1About this Privacy Policy
1.1 Who We Are and Purpose of This Privacy Policy
At Merit Finder, Inc. ("Merit Finder," "we," or "us"), we provide AI-driven recruitment and skills testing to help connect employers with talented applicants. We want to ensure that our users ("you"), whether acting as employers or applicants, are treated fairly and with dignity throughout the screening and hiring processes, especially when using our website.
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the "EU GDPR") and the UK General Data Protection Regulation and Data Protection Act 2018 (the "UK GDPR" and, together with the EU GDPR, the "GDPR"), Merit Finder, Inc. is the controller of the personal data described in this Privacy Policy, except where this Privacy Policy states otherwise (see Section 1.4 on Employers as independent controllers).
Our contact details, and those of our representatives in the European Union and the United Kingdom appointed under Article 27 of the GDPR, are set out in Section 12 (Contacting Merit Finder).
The purpose of this Privacy Policy is to explain, in accordance with Articles 13 and 14 of the GDPR, what personal data we collect, why we collect it, the legal bases on which we process it, how long we keep it, with whom we share it, how we transfer it internationally, and the rights you have in relation to it.
1.2 What this Policy Covers
This Privacy Policy applies to personal data (meaning any information relating to an identified or identifiable natural person) that we collect when you visit our website, www.meritfinder.com (the "Website"), or that we collect in the course of providing our services, including job posting and skills testing, through the Website (the "Services").
1.3 What this Policy Does Not Cover
1.3.1Anonymised and Aggregated Information
In some cases, we may create and use aggregated or fully anonymised information that can no longer be linked to you, directly or indirectly. Such information is not personal data under the GDPR, and this Privacy Policy does not restrict our use of it. Where information is merely pseudonymised or de-identified but could still be attributed to you, it remains personal data and we will treat it in accordance with this Privacy Policy.
1.3.2Information You Disclose to Others; Employers as Independent Controllers
You may use the Services to communicate with other users or to share documents or other information containing your personal data, such as when uploading a CV or portfolio for review by an employer or responding to a voluntary disclosure form.
Employers who receive your personal data through the Services act as independent controllers of that data. Their processing of your personal data (for example, in the course of their recruitment decisions) is governed by their own privacy notices and by applicable data protection law, not by this Privacy Policy. We require employers, under our Terms of Use for Employers, to comply with applicable data protection laws, but we are not responsible for their independent processing of your personal data. We encourage you to review the privacy notice of any employer with whom you interact.
1.3.3Third-Party Websites and Social Media Features
We may provide links to third-party websites. Those sites may have their own privacy policies or similar policies or terms of use. This Privacy Policy does not govern, and we are not responsible for, those third parties' use of personal data.
1.3.4Use by Minors Not Permitted
The Website and our Services are not intended for persons under the age of 18, and we do not knowingly collect, use, or solicit personal data from persons under the age of 18, or allow them to use the Services. If you become aware that a person under 18 is using the Services, we encourage you to report this using the contact information set out in Section 12. We will delete any personal data we have collected about a person under the age of 18 if we become aware that we have collected it.
2Personal Data We Collect, Purposes, and Legal Bases
2.1 Categories of Personal Data
When you visit the Website or use the Services, we may collect the following categories of personal data:
- Identity Data: name; usernames or aliases (including social media aliases); photo ID information (including from a driver's licence, passport, or other photo ID); and, subject to Section 2.3, biometric data such as facial recognition data.
- Profile Data: usernames or aliases; email address; telephone number; payment account information (for employers).
- Contact Data: home or mailing address; email address; telephone number.
- Technical Data: IP address; web browser and session information; browser activity; session activity such as device input recording.
- Application and Assessment Data: CVs, portfolios, applications, skills test responses, test results and scores, and communications submitted through the Services.
2.2 Purposes and Legal Bases for Processing
The GDPR requires us to have a legal basis under Article 6 for each purpose for which we process your personal data. We process your personal data for the following purposes and on the following legal bases:
- Account creation and maintenance (creating and administering user accounts; authenticating users): performance of a contract with you (Article 6(1)(b) GDPR).
- Providing the Services (matching applicants with potential jobs; delivering and scoring skills tests; making applicant information available to employers at the applicant's request; facilitating communications between users): performance of a contract with you (Article 6(1)(b) GDPR).
- Identity verification and test integrity (verifying your identity in connection with proctored skills tests, including, where you choose this option, comparison of your photo ID with images captured by your camera): your explicit consent (Article 6(1)(a) and, for biometric data, Article 9(2)(a) GDPR) — see Section 2.3.
- Payments (processing payments from employers, invoicing, and related record-keeping): performance of a contract (Article 6(1)(b) GDPR) and compliance with legal obligations such as tax and accounting laws (Article 6(1)(c) GDPR).
- Improving and maintaining the Website and Services (operating, maintaining, securing, debugging, and improving the Website and Services): our legitimate interests in operating, securing, and improving our business (Article 6(1)(f) GDPR). For example, we process IP addresses to detect irregular or suspicious activity, such as a distributed denial-of-service attack.
- Safety, security, and legal compliance (preventing fraud and misuse; enforcing our Terms of Use; establishing, exercising, or defending legal claims; complying with legal obligations, including responding to lawful requests from public authorities): compliance with legal obligations (Article 6(1)(c) GDPR) and our legitimate interests in protecting our business and our users (Article 6(1)(f) GDPR).
- Communications (responding to your enquiries; notifying you of changes to the Services, this Privacy Policy, or the applicable Terms of Use): performance of a contract (Article 6(1)(b) GDPR) and our legitimate interests in communicating with our users (Article 6(1)(f) GDPR).
Where we rely on our legitimate interests, we have assessed that those interests are not overridden by your interests or fundamental rights and freedoms. You may object to processing based on legitimate interests as described in Section 7.
Where we rely on your consent, you may withdraw it at any time as described in Section 7, without affecting the lawfulness of processing carried out before withdrawal.
2.3 Special Categories of Personal Data and Biometric Data
Certain data we process is subject to additional protection under Article 9 of the GDPR ("special category data"). We process special category data only in the following circumstances:
2.3.1Biometric data for identity verification. Where you take a proctored skills test, we may offer identity verification that involves processing biometric data (facial recognition data) to compare your photo ID with images captured by your camera. We will only process biometric data for this purpose with your explicit consent (Article 9(2)(a) GDPR). If you do not wish to provide biometric data, As an alternative verification method, you may request a manual review of your photo ID by our trained verification team. To use this service, please contact us at [email protected], and declining biometric verification will not, by itself, prevent you from using the Services.
2.3.2Voluntary diversity and similar disclosures. Employers may invite you to provide, on an entirely voluntary basis, information such as health or disability status, sexual orientation, or racial or ethnic origin. We process such data only with your explicit consent (Article 9(2)(a) GDPR), and only to transmit it to the requesting employer and, where you separately consent, to use it in aggregated and anonymised form to understand and improve how our Services serve different populations. Choosing not to provide this information will not affect your ability to use the Services or apply for any job.
2.3.3Citizenship and immigration status. Where an employer requires information regarding your right to work in a particular region, we may collect information regarding your citizenship or immigration status and disclose it to that employer. We process this data on the basis of your explicit consent and, where applicable, reasons of substantial public interest in verifying eligibility to work under applicable law.
We do not use special category data for the training of machine learning models in identifiable form.
2.4 Where Provision of Personal Data is Required
Some personal data is required for us to enter into or perform our contract with you (for example, the data needed to create an account) or is required by law. If you do not provide that personal data, we may be unable to provide you with some or all of the Services. We will tell you at the point of collection where the provision of particular data is mandatory. We do not make your access to the Services conditional on consent to processing that is not necessary for providing the Services.
3Automated Decision-Making and Profiling
Our Services use automated processing, including AI-driven tools, to match applicants with potential jobs and to score skills tests. Employers — not Merit Finder — make their own decisions regarding interviewing and hiring.
Where any automated processing we carry out produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 of the GDPR, you have the right not to be subject to a decision based solely on automated processing, except where such a decision is necessary for the performance of a contract between you and us, is authorised by applicable law, or is based on your explicit consent. In those cases, you have the right to obtain human intervention, to express your point of view, and to contest the decision, using the contact details in Section 12. Meaningful information about the logic involved in our automated matching and scoring tools, and the significance and envisaged consequences of such processing, is available on request to [email protected].
5Where We Store Your Data and International Transfers
5.1 Data Residency in the EEA
Personal data collected through the Website and Services is stored in a database hosted within the European Economic Area ("EEA") in data center located in europe, and our routine processing to provide the Services takes place within the EEA. We host this data with AWS, which processes personal data on our behalf as our processor under a contract that complies with Article 28 GDPR.
5.2 International Transfers
Merit Finder, Inc. is established in the United States. Although your personal data is stored within the EEA, in limited circumstances our personnel or service providers located outside the EEA and the UK — including our operations in the United States — may access that data remotely in order to operate, support, secure, or improve the Services.
Where personal data is transferred to, or accessed from, a country that has not been found by the European Commission or the UK authorities to provide an adequate level of protection, we implement appropriate safeguards, including the European Commission's Standard Contractual Clauses and, for UK transfers, the UK International Data Transfer Addendum, together with supplementary technical and organisational measures where appropriate. Where applicable: Merit Finder participates in the EU-U.S. Data Privacy Framework, the UK Extension thereto, and the Swiss-U.S. Data Privacy Framework — NOTE TO CLIENT: confirm certification status; if certified, remote access from the U.S. may be covered by the DPF rather than SCCs. You may obtain a copy of the relevant safeguards by contacting us as described in Section 12.
6Data Retention
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, including to comply with legal, accounting, or reporting obligations and to establish, exercise, or defend legal claims. In general:
- Account and profile data is retained for the life of your account and for 1 year following closure of your account;
- Application and assessment data is retained for 1 year following the conclusion of the relevant application;
- Biometric data processed for identity verification is deleted within 1 year;
- Payment records are retained as required by applicable tax and accounting law;
- Technical logs are retained for 1 year.
When retention is no longer necessary, we delete or anonymise the data. Further details of our retention periods are available on request.
7Your Rights
Subject to the conditions and exemptions set out in the GDPR, you have the following rights in relation to your personal data:
- Access (Article 15): to obtain confirmation of whether we process your personal data and a copy of it;
- Rectification (Article 16): to have inaccurate personal data corrected and incomplete data completed;
- Erasure (Article 17): to have your personal data deleted in certain circumstances;
- Restriction (Article 18): to restrict processing in certain circumstances;
- Data portability (Article 20): to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible;
- Objection (Article 21): to object to processing based on our legitimate interests, and to object at any time to processing for direct marketing purposes;
- Withdrawal of consent (Article 7(3)): to withdraw any consent you have given at any time, without affecting the lawfulness of processing before withdrawal;
- Rights relating to automated decision-making (Article 22): as described in Section 3.
You may exercise these rights free of charge by contacting us using the methods described in Section 12 and including "Personal Data Request" in the subject line. We may need to verify your identity before acting on a request, and may ask for additional information for that purpose. We will respond within one month of receiving your request; where a request is complex or we receive numerous requests, we may extend this period by up to two further months, in which case we will inform you of the extension and the reasons for it within the first month. Where requests are manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act on the request, as permitted by Article 12(5) GDPR.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement, or, in the United Kingdom, with the Information Commissioner's Office (www.ico.org.uk). We would appreciate the opportunity to address your concerns first, but you may contact a supervisory authority at any time.
8Data Security and Breach Notification
We use appropriate technical and organisational measures, in accordance with Article 32 GDPR, to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Personal data is stored in a database hosted within the EEA (see Section 5), and access is restricted to authorised personnel and processors on a need-to-know basis. However, no transmission of data over the internet or wireless networks can be guaranteed to be completely secure.
You should also take steps to protect your own personal data. Employers and job seekers are often the targets of scams and attempts to obtain personal data, login credentials, or other sensitive information. Please only disclose such information through private and secure channels, do not post it publicly, and verify the identity of anyone requesting information from you.
In the event of a personal data breach, we will comply with our obligations under Articles 33 and 34 GDPR, including notifying the competent supervisory authority without undue delay and, where required, within 72 hours of becoming aware of the breach, and informing you without undue delay where the breach is likely to result in a high risk to your rights and freedoms. If you believe that your login credentials or other personal data have been compromised, please contact us using the methods described in Section 12.
11Changes to this Privacy Policy
We review our practices regarding personal data from time to time and may update this Privacy Policy. If we make material changes, we will notify you in advance using the email address associated with your account and/or by prominent notice on the Website, and we will indicate the date of the latest version at the top of this Privacy Policy. Where a change involves a new purpose of processing that requires your consent under the GDPR, we will seek that consent before the new processing begins; we will not treat your continued use of the Services as consent in those cases.
12Contacting MeritFinder
Email: [email protected] .
EU Representative (Article 27 EU GDPR): [email protected].
UK Representative (Article 27 UK GDPR): [email protected].
When you contact us to exercise your rights, we may request additional information to verify your identity, as described in Section 7.
