Your privacy,
handled with care
Last updated: 28 July 2026
Beagler LLC (“Beagler”, “we”, “us”, or “our”) builds all-in-one recruitment software that helps agencies and in-house recruiters manage clients, jobs, candidates, interviews, invoicing, payroll and more, across web, desktop and mobile. This policy explains, in plain language, what data we handle, why we handle it, and the control you have over it.
Our Role: Who Controls What
Beagler holds two different kinds of personal data, and our legal responsibility differs for each.
- Data you put into your workspace, such as your clients, contacts and candidates. Here you are the data controller and Beagler is your data processor. You decide what to collect and why; we process it only to provide the Service to you, under your instructions and the terms of our Data Processing Agreement.
- Data about your own account and our website, such as your name and email as a user, billing records, support conversations, and analytics about visitors to beagler.io. Here Beagler is the data controller.
Important. This distinction matters for candidates. If a candidate asks us to access or delete their data, we will normally refer them to the recruiter whose workspace holds it, because that recruiter decides what happens to it. We will always help our customer respond.
Information We Collect
We only collect what we genuinely need to run Beagler for you. Here is the full picture, grouped by where the data comes from.
2.1 Business & Account Information
When you create a workspace, we collect details about your business:
- Business name
- Address and country
- Tax or registration identifiers (if you provide them)
- Website URL
- Company logo
2.2 User Information
For each person you invite into your workspace, we hold:
- Full name
- Email address
- Phone number (optional)
- Job title or role
- Login credentials — passwords are hashed and never stored in plain text
2.3 Client & Contact Information
The client records you create live inside your workspace and may include:
- Company name and industry
- Business address and website
- Contact names, email addresses and phone numbers
- Notes and communication history
2.4 Candidate Information
Beagler stores the candidate data you or your team add or upload:
- Name, email, phone and address
- Resumes and supporting documents (PDF, DOC, DOCX)
- Salary expectations, notice period and availability
- Tags, notes and internal scorecards
- Submission, interview and pipeline history
Important. For client and candidate data, you are the data controller and Beagler is the data processor. You are responsible for collecting this data lawfully and for telling candidates how their information is used. We process it only to provide the Service to you.
2.5 Jobs, Interviews & Recruitment Data
To power your recruitment workflow, we store:
- Job postings, descriptions, categories and tags
- Job and application status
- Interview schedules, participants and modes
- Interview feedback, scorecards and notes
2.6 Invoicing, Payroll & Financial Information
To support our billing and finance features, we store the information you enter:
- Invoices, line items, tax rates and totals
- Client billing details and payment status
- Payroll records — earnings, deductions and net pay
- Expenses, vendors and categories
- Bank or payment details you choose to add
Important. Beagler never stores your full card number. Your subscription payments are handled securely by our payment processor, not by us.
2.7 System & Usage Information
To keep Beagler secure and reliable, we automatically record:
- Sign-in dates, times and IP address (for security and fraud prevention)
- Activity logs (create, update, approve and archive actions)
- Browser, device and operating-system details
How We Use Your Information
We use the information above to:
We do not sell or rent your data, and we never use your client or candidate data for advertising.
- Provide, operate and maintain the Service across web, desktop and mobile
- Authenticate users and enforce role-based permissions
- Power your recruitment workflows — clients, jobs, candidates and interviews
- Generate invoices, payroll, expenses and documents
- Send transactional emails and route the messages you send through your connected Gmail or Outlook account
- Maintain audit logs and internal controls
- Run backups, disaster recovery and maintenance
- Improve the platform’s reliability, usability and performance
Legal Bases for Processing
Where the GDPR or UK GDPR applies and Beagler is the controller, we rely on the following legal bases:
Where you are the controller, for example for candidate data in your workspace, you choose the legal basis for that processing and are responsible for having one.
- Performance of a contract. To create and run your workspace, authenticate you, deliver the features you use and take payment for them.
- Legitimate interests. To keep the Service secure, prevent fraud and abuse, maintain audit logs, and understand how the product is used so we can improve it. We balance this against your interests and rights.
- Consent. For non-essential cookies and similar technologies, and for marketing email. You can withdraw consent at any time without affecting what happened before.
- Legal obligation. To meet accounting, tax and other legal requirements, and to respond to lawful requests.
AI & Automated Processing
Beagler includes AI features that assist your team. They are designed to support your judgment, never to replace it.
Our AI provider is OpenAI. When you use an AI feature, the relevant text is sent to OpenAI’s API and processed on servers in the United States, and the result is returned to your workspace. The model we use is GPT-4o mini.
This happens when you upload a resume, so its details and skills can be read into a candidate profile; when candidates are matched and scored against a role; and when tags or follow-up suggestions are generated. When a resume is read, the resume text is sent. When candidates are matched, what is sent is the candidate’s name, current job title and skill tags, together with the details of the role — the resume itself is not sent for matching.
- AI assists, people decide. Beagler never rejects or advances a candidate on its own; a person takes every action.
- Matching produces a score. When candidates are matched to a role, the model gives each one a score out of 100 and a short reason. These are stored alongside the suggestion shown to the recruiter. Only candidates scoring above a threshold are listed, so a lower-scoring candidate may not be surfaced for that role.
- OpenAI does not use data submitted through its API to train its models.
- Some AI runs automatically. Reading a resume happens when you upload one, but matching also runs on its own whenever a candidate or a job is created, without anyone asking for it.
- AI processing is part of the Service and cannot currently be switched off for a workspace. If that matters to you, please talk to us before you subscribe.
Important. Because AI processing involves a transfer to the United States, see the section on international transfers below. If you act as a data controller for candidate data, you should reflect this processing in your own privacy notice to candidates.
Your Workspace, Your Data
Beagler is a multi-tenant platform, engineered so that your data stays yours:
- Every business workspace is logically isolated from every other
- Users can only ever access data inside their own organization
- Cross-workspace access is strictly prohibited and enforced at the data layer
- Role-based permissions decide what each user can view, create, edit or approve
Data Sharing & Disclosure
We do not share your data with third parties, except in these specific cases:
8.1 Service Providers We Use
We rely on a small set of providers to run Beagler. These are the ones that may handle personal data on our behalf:
- Hetzner Online GmbH (Germany). Hosts the application and stores your workspace database and uploaded files, including resumes and documents.
- Amazon Web Services. Stores encrypted backups of the workspace database and of uploaded files, including resumes and documents. Backups are stored in the European Union (Frankfurt).
- OpenAI. Processes text you submit to an AI feature, including resume content. United States.
- Stripe. Processes subscription payments. We never see or store your full card details.
- Email delivery. Sends transactional email such as verification codes, notifications and invoices.
- Expo, together with Apple and Google. Deliver push notifications to the mobile app using a device token.
- HubSpot. Receives the contact details submitted through our website forms, such as name, email, company and phone, so our team can respond. Workspace data is never sent to HubSpot.
- Google Analytics and Microsoft Clarity. Website and product analytics, loaded only if you accept analytics cookies.
- Meta, LinkedIn and Reddit. Advertising measurement, loaded only if you accept marketing cookies.
Important. Each provider is bound by contract to protect the data and to use it only to deliver their service to us. We do not sell personal data, and we never use client or candidate data for advertising.
8.2 Legal Requirements
We may disclose data where we are required to by law, regulation, court order or a valid government request.
8.3 At Your Direction
When you send a resume, invoice or email through Beagler, that data goes only to the recipients you choose.
Where Your Data Lives & How We Protect It
Your live data is hosted in Germany, in the European Union, on infrastructure provided by Hetzner. Encrypted backups are held separately with Amazon Web Services, also in the European Union (Frankfurt, Germany). Everything is protected with layered, industry standard security:
- Encryption in transit with TLS 1.3, and at rest with AES-256 — covering the live database, your uploaded files and every backup
- Hashed passwords and secure authentication tokens
- Role-based access control across the entire platform
- Continuous activity logging and monitoring
- Automated daily backups of both the database and uploaded files, encrypted at rest
Data Retention & Backups
Within the Service, you control your own retention — what to keep, archive or remove.
- You can export and manage your workspace data at any time
- Archived records stay stored but inactive until you restore or delete them
- Deleted data may remain in encrypted backups for up to 30 days, after which the backup containing it is automatically deleted
- Restoring a backup can overwrite current data
International Data Transfers
Beagler LLC is registered in Delaware, United States, and Beagler is used around the world, so personal data may be transferred to and processed in countries other than your own.
Some of the providers listed under Data Sharing are based in the United States and will therefore receive data outside the European Economic Area and the United Kingdom. The most significant of these is OpenAI, because resume text you submit to an AI feature is processed there. Stripe, HubSpot, Microsoft, Google, Meta, LinkedIn and Reddit are also United States providers.
- Where we transfer personal data out of the EEA or the UK, we rely on the transfer mechanisms in each provider’s data processing agreement, such as the European Commission’s Standard Contractual Clauses or the EU to US Data Privacy Framework where the provider is certified.
- We keep the categories of data sent to each provider to the minimum needed for them to do their job.
Important. If you need a copy of the safeguards that apply to a specific transfer, contact us and we will provide the relevant details.
Your Rights
Depending on where you live, you may have the right to:
To exercise any of these, contact your workspace administrator or reach us directly, and we will respond within the timeframes required by law.
- Access the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Request deletion of your personal data
- Restrict or object to certain processing
- Receive a portable copy of your data
Your Responsibilities
Because you control the client and candidate data in your workspace, you agree to:
- Keep your login credentials confidential
- Collect candidate and client data lawfully
- Tell candidates how their data is used and obtain consent where required
- Keep your account and business details accurate and up to date
Children's Privacy
Beagler is built for businesses and is not intended for anyone under the age of 18. We do not knowingly collect personal data from minors, and we will delete it promptly if we discover that we have.
Changes to This Policy
We may update this Privacy Policy as Beagler evolves. We will post the latest version here and update the date above; significant changes will be highlighted in-app or by email. Continuing to use Beagler after an update means you accept the revised policy.
Contact Us
Questions about your privacy or this policy? We are always happy to help.
