Skip to main content

Legal · BETIHUT-LEGAL-PRIV

Privacy Notice

Entity
XCITERR LTD. · AUTOMAIZE SOLUTIONS LTD
Reg. No.
206478710 · HE 480609
Effective
21 July 2026
Status
Version 1.5 · Effective

This Privacy Notice (the "Notice") explains how XCITERR LTD. (the "Recruitment Operator") and AUTOMAIZE SOLUTIONS LTD (the "Technology Publisher") process personal data in connection with the Betihuti websites, employer portals and iOS and Android candidate applications (together, the "Apps") and the Betihuti hiring service through which candidates build a profile, apply for work, communicate, complete structured artificial-intelligence interviews and receive role matches (the "Service").

This Notice is issued in accordance with Regulation (EU) 2016/679 (the "GDPR") and applicable national data-protection and electronic-communications laws in Cyprus and Bulgaria. References to "we" or "our" mean the entity responsible for the particular purpose described below, and do not merge the two companies into one controller.

1.Controllers, processor relationship and contact details

  1. 1.1XCITERR LTD., Registration No. 206478710, is an independent controller for agency-led job publication, candidate matching and shortlisting, recruitment communications, candidate introductions, assessment review and employment-intermediation compliance.
  2. 1.2AUTOMAIZE SOLUTIONS LTD, Registration No. HE 480609, is an independent controller for platform accounts and authentication, app delivery, platform security and fraud prevention, consent and AI-accountability evidence, technical support, moderation, technology compliance and its own service administration.
  3. 1.3Where Automaize hosts or performs recruitment processing solely on Xciterr's documented instructions, Automaize acts as Xciterr's processor and the parties must apply the terms required by Article 28 GDPR. Where an employer controls a recruitment workflow, the applicable DPA or order must identify whether Xciterr and Automaize act as processors, sub-processors or independent controllers for that specific processing.
  4. 1.4An employer Customer remains an independent controller for its vacancy requirements, employment-law obligations, communications and final hiring decisions.
  5. 1.5You may contact the Betihuti Privacy Lead at privacy@betihuti.com or Xciterr at info@xciterr.com. Requests received by one entity will be routed to the other where necessary, but each entity remains responsible for responding to requests concerning its processing.
  6. 1.6Following a documented Article 37 GDPR assessment dated 16 July 2026, we have not appointed a Data Protection Officer because the current pre-operation processing does not involve large-scale regular and systematic monitoring or large-scale processing of special-category data. A Privacy Lead is available through the published privacy contact. We will reassess this conclusion before material scale, biometric identification or other high-risk processing is introduced.

2.Interpretation

  1. 2.1In this Notice, "personal data", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meanings given to them in the GDPR.
  2. 2.2References to "you" are to the individual whose personal data we process, whether a website visitor, a candidate or a representative of a Customer.
  3. 2.3Headings are included for convenience only and do not affect the interpretation of this Notice.

3.Scope of this Notice

  1. 3.1This Notice applies to visitors to our websites, users of the candidate mobile applications, candidates who register for and use the Service, and representatives of prospective and existing Customers.
  2. 3.2Where Xciterr or Automaize acts as a processor on behalf of a Customer, the relevant Customer's own privacy notice governs that Customer-controlled recruitment processing. This Notice describes the independent-controller processing performed by Xciterr and Automaize and explains the processing chain used to deliver the Service.
  3. 3.3This Notice does not apply to third-party websites, products or services that may be linked from the Website, which are governed by their own privacy notices.

4.Categories of personal data we process

Depending on how you interact with us, we process the following categories of personal data:

  1. 4.1Identity, authentication and contact data, including your name, email address, optional telephone number, account/user identifiers, authentication-provider identifiers and account credentials. We do not receive your password from Apple or Google.
  2. 4.2Profile and preference data, including your CV files, optional profile photo, work history, education, skills, languages, city, country, work authorisation, work-mode and relocation preferences, employer-discovery controls and any information you choose to add to your profile.
  3. 4.3Interview data, including the audio recording and transcript of your structured interview and the scorecard generated against the applicable role rubric. To the extent any such data reveals special categories of personal data within the meaning of Article 9 GDPR, we process it only on the basis of your explicit consent or as otherwise permitted by law.
  4. 4.4Application and engagement data, including roles you view, save or apply to, matches, offers, your status within each recruitment pipeline, notification history and messages exchanged with employers or the AI assistant.
  5. 4.5Technical, security and consent-evidence data, including IP address or a minimized IP-derived region/prefix, browser and device information, app version, session and consent subject identifiers, push-notification tokens, policy versions and hashed IP/user-agent evidence.
  6. 4.6Optional analytics and diagnostics data, including first-party product interactions and mobile crash/performance reports. These transports are off by default and are enabled only after a current choice has been recorded by the consent service; they are not used for advertising or cross-company tracking.
  7. 4.7Communications data, including the content of enquiries, support requests, hiring messages and our responses to them.
  8. 4.8AI accountability data, including the inputs, scores, reasoning, model/prompt/rubric versions, appeal and human-review history needed to explain and audit an automated assessment.

5.Sources of personal data

  1. 5.1Directly from you, when you register, complete your profile, take an interview, apply to roles or contact us.
  2. 5.2Automatically, through your use of the Apps and Service, from essential session/security technology and, only after recorded consent, optional first-party analytics and mobile diagnostics.
  3. 5.3From Customers and third parties, where you are referred to the Service, where a Customer shares limited data to invite you to interview, or where you choose Apple or Google authentication.

6.Google Calendar data

The Google Calendar integration is optional and is initiated by an employer user or interviewer who chooses to connect a work calendar.

  1. 6.1When you connect Google Calendar, Betihuti accesses your Google account identifier and email address, OAuth authorization credentials, busy time ranges, and the owned calendar events needed to create, retrieve, update or cancel an interview event. We do not request access to Gmail, Drive, Contacts or unrelated Google services.
  2. 6.2We use Google Calendar availability only to calculate conflict-free interview slots. Busy windows are processed transiently and are not retained after the available slots have been calculated. We do not access the titles, descriptions, attendees or other content of unrelated calendar events through the free/busy request.
  3. 6.3We use owned-event access only to create and synchronize interview events requested through Betihuti, add the agreed participants and conferencing information, reconcile event status, and update or cancel those events when the interview changes.
  4. 6.4Access and refresh tokens are encrypted at rest with authenticated encryption and protected by access controls. We retain limited connection and subscription metadata, and the related interview booking retains the provider event identifier, scheduled time, participants and meeting details needed to operate and audit the booking.
  5. 6.5We do not sell Google user data, use it for advertising, share raw availability with employers or candidates, or use Google Calendar data to train or improve generalized artificial-intelligence or machine-learning models. Scheduled event details are shared only with the invited participants and service providers necessary to operate and secure the integration.
  6. 6.6You can disconnect Google Calendar from Workspace Integrations. Disconnecting attempts to revoke provider access, removes the stored access and refresh tokens, stops future calendar access, and revokes the local notification subscription. Existing events remain in your Google Calendar, and limited booking or audit records may remain under the retention and legal-hold rules in this Notice. You may request deletion of remaining personal data through your account settings or contact privacy@betihuti.com for assistance.
  7. 6.7Betihuti's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7.Purposes and legal bases of processing

We process personal data only where a lawful basis under Article 6 (and, where relevant, Article 9) GDPR applies, as set out below:

  1. 7.1To create and administer your account and to provide the Service — Article 6(1)(b) (performance of a contract to which you are party).
  2. 7.2To conduct and score your interview and to generate scorecards — Article 6(1)(b); recording is activated only after your specific consent. If interview content incidentally reveals special-category data, we do not seek to infer or use it for matching and apply Article 9 safeguards, including explicit consent where required.
  3. 7.3To match you to suitable roles and disclose evidence to a Customer at your request when you apply — Article 6(1)(b). Optional employer discoverability or sharing beyond a particular application is based on your specific, withdrawable consent under Article 6(1)(a).
  4. 7.4To secure the Service and to prevent fraud, abuse and misuse — Article 6(1)(f) (our legitimate interest in protecting users and the integrity of the Service).
  5. 7.5To maintain, improve and develop the Service using optional first-party analytics or mobile diagnostics only after your recorded consent, and using aggregated or de-identified operational evidence wherever practicable — Article 6(1)(a) and, for necessary service-security analysis, Article 6(1)(f).
  6. 7.6To send you service-related communications and, where you have opted in, marketing communications — Article 6(1)(b) and (f), and Article 6(1)(a) for marketing.
  7. 7.7To comply with our legal and regulatory obligations — Article 6(1)(c).
  8. 7.8We do not sell personal data, use Google Analytics or Vercel Analytics, or use your interview content to train models for purposes unrelated to providing the Service. We do not send optional product events, Sentry browser telemetry or Firebase Crashlytics reports before the applicable consent gate is open.

8.Automated decision-making and profiling

  1. 8.1The Service profiles job-related information by evaluating interview answers and CV/profile evidence against a role-specific rubric and producing a scorecard or match explanation. Automated processing is not automatically an Article 22 decision; Article 22 applies where a decision is based solely on automated processing and has legal or similarly significant effects.
  2. 8.2An automated decline is withheld unless the candidate-facing notice, explanation, contest and human-review safeguards are active. Where a solely automated significant outcome is used, we and the relevant Customer must identify a valid Article 22(2) condition and provide the safeguards required by Article 22(3), including meaningful human intervention.
  3. 8.3We apply safeguards to keep the assessment fair: every candidate for a role family is assessed against the same rubric; the interview is recorded as evidence; and job-relevant language is assessed on the CEFR scale without penalising accent.
  4. 8.4You have the right to obtain human intervention, to express your point of view and to contest any automated outcome. Where a human review changes the outcome, the revised result replaces the automated one in your record. Further detail is set out in our AI Transparency Notice.

9.Marketing communications

  1. 9.1Where you have given your consent, or where otherwise permitted by law, we may send you communications about features, content and opportunities that may be of interest to you.
  2. 9.2You may withdraw your consent and opt out of marketing communications at any time, without charge, by using the unsubscribe mechanism in the relevant communication or by contacting us. Opting out of marketing does not affect service communications necessary to operate your account.

10.Disclosure of personal data

We disclose personal data only as necessary and to the following categories of recipient:

  1. 10.1Customers to which you apply, who receive your profile and interview evidence for so long as your sharing consent remains in place and who may not reuse it once that consent is withdrawn.
  2. 10.2Apple or Google when you deliberately choose their sign-in service, and Firebase Cloud Messaging when you opt into device notifications. Those providers also process data under their own user-facing privacy terms where they act independently.
  3. 10.3Processors and service providers (sub-processors) that host data, assist AI assessment, support scheduling, process payments, monitor security and deliver communications on our behalf under written contracts imposing data-protection obligations consistent with Article 28 GDPR.
  4. 10.4Professional advisers, auditors and insurers, where necessary and subject to confidentiality.
  5. 10.5Competent authorities, courts and regulators, where we are required to do so by law or to establish, exercise or defend legal claims.
  6. 10.6A successor entity, in connection with a merger, acquisition or reorganisation, subject to this Notice.

11.International transfers

  1. 11.1Our default is to host candidate personal data within the European Economic Area (the "EEA").
  2. 11.2Where personal data is transferred to a country outside the EEA, we rely on an adequacy decision of the European Commission or, in its absence, on appropriate safeguards under Article 46 GDPR, principally the Standard Contractual Clauses together with any supplementary measures required following a transfer impact assessment.
  3. 11.3You may request a copy of the relevant safeguards by contacting us at the address in clause 1.

12.Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, after which it is deleted or anonymised:

  1. 12.1Account and profile data is retained while your account is active. The standard account-deletion request immediately disables sign-in and queues permanent erasure of the account, profile, CV/photo/audio objects, applications, messages, push tokens and related product data without support-agent approval.
  2. 12.2CV objects are subject to the approved 12-month cold-file schedule and interview recordings to the approved 90-day schedule unless they are erased earlier through account or application deletion, or a valid legal hold pauses the relevant deletion.
  3. 12.3AI decision audit rows and the associated minimized consent proof are retained without direct account/application/interview links for the approved five-year accountability period, then scheduled for secure deletion. A legal hold may extend only the records within its scope.
  4. 12.4Non-personal technical documentation, quality-management and conformity evidence required for the AI system is maintained separately for the legally required period, which may be ten years under the EU AI Act; it is not used to extend the five-year retention of candidate-level decision evidence.
  5. 12.5Cookie and mobile-analytics consent events normally expire after 395 days; the account link is removed during account deletion. Auth session cookies last up to seven days, the language preference up to one year, and consent cookies up to 395 days.
  6. 12.6Technical and security logs are retained for a limited period for security and troubleshooting. We minimize identifiers and do not treat necessary hosting/security logs as optional product analytics.
  7. 12.7You may request erasure before these periods expire, subject to a documented legal obligation or legal hold. We confirm a deletion request in the app and retain an anonymized completion ticket as evidence.

13.Your rights

Subject to the conditions and exceptions in the GDPR, you have the following rights in relation to your personal data:

  1. 13.1the right of access to your personal data and to obtain a copy of it;
  2. 13.2the right to rectification of inaccurate or incomplete personal data;
  3. 13.3the right to erasure (the "right to be forgotten");
  4. 13.4the right to restriction of processing and the right to object to processing carried out on the basis of legitimate interests;
  5. 13.5the right to data portability;
  6. 13.6the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal; and
  7. 13.7the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
  8. 13.8You may exercise these rights through your privacy settings or by contacting us at privacy@betihuti.com. We will respond within one month of receipt of your request, which period may be extended by two further months where necessary, in accordance with Article 12 GDPR. We do not charge a fee unless a request is manifestly unfounded or excessive.

14.Right to lodge a complaint

  1. 14.1If you consider that our processing of your personal data infringes data-protection law, you have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection (https://www.dataprotection.gov.cy), which is the supervisory authority in the Republic of Cyprus, or with the supervisory authority of your EEA place of residence or work.
  2. 14.2For processing controlled by Xciterr, you may also complain to the Bulgarian Commission for Personal Data Protection. You do not need to determine which authority is competent before contacting either company about your concern.
  3. 14.3We would, however, appreciate the opportunity to address your concerns before you approach the supervisory authority, and encourage you to contact us in the first instance.

15.Cookies and similar technologies

  1. 15.1The websites use cookies and similar technologies as described in our Cookie Policy, which forms part of this Notice. The native mobile apps do not use browser cookies for app operation; their optional analytics/diagnostics preference is recorded through the same consent service.

16.Security

  1. 16.1We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR, including encryption of data in transit and at rest, access controls operating on a least-privilege basis, monitoring and a documented incident-response process. Further detail is set out in our Security Statement.

17.Children

  1. 17.1The Service is intended for persons who are at or above the minimum working age applicable in their jurisdiction. We do not knowingly collect personal data from children, and we will delete such data if we become aware that we hold it.

18.Links to other websites

  1. 18.1The Website may contain links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you.
  2. 18.2We do not control those third-party websites and are not responsible for their privacy practices. We encourage you to read the privacy notice of every website you visit.

19.Changes to this Notice

  1. 19.1We may amend this Notice from time to time to reflect changes in the Service, our practices or applicable law. The version in force is identified by the effective date stated at the head of this document.
  2. 19.2Where changes are material, we will provide notice within the Service or by email before they take effect. Your continued use of the Service after the effective date constitutes acknowledgement of the amended Notice, save where your consent is required.