On this page
Data controller
The controller of your personal data is DIASSET spółka z ograniczoną odpowiedzialnością (a Polish limited liability company) with its registered office in Kraków, ul. Św. Filipa 23/4, 31-150 Kraków, Poland, KRS 0000806751, Tax Identification Number (NIP) 6762571939, REGON 384507610 (“DIASSET”, “AplikAI”, “we”, “us”, “our”).
Contact details for privacy matters and exercise of data-protection rights:
e-mail: support@aplik.ai,
address: DIASSET sp. z o.o., ul. Św. Filipa 23/4, 31-150 Kraków, Poland.
If we appoint a Data Protection Officer in the future, the relevant contact details will be published in this Policy.
Who and what this Policy applies to
This Policy applies to persons who:
create or hold an AplikAI Account,
use job-search, CV/résumé, matching, Application Kit, Autopilot, Apply Agent, Tracking Board or other AplikAI features,
connect AplikAI with Google or LinkedIn,
purchase a Subscription or Tokens,
contact support,
use aplik.ai and, where they provide the required consent, analytics and marketing technologies.
AplikAI is intended only for persons who are at least 18 years old.
Personal data we process
Depending on the features used, we may process the following categories of personal data.
Account and authentication data
first and last name,
e-mail address,
password in cryptographically protected form,
Account identifier,
data provided by Google or LinkedIn during sign-in, to the extent accepted by the user,
session, login and security data.
Professional profile and CV/résumé data
CV/résumé and files uploaded by the user,
employment history, roles, projects and achievements,
education, skills, languages and certificates,
preferences regarding type of work, location, salary, work mode and experience level,
photograph, date of birth and citizenship if the user chooses to provide them,
Public Profile data if the user enables publication.
AplikAI is not designed to collect special categories of personal data within the meaning of Article 9 GDPR, such as health data, religious beliefs, political opinions, ethnic origin, trade union membership or data concerning sex life. Please do not include such information in your CV/résumé or other materials unless it is necessary. We do not use such data for Match Score or candidate assessment.
Job-offer and application-process data
saved job offers and search preferences,
Match Score, Match Insights and the user’s actions concerning job offers,
Autopilot and Apply Agent settings,
Application Kits, job-tailored CVs/résumés, cover letters, follow-ups and other materials,
application statuses, notes, reminders and activity history,
employer or contact data associated with an application,
recruitment-consent settings and historical snapshots of applied settings,
data associated with an Application Page.
AI data
user prompts and instructions,
content sent to a model in order to perform a specific feature,
model output,
technical information about the model used, version, execution time, cost and operation status,
user feedback concerning AI output.
Google data
Depending on the features accepted by the user, AplikAI may process:
basic Google Account data required for sign-in, such as an identifier, name, e-mail address and profile picture,
permission to send e-mail on the user’s behalf through Gmail,
if the user enables reply synchronisation: message content, headers and metadata to the extent required to handle e-mail threads initiated through AplikAI.
AplikAI does not use Gmail access to generally scan the user’s mailbox. Product logic limits processing to messages and threads required for features expressly enabled by the user, in particular threads initiated through AplikAI.
As of the publication date of this version of the Policy, Google Calendar synchronisation is not part of the active Google Integration. If it is enabled in the future, the relevant access will be requested separately in the context of that feature, and this Policy and the notice shown before authorisation will be updated accordingly.
Payment and billing data
selected Plan, billing period and Subscription history,
purchase and use of Tokens,
payment and transaction identifiers,
data required to issue accounting documents,
payment-status information.
Payment-card data is generally handled by Stripe and does not need to be stored by DIASSET in full.
Technical, security and support data
IP address,
device, operating-system and browser information,
event and error logs,
timestamps and technical identifiers,
information concerning suspicious logins, abuse and security,
support correspondence.
Marketing and analytics data
After obtaining the required consent, we may process cookie identifiers and similar data related to use of the website or Application through tools such as Google Analytics, Google Ads, Meta Pixel and PostHog. The scope depends on the user’s consent settings and the relevant tool configuration.
Data received from Google Workspace APIs, including Gmail data, is not transmitted to Meta Pixel, Google Ads, Google Analytics, PostHog or other advertising platforms for ad targeting.
Purposes and legal bases for processing
Purpose | Example data | Legal basis |
|---|---|---|
Creating and maintaining the Account, sign-in and onboarding | Account data, profile | Article 6(1)(b) GDPR – performance of a contract |
Providing AplikAI features, CV/résumé functions, matching, Application Kit, Autopilot, Apply Agent and tracking | profile, CV/résumé, preferences, job-offer data, application materials | Article 6(1)(b) GDPR |
Sending an application or message to an employer at the user’s request | CV/résumé, message content, contact data | Article 6(1)(b) GDPR |
Google and Gmail Integration | Google data, OAuth token, threads and messages within the relevant feature | Article 6(1)(b) GDPR and the user’s conscious grant of the relevant OAuth permissions |
Processing payments, Subscriptions and Tokens | transaction data, billing data | Article 6(1)(b) GDPR |
Accounting, taxes and legal obligations | billing and accounting data | Article 6(1)(c) GDPR |
Security, abuse prevention and protection of legal claims | logs, IP address, security events | Article 6(1)(f) GDPR – legitimate interests of the controller |
Support and complaint handling | Account data, correspondence | Article 6(1)(b), (c) or (f) GDPR, depending on the matter |
Publishing a Public Profile and Application Page | data selected by the user | Article 6(1)(b) GDPR – performance of a feature enabled by the user |
E-mail marketing and newsletter | e-mail address, consent records | Article 6(1)(a) GDPR and the required consent to marketing communications |
Analytics and marketing based on cookies/similar technologies | device identifiers, activity | Article 6(1)(a) GDPR and the relevant consent to use non-essential technologies |
Information about product use in aggregated or anonymised form | statistical data | where personal data is involved: Article 6(1)(f) GDPR; after effective anonymisation the GDPR does not apply |
Where we process data on the basis of legitimate interests, we assess whether those interests are overridden by the rights and freedoms of the data subject.
Profiling, Match Score and automated actions
AplikAI uses profiling within the meaning of the GDPR to the extent it analyses CV/résumé, profile, preference and job-offer data in order to calculate fit and rank job offers.
Match Score concerns the fit between a job offer and the user’s profile and settings. It is not an employer-side candidate score, an employability assessment or a prediction of an employer’s decision.
The user may set a minimum Match Score. For example, if the user sets a threshold of 90, offers below that threshold may not be displayed. The user may change this setting at any time, including setting it to 0 in order to display all available offers.
Apply Agent may perform actions automatically in accordance with rules set by the user. This is automation of the user’s instructions, not an AplikAI decision to grant or deny employment.
AplikAI does not make solely automated decisions concerning the user that produce legal effects or similarly significantly affect the user within the meaning of Article 22 GDPR. Recruitment decisions are made by independent employers.
Artificial intelligence and Amazon Bedrock
AplikAI uses AI systems made available through Amazon Bedrock. Depending on the feature and availability, the user may be able to choose from several supported models.
For users in the EU, we configure available models and inference profiles so that AI processing takes place in supported AWS regions located within the European Union, unless, before a particular feature is used, the user receives clear information about another processing region and the required transfer mechanism.
We send to the model only data necessary to perform the specific feature, for example a fragment of a CV/résumé, the user’s profile, a job description or the user’s instruction.
We do not use users’ CVs/résumés, Gmail data, applications, prompts or outputs to train or improve general-purpose AI models. We do not sell this data to model providers.
We may retain limited technical logs concerning AI operations for security, billing, diagnostics, auditing and product improvement purposes, in accordance with the retention periods described below.
Current information about the use of AI may additionally be presented in the AplikAI interface or on a dedicated AI transparency page.
Google Connect – detailed rules for Google user data
This section applies when the user connects an AplikAI Account with Google.
Access we may request
Depending on the feature, AplikAI may request:
standard Google sign-in permissions (
openid,email,profile),https://www.googleapis.com/auth/gmail.send– to send e-mail messages on the user’s behalf,https://www.googleapis.com/auth/gmail.readonly– only if the feature for reading replies in threads associated with applications initiated through AplikAI is active.
If a feature is not necessary, we should not request the corresponding scope. The scopes displayed on the Google OAuth screen are controlling for the specific connection.
How we use Gmail data
We use Gmail data only for user-facing features, in particular to:
send a message approved by the user or perform automation configured by the user,
associate a reply with a specific job application,
display in AplikAI the status, content and next actions associated with that thread,
prepare a follow-up or another feature concerning a specific application if the user enables it.
We do not use Gmail read permissions to review unrelated messages or to build an independent copy of the user’s mailbox.
What we do not do with Google data
Data received from Google Workspace APIs is:
not sold,
not provided to data brokers,
not used for advertising, retargeting or advertising profiling,
not provided to Meta Pixel, Google Ads, Google Analytics or other advertising tools,
not used to train, create or improve general-purpose AI or ML models,
not made available to employees for manual review except where the user expressly requests support concerning specific data, where manual access is necessary for security, or where required by law.
We may provide Google user data only to service providers acting on our behalf where this is necessary to provide the user with a specific, user-facing feature and is consistent with Google Limited Use requirements and applicable law.
Limited Use
The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google’s policy is available at:
https://developers.google.com/terms/api-services-user-data-policy
Revoking access and deleting Google data
The user may disconnect Google in AplikAI settings and may revoke AplikAI access in the security settings of their Google Account.
After the account is disconnected, OAuth tokens and Google authentication credentials are deleted or invalidated without undue delay.
Data obtained solely from Google Workspace APIs and stored by AplikAI for purposes of an active integration is, as a rule, removed from active systems within 24 hours after disconnection or Account deletion, unless further processing is necessary to complete an operation expressly requested by the user, handle a security incident or comply with a legal obligation.
Content originally created in AplikAI by or for the user, such as a cover letter generated in AplikAI, does not become “Google data” merely because it was subsequently sent through Gmail.
We do not create an independent, permanent archive of the Gmail mailbox.
Who we disclose data to
Data may be provided to service providers only to the extent necessary for a specific purpose. Our current setup may include:
Recipient / category | Purpose |
|---|---|
Amazon Web Services (AWS), including Amazon Bedrock | hosting, storage, backend processing, AI, security |
Stripe | payments, Subscriptions, transaction processing |
sign-in, Gmail, reCAPTCHA and – after consent – analytics/marketing tools | |
sign-in or authentication if selected by the user | |
Cloudflare | security, traffic protection, CDN and network services |
PostHog | product analytics in accordance with configuration and required consents |
MailerLite | e-mail marketing and newsletters after obtaining the required consent |
SMSAPI | SMS delivery where the user uses a feature that requires SMS |
Meta | Meta Pixel and advertising activities only after the required consent |
Framer | hosting or operation of the marketing website |
employers / recruiters selected by the user | receipt of an application, CV/résumé or Application Page in accordance with the user’s instruction |
advisers, accountants, lawyers and public authorities | legal obligations, settlements, protection of rights and legal claims |
We do not provide Google Workspace API data to advertising platforms or analytics providers for advertising purposes.
Transfers of data outside the EEA
AplikAI’s primary application data is stored on AWS infrastructure in the eu-central-1 (Frankfurt) region.
For AI processing of EU users, we aim to use models and inference profiles restricted to EU regions.
Some providers, such as Google, Stripe, Meta, Sentry, MailerLite, LinkedIn or their subprocessors, may process certain data outside the European Economic Area.
Where personal data is transferred outside the EEA, we rely on an appropriate transfer mechanism provided by the GDPR, such as an adequacy decision, participation of the recipient in a recognised transfer mechanism, or Standard Contractual Clauses together with supplementary safeguards where required.
Gmail data and other Google user data is processed subject to the additional Google restrictions described in Section 7.
How long we retain data
We apply the storage-limitation principle. Typical retention periods are as follows:
Category | Retention period |
|---|---|
Account, profile, CV/résumé, preferences, jobs, boards, Application Kits, applications, notes | while the Account remains active; after Delete Account, deletion or irreversible anonymisation from active systems generally within 24 hours |
Google Workspace API data required for an active integration | only for as long as needed for the relevant feature; after disconnect/delete, deletion from active systems generally within 24 hours |
OAuth access/refresh tokens | while the connection remains active; removed/invalidated without undue delay after disconnect |
Raw AI diagnostic logs containing prompt/output content, where necessary | generally no longer than 30 days; where possible we use shorter retention or logging without full content |
AI audit metadata without the full CV/résumé content | up to 12 months where needed for audit, billing and security |
Security and audit logs | generally up to 12 months, unless an incident requires longer retention |
Sentry diagnostic data | generally 30–90 days depending on configuration |
Support data | up to 24 months after the case is closed, unless longer retention is required for legal claims |
Accounting, tax and billing documents | for the period required by law, generally until expiry of the applicable tax-liability limitation period |
Evidence of marketing consents | for the duration of reliance on the consent and thereafter for the period needed to demonstrate compliance or defend claims, generally up to 3 years after withdrawal unless longer retention is necessary |
Analytics/cookie data | in accordance with tool settings and consent; we aim for no more than 14 months for identifiable user analytics |
Backups | on a rotating basis, generally no longer than 35 days |
Data export file prepared for the user | no more than 7 days after preparation, after which it is deleted |
Where specific data is necessary to establish, exercise or defend legal claims, we may restrict its use and retain it until expiry of the applicable limitation period.
Account deletion
The user may delete the Account through the Application where that functionality is available or by sending a request to support@aplik.ai.
Once deletion is confirmed, product data is, as a rule, deleted or irreversibly anonymised from active systems within 24 hours.
Exceptions include data that we must retain due to a legal obligation, settlements, security or legal claims, as well as rotating backups.
Deleting the Account does not delete data that the user previously sent to an independent employer. The user may exercise their rights directly against that employer.
Data export and portability
The user may request access to their data and, where provided by law, portability of the data in a commonly used, machine-readable format.
Until a self-service
Export my datafeature is made available, requests may be submitted to support@aplik.ai.The planned export feature should include profile data, the user’s CV/résumé and files, saved job offers, application history, Application Kit materials, settings, User Content and other data that may lawfully be exported without infringing third-party rights.
An export does not include AplikAI technical secrets, system prompts, keys, other users’ data or content whose disclosure would infringe third-party rights.
Public Profile and Application Page
The profile is private by default. The user decides whether to publish it.
If a separate setting for search-engine indexing is available, it should be independent from the public-availability setting itself and disabled by default.
An Application Page is protected by a unique link/hash and PIN and has an expiry date.
The user may at any time use Revoke now, which invalidates further access before the original expiry date.
A person or company to whom the user provides an Application Page or an application may become an independent controller of the received data.
Cookies, Google Analytics, Google Ads, Meta Pixel and PostHog
Technologies necessary for security, sign-in and operation of the Application may be used without consent where permitted by law.
We enable analytics or marketing cookies and similar technologies after obtaining the required consent.
The consent interface should allow at least the categories
Necessary,AnalyticsandMarketing, and it should be as easy to reject optional technologies as to accept them.The user may change or withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Data obtained from Gmail or other Google Workspace APIs is not used for advertising, retargeting or building marketing profiles.
Electronic marketing
Transactional and product messages necessary to perform the contract, such as registration, payment, security or feature-operation confirmations, may be sent without marketing consent where they are necessary to provide the Service.
Newsletters, promotions and other commercial communications are sent after obtaining the required consent.
Consent may be withdrawn at any time, for example through an unsubscribe link or by contacting support@aplik.ai.
Security
We use technical and organisational measures appropriate to the risk, including access controls, encryption in transit, secrets management, environment separation, monitoring, backups and abuse-detection mechanisms.
Authentication data and OAuth tokens should be protected at rest, and transmission takes place using current secure protocols. Personnel access to user data is limited to persons and situations where such access is necessary to perform their duties.
No system can provide absolute security. If a personal-data breach occurs, we apply procedures required by the GDPR and other applicable laws.
User rights
Depending on the circumstances, the user may have the right to:
access personal data and obtain a copy,
rectify personal data,
erase personal data,
restrict processing,
data portability,
object to processing based on legitimate interests,
withdraw consent at any time where processing is based on consent,
lodge a complaint with a supervisory authority.
In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych – UODO). The user may also contact the competent data-protection authority in the EU country where they live or work, or where they believe an infringement has occurred.
Requests may be submitted to support@aplik.ai. We may request additional identity verification where necessary to protect personal data from disclosure to an unauthorised person.
Objection to legitimate-interest processing
Where we process data on the basis of Article 6(1)(f) GDPR, the user may object on grounds relating to their particular situation. We will stop processing unless we demonstrate compelling legitimate grounds that override the user’s interests and rights, or unless the data is required for the establishment, exercise or defence of legal claims.
In the case of direct marketing, an objection is effective without the user having to provide any reason.
Changes to this Policy
We may update this Policy, in particular in connection with changes to features, providers, laws, AI models or data-processing practices.
If a change materially affects how personal data is used, we will inform users in an appropriate manner, and where a new purpose requires consent, we will obtain it before beginning such processing.
The current version is available at https://aplik.ai/legal/privacy.
Contact
Questions concerning privacy, Google user data, Account deletion, access to or export of data may be directed to:
DIASSET sp. z o.o.
ul. Św. Filipa 23/4
31-150 Kraków, Poland
support@aplik.ai
READY FOR BETTER MATCHES?
Start with opportunities that fit your goals.
Build your profile once and see the roles worth reviewing first.
