Skip to content

Privacy policy

Privacy practices built for accountable hiring

This policy explains what Itya processes, why we process it, who can access it, and the choices available to candidates and workspace members.

Effective
July 9, 2026
Last updated
September 2, 2026

At a glance

A short summary of the complete document below.

Purpose-limited
Hiring data is used to deliver, secure, and support the workflows you request.
Human-controlled
Organizations control access and remain responsible for hiring decisions.
Rights-ready
Verified export and deletion workflows make privacy requests traceable.

Scope and our role

This Privacy Policy applies to Itya websites, applications, interview-workflow services, and support channels that link to it. It covers information about workspace members, candidates, interview participants, visitors, and people who contact us.

When an organization uses Itya for hiring, that organization normally decides why and how candidate and interview information is processed. In that context, the organization is the controller or business and Itya acts as its processor or service provider. Itya may act as a controller for account administration, billing, security, and direct communications.

Your employer, recruiter, or prospective employer may provide an additional privacy notice. Their notice governs the hiring decisions and practices they control.

Information we handle

The information we process depends on how you and your organization use Itya:

  • Account and workspace details: names, business email addresses, roles, organization settings, authentication events, and preferences.
  • Hiring and interview content: candidate profiles, job context, scheduling details, meeting attendance, consent states, recordings when enabled, transcripts, notes, scorecards, debriefs, and follow-up tasks.
  • Technical and usage data: device, browser, IP address, session, diagnostic, feature-usage, integration-health, and audit-log information.
  • Commercial and support data: subscription, invoice, billing-contact, support-request, and related correspondence.
  • Connected-service data: information authorized from calendars, meeting platforms, applicant tracking systems, messaging tools, and other integrations.

Interview content can include sensitive information volunteered during a conversation. Organizations and interviewers should avoid requesting or entering information that is not necessary for a fair, job-related evaluation.

How we use information

We process information to:

  • Provide, operate, maintain, and support Itya and its connected workflows.
  • Authenticate users, enforce workspace permissions, prevent abuse, and keep audit records.
  • Deliver requested interview features such as capture, transcription, search, debriefs, scorecards, reminders, and value reporting.
  • Manage trials, subscriptions, usage limits, invoices, and customer support.
  • Diagnose reliability issues and improve accessibility, safety, and product performance.
  • Meet legal obligations and enforce our agreements.

We do not use candidate interview content for behavioral advertising. Where we rely on consent, you may withdraw it subject to applicable law and the organization's retention obligations.

AI-assisted processing

Itya can use automated systems to transcribe interviews, organize evidence, draft summaries, map content to configured rubrics, and suggest follow-up work. These features assist human reviewers; they do not replace the organization's responsibility for hiring decisions.

Workspace members should review AI-assisted output for accuracy, relevance, unsupported claims, and inappropriate use of protected or sensitive information before relying on or sharing it. Provider access is limited to what is needed to deliver configured features and is governed by applicable service-provider terms and safeguards.

Sharing and disclosures

We may disclose information to:

  • Authorized members and administrators of the relevant workspace.
  • Infrastructure, hosting, communications, analytics, payment, support, security, and AI service providers working for us under appropriate obligations.
  • Integrations and third parties that a workspace administrator chooses to connect.
  • Advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or complete a corporate transaction.

We do not sell candidate interview content. Workspace administrators control which members and connected services can access their organization's records.

Retention and deletion

Interview recordings, transcripts and uploaded candidate files expire on the workspace's retention policy. The default is 30 days, and a workspace administrator can set it anywhere from 7 to 365 days. The deletion deadline for a recording is fixed at the moment consent is captured, from the policy then in force, so a later policy change cannot extend the life of an interview a candidate has already sat.

Here is the full default per data class.

Default retention period for each class of data Itya holds, whether it is configurable, and what enforces it.
Data classDefault retentionConfigurableWhat enforces it
Account and profile recordsRetained for the life of the account.Not configurable.A requested account deletion runs after a 14-day cooling-off window, during which signing in cancels it.
Candidate profiles and application recordsRetained until deletion is requested or the workspace is closed.Deleted on request; no automatic expiry.Candidates can request erasure through the public data-request flow; administrators can delete a candidate directly.
Resumes and uploaded candidate files30 days7–365 days, per workspaceThe hourly retention sweep deletes expired rows and hands the stored objects to a durable deletion janitor.
Interview recordings and captured audio30 days7–365 days, per workspaceThe deletion deadline is fixed at consent time from the retention policy then in force, so a later policy change cannot extend it.
Interview transcripts30 days7–365 days, per workspaceSame consent-time deadline as the recording the transcript came from.
AI scorecards and debriefsRetained until deletion is requested or the workspace is closed.Deleted on request; no automatic expiry.A scorecard is the hiring decision record. Erasing a candidate removes their scorecards with the rest of their record.
Audit logsRetained for the life of the workspace.Not configurable; exportable by administrators.Audit records evidence who did what. They are not expired automatically, and are removed when the workspace is deleted.
Product analytics snapshots90 daysNot configurable.A daily sweep deletes analytics snapshots older than 90 days.
Application logs30 daysNot configurable.Enforced by log rotation on the host.
Support requestsRetained until deletion is requested or the workspace is closed.Deleted on request; no automatic expiry.Kept so a reopened issue still has its history.
Billing and invoice recordsRetained as long as tax and accounting law requires, typically 7 years.Not configurable.Billing webhook payloads, which carry billing contact details, are purged after 90 days once processed.
Data-export downloads7 daysNot configurable.An export produced for a data request expires 7 days after it is generated.
Encrypted backupsAt least 30 daysDeployment-configurable, with a 30-day floor.A deletion is applied to live systems immediately and works through backups as they roll off.

Deletion may be delayed where a record is under legal hold, is needed for a live security investigation, or is subject to another lawful obligation. If that applies to something you asked us to delete, we will tell you and tell you why. A deletion is applied to live systems first and works through encrypted backups as those backups expire on their normal cycle.

Security and international transfers

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, encryption, monitoring, and audit logging. No method of transmission or storage is completely secure, so customers should also configure roles, integrations, and retention carefully.

Itya and its providers may process information in countries other than your own. Where required, we use contractual or other recognized safeguards for international transfers and make additional information available during a customer security review.

Your rights and choices

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to appeal or complain to a regulator. Identity verification may be required before we complete a request.

If a customer organization controls the record, we may route the request to that organization or assist it in responding. You can start with our verified data-request workflow or contact us using the details below. You can manage product communications through the message or workspace preference where available.

Cookies and local storage

We use cookies and similar browser storage that are necessary for authentication, security, locale, theme, preferences, and reliable operation. We may also use limited measurement data to understand performance and feature adoption. Browser controls can remove stored data, but disabling necessary storage may prevent parts of Itya from working.

United States state privacy rights

This section applies to residents of California and of other US states with a comprehensive consumer privacy law. For personal information Itya processes on a customer's behalf, Itya is a service provider (a “processor” in most other states) and the customer organisation is the business. Requests about that data are routed to the customer.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months, including for consumers under 16. We do not use or disclose sensitive personal information for any purpose beyond those permitted without a right to limit.

Categories collected. Identifiers (name, email, phone, account and device identifiers, IP address); customer records (employment and education history in a resume, professional information); professional or employment-related information (interview responses, evaluations, hiring decisions); internet activity (product usage and audit events); audio and visual information (consented interview recordings and the transcripts made from them); and commercial information (subscription and billing records). Inferences are limited to the AI-drafted evaluations a human reviews before use.

Sources. You, when you create an account or submit an application; the customer organisation that entered your record; systems the customer connects at its own direction; and the service itself as you use it.

Purposes. To provide, secure, support and improve the service; to run the hiring workflow the customer configured; to bill; to detect and prevent abuse; and to comply with law. We disclose personal information for a business purpose only to the service providers named on our subprocessor list, each under a contract that restricts them to that purpose.

Your rights. Subject to verification and to the exceptions in the applicable law, you may request to know the categories and specific pieces of personal information we hold, to access a portable copy, to correct inaccurate information, to delete it, and to opt out of sale or sharing — which for Itya requires nothing, because neither happens. To exercise any of them, use the verified data-request flow or email legal@itya.ai. An authorised agent may act for you with written permission and proof of identity.

We answer within 45 days and may extend once by a further 45 days with notice. If we decline, we will say why and how to appeal; an appeal is decided within 45 days.

Non-discrimination. We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right. We run no financial-incentive programme tied to personal information.

Children, updates, and contact

Itya is a business hiring service and is not directed to children. Do not use the service to collect children's information unless your organization has confirmed a lawful, age-appropriate process and Itya has agreed to support it.

We may update this policy as the service, law, or our practices change. We will update the date above and provide additional notice when a material change requires it. Contact security@itya.ai with privacy or data-protection questions.

A privacy question should have a clear route

Reach our security and privacy team or start a verified data request.

Email security@itya.ai and include enough context for us to route your question. Do not include passwords, API keys, or unnecessary candidate information.