Last updated: July 11, 2026
This policy explains how Hyrza ("Hyrza", "we", "us") collects, uses, and protects personal data when you visit hyrza.com, apply for a position, or otherwise interact with us as a candidate. If you're a representative of a company we work with, a separate agreement governs how we handle your organization's data — this page focuses on candidates.
We collect information you give us directly, primarily through the application form:
We also automatically collect limited technical data when you browse our site — such as your browser type, device information, and general location derived from IP address — used only for basic analytics and site security.
We process your data to:
Our legal basis for this processing is your consent (given when you submit an application) and, where relevant, our legitimate interest in operating a recruitment service. You can withdraw consent at any time as described in Section 8.
We do not make decisions that significantly affect you (such as rejecting your application) using fully automated processing without human involvement. A person on our team reviews applications before any outcome is communicated to you.
We share your application materials with the specific hiring company tied to the role you apply for. We do not sell your data, and we do not forward your profile to a company without your application or explicit go-ahead. We may also share limited data with service providers who support our operations — for example, resume storage, email delivery, or website hosting — under confidentiality obligations, and only to the extent needed for them to perform that function.
Some of the service providers we use to operate this site (such as hosting or email delivery) may store or process data outside of Serbia, including in the European Union or the United States. Where this happens, we take reasonable steps to ensure your data continues to receive an appropriate level of protection, consistent with applicable data protection law.
We retain your application data for as long as needed to consider you for relevant roles, generally up to 24 months from your last activity with us, after which it is deleted or anonymized. You can request earlier deletion at any time — see Section 8.
Depending on where you're located, you may have the right to:
To exercise any of these rights, contact us using the details in Section 14. We'll respond within 30 days.
Our services are intended for individuals who are at least 18 years old, or the age of legal majority in their jurisdiction. We do not knowingly collect personal data from anyone below that age. If you believe a minor has provided us with personal data, contact us using the details in Section 14 and we will delete it.
Our site uses a small number of essential and analytics cookies to keep the site functioning and to understand how it's used. You can control cookies through your browser settings; disabling them may affect some site functionality.
We use reasonable technical and organizational measures — including access controls and encrypted storage — to protect your data against unauthorized access, loss, or misuse. No system is completely secure, and we can't guarantee absolute security. If a breach occurs that's likely to put your rights at risk, we will notify you and any relevant authority as required by applicable law.
If Hyrza is involved in a merger, acquisition, restructuring, or sale of assets, your data may be transferred as part of that transaction. We'll require any successor to continue to honor the commitments made in this policy, and will notify you of any material change in ownership or use of your data.
We may update this policy from time to time. If we make material changes, we'll update the date at the top of this page and, where appropriate, notify you directly.
Questions about this policy or your data? Reach us at privacy@hyrza.com.
Note for the Hyrza team: this version adds sections commonly expected in a compliant privacy policy — children's privacy, international transfers, automated-decision-making, breach notification, and business transfers — plus a pointer to Serbia's data protection authority for complaints. That said, please don't treat this as "bulletproof": I'm not a lawyer and can't guarantee compliance with Serbian data protection law or GDPR (if you'll process EU-based candidates' data) — actual compliance depends on your real data practices, retention periods, and sub-processors, which only you know and which I can't verify. Before this goes live with real candidates, have this policy reviewed by a lawyer familiar with Serbian data protection law, update the contact addresses and retention periods to match what you'll actually do, and make sure the practices described here are ones you can genuinely keep to — a privacy policy that overpromises is its own liability.