Privacy Policy
Canada and United States
1. Introduction, scope, and roles
This Privacy Policy (the "Policy") explains how HyreMynd AI Inc. ("HyreMynd", "we", "us", or "our"), an Ontario corporation, collects, uses, discloses, retains, and protects personal information. It covers the HyreMynd platform, the Workplace Fit Assessment, the applicant, candidate and team portals, the HyreMynd browser extension, our websites, and related services (together, the "Platform"). An "Employer" is an organization that subscribes to the Platform under an order form, online subscription terms or signed agreement with HyreMynd (its "Customer Agreement").
This Policy applies to individuals in Canada and the United States whose personal information we process:
- applicants who create an independent account, complete a self-service assessment or apply to a role;
- candidates in an Employer's hiring process, whether they applied or were invited;
- people an Employer finds through the browser extension or open-web sourcing, or imports as contacts, who may never have applied or been contacted;
- referees a candidate names, and other people whose details appear in hiring correspondence;
- employees and managers of an Employer who complete an Assessment for the Employer's team;
- authorized users who use the Platform on an Employer's behalf;
- prospective clients who send a contact or demonstration enquiry, and visitors to our websites.
This Policy is incorporated by reference into the Candidate Terms of Use, the Internal Team Terms of Use and the Platform Terms of Service, and applies alongside an Employer's Customer Agreement and the Data Processing Addendum.
1.1 How the Platform uses rules and AI
The Workplace Fit Assessment does not use AI to score answers. Forced-choice answers are converted into A, B or C working-style positions by fixed majority rules, with ties treated as balanced. Comparisons with a role, a manager and a team, and the outcome categories drawn from them, are computed from those positions by fixed rules. An AI model may then write an explanation of those results; it cannot change them.
AI models are also used elsewhere in the Platform: to read a résumé or professional profile against a role's posted requirements and propose a reading of each requirement and a qualification category (match, worth a conversation, or doesn't fit); to read public pages found by open-web sourcing; to draft assistant replies and correspondence; and to draft interview notes from an existing transcript. Generated text can be incomplete or wrong, and rule-based results depend on limited inputs and design choices. None of these outputs is a diagnosis or a scientifically validated measure of personality or ability. A person reviews the underlying evidence and makes every employment decision.
1.2 Our role
The Employer controls the hiring records it directs: applications, contact records, the assessments of candidates and team members it invites, interview content, references, correspondence, notes and sourcing results. HyreMynd processes those records for the Employer under its documented, lawful instructions. Hiring, rejecting or archiving a candidate, or the end of an individual's employment, does not change who controls a record. HyreMynd controls account administration, security, and the independent account and self-service assessment of an applicant. A self-service sitting can outlive any one Employer's role; when it is used in an application, that use is a separate purpose controlled by the Employer that receives it.
Requests about employer-directed records are handled with the Employer as controller; requests about accounts, security and independent self-service data are handled by HyreMynd as controller. Section 10 explains how.
2. Applicable law
2.1 Canada
Applicable Canadian requirements include PIPEDA and relevant provincial privacy and language laws, including Quebec's Law 25. Bill C-27 of the 44th Parliament was not enacted and is not treated as an in-force requirement. Which law applies depends on the actual purpose and population.
2.2 United States
For U.S. residents, HyreMynd designs its practices to comply, where applicable, with section 5 of the Federal Trade Commission Act, Title VII of the Civil Rights Act as applied by the Equal Employment Opportunity Commission to automated hiring tools, the California Consumer Privacy Act as amended by the California Privacy Rights Act, including its regulations on automated decision-making technology and risk assessments, the Illinois Biometric Information Privacy Act, the Illinois Human Rights Act as amended effective January 1, 2026, New York City Local Law 144 governing automated employment decision tools, the Colorado Privacy Act and Colorado artificial intelligence legislation as in force, the Connecticut Data Privacy Act and the Connecticut Artificial Intelligence Responsibility and Transparency Act as its provisions phase in, the Texas Data Privacy and Security Act and the Texas Responsible Artificial Intelligence Governance Act, the Virginia Consumer Data Protection Act, and the comprehensive consumer privacy statutes of other U.S. states as enacted.
2.3 Classification of Assessment data
Assessment answers and the results derived from them may qualify as sensitive personal information or profiling data under some U.S. state laws. HyreMynd uses them only for the purposes in Section 4, limits access to the controller's authorized users, and does not use identifiable Assessment data to train models.
3. Personal information we collect
3.1 Information you provide
Depending on the feature, you or an Employer provide names, email addresses, phone numbers, account credentials, résumés, education and work history, assessment answers, job information, interview notes, references and referee contact details, correspondence, hire-outcome feedback, and contact or demonstration enquiries. Referees and professional contacts can be data subjects even when they have no Platform account.
3.2 Information the Platform generates
The Platform generates working-style positions from assessment answers; for an Employer's hiring process, comparisons with the role, the manager and the team and their outcome categories; AI-written explanations; résumé readings and qualification categories; interview-note drafts; and the completion time and duplicate-submission protection of each sitting. Generated information is personal information and this Policy treats it as such.
3.3 Information collected through the HyreMynd browser extension
At an Employer's direction, authorized users may capture publicly available professional information with the browser extension, including professional networking profiles. The Employer must establish a lawful basis for collection and contact and give the required notice of source, purpose and rights. The Platform records where each capture came from and supports the Employer's onboarding and assessment disclosures; a general onboarding acknowledgement does not prove that every source-specific notice was given.
3.4 Allocation of employment law compliance
As between HyreMynd and the Employer, the Employer alone is responsible for: candidate and employee notices required of employers or employment agencies, including advance notice and publication duties for automated employment decision tools under New York City Local Law 144 and similar laws; disclosure of artificial intelligence use in job postings, including under section 8.4 of the Ontario Employment Standards Act; procuring any independent bias audit required of a deployer and publishing its summary; any adverse impact analysis expected under Title VII as applied by the EEOC; any legally required alternative selection procedure; any consent required of an employer; making and documenting employment decisions through human decision makers; and reasonable accommodations under applicable human rights and disability law. HyreMynd provides Employers with documentation and reasonable cooperation in support of these obligations. That assistance does not replace the Employer's own audits and counsel.
3.5 Information collected automatically, analytics and performance measurement
When you use the Platform, our systems record device and usage information such as IP address, browser type, operating system and request logs. The Platform uses cookies that are necessary for authentication, security and its own functioning; it uses no cookies for advertising or third-party tracking.
On our public marketing pages, we use Vercel Web Analytics to count page views and a small set of conversion events, such as opening the demonstration form or submitting an enquiry. This measurement is cookieless; only approved public pages are reported, as a bare page address without query string; and the events carry no form content or identity, only a bounded label such as the page placement, the enquiry source and the language. Across the Platform, Vercel Speed Insights records performance measurements, such as loading time, against the page's route template rather than the address you visited, so no identifier, token or query string leaves your browser with them. Both run only on our production service. Acknowledging the cookie notice does not turn either measurement on or off.
3.6 Connected calendar and meeting accounts
An authorized user at an Employer may connect a Google or Microsoft account so that HyreMynd can schedule interviews on their behalf. When they do, we store the email address of the connected account, the access and refresh credentials the provider issues to us, the identifier of the encryption key that protects them, the scopes the provider reports as granted, and the state of the connection, including the error code of a failed credential refresh. The credentials are encrypted at rest, are never displayed or exported, and are sent to no one other than the provider that issued them. A connection belongs to the individual who created it rather than to the Employer, and no colleague can read it. The user may disconnect it at any time in the Platform. The key that encrypts a stored credential can be rotated, and a retired key version withdrawn from use, without the user having to authorize the connection again.
Separately from the calendar connection, the user may enable HyreMynd to send email from the connected account: through Gmail for a Google account, and through Microsoft Graph with the Mail.Send permission for a Microsoft account. It is used only to send the offers, reference requests, and requests for referees that the user reviews and confirms in the Platform. An offer and a request for referees are addressed to the candidate, and a reference request to a referee the candidate named. Each send gives the provider the recipient's address and the reviewed message. The permission allows sending only; HyreMynd cannot use it to read, list, search, or store any message in the mailbox. It is requested through its own consent step and never as part of connecting a calendar. Withdrawing it in the Platform stops HyreMynd from sending, including any message not yet handed to the provider; a message already handed to the provider cannot be recalled. Withdrawing it in the Platform does not remove the permission at Google or Microsoft, which the user can do in that provider's account settings.
3.7 Calendar availability and interview meetings
Reading a connected calendar's availability returns busy intervals only, never the titles, descriptions, locations, organizers or attendees of existing events.
When an interview is scheduled, HyreMynd creates the event and its online meeting on the organizer's connected calendar, and the invitation is sent through one of two channels:
- Native invitation. Used when the candidate can be reached by email and the organizer has acknowledged HyreMynd's current disclosure for that provider. HyreMynd sends the candidate's and the interviewers' email addresses, and a short meeting description in the candidate's language that includes a transcription notice, to Google Calendar and Meet or to Outlook and Teams, and the provider sends the invitations itself.
- Calendar attachment. Used otherwise. The provider event carries no guest list, and HyreMynd emails the invitation with a calendar attachment through its own email provider.
Disconnecting an account, switching to another provider account, or erasing an authorized user's account retires the connection through one departure process. HyreMynd finishes or settles the work bound to that connection and then deletes the stored credentials. Non-secret connection records and operation evidence can remain; disconnecting does not erase provider events or hiring records. HyreMynd then asks Google to revoke its grant, which can fail; Microsoft offers this integration no way to revoke a grant. In either case, the user can remove HyreMynd's access in the provider's account or organization settings, and should do so for Microsoft or whenever Google's revocation is reported as failed. Disconnecting cannot guarantee that every external event is cancelled or that delivered content is recalled.
3.8 Interview transcripts
A Google Meet or Microsoft Teams interview produces a transcript only where a participant turned transcription on inside the meeting. HyreMynd never starts a recording or a transcription: the Platform has no ability to do so, and no part of it asks a provider to begin one. Where a transcript already exists and transcript access was granted, HyreMynd retrieves it once for that meeting, within a bounded window of 48 hours after the interview ends, and stores its text on the application record together with the provider it came from. Most interviews produce no transcript at all, and that is the ordinary outcome rather than a fault. Whether transcription is enabled, and any notice or consent that enabling it requires, is a matter for the Employer and the meeting participants, not for HyreMynd.
3.9 Information HyreMynd collects from the open web at an Employer's direction
An authorized user at an Employer may ask HyreMynd to look for potential candidates for one of that Employer's open roles on the publicly accessible web. The Employer's user sets the criteria and starts the search; HyreMynd then performs the collection on its own infrastructure. This differs from Section 3.3, where the collection happens in the user's own browser through the extension, and both are described because who performs a collection is part of what we must tell you about it.
A search of this kind uses a third-party search provider's index of the public web, followed by HyreMynd retrieving pages that index returns. From those pages HyreMynd may assemble a person's name, current job title and employer, location, work history, education, and any professional contact details the page itself states publicly. HyreMynd records the address of every page relied on and the date each was read, keeps them with the record, and shows them to the Employer's user beside every claim they support. A person for whom no source page can be recorded is not kept at all.
HyreMynd issues no request to linkedin.com on this path or on any other. Where a search result cites a LinkedIn address, HyreMynd stores and displays that address as a citation only.
Artificial intelligence is used within this process to read the retrieved pages and to express what they say about a person against the role's stated requirements, with the sentence from the page that supports each answer. It produces no score. Section 5 governs it, and the Employer makes every decision.
A person found this way has not applied to the Employer and has no account with HyreMynd. If the Employer's user chooses to bring that person into the hiring process, the person becomes a candidate and everything this Policy says about candidates applies to them from that point, including the disclosure notice described in Section 3.3 before any Assessment begins. If the user does not, the record is deleted on the schedule in Section 9 and no notice is sent, because sending one would be the first contact the Employer chose not to make.
The rights in Section 10 apply to information collected this way whether or not you were ever contacted. Section 14 tells you how to reach our Privacy Officer, and an erasure request reaches these records as it reaches every other.
4. Why we collect and use personal information
We use personal information to:
- deliver the Assessment and its rule-based results, with the explanations and decision support described in Section 5, to the Employer running a hiring process;
- run independent applicant accounts: keeping your self-service sitting, showing you your working-style positions, and using that sitting in an application you make or when an Employer considers you for a role, as you agreed when you completed it;
- support an Employer's hiring work: applications, contact records, résumé review, interviews and transcripts, reference requests and requests for referees, offers, notes and hire-outcome feedback;
- find potential candidates at an Employer's direction through the extension and open-web sourcing described in Sections 3.3 and 3.9;
- send email: HyreMynd's own invitations and notifications, and, where a user enabled it, the offers, reference requests and requests for referees that user confirms, sent from their own mailbox as described in Section 3.6;
- schedule interviews by proposing times, detecting conflicts against a connected calendar, creating the meeting and sending its invitations as described in Section 3.7;
- provide the in-product assistant to authorized users, whose messages are kept for the period in Section 9;
- respond to contact and demonstration enquiries;
- measure public-site usage and Platform performance as described in Section 3.5;
- run, secure and support the Platform, including protecting the integrity of Assessment submissions;
- meet legal and contractual obligations, including handling the requests described in Section 10; and
- improve the Platform using de-identified data as described below.
4.1 De-identified and anonymized data
HyreMynd may create de-identified, anonymized, and aggregated data from personal information and may use it for any lawful business purpose, including model validation, calibration, benchmarking, research, and product improvement. We keep this data in a form that cannot reasonably identify anyone, we commit publicly not to attempt re-identification except to test whether our de-identification works, and we require the same commitment from recipients, consistent with U.S. state law and Canadian anonymization standards. Once anonymized under applicable law, this data is no longer personal information. We do not use identifiable Assessment data for model training.
5. AI processing and decision support
Section 1.1 describes where the Platform uses fixed rules and where it uses AI. Assessment results report separate comparisons for the role, the manager's working style and the team rather than one composite score, together with a written explanation for a human reviewer. Everything the Platform produces is decision support: the Employer makes every employment decision, and the Platform Terms of Service require its authorized users to keep a human decision-maker over any decision the output informs.
Where Law 25 applies, individuals are told when a decision rests exclusively on automated processing, can learn the personal information and principal factors behind the decision, and can submit observations to someone at the Employer positioned to review it. On request, the principal factors behind a result can be explained in plain language, in English or in French for Quebec residents. Where U.S. state law applies, individuals receive pre-use notice of automated decision-making technology and may exercise applicable opt-out or appeal rights through the Employer as deployer, or through HyreMynd where a statute makes HyreMynd the responsible party.
Where an interview transcript has been ingested, HyreMynd may generate a draft set of suggested answers to the interview validation questions, each with the passage of the transcript it rests on. The draft is advisory pre-fill and nothing more: it is not a finding, it does not change any Assessment result, and it becomes part of the candidate's record only when a human reviewer confirms it. Generating the draft again replaces the previous one in full rather than accumulating alongside it, so what is shown is always the most recent run. A reviewer may accept, change, or disregard any suggestion, and the recorded conclusion carries the provenance of how it was reached.
6. Google user data and Limited Use
This Section describes how HyreMynd uses data obtained through Google APIs when an authorized user connects a Google account, and it applies in addition to the rest of this Policy. A Google account is connected by an individual user, is used only for that user's own interview scheduling and, where that user separately enables it, to send the messages described for the gmail.send scope in Section 6.1, and can be disconnected at any time.
6.1 Why HyreMynd requests each Google scope
HyreMynd requests the narrowest scopes that support the feature. Each scope it requests, and the feature that requires it, is listed below. No other Google scope is requested, and reading the transcript of a Google Meet meeting requires no additional scope.
- https://www.googleapis.com/auth/calendar.events Creates, reschedules, and cancels the interview event on the connected user's own calendar, including, for a native invitation, the guest list and meeting description described in Section 3.7. HyreMynd requests this scope rather than full calendar access because it is the narrowest grant that supports the feature.
- https://www.googleapis.com/auth/calendar.freebusy Reads free and busy intervals so the Platform can propose interview times and flag conflicts. It returns start and end times only, and no event title, description, location, organizer, attendee, or identifier.
- https://www.googleapis.com/auth/meetings.space.created Creates the Google Meet space attached to the interview event, which is what lets an invited candidate join without waiting to be admitted individually, and reads the transcript of a meeting held in a space created this way where a participant enabled transcription. It reaches only the meeting spaces this application itself created.
- https://www.googleapis.com/auth/gmail.send Sends, from the connected user's own mailbox, the offers, reference requests, and requests for referees that user reviews and confirms in the Platform, so they arrive as ordinary email from that user. It permits sending only: HyreMynd cannot use it to read, list, search, or store any message in the mailbox. It is requested only when the user separately enables sending from that account, and never as part of connecting a calendar.
- openid Identifies the Google account being connected, so the connection is attached to the right user.
- email Returns the email address of the connected account, which the Platform displays so the user can see which account is connected. It is not used to send email and is added to no marketing list.
6.2 Limited Use
HyreMynd's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Data obtained through Google APIs is never used for advertising, and is never used to serve, target, or measure advertisements.
- Data obtained through Google APIs is never sold, and is never shared for cross-context behavioral advertising.
- Data obtained through Google APIs is never used to develop, improve, or train generalized artificial intelligence or machine learning models. Where an interview transcript is processed by an artificial intelligence provider through our API gateway, it is processed solely to produce the advisory draft for that one application.
6.3 Removing HyreMynd's access to your Google account
Disconnecting in the Platform, or erasing your account, deletes the stored credentials through the departure process in Section 3.7, after which HyreMynd asks Google to revoke the grant. You can also remove HyreMynd at any time in your Google account settings, which works even if you never return to the Platform, and you should do so if the Platform reports that revocation failed. Deleting the stored credentials alone is not proof that Google revoked the grant.
7. Disclosure of personal information
We disclose personal information only in these situations:
- to Employers on the Platform, as decision support delivered into their hiring workflow when they consider a person for a role, including when an applicant's self-service sitting is used in an application;
- to the recipients a user directs, such as the candidate or referee who receives a message the user confirms;
- to service providers working for us under written contracts with confidentiality, security, and use limits, covering application hosting with public-site analytics and performance measurement, database and storage infrastructure, caching and background processing, artificial intelligence model providers accessed through an API gateway, email delivery, error and log monitoring, bot protection, the open-web search provider described in Section 3.9, and calendaring, online-meeting and mailbox providers acting on the authorization a user has given them;
- to professional advisors bound by confidentiality;
- to public authorities when the law, a court order, or legal process requires it, in which case we disclose only what is legally required; and
- in a merger, acquisition, financing, or asset sale, with confidentiality protections and this Policy continuing to apply.
HyreMynd publishes a current list of the sub-processors it engages, naming each one's legal entity, purpose, categories of personal information, and processing location, rather than furnishing that list on request. View the HyreMynd sub-processor list.
7.1 No sale or sharing
HyreMynd does not sell personal information and does not share it for cross-context behavioral advertising, as the CCPA and similar state laws define those terms, and has not done so in the preceding twelve months.
7.2 Not a consumer reporting agency
HyreMynd is not a consumer reporting agency and Assessment output is not a consumer report under the U.S. Fair Credit Reporting Act. The Platform Terms of Service prohibit authorized users from using Assessment output as a consumer report.
8. Where your information is processed
The Platform is hosted on infrastructure located in the United States, and its service providers process personal information in the United States, with some delivered through a global edge network. Personal information of Canadian residents is therefore transferred to, stored in, and processed in the United States, where it is subject to U.S. law and lawful access by U.S. authorities. HyreMynd does not claim Canadian data residency.
Quebec law requires an organization to assess, before communicating personal information outside Quebec, whether the information will receive adequate protection. For employer-directed records that duty belongs to the Employer as controller, including any privacy impact assessment required under section 17 of the Quebec Act and transparency under PIPEDA about U.S. processing; for information HyreMynd controls, it belongs to HyreMynd. HyreMynd supports Employers with its published sub-processor list and the transfer information in this Policy, and binds its service providers by written contract.
9. Retention
Each category of personal information follows the ordinary period and starting event below. When a period ends, the content is withdrawn from use and then destroyed; destruction that is interrupted resumes and is not reported as complete until it finishes.
| Category | What it covers | Ordinary period and starting event |
|---|---|---|
| Employer hiring content | An application's answers and derived results, résumés, interview notes, transcripts and drafts, generated explanations and hiring notes | 24 calendar months after the role is closed or permanently deleted |
| Employer contact records | The Employer's contact record for a person, with its résumés, assessments, correspondence and notes, and any identity record the Employer itself created | 24 calendar months after the contact's last hiring activity, once no live application remains |
| Team assessment sittings | A team member's answers and derived positions for an Employer's team | 36 calendar months after completion, or after an invitation was redeemed without answers |
| Open-web search runs | A search run and the results it returned | 90 days after creation, or less where a shorter period is configured; importing a person does not extend the run |
| Unused imported contacts | Contacts imported but never used for an application or accepted outreach | 21 days after import |
| Unfinished assessment drafts | Saved answers of a sitting that was never submitted | 7 days after the last save, bounded by the invitation's expiry |
| Assistant messages | Each message exchanged with the in-product assistant | 30 days after each message; empty conversations are removed |
| Unconfirmed mail drafts | Drafts of correspondence that were never confirmed for sending | 30 days after the last edit |
| Settled correspondence | The text of a sent or abandoned message and of outreach | 30 days after the send is finally settled |
| Mail proof | Minimized records that a message was sent and of sending quotas | 730 days after settlement |
| Contact-consent proof | Minimized proof of a contact's consent or objection to contact | 36 calendar months after the latest expiry, withdrawal or last accepted outreach |
| Data-subject request proof | The identity and outcome record of a settled request | 72 calendar months after settlement; kept for accountability, not because one statutory minimum requires it |
| Audit and security logs | The Platform's own audit and security log entries | 12 calendar months after creation; log storage at service providers follows their contract terms |
| Provider authorization attempts | Browser proof hashes and one-use callback authority | 1 day after authorization expiry |
| Provider revocation secrets | Encrypted grant credentials held only for cleanup delivery | 1 day after creation; successful, refused or exhausted delivery destroys the secret sooner |
| Provider revocation audit | Minimized cleanup outcomes, ticket and operator attribution, including unsupported or refused delivery | 30 days after revocation is finally settled |
| Provider operation archive | Minimized historical operation identity, window, channel and outcome; no copied subject or join URL | 30 days after creation |
Hiring content. The period starts only when the role is closed or permanently deleted. Archiving, hiring, rejecting or withdrawing a candidate, inactivity and reversible workflow changes do not start it.
Contact records. A contact's last hiring activity is the latest of: the contact's creation, the end of the role of any of its applications, the last time the Employer contacted the person, the latest résumé upload for that Employer, the latest assessment sitting, the latest note about the contact and the latest sourcing match. An identity record the Employer created for a person is removed with the last contact that uses it.
Independent accounts. An applicant's independent account and self-service sitting are never destroyed by an Employer's retention period. They remain while needed for their purposes, until you ask us to erase them as Section 10.3 describes.
Legal holds and lawful instructions. An Employer administrator may record a legal hold or a lawful instruction for a role, covering its live applications, or for named applications, with a reason, a review date and an end date. Content under an active hold is not expired. A hold ends on its end date or when it is released, and a released hold stays on record. An erasure request that reaches held content is sent to the controller for review instead of destroying it. A hold cannot restore content already withdrawn. Minimized proof follows its own period above and does not justify keeping hiring text, and decision or billing records that remain are not anonymous merely because narrative text was removed.
10. Your rights
Subject to applicable law and identity verification, you may exercise these rights by contacting the Privacy Officer in Section 14:
- Access and knowledge. Confirm whether we process personal information about you and receive access to it, including categories collected, sources, purposes, and categories of recipients.
- Correction. Correct inaccurate or incomplete personal information.
- Deletion. Request erasure through the process in Section 10.3.
- Withdrawal of consent. Withdraw consent at any time, subject to legal and contractual restrictions and reasonable notice. Withdrawing during an active Assessment ends your participation in that hiring process.
- Portability. Where the law provides, receive computerized personal information you gave us in a structured, commonly used format.
- Automated decision rights. The rights in Section 5, including observations and, where applicable, opt-out or appeal rights for automated decision-making technology.
- U.S. state rights. Know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and appeal a refusal, as the privacy statute of your state provides.
- Non-discrimination. We will not treat you differently for exercising your rights.
10.1 Requests about employer-directed records
Where a request concerns records an Employer controls, including Assessment output already delivered into its hiring workflow, the Employer decides the request as controller and HyreMynd carries out the Employer's decision in the Platform. Erasure by HyreMynd does not recall a copy the Employer already took outside the Platform.
10.2 Timelines and appeals
We respond within the timelines applicable law requires, generally 30 days from the day your request reached us, with extensions where permitted. If we refuse a request, we tell you why and, where the law gives you an appeal right, how to appeal. You may also contact the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec, your provincial commissioner, your state Attorney General, or the California Privacy Protection Agency.
10.3 How an erasure request is handled
Account deletion is performed by our support team rather than from within the Platform. Write to support@hyremynd.com from the email address on your account, or to the Privacy Officer in Section 14. Both addresses reach the same process, which runs in stages:
- Recording. The request is recorded when it reaches us, and its response deadline runs from that day.
- Verification. Your identity is verified through a channel independent of the request.
- Controller authorization. The records found are grouped by controller. Each Employer authorizes and starts the work on the records it controls; HyreMynd authorizes the work on your account and independent self-service data, and erases your account only after each Employer's work has settled.
- Execution. Authorized work destroys or de-identifies the scoped content. A step that fails is retried and, after repeated failure, goes to human review instead of being reported as done. Content under an active legal hold goes to its controller for review.
- Effect evidence. A request is marked complete only once each effect, such as the removal of stored files, is confirmed.
When your account is erased, its identifying information is cleared at execution, and remaining content already stripped of that information is purged after a short, bounded grace period. Destruction cannot be reversed once performed. How long execution takes can depend on each Employer's authorization.
11. Security
HyreMynd uses administrative, technical, and physical safeguards suited to the sensitivity of the information it holds, including encryption in transit, encryption of stored provider credentials, storage with a hosting provider that encrypts data at rest, tenant isolation enforced in the application and in the database, role-based access controls, multi-factor authentication for privileged administrative actions, and audit logging. No system is perfectly secure, and HyreMynd does not promise absolute security. Where a confidentiality incident presents a risk of serious injury, we notify the Commission d'accès à l'information and the affected individuals as Quebec law requires. Where the real risk of significant harm threshold under PIPEDA is met, we notify the Office of the Privacy Commissioner of Canada and affected individuals. We also provide the breach notifications U.S. state law requires.
12. Consent
The account gate requests acknowledgement of the current Privacy Policy and Candidate Terms for applicants, or of the Privacy Policy and Platform Terms of Service for staff. Internal Team Terms are requested immediately before a staff assessment. The Data Processing Addendum, Responsible AI Statement and Data Access Consent Form are public disclosures; publishing them does not mean that each user signed them. Assessment participation and optional provider permissions have their own purpose-specific consent. Acknowledging a legal document is not a separate opt-in to model training or marketing. Material changes require new acceptance of the exact version and content shown; a stale submission is refused and must be reviewed again.
13. Children
The Platform is built for professional workplace use and is not directed to minors. We do not knowingly collect personal information from anyone under the age of majority in their jurisdiction, and we delete any such information when we become aware of it.
14. Privacy Officer and contact
HyreMynd has designated a Privacy Officer, who is also the person in charge of the protection of personal information under Law 25.
Privacy Officer: Marleigh Robertson
Organization: HYREMYND AI INC.
Registered Office: 559 Sammon Ave, East York, Ontario, M4C 2E1, Canada
Email: privacy@hyremynd.com
Account deletion requests: support@hyremynd.com
15. Changes to this Policy
Material changes are published under a new version and effective date, with a concise summary of what changed, and require renewed acceptance of the exact content at the applicable activity gate. Earlier versions and the acceptances recorded against them remain unchanged. Other notice duties to Employers are governed by the Customer Agreement and the Data Processing Addendum.
16. Governing law
This Policy is governed by the laws of Ontario and the federal laws of Canada that apply there. This does not limit mandatory rights you hold under the privacy laws of where you live, including Law 25 for Quebec residents and state law for U.S. residents.
Privacy Policy | Confidential and Proprietary