Privacy Policy & Data Protection Framework
Effective Date: February 14, 2026 • Document Version: 4.2 • Classification: Public Regulatory Disclosure
1. Architecture Overview & Data Protection Principles
Hireframe Technologies Inc. ("Hireframe", "we", "us", or "our") operates a specialized enterprise evaluation defensibility platform designed to generate structured scorecards, evidence citations, and audit records from candidate interview interactions.
Unlike legacy recruitment artificial intelligence platforms that aggregate candidate records for cross-tenant algorithmic modeling, Hireframe operates under a strict principle of Single-Tenant Data Isolation and Zero-Model Training. We believe candidate evaluations must remain verifiable, immutable, and strictly under the control of the hiring employer.
2. The Irrevocable Zero-Model-Training Guarantee
We make an unconditional contractual commitment: Hireframe does NOT use, disclose, license, or process any Customer Data—including interview audio recordings, video streams, speaker-diarized transcripts, coding sandbox artifacts, evaluator notes, or calibrated scoring rubrics—to train, optimize, re-train, or fine-tune generalized, public, commercial, or foundational large language models (LLMs).
All natural language inference and evidence extraction operations occur within ephemeral, dedicated inference runtime containers utilizing private instance endpoints. Weights are never updated based on tenant inputs, and prompt-completion contexts are flushed immediately following cryptographic ledger commitment.
3. Data Controller vs. Data Processor Designations
For the purposes of the General Data Protection Regulation (GDPR Article 28), the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA):
- The Customer (Employer) acts as the sole Data Controller, establishing the lawful basis for processing, defining the job competencies and rubric criteria, and deciding all final employment outcomes.
- Hireframe acts exclusively as a Data Processor / Service Provider, processing interview data strictly in accordance with documented Customer instructions and our executed Data Processing Addendum (DPA).
4. Categories of Information Processed
To deliver evidence-grounded evaluation scorecards, the platform processes the following data classes:
- Interview Telemetry & Recordings: Audio and video streams ingested via ATS integrations (Greenhouse, Lever, Ashby) or video conferencing webhooks (Zoom, Google Meet, Microsoft Teams).
- Transcript & Diarization Data: Text representations of interviews with millisecond-accurate speaker segmentation and timestamping.
- Job Competency Rubrics: Leveled behavioral anchors (scores 1.0 through 5.0) established by Customer hiring managers.
- Evaluator Feedback: Human panelist notes, initial scoring inputs, debrief consensus notes, and secondary opinion reviews.
- Exclusion of Biometric Identifiers: Hireframe does not perform emotional facial analysis, eye-tracking pupilometry, voice stress analysis, or biometric voiceprinting. Audio is processed solely for semantic phonetic transcription.
5. Cryptographic Security Standards & Tenant Isolation
Hireframe implements state-of-the-art administrative, physical, and technical safeguards:
- Encryption in Transit: All web traffic and API integrations require Transport Layer Security (TLS) version 1.3 with Perfect Forward Secrecy. Connections utilizing obsolete protocols (TLS 1.0, 1.1, 1.2 legacy ciphers) are actively rejected.
- Encryption at Rest: Customer databases, transcript chunks, and audit ledgers are encrypted utilizing Advanced Encryption Standard with 256-bit keys in Galois/Counter Mode (AES-256-GCM). Enterprise tiers support Customer-Managed Encryption Keys (AWS KMS / Azure Key Vault).
- SOC 2 Type II Certification: Our infrastructure and operational processes undergo continuous independent auditing against the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria.
6. Candidate Rights & Regulatory Compliance (EEOC, NYC LL 144, EU AI Act)
Hireframe is purpose-built to comply with emerging global statutory mandates governing automated employment decision tools:
- EEOC Uniform Guidelines (§1607): The platform provides the objective job-related validity studies and four-fifths adverse impact documentation required to withstand Title VII disparate impact inquiries.
- New York City Local Law 144: We provide automated tools enabling employers to publish annual independent bias audit summaries and collect required candidate 10-day notice acknowledgments.
- European Union Artificial Intelligence Act: In alignment with EU AI Act classification of employment tools as "High-Risk AI", Hireframe maintains full risk management logs, human-oversight escalation gates, and end-to-end technical documentation.
- Candidate Access & Explanation Rights: Upon request from the Data Controller, Hireframe can export an explainable, plain-language Candidate Feedback Summary detailing the objective rubrics evaluated and timestamped transcript citations.
7. Cryptographic Audit Trail Retention & Disposal
By default, scorecards and decision logs are retained in an immutable, append-only cryptographic ledger for 180 days (Core Tier) or 730 days (Growth Tier). Enterprise customers may define automated retention windows between 90 days and 7 years to satisfy their specific statutory recordkeeping requirements.
Upon expiration of the retention window or upon validated Controller instruction, transcript text and media recordings are permanently sanitized utilizing cryptographic erasure (key destruction) adhering to NIST SP 800-88 Rev. 1 Guidelines for Media Sanitization.
8. Contact Our Data Protection & Compliance Officers
If you have questions regarding this Privacy Policy, wish to execute our Standard Data Processing Addendum, or represent a candidate exercising statutory rights under GDPR/CCPA, please contact our dedicated officers directly:
- Data Protection Officer: dpo@hireframe.online
- Employment Counsel & Compliance: compliance@hireframe.online
- Security & Infrastructure Governance: security@hireframe.online