Privacy Policy
This Privacy Policy (hereinafter as "Privacy Policy") describes the way SAMETA s.r.o. seated Čulenova 7936/5, 811 09 Bratislava, Company ID: 50 706 667, registered with the Slovak Commercial Register of District Court Bratislava III, Insert No. 117160/B (further as "People Flow") collect, process and protect your Personal data. People Flow hereby undertakes to protect your Personal data in accordance with the applicable legal regulations in the area of data protection, such as Regulation of the European Parliament and of the Council (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of Personal data and on the free movement of such data ("GDPR").
This Privacy Policy applies to the processing of Personal data on all services, applications, and websites operated or provided by People Flow, in which Personal data is processed and in which this Privacy Policy is contained or referenced. This Privacy Policy also applies to processing Personal data of website visitors, service users, and also representatives of our business partners or individuals that contact us via our website. This Privacy Policy also applies to some cases as further mentioned in this Privacy Policy where People Flow processes Personal data as a controller.
In case of any discrepancy between this Privacy Policy and the specific privacy policy applicable to any product or service provided by People Flow, the specific privacy policy shall prevail.
The provisions of this Privacy Policy shall apply from the effective date stated above.
About People Flow
People Flow is a web-based platform designed to support companies in managing their hiring processes and candidates efficiently. The platform facilitates everything from job posting and application tracking to interview scheduling, document management, and communication with applicants.
People Flow consists of two core components:
- People Flow Platform: a secure web application used by companies and recruiters for managing job openings, candidates, and internal hiring workflows.
- People Flow Job Portal: a public-facing website where candidates can view job openings and apply directly by submitting their basic personal information and documents.
For more information about us or our products, you may also visit our informational website at https://dev-app.peopleflow.sk/ .
PEOPLE FLOW AS A DATA PROCESSOR
When you use the People Flow platform as part of your company's HR and recruitment activities, People Flow processes Personal Data on your behalf. This includes candidate data, internal user activity, and other HR-related records. In this context, People Flow acts as a data processor, and your company is considered the data controller.
PEOPLE FLOW AS A DATA CONTROLLER
People Flow may also collect and process personal data independently for the operation of the People Flow Platform and Job Portal as part of its business activities. This includes ensuring service functionality, maintaining security, optimizing performance, and developing new features.
Additionally, People Flow acts as a data controller when:
- You browse or interact with our website,
- You contact us through support or contact forms,
- You subscribe to our newsletter.
In these cases, People Flow determines the purposes and means of processing your personal data and is responsible for ensuring compliance with applicable data protection laws.
What Data Do We Process, Why and Based on Which Legal Basis?
INFORMATION WE COLLECT WHEN YOU ARE USING PEOPLE FLOW FOR YOUR COMPANY
When a company uses the People Flow Platform to manage recruitment processes, we act as a data processor and process personal data on behalf of the company (the data controller). The categories of personal data that may be processed include:
- Identification and Contact Data: such as name, email address, phone number, and address of candidates and users involved in the recruitment process.
- Professional and Educational Background: including details on education, academic qualifications, work history, skills, and professional experience submitted by candidates.
- Recruitment-related Information: such as data associated with job postings, position requirements, status of hiring workflows, interview schedules, and internal recruiter evaluations or notes.
- Communication Metadata and Content: including calendar event information (via Google Calendar integration) and the content of emails exchanged with candidates (via Gmail integration), as well as metadata (e.g. timestamps, sender/receiver IDs).
- Document-related Information: data concerning uploaded documents such as CVs, cover letters, motivation letters, diplomas, and professional certificates.
- Usage and Audit Log Data: such as user activity logs that include user identifiers, timestamps, performed actions (e.g. create, edit, delete), affected entities, and original vs. modified data states. This supports traceability, accountability, and internal audit requirements.
- Notification Data: personal data processed to deliver system-generated notifications, such as alerts about new applications, changes in candidate status, and internal comments addressed to specific users.
These data categories may include information relating to data subjects who are job applicants, HR personnel, and other users authorized by the client company.
Legal basis for processing: This processing is based on the performance of a contract you entered into with People Flow.
INFORMATION WE COLLECT WHEN YOU ARE USING PEOPLE FLOW WHILE SEARCHING FOR A JOB
When you apply for a job via the People Flow Job Portal ( https://dev-jobs.peopleflow.sk/ ), we process your personal data to facilitate the recruitment process on behalf of the hiring company. In this context, People Flow acts as a data processor, and the hiring company is the data controller. The types of personal data that may be processed include:
- Identification and Contact Data: Full name, email address, phone number, and other personal details you provide through the application form.
- Application Content and Metadata: Responses to application questions (e.g. availability, motivation, expectations), job position applied for, date and time of submission, current stage and status of your application in the recruitment process.
- Uploaded Documents: CV or résumé, cover letter, diplomas, certificates, and other attachments submitted as part of your application.
- Communication Records: Email communications between you and the hiring company (facilitated through integrated services), calendar invitations and interview scheduling information.
Legal Basis for Processing:
- Pre-contractual necessity at the request of the data subject — as submitting a job application is a step toward potentially concluding an employment contract.
- Consent, in cases where your application includes optional data or communications, keeping your CV in the database even after the hiring is completed, or where such legal basis is required under applicable national laws.
OTHER PERSONAL DATA PROCESSING CONCERNING USERS AND WEBSITE VISITORS
Website Browsing
We collect cookies and usage data on our informational and platform websites to improve the browsing experience and remember user preferences.
Legal basis: Your consent.
Product Feedback and Testing
We may invite users to participate in feedback sessions or usability testing, during which we process personal identifiers and usage data.
Legal basis: Our legitimate interest in improving the People Flow platform.
Customer Support
When you contact us for support or inquiries, we collect information necessary to assist you.
Legal basis: Contract that you entered with us for the use of People Flow Services.
Analytics and Labor Market Insights
We may process personal data to perform internal analyses aimed at improving our services, understanding labour market trends, and supporting recruiters and employers in workforce planning. These analytical operations may include:
- Creating anonymous or pseudonymized profiles for market analysis
- Evaluating skill demand and job supply in different regions
- Predicting workforce trends and salary expectations
- Identifying most requested technologies or experience levels
Whenever feasible, such analysis is carried out using aggregated or pseudonymized data.
Legal basis: Our legitimate interest in service optimization and market intelligence.
Newsletter and Marketing
If you subscribe to our newsletter, we process your contact details to deliver relevant content.
Legal basis: Consent you provide us with, when opting in to such communications.
Legal Compliance
We may process personal data to comply with obligations under tax, accounting, or regulatory laws.
Legal basis: Compliance with legal obligations.
Use of AI in People Flow
To help streamline the recruitment process, People Flow uses AI technologies to process job descriptions and candidate CVs. This includes:
- Extracting structured information from your uploaded résumé (e.g. skills, education, work history)
- Matching you with job opportunities based on content analysis
Before your CV is processed by external AI (e.g. OpenAI), we pseudonymize your personal data (name, email, phone number, etc.) to protect your identity. No data is stored by the AI provider, and the processed output is only saved if you confirm it.
If you are not comfortable with such processing, we provide you with an option to opt out from such processing and not to be subject to a decision based solely on automated processing.
Data Retention
Generally Personal data shall be kept for as long as necessary for the purpose for which it was processed. For how long People Flow will hold your Personal data will as well depend on the legal basis on which your data is processed. Shall the processing be based on legitimate interest your data will be processed for as long as the given legitimate interest of People Flow is in place and shall be erased after. For data kept based on legal obligations the data retention period is prescribed by applicable legal regulations and shall be deleted once the legally prescribed time period lapses. For data processed based on performance of a contract the data is processed for the duration of the contractual relationship and for an applicable limitation period. This data is then erased after. Shall the processing be based on your consent your Personal data shall be erased after you withdraw your consent. Please bear in mind that the same data may as well be processed based on other legal basis in which case your withdrawal of consent might not mean a full erasure of your data.
Use of Cookies and Similar Technologies
Our websites use cookies and similar technologies to improve your experience, understand usage patterns, personalize content, and support secure access to our services, including third-party sign-ins such as Google SSO.
What are cookies?
Cookies are small, encrypted text files that are stored on your device (computer, phone, tablet) when you visit a website. These files help websites function properly and remember your preferences. They also allow us to better understand how our site is being used and how we can improve it.
We also use related technologies, such as web beacons and tracking pixels, for similar purposes – for example, to measure interactions with our marketing emails or monitor website behaviour anonymously.
Why do we use cookies?
We use cookies for the following purposes:
- Essential (Necessary) Cookies: Enable the website to function properly, such as recognizing your login session or enabling secure navigation. These cookies are required for the platform to operate.
- Analytical & Performance Cookies: Help us understand how you interact with our websites, what content is used most often, and how we can improve platform performance. We collect data such as navigation paths, custom event logs, page load times, and technical errors.
- Personalization & Advertising Cookies: Enable us to offer content and ads tailored to your interests and to deliver more relevant advertising, including retargeting across devices and platforms.
- Social Media & External Authentication: We integrate tools like Google SSO so you can sign in quickly and securely using third-party accounts. These integrations may also set cookies.
What kind of data do cookies collect?
Cookies and related tools may collect:
- IP address
- Browser type and settings
- Time zone and language preferences
- Operating system and platform
- Pages visited, duration, and click/interactions (e.g. scrolls, hovers)
- Referrer URL or search terms used
- Login timestamps and session status
- Error messages and diagnostics
- Device identifiers (for analytics and ad tracking)
Your Consent and Control
When you first visit our website, a cookie banner will inform you about our use of cookies and allow you to manage your preferences. You can modify or withdraw your consent at any time via the Privacy Settings link at the bottom of the website.
Essential cookies are processed on the basis of our legitimate interest (Article 6(1)(f) GDPR), as they are required for secure access and functionality.
All non-essential cookies (analytical, advertising, social media) are processed only with your consent.
Disabling Cookies
You can manage or delete cookies in your browser settings. Please note that disabling essential cookies may impact the functionality of the website. Below are links to cookie management instructions for common browsers:
For mobile devices, you can manage ad tracking through your device settings or visit: https://www.networkadvertising.org/mobile-choice/
You may also opt out from interest-based advertising via third-party tools such as:
- Digital Advertising Alliance
- Network Advertising Initiative
- European Interactive Digital Advertising Alliance
Social Plugins
Our website uses social plugins and sign-in integrations (Google). When you visit a page with such a plugin, your browser may automatically connect to the provider's servers. If you are logged into your Google account at the same time, they may associate your browsing with your account—even if you do not interact with the plugin. If you want to prevent this, log out of your social accounts before visiting our website.
Learn more in their respective privacy policies:
Data Sharing and Data Transfers to Third Countries
Your Personal data shall not be shared with any third party except for the following situations:
- data is necessary for provision of People Flow services,
- based on your consent,
- entrusting of Personal data to processors who process Personal data on behalf of People Flow,
- People Flow is obliged to provide the Personal data based on law or upon order by a public authority.
Categories of Processors
People Flow uses trusted third-party providers that in some instances process Personal data on behalf of People Flow and based on instructions provided by People Flow. People Flow may use the following categories of providers (sub-processors under GDPR):
- hosting, data center,
- marketing tools,
- analytical tools,
- task management and communication tools,
- IT tools / providers,
- business administration tools,
- legal, tax accounting, and audit services,
- governmental agencies.
If you are more interested in with whom we share your data with, you can also check out our list of subprocessors .
Transfers to Third Countries
People Flow will transfer your data to countries outside the EU/European Economic Area only if such a transfer is GDPR compliant. That means, for instance, the provider is seated in a country for which the European Commission issued a decision that it provides an adequate level of Personal data protection, Standard Contractual Clauses issued by the European Commission and/or other transfer mechanisms are in place that ensure adequate safeguards with respect to the protection of privacy and fundamental rights and freedoms of individuals and, if necessary, additional measures are applied to ensure that the Data Subject is granted a level of protection essentially equivalent to that guaranteed by the GDPR.
You have a right to receive a copy of the Standard Contractual Clauses ("SCC") we have concluded with our sub-processors that are established outside of the EU/EEA and that are used for transferring Personal data outside of the EU/EEA. If you wish to obtain a copy of the SCCs applicable to a particular transfer of your Personal data, please contact us via [email protected]
Protecting and Securing Your Personal Data
People Flow is committed to store your data securely. Therefore, we have implemented technical and organizational security measures in an effort to safeguard the personal information in our custody and control (which do not, however, deprive you of your duty to take proper steps to secure your data).
Technical Measures
- Data encrypted in transit. All of the passwords, tokens and keys are encrypted as well.
- We avoid storing sensitive data, like passwords in plaintext.
- Every application in our suite is logging its actions.
- We enforce a strong password policy. Where possible, we use MFA authentication. Use of reliable password managers is also strongly enforced.
- We are using principles of least privilege access to only allow the least amount of possible rights to our systems. In our applications, access to production environments is only granted to the people who are actively working on the production support and have all the necessary clauses in the contract.
People Security Measures
- For all of our candidates we perform background checks. The extent of these checks depends on the role and the seniority of the candidate.
- Contracts with our contractors and employees contain necessary confidentiality clauses and they are obliged to follow our rules on data processing.
- All employees and contractors are required to use a strong password.
- All of our technical staff must undergo mandatory security training.
Your Rights
Under GDPR you are entitled to following rights:
RIGHT TO ACCESS
You have the right to obtain confirmation from us regarding the information whenever we process your Personal data. If you wish to obtain such information, please contact us at [email protected] . If we process your Personal data, we will provide you with the following information:
- purposes of processing,
- the categories of Personal data obtained,
- the recipients, or categories of recipients of Personal data,
- if possible, the period for which your Personal data will be retained, or at least the criteria that determine that period,
- the existence of the right to ask the controller to rectify or erase the Personal data or to restrict the processing of Personal data concerning the data subject or to object to such processing,
- right to file a complaint with supervisory authority,
- the sources of your Personal data, if such Personal data have not been obtained directly from you,
- the details of the existence of automated decision-making, including profiling.
RIGHT TO RECTIFICATION
You have the right for any of your incomplete, inaccurate, or out-of-date Personal data to be rectified.
RIGHT TO ERASURE
You are entitled to the erasure of certain Personal data without undue delay. Please be aware that People Flow may be entitled or even obliged to keep some of your Personal data despite your data deletion request. These are mainly situations where we need to process your Personal data in order to comply with our legal obligations or to defend our legal claims.
RIGHT TO RESTRICTION OF PROCESSING
In the cases such as:
- if you object the accuracy of Personal data, for a period that allows us to verify the accuracy of Personal data,
- the processing is illegal, and you do not agree to the deletion of your Personal data and request the restriction of their use,
- We no longer need your data for processing purposes, but your Personal data is necessary to prove, exercise or defend legal claims,
- you have objected to processing in relation to profiling until it is verified that our legitimate grounds outweigh yours,
You can ask People Flow to restrict the processing of your Personal data.
RIGHT TO DATA PORTABILITY
You are entitled to receive the Personal data that you have provided to us in a structured, commonly used and machine-readable format and ask from us to transmit that data to another controller, if it is technically possible. We would like to warn you that this right applies only to the data that you have provided us with and which we process as a controller based on your consent or contract.
RIGHT TO OBJECT
You are entitled to object, on grounds relating to your particular situation, at any time to the processing of Personal data that concerns you and is carried out in the public interest or for the purposes of legitimate interests pursued by People Flow, including profiling.
The exercise of your rights may be limited shall People Flow be obliged to keep any of your Personal data for the purpose of compliance with legal obligations, for the establishment, exercise or defence of legal claims or any other compelling reasons as provided by the relevant data protection law.
RIGHT TO NOT BE SUBJECT TO AUTOMATED DECISION MAKING
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. This does not apply if the decision:
- is necessary for entering into, or performance of, a contract between you and People Flow,
- is authorized by law and the law lays down suitable measures to safeguard your rights and freedoms and legitimate interests; or
- is based on your explicit consent.
People Flow does not make decisions based solely on automated processing that would have significant effects for People Flow user. For completeness, People Flow uses cookies and similar technologies the use of which may amount to profiling. For information on how to withdraw your consent for the use of cookies or disable cookies, please see chapter 4. Use of Cookies of this Privacy Policy.
RIGHT TO FILE A COMPLAINT
If you feel that People Flow process your Personal data unlawfully, please contact us and we will try to resolve this situation. Under GDPR you are entitled to file a complaint with the Office for Personal data Protection, seated Námestie 1.mája 18, 811 06 Bratislava.
Children's Privacy
Our website, services, and applications are not intended for persons under the age of eighteen (18). If you are under the age of eighteen, please do not provide your personal information to People Flow. We do not knowingly collect any personal information from children under the age of eighteen on our website. Users under the age of eighteen (18) (or the age of majority in the applicable jurisdiction) should not use People Flow's websites, services, and applications without authorization from a parent or legal guardian.
Contact Information
If you have any questions regarding the safety of your Personal data, please do not hesitate and contact us directly at [email protected] or by the mail to the address: SAMETA s.r.o. seated Čulenova 7936/5, 811 09 Bratislava
Final Provisions
This Privacy Policy may be amended by People Flow at any time. If we change this Privacy Policy, we will post the changes on our website and/or other places we deem appropriate. We may, but are not obligated to, send you an email or other notice of such a change, but you should check this Privacy Policy from time to time for any significant changes to its text.
If for any reason, any provision herein is found void or unenforceable, it will be severed to the extent void or unenforceable and the remaining provisions will continue in full force and effect.