PiaarFind your people

Privacy policy

This is the formal version. The plain-English version of what we do and don't do lives on Responsible AI.

Last updated: 30 September 2026 · Version 2.5

1. Who we are

Piaar is operated by Saad Abdullah, PhD, trading as PiaarTech, based in Västerås, Sweden. PIAAR is a registered trademark of Saad Abdullah. For the purposes of GDPR, Saad Abdullah is the data controller for the personal data described in this policy. Contact details are at the bottom of this page.

If you're in the EU/EEA, your local data protection authority can hear complaints if you ever feel we've mishandled your data. In Sweden that's the Integritetsskyddsmyndigheten (IMY).

2. What we collect

Information you give us

If you are a business customer

Separately from individual accounts, we hold records for organizations and individual customers who buy organizer plans, event promotion or event reporting:

Information we generate

Information we do not collect

3. Why we collect it

Every piece of data has a specific purpose. If a use case isn't listed here, we don't have it.

For each category of data, the legal basis is one of the following:

5. Sharing

We share your data with a short list of service providers ("processors") that we use to run Piaar:

Event organizers

An event organizer is not one of our processors — they are a separate controller of whatever they receive from us, and their own privacy policy governs what they do with it afterwards. Two things can reach them:

Recruiters

If you're Discoverable and switch on "Open to opportunities," you can see jobs a workspace posts and choose to act on them. Just being shown a job, or eligible for a job alert, does not share anything about you with the recruiter — our server checks eligibility against your coordinates and a recruiter composing an alert only ever sees a rounded count of how many people it reached, never who they are.

Tapping "I'm interested" on a job is different: it requires a separate standing consent, "Share details with recruiters" in Account settings, because it's what lets a recruiter see more of you. Once given, it covers every future job until you turn it off. From that point, the workspace owner can see your public profile (name, headline, category, city, photo, bio, and the skills you offer) and the match score you held at the moment you applied, and can download that alongside your email address in a spreadsheet export — but only while your standing consent is currently switched on. Your exact coordinates and phone number are never part of this. Turning off that consent, or withdrawing from a specific job, stops future sharing; it can't recall a profile or an export a recruiter has already seen or downloaded.

We do not sell your data. Not to advertisers, not to data brokers, and not for money to recruiters either — but if you apply to a job, a recruiter does legitimately receive some of your data with your consent, exactly as described above. We'd rather be precise about that than imply recruiters never see anything about you. If Piaar is ever acquired, we intend that your data would only transfer to the buyer after you re-consent — that's a commitment about how we'd handle an acquisition, not something our systems can enforce on their own.

6. Retention

We keep data only as long as we need it for the purpose we collected it.

7. Your rights

Under GDPR, you have the right to:

To exercise any of these, email privacy@piaartech.com. We respond within statutory windows: one month, extendable by up to two further months for complex requests.

8. Security

All app data lives in Google Firebase, which encrypts data in transit (TLS) and at rest. On top of that we use Firebase App Check to block unauthorized clients from talking to our backend, database security rules that are designed to restrict reads and writes to what a signed-in user should be allowed, password hashing handled by Firebase Authentication (we never store or see passwords), and access to production data limited to the operator. No system is 100% secure. If a breach happens, GDPR requires us to notify our supervisory authority (IMY) within 72 hours of becoming aware of it; if the breach is likely to put you at risk, we will also tell you directly — the law doesn't set a fixed deadline for that part, only "without undue delay."

9. International transfers

Your core data — account, profile, and messages — is processed within the EU: our database (Cloud Firestore) runs in Google Cloud's eur3 multi-region, and our server functions and matching service run in europe-west1 (Belgium). Some processing is not confined to the EU by default: our content-moderation calls to Google Cloud Natural Language and Vision currently run on Google's global endpoints rather than an EU-restricted one (see Sharing, above), and services like push notifications, authentication, and Remote Config are global Google infrastructure by design, not something we can pin to the EU ourselves. If any processor we use is outside the EU/EEA, we rely on Standard Contractual Clauses or an equivalent safeguard in line with the Schrems II ruling. If you sign in with Google, Apple, or LinkedIn, those providers process your sign-in under their own infrastructure and transfer safeguards.

10. Children

Piaar is not intended for users under 18. We don't knowingly collect data from anyone under that age. If you believe a child is using the service, contact privacy@piaartech.com and we will delete the account promptly.

11. Changes to this policy

If we change this policy meaningfully, we'll notify you in-app and by email at least 30 days before the change takes effect. The version number and "last updated" date at the top of this page change with every revision.

12. Contact

All privacy and general questions: privacy@piaartech.com

Postal: Fiholmsgatan, Västerås, Sweden — see Trader details on our contact page.