Privacy Policy
Last updated: April 9, 2026
1. Introduction
Nexu HR ("we", "our", or "us") operates the nexuhr.com platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. Nexu HR acts as a data controller for account information (admins, recruiters, employees of the customer company) and as a data processor on behalf of the customer company for candidate data submitted to that company's careers page or pipeline. The customer is the controller for that candidate data.
For the purposes of GDPR, Nexu HR's lawful bases for processing are: (a) performance of a contract with the customer for all data needed to deliver the service, (b) legitimate interest for security, fraud prevention, product analytics and service improvements, (c) consent for any optional integration the user explicitly enables (such as Google Calendar), and (d) legal obligation for billing records, tax reporting and responses to lawful authority requests.
2. Information We Collect
We collect information that you provide directly to us, including:
- Account information (name, email, password)
- Company information (name, domain, logo, industry)
- Employee data (names, roles, departments, contact info)
- Candidate data (resumes, application details, interview notes)
- Usage data (features used, actions taken within the platform)
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process and manage your recruitment pipeline
- Power AI features such as CV analysis and interview question generation
- Send notifications related to your hiring activities
- Process payments and manage subscriptions
- Respond to your inquiries and support requests
4. AI Processing & Automated Decision-Making
Nexu HR uses artificial intelligence (powered by Anthropic's Claude) to analyze candidate resumes, generate interview questions, and evaluate screening responses. Candidate data processed by AI is used solely for the purpose of providing these features to the customer organization. We do not use your data to train AI models.
Article 22 disclosure. AI-generated fit scores and recommendations are decision support, not automated decisions. A human recruiter or hiring manager always reviews the AI output before any hiring action. Nexu HR does not produce legal or similarly significant effects on candidates without meaningful human review. If you are a candidate and want a human-only review, an explanation of how AI scoring works for your application, or to object to AI processing of your data, contact privacy@nexuhr.com and we will route the request to the relevant customer organization.
5. Google User Data
Nexu HR integrates with Google Calendar to let recruiters and hiring managers schedule interviews on their real availability. When you connect your Google account, Nexu HR requests the following OAuth scopes:
openid,email,profile— to identify your Google account and link it to your Nexu HR user..../auth/calendar.readonly— to read your existing calendar events so we can compute free/busy slots and avoid double-booking..../auth/calendar.events— to create, update, and cancel interview events on your calendar when a candidate books a slot or you reschedule a meeting from Nexu HR.
How we use Google user data
- We read free/busy windows from your primary Google Calendar to display real availability to candidates inside Nexu HR's scheduling links.
- We create calendar events for confirmed interviews, including the candidate, the interviewer panel, the meeting link (Google Meet or external), and the agenda.
- We update or delete those events when an interview is rescheduled or cancelled from Nexu HR.
- Profile data (name, email, picture) is used only to identify your Google account and display it in account settings.
How we store Google user data
We store the OAuth refresh token and a short-lived access token for your Google account so we can perform calendar operations on your behalf. Tokens are encrypted at rest and scoped to your Nexu HR user. Calendar event metadata that we create through Nexu HR (event id, start/end, attendees) is stored alongside the corresponding interview record so we can keep the two in sync. We do not store the body of your existing calendar events; we only read free/busy windows.
How we share Google user data
We do not sell, rent, or share Google user data with third parties. We do not use Google user data for advertising. We do not use Google user data to train, fine-tune, or improve any AI or machine learning model. The only humans who can read Google user data are: (a) you and members of your Nexu HR workspace whom you explicitly grant permission to schedule on your behalf, and (b) Nexu HR engineers when strictly necessary to investigate a security incident or a support request you have filed, and only with your consent.
Disconnecting and deleting Google data
You can disconnect your Google account at any time from Preferences → Integrations. When you disconnect, we revoke the refresh token with Google and delete the stored tokens immediately. You can also revoke access at any time from your Google Account permissions page.
Nexu HR's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Data Sharing
We do not sell your personal information. We may share your information with:
- Service providers: Vercel (hosting and cookieless web analytics), Supabase (database and authentication), Stripe (payment processing), Anthropic (AI processing), Resend (transactional email), Cloudflare Turnstile (bot protection on signup)
- As required by law or legal process
- To protect our rights, privacy, safety, or property
7. Data Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, row-level security policies, and role-based access controls to protect your data.
8. Data Retention
We retain your data for as long as your account is active or as needed to provide services. When a workspace is marked for deletion (either by you, or automatically after a long period of inactivity following subscription cancellation), the workspace and all of its data are kept for a 90-day grace period during which the customer can recover the account by contacting us.
After the 90-day grace period, an automated daily job (purge_expired_companies) runs at 03:00 UTC and permanently deletes the workspace and all associated records. Each purge is recorded in an internal audit log so we can prove the deletion happened on the promised schedule. You may request earlier deletion at any time by emailing privacy@nexuhr.com; we will action verified requests within 30 days.
9. Your Rights
You have the right to:
- Access your personal data (Art. 15)
- Correct inaccurate data (Art. 16)
- Request deletion of your data (Art. 17)
- Export your data in a portable format (Art. 20)
- Object to or restrict processing of your data (Art. 18 & 21)
- Withdraw any consent you previously granted, at any time, without affecting the lawfulness of processing prior to withdrawal
- Lodge a complaint with your local data protection supervisory authority if you believe we have not handled your data in accordance with applicable law (Art. 77)
10. International Transfers
Several of our sub-processors are located in the United States, including Supabase, Vercel, Stripe, Anthropic and Resend. When personal data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (SCCs) and apply the supplementary measures recommended by the EDPB after Schrems II, including encryption in transit and at rest. The complete list of sub-processors and their location is available at /sub-processors.
11. Contact
For privacy-related questions, contact us at privacy@nexuhr.com