Sync Recruiting CRM Privacy Policy

Last updated: 2026-08-07 Version: 2.0

Provider: Vadym Klius — sole trader registered in the Polish CEIDG business register. NIP (tax ID): 5223057985, REGON: 522352462, e-Delivery address: AE:PL-94907-58696-CJJRC-23. Registered and postal address: ul. Erazma Ciołka 25 lok. 50, 01-445 Warsaw, Poland.

The short version. Sync Recruiting CRM is software used by recruitment agencies. If you are a candidate and your data is in the system, the agency running the recruitment is the controller of your data — not us. We are its technology provider (a processor) and we act on its instructions. Send requests about your data to that agency; we will pass them on and help the agency act on them. The Data Deletion page explains how to ask.

§1. General

  1. This Privacy Policy (the "Policy") explains how personal data is processed in connection with the website https://syncrecruiting.app and the Sync Recruiting CRM application at https://app.syncrecruiting.app (the "Site" and the "App").
  2. The App is provided by Vadym Klius, a sole trader entered in the Polish Central Register of Business Activity (CEIDG), principal place of business ul. Erazma Ciołka 25 lok. 50, 01-445 Warsaw, Poland; NIP 5223057985, REGON 522352462 ("Sync", "we", "us").
  3. Data protection contact: vadym.klius@gmail.com, or by post to ul. Erazma Ciołka 25 lok. 50, 01-445 Warsaw, Poland.
  4. "GDPR" means Regulation (EU) 2016/679. "Controller", "processor", "personal data", "processing", "recipient" and "data subject" carry the meanings given in Article 4 GDPR.
  5. This Policy is publicly accessible over HTTPS, requires no login, and is not geo-blocked.

§2. Sync has two roles — this is the key distinction

Sync Recruiting CRM is a multi-tenant SaaS platform for recruitment and temporary-work agencies. Which role we are in depends on whose data it is, and that determines who you should contact.

A. Sync as PROCESSOR — candidate data

For the personal data of candidates, applicants, workers, employer and partner contacts, and anyone else whose data an agency enters into the App or who reaches it through a connected channel:

Are you a candidate? The agency running the recruitment is your controller. It must give you its own privacy notice, and it is the party you send requests to (access, rectification, erasure, objection). If you do not know which agency holds your data, write to us — we will identify it and forward your request to the correct controller no later than the next business day.

B. Sync as CONTROLLER

Sync determines the purposes and means of processing for:

Section §5 covers this role. The processor role is covered in §2A and in the separate Data Processing Agreement (DPA).

§3. What data we process

This list reflects the fields and files the App actually handles. Not every agency uses every module, so the data actually processed depends on the Customer's configuration.

3.1. Candidate and applicant data

Higher-risk data — named explicitly. The App may process: PESEL national identification numbers, passport numbers and passport scans/images, residence and right-to-work documents, IBAN and bank details, date of birth, citizenship, address, photographs and images of a person, and call recordings together with their transcripts. Disclosure of this data could enable identity theft or financial harm. We restrict its display, export, download and administrative access to the minimum necessary. We do not claim that these fields are encrypted with a separate key at the individual column level — §11 sets out the protection that is actually in place.

The App is not intended for special categories of data under Article 9 GDPR (such as health, origin, beliefs or trade union membership) or criminal conviction data under Article 10 GDPR. Entering such data requires a prior, separate instruction and a risk assessment by the Customer as controller.

3.2. Employer, partner and contact data

3.3. Communications data

3.4. App user data (agency staff)

3.5. Technical data and logs

§4. Where the data comes from — every intake channel

Data enters the App only through the channels below. Channels marked optional receive data only once an agency has deliberately connected and configured them.

  1. Public job application form on a vacancy page — name, phone, email, citizenship, an optional passport scan, the consent text, and the IP address the application was sent from.
  2. Passport OCR preview on that form — the document image is sent purely to read its fields. This step stores no file; the image is processed in memory and discarded. A file is only stored when the form is actually submitted (§10).
  3. Website chat widget on the agency's site — message content and any contact details provided.
  4. Telegram (optional) — direct messages, chat ID, sender name and username.
  5. WhatsApp (optional) — messages and the sender's number.
  6. Viber (optional) — messages and sender ID.
  7. Facebook Messenger (optional) — direct messages sent to the agency's Page.
  8. Instagram Direct (optional) — direct messages sent to the agency's business account.
  9. Comments on Facebook and Instagram posts (optional) — the comment text, plus the commenter's ID, name and username.
  10. Meta lead forms (Lead Ads)not currently active. The App does not today hold the Meta permission required to retrieve lead form submissions, and receives no such data. If that permission is granted and an agency enables the feature, the App will receive the fields a person filled in on the ad form; until then this entry is informational only.
  11. Gmail mailbox (optional) — the contents of the agency's connected mailbox, under a read-only permission.
  12. Telephony (optional) — call events and recordings from the carrier.
  13. Manual entry by a recruiter and import from another system (e.g. Kommo) — any field on a record.
  14. Partner submissions through a tokenised link — candidate data submitted by one of the agency's partners.

§5. Purposes and legal bases

5.1. Where the agency is the controller (Sync as processor)

The purpose is to provide the App to the agency: receiving applications, maintaining records, communicating with candidates, running recruitment orders, tasks, reporting, security and service continuity. The legal basis towards the candidate is determined by the agency as controller — usually Article 6(1)(b) GDPR (steps prior to entering a contract at the person's request), Article 6(1)(a) GDPR (consent, particularly for future recruitment processes), or Article 6(1)(f) GDPR. Our own basis for processing is the processing agreement with the agency (Article 28 GDPR).

5.2. Where Sync is the controller

Providing data is voluntary, but without the data needed to enter into and perform the contract the App cannot be used. Providing data for marketing purposes is entirely optional.

§6. The AI interview assistant

The App offers agencies an optional AI assistant that holds a first-line conversation with a candidate in a messaging channel (Telegram, Messenger, Instagram Direct, WhatsApp, or the website chat). It is off by default and runs only once an agency turns it on.

6.1. How it works

6.2. No automated decision is made about you

The assistant does not assess, score, rank or reject candidates. It produces no rating, builds no shortlist and makes no decision about whether you continue in the process. Its job is to collect information and hand it to a person. Recruitment decisions are made by the agency, through its staff.

Accordingly, Sync does not make decisions about candidates based solely on automated processing that produce legal effects or similarly significantly affect them within the meaning of Article 22 GDPR. If an agency builds its own process in which the outcome of an assistant conversation leads to automatic rejection without genuine human assessment, responsibility for Article 22 compliance rests with that agency as controller.

6.3. Your right to be told you are talking to an AI

Under Articles 50(1) and 50(5) of Regulation (EU) 2024/1689 (the AI Act), which has applied since 2 August 2026, a person must be informed that they are interacting with an AI system — clearly and distinguishably, and no later than the first interaction.

Where this actually stands as of the date of this Policy. The wording of the first message and how the assistant introduces itself are configured by the agency, and the App does not currently enforce an automatic notice that the conversation is with an AI system. The duty to inform the candidate therefore sits with the agency, which must configure that first message so that it clearly and understandably states that an automated assistant is conducting the conversation. We say this plainly rather than claim a safeguard the software does not yet enforce.

How to reach a human. At any point in the conversation you can say that you want to speak to a person — the assistant will end the conversation and hand it to a recruiter. You can also contact the agency directly, outside the chat channel.

6.4. What happens to the conversation

The conversation is stored in the App and sent to Google to generate each reply. The model is accessed using an API key belonging to the agency, on the agency's own Google account. That has a consequence we want to state openly:

Which tier applies is determined by the agency through its own Google account configuration — Sync does not control this and cannot verify it. We advise every agency processing candidate data to use the paid tier only. Sync does not use conversation content to train its own models or for any purpose of its own.

§7. Meta Platform Data

If an agency connects its Facebook Page or Instagram business account, the App receives data from Meta's platforms ("Platform Data"). This covers Messenger messages, Instagram Direct messages and comments on posts. Submissions from Meta lead forms (Lead Ads) are not currently retrieved — the App does not hold the permission required for that (see §4 item 10).

What we receive: the content of messages and comments, the sender's identifier within that Page or account, display name and username, the message or comment ID, and a timestamp.

What we use it for: solely to create and service an enquiry inside the system of the agency that owns that Page or account — so that a recruiter can reply and run the recruitment process.

In relation to Platform Data we commit that we:

Instructions for requesting deletion of data originating from Facebook and Instagram are on a dedicated page: syncrecruiting.app/en/data-deletion.

Meta access credentials are stored encrypted using AES-256-GCM with key versioning; they are never written to logs and never exposed to the browser.

§8. Sub-processors and recipients

These are the parties that can actually process data in connection with running the App. Entries marked optional receive data only if an agency enables that feature.

PartyDataLocationStatus
Supabase, Inc.database, authentication, file storage, backups — all App dataeu-north-1 region (Stockholm, EEA)required
Vercel, Inc.application hosting, serverless functions, logs, content delivery networkfunctions in cdg1 (Paris); global network layerrequired
Google LLC — Gemini / Cloud Visiondocument images and extracted fields (OCR); AI assistant conversation contentper Google's service terms; API key belongs to the agencyoptional
Google LLC — Gmail APIcontents of the connected mailbox (read-only)per Google's service termsoptional
Meta Platforms, Inc.Messenger and Instagram Direct messages, comments on postsper platform termsoptional
Telegrammessages and sender identifiersper platform termsoptional
Viber (Rakuten)messages and sender identifiersper platform termsoptional
Zadarma or another telephony carrierphone numbers, call metadata, call recordingsper carrier termsoptional
GitHub, Inc.source code only — no production dataper provider termsrequired (development)
accountants, law firms, auditorsCustomer billing dataPoland / EEArequired

The outbound mail server (SMTP) is configured by the agency in its own settings, so the mail provider is the Customer's choice and the Customer owns that relationship.

Data may be disclosed to public authorities where the law requires it. Processors act under agreements meeting the requirements of Article 28 GDPR. We give Customers advance notice of any planned change to the list of sub-processors involved in candidate data, so they can raise a reasoned objection.

§9. Where data is held, and transfers outside the EEA

  1. The primary database and file storage holding production data are located in the European Economic Area — Supabase region eu-north-1 (Stockholm, Sweden). Application functions are configured in the cdg1 region (Paris).
  2. Choosing an EU region does not by itself rule out access or transfer by an entity in a third country. Supabase, Vercel, Google and Meta are subject to United States jurisdiction; access by personnel outside the EEA and a global network layer remain possible under our agreements with those providers. We would rather say this than imply that an EU region alone settles the question.
  3. Where that happens, the transfer relies on a Chapter V GDPR basis — an adequacy decision of the European Commission (the EU–US Data Privacy Framework, for as long as the provider in question remains certified) or Standard Contractual Clauses, together with a transfer impact assessment and supplementary measures.
  4. You can obtain a copy of the safeguards we rely on by contacting us at the address in §1.

§10. Retention and deletion

10.1. Candidate data — the agency sets the periods

Retention periods for candidate data are set by the agency as controller, and the App reflects them. Sync does not impose those periods and does not delete candidate data on its own initiative. As a rough guide, Polish market practice is around 12 months for a single recruitment process, around 24 months where separate consent for future recruitment was given, and longer where the controller relies on defending legal claims. The period that binds you is the one in the agency's own privacy notice, not this Policy.

10.2. The raw passport file from the public form

Stating the actual position. A passport image or PDF submitted through the public application form goes into private storage and is marked for deletion 30 days after submission. Automatic execution of that deletion is not currently running — the mechanism is implemented but is not yet triggered by a scheduler. Until it is, files of this kind are deleted on request and through the request handling described in §12 and §13. We state this openly, because claiming a working automatic deletion would not be true. The fields read from the document (name, number, dates) are text data and follow the retention period set by the agency.

10.3. Everything else

Other than the mechanism described in §10.2, the App does not currently delete data automatically once a set period has elapsed. Deletion happens on the agency's instruction or in response to a data subject request.

§11. Security

We apply technical and organisational measures in line with Articles 25 and 32 GDPR. The following is what is actually implemented:

What we do not claim. We do not state that PESEL numbers, passport numbers or IBANs are encrypted with a separate key at the individual column level — that has not been implemented. Protection for those fields rests on infrastructure encryption, TLS, private file storage, tenant isolation, permission control, restricted access and operation logging. We also do not claim application-level encryption for API keys or for channel credentials other than Meta's. We would rather describe the protection that exists than claim one that does not.

Personal data breaches. We report any confirmed security incident affecting data entrusted by an agency to that agency without undue delay and no later than 24 hours after we establish it, so the controller can meet its own 72-hour deadline to the Polish supervisory authority. We preserve evidence and logs, contain the impact, remove the cause, and provide a root-cause report. We do not notify individuals or a supervisory authority on an agency's behalf unless the law compels us to.

§12. Your rights

  1. Data subjects have the right of access and to a copy of their data (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), objection to processing based on legitimate interests (Article 21), and withdrawal of consent at any time without affecting the lawfulness of processing before withdrawal (Article 7(3) GDPR).
  2. Where to send your request depends on who you are:
    • You are a candidate, applicant, employer or partner contact, or you messaged an agency through Messenger, Instagram, Telegram, WhatsApp, Viber or chat → the agency is your controller. Send your request to it. If you send it to us instead, we will forward it to the correct agency no later than the next business day and provide technical assistance; we will not action it ourselves without the agency's instruction, because we are not the controller of that data.
    • You hold a user account in the App, represent a Customer, or contacted us directlySync is the controller. Write to vadym.klius@gmail.com.
  3. We respond without undue delay and within one month of receiving a request; in complex cases that period may be extended by a further two months, and we will tell you if it is.
  4. Exercising these rights is free of charge, requires nobody's approval, and is available regardless of the country you live in.
  5. Right to complain: you may lodge a complaint with the President of the Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw, Poland) or, if you live elsewhere in the EEA, with your local supervisory authority.

§13. Data deletion

A separate, publicly accessible page explains how to request deletion of your data, including data that came from Facebook and Instagram:

https://syncrecruiting.app/en/data-deletion

That page sets out what data we hold, what will be deleted, how to submit a request and how long it takes. Submitting a request requires no account, no payment and nobody's approval, and it is available regardless of where you live. Once we accept a request you receive a reference number you can use to check its status.

If the data you want deleted belongs to a record set operated by an agency — which is the case for most candidate data — we will forward your request to that agency as controller, assist it in carrying the deletion out, and tell you who the request was passed to.

§14. Cookies and analytics

  1. syncrecruiting.app uses no analytics tools, no tracking pixels and no advertising cookies. There is no Google Analytics, no Meta Pixel and nothing comparable, which is why the site shows no cookie consent banner — there is nothing to consent to.
  2. In the App (app.syncrecruiting.app) we use only what is strictly necessary to run the service:
    • authentication session cookies — to keep you signed in and to secure the session;
    • a language cookie (sync-lang) — to remember the interface language;
    • browser local storage — to remember light/dark theme and interface layout.
    These are necessary to deliver a service you have requested and do not require separate consent.
  3. We do not profile users, do not build advertising profiles, and do not share usage data with advertising networks.
  4. If we introduce analytics in future, we will update this Policy and implement a prior-consent mechanism before switching anything on.

§15. Children

The App is a business tool for recruitment agencies and is not directed at anyone under 16. We do not knowingly collect data about children. If we learn that data about someone under 16 has entered the system without a proper basis, we will promptly notify the agency acting as controller and support it in deleting that data. Whether a minor may take part in a recruitment process is a decision for the agency.

§16. Changes to this Policy

  1. We may update this Policy as the law, the technology or the scope of the service changes.
  2. We give Customers advance notice of material changes by email or through a message in the App.
  3. The current version is always available on the Site, with the version number and effective date shown at the top of the document. The version a candidate consented to is recorded alongside that consent.
  4. This version 2.0 takes effect on 2026-08-07 and replaces version 1.0 of 2026-07-01.

§17. Contact

For anything concerning personal data or this Policy:
Vadym Klius, ul. Erazma Ciołka 25 lok. 50, 01-445 Warsaw, Poland
email: vadym.klius@gmail.com

If your data reached the App through a recruitment agency, please mention that agency's name or the circumstances of the contact — it lets us identify the right controller and pass the matter on faster.