
Effective date: 20 May 2026 · Last updated: 20 May 2026
This Privacy Policy explains how Nasiya Inc. (“Nasiya”, “we”, “our”, or “us”) collects, uses, stores, shares, and protects information when you use our platform at app.nasiya.co, our Chrome browser extension, and any related services (collectively, the “Service”). By using the Service, you agree to the practices described in this policy.
Nasiya is an AI-powered hiring intelligence platform designed for recruiters, HR professionals, and hiring teams. Our platform helps organisations evaluate job candidates using artificial intelligence, extracting structured insights from CVs, resumes, and candidate profiles to support — not replace — human hiring decisions.
For the purposes of data protection law, Nasiya acts as a data controller for account holder data and as a data processor for candidate personal data that your organisation submits to us.
Contact us at: support@nasiya.co
When you create a Nasiya account or use our platform, we collect:
Candidate data is personal data about third parties that your organisation submits to us. This includes:
Your organisation is the data controller for candidate data. You are responsible for ensuring you have a lawful basis for submitting candidate personal data to Nasiya, and for informing candidates that their data may be processed by AI systems as part of the recruitment process where required by applicable law.
When you use the Nasiya Chrome extension:
chrome.storage.local API. It is never transmitted to any party other than Nasiya's own servers for authentication.chrome.storage.local.The extension does not track your browsing history, does not collect data from pages other than supported candidate profile pages and ATS interfaces, and does not run in the background when you are not actively using it.
If your organisation uses Nasiya's public application form to collect candidate applications directly, we collect:
This data is collected on behalf of your organisation and processed under this policy.
If you connect a third-party ATS (Greenhouse, Lever, or Ashby), we store:
We do not access your ATS account beyond what is required to retrieve job postings and candidate applications for the roles you have explicitly activated.
We automatically collect limited technical data when you use the platform:
We do not use third-party advertising trackers or behavioural advertising networks.
We do not use individual candidate CVs or personal data to train AI models without explicit written consent from your organisation.
We do not send marketing emails without your explicit consent.
Nasiya may use anonymised, aggregated data from your organisation's hiring patterns to improve AI recommendations specifically for your organisation's benefit. This is entirely optional.
If you have not opted in, your data is used solely to deliver the Service (Section 3.1) and for anonymised aggregate product improvement (Section 3.2).
If you are located in the European Economic Area, United Kingdom, or another jurisdiction that applies the GDPR or equivalent legislation, our legal bases for processing personal data are:
For candidate data submitted by your organisation, the lawful basis is determined by your organisation as data controller. Common bases include legitimate interest in hiring, and pre-contractual measures at the request of the data subject.
Nasiya uses the following AI providers to process candidate data:
| Provider | Purpose | Data shared |
|---|---|---|
| Anthropic (Claude) | Candidate scoring, alignment assessment, interview question generation, Ask Nasiya chat | CV text, JD text, org context |
| Google (Gemini) | Claim extraction, technical question generation | CV text, JD text |
| OpenAI (GPT-4o) | PDF text extraction from uploaded CV files | Raw PDF file bytes |
All AI providers are engaged under data processing agreements that prohibit them from using your data to train their general-purpose models. Data sent to AI providers is used solely for processing your specific requests.
Candidate data sent to AI providers is limited to what is necessary for the analysis: CV text, the job description, and your organisation's industry context. No unnecessary personal identifiers (e.g. photos, national ID numbers) are transmitted.
Nasiya's AI analysis outputs constitute AI-assisted decision support under the EU AI Act (Regulation 2024/1689) and may be classified as high-risk AI systems in the context of employment recruitment. We are committed to maintaining transparency logs, human oversight mechanisms, and accuracy standards in line with applicable AI Act obligations as implementation dates take effect. Organisations using Nasiya in the EU should ensure their use complies with their own AI Act obligations as deployers.
We share data only in the following circumstances:
All Account Holders belonging to your organisation can see candidate data, role data, and notes associated with their organisation. Access is scoped strictly by organisation — no other organisation can access your data.
We share data with trusted infrastructure providers under data processing agreements:
When you configure result webhooks or note-writing back to your ATS, Nasiya will send analysis results (score, tier, summary) to that ATS on your behalf. This is always explicitly configured by your organisation.
We may disclose data if required by law, court order, or regulatory authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Nasiya, our users, or the public.
If Nasiya is acquired, merged, or its assets are transferred, candidate and account data may be transferred as part of that transaction. We will notify affected Account Holders via email before any such transfer occurs and give them the opportunity to request deletion.
We do not sell, rent, broker, or trade personal data to any third party for commercial purposes.
| Data type | Retention period |
|---|---|
| Account holder data | Duration of account + 60 days after deletion request |
| Candidate CV files (storage) | Duration of org account; deleted within 30 days of account closure |
| Candidate analysis records | Duration of org account; soft-deleted on request, hard-deleted on account closure |
| ATS connection credentials | Until you disconnect the ATS or close your account |
| Extension API tokens (hashed) | Until revoked by the user or account closure |
| Email OTP codes | 10 minutes from generation; auto-expired |
| Usage logs | 90 days rolling |
| Feedback submissions | 24 months |
Individual candidates and roles can be soft-deleted from within the Nasiya dashboard at any time. To request complete erasure, email support@nasiya.co.
We take the security of your data seriously and implement the following measures:
No system is 100% secure. If you believe you have discovered a security vulnerability, please disclose it responsibly by emailing support@nasiya.co.
Depending on your location and applicable law, you may have the following rights regarding your personal data:
Account Holders can exercise most of these rights directly within the platform (editing profile, deleting candidates/roles, disconnecting ATS integrations). For requests that cannot be completed in-app, email support@nasiya.co and we will respond within 10 days.
Candidates whose data was submitted by a recruiter should first contact the recruiting organisation. If you cannot reach them, contact us at support@nasiya.co and we will facilitate your request.
If you are in the EEA or UK and believe we have not complied with applicable data protection law, you have the right to lodge a complaint with your local supervisory authority.
If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:
To exercise your California rights, email support@nasiya.co with the subject line “California Privacy Request”.
For users and candidates located in the United Arab Emirates, Nasiya processes personal data in accordance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) and its implementing regulations.
We process personal data of UAE data subjects on the following bases:
UAE data subjects have the following rights:
Where personal data of UAE data subjects is transferred outside the UAE, Nasiya ensures that such transfers are protected by appropriate contractual safeguards (such as standard data transfer clauses), adequacy mechanisms recognised under UAE law, or other legally permissible transfer mechanisms.
Consistent with UAE PDPL requirements, we collect only personal data that is adequate, relevant, and limited to what is necessary for our recruitment intelligence purposes. We do not process sensitive personal data as defined under the UAE PDPL — including biometric data, health data, religious beliefs, or financial data — without obtaining explicit prior consent from the data subject.
To exercise your rights under UAE PDPL or for any UAE data protection enquiry, email support@nasiya.co with the subject line “UAE PDPL Request”. We will respond within 10 days of receiving a verified request.
For Australian users and candidates, Nasiya complies with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).
We only collect personal information that is reasonably necessary for our hiring intelligence functions. We collect personal information directly from Account Holders and from candidates via your organisation's recruitment workflows, or from connected ATS platforms on your instruction.
At or before the time we collect personal information (or as soon as practicable afterwards), we notify individuals of our identity and contact details, the purposes for which we are collecting the information, any third parties to whom we would typically disclose the information, and the individual's right to access and correct their information.
Personal information collected for recruitment purposes is not used or disclosed for purposes unrelated to recruitment without the individual's consent, unless an exception under the Privacy Act applies.
We take reasonable steps to protect personal information from misuse, interference, and loss, and from unauthorised access, modification, or disclosure. This includes encryption in transit and at rest, access controls, and row-level database security (see Section 8).
Individuals may request access to their personal information held by Nasiya by emailing support@nasiya.co. We will respond within 10 days. We may charge a reasonable fee for providing access where permitted by law.
Individuals may request correction of inaccurate personal information by emailing support@nasiya.co. We will take reasonable steps to correct the information or, if we do not agree the information requires correction, to note the individual's request alongside the information.
In the event of an eligible data breach that is likely to result in serious harm to one or more individuals, Nasiya will notify the Office of the Australian Information Commissioner (OAIC) and the affected individuals as soon as practicable after becoming aware of the breach, in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act.
Complaints about our handling of personal information may be directed first to support@nasiya.co. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
For users located in the United Kingdom, Nasiya processes personal data in accordance with the UK GDPR as retained in UK domestic law by the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018.
Nasiya is operated from Pakistan. Our infrastructure providers (Supabase, Vercel, Anthropic, Google, OpenAI) may process data in the United States, European Union, and other countries.
For transfers of data from the EEA or UK to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) incorporated into our agreements with sub-processors, or other appropriate transfer mechanisms under GDPR Chapter V.
By using the Service, you acknowledge that your data may be transferred to and processed in countries other than your country of residence.
The Nasiya platform is intended for use by organisations and professional recruiters. It is not directed at, and we do not knowingly collect personal data from, individuals under the age of 18. If we become aware that we have collected data from a minor, we will delete it promptly. If you believe a minor has submitted data to our platform, contact support@nasiya.co.
Nasiya uses minimal cookies strictly necessary for the operation of the platform:
localStorage in your browser.We do not use advertising cookies, behavioural tracking cookies, or any third-party analytics platforms that track you across websites. We do not use Google Analytics or equivalent services.
As a recruiter or hiring manager using Nasiya, you are responsible for:
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
Your continued use of the Service after the effective date of any changes constitutes acceptance of the updated policy.
This section applies to users who access Nasiya through an Agency account — recruiters or recruitment firms who use Nasiya to manage hiring pipelines on behalf of multiple employer clients.
Each client workspace is a logically isolated organisation within Nasiya. A client workspace's candidates, roles, analyses, and interview records are not shared with or visible to any other client workspace. Agency administrators can access all workspaces linked to their agency account; clients cannot see each other's data.
By creating or accepting access to an Agency account, you acknowledge that the agency account holder (your recruiter) can view candidate data, pipeline status, analysis results, and interview records for all workspaces linked to their agency. If you are an employer client granting access to an agency, you consent to this access as part of the service arrangement.
For each client workspace:
Agencies must have a valid Data Processing Agreement (DPA) in place with their employer clients before submitting candidate personal data to Nasiya on their behalf.
Candidates applying to roles in a client workspace are informed — via the mandatory AI screening consent disclosure on the public apply form — that:
Agencies are responsible for ensuring that any candidates submitted outside of the Nasiya apply form (e.g. uploaded directly) have given equivalent informed consent.
If an agency removes a client workspace from their agency view, the workspace is unlinked — not deleted. The employer client's data (roles, candidates, analyses) remains intact and accessible to any remaining members of that workspace. To permanently delete workspace data, the employer client must submit a deletion request to support@nasiya.co.
Agency account data — including the workspace list, scheduling history, and interview records — is retained for 2 years after account closure or the removal of the agency subscription, unless a shorter retention period is required by applicable law or requested by the data controller.
For any questions, concerns, or requests related to this Privacy Policy or your personal data:
Nasiya Inc. — Data Privacy
Email: support@nasiya.co
Security disclosures: support@nasiya.co
Website: app.nasiya.co
We aim to respond to all privacy-related enquiries and subject access requests within 10 days of verification.