This page summarises how aiApply processes personal data on behalf of business customers. For a countersigned DPA, contact privacy@aiapply.ch.
Roles
For individual (B2C) users, aiApply is typically the data controller. For organisational pilots where you upload employee or candidate data, aiApply acts as processor and you are the controller.
Processing instructions
- Process personal data only to deliver the aiApply service per your account configuration.
- Do not sell personal data or use it for unrelated advertising profiles.
- Use sub-processors (Google Cloud, Stripe) under agreements with comparable protections.
Security measures
- Tenant isolation: all user data under users/{uid}/ paths with path-specific rules.
- Encryption in transit (TLS) and at rest (Google Cloud default).
- Server-only writes for billing, pipeline runs, fit scores, and quarantine data.
- App Check and Firebase Auth for client access control.
Data location
Primary storage: Switzerland (europe-west6). AI inference step: EU (europe-west4) as described in the Privacy policy.
Deletion and assistance
On verified request or account deletion, we delete the customer tenant data within our documented retention window and assist with reasonable data-subject requests where we act as processor.