Privacy Policy
Last updated 1 August 2026
This policy explains what personal data Recruitment Whales collects, why we collect it, how long we keep it, and the rights you have over it. It is written to satisfy the EU/UK GDPR and Egypt's Personal Data Protection Law No. 151 of 2020, and it applies to our website, the Recruitment OS application, and our recruitment services.
1. Who we are
Recruitment Whales ("we", "us") is a recruitment and mass-hiring company based in Cairo, Egypt. For candidate and client data processed through our own platform we act as a data controller. When we process candidate data strictly on behalf of a hiring client under their instructions, we act as a data processor for that client.
Privacy contact: privacy@recruitmentwhales.com.
2. Data we collect
- Account data — name, email address, password hash, authentication provider identifiers (Google, LinkedIn), and multi-factor enrolment status.
- Candidate data — CV, work history, education, languages, salary expectations, location, phone number, interview notes and application status.
- Client and recruiter data — company name, contact details, job requirements, contract and billing information.
- Usage and technical data — IP address, device and browser type, pages viewed, and security/audit logs of administrative actions.
- Communications — messages you send us through forms, email or chat.
We do not intentionally collect special-category data (health, religion, political opinions). Please do not include it in your CV or messages.
3. Why we process it, and our legal basis
- To provide recruitment services — matching candidates to roles, sharing shortlists with clients. Basis: performance of a contract, and legitimate interests in operating a recruitment marketplace.
- To operate accounts and security — authentication, role-based access control, fraud prevention, audit logging. Basis: contract and legitimate interests.
- To send service and marketing messages — Basis: consent for marketing (withdrawable at any time), legitimate interests for transactional messages.
- To meet legal obligations — tax, accounting and lawful requests. Basis: legal obligation.
4. Cookies and consent
We use strictly necessary cookies to keep you signed in and to protect the service; these cannot be turned off without breaking authentication. Optional analytics and marketing cookies are only set after you press "Accept all" in our consent banner. Your choice is stored in your browser and you can change it any time by clearing site data.
5. Who we share data with
We share data only with: hiring clients you have applied to or agreed to be presented to; our infrastructure and processing partners (cloud hosting and database, email delivery, payment processing for invoices, and AI assistance features); and authorities where the law requires it. We never sell personal data.
6. International transfers
Our infrastructure providers may process data outside Egypt, including in the EU and the United States. Where data leaves the EEA or Egypt, we rely on Standard Contractual Clauses or an equivalent lawful transfer mechanism, and require our processors to apply equivalent security standards.
7. How long we keep it
- Candidate profiles: up to 24 months after your last activity, then deleted or anonymised.
- Client contracts and invoices: retained as required by Egyptian tax law.
- Security and administrative audit logs: retained for compliance. Where an account is deleted, its audit entries are kept in pseudonymised form with the account reference removed.
8. Your rights
Subject to applicable law you may request access to your data, correction, erasure, restriction or objection to processing, portability of data you provided, and withdrawal of consent. Send requests to privacy@recruitmentwhales.com; we respond within 30 days. You may also complain to your local supervisory authority, or in Egypt to the Personal Data Protection Center.
9. Security
Access to data is enforced at the database level with row-level security and role-based access control. Administrative actions require multi-factor authentication and are written to an immutable audit log. All traffic is encrypted in transit over HTTPS. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as required by law.
10. Children
Our services are for people aged 18 and over. We do not knowingly collect data from children; if we learn we have, we delete it.
11. Changes
We may update this policy. Material changes will be announced in the product or by email, and the "last updated" date above will change.