Legal
How Yardstick collects, uses and protects personal data — for the people who use our product, and for the candidates whose information passes through it.
Last updated
19 September 2026
Effective
1 October 2026
Version
1.0
On this page
01
Scope
This policy covers the Yardstick hiring workspace, our website, and the support and sales channels attached to them. It explains what we do with personal data and the choices you have.
Two groups of people appear in this document. Users are the people at a customer company who log in and run hiring. Candidates are the people being considered for a role. We handle their data differently, and the difference is set out in the next two sections.
02
What we collect
From users we collect account details, workspace settings, and product activity — the pages opened, the searches run, and the actions taken. We collect this so the product works and so we can see where it does not.
Account data: name, work email, job title, and the workspace you belong to.
Authentication data: sign-in events, device and browser, and IP address.
Usage data: feature use, timings, and error reports.
Support data: anything you send us in a ticket, a call, or a shared document.
03
Candidate data
Candidate information reaches us because a customer put it there — by uploading a CV, by connecting an applicant tracking system, or by sourcing a profile from a public source. For that data the customer is the controller and we are the processor. We act on their instructions and nothing else.
If you are a candidate and want your data corrected or deleted, the fastest route is the company you applied to. Write to us and we will pass it on and support them in answering you, but we cannot decide the outcome on their behalf.
04
How we use it
We use personal data to run the service, to keep it secure, to bill for it, and to improve it. That last one deserves a plain statement: we look at aggregate product usage to decide what to build, and we do not sell personal data to anyone.
We do not use candidate data to train general-purpose models. Where a feature ranks or scores candidates, it runs within the customer workspace and on that customer’s data.
05
Legal bases
Where the GDPR applies and we act as a controller, we rely on the following bases.
Contract — to provide the service you have signed up for.
Legitimate interests — to secure the service, prevent abuse, and improve the product, balanced against your rights.
Consent — for marketing email and non-essential cookies, which you can withdraw at any time.
Legal obligation — for tax, accounting, and lawful requests.
06
Sharing
We share personal data with the sub-processors listed on our sub-processors page, each under a written contract that holds them to terms no weaker than ours. We also share data where we are legally required to, and with a buyer if the business is sold — in which case this policy follows the data.
We do not share personal data with advertisers, data brokers, or any third party that wants it for their own purposes.
07
International transfers
Customer data is stored in the European Union by default. Where a sub-processor operates outside the EEA or the UK, the transfer is covered by the European Commission’s Standard Contractual Clauses, the UK Addendum where relevant, and a transfer risk assessment we keep on file.
Enterprise customers can request EU-only processing, which restricts the sub-processor set. Ask us before signing rather than after.
08
Retention
We keep account data for as long as the workspace is open, and for ninety days after it closes so it can be restored if the closure was a mistake. After that it is deleted from live systems, and it ages out of backups within a further thirty days.
Candidate data is kept for as long as the customer instructs. Customers set their own retention windows, and we delete on schedule or on request.
09
Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to how it is used, receive a portable copy, and complain to a supervisory authority.
Write to the contact address at the end of this document. We answer within thirty days, and we do not charge for a first request.
10
Security
Data is encrypted in transit and at rest. Access inside Yardstick is role-based, logged, and reviewed. We run background checks on staff with production access and require hardware keys for it.
No system is perfect. If a breach affects your personal data we will tell you and the relevant regulator within the deadlines the law sets, and we will tell you what we know rather than waiting for a complete picture.
11
Changes and contact
Questions about this policy go to privacy@yardstick.example. Our data protection officer can be reached at the same address.