Privacy policy.
What VRS holds about candidates, clients and the people who use our apps, why we hold it, and how to make us correct or delete it — without a lawyer between you and the answer.
Who we are and what this policy covers
VRS — Verified Recruitment Solutions (“VRS”, “we”, “us”) is a recruitment company based in Amman, Jordan. This policy explains how we handle personal data across everything we run:
- Recruitment services — finding, screening and placing candidates for our clients, and this website, vrsjo.com.
- VRS Recruit — our recruitment web app at app.vrsjo.com, used by our consultants and by client hiring teams.
- Syndeo — our communications product for meetings, messaging and scheduling at app.syndeo.cloud.
Syndeo also has its own detailed privacy policy at app.syndeo.cloud/privacy, which applies alongside this one. How both apps handle information received from Google is set out in Google user data.
Recruitment services and candidates
What we collect about candidates
Your CV and the details you give us: contact information, work history, salary expectation, notice period, location and right-to-work status. Where a role requires it, we also record assessment results, qualification checks and references. We do not collect anything a hiring decision does not require.
Why we hold it
To match you to roles, to represent you accurately to an employer with your consent, and to keep a record of the decisions made about your application. Where the law requires a lawful basis, ours is your consent for the network and legitimate interest for an active application you have started.
Who we share it with
An employer sees your details only after you agree to that specific role. We never sell candidate data, never share it with a third party for marketing, and never pass it to another agency. Assessment providers and background-check partners act on our instruction only, under contract.
How long we keep it
Twenty-four months from your last contact with us, unless you ask us to keep it longer or delete it sooner. Records tied to a placement are held for the period the client's contract and local employment law require, then deleted.
Automated decisions
No candidate is rejected by software. We use automation for transcription, search and organising notes; a named consultant makes every judgement about your application and can tell you the reasoning.
Where data is held
Regional hosting with residency options for the EU, UK and GCC. Where data crosses a border it is covered by standard contractual clauses. Client data in VRS Recruit is held under the residency option chosen by that client.
Client and website data
For clients we hold business contact details and the mandate record. This website sets no advertising or tracking cookies. It stores three things in your own browser, none of which leave it or reach us: your light or dark theme preference, your language choice, and — if you start filling in a form — a local draft of what you have typed, so a refresh does not lose it. Clearing your browser storage removes all three, and the draft is discarded as soon as the form is sent.
The VRS Recruit web app
VRS Recruit is used by our consultants and by the client organisations we work with. Each organisation has its own workspace, kept separate from every other. In it we process:
- Account data — your name, work email address, role, sign-in and security records, and your settings.
- Workspace content — candidates, jobs, notes, messages, interviews and workflows that you and your colleagues create or import.
- Connected accounts — when you choose to connect an outside account, such as Google, the data that connection needs to do what you asked. See Google user data.
- Technical data — request, error and security logs, used to run, secure and fix the service.
When a client uses VRS Recruit for its own hiring, that client decides what goes into its workspace and why, and we process that data on the client’s instructions. People whose data is in a client’s workspace can contact that client, or us, to use their rights.
Syndeo
Syndeo processes your account data, the meetings, messages and contacts you create in it and, where you connect them, data from your calendar and email accounts. Its full privacy policy — including what it records, for how long, and which providers it uses — is at app.syndeo.cloud/privacy.
Google user data
VRS Recruit and Syndeo both let you connect a Google account. Nothing is read from Google until you connect an account yourself, and each connection asks only for the permissions its feature needs. Google shows you those permissions before you agree, and each connection also receives your Google account’s email address so the app can show which account is connected.
What VRS Recruit accesses, and why
- Gmail (
gmail.modify,gmail.send) — only when you connect Gmail, to the unified inbox or to a Google Mail step in a workflow you configure. We read your messages and labels so you can see and handle them in VRS Recruit; we change labels and flags — for example marking a message as read, or moving it to the bin — when you or your workflow asks; and we send email from your account when you send it or your workflow step sends it. We never permanently delete your email. - Google Sheets (
spreadsheets,drive.readonly) — only when you add a Google Sheets step to a workflow. We list the names of your spreadsheets so you can pick one, and add the rows your workflow produces to the sheet you picked. Drive access is used only to list spreadsheet names; we do not open or download your other files. - Google Calendar (
calendar) — only when you connect your calendar for interview scheduling. We read when you are busy, and the events in the period being scheduled, so we offer only times you are free; and we create and cancel the interview events you book, with a Google Meet link when you choose one.
What Syndeo accesses, and why
- Google Meet scheduling (
calendar.events) — when you schedule a Google Meet in Syndeo, we create the event, with its Meet link, on your Google Calendar, and update or cancel it when you change or cancel the meeting in Syndeo. - Availability (
calendar.freebusy) — we read only whether you are free or busy, not what your events are, to offer available times when someone books with you. - Mailbox on the timeline (
gmail.readonly, optional) — if you turn it on, we read the headers (sender, recipients, subject and date) and a short preview of emails exchanged with people who are already your contacts in Syndeo, and show them on that contact’s timeline. This access is read-only: Syndeo never sends, changes or deletes your email.
How we store and protect it
The access and refresh tokens Google issues are encrypted at rest and used only by our servers, only to run the feature you connected. Data moves between Google, our servers and your browser over encrypted connections. Access to our production systems is limited to the people who operate them.
How long we keep it
Tokens are kept while a connection is active and deleted when you disconnect it. Email previews that Syndeo has added to a contact’s timeline become part of that contact’s record and stay until you or your workspace administrator delete them — or until you ask us to, in which case we delete them within thirty days. Emails you sent and calendar events you created through a connection belong to your Google account and stay there after you disconnect.
Disconnecting and revoking access
You can disconnect a Google account at any time from the integration settings in VRS Recruit or Syndeo. You can also revoke our access directly in your Google Account at myaccount.google.com/permissions; the connected feature stops working at once. To have Google data we hold deleted, email hamzah@vrsjo.com.
Limited Use
VRS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Google user data:
- is used only to provide and improve the features described above, which you can see and control in the app;
- is never used for advertising, including retargeting and personalised or interest-based ads;
- is never sold, and is transferred to others only when needed to provide those features, for security purposes, to comply with the law, or as part of a merger, acquisition or sale of assets;
- is never used to develop, improve or train generalised AI or machine-learning models;
- is not read by any person at VRS unless you have given us your affirmative consent to view specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with the law, or it has been aggregated and anonymised for our internal operations.
Service providers
We use a small number of service providers to run our services — for hosting, email delivery, error monitoring and similar infrastructure. They process data only on our instructions and under contract. We do not sell personal data. Ask us and we will tell you which providers process yours.
Security
Data is encrypted in transit, connection tokens and other secrets are encrypted at rest, and each client workspace is kept separate. No system is perfectly secure: if a breach affects your data, we will tell you, and the relevant authorities, as the law requires.
Your rights
Whichever service you use, you can ask to see, correct, export, restrict or delete your personal data, and withdraw any consent you have given. Email hamzah@vrsjo.com. We confirm within five working days and complete the request within thirty days. If we hold your data for one of our clients, we handle the request with that client. You can also complain to the data protection authority where you live.
Changes to this policy
When we change this policy we update the date at the top of this page. If a change materially affects how we use data you have already given us, including Google user data, we will tell you before it takes effect and, where required, ask for your consent again.
Contact
VRS — Verified Recruitment Solutions, Amman, Jordan. For anything about privacy or your data, email hamzah@vrsjo.com. A person answers, within five working days.
Questions about your data?
A person answers, within five working days.