1. Who We Are
HireAI is an AI-powered recruitment platform operated by MOHAN DRESSES, a business registered in India at 753, FUHARA, LORDGANJ, JABALPUR, Jabalpur, Madhya Pradesh 482001. HireAI enables businesses and recruiting agencies to communicate with job candidates through WhatsApp Business messaging. Our platform allows Clients to connect their WhatsApp Business Account and automate candidate outreach, screening, and follow-up using AI.
We act as a data processor on behalf of our Clients (the data controllers) when handling candidate data. We act as a data controller for data relating to our Client accounts and platform operations.
2. Data We Collect
2a. Data from Clients (Recruiters / Businesses)
| Data Type | Examples | Purpose |
|---|---|---|
| Account Information | Name, company name, email, password | Account creation and authentication |
| Facebook / Meta Login Data | Facebook Business ID, access tokens, WhatsApp Business Account (WABA) ID, Phone Number ID | Connecting client's WhatsApp Business Account to our platform |
| Business Information | Company name, industry, job listings | Personalizing AI agent behavior |
| Usage Data | Login times, features used, message volumes | Platform improvement and billing |
2b. Data from Candidates (End Recipients)
| Data Type | Examples | Purpose |
|---|---|---|
| Contact Information | WhatsApp phone number, name (if shared) | Sending and receiving recruitment messages |
| Message Content | Text messages sent and received in the conversation | AI agent context, conversation history, reply generation |
| Conversation Metadata | Message timestamps, read receipts, message IDs | Delivery tracking and conversation management |
3. How We Use Data
We use collected data strictly to provide and improve our recruitment messaging service. Specifically:
- To authenticate Clients via Facebook Login and connect their WhatsApp Business Account
- To send approved WhatsApp message templates to candidates on behalf of Clients
- To receive and process candidate replies via Meta webhooks
- To generate AI-powered responses and send them back to candidates on behalf of Clients
- To maintain conversation history for context continuity within the AI agent
- To provide Clients with a dashboard to monitor and manage conversations
- To detect and prevent fraud, abuse, or policy violations
- To comply with legal obligations
4. Use of Meta / Facebook Platform Data
Our platform integrates with Meta's Facebook Login and WhatsApp Cloud API. When Clients log in using Facebook and connect their WhatsApp Business Account, we receive certain Platform Data from Meta.
What Platform Data We Access
- Facebook Business Account ID and business name
- WhatsApp Business Account (WABA) ID
- WhatsApp Business Phone Number ID
- Access tokens required to send/receive messages via the API
- Incoming message content delivered through Meta Webhooks
How We Use Platform Data
Platform Data obtained from Meta is used exclusively to:
- Authenticate and connect the Client's WhatsApp Business Account to our platform
- Send WhatsApp messages to candidates on behalf of the Client
- Receive and process inbound candidate messages via webhooks
- Enable our AI agent to respond to candidates within the Client's WhatsApp conversation thread
What We Do NOT Do with Platform Data
- We do not sell or license Meta Platform Data to any third party
- We do not use Platform Data for advertising or marketing purposes
- We do not transfer Platform Data to data brokers or analytics platforms
- We do not combine Platform Data with other datasets for profiling purposes
- We do not retain access tokens beyond their operational necessity
Our use of Meta Platform Data complies with Meta's Platform Terms and Developer Policies.
5. WhatsApp Business Messaging
Our platform sends WhatsApp messages to candidates strictly on behalf of Clients using the Client's own WhatsApp Business Account. We do not send messages using our own WhatsApp number.
Candidate Consent
It is the responsibility of our Clients (recruiters and businesses) to ensure that candidates have provided valid opt-in consent to receive WhatsApp messages before initiating any conversation. Our platform provides tools to help Clients record and manage this consent. We do not contact candidates who have not opted in.
Message Templates
Initial outreach messages are sent using Meta-approved message templates only. Free-form AI responses are sent exclusively within the 24-hour customer service window that opens after a candidate replies, in accordance with WhatsApp's messaging policies.
AI-Generated Responses
Our AI agent reads incoming candidate messages to generate contextually appropriate replies. Message content used by the AI is processed in real-time and stored as conversation history solely to maintain context for the ongoing recruitment conversation. This data is not used for AI model training without explicit consent.
6. Data Sharing & Third Parties
We do not sell your data. We only share data in the following limited circumstances:
Service Providers
We work with trusted third-party service providers who assist in operating our platform, such as cloud hosting, database storage, and AI inference. These providers are contractually bound to process data only on our instructions and may not use it for their own purposes.
Meta (Facebook / WhatsApp)
To provide the WhatsApp messaging service, data is transmitted to and from Meta's infrastructure via the WhatsApp Cloud API and Meta Webhooks. This transmission is governed by Meta's own privacy policy and platform terms.
Legal Requirements
We may disclose data if required by law, court order, or to protect the rights, property, or safety of our users or the public.
Business Transfers
In the event of a merger, acquisition, or sale of assets, user data may be transferred as part of the transaction. We will notify affected users in advance.
7. Data Retention
We retain data only as long as necessary to provide our service:
- Client account data — retained for the duration of the account and up to 90 days after account deletion
- WhatsApp access tokens — retained only while the Client's account is active and the integration is connected
- Conversation history — retained for up to 12 months, or until the Client deletes it, whichever is sooner
- Candidate contact data — retained only for the duration of the active recruitment campaign, unless required by law
- Webhook logs — retained for 30 days for debugging and compliance purposes
Clients may request deletion of all their data and their candidates' data at any time by contacting us or using the data deletion tool within the platform dashboard.
8. Data Security
We implement industry-standard technical and organizational measures to protect your data, including:
- AES-256 encryption for stored access tokens and sensitive credentials
- TLS 1.2+ encryption for all data in transit
- Webhook signature verification (X-Hub-Signature-256) on all incoming Meta webhook events
- Role-based access controls limiting internal access to data
- Regular security audits and vulnerability assessments
- Secure, isolated database environments per-tenant
While we take every reasonable precaution, no system is completely immune to security risks. We will notify affected users promptly in the event of a data breach as required by applicable law.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — Request a copy of the data we hold about you
- Correction — Request correction of inaccurate or incomplete data
- Deletion — Request deletion of your personal data (right to be forgotten)
- Portability — Request your data in a structured, machine-readable format
- Objection — Object to certain types of processing, including automated decision-making
- Withdraw Consent — Withdraw previously given consent at any time without affecting prior processing
- Disconnect Integration — Revoke our access to your WhatsApp Business Account at any time via Meta Business Settings
To exercise any of these rights, contact us at karanpeshwani7@gmail.com. We will respond within 30 days.
10. Children's Privacy
Our platform is intended solely for use by businesses and professionals. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided us with personal data, please contact us immediately and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify active Clients via email or an in-platform notification
- Where required by law, request renewed consent
Continued use of our platform after changes are posted constitutes acceptance of the revised policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
📧 Email: karanpeshwani7@gmail.com
🏠 Address: 753, FUHARA, LORDGANJ, JABALPUR, Jabalpur, Madhya Pradesh, 482001
📅 Response Time: Within 30 business days
For data deletion requests specifically related to Facebook or WhatsApp data, you may also visit:
Meta Data Deletion Request Page ↗