01 · Data minimization
Collect for the assessment purpose
Campaigns use role, candidate, response, scoring, and report data needed to run the authorized workflow. Customers should not place unrelated sensitive information in job descriptions or candidate notes.
02 · Transmission
Protect data while it moves
Production web traffic and service calls use encrypted transport. API keys and service credentials stay server-side and are not embedded in candidate-facing pages or browser bundles.
03 · Access control
Keep employer workspaces separated
Authenticated portal roles scope access to the relevant organization and workflow. Candidate links are purpose-specific; recruiter and administrator actions remain separate from the candidate experience.
04 · Consent & notice
Tell candidates what the assessment does
The workflow is designed to present the assessment purpose, expected use, and relevant notice before participation. Employers remain responsible for role relevance, lawful basis, accommodations, and local requirements.
05 · Retention & deletion
Keep data only while it serves the authorized purpose
Retention should follow the customer’s hiring policy and applicable obligations. Authorized deletion requests are verified, scoped, and carried through the relevant candidate and report records rather than treated as an informal inbox request.
06 · Human accountability
Protect people from automated overreach
Theta and Titan organize evidence; they do not own the employment decision. Integrity flags and AI-assisted interpretations require review, and customers remain accountable for adverse decisions.