Privacy Policy and Notice at Collection
What sii{me} collects, why it is used, who handles it, how long it is kept, and how people exercise privacy rights.
Information collected
Account and contact information; professional Passport and opportunity information; work preferences and evidence; consent, match, message, interview, offer, outcome, billing, support, safety, device, and audit events; and voluntary demographic information kept separate from matching. We collect only the Persona inquiry reference and verification outcome from identity verification, not the government-ID image or selfie media.
Purposes
We use information to authenticate accounts, verify people and companies, create Passports, evaluate job-related fit, facilitate consent-based introductions, support interviews and offers, attribute hires, invoice companies, prevent fraud and abuse, improve reliability, comply with law, and respond to rights requests.
Service providers
Service providers may process limited information for hosting, authentication, databases, identity verification, communications, payment processing, analytics, monitoring, and connected applicant-tracking systems. Persona controls identity media under its own notices. Stripe controls bank and card details; sii{me} stores provider references and status, not complete payment credentials.
Sensitive information
Government identifiers and biometric identity media remain with Persona. Voluntary demographic information, work authorization, account credentials, precise contact details, and financial references receive restricted access. Sensitive data is not used to increase or decrease match ranking unless a lawful, disclosed, job-related eligibility requirement applies.
Disclosure and sharing
Private identity and contact details remain hidden until the relevant mutual-consent condition is met. We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We may disclose information to the other participant after consent, to authorized company approvers, to service providers under contract, or when legally required.
Retention
Active account and hiring records are retained while needed to provide the service. Agreement, attribution, invoice, payment, fraud, safety, and audit records may be retained for the applicable legal limitation, tax, and dispute periods. Identity provider media follows Persona’s retention settings. Deleted or revoked data is removed or de-identified unless a documented exception applies.
Your choices and rights
Depending on location, you may request access, export, deletion, correction, limitation of sensitive processing, or opt out of sale or sharing. You may revoke optional product-improvement consent without affecting core access. We verify identity before fulfilling a request and do not discriminate against people who exercise privacy rights.
Security and incidents
We use access controls, row-level authorization, signed webhooks, encrypted transport, provider tokenization, audit events, rate limits, and monitoring. No system is perfectly secure. If a qualifying incident occurs, sii{me} will investigate, contain, preserve evidence, and provide legally required notices.
Automated decision support
sii{me} separates fit from confidence and keeps humans responsible for release and employment decisions. Users may request correction and human review of material factual errors. We evaluate systems for accessibility, job relevance, inconsistent treatment, and unintended barriers.