Trust & Transparency Report · Current as of 2 August 2026

Built for HR. Built for Trust.

We operate with full transparency about how your data moves, who processes it, and what rights you have as a user in the MENA region.

MENA Labour Law AwareAES-256 Encryption at Rest
Regional Alignment

Saudi Arabia

Outputs are calibrated to Saudi Labour Law requirements, including Saudisation (Nitaqat) percentages, probation period caps, and end-of-service gratuity calculations.

United Arab Emirates

Compliant with UAE Labour Law and DIFC/ADGM considerations. Offer letters and JDs reflect UAE-specific statutory requirements.

Gulf (Kuwait, Bahrain, Qatar)

Core Gulf labour law framework applied across shared statutory provisions including probation caps and notice periods.

Jordan

Issued and operated from Amman, Jordan. Jordanian Labour Law applied for Jordanian market outputs.

Security Measures

Every piece of data that flows through Humanly Intelligent is protected by multiple, overlapping security controls.

TLS 1.3 in Transit

All data transmitted between your browser and our servers uses TLS 1.3 encryption. Connections are rejected if they do not meet this standard.

AES-256 at Rest

Uploaded files (including CV documents) are encrypted at rest using AES-256. Encryption keys are stored separately from the data they protect.

Encrypted Recall Memory

Your Recall memory — the professional context stored across tools — is encrypted per-user with a unique key. No other user can access your stored memory.

Strict Data Tenancy

Every database query is scoped to your account. Multi-tenancy isolation is enforced at the data layer — not just the application layer.

Audit Logging

All administrative actions are logged with timestamp, actor, and change summary. Logs are retained for 90 days and monitored for anomalies.

Rate Limiting

API endpoints are rate-limited per user and per IP to prevent abuse and protect service availability for all users.

Blind AI Inference

We do not log or retain your tool inputs beyond the active session. AI inference calls are ephemeral — the provider processes them and discards them after the response is returned.

Your Rights

Most privacy actions are available immediately from your account settings — no waiting, no forms.

Self-Serve (Instant)

Clear Recall Memory

Delete all stored professional context from Settings → Recall at any time.

Go to Settings →

Delete Account & All Data

Permanently delete your account and all associated data from Settings → Account.

Go to Settings →

Smart Shortlist Transparency

Request a bias-audit report on any shortlisting run — available from the Shortlist workspace.

Go to Shortlist →

Correct Data / Request Audit

Update your name or email in Settings. For output corrections or audit requests, contact our Privacy Desk.

Contact Privacy Desk →
Sub-Processor Register
ProcessorRolePrivacy Terms
ReplitInfrastructure & hostingView Terms
hCaptchaBot protection on sign-in & sign-upView Terms
Email ProviderTransactional email delivery (provider being finalized)
Lemon SqueezyPayment processing & Merchant of RecordView Terms
AnthropicAI language model inferenceView Terms
Plausible AnalyticsPrivacy-first analytics (no cookies, no PII)View Terms
GoogleOAuth sign-in (optional — only if you choose to sign in with Google)View Terms
Responsible Disclosure

If you discover a security vulnerability, please report it responsibly to info@humanlyintelligent.com. We commit to acknowledging receipt within 48 hours and providing a resolution timeline within 14 days.

In the event of a confirmed data breach affecting personal data, we will notify affected users and relevant supervisory authorities in accordance with applicable law — within 72 hours of becoming aware of the breach where required.