Internal Data Handling Policy

Version 1.0 · Effective [EFFECTIVE DATE]

Draft for attorney review. Not yet reviewed by counsel. Publishing note: this is an internal operating policy. Publishing it at /legal/internal-data-handling is a legitimate transparency choice, but it binds you publicly to everything in it, so publish only what you actually do.

1. Purpose

This policy governs how everyone working under the Vouchward name handles candidate data. It exists because candidate trust is the asset. One careless export undoes everything the public policies promise.

2. Who may access candidate data

Access is limited to named individuals authorized by the owner, currently: Elio Gerges (owner, full access) and [NAME, role, scoped access]. Sourcing roles see only the data needed to source and book calls. Screening notes and rationale are written and read only by whoever conducts screening. Access is reviewed whenever anyone joins or leaves, and at least every 6 months.

3. Account and device rules

  • Multi factor authentication on every account that touches candidate data: hosting, database, email, scheduling, and Paraform.
  • Unique passwords held in a password manager. No shared passwords, no passwords in chat messages.
  • Work happens in the Vouchward systems. Candidate data is never exported to personal email, personal cloud storage, or local spreadsheets. If a temporary export is unavoidable for a specific task, it is deleted the same day and the export is noted in the record timeline.
  • Devices used for Vouchward work have full disk encryption and auto lock enabled.

4. Data minimisation in practice

Collect only the fields on the form. Write screening notes about work, skills, and fit, never about protected characteristics. If a candidate volunteers protected information, it does not go into notes. If it was typed before anyone caught it, it is removed and the removal is noted. Salary history is never written down even if volunteered; the note records target compensation only.

5. Retention, in one place

DataKept until
Active candidate recordConsent lapse at 24 months without renewal, or deletion request
Screening notes and rationaleSame as the record they belong to
Suppression hashIndefinitely, by design
Consent ledger entriesIndefinitely, as the proof consent existed and was honoured
Financial records tied to placementsAs required by tax law

A deletion sweep for lapsed consent runs at least monthly.

6. Vendor list

The live vendor list is the table in the Data Sharing and Third Party Disclosure Statement. Adding any new tool that touches candidate data requires updating that public statement first, not after.

7. Incident response

If candidate data may have been exposed, lost, or accessed without authorization:

  1. Contain immediately: revoke sessions, rotate credentials, isolate the affected system.
  2. Establish what data, which candidates, and what window of time.
  3. Notify affected candidates promptly and without unreasonable delay, as California Civil Code section 1798.82 requires of any business holding California residents' personal information, and follow the statute's content requirements for the notice. If more than 500 California residents are affected, submit the sample notice to the California Attorney General as the statute requires.
  4. Write the incident up: cause, scope, fix, and the change that prevents recurrence.
  5. If a vendor caused it, hold them to their own notification duties and reassess the vendor.

8. Annual review

Every 12 months, or after any incident, the owner rereads this policy against actual practice and reconciles the two, in whichever direction honesty requires.