Comitium provides recruiting software for organizations and candidates. This Privacy Notice explains how personal data is handled across our websites, accounts, organization workspaces, job pages, application flows, communications, scheduling features, and blockchain-enabled services.
Different parties decide how personal data is used in different parts of the Service. An organization using Comitium for recruitment (an "Organization") normally controls the recruitment data in its workspace. Comitium controls the data needed to provide, secure, and support the Service itself.
How responsibility is allocated
Job applications
The Organization decides why candidate data is collected, how it is used, who may access it, and how long it is kept. It is the controller of that recruitment data, and Comitium processes the data on its instructions under our Data Processing Agreement.
The Organization's own privacy notice, linked in the application flow, applies to its recruitment process. Requests concerning a particular application should normally be sent to that Organization. Comitium assists Organizations with verified requests concerning data processed on their behalf.
Comitium accounts and services
Comitium is the controller when we decide how personal data is used to create and secure accounts, operate and support the Service, maintain our public website, prevent abuse, comply with law, and keep operational records for actions requested through the Service.
Personal data we handle
The data depends on how you use Comitium and may include:
- Recruitment data: identity and contact details, resumes, application answers, candidate profiles, attachments, messages, notes, interview and scheduling records, feedback, evaluations, hiring stages, and decisions.
- Account and service data: authentication details, wallet addresses, profile information, organization membership and roles, sessions, settings, support communications, and connection details for features you choose to use.
- Technical and security data: IP address, browser and device information, request timing, and security events needed to deliver, troubleshoot, and protect the Service.
- Public network data: wallet addresses and transaction or event data recorded on Base, and public organization or job information distributed through IPFS.
Where resume processing is enabled, Comitium may also maintain limited structured professional information, such as skills and job-criteria results, to support recruiting search and review.
Base records are public, maintained independently of Comitium, and generally cannot be changed or deleted by us. Private recruitment content is not intentionally published on-chain. Copies of public IPFS content may remain available from other network participants after Comitium stops hosting it.
Where data comes from
We receive personal data directly from visitors, account holders, candidates, and Organization members. An Organization may also create or import candidate records. Other sources include services a user chooses to connect, public blockchains, and information generated when a device interacts with the Service.
How we use personal data
For Organization-controlled recruitment data, Comitium provides the features selected by the Organization and follows its documented instructions. The Organization determines the legal basis for its recruitment process and provides any additional notice required by law.
Where Comitium is the controller, we use personal data:
- to create accounts, authenticate users, and provide requested features, where this is necessary to perform a contract or take requested steps before entering into one;
- to operate, troubleshoot, secure, and prevent misuse of the Service, based on our legitimate interest in providing a reliable and secure product;
- to respond to support requests and maintain necessary business records, based on our legitimate interests;
- to create aggregated or de-identified statistics used to operate, analyze, secure, and improve the Service, based on our legitimate interests;
- to comply with law and establish, exercise, or defend legal claims, based on legal obligations and our legitimate interests; and
- for an optional activity where consent is required, based on consent. Consent can be withdrawn for future processing.
Some Organizations enable AI-assisted recruiting features. On their instructions, these features may structure professional information, compare it with Organization-defined criteria, and support search. The output assists authorized reviewers; Comitium does not use solely automated processing to make hiring decisions with legal or similarly significant effects. Any available choice about this processing is explained in the application flow. Private recruitment data is not used to train general-purpose AI models. An Organization's use of those features is governed by the AI Feature Terms.
Information marked as required is needed to create an account, submit an application, authorize a transaction, or provide another requested feature. Without it, that part of the Service may not work. Organizations separately decide which application information they require.
Encryption and security
Private recruitment content submitted through Comitium's web application is encrypted in the browser before upload. Incoming email and protected records created by requested processing are encrypted before storage. Ongoing access within the Service is limited to authorized recipients holding the required keys.
Requested features such as resume analysis and message delivery use only the content needed to complete that action and do not create a separate unencrypted stored copy.
Account, permission, routing, and public-network data must remain available to operate the relevant parts of the Service. Our Encryption documentation explains these boundaries and the key design in more detail.
When we share personal data
We do not sell personal data, use private recruitment data for advertising, or share personal data for cross-context behavioral advertising.
We disclose data only where needed to operate the Service, follow an Organization's instructions, complete an integration requested by a user, protect the Service, or comply with law. Recipients may include:
- the Organization and its authorized users;
- infrastructure, storage, security, authentication, email, scheduling, calendar, and processing providers;
- integrations enabled by an organization or user;
- public blockchain and decentralized-storage infrastructure for information intentionally submitted to those networks;
- professional advisers, authorities, or courts where disclosure is necessary; and
- a successor involved in a merger, acquisition, financing, reorganization, or sale, subject to appropriate safeguards.
Service providers are subject to contractual confidentiality, security, and data-protection obligations. Providers that process Organization-controlled recruitment data are listed in our Data Processing Agreement.
Some providers process data outside the European Economic Area. Where the law requires a transfer safeguard, we use an adequacy decision, standard contractual clauses, or another recognized mechanism.
Retention and deletion
Organizations decide how long to keep the recruitment data they control and can instruct Comitium to return or delete it, subject to applicable law.
For data controlled by Comitium, we keep it only for as long as needed to provide and secure the Service, maintain required business records, comply with legal obligations, resolve disputes, and enforce agreements.
Access, correction, export, and deletion requests can be sent to legal@comitium.co. We act on verified requests and Organization instructions. Deleted data may remain in protected backups until those backups are overwritten in the ordinary cycle, or where retention is required by law. Comitium cannot erase records maintained by a public blockchain, and public IPFS content may remain available from other participants.
Cookies and browser storage
Comitium uses cookies and browser storage needed to provide and secure the Service, including authentication and session state, interface preferences, and encrypted remembered-device key material.
We do not currently use advertising or analytics cookies. If we introduce non-essential tracking, we will provide any choices required by law before using it.
Your rights
Depending on the law and circumstances, you may have the right to:
- access your personal data and receive information about its use;
- correct inaccurate or incomplete data;
- request deletion or restriction of processing;
- receive data in a portable format where that right applies;
- object to processing based on legitimate interests;
- withdraw consent for future processing without affecting earlier lawful processing; and
- complain to a competent data-protection authority.
For data connected with a job application, contact the Organization identified in the application flow. For data controlled by Comitium, contact legal@comitium.co. We may need to verify your identity and may retain information where the law permits or requires it. An authorized Organization member may need to help export readable end-to-end encrypted recruitment content.
Changes and contact
We may update this notice when the Service, our providers, or applicable law changes. We will change the "Last updated" date and provide additional notice where required by law.
For privacy questions or requests, contact Comitium at legal@comitium.co.
Use of the Service is also governed by the Terms of Use. Organizations using Comitium to process recruitment data are also subject to the Data Processing Agreement.