DimeRepublic ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services. Please read this policy carefully. By accessing or using our services, you acknowledge that you have read and understood the practices described herein.
1. Information We Collect
Information You Provide
We collect information that you voluntarily provide to us when you express interest in our services, fill out forms on our website, subscribe to our newsletter, submit inquiries via our contact forms, or communicate with us directly. This includes your name, email address, phone number, company name, job title, billing address, payment information, and any other details you choose to share during the onboarding or engagement process. We also collect information you provide when applying for a position through our recruitment services, including your résumé, employment history, educational background, and professional references.
Information Collected Automatically
When you visit our website, we automatically collect certain information about your device and browsing activity. This includes your IP address, browser type and version, operating system, device type, referring URLs, pages viewed, time spent on each page, clickstream data, and interaction patterns. We collect this information using cookies, server logs, web beacons, and similar tracking technologies to analyze trends, administer the site, and gather demographic information about our user base.
Information from Third Parties
We may receive information about you from third-party sources to supplement our records. This includes background verification services for candidates, credit check agencies for billing purposes, professional networking platforms such as LinkedIn, and publicly available sources. We combine this information with the data you provide to us to improve the accuracy of our records, enhance our ability to match talent with client requirements, and deliver more relevant communications.
2. How We Use Your Information
We use the information we collect for the following specific purposes:
- Service Delivery: To assess your talent needs, identify and present suitable candidates, facilitate interviews, manage placements, and administer payroll and compliance services.
- Communication: To respond to your inquiries, provide customer support, send service-related announcements, and share updates about our offerings, industry insights, and promotional content where permitted.
- Transaction Processing: To process payments, issue invoices, manage billing accounts, and handle refunds and credits in accordance with our payment terms.
- Website Improvement: To analyze usage patterns and trends to optimize our website functionality, content, and user experience.
- Security and Fraud Prevention: To detect, investigate, and prevent fraudulent transactions, unauthorized access, and other illegal activities.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, and enforceable governmental requests, and to enforce our terms and policies.
- Recruitment and Talent Matching: To evaluate candidates, verify qualifications, conduct background checks, and match talent with client requirements.
- Marketing and Analytics: To personalize your experience, deliver targeted content and advertisements, and measure the effectiveness of our marketing campaigns.
3. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law. Our retention periods are as follows:
- Client Data: Retained for the duration of the service agreement plus five years thereafter to comply with tax, accounting, and legal obligations.
- Candidate Data: Retained for two years from the date of collection or last engagement to facilitate future placement opportunities, unless the candidate requests earlier deletion.
- Website Usage Data: Retained in aggregated form for up to 26 months for analytics purposes. Individual IP addresses and device identifiers are retained for no more than 12 months.
- Communication Records: Email correspondence and chat records are retained for three years following the last communication.
- Financial Information: Billing and payment records are retained for seven years as required by tax and financial regulations.
- Marketing Data: Contact information used for marketing purposes is retained until you opt out or unsubscribe, after which it is deleted within 30 days.
When data is no longer required, we securely delete or anonymize it using industry-standard methods to prevent unauthorized access or reconstruction.
4. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data. We are committed to facilitating the exercise of these rights in accordance with applicable data protection laws, including the GDPR (for individuals in the European Economic Area) and the CCPA (for residents of California, USA).
- Right to Access: You have the right to request confirmation of whether we process your personal data and, if so, to obtain a copy of that data along with information about how it is processed.
- Right to Rectification: You have the right to request correction of any inaccurate or incomplete personal data we hold about you. We will make the corrections promptly upon verification.
- Right to Erasure (Right to be Forgotten): Under certain circumstances, you have the right to request the deletion of your personal data. This right applies when the data is no longer necessary for the purpose it was collected, when you withdraw consent, or when you object to processing and there are no overriding legitimate grounds.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your data under certain conditions, such as when you contest the accuracy of the data or when the processing is unlawful but you oppose erasure.
- Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller without hindrance, where processing is based on consent or contract and carried out by automated means.
- Right to Object: You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
- Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Right to Non-Discrimination (CCPA): California residents have the right not to receive discriminatory treatment for exercising their CCPA privacy rights. We will not deny services, charge different prices, or provide a different level of service based on the exercise of these rights.
To exercise any of these rights, please contact us using the information in the Contact section below. We will respond to your request within 30 days, or as otherwise required by applicable law.
5. Data Sharing and Disclosure
We only share your information in limited circumstances and with appropriate safeguards in place:
- Service Providers: We engage trusted third-party vendors to perform services on our behalf, including payment processing (Stripe, PayPal), cloud hosting (AWS, Google Cloud), email delivery (SendGrid), analytics (Google Analytics), CRM management (HubSpot), and recruitment platforms. These providers are contractually bound to process data only as instructed and to maintain appropriate security measures.
- Professional Advisors: We may disclose information to our legal counsel, accountants, insurers, and other professional advisors where necessary to obtain professional advice or manage business risks.
- Business Transfers: In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control.
- Legal Requirements: We may disclose information when required by law, court order, subpoena, or other legal process, or in response to valid requests by public authorities (including tax authorities and law enforcement).
- Protection of Rights: We may disclose information to protect our rights, property, or safety, or the rights, property, or safety of our users, clients, candidates, or others.
- Consent: We may share your information for any other purpose with your explicit consent.
6. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our website and store certain information. These technologies include cookies, web beacons, pixel tags, and local storage. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, some parts of our service may not function properly. For detailed information about the cookies we use, the purposes for which we use them, and how you can manage your preferences, please see our Cookie Policy.
7. International Data Transfers
DimeRepublic operates globally and may transfer your personal data to countries outside your country of residence, including to Pakistan where our principal operations are based, and to the United States where our servers and third-party service providers may be located. When we transfer personal data from the European Economic Area (EEA), Switzerland, or the United Kingdom to countries that have not been deemed to provide an adequate level of data protection by the European Commission, we implement appropriate safeguards to protect your data, including:
- Standard Contractual Clauses (SCCs): We enter into European Commission-approved Standard Contractual Clauses with our service providers and partners to ensure an equivalent level of data protection.
- Data Processing Agreements: We execute comprehensive DPAs that incorporate GDPR requirements with all sub-processors who handle personal data.
- Binding Corporate Rules: Where applicable, we adhere to Binding Corporate Rules for intra-group data transfers.
- Adequacy Decisions: Where the European Commission has determined that a recipient country ensures an adequate level of protection, we rely on that adequacy decision for transfers.
By submitting your personal data to us, you acknowledge that your data may be transferred to and processed in countries that may have different data protection laws than your country of residence. We take all reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy.
8. Children's Privacy
Our services are not directed to individuals under the age of 18, and we do not knowingly collect personal data from children. If we become aware that a child under 18 has provided us with personal data without verifiable parental consent, we will take steps to delete that information promptly. If you believe that a child may have provided us with personal data, please contact us immediately so that we can investigate and take appropriate action.
9. Data Security
We implement a comprehensive set of technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Our security measures include:
- Encryption of personal data at rest using AES-256 and in transit using TLS 1.3 protocols.
- Role-based access controls with multi-factor authentication and the principle of least privilege.
- Regular security assessments, penetration testing, and vulnerability scanning conducted by independent third-party firms.
- Annual employee training on data protection, privacy, and information security best practices.
- Incident response and business continuity plans that are tested and updated on a regular basis.
- Physical security controls at our office premises and data centers, including biometric access controls and 24/7 surveillance.
- Data backup and disaster recovery procedures to ensure data availability and integrity.
10. Third-Party Links
Our website may contain links to third-party websites, plugins, and services that are not owned or controlled by DimeRepublic. We are not responsible for the privacy practices or content of these external sites. We encourage you to review the privacy policies of any third-party websites you visit before providing them with your personal information. This Privacy Policy applies solely to information collected by DimeRepublic.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make material changes, we will notify you by:
- Posting the updated policy on this page and updating the "Last updated" date at the top of this policy.
- Sending a notification email to the primary email address associated with your account (if applicable).
- Displaying a prominent notice on our website prior to the change becoming effective.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our services after any changes to this policy constitutes your acceptance of the revised policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: