Privacy Policy
Updated 21 July , 2025
1. Why This Policy Exists
This Privacy Policy explains what data Biznitos Ltd. (“BKK Staff,” “we,” “our,” “us”) collects, why we collect it, how we use it, and the choices you have. By using the BKK Staff platform (“Service”) you agree to the practices described here.
2. Information We Collect
2.1 Data You Provide
- Account details – name, company, email, password
- Billing info – business address, payment method (processed by Stripe; we never see full card numbers)
- Job‑related content – job posts, candidate notes, interview schedules
- Support messages – emails or chat transcripts with our team
2.2 Data We Collect Automatically
- Usage logs – IP address, browser type, pages visited, time stamps
- Device data – operating system, screen size, language
- Cookies – small files that remember preferences and help us measure performance
2.3 Data from Third Parties
- Applicant data imported from job boards or ATS integrations that you connect
- Analytics data from services like Google Analytics
3. How We Use Your Information
- Provide the Service – authenticate users, display dashboards, send notifications
- Improve the Service – analyze feature usage, fix bugs, develop new tools
- Billing & account management – issue invoices, detect fraud
- Support & communication – respond to questions, send product updates
- Legal compliance – satisfy tax, accounting, and employment‑law obligations
We do not sell or rent your personal data.
4. Legal Bases for Processing (GDPR)
- Contractual necessity – to deliver the Service you signed up for
- Legitimate interests – improve security and product experience
- Consent – email marketing (you can opt out anytime)
- Legal obligation – compliance with laws and regulations
5. Cookies & Tracking
We use first‑party cookies for session management and third‑party cookies for analytics. You can disable cookies in your browser, but parts of the Service may not work.
6. How We Share Information
- Service providers – hosting (AWS), payment processing (Stripe), email delivery (Postmark)
- Authorities – when compelled by law or to protect rights, property, or safety
- Business transfers – in the event of a merger or acquisition, subject to this Policy
All vendors are contractually required to safeguard data and use it only for the tasks we specify.
7. Data Retention
We keep your data only as long as necessary:
- Account data – while your account is active plus 12 months
- Candidate data – until you delete it or 24 months after the job closes, whichever comes first
- Billing records – 7 years for tax compliance
8. Your Rights
Depending on your location, you may have the right to:
- Access, correct, or delete personal data
- Object to or restrict processing
- Export your data (data portability)
- Withdraw consent at any time
Email [email protected] to exercise these rights. We respond within 30 days.
9. Security
We employ encryption in transit (HTTPS) and at rest, least‑privilege access controls, regular penetration testing, and 24/7 monitoring. No method is 100 % secure, but we strive to protect your data.
10. Children’s Privacy
The Service is not directed to children under 16. We do not knowingly collect data from minors.
11. International Transfers
Data may be processed and stored on servers in countries outside your own. We rely on Standard Contractual Clauses or similar safeguards for such transfers.
12. Changes to This Policy
We may update this Policy. Material changes will be announced via email or in‑app. Continued use of the Service a