Candidates should read the Candidate Privacy Notice, which is written for them. Region-specific disclosures are in the EU / UK / Swiss, United States and India supplements, which apply in addition to this policy.
This policy explains how Axion Connect (Registered office address — to be confirmed) handles personal data in connection with the HR Assist platform. It covers two situations that the law treats differently:
- Data about our customers' users (recruiters, hiring managers, administrators). Here we are the controller (GDPR), business (California) or Data Fiduciary (India).
- Data about candidates, which our customers enter into the platform or collect through it. Here the customer is the controller and we are its processor, acting on its instructions under our Data Processing Agreement. This policy describes that processing so it is transparent; the customer's own notice governs its purposes.
1. Data we process about workspace users
| Data | Source | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Name, work email, password hash or identity-provider ID, role | You, or your administrator | Provide the account, secure it, send service email | Contract (Art. 6(1)(b)) |
| Sign-in events, IP address, user agent, failed attempts | Your device | Security, rate limiting, abuse prevention | Legitimate interest (Art. 6(1)(f)) |
| Working hours, calendar connection, mailbox connection | You, via OAuth | Scheduling, sending mail from your own account | Contract; consent for the OAuth scopes |
| Activity in the workspace (records created, scores changed, exports) | Your use | Analytics for your workspace's administrators, audit | Legitimate interest |
| Acceptance records (statements accepted, version, time, IP, user agent) | You, at sign-up and when documents change | Evidence of agreement; answering a request or audit | Legal obligation; legitimate interest |
| Billing contact and invoices | Your administrator | Charge for the Service, tax records | Contract; legal obligation |
| Support messages | You | Answer you | Contract |
We send no marketing email and run no product analytics that identify you. There is therefore no marketing or analytics consent to ask for; if that changes, we will ask first and record the answer separately.
2. Data we process about candidates, on our customers' behalf
| Data | Where it comes from | What the platform does with it |
|---|---|---|
| Name, email, phone, résumé and its parsed contents (skills, experience, education) | Uploaded by the customer or submitted by the candidate | Stored; parsed by an AI model; matched to job descriptions to produce a fitment score |
| Interview recordings and transcripts | The customer's Microsoft 365 / Google meeting, with the participants' knowledge | Transcribed by a speech-recognition provider; summarised and scored by an AI model; stored with the candidate record |
| Coding-test submissions, every draft, and browser activity in the test room | The candidate, in the test room | Executed in a sandbox to judge the answer; stored for the customer's review |
| Webcam still frames, short audio clips, screenshots taken at flagged moments during a proctored test | The candidate's device, only after the candidate's explicit consent | Stored as evidence for a human reviewer; face geometry is analysed on the candidate's own device and never leaves it |
| Messages exchanged by email or WhatsApp | The customer and the candidate | Delivered and threaded; AI may draft replies which are always marked as such |
| Questionnaire answers (joining-risk form) | The candidate | Scored to advise the customer on offer risk |
| Interview outcomes and the customer's notes | The customer | Stored; used to show the customer how its own scores relate to its own outcomes |
| Proctoring consent records (statements ticked, version, time, IP, user agent) | The candidate, on the test's start screen | Kept with the test as evidence of consent |
The customer decides why each of these is collected. We process them only to provide the Service, to keep it secure, and as the customer instructs.
3. Sensitive and biometric data
Webcam proctoring analyses the candidate's face on their own device to check presence and attention. Under the GDPR (Art. 4(14), Art. 9) that analysis is processing of biometric data, and under the CCPA/CPRA it is sensitive personal information; under India's DPDP Act it is personal data requiring specific, informed consent, and under the IT (SPDI) Rules 2011 it is sensitive personal data. For that reason:
- proctoring never starts until the candidate ticks each specific statement in the test room, and the statements, their version and time are recorded;
- only still images at flagged moments are stored — never a video stream — and only when the customer has enabled evidence capture;
- no face template is stored; the on-device analysis is discarded when the sitting ends;
- the platform does not infer emotions, and its scores do not use emotion recognition (EU AI Act Art. 5(1)(f)).
The customer must not enable proctoring for candidates in a jurisdiction where it has not established a lawful basis for biometric processing (for example Illinois under BIPA).
4. Automated decision-making
AI scores, transcripts and proctoring signals are decision support. The platform is built so that a person reviews them before any decision, and it does not reject a candidate on its own. Candidates can ask the customer for a human review of any decision assisted by the platform (GDPR Art. 22; CPRA automated decision-making rules; DPDP §11–§13). Where the law requires, the customer must tell candidates before an automated tool is used in their assessment. AI output is labelled as such wherever it appears in the Service.
5. Sub-processors and international transfers
We use the service providers listed on the Sub-processors page — hosting, authentication, AI models, speech recognition, code execution, email and messaging. Several are in the United States and other countries. Transfers from the EEA, UK and Switzerland rely on the European Commission's Standard Contractual Clauses (2021/914) with the UK Addendum, or on the EU-US Data Privacy Framework where a US provider is certified; transfers from India are made under DPDP §16, which permits transfer except to countries the Government has restricted. Where a customer brings its own provider keys, the processing happens under the customer's own contract with that provider.
6. Retention
| Data | Retained |
|---|---|
| Workspace user account | Until deleted by an administrator, then removed within 30 days |
| Candidate records and derived AI output | Under the customer's control while the workspace is active; deleted when the customer deletes the candidate or the workspace |
| Proctoring evidence (frames, clips, screenshots) | With the coding-test record, subject to the customer's retention setting; the customer can delete it at any time |
| Interview recordings and transcripts | With the interview record, as above |
| Security logs, sign-in events | 12 months |
| Consent and acceptance records | For as long as the underlying data exists, plus the limitation period |
| Billing and tax records | As tax law requires (eight years in India under the Companies Act 2013) |
| Backups | Rolling, expire automatically within 35 days of deletion |
7. Your rights
Depending on where you are, you may have the right to access, correct, delete or receive a copy of your data, to object to or restrict processing, to withdraw consent, to opt out of any sale or sharing (we do not sell or share personal data for advertising), to limit the use of sensitive information, to nominate a person to exercise your rights if you die or are incapacitated (India), and to complain to a supervisory authority, the California Privacy Protection Agency or India's Data Protection Board. The supplements list the rights and the authorities for each region.
- Workspace users: write to privacy@axionconnect.com. We verify a request against the account's contact details; an authorised agent must show written authority.
- Candidates: your request goes to the organisation that is recruiting you, because it controls your data; you may also write to us and we will forward it within five business days and help the customer respond.
We do not discriminate against anyone for exercising a right. We answer within one month (GDPR; extendable by two months for complex requests, with notice), 45 days (CCPA/CPRA; extendable by 45 days with notice) or the period the DPDP Rules prescribe, whichever applies.
Global Privacy Control. Our servers treat a browser's Global Privacy Control signal as an opt-out of sale or sharing. Because we do neither, the signal changes nothing about how your data is handled; we honour it so that the record is clear.
8. Security
Data is encrypted in transit; stored provider credentials are encrypted at rest; access is role-based and logged; every query is scoped to one workspace; candidate code runs in an isolated sandbox; test rooms are bound to one device; sign-in is rate-limited and platform operators use multi-factor authentication; the platform is deployed from a reviewed branch with automated tests. No system is perfectly secure.
Breach notification. We notify affected customers without undue delay, and in any event within 48 hours of becoming aware of a personal-data breach, so they can meet their own duties (GDPR Art. 33 — supervisory authority within 72 hours; UK GDPR the same; DPDP §8(6) — the Data Protection Board and affected Data Principals; US state breach laws; the Australian Notifiable Data Breaches scheme). Where we are the controller we notify the authority and the affected people ourselves on the same timelines.
9. Children
The Service is for adults in a hiring context. We do not knowingly process data of anyone under 18 (DPDP §9) or under 16 (GDPR Art. 8), or under 13 (US COPPA), as a candidate or a user; a customer who learns it has done so must delete the record, and we will delete it on notice to privacy@axionconnect.com.
10. Cookies
See the Cookie Policy. We use only cookies that are necessary to sign you in and keep you signed in; there are no advertising cookies and no third-party analytics or session-recording tools.
11. Regional supplements and other regions
- EU / UK / Switzerland — controller identity and representative, lawful bases, retention, GDPR rights, transfers, supervisory authorities, AI Act.
- United States — CCPA/CPRA notice at collection, sensitive personal information, "Do Not Sell or Share", "Limit the Use of My Sensitive Personal Information", Global Privacy Control, multi-state rights, biometric-law notes.
- India — DPDP Act 2023 and Rules, SPDI Rules 2011, IT Rules 2021, Data Principal rights, Consent Manager, Grievance Officer, Data Protection Board.
- Australia and New Zealand. Where the Privacy Act 1988 (Cth) or the Privacy Act 2020 (NZ) applies, this policy is our APP 1 privacy policy; we collect only what section 1 and 2 describe, for the purposes stated; we disclose personal information to the overseas sub-processors listed on the Sub-processors page and remain accountable for them under APP 8; you may ask for access and correction at privacy@axionconnect.com and we respond within 30 days; an eligible data breach is assessed within 30 days and notified to the Office of the Australian Information Commissioner (https://www.oaic.gov.au (opens in a new tab)) or the New Zealand Privacy Commissioner (https://www.privacy.org.nz (opens in a new tab)) and to affected individuals as soon as practicable. We send no direct marketing.
12. Contact and grievance officer
Data protection enquiries: privacy@axionconnect.com. Grievance Officer under the DPDP Act, the SPDI Rules and the IT Rules 2021: Grievance Officer — to be named, reachable at privacy@axionconnect.com; grievances are acknowledged within 24 hours and resolved within 15 days, and in any event within the statutory period. Postal address: Axion Connect, Registered office address — to be confirmed.
13. Changes
We will post changes here with a new version date and, where material, notify workspace administrators in the Service and ask every user to accept the new version before continuing.
Questions about this document?
Write to privacy@axionconnect.com for anything about data and privacy, or support@axionconnect.com for the agreement itself. We reply within one working day.