Privacy Policy
Last updated: July 26, 2026 · version 2026-07-26
This Privacy Policy explains how Personally ("we," "us") collects, uses, shares, and protects information for both job seekers and employers. It is written to be transparent — a core value of the product. The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children. If we learn we have collected information from a child, we will promptly delete it.
Who we are. The Service is operated by Personally LLC ("Personally"), a Texas (USA) limited liability company, administered from Germany. Our role depends on the data. We are the data controller (or "business" under the CCPA) for an employer's own account data and for the profile data job seekers create for the platform itself. We are a processor (or "service provider" under the CCPA) acting on an employer's behalf for candidate data submitted to that employer's requisitions (see our Data Processing Addendum). Questions: contact@personallyhired.com.
1. Information we collect
(Categories of personal information under applicable US state privacy laws — including the CCPA/CPRA and the Texas Data Privacy and Security Act — are noted below.)
From job seekers
- Account details: name, email, password (stored only as a salted hash), and an optional résumé link or file reference.
- Application data: your answers to an employer's screening questions and whether you passed.
- Scheduling data: any introductory call you book.
- Consents: your choices about future consideration and linking to The Workaround Collective.
From employers / hiring managers
- Account and company details, the real email we mask behind a relay address, requisition content, screening questions, interview notes, compliance-acknowledgment audit records, and subscription/billing details.
From all users (collected automatically)
- IP address, browser type, device identifiers, operating system, access timestamps, and related server-log data. Google reCAPTCHA may also collect hardware and software information to verify you are human.
2. How we use information
- To operate screening, scheduling, and the transparency dashboards.
- To share a booking candidate's name, résumé, and questionnaire answers with the relevant hiring manager for that requisition.
- To verify humans (Google reCAPTCHA, subject to Google's Privacy Policy and Terms of Service) and prevent abuse.
- To process employer subscriptions and account administration.
We do not sell or share (as those terms are defined under the California Consumer Privacy Act) your personal information, and we do not use it to train third-party advertising profiles.
3. Your data choices if you don't pass screening
This is central to how Personally treats job-seeker data:
- Delete & retract. You can permanently delete your application and personal details. When you do, we remove your application, answers, and personal record from our active systems. The employer receives only an anonymous count of retractions — none of your information. Residual copies may persist temporarily in encrypted backups and will be overwritten in the ordinary backup-rotation cycle. We may also retain limited records where required by law (for example, certain legal-hold obligations).
- Future consideration.You can opt in to remain in an employer's talent pool for this role (if re-opened) or for any future role. You can withdraw this from your account.
4. The Workaround Collective
If you consent, we will link your Personally account to The Workaround Collective (a nonprofit we support, currently in development) so it can offer you grants, connections, and support. We will only share what is needed to provide those services, and only with your consent, which you can revoke at any time from your account.
5. Sharing
- With employers: only the candidate data described above, and only for the role(s) it relates to (or future roles you opted into).
- With service providers: calendar, email, human-verification, payment, and HR-sync providers (e.g., Workday, Greenhouse), each acting as a service provider or processor under written agreements, strictly to provide the Service.
- For legal reasons: where required by applicable law, regulation, or legal process, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Personally, our users, or the public.
6. Employer data sync
To keep enterprise systems current, we sync recruitment events (status changes, scheduled calls) to connected HR/talent systems. Employers are responsible for the privacy practices of their own connected systems.
7. Google Calendar integration
If you (a hiring manager) choose to connect your Google Calendar, Personally requests two permissions: read-only access to your free/busy information, and permission to manage events that Personally creates on your calendar. We use your free/busy data solely to display your available times to candidates scheduling an introductory call, and we use calendar-event access solely to add a confirmed intro-call event to your calendar and to remove or update it if the call is cancelled or rescheduled. We do not read the contents of your existing calendar events (titles, descriptions, attendees, or locations), and we do not access, modify, or delete events that Personally did not create. We never add candidates as attendees on your calendar events, and we disable Google Meet on the events we create — the call itself takes place in a separate secure video room. You can disconnect your calendar at any time from your account settings, which revokes our access and immediately stops all calendar reads and writes. We store only your OAuth tokens (encrypted at rest) and the identifiers of the events we created; we do not sell calendar data or use it for advertising.
Personally's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Security & retention
We use reasonable technical and organizational measures to protect data, including hashing passwords and masking recruiter emails. However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. We retain personal data for as long as your account is active or as needed to provide the Service, then delete or anonymize it, except where retention is legally required.
9. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on these legal bases under Article 6:
- Performance of a contract (Art. 6(1)(b)) — creating and running your account, processing applications, and scheduling calls.
- Consent (Art. 6(1)(a)) — linking to The Workaround Collective, opting into future consideration, and any optional marketing. You can withdraw consent at any time.
- Legitimate interests (Art. 6(1)(f)) — securing the platform, preventing bots/fraud (Google reCAPTCHA), and enabling employers to search their own talent pool, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — tax, accounting, and responding to lawful requests.
We do not intentionally collect special-category data (Art. 9), such as health information, and we actively discourage employers from asking for it. Please don't include it in free-text fields.
10. International data transfers
Personally is operated from the USA and Germany, so your data may be transferred to and processed in the United States and other countries. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards — the European Commission's Standard Contractual Clauses (SCCs) and/or the EU-US Data Privacy Framework — and we require our sub-processors to provide equivalent protection. See our sub-processors and security overview. You can request a copy of the relevant safeguards at contact@personallyhired.com.
11. Your privacy rights
Depending on where you live (including under the GDPR and UK GDPR, the CCPA/CPRA in California, and the Texas Data Privacy and Security Act), you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Rectify inaccurate or incomplete data.
- Eraseyour data ("right to be forgotten") — built into the product via delete/retract and account deletion.
- Restrict or object to certain processing, including processing based on legitimate interests.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time, without affecting processing already carried out.
- Not be subject to solely automated decisions producing legal or similarly significant effects (Art. 22). Personally does not currently make such decisions: the questionnaire is an eligibility step configured by the employer, and a human hiring manager reviews and makes all interview and hiring decisions. If this changes, we will update this policy and, where required, obtain your consent or provide a right to contest the decision.
- Lodge a complaint. In the EU/EEA, you may complain to a data-protection supervisory authority. The authority competent for us is the LfDI Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany; poststelle@lfdi.bwl.de; www.baden-wuerttemberg.datenschutz.de) — you may also complain to the authority where you live or work. In the US, you may contact the relevant state attorney general (e.g., Texas or California) or, in California, the California Privacy Protection Agency, and you may also contact the Federal Trade Commission.
The fastest way to exercise your rights is to do it yourself, instantly, in your account — no request and no waiting. When signed in you can edit your details (rectification), export your data as JSON (portability), delete your account (erasure), and delete/retract individual applications, future-consideration, and Workaround Collective settings.
If you can't sign inor don't have an account, use our privacy request form or contact contact@personallyhired.com. These requests require manual identity verification and are answered within the applicable legal deadline (GDPR: one month; CCPA: 45 days; TDPSA: 45 days).
12. Manifestly unfounded, excessive, or repetitive requests
We want exercising your rights to be easy — which is why most requests can be completed instantly and free of charge in your account. In the rare case that a request is manifestly unfounded or excessive, in particular because of its repetitive character, data-protection law lets us respond proportionately. In those situations we may, at our discretion, either:
- charge a reasonable fee that reflects the administrative costs of providing the information or communication or taking the requested action; or
- refuse to act on the request.
This follows the GDPR (Art. 12(5)) and, for California residents, the CCPA/CPRA (Cal. Civ. Code § 1798.145(g)(3)), both of which permit a controller or business to charge a reasonable fee or decline to act where a request is manifestly unfounded or excessive, in particular because of its repetitive character. Consistent with the CCPA, we are also not required to respond to more than two access requests from the same consumer in a 12-month period.
If we decide a request meets this threshold, we will tell you why, provide a cost estimate before charging any fee, and explain how you can complain to a supervisory authority or seek a judicial remedy. As the controller/business, we — not you — bear the burden of demonstrating that a request is manifestly unfounded or excessive.
13. Events, webinars & recordings
We host the Candid Conversations webinar series (in collaboration with The Workaround Collective). When you register for a session we collect your name and email through Zoom, acting as our processor, to manage your attendance; you can separately opt in to hear about future events. Sessions are recorded, and a recording may include a speaker's name, voice, and image and — where we publish audience questions asked in the chat — the content of those questions. We publish recordings to third-party platforms such as YouTube (and may add podcast platforms later). We do not embed third-party video or audio players on our event pages, and those pages use no third-party cookies or trackers— links to a recording open on the external platform, where that platform's own privacy policy and cookies apply. We rely on consent (Art. 6(1)(a)) for event registration and optional marketing, and on our and the speakers' legitimate interests (Art. 6(1)(f)) to produce and share the recordings.
14. Cookies
We use only strictly necessary cookiesto run the Service: a session cookie to keep you logged in, and a small preference cookie for the demo "view as" switcher. Third-party tools we use (such as Google reCAPTCHA) may also set their own cookies as necessary to function. We do notuse advertising or third-party tracking cookies. If we add analytics in the future, we will ask for your consent first where required. We do not currently respond to "Do Not Track" browser signals because we do not engage in cross-site tracking.
15. Data controller, EU representative & DPO
Controller: Personally LLC (Texas, USA), administered from Germany — full identity and address in our legal notice (Impressum). Where an EU representative (Art. 27) or Data Protection Officer (Art. 37) is required, their contact details will be published there. For now, all data-protection enquiries go to contact@personallyhired.com.
16. Changes & contact
We will post updates here with a new "last updated" date. If we make material changes that affect how we use personal information previously collected, we will notify you by email or prominent notice on the Service before the changes take effect. For privacy questions or requests, contact contact@personallyhired.com.