Last updated:
This Privacy Policy describes how Sieva s.r.o. ("we", "us") collects, processes, and protects personal data in connection with providing the Sieva SaaS platform. It is drafted in accordance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and applicable laws of the Czech Republic.
By using the Service, the User confirms that they have reviewed this Policy. If you do not agree with the terms of data processing, discontinue use of the Service.
The Data Controller within the meaning of Article 4(7) GDPR is:
Sieva s.r.o., registered address: Prague, Czech Republic.
For questions about the processing of personal data or to exercise data subject rights, contact our DPO (Data Protection Officer) at privacy@sieva.eu. We respond to requests within 30 calendar days in accordance with Article 12 GDPR.
We process three main categories of data:
(a) User account data. When you register and use the Service, we collect email address, name, company name, login history, session IP addresses, and basic payment transaction information (once billing launches in Phase 2A). This data is necessary to identify the User and provide the Service.
(b) Candidate data uploaded by the User. The User, acting as Controller for their own hiring processes, uploads candidate data into the Service: names, phone numbers, email addresses, resumes, conversations on Telegram and other messengers, AI-model assessment results, and recruiter notes and comments. In relation to this data, Sieva s.r.o. acts as a Processor within the meaning of Article 28 GDPR — processing is carried out on the User's instructions.
(c) Technical logs and telemetry. Logs of interaction with the interface, client-side events (clicks, navigation, errors), and browser and device information. Used to ensure security, for debugging, and to improve the quality of the Service.
Personal data is processed on the following legal bases (Article 6 GDPR):
(a) Performance of a contract (Art. 6(1)(b)). Processing of account data and User Content is necessary to provide the Service in accordance with the Terms of Service.
(b) Legitimate interest (Art. 6(1)(f)). Processing of technical logs, prevention of fraud and abuse, and improvement of the Service. Before relying on this basis, we carry out a balancing test to ensure the rights of data subjects prevail where applicable.
(c) Consent (Art. 6(1)(a)). Sending marketing communications and use of optional cookies (Analytics/Marketing, once introduced). Consent can be withdrawn at any time without giving reasons.
(d) Legal obligations (Art. 6(1)(c)). Retention of accounting and tax records as required by Czech law.
We engage the following subprocessors to operate the Service:
The full, current list of subprocessors with their jurisdictions is published on the "Subprocessors" page. All subprocessors are bound by a Data Processing Agreement that meets the requirements of Article 28 GDPR.
Some subprocessors (in particular OpenAI and Anthropic) host infrastructure outside the European Economic Area, primarily in the United States. Such transfers are carried out under Standard Contractual Clauses (SCC) adopted by the European Commission in Decision 2021/914, together with additional technical and organizational safeguards (encryption in transit and at rest, pseudonymization).
Where appropriate, we carry out a Transfer Impact Assessment (TIA) in line with EDPB Recommendations 01/2020 and provide a copy of the transfer mechanisms on User request.
We apply the principle of storage limitation (Art. 5(1)(e) GDPR):
Under Articles 15–22 GDPR, data subjects have the following rights:
Requests to exercise these rights can be sent to privacy@sieva.eu. We respond within 30 days; in complex cases the deadline may be extended by a further two months, with notice to the requester.
We use cookies and similar technologies to operate the Service and to remember user preferences. Details are set out in the Cookie Policy.
We may update this Policy from time to time — for example, when we engage new subprocessors or change Service functionality. We notify Users of material changes by email and via an in-Service banner at least 30 days before they take effect.
A version history of the Policy is available on request. Continued use of the Service after changes take effect constitutes acceptance of the updated version.
Data Protection Officer: privacy@sieva.eu.
The DPO's postal address is the same as the registered address of Sieva s.r.o.. We accept requests in English, Russian, and Czech.
Data subjects have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). In the Czech Republic the competent authority is:
Úřad pro ochranu osobních údajů (Czech Data Protection Authority) Pplk. Sochora 27, 170 00 Praha 7, Česká republika Email: posta@uoou.cz Website: https://uoou.gov.cz
Data subjects also have the right to lodge a complaint with the supervisory authority of their habitual residence or of the place of the alleged infringement.