Legal

Privacy Policy.

This Policy explains how Heartbeat AI collects, uses, shares, and protects personal data across our recruitment platform, our website, and all related Services. It describes the rights you have over your data and how to exercise them.

Operator White Lotus Technologies Ltd
Effective May 2026
Jurisdiction Headquartered in Nigeria; serves globally
Contact connect@heartbeat365.com

01Who We Are & Our Role

Heartbeat AI is an AI-powered recruitment platform operated by White Lotus Technologies Ltd, a company incorporated in Nigeria ("Heartbeat AI", "we", "our", "us"). We help businesses post jobs, screen candidates, conduct AI-assisted interviews, and manage hiring pipelines. Our platform serves clients in Nigeria, Kenya, Ghana, the United Kingdom, the European Union, and globally.

Understanding our role in processing your data matters because it determines your rights and who you should contact.

Who you are Our role What this means
Customer (recruiter, HR team, employer) Data Controller We collect and use your data to provide and improve our Services, manage your account, and communicate with you.
Candidate (job applicant whose data a Customer submits) Data Processor (on behalf of the Customer) We process your data only on instruction from the Customer (your prospective employer). The Customer is the Controller of your data. For most rights, you should contact the Customer directly. We assist where we are able.
Visitor (browsing heartbeat365.com without an account) Data Controller We collect limited data for analytics, security, and marketing.

02Scope of This Policy

This Policy applies to:

  • Our website and subdomains (heartbeat365.com and related pages);
  • Our web and mobile application and all Services provided through it;
  • All communications we send you (email, in-app, SMS);
  • Candidate Data submitted to the platform by Customers;
  • Anyone who attends our webinars, events, or surveys.

This Policy does not govern how Customers use Candidate data in their own hiring processes. Customers are data controllers for Candidate data and their own privacy policies apply to their relationship with candidates.

03Lawful Bases for Processing

We rely on the following lawful bases depending on the type of processing and your jurisdiction. We do not rely on blanket consent based on your use of the platform — each processing activity has its own identified basis.

Legal basisWhen we rely on it
ContractCreating and managing Customer accounts; delivering purchased Services; billing and invoicing. We cannot provide the Service without this processing.
Legitimate InterestsPlatform security and fraud prevention; aggregated analytics to improve the service; marketing to existing Customers about related Heartbeat AI products (you can opt out at any time). We always balance our interests against yours before relying on this basis.
ConsentNon-essential cookies and tracking technologies; marketing emails to prospects who have not yet subscribed; sharing data with advertising partners for targeted advertising; using personally identifiable Candidate data to train AI models. You may withdraw consent at any time without affecting prior processing.
Legal ObligationComplying with applicable law, responding to regulatory requests or court orders, tax and accounting obligations.
Vital InterestsWhere necessary to protect life in an emergency. This basis is rarely, if ever, used in our context.

Heartbeat AI complies with applicable data protection law in every jurisdiction where we operate, including: the Nigeria Data Protection Act 2023 (NDPA) and Nigeria Data Protection Regulation (NDPR); the Kenya Data Protection Act 2019; the EU General Data Protection Regulation (GDPR); the UK GDPR and Data Protection Act 2018; the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA); the South Africa Protection of Personal Information Act (POPIA); and Ghana Data Protection Act 2012. Where applicable laws overlap, we apply the standard most protective of your rights.

04What Personal Data We Collect

4.1 Data we collect about Customers and their users

CategoryExamplesSource
Account & IdentityFull name, work email address, job title, phone numberProvided by you at signup
Organisation DataCompany name, size, industry, website, logo, job descriptions, salary expectationsProvided by you
Billing & PaymentBilling name and address, invoice details. We do not store full payment card numbers. Payments are processed by certified third-party processors.Provided by you; generated by payment processor
Platform UsageLogin timestamps, jobs created, candidates reviewed, features used, time on platform, session duration, clicksGenerated automatically through your use of the platform
CommunicationsEmails, support requests, feedback, survey responses, webinar participation dataProvided by you
Device & TechnicalIP address, browser type and version, operating system, device identifiers, referring URL, cookiesCollected automatically via cookies and server logs

4.2 Candidate Data processed on behalf of Customers

Important. Heartbeat AI does not collect this data directly from candidates. It is submitted by Customers. The Customer is the data controller. If you are a candidate with questions about a specific hiring process, contact the employer (Customer) directly.
CategoryExamplesSensitivity
Identity & ContactName, email, phone number, location, LinkedIn or professional profile linksStandard
Resume & Work HistoryCV/resume documents, employment history, education, skills, certificationsStandard
Application ResponsesWritten answers to screening questions submitted through the platformStandard
AI Interview ContentVideo and audio recordings of AI-facilitated interviews, auto-generated transcripts, AI summariesHigh — biometric-adjacent
Assessment ResultsSkill test scores, AI evaluation metrics, performance rankingsHigh — hiring decisions
AI Screening OutputsShortlist tier (e.g., Strong Match / Needs Closer Review / Not Aligned), AI reasoning and match scoresHigh — automated profiling
MetadataApplication timestamp, time spent on assessments, interaction patterns within the platformStandard

4.3 Data we collect from visitors

When you browse heartbeat365.com without an account, we collect: IP address and approximate location (country/city level); browser type, device type, and operating system; pages visited, time spent, and referring site; and cookie identifiers (see Section 10).

05How We Use Personal Data

5.1 Customer data

PurposeLegal basisDescription
Account management and securityContractCreating and securing your account, verifying identity, managing user access and permissions.
Service delivery and personalisationContractEnabling recruiters to post jobs, generate candidate links, access applicant data, and use all platform features.
Billing and paymentContractProcessing payment information via third-party processors; issuing invoices.
Administrative communicationsContractSending account alerts, verification emails, security notifications, and service updates.
Customer supportLegitimate Interest / ContractResponding to support requests, feedback, and questions.
Platform analytics and improvementLegitimate InterestAnalysing aggregated usage data to improve features, fix bugs, and improve user experience.
Security and fraud preventionLegitimate InterestConducting vulnerability assessments, detecting abuse, and protecting the platform.
Marketing to existing CustomersLegitimate InterestSending information about Heartbeat AI products and features relevant to your use. You can opt out at any time.
Marketing to prospectsConsentSending promotional emails to people who have subscribed or consented. You can withdraw consent at any time.
Targeted advertising via third-party platformsConsentUsing advertising pixels (e.g., Meta, Google) to deliver targeted ads. Only where you have consented. You can opt out via cookie settings.

5.2 Candidate data

We process Candidate Data only to deliver the Services to the Customer who submitted or generated that data. Specifically:

  • Running AI-powered resume screening and generating shortlist tiers with reasoning;
  • Hosting and facilitating AI interview sessions and capturing recordings and transcripts;
  • Generating assessment scores, AI evaluation outputs, and match scores;
  • Storing and displaying Candidate Data within the Customer's hiring pipeline;
  • Enabling Customers to send automated status notifications to candidates (application received, advanced, or unsuccessful).

We do not use Candidate Data for our own marketing, profiling, product development, or any purpose other than delivering the Services to the relevant Customer. We do not sell Candidate Data.

5.3 AI processing and automated decision-making

Heartbeat AI uses artificial intelligence and machine learning to analyse CVs, interview recordings, written responses, and assessment results. This produces:

  • Shortlist tiers;
  • AI reasoning notes explaining why a candidate received a given tier;
  • Match scores comparing candidates against role criteria;
  • Behavioural and competency indicators derived from interview responses.

Human oversight. Heartbeat AI's AI outputs are decision-support tools only. No candidate is hired or rejected by an automated system alone. All final hiring decisions are made by the Customer (the employer). A human decision-maker reviews AI outputs before any consequential decision is taken.

Your right to contest. Under GDPR Article 22, NDPA Section 32, and equivalent provisions in other applicable laws, individuals have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. If you are a candidate and believe a significant decision about you was made without adequate human involvement, contact the employer (Customer) who initiated the process. Customers are obligated to provide information about how AI was used and to facilitate human review upon request.

No special category data by default. Our AI models do not intentionally analyse or infer special category data (race, ethnicity, health, religion, sexual orientation, political opinions, or biometric identity) from candidate submissions. Customers must not use the platform to collect or process special category data without first obtaining explicit consent from candidates and notifying Heartbeat AI.

5.4 AI model training

We may use aggregated, anonymised, or de-identified platform usage data — such as general usage patterns and system interactions — to improve and train our internal AI models. This data contains no personally identifiable information.

We will never use personally identifiable Candidate Data (names, resumes, interview recordings, or assessment responses) for AI model training unless: (i) the Customer has given express written consent; and (ii) appropriate data subject consent from each affected Candidate has been lawfully obtained. We will update this Policy and notify you before any such change.

06Who We Share Data With

We do not sell personal data. We do not share personal data with third parties for their own marketing purposes (including mobile numbers and SMS opt-in data). We share data only as described below.

6.1 Third-party service providers

We engage carefully selected third-party providers who process data on our behalf under binding data processing agreements. They are permitted to use data only for the purposes we specify.

CategoryPurposeData processed
Cloud InfrastructureHosting the platform, data storage and backupAll platform data
AI / LLM ProvidersPowering resume screening, interview analysis, and assessment scoringCandidate Data (on Customer instruction)
Payment ProcessorsProcessing subscription and invoice payments (PCI-DSS certified)Billing information only; not full card numbers
Email & SMS ProvidersSending transactional emails, OTPs, MFA messages, notificationsName, email address, phone number
Analytics ToolsAggregated platform usage analytics (no individual profiling)Anonymised usage data
Customer Support PlatformsManaging support tickets and communicationsSupport correspondence, account identifiers
Video InfrastructureHosting and processing async interview recordingsVideo and audio recordings, transcripts
Advertising Platforms (consent-gated)Delivering targeted advertising to prospective Customers only where you have consented via cookie settingsPseudonymous identifiers, interaction data

6.2 Customers

Candidate Data is made available to the Customer who submitted or generated that data, through the platform. Customers may grant access to their authorised users (HR managers, hiring managers, team members). Customers are solely responsible for managing access within their accounts.

6.3 Legal and regulatory disclosure

We may disclose personal data where required by law, court order, regulatory authority, or a government request, including for law enforcement or national security purposes. In such cases, we will: evaluate the legality and necessity of the request; limit disclosure to the minimum necessary; and notify you in advance where permitted by law.

6.4 Business transfers

If Heartbeat AI undergoes a merger, acquisition, asset sale, or similar transaction, personal data may be transferred to a successor entity. We will notify Customers and, where possible, Candidates via email and prominent platform notice at least 30 days before personal data becomes subject to a different privacy policy.

6.5 Affiliates

We may share data with current or future Heartbeat AI-affiliated entities, provided they use it in a manner consistent with this Policy. We will notify you of any new affiliate data-sharing arrangements.

07International Data Transfers

Heartbeat AI is headquartered in Nigeria. We serve Customers globally, and our third-party service providers may be located in various countries. This means personal data may be transferred to and stored in countries outside your own, including countries with different data protection standards from your jurisdiction.

We do not rely on "user consent through use of the platform" as a transfer mechanism. We put appropriate safeguards in place for every international transfer.

You may request a copy of the relevant transfer safeguards applicable to your data by contacting connect@heartbeat365.com.

08Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, and as required by applicable law. We do not retain data indefinitely.

Where we are required to retain data for longer by law (e.g., for tax or regulatory purposes), we will do so and will restrict it to the minimum necessary. Where data is no longer needed, it is securely deleted or anonymised.

Prior to the deletion of long-held Customer data, we will send a reminder email giving you an opportunity to download or retain information you may need.

Contact connect@heartbeat365.com if you have questions about retention of your specific data.

09Your Privacy Rights

Your rights depend on your jurisdiction. We honour the rights below regardless of location, to the extent technically and legally feasible. To exercise any right, contact connect@heartbeat365.com with the subject line "Privacy Rights Request" and include sufficient information to verify your identity.

9.1 Rights available to all users

RightWhat it means in practice
AccessRequest a copy of the personal data we hold about you, in a readable format.
Correction / RectificationRequest that inaccurate, incomplete, or outdated data be corrected.
Erasure / DeletionRequest deletion of your personal data, subject to legal retention obligations and other lawful grounds for continued processing.
ObjectionObject to processing based on legitimate interests (including direct marketing). We will stop unless we have compelling, legitimate grounds.
RestrictionRequest that we restrict processing of your data in certain circumstances (e.g., while accuracy is contested).
PortabilityReceive your personal data in a structured, commonly used, machine-readable format (JSON or CSV), and transmit it to another controller.
Withdraw ConsentWithdraw consent at any time for consent-based processing. Withdrawal does not affect prior lawful processing.
Automated Decision-MakingNot be subject to a decision based solely on automated processing — including AI-generated hiring scores — that produces significant effects. See Section 5.3.

10Cookies and Tracking Technologies

We use cookies, pixels, and similar technologies to operate our platform, understand how it is used, and — where you consent — deliver targeted advertising.

TypePurposeLegal basisOpt out?
Strictly Necessary Authentication, session management, security. The platform cannot function without these. Contract / Legitimate Interest No — essential to the Service
Functional Remembering your preferences (language, UI settings, notification choices). Legitimate Interest Yes, via cookie settings
Analytics Understanding platform usage: page views, feature use, and session data. Data is aggregated and does not identify individuals. Legitimate Interest / Consent Yes, via cookie settings
Advertising Pixels (Meta, Google, others) Tracking conversions from ads, building audiences for targeted advertising, and remarketing to visitors. Only placed where you consent. Consent Yes — withdraw consent via cookie settings at any time

You can manage cookie preferences through your browser settings or our cookie preference centre on the platform. Withdrawing consent for non-essential cookies does not affect your ability to use the core platform.

Where we use advertising pixels (Meta Pixel, Google Ads, etc.), we do not share personally identifiable information directly with those platforms through the pixel. Pixel data is pseudonymised before transmission. You can also opt out via the advertising platform's own settings (e.g., Google Ads Settings, Facebook Ad Preferences).

11Security of Your Personal Information

We implement security measures designed to protect your information from unauthorized access. Your account is protected by your account password, and we urge you to take steps to keep your Personal Information safe by not disclosing your password and by logging out of your account after each use. We further protect your information from potential security breaches by implementing certain technological security measures.

However, these measures do not guarantee that your information will not be accessed, disclosed, altered, or destroyed by breach of such firewalls and secure server software. While we use reasonable efforts to protect your Personal Information, we cannot guarantee its absolute security. By using our Service, you acknowledge that you understand and agree to assume these risks.

12Children's Privacy

Heartbeat AI is a professional platform intended exclusively for use by businesses and adult individuals. We do not knowingly collect, solicit, or process personal data from anyone under the age of 18. If you are under 18, do not use this platform or provide any personal information.

If we learn that we have inadvertently collected personal data from anyone under 18, we will delete it promptly. If you believe we hold data about a minor, contact connect@heartbeat365.com immediately.

Note. Some jurisdictions set a younger minimum age for data protection purposes (e.g., age 13 under US COPPA, age 16 under some EU member state implementations of GDPR). Regardless, our minimum age for platform use is 18 globally.

13Third-Party Websites and Integrations

Our platform may contain links to third-party websites or integrate with third-party services. This Privacy Policy applies only to data processed by Heartbeat AI. Third-party sites and services have their own privacy policies, which we encourage you to read before using them. We are not responsible for the privacy practices of third parties.

14Marketing Communications

We may contact you with information about Heartbeat AI products and services. The basis for this depends on your relationship with us:

  • Existing Customers. We may send marketing communications based on legitimate interest. You can opt out at any time via the unsubscribe link in any email or by contacting connect@heartbeat365.com.
  • Prospects. We will only send marketing emails where you have given consent. You can withdraw consent at any time.

Even if you opt out of marketing, we may still send essential transactional and administrative communications (e.g., account alerts, invoices, service updates, policy changes). We do not share your email address, mobile number, or SMS opt-in data with third parties for their own marketing purposes.

15Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:

  • Update the Effective Date at the top of this document;
  • Notify Customers by email to the registered account address, at least 14 days before changes take effect;
  • Display a prominent notice on the platform.

Your continued use of the platform after the effective date constitutes acceptance of the updated Policy. If you do not agree, you should discontinue use and may request account deletion before the effective date.

Non-material changes (e.g., corrections, clarifications, updated contact details) take effect immediately upon posting.

16Contact and Complaints

For privacy questions, rights requests, or complaints, contact us at:

Heartbeat AI — Privacy Team
White Lotus Technologies Ltd
Privacy email: connect@heartbeat365.com