Who we are
Recruitsome B.V. provides the recruitment platform of the same name, used by staffing and recruitment agencies to manage vacancies, candidates and placements.
Registered address: Stationsplein 9, 1012 AB Amsterdam · Chamber of Commerce 97194719 · privacy contact Kevin Overtoom, kevin.overtoom@recruitsome.com.
What this statement covers
This statement covers the personal data for which Recruitsome is itself the controller: the data of agency staff who log in to the platform, of visitors to our website, and of our customer and billing records.
Data of candidates and applicants we do not process for ourselves but on behalf of the agency using the platform. For that data the agency is the controller and we are the processor; see the chapter below and the Data Processing Agreement.
What data we process
As a controller we process:
- User account data — name, business email, phone, role and login details.
- Usage data — technical logs, device and connection data, and feature usage.
- Customer and billing data — company details, contacts and payment data.
- Prospect contact data — data you leave via our website or a demo request.
Purposes and legal bases
We use this data to provide and secure the platform, support users, invoice, improve our service and communicate with (prospective) customers.
Legal bases: performance of the contract, legal obligation (incl. tax retention), legitimate interest (security, product improvement, B2B marketing) and, where required, consent.
Candidate data: our role as processor
Candidate and applicant data — including CV, work history and, for payroll, special data such as BSN and IBAN — we process solely on the instructions and under the responsibility of the agency. The agency determines purpose, basis and retention.
Our arrangements are set out in the Data Processing Agreement. Are you a candidate wanting to access or delete your data? Address your request to the agency you were in contact with; we support them.
AI and automated decision-making
The platform includes AI features that help recruiters, such as parsing CVs and drafting text. The AI is assistive: a user of the agency reviews and decides. No legally significant decisions are made in a fully automated way (art. 22 GDPR).
Where AI is used to assess or rank candidates, appropriate safeguards apply, including human oversight and transparency towards candidates, in line with the GDPR and the EU AI Act.
Sub-processors
We engage carefully selected sub-processors, each under a data processing agreement. A current overview — with service, purpose and location — is on our sub-processor page. The main ones are AI providers (Anthropic, OpenAI), document parsing (LlamaParse), payroll (Loket), signing (Signhost), email/SMS (Mailgun, Twilio), storage (AWS), payments (Stripe) and publishing (Indeed).
Transfers outside the EEA
Some providers are based outside the EEA, notably in the United States. Transfers only take place with appropriate safeguards: the EU-US Data Privacy Framework for certified parties, and otherwise the Standard Contractual Clauses (SCCs) with additional measures. The basis per provider is stated on the sub-processor page.
Retention periods
We do not keep data longer than necessary:
- account data: during the agreement and up to 12 months after;
- invoice and tax data: 7 years (statutory retention);
- technical logs: typically up to 12 months;
- prospect data: up to 24 months after last contact.
Candidate data we keep according to the agency's instruction and retention period.
Security
We take appropriate technical and organisational measures, including encryption of sensitive fields (incl. BSN and IBAN), encrypted transport, strict access control, logging and separation of customer environments. An overview is in the annex to the Data Processing Agreement.
Your rights
You have the right of access, rectification, erasure, restriction, objection and data portability. We respond within one month. For data where we are the controller, email kevin.overtoom@recruitsome.com. For candidate data, contact the relevant agency. You may also lodge a complaint with the Dutch Data Protection Authority.
Changes to this statement
We may update this statement. Every version is recorded with an effective date and archived. We actively inform users of material changes.
Version history
Every publication is frozen as an immutable version, so it stays provable which text applied when.
-
2026.1 In effect since 1 Jul 2026Current