Last updated: 20th November 2025
Asterfield Privacy Policy
This Privacy Policy explains how ASTERFIELD LTD (Company No. 789146), operating as Asterfield, collects, uses, stores, and protects your personal data. We are committed to handling your data fairly, transparently, and in compliance with GDPR and all applicable privacy laws.
1. Information We Collect
We collect personal data necessary to provide and improve our services. This includes:
- Account Information: Name, email address, workspace affiliation, and authentication details (including magic link usage).
- Workspace & Agency Data: Details relating to the recruitment agency or company workspace you belong to.
- Candidate & Client Interactions: Notes, feedback, tasks, timelines, approvals, comments, and collaboration activity within the platform.
- Communication Data: Emails, chat messages, WhatsApp interactions (if used), voice notes (transcribed with user consent), and AI-generated communication summaries.
- ATS & Third-Party Integrations: Data synced from applicant tracking systems or tools connected to Asterfield.
- Analytics Data: IP address, device information, browser version, usage patterns, page views, interaction events, error logs, and session recordings (via PostHog, EU-hosted).
- AI Processing Data: Text inputs, comments, feedback, and structured data used to generate summaries, nudges, or predictions (processed using OpenAI or approved AI vendors).
- Files & Uploads: CVs, documents, images, and other files uploaded to the platform, stored securely on AWS S3.
- Payment Data: When applicable (future billing features), billing details and transaction information.
- Cookies & Tracking Data: Information collected via cookies, pixels, tags, and similar technologies.
2. Legal Basis for Processing
We process personal data under the following GDPR-compliant bases:
- Contractual Necessity: To provide access to your workspace, manage candidate submissions, enable client feedback, and deliver core product functionality.
- Legitimate Interests: To improve product performance, secure the platform, detect fraud, automate tasks, and support recruiter–client collaboration.
- Consent: For analytics, cookies, optional marketing communications, WhatsApp interactions, and AI-driven insights where required.
- Legal Obligation: To comply with tax, audit, regulatory, or legal requirements.
3. How We Use Your Data
We use personal data for the following purposes:
- Delivering Core Services: Running your workspace — candidate sourcing and screening, branded candidate submissions, client feedback, role workflows, and recruiter collaboration.
- AI Agents & Automation: Operating AI agents that source and rank candidates, draft branded submissions and outreach, summarise feedback, and generate market intelligence — always subject to human review before anything is sent.
- Email & Magic Link Authentication: Sending login links, notifications, reminders, and workspace-related communications.
- WhatsApp & Messaging: Facilitating two-way communication between recruiters and hiring managers (optional feature).
- Product Improvement: Analysing how the platform is used, diagnosing issues, and improving user experience.
- Security & Fraud Prevention: Monitoring unusual activity, detecting misuse, and protecting user accounts.
- Analytics & Metrics: Using PostHog (EU-hosted) to understand behaviour, measure conversion, and improve performance.
6. Data Retention
We retain your data only for as long as required for the purposes described above or as required by law. Specifically:
- Account & Workspace Data: Retained while your account remains active.
- Candidate, Job & Feedback Data: Retained according to workspace retention settings or until account deletion.
- AI Processing Logs: Retained temporarily and never used for training models.
- Payment Records: Retained for 6 years for tax and accounting purposes.
- Analytics Data: Retained in aggregated or anonymised form where possible.
7. Data Security
We use industry-standard measures to protect your data, including encryption at rest and in transit, access controls, audit logging, secure hosting, and multi-layered firewall protection.
8. International Data Transfers
Some of our service providers operate outside the EU/EEA. When transferring data internationally, we use GDPR-approved safeguards such as SCCs (Standard Contractual Clauses).
9. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access – Request a copy of your data.
- Rectification – Correct inaccurate or incomplete data.
- Erasure – Request deletion of your data.
- Portability – Receive your data in a machine-readable format.
- Restriction – Limit how your data is processed.
- Objection – Object to certain uses of your data.
- Withdraw Consent – For analytics or marketing cookies.
10. Children’s Privacy
Asterfield is intended for business use only and is not directed at individuals under the age of 18. We do not knowingly collect data from minors.
12. Updates to This Privacy Policy
We may update this Privacy Policy periodically. Any changes will be posted on this page, and the date at the top will reflect the most recent update.
Registered in Ireland