Privacy Policy
How eStaffing Inc. handles your personal data
Last updated 29 August 2026
We do not sell personal data. We do not use customer or candidate personal data to train our own or any third party’s AI models. We do not run advertising on it.
1.Who we are
eStaffing Hire is operated by eStaffing Inc.. The entity responsible for your personal data is set out in the contact section below, and how responsibility is shared between us, employers and recruiters is described in the controller and processor section.
2.Who this policy covers
- Employers and their staff, who post roles.
- Recruiters and agencies, who submit candidates.
- Candidates. Candidates may be submitted by recruiters without creating an eStaffing Hire account. We process candidate information in connection with recruitment activities even where the candidate does not have an account, and the rights described below apply to them in full.
3.Information we collect, why, and on what basis
| What | Purpose | Why we process it |
|---|---|---|
| Name, work email, phone, company | Creating and running your account | To provide the service and manage your account |
| Registered name, address, GSTIN, PAN, EIN | Issuing a tax-correct invoice | To meet tax, accounting and legal requirements |
| Candidate name, contact details, résumé, work history | Presenting a candidate for a specific role, and determining who introduced them first | To carry out the submission the recruiter and employer asked for, and to establish who introduced the candidate first |
| Placement, invoice and payment records | Billing, paying recruiters, accounting | To process payments and meet legal and accounting requirements |
| Sign-in times, IP address, actions taken | Security, fraud prevention, and an audit trail for ownership disputes | To protect the platform, prevent fraud and resolve disputes |
Where we rely on consent for a particular activity, we ask for it separately and you can withdraw it at any time. Where UK or EU GDPR applies, the corresponding legal bases are set out in the UK and EU section below.
How candidate contact details are stored depends on how the candidate reached us. We would rather set this out exactly than make a broad claim that is only true of part of the system.
- Submitted by a recruiter. We keep the candidate’s name, and an irreversible one-way hash of their email and phone used solely to detect duplicate submissions. Their email address and phone number are not stored in readable form on the candidate record.
- Applied through an invitation link. The invitation records the email address it was sent to, and the answers the candidate gives on the form, which include their email and phone, are stored as submitted. This is readable data.
- Résumés are stored as the file they arrived as, and will normally contain contact details within them.
4.Candidate information
This is the most sensitive data we hold, so we set out the flow precisely.
When a recruiter submits a candidate:
- the recruiter represents that it has the candidate’s authorisation to share their information for that opportunity;
- the information is processed for that specific recruitment opportunity;
- it is shared only with the employer who posted that role;
- it is never made visible to unrelated recruiters on the marketplace;
- we retain the submission record for ownership, dispute-resolution, invoicing and fraud-prevention purposes.
If you are a candidate and were submitted without your knowledge, email support@estaffinginc.com. We will remove your information and take it up with that recruiter.
5.How we use information
To run accounts, match roles to recruiters, carry submissions to employers, decide introduction ownership, raise invoices, pay recruiters, prevent fraud and abuse, meet legal obligations, and support you.
We may produce aggregated, de-identified statistics about hiring activity. These never identify a person, employer or recruiter.
6.Information sharing
We share personal data only:
- with the employer a candidate was submitted to;
- with the recruiter and agency who made a submission, about their own submissions;
- between the employer, recruiters and agencies working the same role, including business contact details, so they can deal with each other directly about it and take part in an intake call;
- with the service providers listed below, to run the platform;
- with professional advisers, or where required by law or to establish or defend legal claims;
- with an acquirer, if the business is sold, subject to this policy continuing to apply.
We do not share personal data with anyone else, and we do not sell it.
7.Controller and processor roles
Because this is a marketplace, responsibility is shared. To be explicit:
- We are the controller for the platform itself: accounts, submissions, ownership records, invoices, payments and security logs.
- Recruiters are independent controllers of their own candidate relationships. They are responsible for obtaining candidate authorisation and for the lawfulness of the information they give us.
- Employers are independent controllers of candidate information once they receive it, and are solely responsible for their hiring decisions and for anything they do with that information in their own systems.
- Where an employer or recruiter instructs us to process data purely on their behalf, we act as a processor (or service provider) for that activity.
8.Service providers
We rely on a small number of established third-party providers to run the platform. They fall into these categories:
- database and application hosting;
- content delivery, DNS and security;
- transactional email delivery.
Each is a reputable provider bound by contract to process personal data only as necessary to provide its service to us, under confidentiality and data-protection obligations, and never for its own purposes. For security reasons we do not name our specific vendors in this public document; a current list of the processors that handle personal data is available to customers on request at support@estaffinginc.com.
9.International data transfers
Our service providers may process personal data in countries outside your country of residence, currently the United States.
Where applicable law requires safeguards for international transfers, we use appropriate contractual, technical or other legally recognised safeguards. You can ask us what applies to your data.
10.AI and automated processing
We use software to rank and score how well a candidate appears to match a role, and to estimate how likely a role is to be filled. These are aids for a human, not decisions.
No hiring decision is made automatically. Employers decide whom to interview and hire. We do not use customer or candidate personal data to train our own or any third party’s AI models.
Scores and recommendations may be inaccurate and are decision-support information only. A high score is not a recommendation to hire and a low one is not a reason to reject. Users remain responsible for independently reviewing candidate information and making their own recruitment decisions.
No personal data is sent to any third-party AI provider. Match scores and fill estimates are computed inside our own systems by deterministic software, comparing the skills on a role against the skills on a submission. Nothing is sent to an external model, which is why there is no possibility of it being used for training anywhere else.
If we ever introduce a feature that sends personal data to an external provider, we will say so here and name the provider before it goes live.
11.Cookies and similar technologies
We currently use only cookies and similar technologies necessary to operate the service and remember basic preferences, such as keeping you signed in and remembering your theme and display currency. We do not currently use advertising cookies or third-party advertising trackers.
12.Data retention
- Account data: while your account is open, then up to 12 months.
- Candidate submissions and related personal information: retained for as long as reasonably necessary to provide and operate the recruitment marketplace, administer candidate ownership, process placements and payments, resolve disputes, prevent fraud and abuse, enforce our agreements, comply with legal and regulatory obligations, and protect our rights. When personal information is no longer required for these purposes, we delete or anonymise it where appropriate.
- Invoices, placements and payment records: for as long as required by applicable tax, accounting, legal and regulatory requirements, and for legitimate business purposes such as resolving disputes. These generally cannot be deleted on request.
- Reasons information is kept longer: legal or tax obligations, fraud prevention, an open dispute, enforcing an agreement, security, or a regulatory requirement.
- Security and audit logs: up to 12 months.
Visibility is not the same as retention
Something disappearing from a search result does not mean the record was destroyed, and keeping a record does not mean it stays visible. We control the two separately, because a recruiter’s evidence that they introduced a candidate has to outlive the job advert.
- When an employer closes a role, it stops accepting new submissions immediately and is marked closed. For six months it remains findable by recruiters as a closed role, so anyone who worked it can still see what happened.
- After six months, a closed role no longer appears in ordinary recruiter search results. Recruiters who submitted to it keep access to their own submissions.
- If an employer closes its account, its open roles close, its marketplace presence is removed and no new submissions are possible. We do not destroy the history. Recruiters keep access to their own submissions to that employer, and placement, invoice, payment, guarantee and dispute records are preserved.
- An employer closing its account never erases a recruiter’s evidence of a submission, placement, fee, guarantee or dispute.
13.Security
The following are in place today, not planned:
- passwords hashed with Argon2id and never stored in readable form;
- each organisation’s records separated by database-level row security, enforced by the database itself rather than only by application code;
- role-based access control, so a person only reaches what their role permits;
- rate limiting on sign-in and password reset;
- an append-only audit log of significant actions;
- encryption in transit, and encryption at rest by our database and storage providers.
No system is perfect. We do not claim it is, and we would rather tell you what is actually implemented than publish a longer list.
14.Your privacy rights
Wherever you are, and whether or not you hold an account, you can ask us to:
- tell you what personal data we hold about you and why;
- correct anything inaccurate or incomplete;
- delete it;
- restrict or object to a particular use;
- provide it in a portable form, where applicable;
- withdraw consent, where we relied on consent for that activity.
Email support@estaffinginc.com. We respond within the period required by the law that applies to you, and aim to reply within 30 days. Where we cannot act, for example on records we are legally required to keep, we will tell you plainly which records and why.
Withdrawing consent does not affect processing we are required or permitted to continue under applicable law.
15.United States state privacy rights
Depending on where you live and which law applies, you may have additional rights, including in California, Colorado, Virginia, Connecticut, Texas and other states with comprehensive privacy laws. These commonly include the right to know, to delete, to correct, to obtain a portable copy, and to opt out of sale, sharing for cross-context behavioural advertising, and certain profiling.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We do not use personal information for profiling that produces legal or similarly significant effects without human involvement.
We will not discriminate against you for exercising any of these rights. To exercise them, email support@estaffinginc.com. You may use an authorised agent where the law allows it, and we may need to verify your identity first.
16.UK and EU privacy rights
Where UK or EU GDPR applies, you have the rights of access, rectification, erasure, restriction of processing, objection to processing including profiling, data portability, withdrawal of consent, and the right to lodge a complaint with a supervisory authority.
Our legal bases are set out in the information we collect section. Where we rely on legitimate interests, you may object and we will stop unless we have compelling grounds that override your interests.
Contact support@estaffinginc.com. You may complain to your local supervisory authority, or the Information Commissioner’s Office in the UK.
17.Children's privacy
eStaffing Hire is intended for business and employment-related use and is not directed to children. We do not knowingly seek to collect personal data from children. If we learn that we hold a child’s personal data in circumstances where applicable law requires parental or guardian consent, we will take appropriate steps in accordance with that law.
18.Data breach
If we become aware of a personal data breach, we will assess the incident and make notifications to affected individuals and applicable regulatory authorities as required by applicable law and within the time periods required by that law.
Where notification is required, we will provide the information available to us at the time and supplement it as more becomes known, in accordance with applicable law.
19.Changes to this policy
We will post any change here with a new date, and give at least 30 days’ notice by email of any change that materially affects how we use your personal data.
20.Contact and complaints
support@estaffinginc.com
eStaffing Inc., 825 Watters Creek Blvd., Building M, Suite 250, Allen, Texas 75013, United States
If we have not resolved your complaint, you may escalate to your local supervisory authority in the UK or EU, or your state attorney general in the United States.