Last updated: June 2026

ENDE
This English translation is provided for convenience only. The German version is the legally binding text. View the German version.

Privacy Policy of the Pickr Platform

Last updated: June 2026

This Privacy Policy applies to the website pickr.dev (marketing site and blog) as well as the application app.pickr.dev (the platform).


§ 1 Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG) is:

Agusta GmbH (operating as Pickr)
Oberdorferstraße 4
6850 Dornbirn, Austria

Managing Director: Andreas Amann
Email: datenschutz@pickr.dev

§ 2 Data Protection Officer

Under Art. 37 GDPR in conjunction with § 5 DSG, Agusta GmbH is not currently required to appoint a data protection officer, as the applicable conditions (in particular extensive regular and systematic monitoring of data subjects, or extensive processing of special categories of data as a core activity) are not met.

For data protection inquiries, please contact: datenschutz@pickr.dev

§ 3 Categories of Personal Data

In the course of providing and operating the platform, we process the following categories of personal data:

3.1 Candidate Data

Data of applicants and candidates entered or imported into the platform by our customers:

  • Master data: name, email address, phone number, postal address
  • Application data: resume/CV, work experience, education, qualifications, language skills
  • Salary expectations and availability
  • Video and audio recordings of interviews
  • AI-generated interview transcriptions
  • AI-generated match scores and scorecard evaluations
  • Communication history: email threads, WhatsApp messages, LinkedIn messages
  • Notes and evaluations by recruiters and interviewers

3.2 User and Employee Data

Data of registered platform users:

  • Name, email address
  • Role and permission level within the organization
  • Calendar data (interview appointments)
  • Login activity and audit logs

3.3 End-Client Contact Data (Agency Mode)

Data of contact persons at end clients for whom an agency recruits:

  • Name, email address, phone number
  • Job descriptions, requirement profiles, hiring requirements

3.4 Audit Tool User Data

Data of users of the free audit tool (pickr.dev/audit):

  • Email address, company name
  • Submitted process information

§ 4 Legal Bases for Processing

The processing of personal data is based on the following legal bases pursuant to Art. 6(1) GDPR:

4.1 Performance of a Contract (Art. 6(1)(b) GDPR)

  • Provision and operation of the platform under the usage agreement (Terms of Service)
  • Processing of candidate data on behalf of the customer (processing on behalf of a controller pursuant to Art. 28 GDPR, governed by the DPA at pickr.dev/legal/avv/en)
  • Payment processing and invoicing
  • Customer communication and support

4.2 Legitimate Interest (Art. 6(1)(f) GDPR)

  • Ensuring the security and integrity of the platform (fraud prevention, abuse detection)
  • Analysis of usage patterns to improve the platform (based exclusively on anonymized and aggregated data)
  • Logging of access and activities (audit logging) for traceability and troubleshooting
  • Assertion, exercise, or defense of legal claims

4.3 Consent (Art. 6(1)(a) GDPR)

  • Recording of video interviews (consent of interview participants)
  • Sending marketing communications (newsletter, product updates), where the user has given express consent

Consent may be withdrawn at any time with effect for the future. The withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

4.4 Legal Obligation (Art. 6(1)(c) GDPR)

  • Retention of invoices and payment data in accordance with tax and commercial law retention obligations (§ 132 BAO (Austrian Federal Fiscal Code), § 212 UGB (Austrian Commercial Code): 7 years)

§ 5 Purposes of Processing

Personal data is processed for the following purposes:

  • Providing the platform and its core functions (ATS, candidate management, communication)
  • AI-assisted processing (matching, scoring, transcription, interview analysis) – see § 6
  • Conducting and recording video interviews
  • Communication with candidates via integrated channels (email, WhatsApp, LinkedIn)
  • Payment processing and subscription management
  • Security measures and fraud prevention
  • Further development and improvement of the platform (based on anonymized data)
  • Compliance with statutory retention obligations

§ 6 AI-Assisted Processing

(1) The platform uses artificial intelligence for the following functions:

  • Candidate matching and scoring using Anthropic Claude AI: comparing candidate profiles with the requirement profiles of open positions
  • Interview analysis: AI-assisted evaluation of interview content to generate scorecards and rating suggestions
  • Transcription: automatic speech-to-text conversion of video interviews using Deepgram
  • Generation of interview questions based on the candidate profile and job requirements

(2) AI processing takes place exclusively as inference (model queries). Personal data is never used to train, fine-tune, or improve AI models – neither by Pickr nor by the AI sub-processors engaged (Anthropic, Deepgram). This is contractually agreed with the sub-processors.

(3) The results of AI processing serve exclusively as decision support. No decisions based solely on automated processing within the meaning of Art. 22 GDPR are made. Responsibility for all personnel decisions rests with the customer.

(4) In AI processing, only the personal data necessary for the respective purpose is transmitted to the AI services (data minimization pursuant to Art. 5(1)(c) GDPR).

§ 7 Recipients and Sub-Processors

Personal data is disclosed to the following recipients and sub-processors to the extent necessary for the provision of the platform:

RecipientPurposeLocationTransfer mechanism
Supabase, Inc. (via AWS)Database hosting, authentication, file storageZurich, SwitzerlandSwiss adequacy decision
Vercel, Inc.Application hosting, serverless functionsFrankfurt, GermanyEU, no third-country transfer
Anthropic, PBCAI matching, scoring, interview analysisUSAEU-US DPF / SCCs
Deepgram, Inc.Speech-to-text transcriptionUSAEU-US DPF / SCCs
Daily.co, Inc.Video interview infrastructureEU/USAEU-US DPF / SCCs
Resend, Inc.Transactional email deliveryUSAEU-US DPF / SCCs
Stripe, Inc.Payment processingEU/USAOwn Art. 28 DPA, EU-US DPF
Google LLCEmail synchronization, calendar integrationEU/USAGoogle Cloud DPA, EU-US DPF / SCCs
Meta Platforms Ireland LimitedWhatsApp Business messagingEUEU, no third-country transfer
HeyReach d.o.o.LinkedIn outreach synchronizationEUEU, no third-country transfer

All sub-processors are subject to the terms of the Data Processing Agreement (DPA), available at pickr.dev/legal/avv/en.

Personal data is not disclosed to any other third parties beyond this, unless we are legally obliged to do so (e.g., disclosure obligations to law enforcement or supervisory authorities).

§ 8 Use of Google API Data

(1) With your express consent, Pickr accesses certain Google services to provide recruiting functions. Specifically:

8.1 Google Gmail API

Purpose: Synchronizing email conversations with candidates into the Pickr inbox, sending emails on behalf of the user.

Data accessed: Email messages, subject lines, sender and recipient addresses, attachments in conversations with candidates.

Storage:Email content is stored in our database in Switzerland (Supabase, Zurich) and is accessible exclusively to the user's organization.

Retention: Email data is stored for as long as the user account is active. Upon account deletion, all synchronized email data is deleted within 30 days.

Disclosure: Email content is not disclosed to third parties. When AI assistance is enabled, email content is transmitted to our AI provider to generate draft replies, with personal data anonymized beforehand (see § 6 AI-Assisted Processing).

8.2 Google Calendar API

Purpose: Displaying calendar availability for interview scheduling, creating calendar entries for scheduled interviews.

Data accessed: Availability/busy times (no event details), creation of new calendar entries.

Storage: Calendar data is not permanently stored. Availability information is retrieved only at the time of scheduling.

Disclosure: Calendar data is not disclosed to third parties.

8.3 Google OAuth (Sign-In)

Purpose: Authentication and sign-in to Pickr.

Data accessed: Name, email address, profile picture.

Storage: In the user table of our database.

Disclosure: Not to third parties.

(2) Pickr's use of Google API data complies with the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data exclusively to provide the functions described above and do not disclose it for advertising purposes or any other unauthorized purposes.

Google API Limited Use Disclosure: Pickr's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

(3) You can revoke access to your Google data at any time under Settings > Integrations > Disconnect Google. Data already synchronized is not automatically deleted upon disconnection but can be removed upon request.

§ 9 Third-Country Transfers

(1) To the extent personal data is transferred to sub-processors in the USA, the transfer is based on the following safeguards pursuant to Art. 44 et seq. GDPR:

  • EU-US Data Privacy Framework (Art. 45 GDPR) – where the recipient is certified,
  • Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR, in the version of Implementing Decision (EU) 2021/914.

(2) For sub-processors in Switzerland (Supabase/AWS), an adequacy decision of the European Commission pursuant to Art. 45 GDPR is in place.

(3) Transfer Impact Assessments (TIAs) are conducted for all third-country transfers and made available upon request.

§ 10 Retention Periods

Personal data is stored only for as long as necessary for the respective processing purposes or as required by statutory retention obligations:

Data categoryRetention periodConfigurable
Candidate data24 months after last activity on the recordYes, by the customer
Video/audio recordings12 months after recordingYes, by the customer
User dataFor the duration of the user accountNo
Audit logs12 monthsNo
Communication history24 months after last activityYes, by the customer
Audit tool user data (pickr.dev/audit)90 daysNo
Invoice data7 years (§ 132 BAO, § 212 UGB)No

After termination of the usage agreement, personal data is deleted within thirty (30) days, unless statutory retention obligations preclude deletion. Backups are deleted within ninety (90) days of contract termination.

§ 11 Data Subject Rights

Data subjects have the following rights under the GDPR:

Right of access (Art. 15 GDPR): You have the right to request information about the personal data we process concerning you, including the purposes of processing, categories of data, recipients, and retention period.

Right to rectification (Art. 16 GDPR): You have the right to request the rectification of inaccurate personal data or the completion of incomplete personal data.

Right to erasure (Art. 17 GDPR): You have the right to request the deletion of your personal data, provided the conditions of Art. 17 GDPR are met.

Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of processing where one of the conditions set out in Art. 18 GDPR is met.

Right to data portability (Art. 20 GDPR): You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format and to transmit it to another controller.

Right to object (Art. 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(f) GDPR.

Right to withdraw consent (Art. 7(3) GDPR): Where processing is based on consent, you have the right to withdraw that consent at any time. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:

Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40-42
1030 Vienna, Austria
Email: dsb@dsb.gv.at
Web: www.dsb.gv.at

To exercise your rights, please contact: datenschutz@pickr.dev. We will respond to your request within one month (Art. 12(3) GDPR).

Note for candidates: If you are a candidate (applicant) wishing to exercise your rights, please note that Pickr generally processes your data as a processor on behalf of our customer (your prospective employer or the recruitment agency engaged). In this case, we will forward your request to the responsible customer, who decides on the processing of your data.

§ 12 Cookies and Tracking

(1) The platform uses exclusively technically necessary cookies:

  • Session cookie (Supabase Auth): Used for authentication and session management. This cookie is strictly necessary for the platform to function and does not require consent pursuant to § 165 Abs. 3 TKG 2021 (Austrian Telecommunications Act).

(2) The platform currently does not use tracking cookies, third-party analytics tools (such as Google Analytics), or advertising trackers.

(3) Should the use of analytics or marketing cookies be planned in the future, user consent will be obtained in advance via a cookie consent banner.

§ 13 Security Measures

We implement appropriate technical and organizational measures to protect personal data pursuant to Art. 32 GDPR, in particular:

  • Encryption of all data transmissions using TLS 1.2 or higher
  • Encryption of stored data using AES-256
  • Multi-factor authentication (MFA) via TOTP for all user accounts
  • Role-based access control with server-side validation and row-level security at the database level
  • Comprehensive audit logging of all data access
  • Regular backups with geo-redundant storage within the EU

The complete documentation of the technical and organizational measures (TOMs) is contained in Annex 1 of the DPA (pickr.dev/legal/avv/en).

§ 14 Changes to This Privacy Policy

(1) We reserve the right to amend this Privacy Policy as needed, in particular in the event of changes to the platform's functionality, the sub-processors engaged, or the legal situation.

(2) The current version is available at pickr.dev/legal/privacy/en.

(3) We will notify registered users of material changes by email. Continued use of the platform after the change takes effect constitutes acknowledgment.

§ 15 Contact

If you have questions about data protection or wish to exercise your data subject rights, please contact:

Agusta GmbH (Pickr)
Oberdorferstraße 4
6850 Dornbirn, Austria
Email: datenschutz@pickr.dev


Last updated: June 2026 · Agusta GmbH (Pickr), Oberdorferstraße 4, 6850 Dornbirn, Austria · Web: pickr.dev