Last updated: June 2026
Privacy Policy of the Pickr Platform
Last updated: June 2026
This Privacy Policy applies to the website pickr.dev (marketing site and blog) as well as the application app.pickr.dev (the platform).
§ 1 Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG) is:
Agusta GmbH (operating as Pickr)
Oberdorferstraße 4
6850 Dornbirn, Austria
Managing Director: Andreas Amann
Email: datenschutz@pickr.dev
§ 2 Data Protection Officer
Under Art. 37 GDPR in conjunction with § 5 DSG, Agusta GmbH is not currently required to appoint a data protection officer, as the applicable conditions (in particular extensive regular and systematic monitoring of data subjects, or extensive processing of special categories of data as a core activity) are not met.
For data protection inquiries, please contact: datenschutz@pickr.dev
§ 3 Categories of Personal Data
In the course of providing and operating the platform, we process the following categories of personal data:
3.1 Candidate Data
Data of applicants and candidates entered or imported into the platform by our customers:
- Master data: name, email address, phone number, postal address
- Application data: resume/CV, work experience, education, qualifications, language skills
- Salary expectations and availability
- Video and audio recordings of interviews
- AI-generated interview transcriptions
- AI-generated match scores and scorecard evaluations
- Communication history: email threads, WhatsApp messages, LinkedIn messages
- Notes and evaluations by recruiters and interviewers
3.2 User and Employee Data
Data of registered platform users:
- Name, email address
- Role and permission level within the organization
- Calendar data (interview appointments)
- Login activity and audit logs
3.3 End-Client Contact Data (Agency Mode)
Data of contact persons at end clients for whom an agency recruits:
- Name, email address, phone number
- Job descriptions, requirement profiles, hiring requirements
3.4 Audit Tool User Data
Data of users of the free audit tool (pickr.dev/audit):
- Email address, company name
- Submitted process information
§ 4 Legal Bases for Processing
The processing of personal data is based on the following legal bases pursuant to Art. 6(1) GDPR:
4.1 Performance of a Contract (Art. 6(1)(b) GDPR)
- Provision and operation of the platform under the usage agreement (Terms of Service)
- Processing of candidate data on behalf of the customer (processing on behalf of a controller pursuant to Art. 28 GDPR, governed by the DPA at pickr.dev/legal/avv/en)
- Payment processing and invoicing
- Customer communication and support
4.2 Legitimate Interest (Art. 6(1)(f) GDPR)
- Ensuring the security and integrity of the platform (fraud prevention, abuse detection)
- Analysis of usage patterns to improve the platform (based exclusively on anonymized and aggregated data)
- Logging of access and activities (audit logging) for traceability and troubleshooting
- Assertion, exercise, or defense of legal claims
4.3 Consent (Art. 6(1)(a) GDPR)
- Recording of video interviews (consent of interview participants)
- Sending marketing communications (newsletter, product updates), where the user has given express consent
Consent may be withdrawn at any time with effect for the future. The withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
4.4 Legal Obligation (Art. 6(1)(c) GDPR)
- Retention of invoices and payment data in accordance with tax and commercial law retention obligations (§ 132 BAO (Austrian Federal Fiscal Code), § 212 UGB (Austrian Commercial Code): 7 years)
§ 5 Purposes of Processing
Personal data is processed for the following purposes:
- Providing the platform and its core functions (ATS, candidate management, communication)
- AI-assisted processing (matching, scoring, transcription, interview analysis) – see § 6
- Conducting and recording video interviews
- Communication with candidates via integrated channels (email, WhatsApp, LinkedIn)
- Payment processing and subscription management
- Security measures and fraud prevention
- Further development and improvement of the platform (based on anonymized data)
- Compliance with statutory retention obligations
§ 6 AI-Assisted Processing
(1) The platform uses artificial intelligence for the following functions:
- Candidate matching and scoring using Anthropic Claude AI: comparing candidate profiles with the requirement profiles of open positions
- Interview analysis: AI-assisted evaluation of interview content to generate scorecards and rating suggestions
- Transcription: automatic speech-to-text conversion of video interviews using Deepgram
- Generation of interview questions based on the candidate profile and job requirements
(2) AI processing takes place exclusively as inference (model queries). Personal data is never used to train, fine-tune, or improve AI models – neither by Pickr nor by the AI sub-processors engaged (Anthropic, Deepgram). This is contractually agreed with the sub-processors.
(3) The results of AI processing serve exclusively as decision support. No decisions based solely on automated processing within the meaning of Art. 22 GDPR are made. Responsibility for all personnel decisions rests with the customer.
(4) In AI processing, only the personal data necessary for the respective purpose is transmitted to the AI services (data minimization pursuant to Art. 5(1)(c) GDPR).
§ 7 Recipients and Sub-Processors
Personal data is disclosed to the following recipients and sub-processors to the extent necessary for the provision of the platform:
| Recipient | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase, Inc. (via AWS) | Database hosting, authentication, file storage | Zurich, Switzerland | Swiss adequacy decision |
| Vercel, Inc. | Application hosting, serverless functions | Frankfurt, Germany | EU, no third-country transfer |
| Anthropic, PBC | AI matching, scoring, interview analysis | USA | EU-US DPF / SCCs |
| Deepgram, Inc. | Speech-to-text transcription | USA | EU-US DPF / SCCs |
| Daily.co, Inc. | Video interview infrastructure | EU/USA | EU-US DPF / SCCs |
| Resend, Inc. | Transactional email delivery | USA | EU-US DPF / SCCs |
| Stripe, Inc. | Payment processing | EU/USA | Own Art. 28 DPA, EU-US DPF |
| Google LLC | Email synchronization, calendar integration | EU/USA | Google Cloud DPA, EU-US DPF / SCCs |
| Meta Platforms Ireland Limited | WhatsApp Business messaging | EU | EU, no third-country transfer |
| HeyReach d.o.o. | LinkedIn outreach synchronization | EU | EU, no third-country transfer |
All sub-processors are subject to the terms of the Data Processing Agreement (DPA), available at pickr.dev/legal/avv/en.
Personal data is not disclosed to any other third parties beyond this, unless we are legally obliged to do so (e.g., disclosure obligations to law enforcement or supervisory authorities).
§ 8 Use of Google API Data
(1) With your express consent, Pickr accesses certain Google services to provide recruiting functions. Specifically:
8.1 Google Gmail API
Purpose: Synchronizing email conversations with candidates into the Pickr inbox, sending emails on behalf of the user.
Data accessed: Email messages, subject lines, sender and recipient addresses, attachments in conversations with candidates.
Storage:Email content is stored in our database in Switzerland (Supabase, Zurich) and is accessible exclusively to the user's organization.
Retention: Email data is stored for as long as the user account is active. Upon account deletion, all synchronized email data is deleted within 30 days.
Disclosure: Email content is not disclosed to third parties. When AI assistance is enabled, email content is transmitted to our AI provider to generate draft replies, with personal data anonymized beforehand (see § 6 AI-Assisted Processing).
8.2 Google Calendar API
Purpose: Displaying calendar availability for interview scheduling, creating calendar entries for scheduled interviews.
Data accessed: Availability/busy times (no event details), creation of new calendar entries.
Storage: Calendar data is not permanently stored. Availability information is retrieved only at the time of scheduling.
Disclosure: Calendar data is not disclosed to third parties.
8.3 Google OAuth (Sign-In)
Purpose: Authentication and sign-in to Pickr.
Data accessed: Name, email address, profile picture.
Storage: In the user table of our database.
Disclosure: Not to third parties.
(2) Pickr's use of Google API data complies with the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data exclusively to provide the functions described above and do not disclose it for advertising purposes or any other unauthorized purposes.
Google API Limited Use Disclosure: Pickr's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
(3) You can revoke access to your Google data at any time under Settings > Integrations > Disconnect Google. Data already synchronized is not automatically deleted upon disconnection but can be removed upon request.
§ 9 Third-Country Transfers
(1) To the extent personal data is transferred to sub-processors in the USA, the transfer is based on the following safeguards pursuant to Art. 44 et seq. GDPR:
- EU-US Data Privacy Framework (Art. 45 GDPR) – where the recipient is certified,
- Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR, in the version of Implementing Decision (EU) 2021/914.
(2) For sub-processors in Switzerland (Supabase/AWS), an adequacy decision of the European Commission pursuant to Art. 45 GDPR is in place.
(3) Transfer Impact Assessments (TIAs) are conducted for all third-country transfers and made available upon request.
§ 10 Retention Periods
Personal data is stored only for as long as necessary for the respective processing purposes or as required by statutory retention obligations:
| Data category | Retention period | Configurable |
|---|---|---|
| Candidate data | 24 months after last activity on the record | Yes, by the customer |
| Video/audio recordings | 12 months after recording | Yes, by the customer |
| User data | For the duration of the user account | No |
| Audit logs | 12 months | No |
| Communication history | 24 months after last activity | Yes, by the customer |
| Audit tool user data (pickr.dev/audit) | 90 days | No |
| Invoice data | 7 years (§ 132 BAO, § 212 UGB) | No |
After termination of the usage agreement, personal data is deleted within thirty (30) days, unless statutory retention obligations preclude deletion. Backups are deleted within ninety (90) days of contract termination.
§ 11 Data Subject Rights
Data subjects have the following rights under the GDPR:
Right of access (Art. 15 GDPR): You have the right to request information about the personal data we process concerning you, including the purposes of processing, categories of data, recipients, and retention period.
Right to rectification (Art. 16 GDPR): You have the right to request the rectification of inaccurate personal data or the completion of incomplete personal data.
Right to erasure (Art. 17 GDPR): You have the right to request the deletion of your personal data, provided the conditions of Art. 17 GDPR are met.
Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of processing where one of the conditions set out in Art. 18 GDPR is met.
Right to data portability (Art. 20 GDPR): You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format and to transmit it to another controller.
Right to object (Art. 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(f) GDPR.
Right to withdraw consent (Art. 7(3) GDPR): Where processing is based on consent, you have the right to withdraw that consent at any time. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:
Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40-42
1030 Vienna, Austria
Email: dsb@dsb.gv.at
Web: www.dsb.gv.at
To exercise your rights, please contact: datenschutz@pickr.dev. We will respond to your request within one month (Art. 12(3) GDPR).
Note for candidates: If you are a candidate (applicant) wishing to exercise your rights, please note that Pickr generally processes your data as a processor on behalf of our customer (your prospective employer or the recruitment agency engaged). In this case, we will forward your request to the responsible customer, who decides on the processing of your data.
§ 12 Cookies and Tracking
(1) The platform uses exclusively technically necessary cookies:
- Session cookie (Supabase Auth): Used for authentication and session management. This cookie is strictly necessary for the platform to function and does not require consent pursuant to § 165 Abs. 3 TKG 2021 (Austrian Telecommunications Act).
(2) The platform currently does not use tracking cookies, third-party analytics tools (such as Google Analytics), or advertising trackers.
(3) Should the use of analytics or marketing cookies be planned in the future, user consent will be obtained in advance via a cookie consent banner.
§ 13 Security Measures
We implement appropriate technical and organizational measures to protect personal data pursuant to Art. 32 GDPR, in particular:
- Encryption of all data transmissions using TLS 1.2 or higher
- Encryption of stored data using AES-256
- Multi-factor authentication (MFA) via TOTP for all user accounts
- Role-based access control with server-side validation and row-level security at the database level
- Comprehensive audit logging of all data access
- Regular backups with geo-redundant storage within the EU
The complete documentation of the technical and organizational measures (TOMs) is contained in Annex 1 of the DPA (pickr.dev/legal/avv/en).
§ 14 Changes to This Privacy Policy
(1) We reserve the right to amend this Privacy Policy as needed, in particular in the event of changes to the platform's functionality, the sub-processors engaged, or the legal situation.
(2) The current version is available at pickr.dev/legal/privacy/en.
(3) We will notify registered users of material changes by email. Continued use of the platform after the change takes effect constitutes acknowledgment.
§ 15 Contact
If you have questions about data protection or wish to exercise your data subject rights, please contact:
Agusta GmbH (Pickr)
Oberdorferstraße 4
6850 Dornbirn, Austria
Email: datenschutz@pickr.dev
Last updated: June 2026 · Agusta GmbH (Pickr), Oberdorferstraße 4, 6850 Dornbirn, Austria · Web: pickr.dev