1. Overview and scope
Yoria ("we," "us," "our") operates a cloud-based applicant tracking system (ATS) provided as a software-as-a-service platform to recruitment agencies, search firms, and in-house HR and talent acquisition teams ("Customers"). The Service is currently available in the following markets:
- Japan (JP)
- Singapore (SG)
- Australia (AU)
- New Zealand (NZ)
- United Kingdom (GB)
- United States (US)
- Canada (CA)
Access from countries outside this list is restricted by geo-blocking. We may expand to additional markets in the future, and will update this policy accordingly.
This Privacy Policy explains how we collect, use, and protect personal data in connection with the operation of yoria.io. It applies to:
- Platform users — recruiters, HR professionals, and team members employed by Customers who use the Yoria platform
- Candidates and data subjects — individuals whose personal data is entered into the platform by Customers
- Visitors — individuals who visit yoria.io without registering
We are committed to compliance with all applicable data protection laws in our served markets, including: Japan's APPI (個人情報保護法), Singapore's PDPA, Australia's Privacy Act 1988, New Zealand's Privacy Act 2020, the UK GDPR and Data Protection Act 2018, US state privacy laws including the CCPA/CPRA (California), and Canada's PIPEDA and Quebec Law 25.
Note: This policy is provided for informational purposes. Customers operating in regulated industries or jurisdictions with specific legal requirements should obtain independent legal advice regarding their own compliance obligations when using the Yoria platform.
2. Our role: platform provider
Yoria provides software infrastructure. We do not own, collect for our own purposes, or independently control the candidate data stored on the platform.
Candidate data — Customers are responsible
The recruitment agencies and HR teams that subscribe to Yoria are solely responsible for all candidate and contact data they enter, import, or process through the platform. This includes names, contact details, employment history, salary data, resumes, and any other personal information about job seekers, applicants, and client contacts.
Yoria stores and processes this data solely as a service to Customers, acting on their instruction. We have no independent commercial relationship with the individuals whose data Customers manage on the platform.
Each Customer is independently responsible for:
- Providing candidates with appropriate privacy notices at the point of data collection
- Obtaining any required consents under applicable law before entering data into the platform
- Ensuring they have a lawful basis for collecting, storing, and processing candidate personal data
- Responding to candidates' data subject rights requests (access, correction, deletion, portability)
- Complying with all applicable data protection laws in their jurisdiction and the jurisdictions of the candidates they manage
- Ensuring cross-border transfer mechanisms are in place when required by local law before transmitting candidate data to Yoria's systems
Customers who require a Data Processing Agreement (DPA) for compliance with UK GDPR or other applicable laws may request one by contacting [email protected].
Account and billing data — Yoria handles this
Yoria processes the personal data of platform users (name, email, account credentials, and billing information) for the purpose of delivering and administering the Yoria service. This processing is covered in full by this Privacy Policy.
3. What data we collect
3.1 Account and user data
When a Customer registers and invites team members, we collect:
- Name and email address of each platform user (business email required — personal email domains are blocked at signup)
- Organisation name and market/region selection
- Password (bcrypt-hashed — never stored in plain text)
- Role assignment (admin, recruiter, viewer)
- Subscription and billing details — managed by Paddle.com Market Limited; we retain only the last 4 digits of the card, expiry date, and billing email
3.2 Candidate and contact data (entered by Customers)
Customers may enter personal data about candidates and client contacts, including names (English, kanji, katakana), contact information, work history, skills, languages, salary data, notes, assessment records, visa status, and uploaded resume documents. Yoria processes this data solely on Customer instruction. The Customer retains full ownership of and responsibility for this data.
3.3 Usage and technical data
We collect information about how the platform is accessed, including IP addresses, browser type, operating system, and features used. This data is used for service reliability, security monitoring (including rate limiting, fail2ban IP blocking, and abuse detection), and improving the platform.
We use Cloudflare Web Analytics for aggregate, anonymised usage insights. Cloudflare Web Analytics is cookieless and does not track individual users or use any form of client-side state.
3.4 Audit trail
All significant data access and modification events are logged with user identity, IP address, timestamp, and action taken. This audit trail is used for security, compliance, and accountability. Audit records are retained separately from the data they describe and are not deleted when the underlying data is purged.
3.5 Communications
If you contact us by email or through our website, we retain your message and contact details to respond to your enquiry and improve our support.
4. AI processing
Yoria uses AI models to provide several platform features. All AI processing is performed through Amazon Web Services (AWS) Bedrock — a managed service that routes requests to regional AWS endpoints. No customer data is sent to AI model providers directly. AI models are never trained on customer data.
4.1 Resume parsing
When a Customer uploads a resume (PDF, DOCX, or other supported format), the document content is sent to Claude (an AI model by Anthropic, accessed via AWS Bedrock) for structured data extraction. The AI extracts names, contact information, work history, skills, languages, and other professional details. Personally identifiable information (PII) is scrubbed from the stored extracted text. The original uploaded file is stored in private, access-controlled storage.
4.2 Semantic search and candidate matching
Professional profile data is converted to vector embeddings using AWS Bedrock Titan to enable semantic search and candidate-to-job matching. The data sent for embedding includes:
- Job title, seniority, company name, and location
- Job function, skills, industries, and sub-industries
- Languages, visa status, and JLPT level
- Work history (up to 10 entries) and resume text (first 2,000 characters)
The following data is explicitly excluded from embedding generation: candidate name, email, phone number, salary data, notes, assessment notes, nationality, and candidate stage. Nationality is excluded as an anti-discrimination measure.
4.3 Resume formatting
When a Customer uses the resume formatter, candidate profile data is sent to Claude (via AWS Bedrock) to generate a reformatted resume document. The formatted output is stored in private storage and available only to the Customer's organisation.
4.4 AI lead sourcing
Search criteria entered by recruiters are processed by Claude (via AWS Bedrock) to generate candidate sourcing queries. No candidate PII is sent during the search criteria generation phase.
4.5 Regional AI routing
AI requests are routed to the AWS Bedrock region closest to the Customer's market to minimise latency and keep data within the relevant geographic area:
- Japan → ap-northeast-1 (Tokyo)
- Singapore → ap-southeast-1 (Singapore)
- Australia / New Zealand → ap-southeast-2 (Sydney)
- United Kingdom → eu-west-2 (London)
- United States / Canada → us-east-1 (N. Virginia)
4.6 AI data handling commitments
- No customer data is used for AI model training
- AI request data is not retained by AWS Bedrock beyond the processing request
- AI telemetry (logged for usage tracking and billing) stores only metadata — provider, region, model, feature, token counts, and status — never prompts, resume content, candidate data, or model output
- AI features consume monthly credits that vary by subscription tier; usage is metered per organisation
5. Connect: inter-organisation sharing
Yoria Connect allows Customers to share candidate pipeline data with partner organisations (e.g. a recruitment agency sharing shortlisted candidates with a hiring company). Connect sharing operates as follows:
- Explicit share records — the sharing Customer ("owner") creates a share record specifying which jobs, pipeline entries, and candidates to share with the receiving organisation
- Field-level visibility control — the owner selects which candidate fields are visible to the receiver (e.g. name and skills but not salary or contact details)
- Receiver-scoped notes — the receiving organisation can add their own notes on shared candidates; these notes are visible only to the receiver, not the owner
- No bulk data transfer — shared data is accessed through Yoria's platform; the receiver does not receive a copy of the data
Customers who use Connect are responsible for ensuring they have the appropriate legal basis to share candidate data with partner organisations, including any required candidate consent.
6. Sub-processors
We engage the following sub-processors to deliver the Yoria service. All sub-processors are bound by agreements that prohibit use of data for their own purposes and require appropriate security measures.
| Sub-processor | Purpose | Data location |
|---|---|---|
| Supabase, Inc. | Database hosting, authentication, file storage | AWS infrastructure in Customer-selected region (default: Singapore). See Section 7. |
| Amazon Web Services (AWS) | AI model hosting via Bedrock (resume parsing, embeddings, matching, formatting). No model training on customer data. | Regional endpoints — see Section 4.5 |
| Paddle.com Market Limited | Payment processing (Customer billing only — subscription fees, invoices). Card data is tokenised and never transmitted to Yoria. | United Kingdom (London) |
| Cloudflare, Inc. | CDN, edge hosting (Cloudflare Pages), DDoS protection, TLS termination, Web Analytics, Turnstile bot protection | Global edge network; no candidate data stored |
We will notify Customers of any material changes to our sub-processor list with at least 30 days' notice. Customers who require advance notice of sub-processor changes should register at [email protected].
7. Data residency and hosting
Yoria's database infrastructure is hosted on Supabase (running on AWS). The current default region is Singapore. Additional regions are available on request:
| Region | Data centre | Available to |
|---|---|---|
| Asia-Pacific (default) | Singapore | All customers (current default) |
| Japan | Tokyo (ap-northeast-1) | Japan-market customers — on request |
| Australia | Sydney (ap-southeast-2) | Australian customers — on request |
| United States | US-East | US/Canada customers — on request |
Application hosting runs on Cloudflare Pages with a global edge network. Cloudflare does not store candidate data — it routes requests and provides DDoS protection.
Billing data processed through Paddle is processed in the United Kingdom. AI processing through AWS Bedrock is routed to regional endpoints as described in Section 4.5.
8. International data transfers
Where personal data is transferred across borders, we implement appropriate safeguards under applicable law:
United Kingdom (UK GDPR)
Transfers from the UK use UK International Data Transfer Agreements (IDTAs) or the UK Addendum to EU SCCs. Sub-processor agreements include appropriate UK GDPR safeguards. Customers requiring IDTAs in their DPA may request them at [email protected].
Japan (APPI)
Under Japan's 2022 APPI amendments, overseas transfers of personal information require either individual opt-in consent from each data subject or establishment of a contractual "personal information protection system" providing APPI-equivalent protections. Customers operating under Japanese law are responsible for ensuring appropriate consent or contractual frameworks. Our DPA supports this requirement.
Australia and New Zealand
Overseas disclosures are made with contractual safeguards requiring sub-processors to handle data in accordance with the Australian Privacy Principles (APPs) and New Zealand's Information Privacy Principles (IPPs). Where data is held on an Australian regional instance, cross-border transfers are limited to payment processing (Paddle, UK) and AI processing (AWS Bedrock, regional endpoint).
Canada (PIPEDA / Quebec Law 25)
We comply with PIPEDA at the federal level and Quebec's Law 25 for Quebec-based Customers. We can provide documentation to support Privacy Impact Assessment (PIA) requirements. Contact [email protected].
United States
For transfers involving US sub-processors, we rely on contractual safeguards and, where applicable, the EU-US and UK-US Data Privacy Frameworks for certified recipients.
9. Legal basis for processing
Account and user data
We process platform user data on the following bases:
- Contract performance — processing necessary to provide the Yoria service under our Terms of Service
- Legitimate interests — security monitoring, fraud prevention, abuse detection, rate limiting, and service improvement
- Legal obligation — compliance with applicable tax, billing, and regulatory requirements
Candidate data processed on Customer instruction
Yoria processes candidate data as a service provider acting on Customer instruction. The legal basis is the contractual obligation between Yoria and the Customer. The Customer's own legal basis for collecting and using candidate data falls outside the scope of this policy.
10. Data retention and deletion
10.1 Candidate data — two-stage deletion
When a Customer deletes a candidate record, we follow a two-stage process:
- Soft delete (immediate) — the record is hidden from all read paths and marked with a deletion timestamp and reason (user request, GDPR request, duplicate, or other). The record is recoverable during the grace period.
- Purge (after 30 days) — all PII is irreversibly scrubbed: email, phone, resume text, date of birth, salary data, notes, assessment notes, visa details, social profiles, and all uploaded files (resumes and formatted documents) are permanently deleted. Child records (notes, embeddings, assessments) are deleted entirely.
After purging, an identity skeleton is retained to preserve financial record integrity: name, company association, reference number, and pipeline stage. This minimal data is necessary to maintain the validity of placement and fee records required by tax and accounting law.
Audit trail entries for the deleted candidate are retained without PII. Activity records are scrubbed to remove identifying details.
10.2 Account data
We retain Customer account data for as long as the subscription is active. Upon cancellation, account data is retained for 30 days to allow for recovery, after which it may be permanently deleted.
10.3 Billing records
Billing records (invoices, transaction history) may be retained for up to 7 years as required by applicable tax and accounting law.
10.4 Backups
Off-site encrypted backups, when enabled, are subject to the same purge obligations. Our backup restore procedures include a mandatory re-application of any purges that occurred after the backup was created.
11. Security
We implement technical and organisational security measures appropriate to the risk, including:
- Encryption in transit — TLS on all connections, enforced by Cloudflare
- Encryption at rest — AES-256 encryption on all database storage
- Multi-layer tenant isolation — row-level security (RLS) enforced at the database layer, write-time ownership triggers on all tenant tables, response-body validation middleware, and nightly canary-row cross-tenant tests. No organisation can access another's data.
- Authentication — bcrypt password hashing; optional multi-factor authentication (TOTP); IP session binding; Cloudflare Turnstile bot protection on all auth forms
- Access control — role-based permissions (admin, recruiter, viewer); principle of least privilege; column-level database grants preventing privilege escalation
- Rate limiting and abuse detection — per-IP rate limits on authentication and API endpoints; automatic IP blocking (fail2ban) after repeated failures; per-org AI rate limiting
- Content Security Policy — strict CSP with per-request nonces; no inline scripts permitted
- Input validation — all user-supplied text sanitised to prevent XSS; all API inputs validated against schemas; CSRF protection on all cookie-authenticated mutations
- Audit logging — all significant data access and modification events logged with user identity, IP address, and timestamp
- File security — all storage buckets are private; signed download URLs expire in 60 seconds; upload validation with extension whitelist, magic byte verification, and 10 MB size cap
No method of transmission or storage is 100% secure. If you discover a security vulnerability, please disclose it responsibly to [email protected].
13. Rights of platform users (Customers and team members)
If you are a recruiter, HR professional, or team member using the Yoria platform, you have the following rights regarding your personal account data:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate account data
- Erasure — request deletion of your user account and associated personal data
- Restriction — request that we limit processing of your data in certain circumstances
- Portability — receive your account data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
To exercise any of these rights, contact [email protected]. We will respond within 30 days (or within applicable statutory deadlines where shorter periods apply).
14. Rights of candidates and data subjects
If you are a job seeker, applicant, or professional contact whose personal data has been entered into the Yoria platform by a recruitment agency or employer, please read this section carefully.
Yoria is not responsible for your data — the agency or employer is. The recruitment agency or employer that entered your data into the platform is solely responsible for how your personal information is collected, stored, used, and deleted. They are the party with whom you have (or had) a direct relationship.
To exercise your rights — including access, correction, deletion, or portability — contact the recruitment agency or employer directly.
If you do not know which agency holds your data, or if you have contacted them and received no satisfactory response, you may contact us at [email protected] with the subject line "Candidate Data Request". We will use reasonable efforts to identify the responsible Customer, but we cannot delete or modify candidate data without authorisation from the Customer who controls it.
You also have the right to lodge a complaint with your local data protection authority:
- UK: Information Commissioner's Office (ICO) — ico.org.uk
- Japan: Personal Information Protection Commission (PPC) — ppc.go.jp
- Singapore: Personal Data Protection Commission (PDPC)
- Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
- New Zealand: Office of the Privacy Commissioner — privacy.org.nz
- Canada: Office of the Privacy Commissioner of Canada (OPC)
- California (US): California Privacy Protection Agency (CPPA)
15. Jurisdiction-specific provisions
United Kingdom (UK GDPR)
Yoria complies with UK GDPR and the Data Protection Act 2018 as a data processor. We maintain records of processing activities, implement appropriate security measures, and support Customer compliance with data subject rights. UK Customers may request a DPA incorporating UK IDTAs at [email protected]. AI resume parsing is a decision-support tool only; no automated decisions with legal or similarly significant effects are made solely by AI without human review.
Japan (APPI — 個人情報保護法)
Japan's APPI applies to personal information about Japan-resident individuals. Under the 2022 APPI amendments, cross-border transfers require either individual opt-in consent or a contractual protection system ensuring APPI-equivalent protections. Customers recruiting in Japan are responsible for obtaining appropriate consent. Our DPA serves as the contractual protection system required under APPI.
Where candidate data includes "special care-required personal information" (要配慮個人情報), explicit prior consent from the candidate is required. Customers handling such data should consult qualified Japanese legal counsel.
Singapore (PDPA)
Yoria operates as a "data intermediary" under Singapore's PDPA. We implement the protection obligation and comply with data subject access and correction requests within our scope. Singapore-based Customers remain responsible for their own PDPA obligations, including notification and accuracy requirements.
Australia (Privacy Act 1988 / APPs)
Yoria complies with the Australian Privacy Principles (APPs). We make overseas disclosures only with contractual safeguards requiring APP-equivalent protections. For unresolved complaints, the Office of the Australian Information Commissioner (OAIC) is the relevant authority.
New Zealand (Privacy Act 2020)
Yoria complies with New Zealand's Privacy Act 2020 and the Information Privacy Principles (IPPs). We support Customer compliance with the mandatory breach notification regime and data subject rights.
Canada (PIPEDA / Quebec Law 25)
We comply with PIPEDA at the federal level and Quebec's Law 25 for Quebec-based Customers. We can provide documentation to support Customer Privacy Impact Assessment requirements.
United States — California (CCPA / CPRA)
Yoria acts as a "service provider" under the CCPA/CPRA. We do not sell or share personal information for our own commercial purposes. We support Customer compliance with California consumer rights requests (access, deletion, correction, opt-out of sale/sharing). US Customers may request a CCPA service provider agreement at [email protected].
16. Data breach notification
In the event of a confirmed personal data breach affecting Customer data, we will:
- Notify affected Customers without undue delay, and in any event within 72 hours of becoming aware of the breach
- Provide details of: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken to address the breach
- Support Customers in meeting their own notification obligations to supervisory authorities and data subjects
Breach notification timelines under specific laws:
- UK GDPR: 72 hours to ICO (Customer obligation); Yoria notifies Customers without undue delay
- APPI (Japan): prompt notification to PPC for qualifying breaches
- PDPA (Singapore): 3 calendar days to PDPC for mandatory breach notification
- Australia: 30 days to OAIC for eligible data breaches
- New Zealand: notification to the Privacy Commissioner as soon as practicable for notifiable privacy breaches
- Canada (PIPEDA): notification to the OPC as soon as feasible for qualifying breaches
17. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify Customers by email at least 30 days before the change takes effect. The updated policy is always available at yoria.io/privacy.
Continued use of the platform after the effective date constitutes acceptance of the updated policy. If you do not agree with material changes, you may terminate your subscription before the effective date.
18. Contact us
For privacy enquiries, to request a Data Processing Agreement, or for assistance with data subject requests:
- Privacy: [email protected]
- Security disclosures: [email protected]
- Subject line format: Privacy Request — [Your name] — [Jurisdiction]
We aim to respond to all privacy requests within 30 days.