Legal
Security & Compliance
How candidate data is protected
Candidate information exists to run a fair hiring process - not to be sold or reused as a marketing list. Access is limited to the employer, HR, or institution workspace that owns the role or cohort, and to OptioHire staff who need it to operate or support the product. Outcome messages and scores stay inside that process so a candidate is not left without a record of what happened.
Access controls for HR and employer accounts
Workspaces use authenticated accounts and role-based permissions so team members only see the jobs and candidates their role requires. Shared review on a listing is intentional; open access across unrelated departments is not. Session handling and authentication are designed to keep hiring data inside the right team.
Data storage and encryption practices
Data is encrypted in transit and at rest. We collect what the hiring workflow needs, store it on contracted infrastructure, and back it up as part of normal operations. Retention follows the privacy policy: keep records while the process needs them, then delete or anonymise.
Reporting a security concern
If you believe you have found a security issue, contact us at developer@optiohire.com or through the contact form so we can investigate. Please include enough detail to reproduce the concern, and avoid sharing unrelated candidate files unless we ask for them.


