Internal Data Handling Policy
Version 1.0 · Effective [EFFECTIVE DATE]
Draft for attorney review. Not yet reviewed by counsel. Publishing note: this is an internal operating policy. Publishing it at /legal/internal-data-handling is a legitimate transparency choice, but it binds you publicly to everything in it, so publish only what you actually do.
1. Purpose
This policy governs how everyone working under the Vouchward name handles candidate data. It exists because candidate trust is the asset. One careless export undoes everything the public policies promise.
2. Who may access candidate data
Access is limited to named individuals authorized by the owner, currently: Elio Gerges (owner, full access) and [NAME, role, scoped access]. Sourcing roles see only the data needed to source and book calls. Screening notes and rationale are written and read only by whoever conducts screening. Access is reviewed whenever anyone joins or leaves, and at least every 6 months.
3. Account and device rules
- Multi factor authentication on every account that touches candidate data: hosting, database, email, scheduling, and Paraform.
- Unique passwords held in a password manager. No shared passwords, no passwords in chat messages.
- Work happens in the Vouchward systems. Candidate data is never exported to personal email, personal cloud storage, or local spreadsheets. If a temporary export is unavoidable for a specific task, it is deleted the same day and the export is noted in the record timeline.
- Devices used for Vouchward work have full disk encryption and auto lock enabled.
4. Data minimisation in practice
Collect only the fields on the form. Write screening notes about work, skills, and fit, never about protected characteristics. If a candidate volunteers protected information, it does not go into notes. If it was typed before anyone caught it, it is removed and the removal is noted. Salary history is never written down even if volunteered; the note records target compensation only.
5. Retention, in one place
| Data | Kept until |
|---|---|
| Active candidate record | Consent lapse at 24 months without renewal, or deletion request |
| Screening notes and rationale | Same as the record they belong to |
| Suppression hash | Indefinitely, by design |
| Consent ledger entries | Indefinitely, as the proof consent existed and was honoured |
| Financial records tied to placements | As required by tax law |
A deletion sweep for lapsed consent runs at least monthly.
6. Vendor list
The live vendor list is the table in the Data Sharing and Third Party Disclosure Statement. Adding any new tool that touches candidate data requires updating that public statement first, not after.
7. Incident response
If candidate data may have been exposed, lost, or accessed without authorization:
- Contain immediately: revoke sessions, rotate credentials, isolate the affected system.
- Establish what data, which candidates, and what window of time.
- Notify affected candidates promptly and without unreasonable delay, as California Civil Code section 1798.82 requires of any business holding California residents' personal information, and follow the statute's content requirements for the notice. If more than 500 California residents are affected, submit the sample notice to the California Attorney General as the statute requires.
- Write the incident up: cause, scope, fix, and the change that prevents recurrence.
- If a vendor caused it, hold them to their own notification duties and reassess the vendor.
8. Annual review
Every 12 months, or after any incident, the owner rereads this policy against actual practice and reconciles the two, in whichever direction honesty requires.