This Candidate Privacy Notice explains how Persona collects, uses, shares, transfers, stores, and retains personal data when you create a candidate account, submit an application, opt in to be considered for future opportunities, communicate with Persona, or otherwise use the candidate portal or related recruiting workflows.
This Notice also applies, where relevant, to reference contacts and other third-party data subjects whose personal data is provided to Persona in connection with a candidate's application or profile.
If Persona offers optional AI Task Services through the candidate portal, additional task-specific privacy terms may apply to the processing of task-related personal data. Additional category-level information about Persona's AI-assisted systems may be available in the Persona AI Transparency and Human Review Notice. If Persona publishes an AI Task Services privacy supplement for a specific workflow, that supplement controls for that workflow to the extent of any conflict.
1. Controller and scope
For the activities described in this Notice, the data controller is Psychometric, Inc. d/b/a Persona. If applicable law requires Persona to designate an EEA or UK representative, Persona will make that representative's contact details available here or otherwise as required by law.
2. Categories of personal data we collect
Depending on how you interact with Persona, Persona may collect:
Contact and profile information, such as your name, email address, phone number, location, time zone, language, and profile preferences.
Professional, education, and application information, such as your resume or CV, work history, education, skills, certifications, portfolio links, languages, compensation expectations, work preferences, work authorization information where relevant, availability, and other information you choose to provide.
Screening and recruiting information, such as interview notes, scheduling information, communications, assessment results, internal evaluations, internal tags, internal rankings, match signals, reference information where permitted, recruiting workflow status, and client-submission history.
Reference-contact and third-party data, such as names, contact information, professional relationship to the candidate, questionnaire responses, reference feedback, related notes, and communications metadata provided by or about reference contacts or other third parties.
Communications and engagement data, where available, such as email delivery, open, click, bounce, unsubscribe, reply, reminder status, and other interaction metadata associated with account, recruiting, future-opportunity, or related communications.
Automated processing and integrity data, such as match signals, rankings, fraud or integrity signals, routing outcomes, prioritization outcomes, and other internally generated outputs used to support recruiting, security, or operational decisions.
Technical and usage information, such as IP address, browser and device information, account and authentication logs, cookie identifiers, portal activity, network information, diagnostics, and security-event data.
Uploaded files and supporting materials, such as resumes, cover letters, work samples, portfolio documents, and attachments.
Compliance and verification information, where lawful and necessary for a specific role or engagement, such as work authorization, identity verification, background-check-related information, or other compliance information.
Please do not provide sensitive or special-category personal data unless Persona specifically asks for it for a lawful and necessary purpose. If you provide unnecessary sensitive data, Persona may ignore, redact, segregate, or delete it.
3. Sources of personal data
Persona may collect personal data:
- directly from you, through account creation, applications, uploads, communications, profile updates, interviews, scheduling, assessments, and portal activity;
- from referrals, reference sources, or client introductions, where permitted by law;
- from publicly available professional sources you choose to make public, where permitted by law;
- from service providers and tools used to operate recruiting workflows; and
- during Persona's transition to apply.personatalent.com, from legacy intake tools such as online forms, documents, spreadsheets, and similar systems previously used to collect candidate information.
Persona may combine information from multiple sources to create and maintain a unified candidate profile and recruiting record.
Reference contacts and other third-party data subjects
Candidates may provide Persona with personal data about reference contacts and other third parties, such as names, contact details, relationship information, and other context relevant to a recruiting process. Persona may contact those individuals, collect responses or feedback they choose to provide, and process that information as part of evaluating a candidate or documenting a recruiting decision. Candidates are responsible for informing reference contacts and other third parties that Persona may contact them and may process their personal data as described in this Notice.
4. How Persona uses personal data
Persona may use personal data to:
- create and administer your candidate account;
- process and evaluate applications for current opportunities;
- maintain your profile for future opportunities if you choose to opt in;
- identify, assess, and communicate with you about current and future opportunities;
- contact and evaluate reference contacts and other third-party data subjects in connection with candidate evaluation;
- share relevant profile information with specific client companies in connection with specific opportunities;
- operate, secure, monitor, troubleshoot, and improve the candidate portal and recruiting workflows;
- track and manage service-related and optional communications, including delivery, response, engagement, and preference data where available;
- develop, test, validate, monitor, deploy, and improve automated recruiting, fraud-detection, matching, ranking, evaluation, machine learning, artificial intelligence, and related systems and services, subject to applicable law;
- prevent fraud, abuse, duplicate submissions, and security incidents; and
- comply with legal obligations and establish, exercise, or defend legal claims.
Communications categories
Persona may send service-related communications, such as account, application, interview, assessment, reference, verification, security, fraud-prevention, payment, and legal/compliance notices, as reasonably necessary to provide or protect the Services.
Optional future-opportunity, newsletter, promotional, or optional AI Task Services marketing communications will be sent only as permitted by applicable law and may be opted out of where applicable.
5. Legal bases
Where required by applicable law, Persona relies on one or more of the following legal bases, depending on the context:
Steps taken at your request before entering into a contract, and performance of a contract, for account creation, application handling, and recruiting services you request.
Legitimate interests, in operating and improving a recruiting and staffing service, contacting and evaluating reference contacts and other third-party data subjects, maintaining candidate relationships, securing systems, tracking and managing service-related and optional communications, preventing fraud, managing recruiting operations, and developing, testing, validating, monitoring, deploying, and improving automated recruiting, fraud-detection, matching, ranking, evaluation, machine learning, artificial intelligence, and related systems and services, where permitted by law and not overridden by your rights and freedoms.
Consent, where required by law or where Persona chooses to rely on it, including optional consideration for future opportunities in certain jurisdictions and optional promotional or newsletter communications.
Compliance with legal obligations, where Persona must retain, disclose, or process information to comply with applicable law.
When Persona contacts and evaluates reference contacts or other third-party data subjects, Persona generally relies on its legitimate interests in assessing candidate qualifications, protecting clients, preventing fraud, documenting recruiting decisions, and maintaining the integrity of recruiting workflows, except where another legal basis applies.
If Persona processes sensitive or special-category data for a specific role, Persona will do so only where permitted by law and, where required, on the basis of explicit consent or another valid legal basis.
6. How Persona shares personal data
Persona may share personal data with:
Specific client companies, when reasonably necessary in connection with specific current or prospective opportunities that match your application, profile, qualifications, or stated preferences.
Service providers and subprocessors, that process personal data on Persona's behalf to provide database infrastructure, cloud hosting, file storage, content delivery, security, communications, email delivery, analytics, scheduling, authentication, applicant-tracking, and related services.
Affiliates and transaction counterparties, in connection with a merger, acquisition, investment, financing, reorganization, sale of assets, or similar corporate transaction.
Professional advisers, insurers, auditors, and investigators, where reasonably necessary for legal, compliance, insurance, security, or financial purposes.
Authorities and other third parties, where required by law or reasonably necessary to protect rights, safety, security, systems, property, or legal claims.
Persona does not operate a public or client-browsable directory of candidate profiles.
Persona shares candidate information with client companies only in connection with specific opportunities. Where required by law or by Persona's process, Persona will confirm your interest before sharing your information with a client company. In other cases, if you have applied for a role or opted in to be considered for future opportunities, Persona may share relevant profile information with specific client companies as reasonably necessary to provide the recruiting service you requested.
Reference responses and related recruiting evaluations may also be shared internally within Persona and, where reasonably necessary and permitted by law, with service providers or specific client companies involved in the relevant opportunity, subject to confidentiality and security controls.
Once a client company receives your information in connection with an opportunity, that client company may process the information under its own privacy practices and legal obligations, and may act as an independent controller or business for its own recruiting or employment purposes.
7. International transfers
Persona operates from the United States and may use service providers and client systems that process personal data in the United States and other countries. As a result, your personal data may be transferred to and processed outside your home jurisdiction.
Where required by applicable law, Persona uses appropriate safeguards for international transfers, such as contractual transfer clauses, recognized transfer frameworks, or other lawful transfer mechanisms. You may request additional information about relevant transfer safeguards by contacting Persona.
8. Data retention
Persona retains personal data only for as long as reasonably necessary for the purposes described in this Notice, subject to applicable law, security requirements, fraud-prevention needs, and legal claims.
For purposes of this section, "last meaningful contact" includes a login, profile update, application, response to Persona outreach, interview or assessment participation, scheduling activity, an affirmative renewal, or another clear indication that you want Persona to continue considering you for opportunities.
Unless a narrower legal, payment, tax, or compliance rule applies, assessment results, interview notes, reference responses, internal evaluation data, rejection-related communications, and related engagement or interaction metadata are treated as part of the associated candidate application or profile record and follow the same retention logic described in this Section.
Where permitted by applicable law, Persona may also use such data in anonymized or aggregated form for analytics, service improvement, benchmarking, reporting, product development, model development, model evaluation, fraud prevention, and business planning.
Reference-contact data and related responses may be retained as part of the associated candidate record for the same period as the related application or profile, plus any additional period reasonably necessary for legal obligations, legal claims, fraud prevention, security, audit integrity, or ordinary backup retention.
8.1 Application-only records
If you apply for a specific role and do not opt in to be considered for future opportunities, Persona will retain your identifiable application record for at least 12 months after the later of:
- the closure of the relevant role or recruitment process; or
- Persona's last meaningful contact with you about that role.
Once the record is no longer needed for day-to-day recruiting operations, Persona may move it from active recruiting systems into a restricted-access compliance and claims archive.
Archived application-only records will not be used for general candidate sourcing, future-opportunity matching, future-opportunity outreach, or client submission unless you later opt in or another lawful basis applies.
Absent a legal hold, pending claim, regulatory inquiry, fraud investigation, security incident, or other lawful need for longer retention, Persona will not ordinarily retain archived application-only records beyond 5 years after the closure of the relevant recruitment process.
At the end of the applicable retention period, Persona will delete or irreversibly anonymize the data, subject to ordinary backup-overwrite cycles and minimal suppression records retained to honor deletion, opt-out, objection, and do-not-contact requests.
8.2 Candidate profiles for future opportunities
If you opt in to be considered for future opportunities, Persona may retain your identifiable candidate profile while it remains active.
There is no fixed outer calendar limit for an active candidate profile. Retention continues only while the ongoing candidate relationship remains active and the data remains reasonably necessary for recruiting and future-opportunity purposes.
A candidate profile is considered active when there has been last meaningful contact within the prior 24 months. Each affirmative reconfirmation or other last meaningful contact refreshes that 24-month activity period.
If a candidate profile has no last meaningful contact for 24 months, Persona may contact you to ask whether you would like to remain on file for future opportunities. If you do not affirmatively reconfirm within 30 days, Persona will delete or irreversibly anonymize the searchable profile, except to the extent retention remains necessary for legal obligations, legal claims and evidence preservation, fraud prevention or security, audit integrity, ordinary backup retention, or suppression records needed to honor your privacy choices.
8.3 Deletion requests; withdrawal; account closure
You may request deletion, withdraw a consent-based request, or close your account at any time. Persona will delete or irreversibly anonymize your personal data within a reasonable period, except to the extent retention is necessary for legal obligations, security, fraud prevention, suppression records, restricted-access archival purposes, backups, or legal claims.
Deleted data may remain in secure backups for a limited period until overwritten in the ordinary backup cycle.
8.4 Anonymized, aggregated, and suppression data
Persona may retain anonymized or aggregated data indefinitely for analytics, service improvement, benchmarking, reporting, product development, fraud prevention, and business planning.
Persona may retain minimal suppression information, such as a hashed email address or similar identifier, indefinitely for the limited purpose of honoring deletion, opt-out, objection, and do-not-contact requests and preventing unwanted re-import or re-contact.
9. Your rights
Depending on your location and applicable law, you may have rights to:
- access your personal data;
- correct or update inaccurate personal data;
- delete your personal data;
- restrict or object to certain processing;
- withdraw consent where consent is the legal basis;
- receive a portable copy of certain data; and
- complain to a regulator or supervisory authority.
Reference contacts and other third-party data subjects may also have applicable rights with respect to the personal data Persona processes about them, depending on their location and applicable law.
Automated processing and human review
Persona may use automated tools and AI-assisted systems for resume parsing, duplicate detection, fraud and integrity checks, application routing, profile matching, assessment scoring support, prioritization, scheduling, and other quality or risk flags.
Persona does not make final decisions that produce legal or similarly significant effects solely by automated means where prohibited by applicable law.
Where applicable, you may request human review or additional information about an AI-assisted decision by contacting privacy@personatalent.com or using any in-product method Persona makes available. Persona will respond to such requests within the timeframe required by applicable law. Additional category-level information about Persona's AI-assisted systems may be made available in Persona's AI Transparency and Human Review Notice.
10. How to exercise your rights
To exercise privacy rights, request deletion, withdraw consent, object to certain processing, or ask a privacy question, contact Persona at privacy@personatalent.com.
Persona may take reasonable steps to verify your identity before fulfilling certain requests. If applicable law provides a right to appeal a decision on a privacy request, Persona will provide appeal instructions where required.
If account tools are available in the candidate portal, you may also use those tools to update certain information or manage certain settings.
Reference contacts and other third-party data subjects may also use this contact information to exercise applicable rights or ask questions about how Persona processes their personal data.
11. Cookies and similar technologies
Persona may use cookies, pixels, local storage, SDKs, and similar technologies for authentication, security, fraud prevention, preferences, analytics, performance, and portal functionality.
Where required by law, Persona will seek consent before using non-essential cookies or similar technologies. You can manage cookies through your browser settings and, where available, Persona's cookie or consent-management tools.
12. Security
Persona uses reasonable administrative, technical, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. No system or method of transmission or storage is completely secure.
13. Children
The candidate portal is not intended for individuals under 18 years old, and Persona does not knowingly collect personal data from children through the candidate portal.
14. Changes to this Privacy Notice
Persona may update this Privacy Notice from time to time. If changes are material, Persona will provide notice as required by applicable law. The Effective Date above indicates when the current version took effect.