Privacy Policy
Last updated: July 26, 2026 · version 2026-07-26
This Privacy Policy explains how Personally ("we," "us") collects, uses, shares, and protects information for both job seekers and employers. It is written to be transparent — a core value of the product. The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children. If we learn we have collected information from a child, we will promptly delete it.
Who we are. The Service is operated by Personally LLC ("Personally"), a Texas (USA) limited liability company, administered from Germany. Our role depends on the data. We are the data controller (or "business" under the CCPA) for an employer's own account data and for the profile data job seekers create for the platform itself. We are a processor (or "service provider" under the CCPA) acting on an employer's behalf for candidate data submitted to that employer's requisitions (see our Data Processing Addendum). Questions: contact@personallyhired.com.
1. Information we collect
(Categories of personal information under applicable US state privacy laws — including the CCPA/CPRA and the Texas Data Privacy and Security Act — are noted below.)
From job seekers
- Account details: name, email, password (stored only as a salted hash), and an optional résumé link or file reference.
- Application data: your answers to an employer's screening questions and whether you passed.
- Scheduling data: any introductory call you book.
- Consents: your choices about future consideration and linking to The Workaround Collective.
From employers / hiring managers
- Account and company details, the real email we mask behind a relay address, requisition content, screening questions, interview notes, compliance-acknowledgment audit records, and subscription/billing details.
From all users (collected automatically)
- IP address, browser type, device identifiers, operating system, access timestamps, and related server-log data. Google reCAPTCHA may also collect hardware and software information to verify you are human.
2. How we use information
- To operate screening, scheduling, and the transparency dashboards.
- To share a booking candidate's name, résumé, and questionnaire answers with the relevant hiring manager for that requisition.
- To verify humans (Google reCAPTCHA, subject to Google's Privacy Policy and Terms of Service) and prevent abuse.
- To process employer subscriptions and account administration.
We do not sell or share (as those terms are defined under the California Consumer Privacy Act) your personal information, and we do not use it to train third-party advertising profiles.
3. Your data choices if you don't pass screening
This is central to how Personally treats job-seeker data:
- Delete & retract. You can permanently delete your application and personal details. When you do, we remove your application, answers, and personal record from our active systems. The employer receives only an anonymous count of retractions — none of your information. Residual copies may persist temporarily in encrypted backups and will be overwritten in the ordinary backup-rotation cycle. We may also retain limited records where required by law (for example, certain legal-hold obligations).
- Future consideration.You can opt in to remain in an employer's talent pool for this role (if re-opened) or for any future role. You can withdraw this from your account.
4. The Workaround Collective
If you consent, we will link your Personally account to The Workaround Collective (a nonprofit we support, currently in development) so it can offer you grants, connections, and support. We will only share what is needed to provide those services, and only with your consent, which you can revoke at any time from your account.
5. Sharing
- With employers: only the candidate data described above, and only for the role(s) it relates to (or future roles you opted into).
- With service providers: calendar, email, human-verification, payment, and HR-sync providers (e.g., Workday, Greenhouse), each acting as a service provider or processor under written agreements, strictly to provide the Service.
- For legal reasons: where required by applicable law, regulation, or legal process, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Personally, our users, or the public.
6. Employer data sync
To keep enterprise systems current, we sync recruitment events (status changes, scheduled calls) to connected HR/talent systems. Employers are responsible for the privacy practices of their own connected systems.
7. Security & retention
We use reasonable technical and organizational measures to protect data, including hashing passwords and masking recruiter emails. However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. We retain personal data for as long as your account is active or as needed to provide the Service, then delete or anonymize it, except where retention is legally required.
8. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on these legal bases under Article 6:
- Performance of a contract (Art. 6(1)(b)) — creating and running your account, processing applications, and scheduling calls.
- Consent (Art. 6(1)(a)) — linking to The Workaround Collective, opting into future consideration, and any optional marketing. You can withdraw consent at any time.
- Legitimate interests (Art. 6(1)(f)) — securing the platform, preventing bots/fraud (Google reCAPTCHA), and enabling employers to search their own talent pool, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — tax, accounting, and responding to lawful requests.
We do not intentionally collect special-category data (Art. 9), such as health information, and we actively discourage employers from asking for it. Please don't include it in free-text fields.
9. International data transfers
Personally is operated from the USA and Germany, so your data may be transferred to and processed in the United States and other countries. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards — the European Commission's Standard Contractual Clauses (SCCs) and/or the EU-US Data Privacy Framework — and we require our sub-processors to provide equivalent protection. See our sub-processors and security overview. You can request a copy of the relevant safeguards at contact@personallyhired.com.
10. Your privacy rights
Depending on where you live (including under the GDPR and UK GDPR, the CCPA/CPRA in California, and the Texas Data Privacy and Security Act), you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Rectify inaccurate or incomplete data.
- Eraseyour data ("right to be forgotten") — built into the product via delete/retract and account deletion.
- Restrict or object to certain processing, including processing based on legitimate interests.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time, without affecting processing already carried out.
- Not be subject to solely automated decisions producing legal or similarly significant effects (Art. 22). Personally does not currently make such decisions: the questionnaire is an eligibility step configured by the employer, and a human hiring manager reviews and makes all interview and hiring decisions. If this changes, we will update this policy and, where required, obtain your consent or provide a right to contest the decision.
- Lodge a complaint. In the EU/EEA, you may complain to a data-protection supervisory authority. The authority competent for us is the LfDI Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany; poststelle@lfdi.bwl.de; www.baden-wuerttemberg.datenschutz.de) — you may also complain to the authority where you live or work. In the US, you may contact the relevant state attorney general (e.g., Texas or California) or, in California, the California Privacy Protection Agency, and you may also contact the Federal Trade Commission.
The fastest way to exercise your rights is to do it yourself, instantly, in your account — no request and no waiting. When signed in you can edit your details (rectification), export your data as JSON (portability), delete your account (erasure), and delete/retract individual applications, future-consideration, and Workaround Collective settings.
If you can't sign inor don't have an account, use our privacy request form or contact contact@personallyhired.com. These requests require manual identity verification and are answered within the applicable legal deadline (GDPR: one month; CCPA: 45 days; TDPSA: 45 days).
11. Manifestly unfounded, excessive, or repetitive requests
We want exercising your rights to be easy — which is why most requests can be completed instantly and free of charge in your account. In the rare case that a request is manifestly unfounded or excessive, in particular because of its repetitive character, data-protection law lets us respond proportionately. In those situations we may, at our discretion, either:
- charge a reasonable fee that reflects the administrative costs of providing the information or communication or taking the requested action; or
- refuse to act on the request.
This follows the GDPR (Art. 12(5)) and, for California residents, the CCPA/CPRA (Cal. Civ. Code § 1798.145(g)(3)), both of which permit a controller or business to charge a reasonable fee or decline to act where a request is manifestly unfounded or excessive, in particular because of its repetitive character. Consistent with the CCPA, we are also not required to respond to more than two access requests from the same consumer in a 12-month period.
If we decide a request meets this threshold, we will tell you why, provide a cost estimate before charging any fee, and explain how you can complain to a supervisory authority or seek a judicial remedy. As the controller/business, we — not you — bear the burden of demonstrating that a request is manifestly unfounded or excessive.
12. Cookies
We use only strictly necessary cookiesto run the Service: a session cookie to keep you logged in, and a small preference cookie for the demo "view as" switcher. Third-party tools we use (such as Google reCAPTCHA) may also set their own cookies as necessary to function. We do notuse advertising or third-party tracking cookies. If we add analytics in the future, we will ask for your consent first where required. We do not currently respond to "Do Not Track" browser signals because we do not engage in cross-site tracking.
13. Data controller, EU representative & DPO
Controller: Personally LLC (Texas, USA), administered from Germany — full identity and address in our legal notice (Impressum). Where an EU representative (Art. 27) or Data Protection Officer (Art. 37) is required, their contact details will be published there. For now, all data-protection enquiries go to contact@personallyhired.com.
14. Changes & contact
We will post updates here with a new "last updated" date. If we make material changes that affect how we use personal information previously collected, we will notify you by email or prominent notice on the Service before the changes take effect. For privacy questions or requests, contact contact@personallyhired.com.