Privacy Policy
Last updated: March 7, 2026
1. Introduction
MaestroRecruit, a brand operated by MaestroSAT (Pty) Ltd ("we", "us", or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our recruitment platform. This policy applies to all users, including job seekers ("Candidates") and recruitment companies ("Recruiters").
2. Information We Collect
2.1 Candidate Information
- Account Information: Email address, password (stored securely using bcrypt hashing)
- Profile Information: Full name, phone number, location, professional summary
- CV / Resume Data: Work experience, education, skills, certifications, languages — extracted via AI processing
- Job Preferences: Salary expectations, work type preference, availability, citizenship
- Professional Links: LinkedIn, GitHub, portfolio URLs
- Profile Visibility Preference: Whether you have opted in to make your profile searchable by all verified Recruiters
2.2 Recruiter and Company Information
- Account Information: Email address, password, role within company
- Company Details: Company name, legal name, registration number, industry, size, website, physical address
- Verification Documents: Company registration document, proof of address, and administrator identification document — submitted for compliance verification
- Contact Person Details: Name and position of the company contact person
2.3 Payment and Transaction Information
- Credit Purchases: Transaction records, package details, and payment references (processed via Paystack)
- Career Report Purchases: Purchase records and payment references
- Profile Reveal Records: Which company revealed which Candidate, timestamp, and credit amount deducted
- Referral Records: Referral codes used and referral credits earned
Note: We do not store your payment card details. All payment processing is handled securely by Paystack, our third-party payment processor.
2.4 Information Collected Automatically
- Login History: IP address, device type, browser, operating system, and approximate geographic location for each login session
- Usage Data: Pages visited, features used, and interaction patterns
- Cookies: Session cookies for authentication and preferences
3. How We Use Your Information
3.1 For Candidates
- Create and manage your account and profile
- Process and extract data from your CV / Resume using AI technology
- Match you with suitable job opportunities
- If you opt in to profile searchability, display your profile summary (excluding contact details) to verified Recruiters
- Share your full profile with Recruiters who use credits to reveal your details
- Share your profile with companies you apply to directly
- Generate Career Reports and formatted CVs / Resumes when purchased
- Send job alert emails based on your profile and preferences
- Communicate with you about your applications and account
3.2 For Recruiters
- Create and manage company accounts and team members
- Verify company identity and legitimacy through compliance document review
- Facilitate candidate search and profile reveal functionality
- Process credit purchases and track credit balances
- Manage job postings and applications
- Process referral credits when applicable
3.3 For All Users
- Maintain account security and detect unauthorized access via login history monitoring
- Improve our services and user experience
- Comply with legal obligations
- Prevent fraud and abuse of the Platform
4. Profile Visibility and How Your Data Is Shared
4.1 Candidate Profile Searchability
Candidates control whether their profile is searchable by all Recruiters through an opt-in setting. When profile searchability is enabled:
- Your professional summary, skills, experience, and qualifications are visible to verified Recruiters in search results
- Your contact details (email, phone number) are hidden and protected behind our credit-based reveal system
- Recruiters must spend credits to reveal your full contact information
- You may disable searchability at any time, which immediately removes your profile from search results
4.2 Profile Reveals
When a Recruiter reveals your profile using credits:
- Your full profile including contact details becomes accessible to that Recruiter's company
- A record of the reveal is stored (which company, when, and the credit amount)
- The reveal is permanent for that company — they retain access to your full profile
- You are not notified when a Recruiter reveals your profile
4.3 Sharing with Third Parties
We may share your information with:
- Verified Recruiters: Profile data as described above, subject to your searchability preference and the credit reveal system
- Payment Processor (Paystack): Transaction details necessary to process credit purchases and Career Report payments
- Cloud Infrastructure (AWS): Your data is hosted on Amazon Web Services infrastructure with encryption at rest and in transit
- AI Processing Services: CV / Resume data for extraction and Career Report generation
- Legal Requirements: When required by law, regulation, or valid legal process
5. Company Verification and Compliance Data
To protect Candidates and ensure Platform integrity, all recruitment companies must undergo a verification process. The following compliance data is collected and processed:
- Company registration documents — to verify legal business status
- Proof of address — to confirm the company's physical location
- Administrator identification — to verify the identity of the person registering the company
These documents are stored securely in encrypted cloud storage (AWS S3) and are reviewed by our administration team. Documents are retained for the duration of the company's active account and may be retained after account closure as required for legal compliance and audit purposes. AI-assisted verification may be used to assess document validity and generate trust scores.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption at rest: Sensitive profile data is encrypted using AES-256-GCM encryption
- Encryption in transit: All data transmitted between your browser and our servers is encrypted via HTTPS/TLS
- Password security: Passwords are hashed using bcrypt and never stored in plaintext
- Secure authentication: JWT-based session management with httpOnly, secure, and sameSite cookie protections
- Access controls: Role-based access control ensuring users only access data they are authorized to view
- Login monitoring: Login history tracking with IP masking to detect unauthorized access
- Company verification: All Recruiter companies are verified before accessing Candidate data
7. Your Privacy Rights
Depending on your location, you may have rights to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate information
- Erasure: Request deletion of your data and account
- Portability: Receive your data in a portable format
- Objection: Object to certain processing activities
- Withdraw Consent: Withdraw previously given consent, including disabling profile searchability
- Restrict Processing: Request limitation of processing in certain circumstances
To exercise any of these rights, please contact us at admin@maestrorecruit.com or use the account management features available in your account settings, including the option to delete your account.
8. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. Upon account deletion:
- Candidate profiles, CVs / Resumes, and application data are deleted
- Company verification documents are deleted
- Login history records are deleted
- Credit purchase and payment transaction records may be retained as required for financial compliance, tax, and audit purposes
- Profile reveal records may be retained in anonymized form for audit purposes
- Minimal information may be retained for legal compliance, dispute resolution, and fraud prevention
9. International Data Transfers
Your information may be transferred to and processed in countries other than your own, including where our cloud infrastructure (AWS) is located. We ensure appropriate safeguards are in place for such transfers in accordance with applicable data protection laws, including GDPR standard contractual clauses where applicable.
10. Cookies
We use cookies for essential Platform functionality, including:
- Authentication cookies: To maintain your logged-in session (httpOnly, secure)
- Preference cookies: To remember your settings and preferences
You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent you from using the Platform.
11. Children's Privacy
Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and, where appropriate, notifying you via email. Your continued use of the Platform after changes constitutes acceptance of the updated policy.
13. Contact Us
For privacy-related inquiries, to exercise your rights, or to contact our Information Officer (for POPIA purposes), please reach us at: admin@maestrorecruit.com