Legal

Privacy Policy

Last updated: August 2026

At BYOUR Platform Ltd., your privacy is not an afterthought — it's a foundation. This policy explains exactly what data we collect, why we collect it, and how we protect it. We operate under the General Data Protection Regulation (GDPR) and Irish data protection law. We believe in full transparency.

1 Who We Are

Data Controller: BYOUR Platform Ltd., registered in Ireland.

Contact:privacy@byour.co

We act as data controller for all personal data collected through the BYOUR platform. When you use BYOUR, you are entering into a relationship with us — and we take that responsibility seriously.

2 What Data We Collect

Account & Identity Data

When you register, we collect your username, email address, and password (stored as a bcrypt hash — we never store plain-text passwords). If you are a candidate, we also collect your full name, professional headline, country of residence, professional summary, and the CV and work history you choose to provide. If you register as a hiring organisation, we collect your company name, billing contact, and — where required for invoicing — your company registration and VAT numbers.

Payment & Billing Data

BYOUR processes payments through Stripe, a PCI-DSS Level 1 certified payment processor. We do not store your card details. Stripe handles tokenisation and secure storage. We store Stripe customer IDs, subscription and invoice references, and the billing records necessary for platform operation and legal compliance.

Usage Data

We collect information about how you use BYOUR: pages visited, features used, timestamps, and interaction events. This data is pseudonymised and used exclusively to improve the platform experience. We do not sell it.

Technical Data

IP addresses, browser type, device type, and session tokens are collected for security purposes — specifically to detect fraudulent access, enforce rate limiting, and protect user accounts.

3 Legal Basis for Processing

Under GDPR Article 6, we process your data on the following legal bases:

  • Contract performance — processing required to deliver the platform services you signed up for.
  • Legal obligation — financial record keeping and tax reporting.
  • Legitimate interests — fraud prevention, platform security, and product analytics.
  • Consent — for optional communications such as product updates and newsletters. You can withdraw consent at any time.

4 How We Use Your Data

Your data is used exclusively for the following purposes:

  • Creating and managing your account
  • Scoring and matching candidates against the requirements of open roles
  • Processing subscription payments and placement fees via Stripe
  • Sending transactional emails (verification, password reset, payment confirmations)
  • Detecting and preventing fraud, abuse, and security threats
  • Improving platform functionality through anonymised usage analytics

We do not sell your data. Ever. To anyone.

5 Data Sharing & Third Parties

We share your data only with carefully selected processors under strict data processing agreements:

Stripe

Subscription and fee payment processing

PCI-DSS Level 1 compliant
Amazon Web Services

Cloud infrastructure (EU region)

SOC 2 & ISO 27001 certified
SonarQube

Code security scanning (internal)

No personal data processed
Email Provider

Transactional email delivery

GDPR-compliant processor

We do not transfer personal data outside the European Economic Area (EEA) without appropriate safeguards.

6 Data Retention

We retain your data only for as long as necessary for the stated purposes or as required by law:

  • Account data: retained for the duration of your account. Deleted within 30 days of account deletion request.
  • Financial records: retained for 7 years as required by Irish tax and accounting law.
  • Usage logs: retained for 90 days, then automatically purged.
  • Billing records: retained as required by Irish tax law.

7 Your Rights Under GDPR

Right to Access

Request a copy of all personal data we hold about you.

Right to Rectification

Correct any inaccurate or incomplete data.

Right to Erasure

Request deletion of your data (subject to legal retention obligations).

Right to Portability

Receive your data in a machine-readable format.

Right to Object

Object to processing based on legitimate interests.

Right to Restrict

Restrict processing in certain circumstances.

To exercise any of these rights, contact us at privacy@byour.co. We will respond within 30 days. You also have the right to lodge a complaint with the Data Protection Commission (DPC) at www.dataprotection.ie.

8 Security Measures

We take security seriously. The following measures protect your data:

TLS 1.3 encryption in transit
AES-256 encryption at rest
OAuth2 + PKCE authentication
bcrypt password hashing
VPC network isolation on AWS
Automated security scanning (SonarQube)

9 Cookies

BYOUR uses strictly necessary cookies only. We do not use tracking, advertising, or third-party analytics cookies without your explicit consent. The cookies we set are:

  • Session tokens: to maintain your authenticated session securely.
  • CSRF tokens: to protect against cross-site request forgery attacks.

10 Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. When we make significant changes, we will notify you by email and update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.

Questions about your privacy?

Our team is available to answer any questions about how we handle your data.

Contact our Privacy Team