employza
Last updated: 10 September 2026
Privacy Policy
Who We Are and How to Contact Us
1.1. Employza is a modern global AI work platform that uses artificial intelligence, including agentic systems, to support people and organisations in work, career development, recruitment and workforce operations. The Service is operated, and personal data processed for Employza's own purposes is controlled, by Krzysztof Rąpała, operating under the Employza brand ("Employza", "we", "us" or "our").
1.2. Privacy, rights and Service enquiries may be sent to support@employza.pl.
1.3. This Policy applies to Employza websites, accounts, dashboards, job and candidate services, Vision, Vision Advisor, Vision Intelligence, QuickShift, Interview AI, Voice Search AI, AI Profile Sync, Hiring Copilot, Smart Apply, Research & Insights and related services that link to this Policy (the "Service").
1.4. Employza is normally the controller for account administration, platform operation, matching and recommendations, security, billing, support and product communications. An employer is an independent controller for its own recruitment decisions and for personal data it receives or exports from the Service. If a separate written agreement lawfully assigns a processor role, that agreement governs that processing.
Scope and Core Privacy Principles
2.1. We process personal data lawfully, fairly and transparently; collect it for specified purposes; limit it to what is relevant; keep it accurate where reasonably possible; retain it no longer than necessary; and protect it with proportionate safeguards.
2.2. We do not sell personal data. We do not use personal data for cross-context behavioural advertising without the choice required by applicable law. We do not condition access to the core Service on consent to optional marketing.
2.3. The Service is designed for work, recruitment and professional development. Users should not provide passwords, payment-card security codes, national identity documents, health information, political opinions, biometric identifiers or other sensitive data unless a specific, lawful and clearly identified workflow requires it.
2.4. This Policy describes our current practices. Exact feature access, limits and available controls are determined by the current authenticated product and plan.
Personal Data We Process
Depending on how a person uses Employza, we may process:
(a) identity and account data, including name, email address, telephone number, role, account identifiers, authentication status, language and account settings;
(b) candidate and professional data, including profile fields, CVs, education, experience, skills, languages, preferences, availability, location preferences, portfolio links, generated documents, saved jobs or collections and information supplied in applications;
(c) employer and organisation data, including business contact details, organisation profile and branding, verification records, authorised users, job offers and promotions, hiring settings, team assignments, approvals, operational notes, recorded outcomes, shared organisation rules or memory, candidate notes, interview information and application-status actions;
(d) application and recruitment data, including selected job, submitted materials, application status, employer actions, interview and scheduling workflow, outreach and follow-up records, Hiring Copilot output and verified submission records for internal Employza applications;
(e) communications and AI interaction data, including prompts, messages, conversation history, feedback, voice transcriptions, uploaded chat files, requested actions, confirmations and generated outputs;
(f) billing and transaction data, including selected package, currency, price, payment status, transaction reference, billing cycle, invoice information and cancellation or dispute status. Employza does not need to store full payment-card details when payment is handled by a payment provider;
(g) consent, preference and rights-request data, including cookie choices, marketing subscription status, Personal Memory consent, data-export requests, account-deletion requests and related audit evidence;
(h) technical, usage and security data, including IP address, timestamps, device and browser information, session or visitor identifiers, pages and features used, diagnostic events, rate-limit signals, authentication events and suspected abuse; and
(i) public professional and job data obtained from employer career pages, official recruitment feeds, public organisation pages or other lawful public sources.
Where Personal Data Comes From
4.1. We receive data directly from the User when an account is created, a profile or organisation is completed, a document is uploaded, an application is submitted, an AI conversation is started, a purchase is made, a consent is recorded or support is contacted.
4.2. We may receive data from another authorised User, for example when an employer changes the status of an internal application, records an interview event or adds authorised organisation information.
4.3. If the User chooses a third-party sign-in or payment service, that provider sends the minimum account or transaction information needed to complete the requested operation under its own notice and the User's choices.
4.4. We collect limited technical and usage data automatically when the Service is used. Optional analytics or marketing technologies operate only after the choice required by applicable law.
4.5. External job and company information may come from public employer websites, official applicant-tracking-system feeds, public APIs or other public professional sources. We process only information relevant to presenting and maintaining legitimate work opportunities.
Purposes and Legal Bases
We process personal data for the following purposes and, where the GDPR or an equivalent framework applies, on the following legal bases:
(a) to create and administer an account, deliver requested features, display jobs, manage profiles, process internal applications, provide purchased plans and respond to User instructions — performance of a contract or steps requested before a contract;
(b) to operate search, matching, recommendations, AI assistance, document processing, interviews, voice features and confirmed agent actions — performance of a contract and, for optional elements expressly activated by the User, consent where required;
(c) to process payments, invoices, cancellations, statutory withdrawal requests and transaction records — performance of a contract and compliance with legal obligations;
(d) to protect accounts, prevent fraud and abuse, preserve service integrity, diagnose failures, defend legal claims and improve reliability — our legitimate interests or those of Users, balanced against individual rights;
(e) to comply with tax, accounting, consumer, employment-platform, data-protection, law-enforcement and other binding legal duties — compliance with a legal obligation;
(f) to send Research & Insights or other optional marketing communications — consent, or another basis expressly permitted by local law, with an effective opt-out in every message; and
(g) to establish, exercise or defend legal claims and respond to competent authorities — legitimate interests and legal obligations.
Where we rely on consent, it may be withdrawn at any time without affecting processing already carried out lawfully. Where we rely on legitimate interests, a User may object on grounds relating to their particular situation.
Jobs, Matching, Applications and Employer Workflows
6.1. Employza uses profile, document-derived, preference and job data to search, filter and recommend opportunities or candidates. Matching is probabilistic decision support, not a guarantee of suitability, employment, candidate availability or recruitment success.
6.2. Smart Apply and Vision application actions operate only for supported internal Employza jobs. The candidate reviews and explicitly confirms the exact internal selection before submission. External offers are identified for manual completion on the employer's or recruitment provider's website; Employza does not treat opening an external link as a completed application.
6.3. Internal applications create records visible to the candidate and the relevant Employza employer. Hiring Copilot may generate five advisory areas for an eligible internal application: candidate overview, role-specific fit, strengths, matters to verify and interview questions. It does not accept, reject or contact the candidate and does not make an employment decision.
6.4. Employers determine their own recruitment purposes, lawful basis, interview process and employment decisions. They must use candidate data only for lawful recruitment, limit access to authorised personnel, preserve confidentiality and independently satisfy employment, equality and data-protection law.
6.5. QuickShift includes a separate candidate participation and visibility choice. Candidate contact details remain restricted until an authorised reveal is requested and permitted. A public profile alone does not constitute QuickShift participation or permission to disclose contact data.
Vision, Documents, Voice, Interview AI and Personal Memory
7.1. Vision Chat provides conversational assistance without private account access or account actions. Eligible Vision Advisor, Vision Intelligence and administrative surfaces may use authorised account context and tools according to the authenticated role, current plan, confirmation state and server-side permissions.
7.2. AI Profile Sync, Document Matching AI and application-document features may extract and structure information from readable or scanned documents, propose profile updates, generate truthful professional materials or derive job-search criteria. Users must verify generated or extracted information before relying on or submitting it.
7.3. Temporary files attached in Vision or QuickShift chat are retained for up to one hour and then scheduled for deletion. Files deliberately saved to a User's Documents area follow account-document retention instead.
7.4. Voice Search AI and realtime voice features process audio after the User activates microphone access. Audio is used to transcribe or deliver the requested live interaction. Employza does not use these features for speaker identification or persistent voiceprints. Interview AI is a practice environment, not an employer interview. Full audio recordings and replayable full transcripts are not retained as interview-session records; an eligible plan may provide a concise summary.
7.5. Vision Personal Memory is optional and off by default. When expressly enabled, it stores selected non-sensitive preferences and continuity facts. Only relevant items are loaded for a conversation. Users can inspect, add, correct, delete, pause or reset Memory in Account settings. Each item expires no later than 365 days after creation or update unless deleted earlier. Memory never grants a role, plan, permission, confirmation or access right.
7.6. To calculate plan usage and ensure that Realtime sessions are measured correctly, we process technical session metadata such as start and end times, duration, completion or interruption status, and the product feature used. Billable time is not determined from the content of the conversation.
Cookies, Browser Storage and Analytics
8.1. Strictly necessary cookies and similar storage support authentication, security, consent records, language, service continuity, guest Vision limits and interface state. Optional analytics and marketing categories require the choice described in the Cookie Policy where applicable.
8.2. With analytics consent, we may measure visits, feature use and reliability using an analytics provider. We use this information to understand aggregate product performance, not to make employment decisions.
8.3. Browser storage may hold language, interface preferences, active-chat references, temporary state and other data needed to provide the requested experience. Users can remove it through browser controls; doing so may sign the User out or reset preferences.
8.4. The current categories, identifiers, durations and preference controls are described in the Cookie Policy at /cookies.
Recipients and Disclosure
We disclose personal data only as necessary to:
(a) the employer receiving an internal application and its authorised organisation Users;
(b) providers of infrastructure, hosting, storage, email, authentication, payment, analytics, customer support, security and AI processing acting under contract and appropriate confidentiality or data-protection terms;
(c) professional advisers, auditors, insurers and potential transaction counterparties subject to appropriate safeguards;
(d) competent courts, regulators, law-enforcement bodies or other authorities where disclosure is legally required or necessary to protect rights and safety; and
(e) a successor in a lawful merger, financing, reorganisation or transfer of the Service, subject to notice and applicable rights.
External job pages and third-party services are independent environments. Information submitted directly there is governed by their privacy notices, not by this Policy.
International Data Transfers
10.1. Employza may use service providers that process data in countries other than the country in which the User is located. Where personal data protected by EEA, UK or Swiss law is transferred outside the relevant protected area, we use an applicable adequacy decision, approved standard contractual clauses, another lawful transfer mechanism and, where appropriate, supplementary safeguards.
10.2. Users may request information about the applicable transfer safeguard by contacting support@employza.pl. Commercially confidential or security-sensitive material may be redacted, but the information required by law will be provided.
10.3. No transfer mechanism reduces mandatory rights available in the User's jurisdiction.
Retention and Deletion
11.1. We retain personal data only for the period needed for the stated purpose, the active account or contract, security and dispute resolution, and mandatory legal recordkeeping.
11.2. Account profiles, saved documents, conversation history, internal application records and organisation operational records are generally retained while the account, organisation workspace or relevant workflow remains active, unless the authorised User deletes them earlier or a legal obligation requires temporary preservation. Account or organisation deletion initiates deletion of linked files and role- or workspace-specific records, subject to the exceptions below and the rights of other authorised organisation Users.
11.3. Temporary chat attachments are retained for up to one hour. Personal Memory items are retained for no more than 365 days. Consent and transaction evidence is kept for the period needed to demonstrate compliance. Tax, accounting and payment records are retained for the statutory period, ordinarily at least five years where Polish law applies. Security and legal-claim records may be retained until the relevant risk, investigation or limitation period ends.
11.4. Data in protected backups is removed through the normal backup cycle and is not restored for ordinary product use after a valid deletion. Data may be preserved longer where required by law, a binding order, fraud prevention, payment dispute or legal hold.
11.5. Properly anonymised aggregate information that can no longer identify a person may be retained for statistics, reliability and research.
Security and Confidentiality
12.1. We use proportionate organisational and technical safeguards appropriate to the nature of the data and risk, including access control, authentication protections, encryption in transit, restricted administrative access, logging, backup, abuse prevention and incident response.
12.2. No online service can guarantee absolute security. Users must protect credentials, use accurate account contact details, keep devices secure and notify support@employza.pl promptly of suspected unauthorised access.
12.3. If a personal-data breach creates a notification duty, we will notify the competent authority and affected individuals within the periods and with the information required by applicable law.
Individual Rights and Choices
13.1. Depending on applicable law, a person may request access, correction, deletion, restriction, portability, withdrawal of consent, objection to legitimate-interest processing and information about relevant automated processing. A User may also manage many records directly in Account settings, delete conversation threads, control Memory, unsubscribe from Research & Insights and request an account data export.
13.2. Requests may be sent to support@employza.pl. We may need proportionate information to verify identity and authority. We respond within the applicable legal period and explain any lawful limitation or refusal.
13.3. A person in the EEA may complain to the supervisory authority in their habitual residence, place of work or place of an alleged infringement. In Poland, the authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
13.4. Residents of jurisdictions that provide additional privacy rights, including certain United States states, Brazil, Canada and other regions, may use the same contact to request confirmation of processing, access to categories or specific data, correction, deletion, portability, restriction or an appeal where the applicable law provides that right. An authorised agent may submit a request where local law permits and the required authority and identity can be verified.
13.5. Employza does not sell personal data, does not operate a financial-incentive programme for personal data and does not use sensitive personal data to infer characteristics outside the purposes disclosed in this Policy. Where applicable law provides an opt-out from sale, sharing, targeted advertising or qualifying profiling, the same contact and available consent controls may be used. We will not unlawfully discriminate against a person for exercising a privacy right.
Automated Processing, Profiling and Human Oversight
14.1. Search ordering, matching, recommendations, extraction, summaries and Hiring Copilot may involve automated processing or profiling. Typical inputs and limitations are explained in the AI Transparency Notice at /ai-transparency-notice.
14.2. Employza does not make a decision producing legal or similarly significant effects on a candidate solely through these outputs. Employers and authorised human Users remain responsible for recruitment, employment and workforce decisions.
14.3. A User may correct underlying profile information, choose different search criteria, disregard recommendations and ask for human review where applicable. If a future feature would use solely automated decision-making within Article 22 GDPR or an equivalent law, it will not be activated without a valid legal basis, prior notice and the safeguards required by law.
Children and Sensitive Situations
15.1. The Service is not directed to children who cannot lawfully enter into the relevant digital-service agreement. A person below the age of legal capacity or the applicable digital-consent age may use the Service only with the authorisation required by local law. Employer accounts and actions on behalf of an organisation are for adults with authority to bind that organisation.
15.2. If we learn that personal data was collected from a child without the required authorisation, we will take reasonable steps to restrict or delete it. A parent or guardian may contact support@employza.pl.
15.3. Users must not use Employza to infer protected characteristics, discriminate unlawfully, exploit vulnerable people or make decisions about health, credit, insurance, immigration, criminal justice or another incompatible high-impact purpose.
Changes, Language and Further Information
16.1. We may update this Policy when the Service, law or processing practices change. The current date appears at the top. Material changes will be communicated in the Service or by email where required. New consent will be requested when a change cannot lawfully rely on the existing basis.
16.2. Translations are provided for accessibility. The English version is the reference version for international business interpretation. This does not limit mandatory consumer, employment or data-protection rights, including any right to receive information in another language.
16.3. Questions, rights requests and requests for further information may be sent to support@employza.pl.
Scheduled Tasks and Recurring Agent Processing
17.1. When a User creates a Scheduled task, we process its instruction, schedule, timezone, status, required criteria, selected-document reference, confirmation record, run results, sources, artifact links and the control data needed to execute and manage it.
17.2. This processing delivers the requested ongoing agent service and records its authorised scope. It relies on performance of a contract or steps requested by the User and, where law requires, consent. The authorisation is limited to the recorded task and does not extend to unrelated actions or external applications.
17.3. We check the current role, plan entitlement and stored authorisation before each run. If the entitlement ends, processing stops and the records are retained under Section 11 so the User can inspect, pause, resume or delete the task. A later payment alone never restarts processing.
Storage Files, Quotas and Retention
18.1. When an authenticated User stores files in Employza, we process the file content and metadata needed to provide the private Library, including name, type, size, owner, creation time, product source and deletion state. We also process account quota usage and the capacity, start date and expiry date of applicable plans and Storage purchases.
18.2. This processing is necessary to provide the requested storage service, secure access, enforce the combined account limit, complete billing and manage expiry. Files may contain personal data supplied or generated by the User; the User should store only material needed for the intended work or recruitment purpose.
18.3. Files remain while the account has sufficient active capacity or during the 30-day over-quota protection period. If use remains above the available quota after that period, the oldest files may be permanently deleted until use fits the quota. User deletion and account deletion also initiate deletion, subject to legal holds and the normal protected-backup cycle described in Section 11. Billing and transaction evidence is retained separately for the legally required period.