Legal
Privacy Policy
This policy explains what personal data ApplyOnce processes, why, and the choices you have.
1. Who we are
ApplyOnce (“we”, “us”) operates applyonce.net and related application flows. For privacy requests, email privacy@applyonce.net.
2. Data we collect
Account & employer data
- Name, work email, company name, and authentication details (for example Google sign-in)
- Role configuration, screening questions, logos, and published application links
- Billing details when you purchase a paid plan (processed by our payment provider)
Candidate application data
- CV/resume files and extracted profile fields (experience, education, skills, contact details)
- Answers to employer questions, uploaded files, and submission metadata
- Technical logs needed to operate the flow (timestamps, status, error events)
Usage & device data
- IP address, browser type, approximate location derived from IP, and pages viewed
- Cookies or similar technologies described in our Cookie Policy
3. Why we process data
- Provide the Service — create roles, run application flows, show recruiter evidence
- Secure and operate — authentication, abuse prevention, debugging, uptime
- Communicate — respond to support, send service notices
- Improve the product — aggregated analytics and quality fixes
- Legal compliance — respond to lawful requests and enforce Terms
Where GDPR or similar laws apply, we rely on one or more of: contract performance, legitimate interests (secure, improve, and market the Service in a proportionate way), consent (where required), and legal obligation.
4. Sharing
We do not sell personal data. We share data only with:
- The employer that published the application link (for candidate submissions)
- Infrastructure and subprocessors that host, store, authenticate, email, or process payments
- Professional advisors or authorities when required by law or to protect rights and safety
If we integrate with systems such as Workday at your request, data is shared according to that configuration and your instructions.
5. International transfers
We may process data in the EU/EEA, the United States, or other countries where our providers operate. Where required, we use appropriate transfer safeguards such as Standard Contractual Clauses.
6. Retention
We keep personal data only as long as needed for the purposes above: account life plus a reasonable wind-down period; candidate packages according to the employer’s retention needs and our operational limits; and logs for security and debugging for a limited time. You may request deletion subject to legal holds and backup cycles.
7. Your rights
Depending on your location, you may have rights to:
- Access, correct, or delete personal data
- Restrict or object to certain processing
- Data portability
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority
To exercise these rights, email privacy@applyonce.net. Candidates may also contact the employer that received their application.
8. Security
We use technical and organizational measures appropriate to the risk, including encrypted transport (HTTPS), access controls, and least-privilege practices. No method of transmission or storage is 100% secure.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect their data for ApplyOnce accounts.
10. Changes
We may update this policy. The effective date above will change when we do. Material updates will be posted on this page.
11. Contact
Privacy questions: privacy@applyonce.net.