1. General provisions
We aim to be transparent about information handling. This document explains how we collect, use, and protect data, and how users can manage it.
2. Data controller
Personal data is processed by sole proprietor Denis Davydov, registered in the Republic of Georgia.
- Country of registration: Georgia
- Tax ID: 300452588
- Registered address: Georgia, Tbilisi, Gldani district, Gldani settlement, microdistrict III, building 80
- Website: hitit.one
- Contact email: hi@hitit.one
3. Categories of data processed
We collect information required to operate the service:
- Account: email, name, username, encrypted password, technical IDs, Google, Yandex, and VK sign-in data, and Passkey (WebAuthn) public-key and device metadata.
- Profile and resume: name, photo, city, contacts, experience, skills, education, projects, salary expectations, uploaded resume files, and other information provided by the user.
- Career activity: applications, saved and favourite jobs, reactions, viewing history, notes, and job reports.
- AI tools: resume and job fragments, resume-analysis and ATS-check results, job matching, cover letters, vCard generation, and semantic recommendations.
- Messages: chat correspondence, attachments, and message metadata.
- Phone: number and verification status when verification is used.
- Subscription and payments: plan, usage limits, transaction amount and status. Payment providers transmit these details; we do not store full card details.
- Telegram: chat ID, username, and notification settings when the bot is connected.
- Support requests: name, email, and message text submitted through feedback forms.
- Technical data: IP address, approximate country by IP, browser and device type, cookies, action logs, and error logs.
4. Processing purposes
We use data to:
- Create and maintain user accounts.
- Provide job search, salary analytics, AI tools, and paid services.
- Match and recommend jobs, including semantic search.
- Generate cover letters and vCards, and evaluate resume-to-job compatibility.
- Enable communication between users and employers.
- Send email and Telegram notifications.
- Process subscriptions, limits, and payments.
- Protect against fraud, spam, and abuse.
- Analyse feature usage and improve the interface.
5. Public resumes
When a resume is published, it becomes available through a direct link. Anyone with that link can view its content. Before publication, the user gives separate consent to distribute the data. Publication can be revoked in settings, after which the link no longer provides access.
6. Legal bases
We process information to perform our agreement with the user, on the basis of consent, to meet legal requirements, or where data is provided voluntarily. Because the controller is registered in Georgia and the service is available internationally, processing may involve cross-border transfers to hosting servers and partners that operate the platform.
7. Sharing with third parties
We do not sell personal data. Data may only be shared with partners that operate the service:
- Cloud infrastructure and hosting providers.
- Payment systems.
- Email delivery services.
- Yandex Metrica, only after consent to analytics cookies; it receives counters and conversion goals, not resume, chat, or contact text.
- Google, Yandex, and VK when OAuth sign-in is used.
- Telegram when notifications and the bot are enabled.
- AI platforms used for text analysis, cover letters, resume matching, and semantic search.
8. Cookies and analytics
We divide cookies into categories. Necessary cookies provide sign-in, security, and core site functionality and are always active. Analytics and marketing cookies load only after explicit consent.
- Necessary: session, anti-bot, and device-security tokens.
- Analytics: internal product statistics and Yandex Metrica for visits and conversion goals. Webvisor is disabled in dashboard, chat, and settings pages.
- Marketing: advertising tags are disabled by default and are not used until separately connected.
- Retention: consent is stored up to 9 months; technical cookies up to 2 years; Metrica data up to 24 months; raw internal analytics events usually up to 90 days.
- Management: choices can be changed through the “Cookie settings” link in the site footer. Withdrawal stops analytics scripts from loading.
9. Retention periods
- Account and resume: until the user deletes the profile.
- Public links: until unpublished or the account is deleted; distribution consents are stored for up to 3 years to protect the parties’ rights.
- Payment information: at least 5 years under tax-accounting requirements.
- Chat messages: until account deletion or on user request.
- Support requests: up to 3 years.
- AI processing results: for the retention period of the account and related entities.
- Technical logs: usually 90 days.
When consent is withdrawn or an account is deleted, data is deleted unless the law requires longer retention.
10. Data protection
We limit access to databases and use technical encryption measures. AI features follow data minimisation: only the information needed for the algorithms is processed.
11. User rights
You may request information about your data, ask for correction or deletion, and withdraw previously given consent. Send requests to hi@hitit.one.
12. Policy updates
The current text is always available on this page. Continued use of the website after changes means that you accept the updated version.