XORIANT CORPORATION
Candidate Privacy Notice & Consent
Your engaging subtitle goes here. This text should capture attention and provide a brief overview of engaging content that awaits users in this widget.
| Document ID | ACC-PRIV-REC-01 | Version | Draft v0.3 (Legal Updates Incorporated) |
| Owner |
Audit, Compliance & Continuity (ACC) / HR / Sysnet |
Classification |
Confidential (Internal Use) |
| Revision / Date | July 2026 | Status | Final |
Meta description goes here
Title goes here
This Notice explains how Xoriant Corporation (“we”, “our”, “us”) collects and uses Personal Data when you apply for a role with us and during interviews, assessments, background verification, and onboarding. Xoriant recruits across multiple countries, and this Notice is designed to support compliance with the data protection laws of each location from which we hire, including: the EU/EEA General Data Protection Regulation (GDPR) and the national implementing laws of Ireland, the Netherlands, Spain, Lithuania, Estonia, and Latvia; the Law on Personal Data Protection of the Republic of North Macedonia; the United States federal Fair Credit Reporting Act (FCRA) and applicable state privacy laws (including the California Consumer Privacy Act, as amended by the CPRA); Canada’s PIPEDA and provincial privacy laws (including Quebec’s Law 25); the Indian Digital Personal Data Protection Act, 2023 (DPDPA) and the Digital Personal Data Protection Rules, 2025; Singapore’s Personal Data Protection Act 2012 (PDPA); and Australia’s Privacy Act 1988 and the Australian Privacy Principles (APPs).
1. Who We Are (Controller / Fiduciary Details)
Controller/Fiduciary: Xoriant Corporation (1248 Reamwood Avenue, Sunnyvale, CA 94089]). Where applicable, Xoriant may appoint an EU/UK representative. Primary privacy contact (DPO/Privacy Office): [insert DatasubjectResponse@Xoriant.com/+912066046000]. General contact channel: Xoriantinformationsecurity@Xoriant.com.
2. Definitions
• “Personal Data / Personal Information” means information that identifies or can reasonably be linked to an individual. • “Sensitive / Special Category Data” includes health/disability, biometrics, criminal records, and other protected attributes as defined by applicable law. • “Processing” means collection, use, storage, disclosure, transfer, or deletion of Personal Data.
1. Who We Are (Controller / Fiduciary Details)
Controller/Fiduciary: Xoriant Corporation (1248 Reamwood Avenue, Sunnyvale, CA 94089]). Where applicable, Xoriant may appoint an EU/UK representative. Primary privacy contact (DPO/Privacy Office): [insert DatasubjectResponse@Xoriant.com/+912066046000]. General contact channel: Xoriantinformationsecurity@Xoriant.com.
2. Definitions
• “Personal Data / Personal Information” means information that identifies or can reasonably be linked to an individual. • “Sensitive / Special Category Data” includes health/disability, biometrics, criminal records, and other protected attributes as defined by applicable law. • “Processing” means collection, use, storage, disclosure, transfer, or deletion of Personal Data.
Widget title goes here
Your engaging subtitle goes here. This text should capture attention and provide a brief overview of engaging content that awaits users in this widget.
| Term | Description |
|---|---|
| Personal Data / Personal Information | Any information that identifies you or could be used to identify you. For example, your name, email address, or CV. |
| Sensitive / Special Category Data | More private categories such as health or disability information, biometric data, criminal records, or religious beliefs. We collect these only when the law requires or permits it. |
| Processing | All the activities performed with your data — collecting it, storing it, using it, sharing it, or deleting it. |
| Data Controller / Fiduciary | The company that decides why and how your data is used. Xoriant is the controller/fiduciary for recruitment data. |
| Data Processor / Service Provider | A third party (e.g., a background-check company) that handles your data only on our instructions. |
| Consent | Your freely given, specific, informed, and unambiguous agreement to us processing your data for a particular purpose. You can withdraw consent at any time. |
| Lawful Basis | The legal reason that allows us to process your data—for example, because it is necessary to assess your application, to comply with the law, or because you have consented. |
Meta description goes here
Title goes here
3. Personal Data We Collect
We may collect the following (as applicable):
• Identification & contact: name, email, phone, address, date of birth, nationality/citizenship, photograph.
• Recruitment & professional: CV/resume, qualifications, skills, experience, employment history, interview notes and scores.
• Verification: right-to-work documents, references, background verification (BGV) outputs (as applicable).
• Technical (online recruitment tools): device/browser information, IP address, session metadata (as applicable).
• Sensitive / special category data (only if needed and permitted): health/disability, biometrics, criminal records, and other sensitive attributes where required by law or provided by you. The table below sets out the categories of personal data we collect, the specific purpose for each,
and the legal basis (lawful ground) we rely on. We collect only what is necessary for recruitment.
We may collect the following (as applicable):
• Identification & contact: name, email, phone, address, date of birth, nationality/citizenship, photograph.
• Recruitment & professional: CV/resume, qualifications, skills, experience, employment history, interview notes and scores.
• Verification: right-to-work documents, references, background verification (BGV) outputs (as applicable).
• Technical (online recruitment tools): device/browser information, IP address, session metadata (as applicable).
• Sensitive / special category data (only if needed and permitted): health/disability, biometrics, criminal records, and other sensitive attributes where required by law or provided by you. The table below sets out the categories of personal data we collect, the specific purpose for each,
and the legal basis (lawful ground) we rely on. We collect only what is necessary for recruitment.
Widget title goes here
Your engaging subtitle goes here. This text should capture attention and provide a brief overview of engaging content that awaits users in this widget.
| Category of Data | Examples | Purpose & Lawful Basis |
|---|---|---|
| Identification & Contact | Name, email, phone, address, date of birth, nationality, photograph. |
Assessing your application;
communicating with you.
Basis: Pre-contractual steps / Consent (DPDPA). |
| Recruitment & Professional | CV/Resume, qualifications, employment history, interview notes and scores, assessment results. |
Evaluating suitability for
the role; selection decisions.
Basis: Pre-contractual steps / Legitimate interests. |
| Right-to-Work & Compliance | Passport, visa, work permit documents, proof of qualifications. |
Verifying eligibility to work;
meeting legal obligations.
Basis: Legal obligation. |
| Background Verification (BGV) | References, criminal-record checks (where permitted), credit checks (where relevant), sanctions/PEP screening. |
Protecting business and clients;
required by law or policy.
Basis: Legal obligation / Consent (where required by law). |
| Sensitive / Special Category Data | Health/disability data (for reasonable adjustments), biometric data (where required), criminal records (role-specific). |
Legal obligation or
explicit consent.
Collected only where
specifically required.
Basis: Explicit Consent / Legal obligation. |
| Technical & Platform Data | Device/browser information, IP address, session metadata from online recruitment tools. |
Platform security;
fraud prevention;
analytics (aggregate).
Basis: Legitimate interests. |
| Equal Opportunities Data (Voluntary) | Diversity/inclusion data provided voluntarily (e.g., gender, ethnicity). |
Aggregate EO monitoring
(not used in selection decisions).
Basis: Explicit Consent. Entirely voluntary. |
Meta description goes here
Title goes here
4. Purposes (Purpose Limitation)
We use Personal Data only for recruitment and employment-related purposes, including:
• Assessing suitability for the role and managing selection (screening, interviews, assessments).
• Communicating with you about your application, interviews, and offers.
• Conducting background verification / reference checks (where applicable).
• Meeting legal and contractual obligations (e.g., right-to-work, statutory requirements).
• Protecting legitimate interests such as preventing fraud, ensuring security, and defending legal claims.
5. Lawful Basis & Consent (GDPR / DPDPA / CCPA/Any other applicable privacy law)
Most recruitment processing is carried out under one or more lawful bases such as steps prior to entering into a contract, legal obligation, and (where applicable) legitimate interests. Consent is used only where required by law (e.g., certain background checks, recordings, or processing of sensitive/special category data).
• Contract necessity: steps prior to entering an employment/engagement contract.
• Legal obligation: compliance with labor, tax, immigration, and other applicable laws. • Legitimate interests (GDPR): recruitment administration, security, fraud prevention, and legal defense (subject to balancing).
• Consent (DPDPA/GDPR where required): specific processing such as certain BGV checks, recordings (if used), and sensitive/special category data. Where we rely on legitimate interests (where applicable), Xoriant maintains a legitimate interest’s assessment, and you may object as permitted by law. Where consent is used, it is voluntary and may be withdrawn at any time; withdrawal does not affect processing already performed lawfully.
6. Automated Decision-Making and AI-Assisted Recruitment
We use online recruitment tools, applicant tracking systems, and AI-assisted features to help manage applications to support interview management. These tools support our recruiters; they are not used to make final selection decisions about you without human involvement, unless we tell you otherwise.
7. Retention (Data Retention Periods)
We retain Personal Data only for as long as necessary for the purposes above and to meet legal, audit, or reporting needs. Retention and disposal follow Xoriant’s records management / retention schedule. Recruitment records for unsuccessful candidates are typically retained for 36 Months unless a longer period is required by law or to establish/defend legal claims. Where possible, data may be anonymized.
8. Sharing with Third Parties (Vendors)
We may share relevant data with the following categories of recipient:
• Service Provider including background verification providers, assessment platforms, and interview management tools (including AI-enabled tools where used).
• Professional advisors (legal/audit) and regulators/law enforcement where required by law.
• Xoriant group entities and internal stakeholders involved in recruitment (HR, hiring managers, interviewers).
• Successor entities or acquiring organizations in connection with a merger, acquisition, or other corporate transactions. Where third parties act as processors/service providers, they are engaged under written agreements (including data protection clauses/DPAs), confidentiality obligations, and appropriate security requirements. Sub-processors are controlled as required by contract and law.
9. Cross-Border Transfers
Xoriant operates globally, hence the recruitment process involves international transfers. We apply appropriate safeguards consistent with applicable law, such as Standard Contractual Clauses (SCCs) or equivalent contractual and organizational measures, and/or reliance on adequacy decisions where available. Where applicable, we also assess transfer risks and implement supplementary safeguards as required. You may request a copy of relevant transfer safeguards (e.g., SCCs) by contacting the privacy contact listed above.
10. Your Rights (Candidate / Data Subject Rights)
Subject to applicable law, you may request:
• Access to your Personal Data, correction/rectification, and copies of data (portability where applicable).
• Deletion/erasure and restriction/objection (where provided under law and subject to lawful exceptions).
• Withdrawal of consent (where processing is based on consent).
• Right to lodge a complaint with a supervisory authority/regulator (where applicable).
• Under CCPA/CPRA (where applicable): right to know, delete, correct, and opt-out of sale/sharing (if applicable), and non-discrimination.
• Right to Nominate another individual to exercise your data principal rights on your behalf in the event of your death or incapacity.
Certain rights may be limited where Xoriant must retain data to meet legal obligations or to establish, exercise, or defend legal claims. The specific rights available to you, and how to exercise them, depend on your location and are detailed in the Annex for your jurisdiction. To make a request, contact the privacy contact in Section 1; we will verify your identity and respond within the timeframe required by applicable law.
11. CCPA/CPRA (California) Additional Disclosure (Where Applicable)
Xoriant does not sell Personal Information in the ordinary course of recruitment. If any processing qualifies as “sale” or “sharing” under CCPA/CPRA, you may exercise your opt-out rights by contacting Xoriantinformationsecurity@Xoriant.com. If sensitive personal information is used for limited purposes only, you may also request limiting its use/disclosure where applicable.
12. Security & Breach Notification
We implement administrative, technical, and physical safeguards to protect Personal Data. Security incidents are handled under an incident response process. Where legally required, we will notify affected individuals and/or regulators without undue delay.
13. Grievance & Redressal
For questions, complaints, or requests, contact Xoriantinformationsecurity@Xoriant.com or the designated privacy contact/DPO in Section 1. If you are not satisfied with our response, you may complain to the supervisory or data protection authority for your location.
14. Changes to this Notice
We may update this Notice from time to time to reflect changes in law, our practices, or our services. The version date at the top of this document indicates when it was last updated. Where we rely on your consent, we will re-obtain it if a material change affects the processing for which consent was given.
15. Candidate Acknowledgement & Granular Consent
By signing/accepting below, you confirm that you have read and understood this Notice and that the information provided is accurate.
We use Personal Data only for recruitment and employment-related purposes, including:
• Assessing suitability for the role and managing selection (screening, interviews, assessments).
• Communicating with you about your application, interviews, and offers.
• Conducting background verification / reference checks (where applicable).
• Meeting legal and contractual obligations (e.g., right-to-work, statutory requirements).
• Protecting legitimate interests such as preventing fraud, ensuring security, and defending legal claims.
5. Lawful Basis & Consent (GDPR / DPDPA / CCPA/Any other applicable privacy law)
Most recruitment processing is carried out under one or more lawful bases such as steps prior to entering into a contract, legal obligation, and (where applicable) legitimate interests. Consent is used only where required by law (e.g., certain background checks, recordings, or processing of sensitive/special category data).
• Contract necessity: steps prior to entering an employment/engagement contract.
• Legal obligation: compliance with labor, tax, immigration, and other applicable laws. • Legitimate interests (GDPR): recruitment administration, security, fraud prevention, and legal defense (subject to balancing).
• Consent (DPDPA/GDPR where required): specific processing such as certain BGV checks, recordings (if used), and sensitive/special category data. Where we rely on legitimate interests (where applicable), Xoriant maintains a legitimate interest’s assessment, and you may object as permitted by law. Where consent is used, it is voluntary and may be withdrawn at any time; withdrawal does not affect processing already performed lawfully.
6. Automated Decision-Making and AI-Assisted Recruitment
We use online recruitment tools, applicant tracking systems, and AI-assisted features to help manage applications to support interview management. These tools support our recruiters; they are not used to make final selection decisions about you without human involvement, unless we tell you otherwise.
7. Retention (Data Retention Periods)
We retain Personal Data only for as long as necessary for the purposes above and to meet legal, audit, or reporting needs. Retention and disposal follow Xoriant’s records management / retention schedule. Recruitment records for unsuccessful candidates are typically retained for 36 Months unless a longer period is required by law or to establish/defend legal claims. Where possible, data may be anonymized.
8. Sharing with Third Parties (Vendors)
We may share relevant data with the following categories of recipient:
• Service Provider including background verification providers, assessment platforms, and interview management tools (including AI-enabled tools where used).
• Professional advisors (legal/audit) and regulators/law enforcement where required by law.
• Xoriant group entities and internal stakeholders involved in recruitment (HR, hiring managers, interviewers).
• Successor entities or acquiring organizations in connection with a merger, acquisition, or other corporate transactions. Where third parties act as processors/service providers, they are engaged under written agreements (including data protection clauses/DPAs), confidentiality obligations, and appropriate security requirements. Sub-processors are controlled as required by contract and law.
9. Cross-Border Transfers
Xoriant operates globally, hence the recruitment process involves international transfers. We apply appropriate safeguards consistent with applicable law, such as Standard Contractual Clauses (SCCs) or equivalent contractual and organizational measures, and/or reliance on adequacy decisions where available. Where applicable, we also assess transfer risks and implement supplementary safeguards as required. You may request a copy of relevant transfer safeguards (e.g., SCCs) by contacting the privacy contact listed above.
10. Your Rights (Candidate / Data Subject Rights)
Subject to applicable law, you may request:
• Access to your Personal Data, correction/rectification, and copies of data (portability where applicable).
• Deletion/erasure and restriction/objection (where provided under law and subject to lawful exceptions).
• Withdrawal of consent (where processing is based on consent).
• Right to lodge a complaint with a supervisory authority/regulator (where applicable).
• Under CCPA/CPRA (where applicable): right to know, delete, correct, and opt-out of sale/sharing (if applicable), and non-discrimination.
• Right to Nominate another individual to exercise your data principal rights on your behalf in the event of your death or incapacity.
Certain rights may be limited where Xoriant must retain data to meet legal obligations or to establish, exercise, or defend legal claims. The specific rights available to you, and how to exercise them, depend on your location and are detailed in the Annex for your jurisdiction. To make a request, contact the privacy contact in Section 1; we will verify your identity and respond within the timeframe required by applicable law.
11. CCPA/CPRA (California) Additional Disclosure (Where Applicable)
Xoriant does not sell Personal Information in the ordinary course of recruitment. If any processing qualifies as “sale” or “sharing” under CCPA/CPRA, you may exercise your opt-out rights by contacting Xoriantinformationsecurity@Xoriant.com. If sensitive personal information is used for limited purposes only, you may also request limiting its use/disclosure where applicable.
12. Security & Breach Notification
We implement administrative, technical, and physical safeguards to protect Personal Data. Security incidents are handled under an incident response process. Where legally required, we will notify affected individuals and/or regulators without undue delay.
13. Grievance & Redressal
For questions, complaints, or requests, contact Xoriantinformationsecurity@Xoriant.com or the designated privacy contact/DPO in Section 1. If you are not satisfied with our response, you may complain to the supervisory or data protection authority for your location.
14. Changes to this Notice
We may update this Notice from time to time to reflect changes in law, our practices, or our services. The version date at the top of this document indicates when it was last updated. Where we rely on your consent, we will re-obtain it if a material change affects the processing for which consent was given.
15. Candidate Acknowledgement & Granular Consent
By signing/accepting below, you confirm that you have read and understood this Notice and that the information provided is accurate.