CoHire AI Privacy Policy
Last Updated: June 10, 2026
1. Introduction
CoHire AI Limited ("CoHire AI," "we," "us," or "our") is committed to protecting your privacy and Personal Data. This Privacy Policy explains how we collect, use, disclose, and protect information about you when you use our Platform, including our website, mobile applications, and AI-powered recruitment services.
We comply with applicable data protection laws, including the Kenya Data Protection Act, 2019, GDPR (for EU users), and other relevant privacy regulations. By using our Platform, you acknowledge that you have read and understood this Privacy Policy.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person
- "Processing" means any operation performed on Personal Data
- "Data Controller" means the entity that determines the purposes and means of Processing
- "Data Processor" means the entity that Processes Personal Data on behalf of the Controller
- "Data Subject" means the individual to whom Personal Data relates
3. Data Controller Information
CoHire AI Limited
Email: privacy@cohire.ai
Physical Address: Nairobi, Kenya
Data Protection Officer: dpo@cohire.ai
4. Personal Data We Collect
4.1 Candidate Data
- Identity Data: Name, date of birth, gender, nationality, identification documents
- Contact Data: Email address, phone number, physical address
- Professional Data: Resume/CV, work history, education, certifications, skills
- Interview Data: Video recordings, audio responses, behavioral analysis
- Assessment Data: Test scores, psychometric results, skills evaluations
- Preference Data: Job preferences, location preferences, salary expectations
- Technical Data: IP address, device information, browser type, usage logs
- Communication Data: Messages, feedback, support inquiries
4.2 Employer/Recruiter Data
- Company Data: Business name, registration details, industry, size
- Contact Data: Representative names, titles, email addresses, phone numbers
- Payment Data: Billing information, payment method details, transaction history
- Usage Data: Platform activity, feature usage, analytics
- Job Data: Job postings, requirements, evaluation criteria
4.3 Sensitive Personal Data
We may collect certain sensitive data with explicit consent:
- Biometric Data: Facial recognition data from video interviews
- Health Data: Disability information for accommodation purposes
- Background Check Data: Criminal records, credit history (where legally permitted)
5. How We Collect Personal Data
5.1 Direct Collection
- Account registration and profile creation
- Job applications and interview submissions
- Subscription purchases and payment processing
- Customer support interactions
- User surveys and feedback forms
5.2 Automated Collection
- Cookies and similar tracking technologies
- Server logs and analytics tools
- AI analysis of video and audio content
- Device and browser information
5.3 Third-Party Sources
- Linked social media profiles (with consent)
- Integrated ATS/HRIS systems
- Background check providers (with consent)
- Publicly available professional information
6. Purposes of Processing
6.1 Service Delivery
- Providing Platform functionality
- Matching candidates with job opportunities
- Facilitating communication between users
- Processing payments and subscriptions
- Delivering customer support
6.2 AI and Analytics
- Training and improving AI models
- Generating candidate assessments
- Providing predictive analytics
- Detecting bias and ensuring fairness
- Conducting research and development
6.3 Legal Compliance
- Meeting regulatory requirements
- Responding to legal requests
- Preventing fraud and abuse
- Enforcing Terms of Service
- Protecting intellectual property rights
6.4 Marketing and Communications
- Sending service-related notifications
- Providing product updates
- Conducting marketing campaigns (with consent)
- Personalizing user experience
- Soliciting feedback
7. Legal Bases for Processing
7.1 Contractual Necessity
Processing is necessary for the performance of our Terms of Service with users.
7.2 Legitimate Interests
Processing is necessary for our legitimate business interests, including:
- Platform improvement and development
- Fraud prevention and security
- Marketing to existing users
- Business analytics and reporting
7.3 Consent
We rely on consent for:
- Processing sensitive Personal Data
- Marketing communications
- Third-party data sharing beyond service provision
- AI training with personal identifiers
7.4 Legal Obligations
Processing is necessary to comply with applicable laws and regulations.
8. AI-Specific Processing
8.1 AI Training and Development
- We use aggregated, anonymized data to train AI models
- Personal identifiers are removed or pseudonymized for training
- Users may opt-out of AI training with their personal data
8.2 Automated Decision-Making
- AI provides recommendations and scores, not final decisions
- Users have the right to request human review of AI decisions
- We provide explanations of AI logic upon request
- Users may contest AI-generated assessments
8.3 Bias Detection and Mitigation
- We regularly test AI models for demographic bias
- We implement fairness constraints in AI algorithms
- Users can report suspected bias or discrimination
- We provide transparency about AI training data sources
9. Data Sharing and Disclosure
9.1 Within CoHire AI
- Authorized personnel access data based on job requirements
- Data is shared across teams for service provision and improvement
- Access controls and monitoring prevent unauthorized use
9.2 With Other Users
- Candidate profiles are shared with potential employers
- Employer job requirements are shared with candidates
- Interview recordings are accessible to relevant employers
- Users control visibility settings for their content
9.3 With Service Providers
- Cloud hosting and infrastructure providers
- Payment processing services
- Customer support platforms
- Analytics and monitoring tools
- Background check providers (with consent)
9.4 With Authorities
- Law enforcement agencies when legally required
- Regulatory bodies for compliance purposes
- Courts and legal proceedings
- Government agencies for national security
10. International Data Transfers
10.1 Transfer Mechanisms
- Data is processed primarily in Kenya but may be accessed globally
- We implement appropriate safeguards for international transfers
- Standard Contractual Clauses are used where required
- Users consent to necessary international transfers
10.2 Data Localization
- Some countries require data to remain within their borders
- We comply with applicable data localization requirements
- Users are notified of data transfer locations
11. Data Retention
11.1 Retention Periods
- Active Accounts: Data retained while account is active
- Inactive Accounts: Data retained for 24 months after last activity
- Deleted Accounts: Data deleted within 90 days of account deletion
- Legal Requirements: Some data retained longer as required by law
11.2 Deletion Criteria
We delete Personal Data when:
- It is no longer necessary for the purposes collected
- Users withdraw consent and no other legal basis exists
- Data must be deleted to comply with legal obligations
- Users successfully exercise their right to deletion
11.3 Archival and Backup
- Deleted data may persist in backup systems for up to 90 days
- Archived data is not actively processed or accessible
- Backup data is securely deleted when no longer needed
12. Data Subject Rights
12.1 Right to Access
Users may request copies of their Personal Data within 30 days of request.
12.2 Right to Rectification
Users may request correction of inaccurate or incomplete data.
12.3 Right to Erasure
Users may request deletion of their Personal Data, subject to legal exceptions.
12.4 Right to Restriction
Users may limit processing of their data in certain circumstances.
12.5 Right to Object
Users may object to processing based on legitimate interests or direct marketing.
12.6 Right to Data Portability
Users may receive their data in a structured, machine-readable format.
12.7 Right to Withdraw Consent
Users may withdraw consent at any time without affecting prior processing.
12.8 Right to Lodge Complaints
Users may complain to supervisory authorities about our data practices.
14. Security Measures
14.1 Technical Safeguards
- Encryption of data in transit and at rest
- Multi-factor authentication for sensitive operations
- Regular security assessments and penetration testing
- Network monitoring and intrusion detection
- Secure software development practices
14.2 Organizational Measures
- Data protection training for all staff
- Access controls based on job requirements
- Vendor security assessments
- Incident response procedures
- Regular privacy impact assessments
14.3 Breach Notification
- We notify affected users of data breaches within 72 hours where required
- Regulatory authorities are notified as required by law
- Users receive guidance on protective measures
15. Children's Privacy
- The Platform is not intended for users under 18 years of age
- We do not knowingly collect data from children
- Accounts of users found to be under 18 will be terminated
- Parents may request deletion of their children's data
16. Third-Party Links
- The Platform contains links to third-party websites
- We are not responsible for third-party privacy practices
- Users should review third-party privacy policies
- Integration with third-party services is subject to their terms
17. Marketing and Communications
17.1 Marketing Consent
- We obtain consent before sending marketing communications
- Users may opt-out of marketing at any time
- Service-related communications cannot be opted out of
17.2 Targeted Advertising
- We use data for personalized advertising with consent
- Users may opt-out of targeted advertising
- Advertising preferences can be managed in account settings
18. Changes to this Policy
- We may update this Privacy Policy periodically
- Material changes will be communicated to users
- Continued use after changes constitutes acceptance
- Users should review the policy periodically
19. Contact Information
19.1 Data Protection Officer
Name: Data Protection Officer
Email: dpo@cohire.ai
Phone: +254 793 878 352
Address: Nairobi, Kenya
19.2 EU Representative
For EU users:
Name: EU Data Protection Representative
Email: dpo@cohire.ai
19.3 Supervisory Authority
Users may contact their local data protection authority with complaints.