Privacy Policy
Effective date: 1 August 2026 · Last reviewed: 1 August 2026
1. Who we are
Emvio Intelligence ("Emvio", "we", "our") operates an AI-powered recruitment platform that enables companies to screen, interview, and shortlist candidates using voice AI. Our registered contact address for data-protection matters is: [email protected].
When a company uses Emvio to hire, the company is the Data Controller and Emvio is the Data Processor. When we collect data for our own purposes (account management, security, compliance), Emvio is the Controller. This policy covers both roles.
2. Data we collect
| Category | Examples | Who it applies to | Legal basis (GDPR) |
|---|---|---|---|
| Identity & contact | Name, email address, phone number | Candidates, company users | Art. 6(1)(b) — contract performance |
| Job application data | CV / résumé, job role applied for, application timestamp | Candidates | Art. 6(1)(b) — contract performance |
| Voice recording BIPA | Raw audio recorded during the AI interview session | Candidates | Art. 9(2)(a) — explicit consent |
| Interview transcript | Speech-to-text transcription of your interview answers | Candidates | Art. 9(2)(a) — explicit consent |
| AI assessment scores | Technical, experience, communication, and authenticity scores; hire signal | Candidates | Art. 9(2)(a) — explicit consent |
| Gaze / behavioural signals BIPA | Estimated gaze direction from browser camera (anti-cheat analysis) | Candidates (Phase 2 feature) | Art. 9(2)(a) — explicit consent |
| Anti-cheat metadata | Response latency timestamps (ms), audio artifact flags | Candidates | Art. 9(2)(a) — explicit consent |
| Account data | Company name, billing email, subscription plan, login timestamps | Company users | Art. 6(1)(b) — contract performance |
| Usage & log data | IP address, browser type, API call timestamps, error logs | All users | Art. 6(1)(f) — legitimate interest (security) |
We do not collect demographic data (race, gender, age, religion) and our scoring model does not use any demographic proxies.
3. How we use your data
- Conducting AI interviews — streaming your voice to our STT provider, generating interviewer questions, scoring answers in real time.
- Producing the hiring shortlist — ranking candidates by composite score and delivering a "hiring brief" to the company.
- Anti-cheat analysis — detecting response patterns inconsistent with genuine, unassisted answers. Results are visible only to Emvio and the hiring company.
- Platform operation — account authentication, billing, support, and security monitoring.
- Legal and compliance obligations — maintaining an immutable audit log as required by EU AI Act Art. 26 and responding to subject-access or erasure requests.
We do not sell, rent, or trade personal data to third parties. We do not use interview data to train our AI models without separate explicit consent.
4. Sub-processors
The following third parties process personal data on our behalf. All are bound by data-processing agreements requiring GDPR-equivalent protections.
| Sub-processor | Purpose | Data transferred | Location | Safeguard |
|---|---|---|---|---|
| Supabase Inc. | Relational database, authentication, file storage (résumés) | All candidate and company data, résumé files | USA (AWS us-east-1) | DPA + SCCs (EU–US) |
| OpenAI Inc. | LLM — job-description parsing, interview question generation, answer scoring, hiring brief | Anonymised interview transcript excerpts, job description text | USA | OpenAI DPA + SCCs; Zero Data Retention API option enabled |
| Sarvam AI Pvt. Ltd. | Text-to-speech (Riya's voice) and response humanisation LLM | Riya's generated text (no candidate personal data sent to TTS) | India | DPA under DPDP Act 2023 |
| Deepgram Inc. | Real-time speech-to-text (Nova-3 model) | Raw candidate voice audio (streaming) | USA | Deepgram DPA + SCCs; audio not retained by Deepgram after transcription |
| LiveKit Inc. | WebRTC room token issuance for video sessions | Room join tokens only — no media passes through LiveKit servers | USA | LiveKit DPA |
| Cloudflare Inc. | CDN, DNS, and static-site hosting (Pages) | IP addresses, HTTP request metadata | Global edge | Cloudflare DPA + SCCs |
We will notify you of any material change to this sub-processor list at least 30 days in advance via the email on your account.
5. Data retention
| Data type | Retention period | Reason |
|---|---|---|
| Application records & AI scores | 730 days (2 years) from application date | EEOC record-keeping guidance; pipeline re-engagement window |
| Interview voice recordings | 90 days from session end | Dispute resolution; Deepgram does not retain raw audio |
| Interview transcripts | 730 days (stored as part of application record) | Same as application records |
| Résumé / CV file | 730 days; deleted alongside application record | Storage cleanup enforced daily by automated script |
| Audit log entries | 7 years (append-only, cannot be deleted) | EU AI Act Art. 26 immutability requirement |
| Account & billing data | Duration of contract + 7 years | Tax and accounting obligations |
| Server / access logs | 90 days rolling | Security monitoring |
Expired records are automatically deleted by a daily retention job. You may request early erasure under Section 6.
6. Your rights
Depending on your jurisdiction you have some or all of the following rights. Submit requests via the Privacy & Data Centre in your candidate account, or email [email protected].
- Access (Art. 15 GDPR) — obtain a copy of the personal data we hold about you.
- Rectification (Art. 16) — correct inaccurate data.
- Erasure / "right to be forgotten" (Art. 17) — request deletion of your data. We will cascade-delete your application record, résumé file, and candidate profile within 30 days. Audit log entries cannot be erased (immutable by law).
- Restriction (Art. 18) — ask us to stop processing while a dispute is resolved.
- Portability (Art. 20) — receive your interview transcript and scores in machine-readable JSON.
- Object (Art. 21) — object to processing based on legitimate interest.
- Human review of automated decisions (Art. 22) — if your application was rejected solely by AI, you may request a human recruiter to personally review your assessment. Use the "Request Human Review" button on your My Applications page.
- Withdraw consent — withdraw at any time; withdrawal does not affect prior processing.
We respond to all rights requests within 30 days. If you believe we have violated your rights, you may lodge a complaint with your supervisory authority (EU: your national DPA; UK: ICO; India: Data Protection Board).
7. Illinois Biometric Information Privacy Act (BIPA) notice
If you are an Illinois resident, this section applies to you. Voice recordings and gaze-tracking data constitute biometric identifiers under 740 ILCS 14/ (BIPA).
What we collect
We collect voice audio and (in Phase 2) estimated gaze direction during AI interviews. Voice is transcribed by Deepgram and the audio is deleted within 90 days. Gaze signals are processed in-browser and only the derived behavioural flag is stored — raw camera frames are never transmitted to our servers.
Retention and destruction schedule
Biometric data is retained for the shorter of: (a) the initial purpose of the collection (the interview), (b) 3 years from collection, or (c) as required by applicable law. Under our standard policy, voice recordings are purged at 90 days and all remaining biometric-derived data is purged with the application record at 730 days. Our full, publicly available written biometric retention and destruction policy is at biometric-policy.html, in accordance with 740 ILCS 14/15(a).
No sale of biometric data
Emvio does not and will not sell, lease, trade, or profit from biometric identifiers or biometric information.
Consent
We obtain written consent via the interview entry screen before any biometric data is collected. You may revoke consent and request erasure of biometric data at any time by emailing [email protected].
8. India Digital Personal Data Protection Act 2023 (DPDP)
If you are in India, Emvio processes your data under the DPDP Act as a Data Fiduciary.
- Consent — we collect explicit consent before processing sensitive personal data (biometrics, health, financial).
- Purpose limitation — data is used only for the purposes stated in Section 3 of this policy.
- Data principal rights — you have the right to access, correct, erase, and nominate. Submit requests to [email protected].
- Grievance officer — for escalations, contact our Grievance Officer at [email protected]. We respond within 48 hours.
- Cross-border transfer — your data is stored in the USA (Supabase / AWS). We transfer data only to jurisdictions listed by the Board as permissible, or under contractual safeguards.
9. California / US privacy rights (CCPA / CPRA)
California residents have the right to know what personal information is collected, to delete it, to opt out of its sale, and to non-discrimination for exercising these rights.
Emvio does not sell personal information as defined by CCPA. We do not share personal information with third parties for cross-context behavioural advertising.
To exercise your California rights, email [email protected] with the subject line "California Privacy Request".
11. Contact and complaints
Data Protection contact: [email protected]
Grievance Officer (India): [email protected]
If you are in the EU/EEA and believe we have not handled your data appropriately, you may also contact your national data protection authority. A list of EU DPAs is available at edpb.europa.eu.
This privacy policy was last updated on 1 August 2026. We will notify registered users of material changes via email at least 30 days before they take effect.