shield

Privacy Policy

Effective date: 1 August 2026  ·  Last reviewed: 1 August 2026

GDPR / UK GDPR Illinois BIPA India DPDP Act 2023

1. Who we are

Emvio Intelligence ("Emvio", "we", "our") operates an AI-powered recruitment platform that enables companies to screen, interview, and shortlist candidates using voice AI. Our registered contact address for data-protection matters is: [email protected].

When a company uses Emvio to hire, the company is the Data Controller and Emvio is the Data Processor. When we collect data for our own purposes (account management, security, compliance), Emvio is the Controller. This policy covers both roles.

2. Data we collect

CategoryExamplesWho it applies toLegal basis (GDPR)
Identity & contactName, email address, phone numberCandidates, company usersArt. 6(1)(b) — contract performance
Job application dataCV / résumé, job role applied for, application timestampCandidatesArt. 6(1)(b) — contract performance
Voice recording BIPARaw audio recorded during the AI interview sessionCandidatesArt. 9(2)(a) — explicit consent
Interview transcriptSpeech-to-text transcription of your interview answersCandidatesArt. 9(2)(a) — explicit consent
AI assessment scoresTechnical, experience, communication, and authenticity scores; hire signalCandidatesArt. 9(2)(a) — explicit consent
Gaze / behavioural signals BIPAEstimated gaze direction from browser camera (anti-cheat analysis)Candidates (Phase 2 feature)Art. 9(2)(a) — explicit consent
Anti-cheat metadataResponse latency timestamps (ms), audio artifact flagsCandidatesArt. 9(2)(a) — explicit consent
Account dataCompany name, billing email, subscription plan, login timestampsCompany usersArt. 6(1)(b) — contract performance
Usage & log dataIP address, browser type, API call timestamps, error logsAll usersArt. 6(1)(f) — legitimate interest (security)

We do not collect demographic data (race, gender, age, religion) and our scoring model does not use any demographic proxies.

3. How we use your data

  • Conducting AI interviews — streaming your voice to our STT provider, generating interviewer questions, scoring answers in real time.
  • Producing the hiring shortlist — ranking candidates by composite score and delivering a "hiring brief" to the company.
  • Anti-cheat analysis — detecting response patterns inconsistent with genuine, unassisted answers. Results are visible only to Emvio and the hiring company.
  • Platform operation — account authentication, billing, support, and security monitoring.
  • Legal and compliance obligations — maintaining an immutable audit log as required by EU AI Act Art. 26 and responding to subject-access or erasure requests.

We do not sell, rent, or trade personal data to third parties. We do not use interview data to train our AI models without separate explicit consent.

4. Sub-processors

The following third parties process personal data on our behalf. All are bound by data-processing agreements requiring GDPR-equivalent protections.

Sub-processorPurposeData transferredLocationSafeguard
Supabase Inc. Relational database, authentication, file storage (résumés) All candidate and company data, résumé files USA (AWS us-east-1) DPA + SCCs (EU–US)
OpenAI Inc. LLM — job-description parsing, interview question generation, answer scoring, hiring brief Anonymised interview transcript excerpts, job description text USA OpenAI DPA + SCCs; Zero Data Retention API option enabled
Sarvam AI Pvt. Ltd. Text-to-speech (Riya's voice) and response humanisation LLM Riya's generated text (no candidate personal data sent to TTS) India DPA under DPDP Act 2023
Deepgram Inc. Real-time speech-to-text (Nova-3 model) Raw candidate voice audio (streaming) USA Deepgram DPA + SCCs; audio not retained by Deepgram after transcription
LiveKit Inc. WebRTC room token issuance for video sessions Room join tokens only — no media passes through LiveKit servers USA LiveKit DPA
Cloudflare Inc. CDN, DNS, and static-site hosting (Pages) IP addresses, HTTP request metadata Global edge Cloudflare DPA + SCCs

We will notify you of any material change to this sub-processor list at least 30 days in advance via the email on your account.

5. Data retention

Data typeRetention periodReason
Application records & AI scores730 days (2 years) from application dateEEOC record-keeping guidance; pipeline re-engagement window
Interview voice recordings90 days from session endDispute resolution; Deepgram does not retain raw audio
Interview transcripts730 days (stored as part of application record)Same as application records
Résumé / CV file730 days; deleted alongside application recordStorage cleanup enforced daily by automated script
Audit log entries7 years (append-only, cannot be deleted)EU AI Act Art. 26 immutability requirement
Account & billing dataDuration of contract + 7 yearsTax and accounting obligations
Server / access logs90 days rollingSecurity monitoring

Expired records are automatically deleted by a daily retention job. You may request early erasure under Section 6.

6. Your rights

Depending on your jurisdiction you have some or all of the following rights. Submit requests via the Privacy & Data Centre in your candidate account, or email [email protected].

  • Access (Art. 15 GDPR) — obtain a copy of the personal data we hold about you.
  • Rectification (Art. 16) — correct inaccurate data.
  • Erasure / "right to be forgotten" (Art. 17) — request deletion of your data. We will cascade-delete your application record, résumé file, and candidate profile within 30 days. Audit log entries cannot be erased (immutable by law).
  • Restriction (Art. 18) — ask us to stop processing while a dispute is resolved.
  • Portability (Art. 20) — receive your interview transcript and scores in machine-readable JSON.
  • Object (Art. 21) — object to processing based on legitimate interest.
  • Human review of automated decisions (Art. 22) — if your application was rejected solely by AI, you may request a human recruiter to personally review your assessment. Use the "Request Human Review" button on your My Applications page.
  • Withdraw consent — withdraw at any time; withdrawal does not affect prior processing.

We respond to all rights requests within 30 days. If you believe we have violated your rights, you may lodge a complaint with your supervisory authority (EU: your national DPA; UK: ICO; India: Data Protection Board).

7. Illinois Biometric Information Privacy Act (BIPA) notice

If you are an Illinois resident, this section applies to you. Voice recordings and gaze-tracking data constitute biometric identifiers under 740 ILCS 14/ (BIPA).

What we collect

We collect voice audio and (in Phase 2) estimated gaze direction during AI interviews. Voice is transcribed by Deepgram and the audio is deleted within 90 days. Gaze signals are processed in-browser and only the derived behavioural flag is stored — raw camera frames are never transmitted to our servers.

Retention and destruction schedule

Biometric data is retained for the shorter of: (a) the initial purpose of the collection (the interview), (b) 3 years from collection, or (c) as required by applicable law. Under our standard policy, voice recordings are purged at 90 days and all remaining biometric-derived data is purged with the application record at 730 days. Our full, publicly available written biometric retention and destruction policy is at biometric-policy.html, in accordance with 740 ILCS 14/15(a).

No sale of biometric data

Emvio does not and will not sell, lease, trade, or profit from biometric identifiers or biometric information.

Consent

We obtain written consent via the interview entry screen before any biometric data is collected. You may revoke consent and request erasure of biometric data at any time by emailing [email protected].

8. India Digital Personal Data Protection Act 2023 (DPDP)

If you are in India, Emvio processes your data under the DPDP Act as a Data Fiduciary.

  • Consent — we collect explicit consent before processing sensitive personal data (biometrics, health, financial).
  • Purpose limitation — data is used only for the purposes stated in Section 3 of this policy.
  • Data principal rights — you have the right to access, correct, erase, and nominate. Submit requests to [email protected].
  • Grievance officer — for escalations, contact our Grievance Officer at [email protected]. We respond within 48 hours.
  • Cross-border transfer — your data is stored in the USA (Supabase / AWS). We transfer data only to jurisdictions listed by the Board as permissible, or under contractual safeguards.

9. California / US privacy rights (CCPA / CPRA)

California residents have the right to know what personal information is collected, to delete it, to opt out of its sale, and to non-discrimination for exercising these rights.

Emvio does not sell personal information as defined by CCPA. We do not share personal information with third parties for cross-context behavioural advertising.

To exercise your California rights, email [email protected] with the subject line "California Privacy Request".

10. Cookies and tracking

We use one first-party cookie for theme preference (emvio-theme) and one for cookie consent state (emvio_cookie_consent). Neither contains personal data. We use Cloudflare CDN which may set short-lived security cookies. We do not use advertising trackers or third-party analytics cookies.

See our Cookie Policy for full details.

11. Contact and complaints

Data Protection contact: [email protected]

Grievance Officer (India): [email protected]

If you are in the EU/EEA and believe we have not handled your data appropriately, you may also contact your national data protection authority. A list of EU DPAs is available at edpb.europa.eu.

This privacy policy was last updated on 1 August 2026. We will notify registered users of material changes via email at least 30 days before they take effect.