Privacy Policy
Last updated: January 2026
This Privacy Policy explains how Izerra (DMS Infra OÜ, Meistri 16, 13516 Tallinn, Estonia) ("we", "us", "our") processes personal data when:
- You visit izerra.com or our other websites.
- You use the Izerra platform as a Tenant or Authorized User.
- You apply for a job or otherwise interact as a Candidate via a Careers Portal powered by Izerra.
This Policy applies globally to our processing of personal data in connection with Izerra. We comply with applicable data protection laws in the regions where we operate, including the EU General Data Protection Regulation (GDPR) where it applies.
1. Roles and Responsibility
When we determine the purposes and means of processing (for example, for operating izerra.com, our own recruitment, billing, security, or marketing), we act as a data controller.
When we process personal data on behalf of Tenants in their HR and recruitment processes (for example, Candidate and employee data within a Tenant's Izerra account), we act as a data processor and the Tenant is the data controller.
In the latter case, the Tenant's own privacy notice applies in addition to this Policy.
When GDPR applies, we follow its core principles: lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, and integrity and confidentiality.
2. Personal Data We Collect
2.1 Visitors to izerra.com and Careers Portals
We may collect:
- Technical data: IP address, browser type and version, device type and identifiers, operating system, date and time of visit, URLs visited, and referrer URLs.
- Usage data: interactions with pages and elements, clicks, time spent on pages, and general navigation patterns.
- Cookies and similar technologies: as described in Section 5 below.
2.2 Tenant and Authorized User Data
When you create or use a Tenant account:
- Identification and contact details: name, email address, phone number, company name, job title or role.
- Account details: username, hashed passwords or access tokens, user settings and preferences.
- Subscription and billing information: billing contact details, plan information, invoices, and payment‑related details processed by our payment provider.
- Usage and log data: actions taken within the platform (such as creating job postings, modifying Candidate records), timestamps, and other metadata.
2.3 Candidate Data
When you apply for a job or are added as a Candidate in a Tenant's account:
- Basic details: first name, last name, email address, phone number, and other contact data you provide.
- Application information: CV/resume, cover letter, portfolio, links to professional profiles, responses to application questions, salary expectations, availability, and any other information you share.
- Recruitment data: interview notes, assessments, internal comments, decisions, and status changes in the recruitment process.
- Supporting documents: recommendation letters, references, certificates, and similar documentation.
- Communication data: messages exchanged via the Careers Portal or through integrated communication channels, and related metadata (timestamps, recipients).
Tenants may create additional custom fields in their forms. The Tenant is responsible for ensuring that collecting such data is lawful and appropriate.
2.4 Data from Other Sources
Depending on Tenant settings and your choices, we and/or the Tenant may also receive data from:
- Public professional profiles (e.g. LinkedIn, portfolio sites).
- Referees, recruitment agencies, or other service providers engaged by the Tenant.
- Payment providers when you pay us for a subscription.
3. Purposes and Legal Bases
When GDPR applies, we rely on one or more of the following legal bases: performance of a contract, compliance with legal obligations, legitimate interests, and consent where required.
3.1 Providing and Operating the Service
We process data to:
- Create and maintain Tenant accounts.
- Provide access to the platform and Careers Portals.
- Host and process Customer Data on behalf of Tenants.
- Provide support, respond to inquiries, and manage the customer relationship.
Legal bases (where GDPR applies): performance of a contract (Article 6(1)(b)), legitimate interest in operating and improving our services (Article 6(1)(f)), and compliance with legal obligations (Article 6(1)(c)).
3.2 Tenant HR and Recruitment (Processor Role)
For employee and Candidate data in Tenant accounts, we process personal data only in accordance with the Tenant's documented instructions and for the purposes defined by the Tenant (e.g. recruitment, onboarding, HR management). The Tenant is responsible for identifying the appropriate legal basis and informing data subjects.
3.3 Our Own Recruitment
If you apply for a role at Izerra itself, we process your data to:
- Receive and review your application.
- Communicate with you, schedule interviews, and perform evaluations.
- Make hiring decisions and, if applicable, prepare an employment contract.
Legal bases: taking steps at your request before entering into a contract, legitimate interest in recruiting staff, and compliance with legal obligations in employment law.
3.4 Security, Monitoring, and Improvement
We use technical and usage data to:
- Maintain the security and integrity of the Service.
- Detect and prevent fraud, misuse, and technical issues.
- Monitor performance and improve the Service.
Legal bases: legitimate interest in ensuring security and improving the Service, and compliance with legal obligations.
3.5 Marketing and Communication
We may use contact details of Tenants and prospects to:
- Send service‑related notifications (e.g. changes, downtime, legal updates).
- Send marketing communications about new features, offers, or events, where permitted.
Legal bases: legitimate interest in promoting the Service, or consent where required. You may opt out of marketing communications at any time through the unsubscribe link or by contacting us. Service‑critical communications are generally not optional.
4. Sharing of Personal Data
We may share personal data with:
- Tenants: If you are a Candidate or employee whose data is processed in a Tenant account, your data is shared with that Tenant and its Authorized Users.
- Service providers: Hosting, infrastructure, email services, analytics, customer support tools, payment providers, and other vendors that support our operations. These providers process data only on our instructions and under appropriate contractual safeguards.
- Professional advisers: Lawyers, auditors, or consultants where necessary for legal and business purposes.
- Authorities: Where required by law, regulation, or court order, or to protect our rights or the rights of others.
- Business transfers: In the context of a merger, acquisition, or other business transaction, personal data may be transferred to the relevant parties, subject to appropriate protections and, where required, information to you.
We do not sell personal data.
5. Cookies and Similar Technologies
We use cookies and similar technologies on izerra.com and Careers Portals to:
- Enable essential site functionality (such as log‑in sessions and security).
- Remember your preferences (such as language or cookie settings).
- Collect anonymized or aggregated statistics on usage, where permitted.
Where required by law, we request your consent for non‑essential cookies via a banner or consent tool. You can manage cookies through your browser settings, but disabling some cookies may affect functionality.
6. International Data Transfers
We operate globally and may process personal data in countries outside your own, including outside the EU/EEA and the UK.
Where personal data is transferred from the EU/EEA or the UK to a country that does not have an adequacy decision, we implement appropriate safeguards, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission (and, where applicable, the UK addendum), and
- Additional technical and organizational measures where necessary to ensure an essentially equivalent level of protection.
You can contact us for more information about the safeguards in place and, where applicable, a copy of the relevant transfer mechanisms.
7. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy or as required by law.
- Tenant account and billing data: kept for the duration of the contract and for a period afterwards as needed for accounting, tax, and legal purposes.
- Candidates for Izerra roles: retained for the recruitment process and for a limited period afterwards, for example to consider you for future roles or defend against legal claims, in line with local law.
- Candidates and employees in Tenant accounts: primary retention decisions are made by each Tenant. Tenants can configure retention settings and delete or anonymize data. After a Tenant's contract ends, we delete or anonymize data in accordance with our DPA, internal policies, and legal obligations.
- Technical and usage data: retained for a period necessary for security, analytics, and improvement, and then deleted or anonymized.
8. Your Rights
Your rights depend on your location and the laws that apply to you. Where GDPR applies (EU/EEA and in similar frameworks like UK GDPR), you have the following rights:
- Right of access: to obtain confirmation and a copy of personal data we hold about you.
- Right to rectification: to have inaccurate or incomplete personal data corrected.
- Right to erasure: to request deletion of your personal data in certain circumstances ("right to be forgotten").
- Right to restriction: to request that we restrict processing under certain conditions.
- Right to data portability: to receive your personal data in a structured, commonly used, and machine‑readable format and transmit it to another controller where technically feasible.
- Right to object: to object to processing based on legitimate interests, including profiling, and to direct marketing.
- Right to withdraw consent: where processing is based on your consent, you can withdraw it at any time without affecting prior processing.
If we process your data on behalf of a Tenant (for example, as a Candidate applying to that Tenant), you should usually contact the Tenant directly to exercise your rights. We will support the Tenant as required by our agreement and by law.
For data we control, you can exercise your rights by contacting us using the details in Section 11. We may ask for information to verify your identity before responding.
You also have the right to lodge a complaint with a supervisory authority, such as the Estonian Data Protection Inspectorate or the authority in your country of residence or work.
9. Security
We use appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include, where appropriate:
- Access controls and authentication.
- Encryption in transit and/or at rest.
- Logging and monitoring.
- Regular updates and security patches.
- Backups and disaster recovery procedures.
No system is completely secure, but we work continuously to maintain and improve our security posture.
10. Children
The Service is intended for use by businesses and adult users. Careers Portals and the platform are not designed for children under the minimum working age in the relevant jurisdiction.
If you believe we have collected personal data from a child inappropriately, please contact us so we can investigate and take appropriate action.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version will always be available on izerra.com with a "Last updated" date.
If we make material changes, we may provide additional notice (for example, via email or in‑app notice). Your continued use of the Service after changes become effective means you accept the updated Policy.
12. Contact
For questions, requests, or concerns about this Privacy Policy or our data practices, you can contact: