Savannah Privacy PolicyIntroduction
Savannah Apps Inc ("Savannah", "we", "us", or "our") is committed to protecting your personal information and your right to privacy. This Privacy Policy is designed to inform applicants who directly apply for roles advertised on Savannah Apps about our data handling practices and will explain how we collect, use, disclose and safeguard your data when you use our platform, on both our mobile application (the "Savannah App") and our B2B SaaS recruitment platform (the "Savannah Platform"), as well as any other related service we use (collectively, the "Services").
Savannah Apps Inc is registered in the United States of America. We act as a data controller for the personal data we collect from candidates, and as a data processor for personal data we handle on behalf of our hiring clients.
By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, please discontinue use of our Services.Who We Are
Savannah Apps Inc is the data controller responsible for your personal data.
Company name: Savannah Apps Inc
Registered address: 7001 Brush Hollow Rd, Westbury, NY 11590, USA
Email: [email protected]
Website: www.savannahapps.comDefinitionsData Controller An entity such as a company, sole trader or public authority that determines the purposes and means of processing personal data.
Data Processor A legal person, public authority, agency or other body that processes personal data solely on behalf of a data controller.
Job Applicant An individual who formally expresses interest in an open position by submitting required materials such as a cv, resume, cover letter or application form to an employer.
Employer A person or organisation that employs people
Personal Data Any information relating to a living, identified, or identifiable individual including name, ID number, location data or online identifiers like IP addresses
Sensitive Data Any information that requires special protection against unauthorised access or disclosure to legal, ethical or security reasons such as privacy risks or financial loss.
Special Categories of Personal Data Specific, highly sensitive personal information under UK GDPR that requires increased protection. It can include information revealing racial / ethnic origin, political opinions, religious beliefs, trad union membership, genetics, biometrics (for identification), health data and sexual orientation
UK GDPR The UK General Data Protection Regulation (UK GDPR) is a UK law that sets out the key principles, rights and obligations for most processing of personal data in the UK
Data Protection Act 2018 The UK’s primary legislation governing data protection, implementing the General Data Protection Regulation (GDPR) and setting rules for handling personal data.Data Collection
When registering for use on one of our services, Savannah Apps Inc will collect and process personal data of job applicants. This Privacy Policy applies to all job applicants and explains how we handle your data whilst protecting the privacy and security of any personal information collected and stored to meet the data protection obligations under the General Data Protection Regulation (“GDPR”) and the Data Protection Act 2018.
When registering for use on one of our services, Savannah Apps Inc will collect and process personal data for job applicants.
Types of data that may be collected
Personal Identification Information
Full Name, Email Address, Phone Number, Date of birth and gender (this may be collected for identity verification or compliance), Government Identification (e.g., National Insurance Number, Social Security Number, Passport), Photographs (if uploaded to profile)
Professional and Employment Data Resume/CV Content (including work experience, Education qualifications, skills), References (contact details of former managers/colleagues), Background Check information (criminal convictions, credit checks, driving records – if applicable for role/employer), Salary expectations, Job preferences
Sensitive Personal Data (this data will only be collected when required for compliance or legal purposes and in accordance with applicable data protection laws) Racial or Ethnic origin, Health and Medical Information (disability status for workplace accommodations), Equal Opportunities information, right to work status
Technical and Usage Data (Automatic Collection) IP Address, Device ID, Operating System, Browser Type, App Interaction (time spent, links clicked, app version, session activity, swiping and matching activity), Geolocation data (location to match local jobs – if you grant permission), log data (server logs, error reports, performance data) Cookies and Tracking Technologies
Financial and Third-Party Data Bank Account Info (for direct deposit set up if applicable), Information from social login providers (LinkedIn, Google or processional background services – with consent and only when legally required), hiring clients who share your application via our B2B platform, Job boards or partner platforms where you have chosen to share your profile, Analytics and advertising pertners
Data Collected for Safety and Security Camera/Microphone Access (for video upload/video interviews), user content (messages, support chat history)Purposes for processing Personal Data
Contractual necessity:
• Creating and managing your account
• Matching job applicants with relevant job opportunities using our AI-powered algorithm
• Enabling communication between candidates and hiring clients
• Processing payments for premium features
• Delivering our B2B platform to hiring companies
Legitimate interests:
• Improving and personalising our platform and matching algorithms
• Analysing usage patterns to enhance product features
• Fraud prevention and platform security
• Internal analytics and business reporting
Consent (where explicitly obtained):
• Sending marketing communications and product updates
• Using non-essential cookies and tracking technologies
• Sharing your profile with prospective employers beyond your explicit match actions
Legal Basis for Processing
Savannah Apps Inc process any personal data collected in accordance with the UK General Data Protection Regulations and Data Protection Act 2018.
When processing personal data, we comply with the seven key principles set out under UK GDPR:
• Lawfulness, Fairness and Transparency
• Purpose Limitation
• Data minimisation
• Accuracy
• Storage Limitation
• Security
• Accountability
Savannah Apps Inc will comply with all GDPR principles to fulfil legal obligations. Where / if we process special categories of personal data such as health or diversity information, we do so in accordance with Article 9 of the UK GDPR relying on:
- Explicit consent
- Employment law obligations
- Substantial public interest (such as equality monitoring)
AI & Automated Decision-Making
• Savannah uses artificial intelligence and machine learning to power candidate-to-job matching, candidate ranking, and shortlist generation. This involves automated processing of personal data to produce scores or recommendations that may influence hiring decisions.• Under UK GDPR, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. In practice, our AI recommendations are always reviewed by human recruiters or hiring managers before any decision is made. You may request a human review of any AI-generated recommendation by contacting us at [email protected].• We are committed to fairness, transparency, and bias reduction in our AI systems. Our models are regularly audited to identify and mitigate potential discrimination.Data Sharing and Transfer Details
Under the UK General Data Protection Regulation, we may share or transfer personal data where we have a lawful basis to do so.- With Employers / Hiring Managers: When you apply to a role or are matched with an opportunity, relevant profile information is shared with the relevant employer or recruitment agency using our platform.
- With service providers: We use trusted third-party providers to operate our Services, including cloud hosting, payment processing, analytics, and customer support. These parties are contractually bound to process data only on our instructions and in accordance with applicable law.
- For legal compliance: We may disclose data to comply with applicable law, court orders, or regulatory requirements, or to protect the rights and safety of Savannah, our users, or the public.
- Business transfers: In the event of a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction. We will provide notice to affected users prior to any such transfer.
International Data Transfers
Savannah is based in the United Kingdom. As we expand internationally, your data may be transferred to and processed in countries outside the UK and European Economic Area (EEA). Where such transfers occur, we ensure appropriate safeguards are in place, including:
• Adequacy decisions recognised by the UK Information Commissioner's Office (ICO)
• Standard Contractual Clauses (SCCs) approved by the ICO
• Binding Corporate Rules or other lawful transfer mechanisms approved under UK data protection law
We take reasonable steps to ensure that all third parties who receive personal data process it securely and only for the purposes for which it was shared, in accordance with the requirements of UK GDPR and the Data Protection Act 2018.
By using our Services, you acknowledge that your data may be transferred internationally in accordance with these safeguards.
Data Retention
All personal data received by Savannah Apps Inc will only be retained for as long as is necessary for the purposes described in this policy, or as required by applicable law.
Our standard retention periods are:
• Active candidate accounts: duration of account activity plus 2 years
• Inactive accounts: 12 months after last login, after which accounts are flagged for deletion
• Hiring client data: duration of the client relationship plus 7 years for legal and tax compliance
• Application and matching records: 24 months from date of application
• Financial transaction records: 7 years, as required under UK law
End of Service / Purpose
Upon termination of a user’s account, or when the data is no longer needed for its original purpose, we will delete or anonymise the data within 30 days.
You may request deletion of your account and associated personal data at any time by contacting [email protected].
Anonymisation Process
Anonymisation shall be performed by irreversibly removing or obscuring all personally identifiable information including but not limited to:
- Removing direct identifiers (e.g., name, email, address, phone number)
- Generalising or aggregating data (e.g., converting exact birth dates to age ranges)
- Replacing identifiers with random, non-attributable data.
Treatment of Anonymised Data
Once data is fully anonymous, it is no longer considered “personal data” under GDPR and be retained and used for statistical research and analytical purposes.
Re-identifiable Prohibition
Savannah Apps Inc will not attempt to re-identify individuals once anonymised, nor will it disclose any key information that could allow for such re-identification.
Data Subject Rights
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the following rights:
• Right of access: request a copy of the personal data we hold about you
• Right to rectification: request correction of inaccurate or incomplete personal data
• Right to erasure: request deletion of your personal data, subject to legal obligations
• Right to restriction: request that we limit how we process your data in certain circumstances
• Right to portability: receive your personal data in a structured, commonly used, machine-readable format
• Right to object: object to processing based on legitimate interests, or to direct marketing at any time
• Rights related to automated decision-making: request human review of any AI-driven decision
• Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing
To exercise any of these rights, contact us at [email protected].
We will respond within 30 calendar days. We may need to verify your identity before processing your request.
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Data Security
Savannah takes the security of personal data seriously and has implemented industry-standard technical and organisational security measures to protect your data against unauthorised access, disclosure, loss, misuse, alteration, or destruction which include:
• Encryption of data in transit using TLS and at rest using AES-256
• Role-based access controls and least-privilege permissions for all internal systems
• Regular security audits, vulnerability assessments, and penetration testing
• Incident response and data breach notification procedures
Access to personal data is limited to authorised personnel only who required the information for legitimate recruitment or operational purposes. We also ensure that any third party who process personal data on our behalf are required to always implement appropriate security safeguards.
Although all processing of personal data at Savannah is carried out in accordance with UK GDPR and the Data Protection Act 2018, no method of electronic transmission or storage of data is completely secure. If a breach of data occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority, the Information Commissioners Office in accordance with the requirements of the UK General Data Protection Regulation. Where the breach is likely to result in a high risk to affected individuals, we will also notify impacted users without undue delay and provide information about the nature of the breach, the potential consequences and the steps being taken to address it.
If you believe your personal data may have been compromised, you should contact us immediately using the contact details provided in this policy. Users may also take steps such as updating their account passwords, monitoring their accounts for unusual activity and reporting concerns to the Information Commissioners Office if they believe their data protection rights have been affected.
Information Commissioners Office (ICO)
Website: http://ico.org.uk
Helpline: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK5 5AF, United Kingdom
Cookies & Tracking Technologies
We use cookies and similar technologies (including pixels and local storage) to operate and improve our Services. These are categorised as follows:
• Strictly necessary: Essential for the platform to function, such as authentication and session management. These cannot be disabled.
• Performance and analytics: Help us understand how users interact with the platform (e.g. usage statistics, error tracking). These require your consent.
• Marketing and targeting: Used to deliver relevant advertising and measure campaign effectiveness. These require your consent.
You can manage your cookie preferences through our Cookie Settings banner on first visit, or at any time via your account settings. Disabling certain cookies may affect platform functionality.
Children's Privacy
Our Services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child under 16 has provided personal data through our platform, please contact us immediately at [email protected] and we will take steps to delete that data promptly.
Third-Party Links & Integrations
Our platform may contain links to third-party websites or integrate with third-party services such as applicant tracking systems or job boards. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before sharing any personal data with them.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or platform features. When we make material changes, we will notify you by email or via a prominent notice within the platform at least 14 days before the changes take effect.
The "Last updated" date at the top of this document reflects the most recent revision. We encourage you to review this policy periodically.
Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or our data practices, please reach out:
Email: [email protected]
Post: Data Privacy, Savannah Apps Inc, 7001 Brush Hollow Rd, Westbury, NY 11590, USA
Website: www.savannahapps.comWe aim to respond to all privacy enquiries within 5 business days.Appendix 1
How to Delete Your Account
You have the right to delete your Savannah Apps account and associated personal data at any time. We have made this process as simple as possible.Option 1 — Delete directly in the app:
Open the Savannah App on your mobile device
Go to Profile > Settings > Account
Tap 'Delete Account' and follow the on-screen confirmation steps
Your account will be scheduled for deletion immediatelyOption 2 — Submit a deletion request by email:
Email us at [email protected] with the subject line: Account Deletion Request
Include the email address associated with your account
We will confirm receipt within 2 business days and process the deletion within 30 daysWhat happens when you delete your account:
Your profile, job preferences, and matching history will be permanently removed from our active systems
Any active applications in progress will be withdrawn and hiring clients notified
You will no longer receive any communications from Savannah Apps
Certain data may be retained for a limited period where required by law (e.g. financial transaction records for up to 7 years as required under US federal and state law)
Anonymised and aggregated data that cannot identify you may be retained for analytics and platform improvement purposesPlease note that account deletion is permanent and cannot be undone. If you later wish to use Savannah Apps again, you will need to create a new account.If you encounter any issues with the deletion process, please contact us at [email protected] and we will assist you promptly.
© 2026 Savannah. All rights reserved.
Savannah is built with privacy and fairness in mind. We never sell candidate data.