The English text is the authoritative version of this document. It is not translated, because four translations of a legal notice are four texts that can disagree.
Who is responsible
CandidateBrief is a processing tool for recruitment agencies. The agency that uploads a candidate's document is the controller of the personal data in it: it decides what is uploaded, why, and who it is shared with. CandidateBrief is the processor, and acts only on the agency's instructions. It does not use the data for its own purposes and does not sell it.
The processor is the operator of candibrief.com. Write to support@candibrief.com with any question about this notice or about data held for your workspace; that address reaches the people who run the service, and it is the address every page on this site uses.
No separate company name or registered address is published for this service. That is stated plainly rather than filled in with an invented one; the address above is the one that reaches somebody who can act.
Payment
Card payments are handled by Waffo, which acts as the merchant of record for the sale. It is the seller on the receipt, it collects the payment and billing details, and it is responsible for the sales tax or VAT due.
CandidateBrief receives from Waffo only the name of the plan purchased, the state of the subscription, and the email address on the account. No card number reaches this service at any point.
What is stored
When a document is uploaded, the following are stored: the original file, its SHA-256 hash, the extracted text broken into paragraphs, the structured fields derived from that text, the review decisions made about each field, and an access log for shared links.
The original file is stored in a private bucket. It is not served from a public address and cannot be reached without an authenticated request. Uploaded files carry an opaque key built from the workspace id and the content hash; no filename and no candidate name appears in a storage path.
What is not stored
No third-party analytics, advertising or tracking script runs on this site or in the application. There is no cookie other than the session cookie that keeps a signed-in user signed in, and a short-lived cookie that records that a share-link password was entered correctly.
No IP address is stored in the clear. Share-link access events record a salted hash of the address, which is used to count attempts against a link and cannot be reversed to an address. No geolocation beyond a two-letter country code from the content delivery network is recorded, and only when the network supplies it.
No device fingerprint, no cross-site identifier and no behavioural profile is collected.
How long it is kept
The uploaded file itself is deleted 90 days after upload by default, and a workspace can choose a shorter window in Settings. A workspace can also delete a candidate, a document, a package or the whole workspace at any time, which removes everything belonging to it, including the links that served it.
What survives the retention window is the text extracted from the original file and the fields a member of the agency confirmed. Those stay with the profile, because they are the profile: deleting them would leave a candidate nothing can be reviewed or exported from. They are removed when the candidate or the workspace is deleted.
A profile that has been exported, or shared, is not recalled by deleting it here. A client may already hold the file, and this service cannot reach into their inbox. Deleting it removes the agency’s own copy and stops any shared link from resolving.
Who can reach it
Members of the workspace, according to the role they hold. A Viewer can read a profile; an Editor can change fields; only an Owner can delete data or manage billing. Every request re-reads the caller’s membership, so removing someone ends their access on their next request rather than when their session expires.
A shared link grants access to one package, for a limited time, only after a password is entered. Only a hash of the link is stored: the link itself exists once, in the response to the person who created it.
Model providers
The drafting assistant that proposes summary text is switched off unless a workspace has configured a model provider. When it is on, the text sent to the provider is the candidate’s structured profile, not the original file. The provider is named in the sub-processor list, and the capability is off by default.
Your rights
A candidate who wants their data removed should contact the agency that holds their profile; the agency can act on it directly. This service supports that with an export of everything held for a candidate, a deletion that removes it, and a record of who changed which field and when.