Privacy Policy

EWA Candidate Portal & Marketing Website · Effective Date: July 1, 2026 · Version 1.0

1

Introduction

EWA (Employee Workforce Application) is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our Candidate Portal, marketing website (iewa.io), and related services (collectively, the "Services").

By accessing or using our Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with this policy, please do not use our Services.

EWA is operated by EWA FZE, registered at Al Zahia Area – Entrance No. 2 – Ground Floor – Sheikh Mohammed Bin Zayed Rd – Sharjah – United Arab Emirates. For any privacy-related inquiries, please contact our Data Protection Officer at [email protected].

2

Scope of This Policy

This Privacy Policy applies to:

  • The EWA Candidate Portal (mobile web application)
  • The EWA marketing website (iewa.io)
  • All related subdomains, APIs, and services
  • Email communications and marketing materials
  • Any third-party services integrated with EWA

This policy covers all users, including candidates, clients (employers), administrators, and visitors to our marketing website.

3

Data Controller Information

The data controller responsible for processing your personal data is:

  • Company Name: EWA FZE
  • Registered Address: Al Zahia Area – Entrance No. 2 – Ground Floor – Sheikh Mohammed Bin Zayed Rd – Sharjah – United Arab Emirates
  • Company Number: 4309434.01
  • VAT Number: 1043206711000XC

Data Protection Officer (DPO):

  • Email: [email protected]
  • Phone: +971 56 900 7505
  • Address: Al Zahia Area – Entrance No. 2 – Ground Floor – Sheikh Mohammed Bin Zayed Rd – Sharjah – United Arab Emirates
4

Personal Data We Collect

4.1 Information You Provide Directly

When you register for or use our Services, we may collect:

Account Information:

  • Full name (first and last)
  • Email address
  • Phone number
  • Password (encrypted)
  • Profile photo (optional)

Professional Information:

  • Job title and position applied for
  • Employment history and work experience
  • Educational background and qualifications
  • Skills and certifications
  • Curriculum vitae (CV) / résumé
  • Cover letters and application documents

Identity Verification:

  • Government-issued ID (when required by client)
  • Date of birth
  • Nationality / citizenship
  • Passport or national ID number

Financial Information (for salary requests):

  • Current salary information (if visible setting enabled)
  • Salary expectations
  • Bank account details (for payroll processing, if hired)

Communication Data:

  • Messages sent through the platform
  • Email correspondence
  • Support tickets and inquiries

4.2 Information Collected Automatically

Device & Technical Data:

  • IP address and geolocation data
  • Device type, model, and operating system
  • Browser type and version
  • Screen resolution and language settings
  • Mobile network information

Usage Data:

  • Login times and session duration
  • Pages visited and features used
  • Click patterns and navigation paths
  • Attendance check-in/check-out records
  • Biometric verification logs (fingerprint/location)

Location Data:

  • GPS coordinates (with consent, for attendance verification)
  • Geofencing radius compliance data
  • Approximate location from IP address

Cookies & Tracking Technologies:

  • Session cookies (essential for login)
  • Preference cookies (language, theme)
  • Analytics cookies (Google Analytics, Mixpanel)
  • Marketing cookies (Meta Pixel, LinkedIn Insight)

4.3 Information from Third Parties

We may receive information about you from:

  • Your employer/client company (job assignment details, company policies)
  • Recruitment agencies and job boards (LinkedIn, Indeed)
  • Background check providers (with your consent)
  • Professional social networks (when you connect your profile)
  • Publicly available sources (professional directories, company websites)
5

How We Use Your Personal Data

We process your personal data for the following purposes and legal bases:

PurposeLegal BasisData Categories
Account creation & managementContract performanceAccount, Identity
Candidate recruitment & placementContract performanceProfessional, Account
Attendance tracking & verificationContract performance / Legal obligationLocation, Biometric, Usage
Leave & permission request processingContract performanceAccount, Communication
Salary & compensation managementContract performance / ConsentFinancial, Professional
Platform security & fraud preventionLegitimate interest / Legal obligationTechnical, Usage, Location
Customer support & communicationContract performanceCommunication, Account
Service improvement & analyticsLegitimate interest / ConsentUsage, Technical
Marketing & promotional communicationsConsentAccount, Communication
Legal compliance & dispute resolutionLegal obligationAll categories
6

Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), we rely on the following legal bases:

6.1 Contract Performance (Article 6(1)(b)) — Processing necessary to fulfill our contract with you or to take steps at your request before entering into a contract. This includes account creation, recruitment services, attendance tracking, and request processing.

6.2 Legal Obligation (Article 6(1)(c)) — Processing required to comply with applicable laws, including labor laws, tax regulations, and anti-fraud measures.

6.3 Legitimate Interests (Article 6(1)(f)) — Processing necessary for our legitimate business interests, provided these interests do not override your fundamental rights. This includes platform security, service improvement, and fraud prevention.

6.4 Consent (Article 6(1)(a)) — Processing based on your explicit consent, which you can withdraw at any time. This applies to:

  • Marketing communications
  • Location tracking for attendance
  • Biometric data processing
  • Salary visibility settings
  • Cookie preferences (non-essential)

6.5 Vital Interests (Article 6(1)(d)) — Processing necessary to protect your vital interests or those of another person, applicable in emergency situations.

7

How We Share Your Data

We do not sell your personal data. We may share your data with the following categories of recipients:

7.1 Client Companies (Employers) — When you apply for or are assigned to a position, your profile data, CV, and application materials are shared with the hiring company. The scope of sharing is controlled by your privacy settings and the client's data processing agreement.

7.2 Service Providers (Data Processors) — We engage third-party providers to support our Services:

  • Cloud Hosting: AWS / Google Cloud / Azure (infrastructure)
  • Authentication: Auth0 / Firebase Auth (secure login)
  • Analytics: Google Analytics, Mixpanel (usage insights)
  • Communication: SendGrid, Twilio (email/SMS)
  • Payment: Stripe, PayPal (if applicable)
  • AI/ML Services: resume parsing, matching

All processors are bound by Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs) where required.

7.3 Legal & Regulatory Authorities — We may disclose data when required by law, court order, or governmental request, including tax authorities, labor inspectorates, law enforcement agencies, and regulatory bodies.

7.4 Business Transfers — In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity, subject to the same privacy protections.

7.5 Professional Advisors — We may share data with legal, accounting, and insurance professionals bound by confidentiality obligations.

8

International Data Transfers

EWA operates globally, and your data may be transferred to and processed in countries outside your country of residence, including:

  • United States (cloud hosting infrastructure)
  • European Union (data processing centers)
  • United Kingdom (post-Brexit data arrangements)
  • Middle East & North Africa (client operations)

For transfers outside the European Economic Area (EEA), we implement appropriate safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for recognized countries
  • Binding Corporate Rules (BCRs) for intra-group transfers
  • Additional technical measures (encryption, pseudonymization)

For UK residents, we comply with the UK GDPR and Data Protection Act 2018. For transfers to the US, we adhere to the EU-US Data Privacy Framework principles where applicable.

9

Data Retention Periods

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law:

  • Account Data: Retained while your account is active + 2 years after closure
  • Application Data: 12 months after application process completion (EU) / 3 years (US)
  • Profile Data (with consent): 2 years from last activity (extendable with renewed consent)
  • Attendance Records: 3 years (labor law compliance)
  • Financial/Payroll Data: 7 years (tax law compliance)
  • Communication Logs: 2 years
  • Server Logs & Analytics: 6 months
  • Deleted Account Backups: 30 days (then permanently erased)

After the retention period expires, your data is either permanently deleted using secure erasure methods, anonymized for statistical purposes (no longer personally identifiable), or archived in encrypted form for legal hold purposes only.

You may request early deletion of your data at any time by contacting [email protected].

10

Data Security Measures

We implement comprehensive technical and organizational measures to protect your data:

10.1 Technical Measures

  • Encryption at Rest: AES-256 encryption for all stored data
  • Encryption in Transit: TLS 1.3 for all data transmissions
  • Password Security: bcrypt hashing with salt (never stored in plain text)
  • Multi-Factor Authentication (MFA): Optional for all accounts
  • API Security: OAuth 2.0 / JWT tokens with short expiry
  • Biometric Data: Stored as encrypted templates (not raw images)
  • Regular Security Audits: Penetration testing (quarterly)
  • Vulnerability Scanning: Automated daily scans
  • DDoS Protection: Cloudflare / AWS Shield

10.2 Organizational Measures

  • Role-Based Access Control (RBAC): Minimum privilege principle
  • Employee Training: Annual data protection training
  • Confidentiality Agreements: All staff and contractors
  • Incident Response Plan: 72-hour breach notification protocol
  • Data Protection Impact Assessments (DPIAs): For high-risk processing
  • Regular Policy Reviews: Quarterly updates to security policies

10.3 Physical Security

  • SOC 2 Type II certified data centers
  • 24/7 surveillance and access controls
  • Redundant power and cooling systems
  • Fire suppression and environmental controls

Despite these measures, no internet transmission is 100% secure. We encourage you to protect your account with a strong, unique password and enable MFA.

11

Your Data Protection Rights

Depending on your location, you have the following rights regarding your personal data:

11.1 Right to Access (Article 15 GDPR) — You have the right to request a copy of all personal data we hold about you, free of charge, within one month.

11.2 Right to Rectification (Article 16 GDPR) — You may request correction of inaccurate or incomplete data at any time through your profile settings or by contacting us.

11.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR) — You may request deletion of your data when:

  • The data is no longer necessary for its original purpose
  • You withdraw consent (where consent was the legal basis)
  • You object to processing and we have no overriding legitimate grounds
  • The data was unlawfully processed
  • Deletion is required by law
Note: We may retain certain data where required by law or for legal claims.

11.4 Right to Restrict Processing (Article 18 GDPR) — You may request that we limit processing of your data while we verify its accuracy or assess your objection.

11.5 Right to Data Portability (Article 20 GDPR) — You may request your data in a structured, machine-readable format (JSON/CSV) and transfer it to another service.

11.6 Right to Object (Article 21 GDPR) — You may object to processing based on legitimate interests or for direct marketing purposes at any time.

11.7 Right to Withdraw Consent — Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

11.8 Right to Lodge a Complaint — You have the right to complain to your local data protection authority:

  • EU: European Data Protection Board (edpb.europa.eu)
  • UK: Information Commissioner's Office (ico.org.uk)
  • US: State Attorney General offices
  • UAE: Dubai Data Protection Office

11.9 Rights Under Other Jurisdictions

  • California (CPRA): Right to know, delete, correct, opt-out of sale/sharing
  • Brazil (LGPD): Similar rights to GDPR
  • PIPL (China): Rights to access, copy, correct, delete, and portability
  • KVKK (Turkey): Rights to information, access, correction, deletion
12

Cookies & Tracking Technologies

12.1 Essential Cookies (Strictly Necessary) — Required for the platform to function and cannot be disabled:

  • Session cookies (maintain login state)
  • CSRF tokens (prevent cross-site request forgery)
  • Security cookies (detect suspicious activity)
  • Load balancing cookies

12.2 Preference Cookies

  • Language selection (EN/AR)
  • Theme/display preferences
  • Remember me functionality

12.3 Analytics Cookies

  • Google Analytics (_ga, _gid): Usage patterns and demographics
  • Mixpanel: Feature engagement tracking
  • Hotjar: Session recordings and heatmaps (anonymized)

12.4 Marketing Cookies

  • Meta Pixel: Ad conversion tracking
  • LinkedIn Insight Tag: B2B marketing analytics
  • Google Ads: Remarketing campaigns

12.5 Cookie Management — You can manage your cookie preferences through:

  • Browser settings (block all or specific cookies)
  • Our Cookie Consent Banner (accessible anytime)
  • Individual opt-out mechanisms: Google Analytics · Meta · LinkedIn

For more information, please see our Cookie Policy at iewa.io/cookies.

13

Children's Privacy

Our Services are not intended for children under the age of 16 (or the minimum age of employment in your jurisdiction). We do not knowingly collect personal data from children under 16.

If we discover that we have inadvertently collected data from a child under 16, we will:

  • Immediately delete the account and all associated data
  • Notify the parent/guardian where contact information is available
  • Report to relevant authorities if required by law

If you believe a child under 16 has provided us with personal data, please contact us immediately at [email protected].

14

AI & Automated Decision-Making

14.1 Use of Artificial Intelligence — EWA may use AI and machine learning technologies for:

  • Resume parsing and skill extraction
  • Candidate-to-job matching recommendations
  • Attendance pattern analysis
  • Fraud detection and security monitoring

14.2 Human OversightImportant: No hiring decisions are made solely by automated means. All AI outputs are reviewed by human recruiters and hiring managers. You have the right to:

  • Request human review of any AI-assisted decision
  • Contest automated recommendations
  • Obtain meaningful information about the logic involved

14.3 Bias Prevention — We regularly audit our AI systems to ensure:

  • No discrimination based on age, gender, ethnicity, religion, or disability
  • Fair and transparent algorithms
  • Regular bias testing and mitigation
  • Compliance with EU AI Act requirements (where applicable)
15

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or services, new legal or regulatory requirements, feedback from users and stakeholders, or technological advancements.

We will notify you of material changes by:

  • Email notification to your registered address
  • In-app notification banner
  • Updated effective date at the top of this policy
  • Prominent notice on our website

We encourage you to review this policy periodically. Continued use of our Services after changes constitutes acceptance of the revised policy. Previous versions of this policy are archived and available upon request.

16

Contact Us

Data Protection Officer

  • Email: [email protected]
  • Phone: +971 56 900 7505
  • Address: Al Zahia Area – Entrance No. 2 – Ground Floor – Sheikh Mohammed Bin Zayed Rd – Sharjah – United Arab Emirates
  • Hours: Sunday – Thursday, 9:00 AM – 6:00 PM GST

For urgent matters (data breaches): [email protected] — response within 24 hours

You also have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not handled your data in accordance with applicable law.

A

Appendix A: Glossary

  • "Personal Data" — Any information relating to an identified or identifiable natural person
  • "Processing" — Any operation performed on personal data (collection, storage, use, deletion)
  • "Data Controller" — The entity that determines the purposes and means of processing
  • "Data Processor" — An entity that processes data on behalf of the controller
  • "Data Subject" — The individual whose personal data is being processed
  • "Consent" — Freely given, specific, informed, and unambiguous indication of wishes
  • "Biometric Data" — Personal data resulting from specific technical processing relating to physical, physiological, or behavioral characteristics
  • "Pseudonymization" — Processing personal data in such a manner that the data can no longer be attributed to a specific data subject without additional information
  • "Data Breach" — A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data

Document Version: 1.0 | Last Updated: July 1, 2026 | Next Review: January 1, 2027

Questions About This Policy?

If you have any questions or concerns about our Privacy Policy, please contact us at:

Contact Us