Global privacy Notice

Last updated: May 26, 2025

Emprofy.com Terms of Use 

Emprofy.com Global Privacy Notice and Data Handling Standard 

Organization details and contacts 
Controller/Business: PureVi Tech Solutions Inc. (Ontario, Canada) Brand/Product: emprofy.com (rebranding from ReferenceCheck.online) Registered address: 1900 City Park Dr, Suite 300 Ottawa, ON, Canada  Privacy Officer / DPO:  privacy@emprofy.com Effective date: 01 January 2026 Last updated: 01 January 2026 Version: 1.2 
Scope and roles 
This notice applies to candidates/students, referees, organization users, and visitors.  Role matrix (operational): – Candidate accounts & referee submissions: PureVi is the controller/business for operating emprofy.com, providing candidate-controlled sharing features, fraud prevention, and platform security. – Organization customer use (recruitment/verification): For candidate data processed on behalf of a subscribing organization, PureVi is a processor/service provider under the DPA, and the organization is the controller/business for its hiring/verification decisions. Processor obligations are governed by GDPR-style processor contract requirements where applicable. [50] 
Data collection and sources 
We collect personal information in these ways: – Directly from candidates/students and organization users during account creation and use. – From referees when they submit references. – From integrations (e.g., ATS/HR systems) when enabled by an organization. – Automatically through logs and cookies/SDKs for security and analytics.  For individuals whose personal data we obtain indirectly (e.g., candidate information contained in a referee reference, or institutional verification), we provide notices consistent with applicable requirements (including GDPR Art. 14 timing/content where applicable). [32] 
Processing table (GDPR legal basis + global purpose mapping) 
Use this table as the “single source of truth.” It also supports CCPA notice-at-collection and retention disclosure requirements. [51] 
Data category  Typical data elements  Source  Primary purposes  GDPR lawful basis (EU only)  Default retention 
Candidate identity & account  Name, email, phone, country, DOB (if collected), IDs (if uploaded)  Candidate  Account creation; authentication; candidate-controlled sharing  Contract (Art. 6(1)(b)); legitimate interests for security (Art. 6(1)(f)) [52]  While account active; deletion within 30 days of verified deletion request; backups expire in 90 days 
Employment/academic documents  Letters, transcripts, certificates  Candidate / institution (if enabled)  Store evidence profile; share with orgs per candidate instruction  Contract; consent where required for specific sharing  While candidate retains; hard delete within [30] days after removal; backup expiry [90] days 
References and feedback  Referee name/contact, relationship, ratings, free-text  Referee  Provide reference checking feature; integrity/fraud prevention  Contract; legitimate interests; consent where required; respond to access rights with lawful exceptions  References retained while candidate account active unless deleted; post-deletion backups expire [90] days   
Organization account & billing  Org name, users, billing contact, invoices  Organization user  Subscription management; invoicing; support  Contract; legal obligation for tax/accounting  Invoices retained 7 years subject to law 
Usage/security logs  IP, device/browser, event logs  Automatic  Security, fraud prevention, debugging, service reliability  Legitimate interests; legal obligation where required  Security logs retained 24 months 
Cookies/analytics  Cookie IDs, telemetry  Automatic  Essential service features; analytics (if enabled); marketing (if enabled)  Consent where required (EU/UK)  Consent record retained 24 months; cookie durations per inventory 
AI processing inputs/outputs  Document/reference text submitted for summarization; summary outputs  Candidate/referee content  Generate summaries/analytics; flag potential integrity issues  Contract; legitimate interests; consent where required  AI inputs/outputs retained in line with the underlying record; AI provider retention per contract 
Sharing, disclosures, and candidate-controlled access 
Candidate sharing is permission-based: organizations only access candidate records that the candidate actively shares. If a candidate revokes access, Emprofy stops further access from within the platform; organizations may retain copies they lawfully exported as controllers/businesses (this must be disclosed clearly). (This aligns to CCPA transparency on disclosures and GDPR recipient transparency.) [39]  We disclose data to service providers/sub-processors only under written agreements and for limited purposes. Under GDPR processor relationships, sub-processing must be governed by contract controls. [11] 
International transfers 
Where personal data is transferred across borders: – For GDPR-covered transfers, we use lawful transfer tools (e.g., SCCs where appropriate safeguards are required) and apply supplementary measures/TIAs when needed. [26] – For Australia, before disclosing personal information to overseas recipients, we take reasonable steps consistent with APP 8. [13] – For Canada, cross-border processing is permitted, but we remain accountable through contracts and oversight. [27] 
Data retention and deletion 
We retain personal information only as long as necessary and as disclosed in the Processing Table and the Retention Schedule. GDPR requires storage limitation as a principle, and CCPA requires retention period/criteria disclosure at collection. [53]  A documented legal hold process may suspend deletion where required by law, dispute, or security investigations. 
Security 
We maintain reasonable and appropriate security measures, including encryption in transit, encryption at rest, strong access controls, logging/monitoring, and secure development practices. GDPR requires risk-appropriate security measures (Art. 32). [18] California requires reasonable security procedures/practices for certain PI contexts. [19] PIPEDA requires safeguards appropriate to sensitivity. [20] APP 11 requires reasonable steps to protect PI. [21] 
Individual rights and request handling 
We support rights according to location and role: 
  • EU/EEA/UK: rights include access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making; responses within one month (extendable). [54] 
  • California: rights include right to know, delete, correct; response generally within 45 days (extendable). [15] 
  • Canada (PIPEDA): access typically within 30 days (limited extensions), correction, and withdrawal of consent where applicable. [55] 
  • Australia: access and correction rights under APP 12/13, with response within a reasonable period (~30 days is considered reasonable by OAIC). [48] 
Requests can be submitted at: [privacy@emprofy.com] and via in-app tools where available. We verify identity as required and support authorized agents/representatives where applicable. 
AI, profiling, and human review 
We may use AI tools to generate summaries or integrity indicators from submitted documents and references. Where profiling/automated processing is used in a manner that materially affects individuals, transparency and data subject rights requirements apply (including disclosures under GDPR Art. 14 and restrictions under Art. 22 for solely automated significant decisions). [56] Recommended operational commitment: Emprofy does not make hiring decisions; organization customers are responsible for their employment decisions, and Emprofy provides tools designed to support human review. 
Breach notification 
When an incident involves personal information, we follow a documented incident response plan and comply with legal notification duties: – GDPR supervisory authority notification within 72 hours where required. [22] – California consumer notification within 30 calendar days under Civ. Code §1798.82 (subject to statutory exceptions/delay). [23] – PIPEDA reporting/notification for breaches posing real risk of significant harm and breach recordkeeping obligations. [57] – OAIC NDB notification where serious harm is likely. [25] 
Emprofy | The Global Career Passport