Nasiya

Privacy Policy

Effective date: 20 May 2026  ·  Last updated: 20 May 2026

This Privacy Policy explains how Nasiya Inc. (“Nasiya”, “we”, “our”, or “us”) collects, uses, stores, shares, and protects information when you use our platform at app.nasiya.co, our Chrome browser extension, and any related services (collectively, the “Service”). By using the Service, you agree to the practices described in this policy.

1. Who We Are

Nasiya is an AI-powered hiring intelligence platform designed for recruiters, HR professionals, and hiring teams. Our platform helps organisations evaluate job candidates using artificial intelligence, extracting structured insights from CVs, resumes, and candidate profiles to support — not replace — human hiring decisions.

For the purposes of data protection law, Nasiya acts as a data controller for account holder data and as a data processor for candidate personal data that your organisation submits to us.

Contact us at: support@nasiya.co

2. Data We Collect

2.1 Account Holder Data

When you create a Nasiya account or use our platform, we collect:

  • Identity data: full name, email address, job designation
  • Authentication data: hashed password or third-party authentication tokens
  • Profile preferences: chosen theme, interview language preference, notification settings
  • Organisation data: organisation name, domain, industry context descriptions, hiring location and jurisdiction settings, AI calibration preferences (scoring weights, prompt addenda)
  • Usage logs: pages visited, roles created, candidates viewed, features used, timestamps of actions. We use this internally for product improvement and support.
  • Feedback submissions: any in-app feedback messages you send us

2.2 Candidate Data (submitted by your Organisation)

Candidate data is personal data about third parties that your organisation submits to us. This includes:

  • Identity: full name, email address, phone number, LinkedIn URL
  • CV / resume content: work history, education, skills, achievements, qualifications — either uploaded as a file (PDF, DOCX) or entered as text
  • ATS metadata: application IDs, job IDs, application status, and timestamps from connected ATS platforms
  • Nasiya analysis outputs: suitability score, tier classification, AI-generated candidate brief, claim extraction results, risk assessments, JD coverage analysis, interview question sets, alignment assessment, and growth velocity scores
  • Interview round data: stage progression, interviewer signal (strong / neutral / weak), notes added by your team
  • Candidate notes: free-text notes written by Account Holders about specific candidates
  • Pipeline stage: applied, shortlisted, interviewing, offer, hired, rejected

Your organisation is the data controller for candidate data. You are responsible for ensuring you have a lawful basis for submitting candidate personal data to Nasiya, and for informing candidates that their data may be processed by AI systems as part of the recruitment process where required by applicable law.

2.3 Data Collected via the Chrome Extension

When you use the Nasiya Chrome extension:

  • API token: your extension token is stored locally in your browser using Chrome's chrome.storage.local API. It is never transmitted to any party other than Nasiya's own servers for authentication.
  • Profile text: when you navigate to a supported candidate profile page and explicitly click “Score”, the visible text content of that page is extracted and sent to Nasiya's servers for AI analysis. This happens only on user action — the extension does not collect data passively or in the background.
  • Selected role: the Nasiya role ID you have selected for scoring is stored locally in chrome.storage.local.
  • ATS candidate data: when used inside a connected ATS interface, the extension may read candidate details visible on screen and submit them for analysis, subject to the ATS integration permissions your organisation has configured.

The extension does not track your browsing history, does not collect data from pages other than supported candidate profile pages and ATS interfaces, and does not run in the background when you are not actively using it.

2.4 Public Application Form Data

If your organisation uses Nasiya's public application form to collect candidate applications directly, we collect:

  • Candidate full name, email address, and phone number
  • Pre-screening question answers
  • Uploaded CV file
  • Email verification status

This data is collected on behalf of your organisation and processed under this policy.

2.5 ATS Integration Data

If you connect a third-party ATS (Greenhouse, Lever, or Ashby), we store:

  • Your encrypted ATS API key (stored in our database; never exposed in plain text after initial entry)
  • Job/posting metadata fetched from the ATS (titles, departments, locations)
  • Candidate records pulled from the ATS, including names, emails, and CV files
  • Sync timestamps and processing status

We do not access your ATS account beyond what is required to retrieve job postings and candidate applications for the roles you have explicitly activated.

2.6 Technical and Device Data

We automatically collect limited technical data when you use the platform:

  • IP address (used for security and abuse prevention, not for tracking)
  • Browser type and version
  • Operating system
  • Referring URL
  • Session timing data

We do not use third-party advertising trackers or behavioural advertising networks.

3. How We Use Your Data

3.1 Service Delivery

  • Authenticating Account Holders and managing access control
  • Running AI analysis on candidate CVs and profiles to produce scores, verdicts, and structured insights
  • Syncing candidate data from connected ATS platforms
  • Generating and delivering email OTP codes for candidate application verification
  • Sending invite emails to new team members
  • Displaying candidate dossiers, interview kits, and pipeline views to authorised Account Holders within your organisation

3.2 Product Improvement

  • Analysing aggregate usage patterns to improve the platform (e.g. which features are used, where errors occur)
  • Diagnosing bugs, performance issues, and errors
  • Improving AI scoring accuracy over time using aggregated, anonymised outcome data where you have consented

We do not use individual candidate CVs or personal data to train AI models without explicit written consent from your organisation.

3.3 Security and Compliance

  • Detecting and preventing fraudulent, abusive, or unauthorised use
  • Verifying identity and preventing multiple accounts
  • Complying with legal obligations

3.4 Communications

  • Transactional emails (OTP codes, invitations, password resets)
  • Service notifications (processing complete, analysis ready)
  • Material updates to this Privacy Policy or our Terms of Service

We do not send marketing emails without your explicit consent.

3.5 AI Model Training (Optional — Requires Explicit Consent)

Nasiya may use anonymised, aggregated data from your organisation's hiring patterns to improve AI recommendations specifically for your organisation's benefit. This is entirely optional.

  • This consent is never assumed or pre-selected — you must actively opt in during onboarding or via your organisation settings.
  • If you opt in: we may use aggregated, anonymised signals (e.g. which types of candidates your team tends to advance, which scoring dimensions correlate with your actual hire outcomes) to calibrate Nasiya's models for your organisation specifically.
  • What we DO NOT do: We do not use individual candidate CVs, personal data, or identifiable information to train any AI model. We do not share your organisation's data with other organisations or use it to train general-purpose AI models.
  • Withdrawal: You may withdraw this consent at any time from your Organisation Settings → Data & Privacy. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

If you have not opted in, your data is used solely to deliver the Service (Section 3.1) and for anonymised aggregate product improvement (Section 3.2).

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area, United Kingdom, or another jurisdiction that applies the GDPR or equivalent legislation, our legal bases for processing personal data are:

  • Contract performance — processing account data to deliver the Service you have subscribed to
  • Legitimate interests — improving our platform, detecting abuse, and maintaining security, where these interests are not overridden by your rights
  • Legal obligation — where we are required to process data to comply with applicable law
  • Consent — where we ask for your explicit consent (e.g. for any optional communications or specific uses of anonymised data for AI training)

For candidate data submitted by your organisation, the lawful basis is determined by your organisation as data controller. Common bases include legitimate interest in hiring, and pre-contractual measures at the request of the data subject.

5. AI Processing and Third-Party AI Providers

Nasiya uses the following AI providers to process candidate data:

ProviderPurposeData shared
Anthropic (Claude)Candidate scoring, alignment assessment, interview question generation, Ask Nasiya chatCV text, JD text, org context
Google (Gemini)Claim extraction, technical question generationCV text, JD text
OpenAI (GPT-4o)PDF text extraction from uploaded CV filesRaw PDF file bytes

All AI providers are engaged under data processing agreements that prohibit them from using your data to train their general-purpose models. Data sent to AI providers is used solely for processing your specific requests.

Candidate data sent to AI providers is limited to what is necessary for the analysis: CV text, the job description, and your organisation's industry context. No unnecessary personal identifiers (e.g. photos, national ID numbers) are transmitted.

Nasiya's AI analysis outputs constitute AI-assisted decision support under the EU AI Act (Regulation 2024/1689) and may be classified as high-risk AI systems in the context of employment recruitment. We are committed to maintaining transparency logs, human oversight mechanisms, and accuracy standards in line with applicable AI Act obligations as implementation dates take effect. Organisations using Nasiya in the EU should ensure their use complies with their own AI Act obligations as deployers.

6. Data Sharing and Disclosure

We share data only in the following circumstances:

6.1 Within your Organisation

All Account Holders belonging to your organisation can see candidate data, role data, and notes associated with their organisation. Access is scoped strictly by organisation — no other organisation can access your data.

6.2 Service Providers

We share data with trusted infrastructure providers under data processing agreements:

  • Supabase — database storage, file storage (resumes), and authentication
  • Vercel — application hosting and serverless function execution
  • Resend — transactional email delivery (OTP codes, invitations)
  • Cloudflare — bot protection on public application forms (Turnstile)

6.3 ATS Platforms (on your instruction)

When you configure result webhooks or note-writing back to your ATS, Nasiya will send analysis results (score, tier, summary) to that ATS on your behalf. This is always explicitly configured by your organisation.

6.4 Legal Requirements

We may disclose data if required by law, court order, or regulatory authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Nasiya, our users, or the public.

6.5 Business Transfers

If Nasiya is acquired, merged, or its assets are transferred, candidate and account data may be transferred as part of that transaction. We will notify affected Account Holders via email before any such transfer occurs and give them the opportunity to request deletion.

We do not sell, rent, broker, or trade personal data to any third party for commercial purposes.

7. Data Retention

Data typeRetention period
Account holder dataDuration of account + 60 days after deletion request
Candidate CV files (storage)Duration of org account; deleted within 30 days of account closure
Candidate analysis recordsDuration of org account; soft-deleted on request, hard-deleted on account closure
ATS connection credentialsUntil you disconnect the ATS or close your account
Extension API tokens (hashed)Until revoked by the user or account closure
Email OTP codes10 minutes from generation; auto-expired
Usage logs90 days rolling
Feedback submissions24 months

Individual candidates and roles can be soft-deleted from within the Nasiya dashboard at any time. To request complete erasure, email support@nasiya.co.

8. Security

We take the security of your data seriously and implement the following measures:

  • Encryption in transit: all data is transmitted over HTTPS/TLS. No unencrypted connections are permitted.
  • Encryption at rest: CV files and database records are stored on Supabase infrastructure with AES-256 encryption at rest.
  • Row-level security: all database tables are protected by PostgreSQL row-level security policies enforced by Supabase, ensuring organisations cannot access each other's data even if an API key is compromised.
  • Token hashing: extension API tokens are stored only as SHA-256 hashes. The raw token is shown once at generation and cannot be retrieved from our systems.
  • Access control: staff access to production data is restricted on a need-to-know basis and subject to audit logging.
  • Dependency monitoring: we monitor third-party dependencies for known vulnerabilities.

No system is 100% secure. If you believe you have discovered a security vulnerability, please disclose it responsibly by emailing support@nasiya.co.

9. Your Rights

Depending on your location and applicable law, you may have the following rights regarding your personal data:

  • Right of access: request a copy of the personal data we hold about you
  • Right to rectification: request correction of inaccurate or incomplete data
  • Right to erasure: request deletion of your personal data (“right to be forgotten”)
  • Right to restriction: request that we restrict processing of your data in certain circumstances
  • Right to data portability: receive your data in a structured, machine-readable format
  • Right to object: object to processing based on legitimate interests
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time

Account Holders can exercise most of these rights directly within the platform (editing profile, deleting candidates/roles, disconnecting ATS integrations). For requests that cannot be completed in-app, email support@nasiya.co and we will respond within 10 days.

Candidates whose data was submitted by a recruiter should first contact the recruiting organisation. If you cannot reach them, contact us at support@nasiya.co and we will facilitate your request.

If you are in the EEA or UK and believe we have not complied with applicable data protection law, you have the right to lodge a complaint with your local supervisory authority.

10. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:

  • Right to know: what personal information we collect, use, disclose, and sell (we do not sell)
  • Right to delete: request deletion of your personal information
  • Right to correct: request correction of inaccurate personal information
  • Right to opt out of sale/sharing: we do not sell or share personal information for cross-context behavioural advertising
  • Right to limit use of sensitive personal information: we do not use sensitive personal information beyond what is necessary to provide the Service
  • Right to non-discrimination: we will not discriminate against you for exercising any of these rights

To exercise your California rights, email support@nasiya.co with the subject line “California Privacy Request”.

11. UAE Personal Data Protection Law (PDPL)

For users and candidates located in the United Arab Emirates, Nasiya processes personal data in accordance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) and its implementing regulations.

11.1 Lawful Basis

We process personal data of UAE data subjects on the following bases:

  • Contract performance: processing account and service data necessary to deliver the subscription you have entered into
  • Legitimate interests: product improvement, security monitoring, and fraud prevention, where such interests do not override data subjects' rights
  • Explicit consent: where required under UAE PDPL (e.g. optional AI training, sensitive data processing)

11.2 Data Subject Rights under UAE PDPL

UAE data subjects have the following rights:

  • Right of access: request confirmation of whether we process your personal data and obtain a copy
  • Right to rectification: request correction of inaccurate or incomplete personal data
  • Right to erasure: request deletion of personal data where retention is no longer necessary or lawful
  • Right to restrict processing: request limitation of processing in specified circumstances
  • Right to object to automated decisions: object to decisions made solely on the basis of automated processing, including AI-generated candidate assessments, where such decisions significantly affect you

11.3 Cross-Border Transfers

Where personal data of UAE data subjects is transferred outside the UAE, Nasiya ensures that such transfers are protected by appropriate contractual safeguards (such as standard data transfer clauses), adequacy mechanisms recognised under UAE law, or other legally permissible transfer mechanisms.

11.4 Data Minimisation and Sensitive Data

Consistent with UAE PDPL requirements, we collect only personal data that is adequate, relevant, and limited to what is necessary for our recruitment intelligence purposes. We do not process sensitive personal data as defined under the UAE PDPL — including biometric data, health data, religious beliefs, or financial data — without obtaining explicit prior consent from the data subject.

To exercise your rights under UAE PDPL or for any UAE data protection enquiry, email support@nasiya.co with the subject line “UAE PDPL Request”. We will respond within 10 days of receiving a verified request.

12. Australian Privacy Act 1988 and Australian Privacy Principles

For Australian users and candidates, Nasiya complies with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).

APP 3 — Collection of Solicited Personal Information

We only collect personal information that is reasonably necessary for our hiring intelligence functions. We collect personal information directly from Account Holders and from candidates via your organisation's recruitment workflows, or from connected ATS platforms on your instruction.

APP 5 — Notification of Collection

At or before the time we collect personal information (or as soon as practicable afterwards), we notify individuals of our identity and contact details, the purposes for which we are collecting the information, any third parties to whom we would typically disclose the information, and the individual's right to access and correct their information.

APP 6 — Use or Disclosure of Personal Information

Personal information collected for recruitment purposes is not used or disclosed for purposes unrelated to recruitment without the individual's consent, unless an exception under the Privacy Act applies.

APP 11 — Security of Personal Information

We take reasonable steps to protect personal information from misuse, interference, and loss, and from unauthorised access, modification, or disclosure. This includes encryption in transit and at rest, access controls, and row-level database security (see Section 8).

APP 12 — Access to Personal Information

Individuals may request access to their personal information held by Nasiya by emailing support@nasiya.co. We will respond within 10 days. We may charge a reasonable fee for providing access where permitted by law.

APP 13 — Correction of Personal Information

Individuals may request correction of inaccurate personal information by emailing support@nasiya.co. We will take reasonable steps to correct the information or, if we do not agree the information requires correction, to note the individual's request alongside the information.

Notifiable Data Breaches (NDB)

In the event of an eligible data breach that is likely to result in serious harm to one or more individuals, Nasiya will notify the Office of the Australian Information Commissioner (OAIC) and the affected individuals as soon as practicable after becoming aware of the breach, in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act.

Complaints about our handling of personal information may be directed first to support@nasiya.co. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

13. UK GDPR and Data Protection Act 2018

For users located in the United Kingdom, Nasiya processes personal data in accordance with the UK GDPR as retained in UK domestic law by the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018.

  • All rights under Section 4 (GDPR): all rights described in our GDPR section apply equally to UK residents under the UK GDPR, including rights of access, rectification, erasure, restriction, data portability, and the right to object.
  • UK ICO: if you are a UK resident and believe we have not complied with UK data protection law, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. We would, however, appreciate the opportunity to address your concerns before you contact the ICO.
  • UK adequacy and transfer safeguards: for transfers of UK personal data to countries that do not benefit from a UK adequacy decision, we rely on UK International Data Transfer Agreements (IDTAs) or other transfer mechanisms recognised under UK law as providing adequate safeguards.

14. International Data Transfers

Nasiya is operated from Pakistan. Our infrastructure providers (Supabase, Vercel, Anthropic, Google, OpenAI) may process data in the United States, European Union, and other countries.

For transfers of data from the EEA or UK to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) incorporated into our agreements with sub-processors, or other appropriate transfer mechanisms under GDPR Chapter V.

By using the Service, you acknowledge that your data may be transferred to and processed in countries other than your country of residence.

15. Children's Privacy

The Nasiya platform is intended for use by organisations and professional recruiters. It is not directed at, and we do not knowingly collect personal data from, individuals under the age of 18. If we become aware that we have collected data from a minor, we will delete it promptly. If you believe a minor has submitted data to our platform, contact support@nasiya.co.

16. Cookies and Tracking

Nasiya uses minimal cookies strictly necessary for the operation of the platform:

  • Authentication cookies: set by Supabase to maintain your logged-in session. These are session cookies and expire when you close your browser or sign out.
  • Preference storage: theme and language preferences may be stored in localStorage in your browser.

We do not use advertising cookies, behavioural tracking cookies, or any third-party analytics platforms that track you across websites. We do not use Google Analytics or equivalent services.

17. Candidate Consent and Recruiter Obligations

As a recruiter or hiring manager using Nasiya, you are responsible for:

  • Ensuring you have a lawful basis under applicable data protection law to process candidate personal data using an AI platform
  • Informing candidates, where required, that their CV or profile may be analysed by AI systems as part of the recruitment process
  • Not submitting sensitive personal data (racial or ethnic origin, health data, biometric data, religious beliefs, sexual orientation) to Nasiya unless you have obtained explicit consent from the candidate and have a specific lawful basis
  • Complying with your obligations under the EU AI Act (where applicable), particularly regarding AI-assisted decision-making in recruitment
  • Ensuring that Nasiya's AI outputs are used as a decision-support tool and not as the sole basis for hiring or rejection decisions

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the “Last updated” date at the top of this page
  • Notify Account Holders by email at least 14 days before the change takes effect
  • Where required by law, obtain fresh consent

Your continued use of the Service after the effective date of any changes constitutes acceptance of the updated policy.

19. Agency & Multi-Workspace Accounts

This section applies to users who access Nasiya through an Agency account — recruiters or recruitment firms who use Nasiya to manage hiring pipelines on behalf of multiple employer clients.

19.1 Data Isolation

Each client workspace is a logically isolated organisation within Nasiya. A client workspace's candidates, roles, analyses, and interview records are not shared with or visible to any other client workspace. Agency administrators can access all workspaces linked to their agency account; clients cannot see each other's data.

19.2 Agency Administrator Access

By creating or accepting access to an Agency account, you acknowledge that the agency account holder (your recruiter) can view candidate data, pipeline status, analysis results, and interview records for all workspaces linked to their agency. If you are an employer client granting access to an agency, you consent to this access as part of the service arrangement.

19.3 Data Processor and Controller Roles

For each client workspace:

  • Nasiya Inc. acts as the data processor — we process candidate data on documented instructions from the data controller.
  • The employer client (the organisation whose candidates are being screened) is the data controller — they determine the purposes and means of processing.
  • The agency acts as a sub-processor on behalf of the employer client and is responsible for ensuring their use of Nasiya complies with applicable data protection laws in their jurisdiction.

Agencies must have a valid Data Processing Agreement (DPA) in place with their employer clients before submitting candidate personal data to Nasiya on their behalf.

19.4 Candidate Consent

Candidates applying to roles in a client workspace are informed — via the mandatory AI screening consent disclosure on the public apply form — that:

  • Their CV and application data will be processed by AI;
  • The processing is conducted on behalf of the employer;
  • A human makes the final hiring decision.

Agencies are responsible for ensuring that any candidates submitted outside of the Nasiya apply form (e.g. uploaded directly) have given equivalent informed consent.

19.5 Workspace Removal

If an agency removes a client workspace from their agency view, the workspace is unlinked — not deleted. The employer client's data (roles, candidates, analyses) remains intact and accessible to any remaining members of that workspace. To permanently delete workspace data, the employer client must submit a deletion request to support@nasiya.co.

19.6 Agency Account Retention

Agency account data — including the workspace list, scheduling history, and interview records — is retained for 2 years after account closure or the removal of the agency subscription, unless a shorter retention period is required by applicable law or requested by the data controller.

20. Contact Us

For any questions, concerns, or requests related to this Privacy Policy or your personal data:

Nasiya Inc. — Data Privacy

Email: support@nasiya.co

Security disclosures: support@nasiya.co

Website: app.nasiya.co

We aim to respond to all privacy-related enquiries and subject access requests within 10 days of verification.