Privacy Policy

Last updated: March 6, 2026

1. Who We Are

Rekroot is operated by QBS Global FZCO, registered in IFZA Free Zone, Dubai, United Arab Emirates. We are the data processor for candidate data and data controller for employer account data.

Contact: support@rekroot.ae

2. Data We Collect

From Employers (Account Holders)

Full name, company name, email address, and payment information (processed by Stripe; we do not store card numbers). We also collect job posting content and email template configurations you create within the platform.

From Candidates (Applicants)

Full name, email address, phone number (optional), and uploaded resume files (PDF or DOCX). Resume content is processed by our AI screening system to generate a compatibility score against job requirements.

Automatically Collected

We collect basic usage data including pages visited, browser type, and IP address for security and service improvement purposes. We do not currently use third-party analytics or tracking cookies.

3. How We Use Your Data

We use personal data for the following purposes:

(a) Providing the Service — account management, job posting, candidate management, and AI resume screening; (b) Communication — transactional emails (account confirmation, application notifications, candidate status updates); (c) Billing — processing subscription payments via Stripe; (d) Security — preventing unauthorized access and detecting abuse; (e) Service improvement — understanding usage patterns to improve the platform.

We do not sell, rent, or share personal data with third parties for marketing purposes.

4. AI Processing of Resumes

When a candidate applies for a job, their resume is processed by an AI system (powered by OpenAI) to extract relevant information and generate a compatibility score. This processing is performed for the legitimate purpose of assisting employers with candidate screening.

The AI score is a recommendation only and does not constitute an automated decision with legal or significant effects. All hiring decisions are made by the employer. Resume data sent to OpenAI is processed under their data processing agreement and is not used to train their models.

5. Data Storage & Security

Account data and candidate records are stored in Supabase (PostgreSQL database hosted on AWS). Resume files are stored in Supabase Storage. All data is encrypted in transit (TLS) and at rest. Access to production data is restricted to authorized personnel only.

Payment data is processed and stored by Stripe in accordance with PCI DSS Level 1 compliance. We do not store credit card numbers on our servers.

6. Data Retention

Employer account data is retained for the duration of the account plus 30 days after deletion. Candidate application data (including resumes) is retained for as long as the employer maintains an active account. Employers may delete individual candidate records at any time through the platform.

After account deletion, all associated data is permanently removed within 30 days, unless a longer retention period is required by applicable law.

7. Your Rights

Under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, you have the right to:

(a) Access — request a copy of your personal data; (b) Rectification — correct inaccurate or incomplete data; (c) Erasure — request deletion of your data (subject to legal retention requirements); (d) Restriction — limit how we process your data; (e) Data portability — receive your data in a structured, machine-readable format; (f) Objection — object to processing based on legitimate interests.

Candidates who wish to exercise these rights should contact the employer who posted the job. Employers can contact us at support@rekroot.ae.

8. Third-Party Services

We use the following third-party services to operate the platform:

(a) Supabase — database, authentication, and file storage (AWS infrastructure); (b) OpenAI — AI resume screening and job description generation; (c) Stripe — payment processing; (d) Resend — transactional email delivery; (e) Vercel — web application hosting.

Each provider processes data in accordance with their respective privacy policies and data processing agreements.

9. International Data Transfers

Some of our third-party service providers process data outside the UAE. Where data is transferred internationally, we ensure appropriate safeguards are in place, including standard contractual clauses and data processing agreements, in compliance with UAE data protection law.

10. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at support@rekroot.ae.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The "Last updated" date at the top of this page indicates when the policy was last revised.

12. Contact Us

For privacy-related inquiries or to exercise your data rights:

QBS Global FZCO
IFZA Free Zone, Dubai, UAE
Email: support@rekroot.ae