PRIVACY

Your data. Stated plainly.

This policy covers get-pyro.com, the Pyro application at app.get-pyro.com and the candidate portal at jobs.get-pyro.com. It is written to be read, not skimmed. Where the honest answer is “it depends on who you are”, we say so and explain.

Effective 9 October 2026
01

Who we are, and which hat we wear

Pyro (“we”, “us”) operates the website at get-pyro.com, the Pyro application and the candidate portal. Which responsibilities we have for your personal data depends on who you are:

You are
We are
Which means
You areA visitor to get-pyro.com
We areThe controller
Which meansWe decide what is collected on this site and why. It is very little; see the cookies page.
You areA customer, or a user at a customer
We areThe controller for your account data
Which meansWe hold your name, email, role and activity in order to run your account and bill for it.
You areA candidate with a global profile on the portal
We areThe controller for the profile
Which meansThe profile you create at jobs.get-pyro.com is held by us so it can follow you to every role on Pyro.
You areA candidate applying to a specific employer
We areA processor for that employer
Which meansThe employer decides why your application data is used and for how long. We process it on their instructions under a Data Processing Agreement.

Where we act as a processor, the employer is the first place to send a request about your data. We will still help you reach them, and we will act on any instruction they give us.

02

What we collect

We collect what the service needs and not more. By audience:

Visitors to get-pyro.com

  • Aggregated, cookieless page statistics: which pages were viewed, roughly where from, on what kind of device.
  • If you allow it, Google Analytics, which sets cookies. It is off by default in the EEA, the UK and Switzerland until you say otherwise.
  • When you book a demo, through Calendly: your name, your email address, the time you choose and your answers on the booking form.
  • Anything you send us by email.

Customers and their users

  • Account details: name, work email, role, the organisation you belong to.
  • Sign-in details, handled by Google's identity platform. We never see your password.
  • What you do in the application, written to the audit record: the roles you write, the searches you run, the decisions you make and when you made them.
  • Billing details and usage: metered AI runs, ARIA rounds and hires. Card details go directly to our payment processor; we never hold full card numbers.
  • If your organisation's administrator connects a Google Drive or OneDrive: the CVs in the one folder they choose, including any added to it later. Section 9 explains exactly what Pyro reads and how.
  • If you connect your own Google Calendar or Microsoft Outlook calendar: the interview events Pyro places on it and changes to them, and your other meetings, read when you open your Pyro calendar and not stored. Section 9 explains exactly what Pyro reads and how.

Candidates

  • Your profile: name, contact details, CV, work history and anything you choose to add.
  • Your applications: the answers you give, the evidence the screen finds in your CV, and the stage you are at.
  • Your interviews: for an ARIA round, the transcript with timestamps and the evidence drawn from it. For a human-led round, the notes and the outcome the interviewer records.
  • Your consent: what you agreed to, when, and whether you have since withdrawn it.
  • Optional diversity information (such as gender, ethnicity, age, disability or veteran status) only if an employer asks for it and only if you choose to give it. It is stored apart from your application, is never shown to anyone making a hiring decision, and is never used by the AI. See section 8.

Everyone

  • Technical data needed to serve and secure the service: IP address, browser and device type, timestamps, and error logs.
03

Where it comes from

  • From you directly, when you create a profile, apply, sign a consent, or use the application.
  • From the employer you applied to, when they enter or update your application.
  • From the shared drive an employer connects, where your CV may already have been stored by them.
  • From your interviews, in the form of transcripts and interviewer notes.

We do not buy personal data, and we do not scrape it from social networks or job boards.

04

Why we use it, and on what basis

Purpose
What that involves
Legal basis
PurposeRunning the recruitment process
What that involvesWriting roles, searching CVs, scoring against criteria, interviewing, recording decisions
Legal basisThe employer's legitimate interest in hiring, or the contract you are entering into with them; consent for the ARIA round
PurposeRunning your account
What that involvesSign-in, permissions, notifications, support
Legal basisOur contract with you or your organisation
PurposeBilling
What that involvesMetering usage, invoicing, collecting payment
Legal basisOur contract with the customer
PurposeKeeping the record
What that involvesWriting who decided what, on which evidence, with which model
Legal basisLegitimate interest in accountability; legal obligations in employment and AI law
PurposeSecurity and reliability
What that involvesLogs, abuse detection, backups
Legal basisLegitimate interest in running a secure service
PurposeMeasuring this website
What that involvesAggregated page statistics; Google Analytics where you allow it
Legal basisLegitimate interest for cookieless statistics; consent for Google Analytics where required
PurposeMeeting legal obligations
What that involvesResponding to lawful requests; retaining what law requires
Legal basisLegal obligation

We do not sell personal data. We do not use candidate data for advertising, and we do not use anyone's data to build profiles for purposes unrelated to the role they applied for.

05

AI on Pyro

Pyro uses large language models to draft and grade postings, to read CVs for meaning, to score applications against a role's criteria, to conduct ARIA's first-round interview, and to assist a human interviewer. We want to be exact about what that does and does not mean for you.

  • No hiring decision is made by AI alone. Advancing, rejecting and hiring are done by a person at the employer, and the record names that person. This is a design constraint of the system, not a configurable option.
  • Scores are evidence, not verdicts. A score is a list of criteria, each either quoted from your CV or interview, or marked unanswered. Nothing is inferred from a missing word.
  • Every AI run is logged with the model and version used, and the time. If a decision is questioned, the record shows exactly which model contributed what.
  • Protected characteristics are never provided to the models and never shown to decision-makers.
  • Your data is not used to train models. Neither we nor our AI providers train on the CVs, transcripts or records processed for an account.
  • ARIA is disclosed. A candidate is told they are speaking to an AI interviewer and signs a consent naming the scope before the round begins. They can withdraw it afterwards.

Under the GDPR you have the right not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you. Pyro is built so that no such decision is made: a person decides, and you can ask the employer for that person's review of any outcome.

06

Who we share it with

We share personal data only with the parties needed to run the service, and only the data each one needs.

Who
What for
What they see
WhoThe employer you applied to
What forRunning their recruitment process
What they seeYour profile, application, evidence and interview record. Never your diversity information.
WhoGoogle Cloud
What forHosting, database, storage, sign-in, and AI models
What they seeEncrypted data at rest; the text sent to models for a given task
WhoAnthropic
What forAI models for some tasks
What they seeThe text sent for that task, under terms that bar training on it
WhoSpeech and real-time media providers
What forTranscribing and carrying ARIA and live interviews
What they seeThe audio and text of the round while it runs
WhoEmail delivery providers
What forSending notifications and invitations
What they seeYour email address and the message
WhoPayment processors
What forTaking payment from customers
What they seeBilling details of the paying customer; never candidate data
WhoWebsite analytics providers
What forMeasuring get-pyro.com
What they seeSee the cookies page; cookieless by default
WhoCalendly
What forBooking demos from get-pyro.com
What they seeYour name, email address, chosen time and booking-form answers

The full, current list of sub-processors with their locations is part of our Data Processing Agreement and is available to any customer on request at privacy@get-pyro.com. We also disclose personal data where the law requires it, for instance in response to a valid court order, and we tell the affected customer unless we are legally prevented from doing so.

07

Where it lives, and how it travels

Pyro runs on Google Cloud. Production data is stored in Google Cloud's India region today. Customers on Enterprise plans can have their tenant hosted in an EU region, with the region named in their Data Processing Agreement.

Some of the providers in section 6 process data outside the country you are in. Where data leaves the EEA or the UK, we rely on the safeguards those laws recognise, principally the European Commission's Standard Contractual Clauses and the UK Addendum, and on the providers' own certifications. Copies of the relevant clauses are available on request.

08

How we protect it

We treat the following as sensitive data: CVs and the personal details in them, interview transcripts and recordings, optional diversity information, the access tokens that connect a customer's Google Drive or OneDrive or a user's calendar, and all data received through Google APIs or Microsoft Graph. It is protected as follows.

  • Encryption at rest. All stored data is encrypted with AES-256. Personal fields such as names and contact details are additionally encrypted one by one with AES-256-GCM, using a key that belongs to a single customer. Those keys are themselves protected by Google Cloud Key Management Service, so one customer's data cannot be read with another's key.
  • Encryption in transit. Everything travels over TLS: between your browser and Pyro, and between Pyro and the services it uses.
  • Access tokens. The long-lived tokens that let Pyro use a connected drive or calendar are encrypted with the customer's own key before they are stored, and are decrypted only in server memory at the moment they are used. A calendar's short-lived access token, which expires within about an hour, is held only in Pyro's private server cache until it expires and is never written to the database. No token is ever sent to a browser.
  • Least privilege. Pyro asks for read-only access to a connected drive. It never creates, changes or deletes a file in it, and it reads only the folder the administrator chose. For a connected calendar, Pyro asks for access to events only, not to calendar settings or sharing, and it creates, changes or cancels only the interview events it schedules itself.
  • Role-based access. Only an organisation's administrators can connect or disconnect a drive or choose the folder Pyro reads. Other users see the candidates created from it, as their permissions allow, and nothing else of the drive. A calendar is connected by its own user and only that user sees its details in Pyro; colleagues arranging an interview see only when that person is busy.
  • Customer isolation. Each customer's data is isolated at the database with row-level security, enforced by the database itself rather than by application code that could forget a filter. Stored files are kept under a path that belongs to one customer.
  • Protected characteristics, where a candidate chooses to give them, are held apart from the application and are never rendered on any screen used to make decisions.
  • Access by our own staff is limited, logged, and used only for support you have asked for or to keep the service running.
  • Audit trail. Connecting and disconnecting a drive is written to the audit record with who did it and when, alongside every decision made in the application.
  • Erasure is a deletion. When data is erased under this policy, the rows are removed at the database and the erasure itself is logged.

No system is perfectly secure. If a breach affects your personal data we will tell the affected customer without undue delay, and we will notify regulators and individuals where the law requires it.

09

Google and Microsoft user data

This section describes how Pyro handles information it receives from Google APIs and from Microsoft Graph. It applies when an administrator at a customer connects the organisation's Google Drive or Microsoft OneDrive to Pyro, and when a user connects their own Google Calendar or Microsoft Outlook calendar. In this section, “drive data” means what Pyro receives from a connected drive, “calendar data” means what it receives from a connected calendar, and “Google and Microsoft data” means both. Every commitment here applies to Google and to Microsoft alike.

What we access, and why

  • From Google: the connected account's email address (the openid and email permissions), used only to show the administrator which account is connected; and read-only access to Google Drive (the drive.readonly permission), used only to read the CVs in the one folder the administrator chooses.
  • From Microsoft: the connected account's email address (the openid and email permissions), used only to show the administrator which account is connected; read-only access to files (the Files.Read.All permission), used only to read the CVs in the one folder the administrator chooses; and the offline_access permission, so the folder keeps syncing without the administrator signing in again.
  • From Google, for a connected calendar: the connected account's email address (the openid and email permissions), used only to show the user which account is connected; and access to calendar events (the calendar.events permission), used only to create, update and cancel the interview events the user schedules in Pyro, to learn when those events are moved, deleted or answered, and to show the user their other meetings in Pyro. Pyro does not ask for access to calendar settings or sharing.
  • From Microsoft, for a connected calendar: the connected account's email address and basic profile (the openid, email and User.Read permissions), used only to show the user which account is connected; access to calendar events (the Calendars.ReadWrite permission), used for the same purposes as on Google; and the offline_access permission, so interview events stay up to date without the user signing in again.

How the folder is chosen

  • The administrator chooses one folder, once, when setting up the integration. Pyro then watches that folder and its sub-folders and imports each CV (PDF or Word, and Google Docs on Google Drive) that is added to it or updated in it.
  • Other users at the organisation, including recruiters and hiring managers, cannot connect a drive, browse it, pick files from it, or select or change the folder. Only an administrator can change the folder or disconnect the drive.
  • Google and Microsoft notify Pyro when something in the drive changes. Pyro uses those notifications only to find files inside the chosen folder. A change outside the folder is ignored: that file is not opened, downloaded or stored.

How a calendar is connected and used

  • Connecting a calendar is optional. Each user connects only their own calendar, in their own settings; nobody, including an administrator, can connect a calendar on someone else's behalf. A user who does not connect a calendar receives interview invitations by email as before.
  • Interview events. When a user with a connected calendar organises an interview, Pyro creates the event on that user's calendar with the time, the meeting link and the interview panel as guests. Google or Microsoft sends the invitations to the panel and may add a Google Meet or Microsoft Teams link. Pyro updates or cancels the event when the interview changes. The candidate is never added to this event; candidates receive Pyro's own invitation.
  • Changes made in the calendar. Google and Microsoft notify Pyro when a connected calendar changes. Pyro uses those notifications only to find its own interview events: if the organiser moves one, Pyro reschedules the interview and tells the candidate; if the organiser deletes one, Pyro cancels the interview; and panel members' replies are recorded as their answers. A change to any other event is ignored and is not stored.
  • Your other meetings. When you open your calendar in Pyro, Pyro reads your other meetings for the dates on screen and shows them to you with their details. Only you see them. When colleagues arrange an interview with you, they see only the times you are busy, with no titles, attendees or locations. These meetings are never written to Pyro's database, never logged and never given to AI models; they are held in a temporary server cache for a few minutes so the page loads quickly, and are then discarded.

How we use it

  • Each CV from the folder becomes a candidate record in that organisation's Pyro account, so its recruiters can search it and consider it for their open roles. To do this the CV is read by AI models, acting on our instructions, which extract skills and experience and match them to the organisation's roles.
  • Calendar data is used only to schedule interviews, keep them up to date and show you your own calendar, as described above. It is not read by AI models.
  • We do not use Google and Microsoft data for advertising, we do not sell it, and we do not use it to determine creditworthiness or for lending.
  • We do not use Google and Microsoft data to develop, improve or train generalised AI or machine-learning models. The AI providers that process drive data on our behalf are contractually barred from training on it.
  • No person at Pyro reads Google and Microsoft data unless the customer asks us to for support, it is needed for security or to comply with the law, or it has been aggregated and anonymised for running the service.

Where it is stored, and who sees it

  • A copy of each imported CV is stored in Google Cloud Storage under a path that belongs to that customer, encrypted at rest. The personal details taken from it are encrypted with the customer's own key, as described in section 8. This is the same whether the CV came from Google Drive or OneDrive.
  • For a connected calendar, Pyro stores the connected account's email address and its access token, both encrypted with the customer's own key; an encrypted marker that tells Pyro which calendar changes it has already seen; and, for each interview, the identifier of the event it created and the panel's replies. It does not store the details of your other meetings.
  • Google and Microsoft data is shared only with the customer whose user connected the drive or calendar and with the sub-processors in section 6 that are needed to provide these features: Google Cloud, and, for drive data, AI model providers acting on our instructions. It is not transferred to anyone else, except where the law requires it or the customer instructs us to.

Disconnecting and deletion

  • An administrator can disconnect the drive at any time in Pyro's settings. Pyro then stops watching the folder, cancels its change notifications, and reads nothing further.
  • For Google Drive, Pyro also asks Google to revoke its access. Access can also be removed from the Google account at https://myaccount.google.com/permissions.
  • For Microsoft OneDrive, Pyro stops using its stored access. To remove the permission at Microsoft as well, the organisation's Microsoft administrator can remove Pyro under Enterprise applications in Microsoft Entra, or the user can remove it from their Microsoft account's app permissions.
  • A user can disconnect their calendar at any time in Pyro's settings. Pyro then stops reading the calendar, cancels its change notifications and deletes its stored access. For Google Calendar, Pyro also asks Google to revoke its access; for a Microsoft calendar, the permission can be removed at Microsoft in the same ways as for OneDrive. Interview events Pyro had already created stay on the calendar, like any other invitation, and can be deleted there; Pyro no longer sees or changes them.
  • CVs already imported remain part of the customer's candidate records and follow the customer's retention period (section 10). The customer can delete them at any time, and a candidate can ask for their data to be erased (section 11). To have drive data deleted, write to privacy@get-pyro.com.

Pyro's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

Pyro's use of information received from Microsoft Graph follows the Microsoft APIs Terms of Use (https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use), and is limited to providing the drive sync and calendar features described in this section.

10

How long we keep it

Data
Kept for
DataYour global candidate profile
Kept forUntil you delete it, or after a long period of inactivity of which we will warn you first
DataAn application to an employer, including evidence and interview transcripts
Kept forThe retention period the employer sets, within the limits of the law where they hire. The employer's own privacy notice governs
DataYour consent record
Kept forFor as long as the application it belongs to, so it can be shown that consent was given and, if it was, withdrawn
DataCustomer account data
Kept forFor the life of the account, then a 30-day export window, then deletion
DataAudit and billing records
Kept forFor the period the law and the customer's contract require, after which they are deleted
DataWebsite analytics
Kept forSee the cookies page for each provider's retention

When a retention period ends, the data is deleted, not archived under a flag. Backups roll off on their own schedule and are encrypted throughout.

11

Your rights

Depending on where you live you have some or all of the following rights, and we honour them regardless of where you live:

  • To access the personal data we hold about you, and to receive a copy.
  • To correct data that is wrong or incomplete.
  • To have your data erased.
  • To restrict or object to how it is used.
  • To receive your data in a portable format.
  • To withdraw a consent you gave, without affecting what was done before you withdrew it.
  • To not be subject to a solely automated decision with legal or similarly significant effect.
  • To complain to a data protection authority. We would rather you told us first, but the right is yours either way.

Candidates can exercise most of these directly from the portal: edit your profile, withdraw a consent, or request erasure. For anything else, write to privacy@get-pyro.com. Where we are a processor for an employer we will forward your request to them and help them answer it within the time the law allows. We will never charge you for exercising a right, and we will ask you to verify your identity only where we genuinely need to.

12

Consent, for candidates

Before an employer's process on Pyro touches your application with AI, you are asked to consent to a named scope, typically screening and the ARIA interview. The consent is a signed row in the record: who, when, and what for.

You can withdraw it at any time from the portal. Withdrawing stops any further processing under that consent. It does not undo what was lawfully done before, and the employer may still hold your application on another legal basis, such as their own legitimate interest in the hiring process, subject to their retention period. Declining or withdrawing is recorded as a choice, not as evidence against you.

13

Cookies and similar technologies

get-pyro.com is measured without cookies by default. One provider, Google Analytics, sets cookies, and only after you allow it where consent is required. The application and portal use a small number of strictly necessary cookies and browser storage entries to keep you signed in and remember your preferences. Every one of them is listed, with its purpose and lifetime, on the cookies page.

14

Children

Pyro is for working-age adults. We do not knowingly collect data from anyone under 18, and if we learn that we have, we delete it.

15

Changes to this policy

When we change this policy we change the date at the top. If a change reduces your rights or widens what we collect, we tell customers and portal users before it takes effect, and we keep earlier versions available on request.

16

Contact

Questions, requests and complaints about personal data: privacy@get-pyro.com. Anything else: hello@get-pyro.com. A person reads both.