VanaHR

PRIVACY

Privacy Policy (Beta)

We only collect what we need to run onboarding and compliance workflows. We do not sell candidate or staff data. We protect sensitive fields, limit access by role, and keep auditable records of key actions.

What we collect

Organization account information, onboarding workflow data, document/signature evidence, and operational audit events.

How we protect data

Access is scoped by organization and role. Candidate magic-link tokens are hash-only at rest. Sensitive mutable payloads are encrypted at rest. Signed/finalized evidence is immutable for compliance integrity.

Retention and deletion

Mutable PII is handled through redaction/tombstone workflows where policy allows. Immutable compliance evidence is retained per platform policy and audit requirements.

Questions or requests

Email support@vanahr.com and we will route your request to support and operations.

Beta notice: this policy page is a launch baseline and should be reviewed by legal counsel before paid public release.