bars icon

Legal

Privacy PolicyTerms of Use for EmployersTerms of Use for Applicant
Last Updated: 20-07-2026

1About this Privacy Policy

1.1 Who We Are and Purpose of This Privacy Policy

At Merit Finder, Inc. ("Merit Finder," "we," or "us"), we provide AI-driven recruitment and skills testing to help connect employers with talented applicants. We want to ensure that our users ("you"), whether acting as employers or applicants, are treated fairly and with dignity throughout the screening and hiring processes, especially when using our website.

For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the "EU GDPR") and the UK General Data Protection Regulation and Data Protection Act 2018 (the "UK GDPR" and, together with the EU GDPR, the "GDPR"), Merit Finder, Inc. is the controller of the personal data described in this Privacy Policy, except where this Privacy Policy states otherwise (see Section 1.4 on Employers as independent controllers).

Our contact details, and those of our representatives in the European Union and the United Kingdom appointed under Article 27 of the GDPR, are set out in Section 12 (Contacting Merit Finder).

The purpose of this Privacy Policy is to explain, in accordance with Articles 13 and 14 of the GDPR, what personal data we collect, why we collect it, the legal bases on which we process it, how long we keep it, with whom we share it, how we transfer it internationally, and the rights you have in relation to it.

1.2 What this Policy Covers

This Privacy Policy applies to personal data (meaning any information relating to an identified or identifiable natural person) that we collect when you visit our website, www.meritfinder.com (the "Website"), or that we collect in the course of providing our services, including job posting and skills testing, through the Website (the "Services").

1.3 What this Policy Does Not Cover

1.3.1Anonymised and Aggregated Information

In some cases, we may create and use aggregated or fully anonymised information that can no longer be linked to you, directly or indirectly. Such information is not personal data under the GDPR, and this Privacy Policy does not restrict our use of it. Where information is merely pseudonymised or de-identified but could still be attributed to you, it remains personal data and we will treat it in accordance with this Privacy Policy.

1.3.2Information You Disclose to Others; Employers as Independent Controllers

You may use the Services to communicate with other users or to share documents or other information containing your personal data, such as when uploading a CV or portfolio for review by an employer or responding to a voluntary disclosure form.

Employers who receive your personal data through the Services act as independent controllers of that data. Their processing of your personal data (for example, in the course of their recruitment decisions) is governed by their own privacy notices and by applicable data protection law, not by this Privacy Policy. We require employers, under our Terms of Use for Employers, to comply with applicable data protection laws, but we are not responsible for their independent processing of your personal data. We encourage you to review the privacy notice of any employer with whom you interact.

1.3.3Third-Party Websites and Social Media Features

We may provide links to third-party websites. Those sites may have their own privacy policies or similar policies or terms of use. This Privacy Policy does not govern, and we are not responsible for, those third parties' use of personal data.

1.3.4Use by Minors Not Permitted

The Website and our Services are not intended for persons under the age of 18, and we do not knowingly collect, use, or solicit personal data from persons under the age of 18, or allow them to use the Services. If you become aware that a person under 18 is using the Services, we encourage you to report this using the contact information set out in Section 12. We will delete any personal data we have collected about a person under the age of 18 if we become aware that we have collected it.

3Automated Decision-Making and Profiling

Our Services use automated processing, including AI-driven tools, to match applicants with potential jobs and to score skills tests. Employers — not Merit Finder — make their own decisions regarding interviewing and hiring.

Where any automated processing we carry out produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 of the GDPR, you have the right not to be subject to a decision based solely on automated processing, except where such a decision is necessary for the performance of a contract between you and us, is authorised by applicable law, or is based on your explicit consent. In those cases, you have the right to obtain human intervention, to express your point of view, and to contest the decision, using the contact details in Section 12. Meaningful information about the logic involved in our automated matching and scoring tools, and the significance and envisaged consequences of such processing, is available on request to [email protected].

4How We Share Personal Data (We Do Not Sell It)

We disclose personal data to the following categories of recipients:

  • Other users, including employers: for example, sharing an applicant's name, application, and test results with an employer for consideration for a job opening, at the applicant's request.
  • Service providers (processors): providers of hosting (located within the EEA), cloud infrastructure, payment processing, identity verification, analytics, and customer support services who process personal data on our behalf under contracts that comply with Article 28 GDPR.
  • Professional advisers: lawyers, auditors, and insurers where necessary.
  • Public authorities: where required by law or as described in Section 9 (disclosures to authorities).
  • Corporate transactions: a purchaser or prospective purchaser of our business, subject to appropriate safeguards.

We do not sell your personal data, and we do not disclose it to third parties for their own direct marketing purposes. It is a violation of our Terms of Use for users, including employers, to use personal data received through the Services for marketing purposes. If you believe another user is doing so, please contact us using the methods described in Section 12, and we will investigate and take remedial measures, which may include terminating that user's access to the Services.

5Where We Store Your Data and International Transfers

5.1 Data Residency in the EEA

Personal data collected through the Website and Services is stored in a database hosted within the European Economic Area ("EEA") in data center located in europe, and our routine processing to provide the Services takes place within the EEA. We host this data with AWS, which processes personal data on our behalf as our processor under a contract that complies with Article 28 GDPR.

5.2 International Transfers

Merit Finder, Inc. is established in the United States. Although your personal data is stored within the EEA, in limited circumstances our personnel or service providers located outside the EEA and the UK — including our operations in the United States — may access that data remotely in order to operate, support, secure, or improve the Services.

Where personal data is transferred to, or accessed from, a country that has not been found by the European Commission or the UK authorities to provide an adequate level of protection, we implement appropriate safeguards, including the European Commission's Standard Contractual Clauses and, for UK transfers, the UK International Data Transfer Addendum, together with supplementary technical and organisational measures where appropriate. Where applicable: Merit Finder participates in the EU-U.S. Data Privacy Framework, the UK Extension thereto, and the Swiss-U.S. Data Privacy Framework — NOTE TO CLIENT: confirm certification status; if certified, remote access from the U.S. may be covered by the DPF rather than SCCs. You may obtain a copy of the relevant safeguards by contacting us as described in Section 12.

6Data Retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, including to comply with legal, accounting, or reporting obligations and to establish, exercise, or defend legal claims. In general:

  • Account and profile data is retained for the life of your account and for 1 year following closure of your account;
  • Application and assessment data is retained for 1 year following the conclusion of the relevant application;
  • Biometric data processed for identity verification is deleted within 1 year;
  • Payment records are retained as required by applicable tax and accounting law;
  • Technical logs are retained for 1 year.

When retention is no longer necessary, we delete or anonymise the data. Further details of our retention periods are available on request.

7Your Rights

Subject to the conditions and exemptions set out in the GDPR, you have the following rights in relation to your personal data:

  • Access (Article 15): to obtain confirmation of whether we process your personal data and a copy of it;
  • Rectification (Article 16): to have inaccurate personal data corrected and incomplete data completed;
  • Erasure (Article 17): to have your personal data deleted in certain circumstances;
  • Restriction (Article 18): to restrict processing in certain circumstances;
  • Data portability (Article 20): to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible;
  • Objection (Article 21): to object to processing based on our legitimate interests, and to object at any time to processing for direct marketing purposes;
  • Withdrawal of consent (Article 7(3)): to withdraw any consent you have given at any time, without affecting the lawfulness of processing before withdrawal;
  • Rights relating to automated decision-making (Article 22): as described in Section 3.

You may exercise these rights free of charge by contacting us using the methods described in Section 12 and including "Personal Data Request" in the subject line. We may need to verify your identity before acting on a request, and may ask for additional information for that purpose. We will respond within one month of receiving your request; where a request is complex or we receive numerous requests, we may extend this period by up to two further months, in which case we will inform you of the extension and the reasons for it within the first month. Where requests are manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on the request, as permitted by Article 12(5) GDPR.

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement, or, in the United Kingdom, with the Information Commissioner's Office (www.ico.org.uk). We would appreciate the opportunity to address your concerns first, but you may contact a supervisory authority at any time.

8Data Security and Breach Notification

We use appropriate technical and organisational measures, in accordance with Article 32 GDPR, to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Personal data is stored in a database hosted within the EEA (see Section 5), and access is restricted to authorised personnel and processors on a need-to-know basis. However, no transmission of data over the internet or wireless networks can be guaranteed to be completely secure.

You should also take steps to protect your own personal data. Employers and job seekers are often the targets of scams and attempts to obtain personal data, login credentials, or other sensitive information. Please only disclose such information through private and secure channels, do not post it publicly, and verify the identity of anyone requesting information from you.

In the event of a personal data breach, we will comply with our obligations under Articles 33 and 34 GDPR, including notifying the competent supervisory authority without undue delay and, where required, within 72 hours of becoming aware of the breach, and informing you without undue delay where the breach is likely to result in a high risk to your rights and freedoms. If you believe that your login credentials or other personal data have been compromised, please contact us using the methods described in Section 12.

9Disclosures to Public Authorities

We may be required to disclose personal data in response to lawful requests from public authorities, including under court orders or other legal processes. We will disclose personal data to public authorities only where we have a legal obligation to do so or where disclosure is otherwise lawful under the GDPR, and we will make reasonable efforts to notify you of any such disclosure unless prohibited by law or by the terms of the legal process.

10Cookies and Similar Technologies

We use cookies and similar technologies on the Website. Where required by applicable law (including the ePrivacy Directive as implemented in EEA Member States and the UK Privacy and Electronic Communications Regulations), we will only place non-essential cookies with your consent, which you may give or refuse through our cookie banner and manage at any time through cookie settings.

11Changes to this Privacy Policy

We review our practices regarding personal data from time to time and may update this Privacy Policy. If we make material changes, we will notify you in advance using the email address associated with your account and/or by prominent notice on the Website, and we will indicate the date of the latest version at the top of this Privacy Policy. Where a change involves a new purpose of processing that requires your consent under the GDPR, we will seek that consent before the new processing begins; we will not treat your continued use of the Services as consent in those cases.

12Contacting MeritFinder

Email: [email protected] .

EU Representative (Article 27 EU GDPR): [email protected].

UK Representative (Article 27 UK GDPR): [email protected].

When you contact us to exercise your rights, we may request additional information to verify your identity, as described in Section 7.

Merit Finder, Inc.    © 2026 All Rights Reserved Worldwide