Candidate, Training, Research Participant, and Website Privacy Notice
Privacy Policy
This Privacy Notice explains how LearningBranch Inc., operating as HiringBranch ("HiringBranch," "we," "us," or "our"), collects, uses, shares, stores, and protects your personal information when you visit our website, take a hiring assessment or a training session through our platform, or take part in a testing Study as a research participant.
We have written this notice in plain language because the people who read it most are candidates applying for jobs, learners completing training through an employer or educational institution, and research participants helping us test our platform, not lawyers. We have also written it to meet the requirements of Quebec's Act respecting the protection of personal information in the private sector (Law 25), the Personal Information Protection and Electronic Documents Act (PIPEDA), provincial privacy laws in Alberta and British Columbia, the European Union's General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, India's Digital Personal Data Protection Act 2023, and, where applicable to our infrastructure providers, Singapore's Personal Data Protection Act, as well as the disclosure obligations under the EU AI Act and Ontario's Working for Workers Four Act. Where a specific law applies only to certain individuals or regions, the relevant section below identifies that scope.
This notice applies in three places. First, on our website at hiringbranch.com and any other site we operate. Second, inside our assessment and training platform, which candidates and employees access through links sent by employers who use HiringBranch, whether for a hiring assessment or a training session. Third, inside testing Studies that research participants access through Prolific or a similar research panel. The same notice governs all three, because the same core protections apply throughout, with a small number of practices that differ depending on which relationship you have with us, and on whether your session is a hiring assessment or a training session. We flag those differences clearly wherever they occur.
Please read this notice before taking an assessment or a testing Study, or providing personal information through our website. We obtain your consent on an opt-in basis before you begin. Before you begin, we present this notice, or a summary of it, and require you to take an affirmative action to consent. Consent is not pre-checked or assumed.
By taking an assessment or a Study, or using our website, you consent to the processing of your personal information as described here. If you do not agree, please do not proceed.
This notice is available in English and Canadian French. If you are a Quebec resident, you have the right to receive this notice and conduct your assessment in French.
1. Who We Are
HiringBranch is an AI-powered assessment and training platform. Employers use it in two ways: to evaluate candidates for hiring, and to deliver skills assessment and training to their own employees, both covering skills relevant to customer-facing and operational roles, including speaking, writing, listening, reading, customer focus, quality focus, problem-solving, and related competencies.
Our legal entity is LearningBranch Inc., a Canadian corporation operating as HiringBranch. Our head office is in Canada. Our Privacy Officer is Eric Dofonsou, who can be contacted at privacy@hiringbranch.com.
Two Purposes on Our Platform: Hiring Assessments and Training
An employer, university, college, or other organization that commissions a Hiring Assessment or Training on our platform (we call any of them an "Institutional Customer") may invite you to our platform for one of two different purposes. What matters legally is the purpose of your specific session, not a fixed category of person, since the same individual could complete a Hiring Assessment on one occasion and a Training session on another.
- Hiring Assessments. You are applying for a role, and the employer uses your results to help make a hiring decision. HiringBranch generates assessment scores and recommendations, but the final hiring decision is always made by the employer, not by us and not by our AI.
- Training. You are a current employee, student, or other learner engaged through an Institutional Customer, whether your employer or an educational institution such as a university (we call you a "Learner"). An Institutional Customer may add its own curriculum or content in addition to, or instead of, HiringBranch-authored material. The session is for skills assessment, professional development, or coursework, as applicable. HiringBranch itself never makes a hiring, promotion, discipline, admissions, grading, academic-standing, or employment decision based on a Training session, and our AI is not used to make one, though the Institutional Customer may separately use your results for its own decisions under its own policies, described further in Section 4. Training is delivered through a separate platform surface with its own consent flow, described in Section 10, though it shares the same underlying architecture, infrastructure, and security controls described in this notice.
Where this notice describes something that applies only to a Hiring Assessment or only to Training, we say so explicitly. Where a section does not distinguish between the two, it applies the same way to both, because the same privacy notice governs both platforms. Wherever this notice refers to an "employer" or "employee" in connection with Training, that reference includes an Institutional Customer and a Learner respectively, since a Learner may be a student rather than an employee.
Research and Testing Participants
- Research and Testing Participants. If you were recruited through Prolific, or a similar third-party research or user-testing panel, to test our platform, provide sample assessment responses, or contribute to model calibration and independent bias-audit studies, you are a Research and Testing Participant. No employer and no hiring decision is involved in your participation. We refer to you as a "participant" in the sections that follow. Where our practices differ for participants, we say so explicitly; where a section does not mention participants, it applies to you in the same way it applies to candidates and employees.
2. What Personal Information We Collect
We collect only the information we need to deliver the assessment or training session, support the employer's hiring or training purposes, run testing Studies, and operate our website. The categories below describe what we collect from candidates and employees taking a session. Website visitors who do not take a session provide a smaller subset, mainly technical data and any information you submit through a contact form.
Identification Data
Your name and email address, used to send you the assessment, identify your results, and return them to the employer. Research and Testing Participants generally do not provide this; see below.
Assessment Response Data
Voice recordings of your spoken responses, transcripts of those responses, written text responses, and your scored answers to assessment questions. This is the core data we need to evaluate your skills, or, for participants, to test the platform.
Performance and Skills Data
Behavioral and interaction patterns during the assessment, and scores measuring proficiency against role-specific criteria defined by the employer, or, for testing Studies, against the criteria defined by the Study.
Proctoring Data (only where the employer has enabled proctoring)
Webcam video recordings captured during the assessment to verify your identity and confirm assessment integrity. Proctoring is optional and is configured by the employer. If proctoring is enabled, you will be asked for a separate explicit opt-in before the assessment begins. Proctoring video is used only for proctoring. It is not analyzed by AI, not used to infer traits, not used to make hiring decisions, and not used to train AI models. We do not use proctoring in testing Studies.
Technical Data
IP address, device identifier, browser type, operating system, screen resolution, language settings, referring URLs, and related technical information necessary to deliver the platform, detect fraud, and operate our website.
Consent and Process Data
Timestamps recording when you consented to this notice, the version of the notice you consented to, any accommodation requests you make, and audit logs of system access to your records.
Cookies and Web Analytics
When you visit our website, we use cookies and analytics tools to understand how the site is used and improve it. You can manage cookies through our cookie banner and your browser settings. Declining non-essential cookies will not prevent you from using the site.
Research and Testing Participants
If you are a Research and Testing Participant recruited through Prolific, we collect a narrower set of information than we do from Candidates. We generally identify you only by your Prolific ID, a pseudonymous identifier Prolific assigns you, rather than by your name or email address, and we do not request your name or contact details to take part in a testing Study unless we tell you otherwise in the Study listing. Your Prolific ID is still your personal information, since Prolific can link it back to you even though we generally cannot, and all of the rights described in Section 9 apply to you on the same basis as to Candidates and Learners, using your Prolific ID in place of a name. We also collect any demographic or screening data Prolific shares with us in connection with the Study, by reference to your Prolific ID.
We do not collect webcam proctoring video, payment information, or identity verification data from participants; Prolific handles your identity verification and payment directly, under its own Participant Privacy Notice.
What We Do Not Collect
We do not collect demographic information such as race, ethnicity, gender identity, age, disability, religion, sexual orientation, or national origin as part of the assessment process. We do not extract voiceprint identifiers for identity recognition. We do not perform emotion detection. We do not infer mental or physical health conditions from your voice, text, or video. We do not infer personality traits or political views from your responses.
We collect demographic information only with separate, explicit consent and solely for the purpose of conducting bias analyses and independent bias audits (as described in Section 6). This information is processed only in aggregated and de-identified form and is never used to score, rank, or otherwise evaluate individual candidates or participants.
3. How We Use Your Personal Information
We use your personal information for specific, disclosed purposes. We do not use it for advertising, marketing to candidates or participants, sale to third parties, profiling beyond the assessment or testing context, or any unrelated commercial purpose.
- Delivering the assessment. Identifying you, sending the invitation, evaluating your speaking, listening, reading, and writing proficiency against the criteria defined by the employer, and returning results to the employer.
- Generating explainability reports (Hiring Assessments only). Producing reports that identify the principal factors and your results. You can request your explainability report at any time.
- Supporting the employer's hiring decision (Hiring Assessments only). Providing scores to the employer. The final hiring decision is made by the employer's human recruiters and hiring managers, not by HiringBranch and not by our AI.
- Supporting skills training, professional development, or academic coursework (Training only). Providing your results to the Institutional Customer for development, program, or academic purposes. HiringBranch itself makes no hiring, promotion, or discipline decision, and any grading or academic-standing decision is made solely by the Institutional Customer under its own policies, not by HiringBranch, described further in Section 4.
- Testing and platform development (Research and Testing Participants only). Using your Study responses for platform testing, quality assurance, calibrating our assessment scoring models, and independent bias audits, as disclosed in the Study you accepted. No hiring recommendation, employer, or hiring decision ever results from your participation.
- Assessment integrity. Detecting abnormal completion patterns and, where enabled by the employer, conducting proctoring to verify identity.
- Platform operation and security. Operating the platform, detecting fraud, monitoring performance, and maintaining audit logs.
- Accommodation requests. Handling any accommodation request you make, used only to provide the accommodation, never for scoring or model training.
- Communications. Responding to inquiries, sending service-related communications, and, only with your consent, marketing communications about HiringBranch.
- Legal compliance. Meeting our legal obligations, demonstrating lawful basis for processing, supporting candidate and participant rights requests, and responding to lawful requests from regulators.
4. How We Use AI
HiringBranch uses AI to evaluate your assessment responses and generate scores and recommendations. We believe candidates and participants have a right to understand how this works, so this section explains it plainly.
What the AI Does
Our scoring combines rule-based methods with supervised machine learning rooted in linguistic research. The AI evaluates job-relevant criteria such as language proficiency, customer focus, quality focus, critical thinking, problem-solving, empathy, and attention to detail. The specific criteria and their weights are configured to the bona fide occupational requirements of the role the employer is hiring for, or, for a testing Study, to the purpose described in that Study.
Scoring is deterministic and consistent. The same response produces the same score. There is no randomness introduced at runtime.
Decision Support, Not Automated Decision-Making
HiringBranch produces scores. We do not make hiring decisions. The employer's human recruiters and hiring managers make the final hiring decision and retain full discretion to override, adjust, or disregard any HiringBranch-generated score.
This positions our platform as automated decision support rather than fully automated decision-making under Quebec Law 25 and Article 22 of the GDPR. It also means a human is always in the loop on the decision that affects you in a Hiring Assessment. For Research and Testing Participants, there is no hiring decision at all, and no employer ever receives your results.
For Training, HiringBranch itself makes no hiring, promotion, discipline, or similar employment decision, and our AI is not used to make one. Some Institutional Customers, for example universities, may nonetheless use Training results as an input into their own decisions about a Learner, such as grading, a pass or fail determination, academic standing, or a disciplinary referral. Where an Institutional Customer has confirmed to us that it does this, we extend the same disclosures given for Hiring Assessments to that Training population: notice that AI was used, disclosure of the main factors behind the score, and support for the Learner's right to request human review, exercised through the Institutional Customer or our Privacy Officer. Absent that confirmation, Training results are provided for development or coursework-support purposes only, and questions about any resulting academic or employment decision should be directed to the Institutional Customer, which is solely responsible for that decision.
For our educational Institutional Customers specifically, such as universities, any decision made about a Learner using Training results, including grading, a pass or fail determination, or academic standing, is made entirely by the Institutional Customer's own human staff. HiringBranch's AI plays no role in that decision, and no such decision is automated.
Your Right to Human Review and Explanation
If you completed a Hiring Assessment, you have the right to request human review of any decision based on your assessment and to receive an explanation of the principal factors that contributed to your result. The same right applies to a Training session where the Institutional Customer uses your results to make a decision about you, as described above. Where no such decision is made, you may still request an explanation of your results from the Privacy Officer.
You may submit a request for review through the recruiter or employer responsible for the hiring process, who makes the final hiring decision. You may also contact HiringBranch's Privacy Officer at privacy@hiringbranch.com to request a review of how the assessment was conducted.
5. Who We Share Your Personal Information With
We share your personal information with a limited number of carefully vetted service providers (we call them "subprocessors") that are necessary to deliver the platform. We do not sell your personal information. We do not share it with advertisers, data brokers, recruitment marketing platforms, other HiringBranch customers, or any party outside the list below.
The Employer or Institutional Customer
For a Hiring Assessment, we return your assessment results, including scores and explainability reports, to the employer that invited you. The employer is the party making the hiring decision. For Training, we return your results to the Institutional Customer for development, program, or academic purposes, as described in Section 4. In both cases, the Institutional Customer's own use of your information is governed by their own privacy policy and their own employment or academic practices, not by HiringBranch.
Institutional Customer-Provided Content
Where an Institutional Customer, such as an employer, university, or college, uploads or otherwise adds its own training content, curriculum, case studies, or similar material to the platform, HiringBranch and that Institutional Customer act as independent, separate controllers of that content, not joint controllers.
HiringBranch acts only as a hosting and delivery platform for it: we do not review, vet, or take responsibility for its substance, accuracy, or legality, including whether it contains personal information about third parties, such as other students or individuals referenced in a case study. The Institutional Customer is solely responsible for having the rights and legal basis needed to include any such content, and is the controller for any personal information it embeds within it. If you believe content added by an Institutional Customer contains personal information about you, contact that Institutional Customer directly, or contact our Privacy Officer, who will refer your request to them.
Prolific (Research and Testing Participants Only)
On a Prolific Study, HiringBranch is the "Researcher" running the Study and the data controller for the Study responses you provide to us, such as your voice or text answers. Prolific is a separate and independent data controller for your Prolific account information, including your name, email, payment details, and any demographic pre-screening answers; see Prolific's own Participant Privacy Notice for how Prolific handles that data. HiringBranch does not receive or control your Prolific account data.
We share limited information with Prolific, such as confirmation of your completion of a Study and your performance where needed to authorize your payment, by reference to your Prolific ID. We do not share participant data with any employer, because no employer is involved in a testing Study.
Subprocessors That Process Candidate and Participant Data
- Amazon Web Services (AWS). Web and application hosting and infrastructure management, with data centres in Canada, Germany, Singapore, and the United States. Which region hosts your data depends on the contract between HiringBranch and the employer that invited you, or, for a testing Study, the region assigned to that project. AWS holds SOC 2 Type II and ISO 27001 certifications.
- MongoDB Atlas. Cloud database services, with data centres in Canada, Germany, and Singapore, on the same contract-dependent basis as AWS above. MongoDB holds SOC 2 Type II and ISO 27001 certifications.
- BablAI. Independent bias auditing in the United States. Only aggregated and de-identified outcome data is shared. No candidate- or participant-identifiable information is transferred.
Operational Subprocessors That Do Not Process Assessment Data
We use Google Workspace for internal email, Intercom for customer support ticketing, and Datadog for platform monitoring. These services do not process candidate or participant assessment data. They are listed here for transparency.
Subprocessor Safeguards
Each subprocessor is bound by a written data processing agreement that imposes obligations consistent with PIPEDA, Quebec Law 25, and where applicable GDPR and UK GDPR, including purpose limitation, confidentiality, security requirements, breach notification, data subject rights support, and audit cooperation. Subprocessors are prohibited from using candidate or participant data for any purpose outside the service they provide to us.
Singapore is not a participating jurisdiction under the EU-U.S. or UK-U.S. Data Privacy Framework, so for transfers to Singapore we rely on Standard Contractual Clauses, and for UK-originated data, the UK Addendum to the EU Standard Contractual Clauses or an International Data Transfer Agreement, rather than the Framework.
Legal Disclosure
We may disclose personal information where required by law, in response to lawful requests from regulators or law enforcement, to establish or defend legal claims, or in connection with a corporate transaction such as a merger or acquisition, subject to customary confidentiality protections.
6. AI Model Improvement and Independent Bias Auditing
This section explains two specific uses of your assessment data beyond delivering your individual assessment or Study. We disclose them here because we believe you have a right to know.
Model Calibration and Improvement
Aggregated and de-identified candidate and participant data contributes to ongoing calibration and improvement of HiringBranch's shared assessment models. This raises scoring accuracy and fairness for all candidates and employers using the platform.
Before any data is used for this purpose, we de-identify it by removing direct identifiers such as name and email address (or Prolific ID, for participants), and we handle indirect identifiers to reduce the risk of re-identification, consistent with Quebec Law 25 and PIPEDA. We then aggregate it across many candidates and participants, so analysis happens at the population level rather than the individual level.
Voice recordings and text responses contribute to this process. Webcam video, where collected for proctoring, does not. We do not use proctoring video to train AI models.
Independent Bias Auditing
We commission annual independent third-party bias audits through BablAI to validate that our AI does not produce discriminatory outcomes across protected groups. We completed audits in 2025 and 2026. The audits apply the four-fifths rule and test for disparate impact across protected categories including race, ethnicity, sex, and intersectional combinations.
These audits satisfy New York City's Local Law 144, the most rigorous Automated Employment Decision Tool regulation currently in force in North America. We use them as evidence of fairness in every market we operate in, including Canada and the European Union. The audit reports are available to employers and can be reviewed by candidates, participants, and regulators on request.
Only aggregated and de-identified outcome data is shared with BablAI. We do not share identifiable candidate or participant information with BablAI for this purpose.
How This Applies Differently to Candidates, Learners, and Participants
For Candidates, the uses described in this section are secondary uses of data originally collected to deliver your individual assessment. Because the data is de-identified and aggregated before use, individual opt-out is not offered, consistent with Law 25 and PIPEDA's recognition of compatible secondary use of de-identified information.
The same compatible-secondary-use basis applies to Training learner data, unless an Institutional Customer's contract with HiringBranch specifies otherwise, for example, an educational institution may require its own opt-in consent from learners before their coursework responses are used for model calibration, given research-ethics or public-body obligations that may apply to it. Ask your Institutional Customer or our Privacy Officer which basis applies to your program.
For Research and Testing Participants recruited specifically to generate model-calibration or bias-audit data, this is the primary and disclosed purpose of the Study you accepted, not a secondary use, and your acceptance of the Study constitutes your consent to that specific use. Because this data trains and validates the same AI that produces real scores for job candidates elsewhere on our platform, your participation contributes to a system that affects other people's hiring outcomes, not only our own product testing. We will honour a withdrawal request you make before we de-identify and aggregate your data.
De-identification for this purpose may happen earlier than the standard retention period described in Section 8, so if you want to preserve your ability to withdraw, we encourage you to act promptly rather than assuming you have the full retention period to decide. Once de-identified and aggregated, individual withdrawal is no longer technically possible because the data can no longer be traced back to you.
Your Choices Around These Uses
If you have concerns about either of these uses, you can contact the Privacy Officer at privacy@hiringbranch.com to discuss your specific situation. You can also exercise any of the other rights described in Section 9, including declining the assessment or Study, withdrawing consent, and requesting deletion.
7. Where We Store Your Personal Information
If you are located in Canada, or the employer or testing project associated with your assessment is based in Canada, your identifiable personal information is stored and processed in Canada, using our subprocessors' Canadian infrastructure described in Section 5. It does not leave the country, other than the aggregated, de-identified bias-audit flow described below.
If you are located in the European Union or the European Economic Area, or the employer, Institutional Customer, or testing project associated with your assessment or Training is based there, your identifiable personal information is stored and processed in Germany, using our subprocessors' German infrastructure, and stays within the EU/EEA.
If you are located in the United Kingdom, or the employer, Institutional Customer, or testing project associated with your assessment or Training is based there, your identifiable personal information is also stored and processed in Germany, using the same German infrastructure. The UK's data protection authority recognizes the European Union as providing an adequate level of protection, so this storage location does not itself require additional transfer safeguards under UK data protection law.
If you are located elsewhere, or the employer, Institutional Customer, or testing project associated with your assessment or Training is based elsewhere, your identifiable personal information is stored and processed in Singapore or the United States, using our subprocessors' infrastructure in that region, under the contract between HiringBranch and that employer or Institutional Customer, or the region assigned to that testing project.
Because Canadian data stays in Canada and European and UK data stays within the EU/EEA, most candidates, Learners, and participants never have their identifiable information cross into a country with different privacy protections. Where identifiable information is stored in Singapore or the United States under this section, we rely on the transfer safeguards built into our subprocessors' standard agreements.
Both AWS and MongoDB Atlas are active, certified participants in the EU-U.S. Data Privacy Framework and its UK Extension, and both incorporate Standard Contractual Clauses into their standard data processing agreements, which apply where the Data Privacy Framework does not cover a particular transfer. For UK-originated personal information specifically, we rely on the UK Extension to the EU-U.S. Data Privacy Framework for transfers to the United States, and on the UK Addendum to the EU Standard Contractual Clauses, or an International Data Transfer Agreement, for transfers to Singapore, rather than the EU-only versions of those mechanisms.
Where a transfer involves personal information subject to Quebec Law 25, we also complete a privacy impact assessment confirming the destination provides protection recognized as equivalent before the transfer takes place, consistent with Section 17 of Law 25.
India's Digital Personal Data Protection Act 2023 uses a negative-list approach to cross-border transfers: transfers are permitted to any country except those the Indian government specifically restricts by notification. As of this notice, no such restriction list has been issued, so our transfers of information relating to India-located data subjects are not currently limited under this framework. We monitor for changes and will update this notice if a restriction list affecting our subprocessors is issued.
Aggregated and de-identified outcome data is also shared with BablAI in the United States for our annual independent bias audit, described in Section 6. Because this data is de-identified before transfer, it does not raise the same cross-border transfer obligations as identifiable data.
Operational subprocessors located outside Canada (Google Workspace, Intercom, Datadog) do not process candidate or participant assessment data.
For Research and Testing Participants, the storage region for your Study data is fixed by the Study's configuration and is identified for you on the Study's consent screen before you accept the Study, applying the same regional rules described above.
We will provide documentation about cross-border data flows on request to any candidate, Learner, or participant. If you are a Quebec resident and your information is ever stored or processed outside Canada, you may request a summary of the privacy impact assessment completed for that transfer, under Section 17 of Law 25.
8. How Long We Keep Your Personal Information
Our standard retention period for candidate, Learner, and Institutional Customer-identifiable data is twelve months from the date of your assessment or Training session, unless a different period is set out in our contract with the employer or Institutional Customer or requested by them, and you may request earlier deletion as described in Section 9.
Network, security, and application logs are retained for twelve months or longer where required for security investigations. Backups are retained for ninety days.
Aggregated and de-identified data already used for model improvement and bias auditing may be retained for those purposes, because once de-identified and aggregated it is no longer associated with any identifiable candidate, Learner, or participant, consistent with the standards recognized under Law 25 and PIPEDA.
When the employer's or Institutional Customer's contract with HiringBranch ends, they have a thirty-day window to export historical assessment or Training data. After the export window closes, all customer-identifiable data is permanently deleted from production systems, with deletion extending to backups according to our documented retention schedule. A certificate of destruction is available on request.
For data subjects located in India, we erase personal information as soon as it is reasonably practicable to do so once the purpose for which it was collected is no longer being served and retention is no longer required by law, consistent with India's Digital Personal Data Protection Act 2023, which operates alongside, and does not extend, the standard twelve-month period described above.
Research and Testing Participants
We retain identifiable data from a testing Study for the same standard twelve months as Candidate data, unless a shorter or longer period is set out in the contract for that Study or requested by the customer commissioning the Study, after which it is deleted, except for data already aggregated and de-identified for model improvement or bias-audit purposes, which we retain as described above.
The thirty-day employer export window described above applies only to Candidate data tied to an employer relationship, and has no equivalent for participants, since no employer is involved. Where a Study's primary purpose is model calibration or bias-audit data collection, the de-identification timing described in Section 6 controls over this standard period for purposes of your withdrawal right.
9. Your Rights
You have meaningful rights over your personal information. The list below applies to all candidates, Learners, and participants. Additional rights may apply depending on where you live.
- Right to be informed. To understand what personal information we collect, how we use it, how we share it, and how long we keep it. This notice exists to fulfill that right.
- Right to access. To request a copy of the personal information we hold about you, including your assessment results and explainability report, where applicable.
- Right to correction. To request that we correct inaccurate or incomplete personal information.
- Right to deletion. To request deletion of your candidate-, Learner-, or participant-identifiable data, subject to applicable legal exceptions.
- Right to withdraw consent. To withdraw your consent to the processing of your personal information at any time. Withdrawing consent during an assessment, Training session, or Study may prevent you from completing it.
- Right to human review of automated decisions (Hiring Assessments only). To request human review of any decision based on your assessment, and to receive an explanation of the principal factors that contributed to your result. Since no hiring or employment decision is made based on a Training session, this right applies specifically to Hiring Assessments.
- Right to portability. To receive your personal information in a structured, commonly used format, or to have it transmitted to another organization where technically feasible. This right is expressly recognized under GDPR and UK GDPR; Canadian federal and provincial privacy law does not currently codify a standalone portability right, but we will accommodate a portability request where technically feasible as a matter of practice.
- Right to object. To object to the processing of your personal information in certain circumstances, including direct marketing.
- Right to nominate (India only). If you are located in India, to nominate another individual to exercise your rights under the Digital Personal Data Protection Act 2023 on your behalf in the event of your death or incapacity, consistent with Section 14 of that Act.
- Right to make a complaint. To make a complaint about the processing of your personal information, either to us through our Privacy Officer or to your local privacy regulator. In Quebec, the regulator is the Commission d'acces a l'information (CAI). In other Canadian jurisdictions, the regulator is the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner. In the European Union, your national data protection authority. In the United Kingdom, the Information Commissioner's Office (ICO). In India, the Data Protection Board of India, once it is operational for complaint intake.
How to Exercise Your Rights
You can exercise any of these rights by contacting our Privacy Officer at privacy@hiringbranch.com, or, if you are a Candidate or Learner, by contacting the employer or Institutional Customer who invited you to the assessment or Training. We will respond within thirty days, consistent with Law 25, PIPEDA, and GDPR. We may verify your identity before fulfilling a request.
If you are a Research and Testing Participant, the channel depends on what the request concerns. For a request about your Study responses, contact our Privacy Officer at privacy@hiringbranch.com with your Prolific ID, since that is the data HiringBranch controls. For a request about your Prolific account, profile, demographic pre-screening answers, or payment, contact Prolific directly, since HiringBranch does not hold or control that information; Prolific can also help route a Study-data request to us if you are unsure which applies.
10. Consent
We obtain your consent on an opt-in basis before you take a Hiring Assessment or a Training session. Before you begin, we present this notice and require you to take an affirmative action to consent. Consent is not pre-checked or assumed.
Where webcam-enabled proctoring is used, we obtain a separate explicit opt-in for proctoring, because of the heightened consent obligations that apply to biometric-adjacent data under Law 25 and GDPR.
You may withdraw consent at any time by contacting our Privacy Officer at privacy@hiringbranch.com or the employer who invited you. We record consent timestamps and the version of the notice you consented to in audit logs.
Training
The consent screen you see before a Training session describes the purpose of that session, skills assessment and development, and states clearly that no hiring, promotion, discipline, or employment decision is made based on your results. It does not use Hiring Assessment language, since that would describe a use of your data that is not actually happening.
Research and Testing Participants
If you are a Research and Testing Participant, your consent is obtained through your acceptance of the Study listing on Prolific and the on-platform consent screen describing the purpose of that Study, including where the primary purpose is model calibration or bias-audit data collection as described in Section 6.
Compensation for taking part in a Study is handled and approved by Prolific under its own terms and payment schedule; HiringBranch does not process, approve, or issue your payment, though we may confirm your completion of a Study to Prolific to support that process.
A Note on India's Employment Exemption
India's Digital Personal Data Protection Act 2023 permits an employer to process an employee's personal information without consent for certain legitimate employment-related purposes, such as attendance or provisioning access, under Section 7(f) of that Act. That exemption is narrow and does not apply to our platform: it does not extend to a job candidate who has not yet been hired, or to a student or other Learner engaged through an educational Institutional Customer, since neither is in an existing employment relationship with the employer for the purpose of that processing. We obtain affirmative consent from Candidates and Learners as described above regardless of this exemption.
11. How We Protect Your Personal Information
We protect your personal information through layered technical, operational, and contractual controls.
- Encryption. All candidate and participant data is encrypted in transit using TLS and at rest using AES-256, end to end across our environment and during any transfer to subprocessors.
- Access controls. Access to the platform is secured by unique credentials per user with multi-factor authentication, role-based permissions, and full audit logging of access events. SSO is built in.
- Internal access restrictions. Internal access to candidate and participant data is restricted to authorized personnel on a need-to-know basis, gated by a documented request process with a stated reason, and recorded in audit logs.
- Infrastructure security. We host on AWS Canadian regions with primary storage in MongoDB Atlas Canada. Both hold SOC 2 Type II and ISO 27001 certifications.
- Independent validation. We maintain a current SOC 2 Type II certification covering security, availability, and confidentiality. We conduct annual third-party penetration testing through websec.ca. We commission annual independent bias audits through BablAI.
- Backup and continuity. We operate automated, encrypted backups and a documented business continuity and disaster recovery program.
No security program is perfect. We commit to maintaining strong protections, and to notifying affected parties promptly in the event of a confirmed breach, consistent with our obligations under Law 25, PIPEDA, and GDPR.
12. Breach Notification
If we experience a confirmed breach of security safeguards involving your personal information that creates a real risk of significant harm, we will notify you and the relevant privacy regulators in accordance with applicable law. Our breach management process follows a four-phase procedure of detect, contain, assess, and notify, overseen by our Incident Management Team, Senior Executive Team, and independent legal counsel.
For a breach involving personal information of a data subject located in India, we follow the notification standard under India's Digital Personal Data Protection Act 2023, which does not condition notification on a risk threshold: we notify the Data Protection Board of India within seventy-two hours of becoming aware of the breach, and we notify affected individuals without the significant-harm threshold applied elsewhere in this section.
13. Children
Our platform is primarily intended for adults applying for employment, taking part in research Studies, or engaged in workplace training. The age at which someone can use our platform without a parent or guardian's involvement depends on where they live: fourteen in Quebec, sixteen elsewhere in Canada, thirteen in the United Kingdom, and either thirteen or sixteen in the European Union depending on the specific member state. If you are located in India, we do not process a child's personal information (under eighteen) without verifiable parental consent.
Our Training feature is also used by Institutional Customers, including universities, whose student population may include individuals who are minors under one or more of these thresholds, for example, secondary-school partnership programs. In that context, HiringBranch relies on the Institutional Customer to verify age where required and to obtain any parental or guardian consent needed before a Learner begins Training, consistent with the Institutional Customer's own policies and legal obligations.
If you believe we have collected information from a minor without the appropriate consent, please contact our Privacy Officer and we will take appropriate steps to delete it.
14. Changes to This Notice
We may update this notice from time to time. When we make material changes, we will update the "Last Updated" date at the top, and where appropriate we will notify candidates, Learners, participants, and customers through reasonable means. Continued use of our website or platform after changes take effect constitutes acceptance of the updated notice.
15. Languages
This notice is published in English and Canadian French. If you are a Quebec resident, you have the right to receive this notice, exercise your rights, and take your assessment in French. The French version and the English version are intended to have the same meaning. In the event of any conflict, please contact our Privacy Officer for clarification.
If you are located in India, you may request a copy of this notice, or a summary of it, in English or in any language listed in the Eighth Schedule to the Constitution of India, consistent with Section 5(3) of the Digital Personal Data Protection Act 2023. Contact our Privacy Officer to make that request.
For users in the United Kingdom, the English version of this notice satisfies the transparency requirements under UK GDPR and the Data Protection Act 2018.
16. Contact Us
If you have any questions about this notice, want to exercise your rights, or want to make a complaint, please contact our Privacy Officer:
Eric Dofonsou, Privacy Officer
Email: privacy@hiringbranch.com
LearningBranch Inc., operating as HiringBranch
Eric Dofonsou also serves as our Grievance Officer for purposes of India's Digital Personal Data Protection Act 2023, and can be reached at the same email address for any grievance regarding your personal information under that Act.
EU and UK Representative
HiringBranch has no establishment in the European Union or the United Kingdom. Consistent with Article 27 of the GDPR and Article 27 of the UK GDPR, we have designated a representative you or your regulator can contact on matters relating to our processing of your personal information, in addition to contacting our Privacy Officer directly:
Eric Dofonsou, EU and UK Representative
Email: eric@hiringbranch.com
If you are not satisfied with our response, you have the right to lodge a complaint with your local privacy regulator, generally after first giving us a reasonable opportunity to address your concern. In Quebec, the Commission d'acces a l'information (CAI). In other Canadian jurisdictions, the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner. In the European Union, your national data protection authority. In the United Kingdom, the Information Commissioner's Office (ICO). In India, the Data Protection Board of India, once it is operational for complaint intake.




