jobhiring.AI / me.jobhiring.ai / jobhiring.AI Employer Portal
Effective Date: 8 August 2026
Last Updated: 8 August 2026
This GDPR Compliance & Data Protection Policy establishes the principles, controls, responsibilities, and procedures adopted by Minds Invasion LLC in relation to Personal Data subject to Regulation (EU) 2016/679, commonly known as the General Data Protection Regulation (“GDPR”). This Policy applies to the processing of Personal Data through the jobhiring.AI ecosystem, including:
Minds Invasion LLC DB Gurudev Complex, Phase 2 Sayli Road, Silvassa, India
support@jobhiring.ai
+965 66883733 For processing activities where Minds Invasion LLC determines the purposes and means of processing Personal Data, Minds Invasion LLC acts as the Data Controller within the meaning of Article 4(7) GDPR. Where Minds Invasion LLC processes Personal Data exclusively on documented instructions from an Employer or Recruitment Agency, it may act as a Data Processor within the meaning of Article 4(8) GDPR.
This Policy applies where processing falls within the territorial scope of Article 3 GDPR.
For purposes of this Policy, the EEA includes the Member States of the European Union together with Iceland, Liechtenstein, and Norway.
Where an inconsistency exists, mandatory requirements of the GDPR prevail.
Personal Data means information relating to an identified or identifiable natural person. Data Subject means the individual to whom Personal Data relates. Processing means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, alteration, retrieval, consultation, use, disclosure, transmission, dissemination, combination, restriction, erasure, or destruction. Controller means the person or organization determining the purposes and means of processing. Processor means an organization processing Personal Data on behalf of a Controller. Sub-processor means a Processor engaged by another Processor. Profiling means automated processing of Personal Data used to evaluate personal aspects relating to an individual. Special Categories of Personal Data have the meaning provided by Article 9 GDPR. Personal Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data. Supervisory Authority means an independent EEA data-protection authority established under the GDPR.
Minds Invasion LLC will seek to ensure that Personal Data subject to the GDPR is processed according to the principles contained in Article 5 GDPR.
Personal Data must be processed lawfully, fairly, and transparently.
Personal Data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
Only Personal Data reasonably necessary for a legitimate processing purpose should be collected.
Reasonable steps should be taken to ensure Personal Data is accurate and kept up to date where necessary.
Personal Data should not be retained in identifiable form longer than necessary.
Personal Data must be protected using appropriate technical and organizational measures.
Minds Invasion LLC must be able to demonstrate compliance with applicable GDPR requirements.
GDPR compliance is not satisfied merely by publishing a Privacy Policy. Minds Invasion LLC will seek to maintain appropriate compliance documentation and operational measures, including where applicable:
jobhiring.AI may process the following categories of Personal Data.
Business KYC Information
Article 9 GDPR provides enhanced protection for certain categories of Personal Data, including information revealing:
jobhiring.AI does not require Applicants to provide such information for ordinary recruitment unless legitimately necessary and legally permitted. Applicants should not voluntarily include unnecessary Special Category Data in their CV.
A normal Applicant photograph is not automatically Special Category Personal Data. A facial photograph may become biometric Personal Data under Article 9 where it is technically processed for the purpose of uniquely identifying an individual. If jobhiring.AI introduces facial-recognition, voiceprint, facial-template, or other biometric identification functionality, Minds Invasion LLC will conduct a separate legal assessment before implementation.
Personal Data concerning criminal convictions and offenses is governed by Article 10 GDPR. Minds Invasion LLC will not process such information unless authorized by applicable Union or Member State law or otherwise processed under appropriate official authority as required by Article 10. Employers must not use jobhiring.AI to conduct unlawful criminal-background screening.
Every processing activity subject to the GDPR must have a lawful basis. Minds Invasion LLC may rely on one or more lawful bases under Article 6 GDPR.
Contractual necessity will not be used where processing is merely useful but not objectively necessary to provide the requested service.
Article 6(1)(a) may be relied upon where an individual freely gives specific, informed, and unambiguous consent.
Where explicit consent is required, Minds Invasion LLC will seek an appropriate affirmative action satisfying GDPR requirements.
Minds Invasion LLC will not assume that silence, inactivity, or a pre-ticked box constitutes valid GDPR consent.
Where employment or recruitment circumstances create a power imbalance, consent will not automatically be relied upon if the individual cannot reasonably refuse without disadvantage.
Where processing is based on consent, Data Subjects may withdraw consent at any time. Withdrawal must be as easy as giving consent. Withdrawal will not affect the lawfulness of processing conducted before consent was withdrawn.
Minds Invasion LLC may rely on Article 6(1)(f) where processing is necessary for legitimate interests and those interests are not overridden by Data Subject rights and freedoms.
Where appropriate, Minds Invasion LLC will conduct a Legitimate Interests Assessment (“LIA”).
Article 6(1)(c) may apply where processing is necessary for Minds Invasion LLC to comply with a legal obligation.
Article 6(1)(d) or Article 6(1)(e) will only be relied upon where their legal requirements are genuinely satisfied. These bases are not expected to be the ordinary basis for operation of jobhiring.AI.
Minds Invasion LLC should maintain an internal record broadly identifying applicable purposes and legal bases.
| Processing Activity | Potential GDPR Basis |
|---|---|
| Applicant registration | Contract |
| Employer registration | Contract |
| Login/authentication | Contract / Legitimate Interests |
| Applicant job application | Contract |
| CV storage | Contract |
| Applicant KYC | Legitimate Interests / Legal Obligation where applicable |
| Employer KYC | Legitimate Interests / Legal Obligation where applicable |
| Fraud prevention | Legitimate Interests |
| Cybersecurity | Legitimate Interests / Legal Obligation |
| Optional marketing | Consent or other lawful basis where permitted |
| Non-essential analytics cookies | Consent where required |
| Subscription billing | Contract / Legal Obligation |
| Record retention for legal claims | Legitimate Interests / Legal Obligation |
| Required regulatory disclosures | Legal Obligation |
| AI candidate matching | Contract and/or Legitimate Interests depending on implementation |
| Significant automated decisions | Article 22 analysis required |
The actual basis must be assessed for each specific processing activity.
Applicant KYC may involve processing copies of passports, National IDs, or similar documents. Because government-identification information can create significant identity-theft risks, it should receive heightened protection.
Where possible, Employers should receive only an identity-verification status instead of unrestricted access to original Applicant identity documents.
Information about identifiable directors, representatives, or owners contained within business records may constitute Personal Data.
KYC does not justify indefinite collection of every field appearing on a document. Where technically and legally feasible, Minds Invasion LLC should consider:
CVs may contain substantial Personal Data. jobhiring.AI must therefore ensure that CV access is connected to legitimate recruitment purposes. Employers should not be given unrestricted access to every Applicant simply because they have an Employer account.
This design may support GDPR principles of data minimization and privacy by default. Employers must not attempt to circumvent contact-information restrictions.
These activities may constitute profiling within the meaning of Article 4 GDPR.
Where applicable, Data Subjects should be informed that AI or automated processing is being used.
Article 22 GDPR provides protections concerning decisions based solely on automated processing, including profiling, where such decisions produce legal effects or similarly significantly affect an individual. Employment and recruitment decisions can have significant effects on individuals. Accordingly, jobhiring.AI will not treat AI-generated candidate scores as an unrestricted basis for automatically rejecting or selecting EEA Applicants without an Article 22 assessment.
Where appropriate, jobhiring.AI should design recruitment workflows so that significant hiring decisions involve meaningful human review. Human review should be genuine rather than ceremonial.
Where a solely automated significant decision is used, it must satisfy an applicable Article 22 exception.
Where Article 22(2)(a) or Article 22(2)(c) applies, safeguards must include at least the ability to:
Additional restrictions apply where automated decision-making uses Special Category Data. Minds Invasion LLC will not use Special Category Data for significant automated recruitment decisions unless all applicable Article 9 and Article 22 requirements are satisfied.
Appropriate technical and organizational controls should be implemented where risks are identified.
Article 35 GDPR requires a Data Protection Impact Assessment where processing is likely to result in a high risk to individuals. A DPIA should be completed before high-risk processing begins.
Processing activities that should receive particular DPIA consideration include:
Where a DPIA identifies residual high risk that cannot be sufficiently mitigated, Minds Invasion LLC should consult the competent Supervisory Authority before commencing the processing as required by Article 36 GDPR.
Article 25 requires Data Protection by Design and by Default. Privacy considerations should therefore be integrated during development rather than added after deployment.
Articles 12, 13, and 14 GDPR require transparent information regarding processing.
Where Personal Data is collected directly from an Applicant or Employer representative, Article 13 transparency requirements should be provided at or around the time of collection as required.
Where an Employer uploads an Applicant CV that jobhiring.AI did not receive directly from the Applicant, Article 14 may apply. Minds Invasion LLC and the relevant Employer should determine which party is responsible for providing the required information.
Roles must be determined based on actual processing activities rather than labels in contracts.
Minds Invasion LLC as Controller
Employer as Independent Controller
Minds Invasion LLC as Processor Minds Invasion LLC may act as Processor where an Employer instructs the Platform to process Applicant Personal Data solely on the Employer’s behalf for a defined recruitment function.
Where Minds Invasion LLC and another party jointly determine both the purposes and essential means of processing, Article 26 joint-controller requirements may apply. Where joint controllership exists, the parties should transparently determine their respective responsibilities. The substance of the arrangement must be made available to Data Subjects where required.
Where Minds Invasion LLC acts as a Processor for an EEA Employer Controller, processing must be governed by an Article 28-compliant Data Processing Agreement.
Minds Invasion LLC may use third-party Sub-processors for activities including:
Where Article 28 applies, required authorization and contractual safeguards must be implemented before relevant Sub-processors process Personal Data.
Minds Invasion LLC should maintain an accurate internal list of Sub-processors processing GDPR-regulated Personal Data.
Chapter V GDPR restricts transfers of Personal Data outside the EEA. Minds Invasion LLC will use a legally recognized transfer mechanism where Chapter V applies.
Where the European Commission has issued an applicable adequacy decision for the destination country or framework, Personal Data may be transferred in accordance with Article 45 GDPR.
Where an adequacy decision does not apply and the relevant transfer qualifies for SCC use, Minds Invasion LLC may implement the European Commission’s applicable Standard Contractual Clauses (“SCCs”). The correct module must be selected depending on the parties’ roles.
Minds Invasion LLC operates from India. Where EEA Personal Data is transferred to India and no applicable adequacy mechanism covers the transfer, an appropriate Chapter V transfer safeguard must be implemented. This may include applicable SCCs where legally appropriate.
Where appropriate, transfers relying on SCCs should be supported by a documented assessment of:
Additional technical, contractual, or organizational safeguards should be implemented where necessary.
Where Article 3(2) GDPR applies to Minds Invasion LLC and the Article 27 exemption does not apply, Minds Invasion LLC must designate in writing a representative within the European Union. The representative should be established in a Member State where relevant Data Subjects are located.
regarding GDPR processing matters.
[To be formally appointed and published where Article 27 requires appointment.] This information must be updated before Minds Invasion LLC relies on this document as a complete Article 27 compliance notice for affected EEA operations.
Article 37 GDPR requires appointment of a Data Protection Officer in specified circumstances, including certain cases involving:
Because jobhiring.AI provides recruitment technology that may involve systematic Applicant profiling, candidate scoring, AI evaluation, and potentially large-scale Personal Data processing, Minds Invasion LLC should formally assess its Article 37 DPO obligations.
[To be formally designated and published where required.]
Minds Invasion LLC will maintain Article 30 Records of Processing Activities where required.
Separate records should be maintained for Controller and Processor activities where necessary.
Personal Data must not be retained indefinitely merely because storage is technically inexpensive. Retention periods should be linked to a legitimate business, contractual, security, or legal requirement. Minds Invasion LLC should maintain a documented retention schedule.
Applicant profile information may generally be retained while an Applicant account remains active.
Job-application information may be retained for reasonable recruitment, audit, fraud prevention, dispute, or legal purposes. Employers independently retaining downloaded Applicant Data must establish their own lawful retention periods.
Copies of Applicant identity documents should not be retained indefinitely.
Where feasible, the original document should be deleted after the need for retention ends while a limited verification record may be retained where lawful and necessary.
Expired documents should be securely replaced or deleted when no longer necessary.
Minds Invasion LLC will implement technical and organizational security measures appropriate to risk.
Access should be removed promptly when no longer necessary.
Technical and organizational measures should be periodically tested and evaluated where appropriate.
Minds Invasion LLC will maintain a documented Personal Data Breach process. Potential incidents should be promptly escalated to designated security and privacy personnel.
Where Minds Invasion LLC acts as Controller and a Personal Data Breach is likely to result in a risk to individuals’ rights and freedoms, the competent Supervisory Authority must be notified without undue delay and, where feasible, within 72 hours after becoming aware of the breach, as required by Article 33. If notification is delayed beyond 72 hours, reasons for the delay should be documented and provided where required.
Where Minds Invasion LLC acts as Processor, it must notify the relevant Controller without undue delay after becoming aware of a Personal Data Breach affecting Controller Personal Data. Processor contracts may impose additional reporting timelines.
Where a Personal Data Breach is likely to result in a high risk to Data Subjects, Article 34 may require communication to affected individuals without undue delay.
All qualifying Personal Data Breaches should be documented, including breaches not reported to a Supervisory Authority.
Subject to applicable GDPR conditions and exemptions, individuals may have rights including:
Under Article 15, a Data Subject may request confirmation whether Personal Data concerning them is being processed.
Under Article 16, individuals may request correction of inaccurate Personal Data and completion of incomplete Personal Data. Applicants should also be provided reasonable account functionality to update information directly where appropriate.
Under Article 17, Data Subjects may request deletion where applicable.
Deletion may not be required where processing remains necessary for reasons including:
Any retained information should remain limited to the applicable lawful purpose.
Article 18 may provide a right to restrict processing in circumstances including disputes regarding:
Restricted Personal Data should be appropriately flagged and access limited.
in a structured, commonly used, machine-readable format. Where technically feasible and legally applicable, information may be transmitted directly to another Controller.
Under Article 21, Data Subjects may object to processing based on particular grounds, including certain processing based on legitimate interests. Minds Invasion LLC must assess the objection and determine whether compelling legitimate grounds justify continued processing.
Where Personal Data is processed for direct marketing, an individual may object at any time. Upon such objection, relevant Personal Data must no longer be processed for those direct-marketing purposes.
Where Article 22 applies, individuals may be entitled to protections concerning significant solely automated decisions.
support@jobhiring.ai
Minds Invasion LLC may request information reasonably necessary to confirm the identity of a person exercising GDPR rights. Verification should be proportionate. The verification process should not unnecessarily collect additional sensitive Personal Data.
GDPR requests must be handled without undue delay and generally within one month of receipt. Where permitted under Article 12, the response period may be extended by up to two additional months where necessary because of complexity or number of requests. The individual must be informed of the extension and reasons within the initial one-month period.
GDPR requests should generally be handled free of charge. Where a request is manifestly unfounded or excessive, particularly because of repetitive character, the GDPR may permit:
Any refusal should be documented.
If Minds Invasion LLC declines a request, the Data Subject should be informed as required of:
EEA Data Subjects may have the right to lodge a complaint with a competent Supervisory Authority, particularly in the Member State of:
Minds Invasion LLC will cooperate with competent Supervisory Authorities where legally required.
Where an Employer is the Controller and Minds Invasion LLC acts as Processor, the Employer is generally responsible for responding to the Data Subject. Minds Invasion LLC will provide reasonable assistance consistent with Article 28 and the applicable Data Processing Agreement.
If an Employer downloads a CV or Applicant file and stores it in an independent system, Minds Invasion LLC may not be able to delete that Employer-controlled copy. The Employer remains independently responsible for applicable GDPR rights concerning its own copy.
Recruitment Agencies operating in the EEA or handling EEA Personal Data must determine their own GDPR role.
depending on the circumstances. A Recruitment Agency must not assume that jobhiring.AI’s GDPR compliance automatically satisfies the Agency’s own GDPR obligations.
Employers exporting Applicant information from jobhiring.AI become responsible for protecting the exported information. jobhiring.AI access controls cannot protect an exported copy once it has lawfully left the Platform.
Use of cookies and similar technologies may involve both GDPR and separate electronic-communications or ePrivacy rules. Non-essential analytics or advertising technologies should not be treated as automatically lawful merely because a general Privacy Policy exists. Where consent is legally required, appropriate consent should be obtained before relevant technologies are activated.
Where Google Analytics is used for EEA visitors, jobhiring.AI should configure the service consistently with applicable consent and data-protection requirements.
jobhiring.AI is primarily intended for persons legally permitted to seek employment and enter relevant contractual arrangements. Where GDPR protections concerning children apply, additional safeguards may be required. The Platform should avoid relying upon parental-consent rules as a substitute for compliance with employment-age restrictions.
Requests by governments or law-enforcement agencies for EEA Personal Data should be reviewed by authorized personnel where legally possible.
Where permitted, overbroad or unlawful requests should be challenged.
Vendors processing EEA Personal Data should undergo proportionate privacy and security due diligence.
Contracts with processors should contain GDPR-appropriate terms.
Personnel handling Personal Data should receive appropriate privacy and security training. Training should be proportionate to role.
may require additional specialized training.
Employees, contractors, and other personnel with Personal Data access should be bound by appropriate confidentiality obligations. Unauthorized disclosure may result in disciplinary, contractual, or legal consequences.
Access permissions should be reviewed periodically.
Personal Data used for developing, testing, tuning, or evaluating AI functionality requires its own lawful basis and purpose analysis. Applicant information collected for recruitment must not automatically be considered available for unrelated AI model training. Where Personal Data is proposed for AI training, Minds Invasion LLC should assess:
Where information is irreversibly anonymized so that an individual is no longer identifiable by reasonably likely means, the resulting information may fall outside GDPR Personal Data requirements. True anonymization should not be confused with pseudonymization.
Pseudonymized information remains Personal Data where re-identification remains possible using additional information. Pseudonymization may nevertheless be an important security and privacy safeguard.
Minds Invasion LLC may use appropriately aggregated or anonymized data for:
Where underlying Personal Data remains identifiable, GDPR obligations continue to apply.
AI systems and recruitment decisions may be adversely affected by inaccurate Personal Data.
Where legally required, individuals affected by automated processing should receive meaningful information regarding the logic involved rather than proprietary source code.
GDPR compliance must operate together with applicable EU and national anti-discrimination requirements. AI systems must not intentionally use sensitive or proxy information to produce unlawful discriminatory recruitment outcomes.
Member States may establish additional rules for processing Personal Data in the employment context under Article 88 GDPR. Employers recruiting in multiple EEA countries must therefore consider local employment privacy laws in addition to GDPR.
Minds Invasion LLC will seek to maintain sufficient evidence to demonstrate compliance.
Material new functionality involving Personal Data should undergo a privacy review before production deployment.
Minds Invasion LLC may conduct periodic internal or external GDPR-related audits.
Personnel who knowingly violate applicable data-protection requirements may be subject to:
Minds Invasion LLC will cooperate with competent EEA Supervisory Authorities to the extent required by law.
GDPR violations may result in significant regulatory measures. Depending on the provision breached, Article 83 permits administrative fines up to applicable statutory thresholds, which may include percentages of worldwide annual turnover. Minds Invasion LLC therefore treats GDPR compliance as a governance and operational responsibility rather than solely a contractual matter.
The United Kingdom operates a separate data-protection framework following its departure from the European Union. This Policy is primarily an EU/EEA GDPR Policy. UK Personal Data should also be handled according to applicable UK GDPR and UK Data Protection Act requirements.
Compliance with the GDPR does not itself establish compliance with European Union legislation governing artificial intelligence. AI systems used for employment, worker management, recruitment, candidate screening, or selection may have additional regulatory obligations under applicable EU AI legislation. Minds Invasion LLC should maintain a separate AI governance and regulatory-compliance program in addition to this GDPR Policy.
Material changes should be appropriately communicated.
Minds Invasion LLC Privacy & Data Protection – jobhiring.AI DB Gurudev Complex, Phase 2 Sayli Road, Silvassa, India
support@jobhiring.ai
+965 66883733
Where Article 27 GDPR requires Minds Invasion LLC to appoint an EU Representative, the representative’s identity and contact details must be published here and in applicable EEA Privacy Notices:
[TO BE APPOINTED]
[TO BE PROVIDED]
[TO BE PROVIDED] The representative must be formally appointed before this section should be represented to EEA users as completed Article 27 compliance.
Where Article 37 requires appointment of a Data Protection Officer, the DPO’s information should be published here:
[TO BE APPOINTED / CONFIRMED FOLLOWING ARTICLE 37 ASSESSMENT]
[TO BE PROVIDED] The DPO should be contactable directly by Data Subjects regarding issues relating to processing and GDPR rights.
Minds Invasion LLC recognizes that recruitment technology involves information capable of materially affecting individuals’ careers, opportunities, identities, and livelihoods. Accordingly, jobhiring.AI seeks to implement GDPR principles throughout the lifecycle of Applicant and Employer Personal Data.
GDPR compliance is an ongoing obligation. This Policy must therefore operate together with appropriate technology controls, contracts, internal procedures, risk assessments, staff training, security practices, and management oversight. Legal Entity: Minds Invasion LLC Platform: jobhiring.AI / me.jobhiring.ai Business Address: DB Gurudev Complex, Phase 2, Sayli Road, Silvassa, India Email: support@jobhiring.ai Telephone: +965 66883733 Effective Date: 8 August 2026 Last Updated: 8 August 2026
© 2026 Minds Invasion LLC. All Rights Reserved.