Last updated: August 2026
Cayus (Agen, France) is a recruitment service that sources, contacts, and qualifies job candidates on behalf of hiring companies ("clients"). This Privacy Policy explains how we handle personal data belonging to two different groups: our clients, and the candidates we source and contact on a client's behalf. Candidates are not our users, and this policy explains how their data is handled under Article 14 GDPR (see Section 5).
To fill a client's open role, we source publicly available professional profile data (name, current title, employer, tenure, skills, public contact details) through a third-party sourcing platform. We contact a small number of sourced candidates directly. For candidates who respond, we additionally record:
Candidate names and identifying details are not shared with the client until the client has signed engagement terms for that specific role.
Because candidate data is not collected directly from the candidate in the first instance, GDPR Article 14 requires this notice. We process candidate data on the basis of legitimate interest: matching a professional to a specific, named job opening they may not otherwise have heard about. We balance this interest against the candidate's rights as follows:
Candidates can object to this processing or request erasure at any time by emailing privacy@cayus.io, or by replying "opt out" to any message from us.
We do not sell candidate or client personal data.
We use AI tools internally to help draft outreach and structure qualification notes from candidate replies. A person reviews every candidate-facing message and every qualification claim before it is sent or shared with a client. Data processed by our AI tooling provider is governed by their data processing terms and is not used to train their general-purpose models.
We share data with a small number of vetted service providers acting as processors on our behalf, each bound by a data processing agreement:
We describe these by function rather than by brand for competitive reasons; the identity of each provider is available on request to clients and candidates exercising their data rights under Section 12.
Cayus is based in France. Some sub-processors are located outside the European Economic Area (EEA), including in the United States. Where data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
We use TLS 1.2+ in transit, encryption at rest, and role-based access control. In the event of a personal data breach that poses a risk to affected individuals, we will notify the CNIL within 72 hours and affected individuals without undue delay.
Under GDPR, both clients and candidates have the right to:
California residents have equivalent rights under the CCPA, including the right to know, delete, and opt out of sale (we do not sell personal data).
To exercise any right, contact privacy@cayus.io. We respond within 30 days.
The Cayus website does not set cookies. No advertising, analytics, or cross-site tracking. See our Cookie Policy for detail.
The Service is not directed at individuals under 18. We do not knowingly source or contact minors as candidates.
We may update this Privacy Policy. Material changes are notified by email to active clients at least 30 days before taking effect.
Questions about this policy or your data: privacy@cayus.io. EU complaints: CNIL at cnil.fr.