public job application form on a vacancy page — name, phone, email, citizenship, an optional passport scan, the consent text, and the IP address the application was sent from.
- Passport OCR preview on that form — the document image is sent purely to read its fields. This step stores no file; the image is processed in memory and discarded. A file is only stored when the form is actually submitted (§10).
- Website chat widget on the agency's site — message content and any contact details provided.
- Telegram (optional) — direct messages, chat ID, sender name and username.
- WhatsApp (optional) — messages and the sender's number.
- Viber (optional) — messages and sender ID.
- Facebook Messenger (optional) — direct messages sent to the agency's Page.
- Instagram Direct (optional) — direct messages sent to the agency's business account.
- Comments on Facebook and Instagram posts (optional) — the comment text, plus the commenter's ID, name and username.
- Meta lead forms (Lead Ads) — not currently active. The App does not today hold the Meta permission required to retrieve lead form submissions, and receives no such data. If that permission is granted and an agency enables the feature, the App will receive the fields a person filled in on the ad form; until then this entry is informational only.
- Gmail mailbox (optional) — the contents of the agency's connected mailbox, under a read-only permission.
- Telephony (optional) — call events and recordings from the carrier.
- Manual entry by a recruiter and import from another system (e.g. Kommo) — any field on a record.
- Partner submissions through a tokenised link — candidate data submitted by one of the agency's partners.
§5. Purposes and legal bases
5.1. Where the agency is the controller (Sync as processor)
The purpose is to provide the App to the agency: receiving applications, maintaining records, communicating with candidates, running recruitment orders, tasks, reporting, security and service continuity. The legal basis towards the candidate is determined by the agency as controller — usually Article 6(1)(b) GDPR (steps prior to entering a contract at the person's request), Article 6(1)(a) GDPR (consent, particularly for future recruitment processes), or Article 6(1)(f) GDPR. Our own basis for processing is the processing agreement with the agency (Article 28 GDPR).
5.2. Where Sync is the controller
- Account registration and running the contract — Article 6(1)(b) and (f) GDPR. Retained for the term of the contract plus the limitation period for claims.
- Billing and accounting obligations — Article 6(1)(c) GDPR. Retained 5 years from the end of the year the accounting document was issued.
- Technical support and service requests — Article 6(1)(b) and (f) GDPR. Retained while the request is handled, plus the limitation period.
- Sales enquiries and demo requests — Article 6(1)(f) GDPR. Retained until you object, and no longer than the limitation period.
- Direct marketing and newsletter — Article 6(1)(f) GDPR together with the separate consent required by the Polish Electronic Communications Law of 12 July 2024 (opt-in). Retained until consent is withdrawn or you object.
- Security, logging and abuse prevention — Article 6(1)(f) GDPR. Retained as set out in §10.
- Establishing, pursuing and defending claims — Article 6(1)(f) GDPR. Retained until the limitation period expires.
Providing data is voluntary, but without the data needed to enter into and perform the contract the App cannot be used. Providing data for marketing purposes is entirely optional.
§6. The AI interview assistant
The App offers agencies an optional AI assistant that holds a first-line conversation with a candidate in a messaging channel (Telegram, Messenger, Instagram Direct, WhatsApp, or the website chat). It is off by default and runs only once an agency turns it on.
6.1. How it works
- It responds; it does not reach out. The assistant only replies after the candidate has messaged first. It does not broadcast and does not initiate contact.
- It asks questions and records the answers. It collects answers to a list of questions defined by the agency and saves them to the contact record. Anything outside that list is discarded.
- It is capped. The conversation has a maximum number of turns (10 by default).
- It hands over to a person. Once it has the information, once the cap is reached, or as soon as the candidate asks to speak to a human, the assistant ends the conversation, writes a summary and notifies the responsible recruiter.
- Model: Google Gemini (gemini-flash-latest). The conversation history — up to the last 30 messages — is sent to the model on each turn, along with the instructions the agency configured.
6.2. No automated decision is made about you
The assistant does not assess, score, rank or reject candidates. It produces no rating, builds no shortlist and makes no decision about whether you continue in the process. Its job is to collect information and hand it to a person. Recruitment decisions are made by the agency, through its staff.
Accordingly, Sync does not make decisions about candidates based solely on automated processing that produce legal effects or similarly significantly affect them within the meaning of Article 22 GDPR. If an agency builds its own process in which the outcome of an assistant conversation leads to automatic rejection without genuine human assessment, responsibility for Article 22 compliance rests with that agency as controller.
6.3. Your right to be told you are talking to an AI
Under Articles 50(1) and 50(5) of Regulation (EU) 2024/1689 (the AI Act), which has applied since 2 August 2026, a person must be informed that they are interacting with an AI system — clearly and distinguishably, and no later than the first interaction.
How to reach a human. At any point in the conversation you can say that you want to speak to a person — the assistant will end the conversation and hand it to a recruiter. You can also contact the agency directly, outside the chat channel.
6.4. What happens to the conversation
The conversation is stored in the App and sent to Google to generate each reply. The model is accessed using an API key belonging to the agency, on the agency's own Google account. That has a consequence we want to state openly:
- on Google's paid tier, Google states that it does not use submitted prompts or responses to improve its products;
- on the free tier, Google reserves the right to use submitted content to develop its products and machine learning technologies, and that content may be reviewed by humans.
Which tier applies is determined by the agency through its own Google account configuration — Sync does not control this and cannot verify it. We advise every agency processing candidate data to use the paid tier only. Sync does not use conversation content to train its own models or for any purpose of its own.
§7. Meta Platform Data
If an agency connects its Facebook Page or Instagram business account, the App receives data from Meta's platforms ("Platform Data"). This covers Messenger messages, Instagram Direct messages and comments on posts. Submissions from Meta lead forms (Lead Ads) are not currently retrieved — the App does not hold the permission required for that (see §4 item 10).
What we receive: the content of messages and comments, the sender's identifier within that Page or account, display name and username, the message or comment ID, and a timestamp.
What we use it for: solely to create and service an enquiry inside the system of the agency that owns that Page or account — so that a recruiter can reply and run the recruitment process.
In relation to Platform Data we commit that we:
- do not sell, license or transfer it to any third party;
- do not use it for advertising, and do not use it to build or enrich advertising profiles;
- do not use it to train machine learning models of Sync, and do not make it available to third parties for that purpose;
- process it only on the instructions of, and for, the specific Customer that owns the Page or account, and for no other person and no other purpose;
- keep it isolated — each Customer's data is separated from every other Customer's at the database level, and no Customer can access another Customer's data;
- delete it when it is no longer needed to provide the service, when the user or Meta asks us to, when the Customer disconnects the integration or stops using the service, and when the law requires it. On disconnection, access credentials are revoked and the associated Platform Data is deleted within the period set out in §10.
Instructions for requesting deletion of data originating from Facebook and Instagram are on a dedicated page: syncrecruiting.app/en/data-deletion.
Meta access credentials are stored encrypted using AES-256-GCM with key versioning; they are never written to logs and never exposed to the browser.
§8. Sub-processors and recipients
These are the parties that can actually process data in connection with running the App. Entries marked optional receive data only if an agency enables that feature.
| Party | Data | Location | Status |
|---|---|---|---|
| Supabase, Inc. | database, authentication, file storage, backups — all App data | eu-north-1 region (Stockholm, EEA) | required |
| Vercel, Inc. | application hosting, serverless functions, logs, content delivery network | functions in cdg1 (Paris); global network layer | required |
| Google LLC — Gemini / Cloud Vision | document images and extracted fields (OCR); AI assistant conversation content | per Google's service terms; API key belongs to the agency | optional |
| Google LLC — Gmail API | contents of the connected mailbox (read-only) | per Google's service terms | optional |
| Meta Platforms, Inc. | Messenger and Instagram Direct messages, comments on posts | per platform terms | optional |
| Telegram | messages and sender identifiers | per platform terms | optional |
| Viber (Rakuten) | messages and sender identifiers | per platform terms | optional |
| Zadarma or another telephony carrier | phone numbers, call metadata, call recordings | per carrier terms | optional |
| GitHub, Inc. | source code only — no production data | per provider terms | required (development) |
| accountants, law firms, auditors | Customer billing data | Poland / EEA | required |
The outbound mail server (SMTP) is configured by the agency in its own settings, so the mail provider is the Customer's choice and the Customer owns that relationship.
Data may be disclosed to public authorities where the law requires it. Processors act under agreements meeting the requirements of Article 28 GDPR. We give Customers advance notice of any planned change to the list of sub-processors involved in candidate data, so they can raise a reasoned objection.
§9. Where data is held, and transfers outside the EEA
- The primary database and file storage holding production data are located in the European Economic Area — Supabase region eu-north-1 (Stockholm, Sweden). Application functions are configured in the cdg1 region (Paris).
- Choosing an EU region does not by itself rule out access or transfer by an entity in a third country. Supabase, Vercel, Google and Meta are subject to United States jurisdiction; access by personnel outside the EEA and a global network layer remain possible under our agreements with those providers. We would rather say this than imply that an EU region alone settles the question.
- Where that happens, the transfer relies on a Chapter V GDPR basis — an adequacy decision of the European Commission (the EU–US Data Privacy Framework, for as long as the provider in question remains certified) or Standard Contractual Clauses, together with a transfer impact assessment and supplementary measures.
- You can obtain a copy of the safeguards we rely on by contacting us at the address in §1.
§10. Retention and deletion
10.1. Candidate data — the agency sets the periods
Retention periods for candidate data are set by the agency as controller, and the App reflects them. Sync does not impose those periods and does not delete candidate data on its own initiative. As a rough guide, Polish market practice is around 12 months for a single recruitment process, around 24 months where separate consent for future recruitment was given, and longer where the controller relies on defending legal claims. The period that binds you is the one in the agency's own privacy notice, not this Policy.
10.2. The raw passport file from the public form
10.3. Everything else
- Messages and conversation history — kept for as long as the agency uses the App; deleted on its instruction. A message deleted in the interface is marked as deleted.
- Audit log and security logs — kept for as long as needed for accountability and security. We do not currently apply automatic deletion to audit records.
- Call recordings — held by the telephony carrier and in the App according to the agency's decision; Sync applies no automatic deletion of its own.
- Customer and App user data (controller role) — as set out in §5.2.
- When an agency's contract ends — at its choice we return the data in a commonly used format or delete it, and we delete remaining copies within 30 days, unless the law requires further retention.
- Backups — expire on a rotation cycle of no more than 30 days; until they expire they stay isolated and are not used in day-to-day operation.
Other than the mechanism described in §10.2, the App does not currently delete data automatically once a set period has elapsed. Deletion happens on the agency's instruction or in response to a data subject request.
§11. Security
We apply technical and organisational measures in line with Articles 25 and 32 GDPR. The following is what is actually implemented:
- encryption in transit — HTTPS/TLS across the whole user–application–API path;
- encryption at rest provided by our infrastructure providers (Supabase, Vercel);
- tenant isolation — every record is bound to an organisation identifier, enforced by PostgreSQL Row Level Security policies in the database itself, not merely in application code;
- role-based access control with per-module permissions, checked server-side on every request;
- private file storage for candidate documents, passports, employer, partner and task documents, with downloads served through short-lived signed URLs;
- encryption of Meta integration credentials using AES-256-GCM with a versioned key ring and context binding; OAuth tokens are stored encrypted;
- audit logging of business and administrative operations (who changed what, and when);
- backups per our database provider's plan;
- input validation, change control, and secrets held only in environment variables — never in code, logs or support tickets.
Personal data breaches. We report any confirmed security incident affecting data entrusted by an agency to that agency without undue delay and no later than 24 hours after we establish it, so the controller can meet its own 72-hour deadline to the Polish supervisory authority. We preserve evidence and logs, contain the impact, remove the cause, and provide a root-cause report. We do not notify individuals or a supervisory authority on an agency's behalf unless the law compels us to.
§12. Your rights
- Data subjects have the right of access and to a copy of their data (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), objection to processing based on legitimate interests (Article 21), and withdrawal of consent at any time without affecting the lawfulness of processing before withdrawal (Article 7(3) GDPR).
- Where to send your request depends on who you are:
- You are a candidate, applicant, employer or partner contact, or you messaged an agency through Messenger, Instagram, Telegram, WhatsApp, Viber or chat → the agency is your controller. Send your request to it. If you send it to us instead, we will forward it to the correct agency no later than the next business day and provide technical assistance; we will not action it ourselves without the agency's instruction, because we are not the controller of that data.
- You hold a user account in the App, represent a Customer, or contacted us directly → Sync is the controller. Write to vadym.klius@gmail.com.
- We respond without undue delay and within one month of receiving a request; in complex cases that period may be extended by a further two months, and we will tell you if it is.
- Exercising these rights is free of charge, requires nobody's approval, and is available regardless of the country you live in.
- Right to complain: you may lodge a complaint with the President of the Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw, Poland) or, if you live elsewhere in the EEA, with your local supervisory authority.
§13. Data deletion
A separate, publicly accessible page explains how to request deletion of your data, including data that came from Facebook and Instagram:
https://syncrecruiting.app/en/data-deletion
That page sets out what data we hold, what will be deleted, how to submit a request and how long it takes. Submitting a request requires no account, no payment and nobody's approval, and it is available regardless of where you live. Once we accept a request you receive a reference number you can use to check its status.
If the data you want deleted belongs to a record set operated by an agency — which is the case for most candidate data — we will forward your request to that agency as controller, assist it in carrying the deletion out, and tell you who the request was passed to.
§14. Cookies and analytics
- syncrecruiting.app uses no analytics tools, no tracking pixels and no advertising cookies. There is no Google Analytics, no Meta Pixel and nothing comparable, which is why the site shows no cookie consent banner — there is nothing to consent to.
- In the App (app.syncrecruiting.app) we use only what is strictly necessary to run the service:
- authentication session cookies — to keep you signed in and to secure the session;
- a language cookie (sync-lang) — to remember the interface language;
- browser local storage — to remember light/dark theme and interface layout.
- We do not profile users, do not build advertising profiles, and do not share usage data with advertising networks.
- If we introduce analytics in future, we will update this Policy and implement a prior-consent mechanism before switching anything on.
§15. Children
The App is a business tool for recruitment agencies and is not directed at anyone under 16. We do not knowingly collect data about children. If we learn that data about someone under 16 has entered the system without a proper basis, we will promptly notify the agency acting as controller and support it in deleting that data. Whether a minor may take part in a recruitment process is a decision for the agency.
§16. Changes to this Policy
- We may update this Policy as the law, the technology or the scope of the service changes.
- We give Customers advance notice of material changes by email or through a message in the App.
- The current version is always available on the Site, with the version number and effective date shown at the top of the document. The version a candidate consented to is recorded alongside that consent.
- This version 2.0 takes effect on 2026-08-07 and replaces version 1.0 of 2026-07-01.
§17. Contact
For anything concerning personal data or this Policy:
Vadym Klius, ul. Erazma Ciołka 25 lok. 50, 01-445 Warsaw, Poland
email: vadym.klius@gmail.com
If your data reached the App through a recruitment agency, please mention that agency's name or the circumstances of the contact — it lets us identify the right controller and pass the matter on faster.