Legal

Privacy Policy

Learn how your personal data is collected, used, and protected.

1. Data Collected

When you use the platform, account information, business information, integration data, communication data, usage logs, and automation scenarios may be collected.

2. Purposes of Data Use

Data is used to provide services, run integrations, maintain security, provide technical support, and fulfill legal obligations.

3. Data Protection Mechanisms

Data security is ensured with encryption, HTTPS, OAuth 2.0, access controls, and regular security updates.

4. Retention and Deletion Policy

Communication records can be deleted through the platform. Account information is retained until the account is closed; some records may be kept longer due to legal requirements.

5. Sharing with Third Parties

Limited data sharing may occur with integration providers, voice call and AI services, payment processors, and within legal obligations.

6. Cookies

Four categories of cookies may be used on the site: (i) Necessary — required for session management, security, and core functionality, and cannot be disabled; (ii) Functional — remembers preferences such as theme and language; (iii) Analytics — measures site usage with Google Analytics; (iv) Marketing — used for ad performance and retargeting. Analytics and marketing cookies run only with explicit consent. You can change your preferences at any time via the Cookie Preferences link at the bottom of the page or through your browser settings.

7. User Rights

Applications for access, correction, deletion, objection, and data portability rights can be made via destek@candit.ai.

8. Children's Privacy

The platform is not intended for users under 18 and does not knowingly collect data without parental consent.

9. Changes

The policy may be updated from time to time. Significant changes are announced via email or platform notification.

10. Contact

You can reach destek@candit.ai for privacy-related questions.

11. Google User Data (Google API Services)

When a recruiter connects their Google account to Candit, our application accesses the Google Calendar API with only two scopes: calendar events (calendar.events) — to create, update, and cancel interview events with Google Meet links on the connected user's own calendar; and read-only calendar access (calendar.readonly) — to read free/busy information in order to avoid scheduling conflicts. We store only the ID and Google Meet link of the events we create; no other calendar content is stored. Google user data is used solely to provide the interview scheduling feature; it is not used for advertising, is not sold, and is not transferred to third parties. Google user data is not used to create, train, or improve any artificial intelligence or machine learning models (including generalized or foundational models), and is not transferred to third-party AI services for such purposes. Candit's use of raw or derived user data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements ("The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements."). You can disconnect your Google account at any time from Settings → Integrations in the app or from your Google Account security settings (myaccount.google.com/connections); to request deletion of your Google data, contact destek@candit.ai.

Manage Your Cookie Preferences

You can review the consent you have given for analytics and marketing cookies at any time and change it by category.