hamrr
Workflows Security Docs
Sign in Book a walkthrough
Workflows Security Docs Sign in
Legal

Privacy Policy

Last updated 20 August 2026

Hamrr is a recruiting assistant that connects to the systems a recruiter already uses — their applicant tracking system, mailbox and calendar — reads what is there, and acts on it. This policy explains what we collect, why, where it lives, and what you and the candidates on your desk can ask us to do about it.

  1. Who we are
  2. Two different roles we play
  3. What we collect
  4. What we use it for
  5. Our legal bases
  6. AI processing
  7. Who else processes your data
  8. Where your data is stored
  9. How long we keep it
  10. Your rights
  11. If you are a candidate
  12. Security
  13. Cookies
  14. Changes and contact

1. Who we are

Hamrr is a product of M3 Labs Ltd, a company registered in England and Wales. In this policy, "Hamrr", "we" and "us" mean M3 Labs Ltd.

You can reach us about anything in this policy at support@hamrr.ai.

2. Two different roles we play

This distinction matters, because it decides who you go to with a request.

  • For your own account, we are the controller. Your name, email, settings, subscription and usage are ours to answer for.
  • For candidate and client data, we are a processor and you are the controller. The people in your pipeline are on your desk, not ours. We hold their information because you asked us to work on it, and we act on your instructions.

So a candidate asking what is held about them, or asking for it to be deleted, is asking the recruiter who holds their file — not us. We will help you answer, and we will pass on any request that reaches us directly.

3. What we collect

Account information

Your name, email address, and the sign-in identity from the provider you chose (Microsoft, Google, or email and password). Your settings, including which categories of work you have allowed Hamrr to carry out unattended.

Data from the systems you connect

Only from systems you explicitly connect, and only while they stay connected:

  • Your applicant tracking system — jobs, candidates, applications, stages, notes and contact details.
  • Your mailbox — messages between you and the people on your desk, so Hamrr can see what has already been said before it drafts a reply.
  • Your calendar — free/busy times and interview events, so it can offer slots that exist.
  • Messaging channels — Slack, Microsoft Teams or WhatsApp, if you choose to talk to Hamrr there.

Candidate information

Names, contact details, CVs, work history, notes, interview records and the outcome of each conversation. Where you upload a CV, we also generate and store a redacted copy with identifying details removed, so a client-facing version exists.

Usage and billing

Records of what ran, when, and what it cost to run — including the actions Hamrr took on your behalf. Payment card details are handled by Stripe and never reach our servers.

4. What we use it for

  • Running the product: reading your desk, working out what needs you, drafting the messages, and sending them where you have allowed that.
  • Keeping a record of what was done on your behalf, so you can see and audit it.
  • Billing, support, security and fraud prevention.
  • Diagnosing faults and improving the product.
We do not sell your data, and we do not use candidate or client data to advertise to you or anyone else.

5. Our legal bases

WhatBasis
Providing the service to youPerformance of our contract with you
Billing and account administrationContract, and our legal obligations
Security, fault diagnosis, product improvementOur legitimate interests in running a reliable, secure service
Processing candidate and client dataOn your documented instructions, under your own lawful basis as controller

6. AI processing

Hamrr uses large language models to read context and draft text. These run on Amazon Bedrock within our own cloud account. Content sent to Bedrock is not used by the model provider to train their models.

Model output is a draft. Where a category of work is set to require your approval, nothing is sent until you approve it. Where you have switched a category to run unattended, Hamrr acts without asking and records exactly what it did.

7. Who else processes your data

We use a small number of providers to run the service. Each processes data only to provide their part of it:

ProviderWhat for
Amazon Web ServicesHosting, storage, database, and AI models via Amazon Bedrock
StripeSubscription payments
MicrosoftSign-in, and mail, calendar and Teams access where you connect them
GoogleSign-in, and mail and calendar access where you connect them
LinkupPublic web search used when researching a candidate profile
Your ATS providerThe system you chose to connect; data flows both ways at your instruction

We may also disclose information where the law requires it, or to establish or defend legal claims. If our business is sold or reorganised, data may transfer as part of that — we will tell you before it does.

8. Where your data is stored

Your workspace, including candidate records and CVs, is stored in the United Kingdom (Amazon Web Services, London region). Each customer's workspace is held separately.

Some of our providers operate internationally and may process limited data outside the UK. Where that happens, it is covered by the safeguards those providers offer under UK data protection law, including the International Data Transfer Agreement or Addendum.

9. How long we keep it

  • While your account is open, we keep your workspace so the product works — the history is what tells Hamrr who has gone quiet and what has already been said.
  • When you close your account, we delete your workspace within 30 days, except where we must keep something longer by law.
  • Billing records are kept for six years, as UK tax law requires.
  • You can ask us to delete specific records at any time, and we will, unless doing so would break something you still rely on — in which case we will tell you.

10. Your rights

Under UK data protection law you can ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct anything that is wrong;
  • delete it, or restrict what we do with it;
  • provide it in a portable form;
  • stop processing it where we rely on legitimate interests.

Write to support@hamrr.ai and we will respond within one month. If you are unhappy with how we have handled it, you can complain to the UK Information Commissioner's Office at ico.org.uk.

11. If you are a candidate

If a recruiter is using Hamrr to work on your application, your information is held on their instructions, not ours. They decide what is held and for how long, so requests about your data should go to the recruitment agency you are dealing with.

If you contact us instead, we will pass your request on to them promptly and tell you we have done so.

12. Security

  • Data is encrypted in transit and at rest.
  • Credentials for the systems you connect are encrypted separately, and are only decrypted at the moment they are used.
  • Each customer's workspace is isolated from every other.
  • Access by our staff is limited to what is needed to run and support the service.

No system is perfectly secure. If a breach affects your data, we will tell you and the Information Commissioner's Office where the law requires it.

13. Cookies

We use only the cookies and local storage needed to keep you signed in and remember your settings. We do not use advertising cookies or third-party tracking on this website.

14. Changes and contact

If we change this policy materially, we will update the date at the top and tell account holders by email before the change takes effect.

Questions, requests or complaints: support@hamrr.ai.

© 2026 Hamrr Ltd · Registered in England & Wales Documentation Security Privacy Terms support@hamrr.ai