01Who we are and what this covers
Schela(“Schela”, “we”, “us”) provides an AI recruiting coordinator that contacts candidates, books interview slots, sends reminders, and handles rescheduling across WhatsApp and email. This policy explains what personal data we handle, why, and what rights you have over it.
It applies to our marketing website at schela.app, our early access waitlist, and the Schela application.
Two very different roles
Schela handles two categories of personal data, and our responsibilities differ for each. This distinction matters, so we set it out up front:
02Data we collect
Information you give us
- Waitlist and early access: name, email address, job role, company name (optional), team size, and the candidate outreach channels you use today.
- Account data: name, work email, password hash or federated identity (Google, LinkedIn), company name, and role.
- Billing data: plan, billing contact, and transaction records. Card details are handled by our payment provider and never touch our servers.
- Support and sales correspondence: whatever you choose to send us by email or through the product.
Candidate data processed on your behalf
When you use Schela to coordinate interviews, we process the candidate information you provide or connect: name, email address, phone number, the role they applied for, interview stage and status, scheduling preferences and availability, and the content of the WhatsApp and email threads Schela conducts with them.
Please do not send us special category data. Schela is not designed to hold health information, biometric data, or data revealing race, religion, political opinions, trade union membership, or sexual orientation. Do not upload it or paste it into message threads.
Information collected automatically
- Technical data: IP address, browser and device type, operating system, referring page, and timestamps.
- Usage data: pages viewed, features used, and actions taken in the product, used to fix bugs and decide what to build next.
- Delivery metadata: whether a message was sent, delivered, or failed, so we can retry and report accurately.
03How we use personal data
- To deliver the service: send outreach, book slots, issue reminders, and handle replies.
- To create and administer accounts, authenticate users, and provide support.
- To process payments and maintain financial records.
- To monitor performance, debug failures, and keep the service secure.
- To contact waitlist subscribers when early access opens, and to send product updates you can unsubscribe from at any time.
- To meet legal, tax, and regulatory obligations.
AI processing
Schela uses third-party large language models to draft messages, interpret candidate replies, and decide on scheduling actions. Message content and the minimum surrounding context are sent to those providers to generate a response. We select providers that contractually commit not to train their models on data submitted through their API, and we do not use your content or candidate content to train our own models.
A human should review anything consequential. Schela drafts and sends coordination messages, but AI output can be wrong. You remain responsible for the hiring decisions and communications sent from your account.
04Legal bases for processing
Where the GDPR or UK GDPR applies, we rely on the following legal bases when acting as a controller:
- Contract: to provide the service you signed up for and to bill you for it.
- Legitimate interests: to secure and improve the product, prevent abuse, and communicate with business contacts — balanced against your rights.
- Consent: for the early access waitlist, marketing emails, and non-essential cookies. You can withdraw consent at any time.
- Legal obligation: for accounting, tax, and lawful requests from authorities.
When we act as a processor for candidate data, the customer is responsible for establishing a lawful basis for that processing and for informing candidates.
06International transfers
Schela is operated from Sri Lanka, and our sub-processors operate globally. Your data will therefore be transferred to and stored in countries outside your own, including the United States and the European Union.
Where personal data leaves the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant) together with additional technical safeguards such as encryption in transit and at rest. A copy of the relevant transfer mechanism is available on request.
07How long we keep data
- Account data: for as long as your account is active, then deleted within 90 days of closure.
- Candidate data: for as long as you instruct. You can delete individual candidates or entire pipelines at any time; deletion propagates from our live systems within 30 days.
- Message threads and delivery logs: retained for the life of the account for audit purposes, unless you delete them sooner.
- Waitlist entries: until early access closes or you ask us to remove you, whichever comes first.
- Billing records: for the period required by tax and accounting law, typically seven years.
Encrypted backups persist for a short rolling window after deletion and are overwritten on a fixed schedule.
08Your rights
Depending on where you live, you may have the right to access a copy of your personal data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent. Residents of California may additionally request disclosure of the categories of data collected and shared, and may opt out of sale or sharing — although we do neither. We will not discriminate against you for exercising any of these rights.
To make a request, email privacy@schela.app. We will respond within 30 days and may ask you to verify your identity first.
Candidates: if a company used Schela to contact you about a role, that company controls your data. Ask them directly, or write to us and we will forward your request to them and assist them in fulfilling it.
If you are in the EEA or the UK, you also have the right to lodge a complaint with your local data protection authority.
09Security
We encrypt data in transit with TLS and at rest, enforce row-level tenant isolation in the database so that one customer’s data cannot be read by another, restrict internal access on a need-to-know basis, and store credentials and API keys in a secrets manager rather than in application code.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority without undue delay and, where required, within 72 hours. To report a vulnerability, email security@schela.app.
11Children
Schela is a business tool and is not directed at anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact privacy@schela.app and we will delete it.
12Changes to this policy
We may update this policy as the product evolves. When we make a material change, we will update the “last updated” date at the top and, for account holders, notify you by email or in-app before the change takes effect. Continuing to use Schela after that point means you accept the revised policy.
13Contact us
For any privacy question, request, or complaint, write to privacy@schela.app.
Questions?
Privacy questions go to privacy@schela.app. We answer every one.