Privacy Policy
- Effective
- August 25, 2026
- Updated
- August 25, 2026
Contentsshow
- Who we are, and which role we play
- What we collect
- How we use it
- AI and automated processing
- Legal bases for processing
- How we share information
- If you are a candidate
- Cookies and analytics
- Public data and sourcing
- How long we keep it
- Security
- International transfers
- Your rights
- US state privacy rights
- Third-party links
- Changes to this policy
- Contact
- Who we are, and which role we play
- What we collect
- How we use it
- AI and automated processing
- Legal bases for processing
- How we share information
- If you are a candidate
- Cookies and analytics
- Public data and sourcing
- How long we keep it
- Security
- International transfers
- Your rights
- US state privacy rights
- Third-party links
- Changes to this policy
- Contact
Chosen HQ LLC operates the Chosen HQ website, platform, applications, and related services. This policy explains what information we collect, how we use it, how we share it, and what rights you have over it.
By using the platform you agree to this policy and to the Terms of Service. If you do not agree, please do not use it.
Who we are, and which role we play
Chosen HQ LLC is a California limited liability company at 319 Ivy Street, San Francisco, CA 94102. We run a recruiting marketplace with an applicant tracking system built into it.
Which data protection role we play depends on the data:
- For your account and billing information, we are the controller
- For candidate data a hiring company manages in its own workspace, that company is the controller and we are its processor
- For candidate data an independent recruiter manages in their own workspace, that recruiter is the controller and we are their processor
- For the marketplace itself, including recruiter applications, candidate consent records, attribution, and packet review, we are a controller in our own right
That last one matters: a recruiter and a hiring company are separate businesses, and moving a candidate between them is something we do rather than something we do purely on someone's instruction.
The platform uses artificial intelligence for scheduling assistance, sourcing, resume analysis, candidate matching, and communication management. This policy covers how data is processed by those features.
What we collect
What you give us
- Account and profile information: name, work email, company name, job title
- Login credentials, stored encrypted
- Billing details, processed by third-party payment processors; we do not store full card numbers
- Resumes, CVs, and supporting documents uploaded for parsing and analysis
- Job descriptions, hiring criteria, and recruiting preferences
- Interview notes, feedback, evaluations, and hiring annotations
- Recruiter applications, including work history, specialties, and placement track record
- Support requests, feedback, and anything else you send us
What we collect automatically
- IP address and the approximate location derived from it
- Browser, device, operating system, and version
- Pages viewed, actions taken, timestamps, and referring URLs
- Log files, error reports, and performance data
This is how we operate, secure, and improve the platform.
Cookies
We use cookies, pixels, and similar technologies to run the platform, remember preferences, and understand usage. Some are essential and cannot be turned off. Others, including analytics, you can control from your browser settings.
What we process for our customers
Companies and recruiters bring candidate information into their workspaces. That can include:
- Names, contact details, resumes, work history, skills, education, and qualifications
- Interview scheduling data, calendar availability, and meeting details
- Email between recruiters and candidates, including content, headers, metadata, and threading
- Interview feedback and hiring notes
- AI-generated data derived from all of the above, such as match scores, parsed resume fields, intent classifications, and assessments
We process it on their instructions and under our agreements with them. We do not knowingly collect personal information from children under 16.
What we collect through integrations
- Calendar, such as Google Calendar: event data, attendee information, and free/busy availability, to schedule interviews
- Email, such as Gmail: messages including content, headers, and metadata from your connected account, to synchronize communication and drive scheduling features; we may receive push notifications of new messages
- Video conferencing, such as Zoom: the account information needed to generate meeting links
- Productivity tools, such as Notion: data synchronized with your connected workspace
- Authentication providers: identity and profile information used to manage account access
We ask for the minimum permissions each integration needs, and what we can reach is limited to what you granted during authorization. You can revoke any of it from your settings or from the third-party service.
What sourcing collects
Sourcing collects publicly available information about potential candidates from the open web: names and professional headlines, locations, work history, skills, links to public profiles such as LinkedIn or GitHub, and text excerpts from public pages that evidence a qualification.
That information is normalized and enriched by AI into structured profiles, skill assessments, and relevance scores. We collect only what is publicly available. We do not access password-protected accounts, private social profiles, or non-public databases.
How we use it
- Running, maintaining, securing, and improving the platform
- Creating and managing accounts, and processing payments and invoices
- Answering questions and providing support
- Sending service notices, updates, and security alerts
- Parsing resumes and documents into structured data with AI
- Matching candidates to role requirements and generating relevance scores
- Classifying incoming email by intent, such as a confirmation or a reschedule
- Drafting email responses for a recruiter to review, or to send automatically where that recruiter has turned it on
- Synchronizing calendars, interview schedules, and meeting logistics
- Searching public web data to build structured candidate profiles for sourcing
- Building data representations of profiles and roles to make search and matching work
- Drafting and assisting with job descriptions
- Interpreting natural-language queries so people can search their own data
- Running the marketplace: reviewing recruiter applications, recording candidate consent, resolving attribution, reviewing packets, and calculating what is owed
- Analyzing usage to improve performance
- Protecting against fraud, misuse, and unauthorized access
- Meeting our legal and regulatory obligations
- Supporting accounts, including authorized internal access for troubleshooting, security, and compliance
Where an AI feature writes a message for a recruiter, it is written in that recruiter's voice and sent from that recruiter's connected account, with their knowledge and under whatever approval setting they configured.
We do not use customer data to train generalized or public AI models. We do not sell personal information.
AI and automated processing
AI features generate insights, classifications, and recommendations. They do not make employment decisions.
Where AI is used
- Resume parsing and structured data extraction
- Candidate and role matching, and relevance scoring
- Email intent classification
- Draft email response generation on a recruiter's behalf
- Sourcing from publicly available web data
- Natural language search and query interpretation
- Job description drafting assistance
- Evidence packet match reports scored against a role's ranked requirements
A person stays in the loop
AI output is there to help a person decide. Hiring decisions stay with the company. Where AI drafts email, the account holder chooses whether it sends automatically or waits for review. Both the Terms of Service and the Recruiter Network Agreement forbid using an AI score or assessment as the sole basis for a decision about a person.
No training on your data
We do not use customer data, candidate information, or user content to train generalized AI models made available outside the platform.
Fairness
We design and monitor these systems to mitigate bias in recruiting and hiring. If you operate somewhere with specific obligations for automated employment decision tools, including notice, consent, or bias auditing, meeting them is your responsibility and we will support reasonable requests for information.
Legal bases for processing
Where the law requires one, including under the GDPR, we rely on:
- Performance of a contract
- Legitimate business interests, such as security and product improvement
- Compliance with legal obligations
- Consent, where it is required
- Explicit consent for reaching a third-party service through OAuth or a similar protocol
- For candidate representation in the marketplace, the candidate's own consent, captured through Chosen
If you are a candidate
Candidates never pay Chosen anything, and are never charged to be represented, submitted, or hired.
If a recruiter wants to represent you to a company through the marketplace, you will be asked for consent directly. That consent covers one company, lasts 12 months, and you can withdraw it at any time from the link in the request. Withdrawing releases that recruiter's claim to represent you at that company.
For data a company or recruiter holds about you in their own workspace, they are the controller and your request goes to them. For consent records, marketplace attribution, and anything else we hold in our own right, write to contact@chosenhq.com and we will handle it directly.
We send system notifications, transactional email, and service messages through third-party delivery providers. You can opt out of non-essential marketing at any time using the unsubscribe link or by writing to us.
Email sent through the platform on a recruiter's behalf, such as an interview invitation, comes from that recruiter's connected account and is subject to their own practices.
Commercial email we send complies with the CAN-SPAM Act: accurate headers, identification as an advertisement where that applies, a working opt-out, and a valid physical postal address, which is Chosen HQ LLC, 319 Ivy Street, San Francisco, CA 94102.
Public data and sourcing
Sourcing collects and processes publicly available information from the open web so customers can identify potential candidates.
Chosen HQ is not a consumer reporting agency and sourcing output is not a consumer report under the Fair Credit Reporting Act. Anyone using sourcing data as a factor in an employment decision is responsible for complying with the law that applies to them, including the FCRA, state fair employment law, and federal equal employment opportunity law.
We collect only publicly available information, and never reach non-public accounts, private databases, or password-protected content for sourcing.
How long we keep it
We keep personal information only as long as we need it to run the platform, meet our contractual obligations, satisfy legal, accounting, or regulatory requirements, and resolve disputes.
Data we process for a customer is retained under our agreement with them and deleted or returned on request, subject to law.
- Email synchronized from a connected account is kept while the connection lasts and for a reasonable period after disconnection so it can be exported
- OAuth access and refresh tokens are kept only while the integration is active and deleted on disconnection
- AI-generated data is kept as part of the candidate or role record it belongs to
- Sourcing data is kept according to customer configuration and applicable retention agreements
- Derived representations used for search and matching are deleted when their source records are
- Marketplace consent records, attribution history, and payment records are kept as long as needed to administer and audit them, because they determine who is owed what
Security
- Encryption in transit over TLS, and encryption at rest for sensitive data including AES-256 for integration credentials and OAuth tokens
- Multi-tenant isolation with organization-level access controls
- Row-level security enforced in the database
- Role-based access control
- Secure cloud infrastructure with ongoing security monitoring
No system is completely secure. Internal access to accounts by authorized staff is restricted, logged, and auditable.
International transfers
We may process and store information outside your own country. Where required, we use appropriate safeguards such as Standard Contractual Clauses.
Your rights
Depending on where you are and what law applies, you may have the right to:
- Access the personal information we hold about you
- Have inaccurate information corrected
- Have your personal information deleted
- Object to or restrict certain processing
- Receive a portable copy of your data
- Withdraw consent where processing rests on it
- Opt out of marketing
Write to contact@chosenhq.com. We may need to verify who you are before we act.
US state privacy rights
California
If you live in California, the CCPA and CPRA give you these rights:
- To know what categories and specific pieces of personal information we collected, where it came from, why we collected it, and who we shared it with
- To have your personal information deleted, subject to some exceptions
- To have inaccurate personal information corrected
- To opt out of sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioral advertising
- To limit our use of sensitive personal information to what providing the service requires
- Not to be discriminated against for exercising any of these rights
- To appoint an authorized agent, whose authorization we may verify
Virginia, Colorado, Connecticut, and other states
- To confirm whether your personal data is being processed, and to access it
- To correct inaccuracies
- To have it deleted
- To obtain a portable copy
- To opt out of processing for targeted advertising, sale, or profiling that produces legal or similarly significant effects
- To appeal a denied request by writing to contact@chosenhq.com
To exercise any of these, write to contact@chosenhq.com. We may need to verify your identity first.
Third-party links
The platform may link to third-party sites and services. We are not responsible for their privacy practices.
Changes to this policy
We may update this policy. When we do, we update the dates at the top and post the revised version here.
Contact
Chosen HQ LLC, 319 Ivy Street, San Francisco, CA 94102, United States.
Email: contact@chosenhq.com