Sieva Privacy Policy
Last updated:
This Privacy Policy describes how Sieva s.r.o. ("we", "us") collects, processes, and protects personal data in connection with providing the Sieva SaaS platform. It is drafted in accordance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and applicable laws of the Czech Republic.
By using the Service, the User confirms that they have reviewed this Policy. If you do not agree with the terms of data processing, discontinue use of the Service.
1. Data Controller
The Data Controller within the meaning of Article 4(7) GDPR is:
Sieva s.r.o., registered address: Prague, Czech Republic.
For questions about the processing of personal data or to exercise data subject rights, contact our DPO (Data Protection Officer) at privacy@sieva.eu. We respond to requests within 30 calendar days in accordance with Article 12 GDPR.
2. Categories of Data Collected
We process three main categories of data:
(a) User account data. When you register and use the Service, we collect email address, name, company name, login history, session IP addresses, and basic payment transaction information (once billing launches in Phase 2A). This data is necessary to identify the User and provide the Service.
(b) Candidate data uploaded by the User. The User, acting as Controller for their own hiring processes, uploads candidate data into the Service: names, phone numbers, email addresses, resumes, conversations on Telegram and other messengers, AI-model assessment results, and recruiter notes and comments. In relation to this data, Sieva s.r.o. acts as a Processor within the meaning of Article 28 GDPR — processing is carried out on the User's instructions.
(c) Technical logs and telemetry. Logs of interaction with the interface, client-side events (clicks, navigation, errors), and browser and device information. Used to ensure security, for debugging, and to improve the quality of the Service.
3. Legal Basis for Processing
Personal data is processed on the following legal bases (Article 6 GDPR):
(a) Performance of a contract (Art. 6(1)(b)). Processing of account data and User Content is necessary to provide the Service in accordance with the Terms of Service.
(b) Legitimate interest (Art. 6(1)(f)). Processing of technical logs, prevention of fraud and abuse, and improvement of the Service. Before relying on this basis, we carry out a balancing test to ensure the rights of data subjects prevail where applicable.
(c) Consent (Art. 6(1)(a)). Sending marketing communications and use of optional cookies (Analytics/Marketing, once introduced). Consent can be withdrawn at any time without giving reasons.
(d) Legal obligations (Art. 6(1)(c)). Retention of accounting and tax records as required by Czech law.
4. Recipients and Subprocessors
We engage the following subprocessors to operate the Service:
- OpenAI, L.L.C. — analysis of candidate conversations, message generation, and response evaluation using LLMs.
- Anthropic, PBC — alternative AI-model provider for the same tasks.
- Telegram FZ-LLC — messaging with candidates via the Bot API.
- Stripe, Inc. — payment processing (once billing launches in Phase 2A).
- Cloud infrastructure within the EEA — application and database hosting.
The full, current list of subprocessors with their jurisdictions is published on the "Subprocessors" page. All subprocessors are bound by a Data Processing Agreement that meets the requirements of Article 28 GDPR.
5. International Data Transfers
Some subprocessors (in particular OpenAI and Anthropic) host infrastructure outside the European Economic Area, primarily in the United States. Such transfers are carried out under Standard Contractual Clauses (SCC) adopted by the European Commission in Decision 2021/914, together with additional technical and organizational safeguards (encryption in transit and at rest, pseudonymization).
Where appropriate, we carry out a Transfer Impact Assessment (TIA) in line with EDPB Recommendations 01/2020 and provide a copy of the transfer mechanisms on User request.
6. Retention Periods
We apply the principle of storage limitation (Art. 5(1)(e) GDPR):
- Active account: data is retained for the duration of the subscription and use of the Service.
- Account deletion: the User's personal data and uploaded Content are removed from production systems within 30 calendar days. Backups are rotated on a standard schedule and fully overwritten within 90 days.
- Accounting and tax records: retained for up to 10 years as required by Czech law (Zákon č. 563/1991 Sb. on accounting).
- Technical logs: retained for no longer than 180 days, after which they are purged automatically.
7. Data Subject Rights
Under Articles 15–22 GDPR, data subjects have the following rights:
- Right of access (Art. 15) — to obtain confirmation of processing and a copy of the data being processed.
- Right to rectification (Art. 16) — to request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17, "right to be forgotten") — to request deletion of data where there is no legal basis for continued processing.
- Right to restriction of processing (Art. 18) — to pause processing while an objection is reviewed.
- Right to data portability (Art. 20) — to receive data in a machine-readable format (JSON) and transmit it to another controller.
- Right to object (Art. 21) — including to processing based on legitimate interest and to profiling.
Requests to exercise these rights can be sent to privacy@sieva.eu. We respond within 30 days; in complex cases the deadline may be extended by a further two months, with notice to the requester.
8. Cookies
We use cookies and similar technologies to operate the Service and to remember user preferences. Details are set out in the Cookie Policy.
9. Changes to this Policy
We may update this Policy from time to time — for example, when we engage new subprocessors or change Service functionality. We notify Users of material changes by email and via an in-Service banner at least 30 days before they take effect.
A version history of the Policy is available on request. Continued use of the Service after changes take effect constitutes acceptance of the updated version.
10. DPO Contact
Data Protection Officer: privacy@sieva.eu.
The DPO's postal address is the same as the registered address of Sieva s.r.o.. We accept requests in English, Russian, and Czech.
11. Right to Lodge a Complaint with a Supervisory Authority
Data subjects have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). In the Czech Republic the competent authority is:
Úřad pro ochranu osobních údajů (Czech Data Protection Authority) Pplk. Sochora 27, 170 00 Praha 7, Česká republika Email: posta@uoou.cz Website: https://uoou.gov.cz
Data subjects also have the right to lodge a complaint with the supervisory authority of their habitual residence or of the place of the alleged infringement.