Last updated: 16 September 2026
Workcraft is an AI-assisted hiring platform operated by WUQLA SOFTWARE CO. L.L.C, a company incorporated in Dubai, United Arab Emirates ("Workcraft", "we", "us"). This policy explains what personal data we collect, why, who we share it with, and what rights you have.
It applies to three groups of people:
For candidate data, the hiring organization that posted the job or uploaded your resume is the data controller. Workcraft processes candidate data on that organization's behalf and under its instructions. Questions about why a particular organization holds your data, or how it will use it in its hiring decision, should go to that organization. We will still help you exercise your rights, and you can always contact us directly.
For user, organization and visitor data, Workcraft is the data controller.
When you apply through a job page:
When a hiring organization uploads your resume on your behalf:
In both cases we then generate and store:
We do not ask for, and our systems do not deliberately extract, sensitive information such as health, religion, ethnicity or political opinions. If your resume contains such information it will be processed along with the rest of the document, so we recommend leaving it out.
Candidate data is used to assess your application for the specific role you applied to or were added to. Our AI system extracts a structured profile from your resume and scores it against the competencies the hiring organization defined for the role. It also checks answers to screening questions against the organization's requirements.
The AI system does not make hiring decisions. It produces a score and a summary. Every change to your application status, including rejection, shortlisting and hiring, is made by a person at the hiring organization. You have the right to ask that organization for a human review of any decision.
We do not use candidate data, resumes or organization data to train AI models, and our AI providers are contractually prohibited from doing so.
User and organization data is used to provide the service: running your account, posting jobs, scheduling interviews, billing, and sending you transactional email about your account.
Visitor data is used to understand how our website and product are used, to answer your messages, and to show hiring organizations how many people viewed their job and from where.
Where the GDPR or UK GDPR applies, we rely on:
We do not sell personal data. We share it with the service providers below, each of which processes data only on our instructions and under a data processing agreement.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Supabase | Database, sign-in, and file storage for resumes and images | All data | Frankfurt, Germany |
| Vercel | Web hosting and routing of AI requests | All data passing through the application | Frankfurt, Germany, and USA for AI routing |
| Anthropic | AI model that extracts and scores resumes and helps write job postings | Resumes, screening answers, job and company descriptions | USA |
| Trigger.dev | Background job processing | Internal record identifiers and processing metrics only | Frankfurt, Germany |
| Postmark | Sending transactional email | Recipient name and email, message content | USA |
| Stripe | Payments and invoicing | Billing details, entered directly with Stripe | USA |
| Nylas | Calendar connection for interview scheduling | Calendar credentials, interview events including candidate name and email | EU |
| Google and Microsoft | Sign-in, and calendar events when a calendar is connected | Sign-in identity; interview events | Global |
| PostHog | Product analytics, with consent where required | Usage events, and for signed-in users their name, email and profile picture | Frankfurt, Germany |
| Sentry | Error monitoring | Technical error reports, without user identity | USA |
| Crisp | Support chat | Chat messages; name, email and profile picture of signed-in users | EU |
| Upstash | Rate limiting | Organization identifiers only | USA |
| Firecrawl | Extracting company information from your public website during onboarding | Your website address | USA |
| Formspree | Contact form on our website | Name, email and message you submit | USA |
Hiring organizations can share a shortlist of candidates, including names, scores and the AI system's reasoning, with people outside Workcraft by email, for example with a hiring manager. Responsibility for that sharing lies with the organization.
We will also disclose data where required by law, or to protect the rights and safety of Workcraft, our users, or others.
Workcraft is based in the United Arab Emirates. Our database and file storage are in Frankfurt, Germany. Some of the providers above are in the United States.
Where data about people in the European Economic Area, the United Kingdom or Switzerland is transferred outside those areas, including to Workcraft staff in the UAE and to US providers, we rely on the European Commission's Standard Contractual Clauses or the provider's certification under the EU-US Data Privacy Framework, together with additional safeguards where needed.
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent. You also have the right to lodge a complaint with your local data protection authority.
Candidates can see everything we hold about an application by signing in to the candidate portal using the link in any email we sent you, or by requesting a new link from the job page you applied to. To delete your data, reply to any email you received from us or write to hi@workcraft.ai. We will confirm deletion within 30 days. If you were added by a hiring organization and did not expect it, tell us and we will remove your data.
Users can edit their name, picture and preferences in the app, and can disconnect their calendar at any time. To close an account or delete an organization, write to hi@workcraft.ai.
We will answer any request within one month. We may ask you to confirm your identity before acting on it.
We use these cookies:
Our support chat runs in a mode that does not set cookies or store data in your browser.
Data is encrypted in transit and at rest. Resumes are stored privately and served only through short-lived signed links. API keys are stored hashed. Access to production data is limited to Workcraft staff who need it, and hiring organizations can only see candidates for their own jobs.
If a breach puts your data at risk, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where the law requires, and notify affected people without undue delay with what happened and what we are doing about it.
Workcraft is not intended for anyone under 16, and we do not knowingly collect their data.
We will post changes here and update the date at the top. For material changes we will notify users by email.
Workcraft's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar access only to check availability and create, update and cancel interview events on your behalf. We do not use Google Workspace APIs to develop, improve, or train generalized AI or machine learning models.