P
Popcorns HireFlow

Privacy Policy

Last updated: June 2026

In plain language: We store only the data you give us to operate the Service. We do not sell it. We do not use your offer content or candidate data to train AI, market to your candidates, or build profiles of individuals. We use aggregated, anonymized data for platform analytics and benchmarking — no individual, company, or candidate can be identified from it. The company using HireFlow is the issuer of every offer and the controller of the candidate data inside it — Popcorns is the processor on their behalf.

1. Who we are

Popcorns ("we", "us") operates Popcorns HireFlow. For privacy questions, contact privacy@popcorns.ch.

2. What we collect

Account data (about you as a user):

  • Your name, email, username, interface language preference.
  • Your company name, country, size, tax ID, contact details you provide at registration.
  • Your login history (timestamps, last login).

Offer content (data you enter into offers):

  • Candidate name, email, phone (if you choose to add them).
  • Job title, salary, benefits, and other offer details you enter.
  • Offer status changes and timestamps (draft, active, sent, accepted, etc.).

Technical data (when the public offer link is opened):

  • View counts and timestamps of when the public offer link is accessed. We do NOT log IP addresses or device fingerprints of candidates.

3. Why we process this data (legal basis)

  • Contract: To provide the Service you signed up for.
  • Legitimate interest: To protect candidates from fraudulent offers (account verification), and to secure the platform.
  • Legal obligation: To comply with tax, accounting, and legal obligations where applicable.

4. How we use your data

  • To operate the platform: create, store, and render offers.
  • To verify your company and prevent misuse.
  • To communicate service-related information (login confirmations, verification emails).

Aggregate and anonymized analytics. We derive aggregate, anonymized insights from data across the platform — for example, average salary ranges by role type or industry, offer acceptance rates by region, hiring volume trends, or common benefit structures. This data is always anonymized: no individual company, user, or candidate can be identified from it. We may use these aggregate insights to improve the Service or publish them as market research and benchmarking reports. By using the Service, you consent to this use of anonymized, aggregate data derived from your activity.

5. What we do NOT do

  • We do not sell your data to third parties.
  • We do not use your offer content to train AI models.
  • We do not market to the candidates you enter into the system.
  • We do not share your data with recruiters, competitors, or data brokers.
  • We do not use tracking cookies for advertising.

6. Candidate data specifically

When you enter a candidate's details into an offer, Popcorns acts as a data processor and you are the data controller. You are responsible for ensuring you have a legal basis to process the candidate's data (typically: you are actively in a hiring process with them).

Candidate data is stored only within your account. It is not visible to other accounts, not used for any other purpose, and is deleted when you delete the offer.

7. Data retention

  • Active account data is retained while your account is active.
  • Offer content and audit logs are retained for as long as the offer exists in your account.
  • On account deletion, all your data is deleted within 30 days, except data we are legally required to retain (e.g., billing records).
  • Unverified accounts that remain inactive for 90 days may be deleted.

8. Your rights (GDPR)

If you are in the EU or EEA, you have the right to:

  • Access: Request a copy of the data we hold about you.
  • Rectification: Correct inaccurate data.
  • Erasure: Request deletion (subject to legal obligations).
  • Portability: Receive your data in a machine-readable format.
  • Object: Object to processing based on legitimate interest.
  • Restriction: Request that processing be limited.
  • Complaint: File a complaint with your local data protection authority.

To exercise these rights, email privacy@popcorns.ch.

9. Data location and transfers

Data is stored on infrastructure located within the European Union. We do not transfer personal data outside the EU/EEA except where appropriate legal safeguards are in place (such as standard contractual clauses or an adequacy decision recognized by the European Commission).

Operational support and account management may be provided from outside the EU/EEA (specifically: from Serbia, where the operating company iConsult d.o.o. is registered). Any access from Serbia is performed on infrastructure located within the EU under appropriate technical and organizational safeguards.

10. Security

We use technical and organizational measures appropriate to the sensitivity of the data, including:

  • HTTPS/TLS for all connections to the Service
  • Encryption at rest at the infrastructure layer
  • Encrypted, separately stored database backups
  • Role-based access controls within accounts
  • Restricted, logged access by Popcorns staff (only when necessary for support or operations)
  • Audit logging of significant actions on offers

No system is perfectly secure. In the event of a personal data breach affecting your data, we will notify affected accounts within seventy-two hours of becoming aware of the breach (in accordance with GDPR Article 33), describing what happened, what data was affected, and what action you should take.

For a more detailed overview of how data is handled, see the Security and data handling page.

11. Cookies

We use only strictly necessary cookies for session management (keeping you logged in). We do not use analytics cookies, advertising cookies, or third-party tracking cookies.

12. Changes

We may update this policy. Significant changes will be communicated to registered users. The "last updated" date above indicates the latest revision.

← Back to Popcorns HireFlow · Terms of Service · Security · FAQ