Skip to content
CandidateBrief
Menu
Sign in
Start free trial
Legal

Privacy notice

What is stored when a workspace uploads a candidate’s document, who can reach it, how long it is kept, and what happens when it is deleted.

The English text is the authoritative version of this document. It is not translated, because four translations of a legal notice are four texts that can disagree.

Who is responsible

CandidateBrief is operated by Ren Sike, an individual (sole proprietor) based in Beijing, People's Republic of China. Write to support@candibrief.com with any question about this notice, about data held for your account or workspace, or to exercise a right described below; that address is read by the person who runs the service.

For the account data of the people who sign up — name, email address, sign-in records, billing state — the operator is the controller. For the personal data inside an uploaded document, the agency that uploads it is the controller: it decides what is uploaded, why, and who it is shared with. CandidateBrief is then the processor, and acts only on the agency's instructions. It does not use that data for its own purposes and does not sell it.

What is collected

Only what the service needs to run, in four groups:

  • Account: the name and email address entered at sign-up, a password hash (never the password itself), sign-in sessions, the workspaces a person belongs to and the role held in each, and an audit record of changes they made.
  • Workspace content: uploaded original files and their SHA-256 hash, the text extracted from them, the structured fields derived from that text, review decisions, brand settings, generated documents, and a log of share-link downloads.
  • Billing: the plan, its interval and its status, as reported by Waffo Pancake. No card number, bank detail or billing address reaches this service.
  • Site usage: first-party page-view counts, described under “What is not stored”.

Why, and on what basis

Account and workspace data are used to provide the service the agency signed up for — performance of a contract (GDPR Art. 6(1)(b)). Candidate data inside uploaded documents is processed on the agency’s instructions, under the lawful basis the agency has for holding it.

Transactional email (verification, password reset, invitations, billing notices) is sent to perform the contract and is not marketing. No marketing email is sent.

Page-view counts and security logs are kept on the basis of legitimate interest (Art. 6(1)(f)): knowing which pages are read, and keeping the service secure.

Payment

Payments are processed by Waffo Pancake, operated by Waffo.com Limited, which acts as the merchant of record for the sale. It is the seller on the receipt, it collects the payment and billing details on its own PCI-DSS compliant checkout, and it is responsible for the sales tax or VAT due.

CandidateBrief receives from Waffo Pancake only the plan purchased, the state of the subscription, and the email address on the account.

Sharing

Personal information is not sold, rented or traded, and is not shared for advertising. It is shared only with the infrastructure providers named on the sub-processors page, each of which receives only what it needs to perform its function, and with a recipient an agency member chooses to send a share link to.

How it is stored and secured

The original file is stored in a private bucket. It is not served from a public address and cannot be reached without an authenticated request. Uploaded files carry an opaque key built from the workspace id and the content hash; no filename and no candidate name appears in a storage path.

Every connection is encrypted in transit, and the storage and database providers encrypt data at rest. Row-level security in the database keeps one workspace’s rows invisible to another. Only a hash of a share link is stored.

If a personal data breach affects a workspace, its owner is notified without undue delay and in any case within 72 hours of the breach becoming known, with what is known about its scope.

What is not stored

No third-party analytics, advertising or tracking script runs on this site or in the application. There is no cookie other than the session cookie that keeps a signed-in user signed in, a cookie that remembers the chosen interface language, and a short-lived cookie that records that a share-link password was entered correctly.

No IP address is stored in the clear. Share-link access events record a salted hash of the address, which is used to count attempts against a link and cannot be reversed to an address. No geolocation beyond a two-letter country code from the content delivery network is recorded, and only when the network supplies it.

Page views on the public site are counted by this service itself, not by a third party, so the operator can see which pages are read. Each count stores the page path, the referring site, a coarse device class and the country code, plus a visitor key that is a hash of the address and browser with a salt that changes every day — so a visitor cannot be followed from one day to the next. A browser that sends Do Not Track or Global Privacy Control is not counted at all.

No device fingerprint, no cross-site identifier and no behavioural profile is collected.

How long it is kept

The uploaded file itself is deleted 90 days after upload by default, and a workspace can choose 30 or 7 days instead in Settings. Generated packages follow the same window. A workspace can also delete a candidate, a document, a package or the whole workspace at any time, which removes everything belonging to it, including the links that served it.

What survives the retention window is the text extracted from the original file and the fields a member of the agency confirmed. Those stay with the profile, because they are the profile: deleting them would leave a candidate nothing can be reviewed or exported from. They are removed when the candidate or the workspace is deleted.

Account data is kept while the account exists and is deleted with it. Sign-in sessions expire after 7 days. Page-view counts are deleted after 400 days. Backups roll over on their own cycle of at most 30 days, after which deleted data is gone from them too.

A profile that has been exported, or shared, is not recalled by deleting it here. A client may already hold the file, and this service cannot reach into their inbox. Deleting it removes the agency’s own copy and stops any shared link from resolving.

Who can reach it

Members of the workspace, according to the role they hold. A Viewer can read a profile; an Editor can change fields; only an Owner can delete data or manage billing. Every request re-reads the caller’s membership, so removing someone ends their access on their next request rather than when their session expires.

A shared link grants access to one package, for a limited time, only after a password is entered. Only a hash of the link is stored: the link itself exists once, in the response to the person who created it.

Automated processing and AI

Text extraction and structuring are deterministic rules, not a machine-learning model, and no decision about a candidate is made automatically: every field is confirmed by a person before anything is exported.

This deployment sends no data to a third-party AI model. The optional drafting assistant that can propose summary text is switched off; if it is ever switched on, the provider is named on the sub-processors page before it is used, it receives the structured profile rather than the original file, and its proposals are labelled as such and still need a person to confirm them.

Your rights

Under the GDPR and similar laws you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent where processing relies on it. Write to the support address to exercise any of them; a request is answered within 30 days.

A candidate whose résumé an agency uploaded should contact that agency, which can act on the request directly: the service gives it an export of everything held for a candidate, a deletion that removes it, and a record of who changed which field and when. A request sent here about an agency’s candidate is passed to that agency.

You also have the right to lodge a complaint with the data protection authority where you live or work.

Children

The service is for businesses and is not directed at anyone under 18. Accounts may only be created by people aged 18 or over.

Changes to this notice

A material change is announced by email to workspace owners at least 14 days before it takes effect. The date at the top of this page is the date of the current version.