GDPR Compliance & Data Protection

Home / GDPR

GDPR Compliance & Data Protection Policy

jobhiring.AI / me.jobhiring.ai / jobhiring.AI Employer Portal

Effective Date: 8 August 2026

Last Updated: 8 August 2026

1. PURPOSE

This GDPR Compliance & Data Protection Policy establishes the principles, controls, responsibilities, and procedures adopted by Minds Invasion LLC in relation to Personal Data subject to Regulation (EU) 2016/679, commonly known as the General Data Protection Regulation (“GDPR”). This Policy applies to the processing of Personal Data through the jobhiring.AI ecosystem, including:

  • jobhiring.ai;
  • me.jobhiring.ai;
  • ai.jobhiring.ai;
  • Applicant Portal;
  • Employer Portal;
  • Recruitment Agency Portal functionality;
  • AI recruitment functionality;
  • Resume Builder;
  • CV analysis;
  • candidate matching;
  • interview management;
  • VoiceAI screening and interviews;
  • Applicant KYC;
  • Employer KYC;
  • job applications;
  • offer-letter functionality;
  • electronic-signature functionality;
  • recruitment communications;
  • related web and mobile applications;
  • APIs;
  • administrative systems;
  • databases;
  • support systems;
  • related services operated by Minds Invasion LLC.

2. LEGAL ENTITY

The jobhiring.AI Platform is owned and operated by

Minds Invasion LLC DB Gurudev Complex, Phase 2 Sayli Road, Silvassa, India

Privacy Contact

support@jobhiring.ai

Telephone

+965 66883733 For processing activities where Minds Invasion LLC determines the purposes and means of processing Personal Data, Minds Invasion LLC acts as the Data Controller within the meaning of Article 4(7) GDPR. Where Minds Invasion LLC processes Personal Data exclusively on documented instructions from an Employer or Recruitment Agency, it may act as a Data Processor within the meaning of Article 4(8) GDPR.

3. TERRITORIAL SCOPE

This Policy applies where processing falls within the territorial scope of Article 3 GDPR.

This may include circumstances where Minds Invasion LLC

  1. Processes Personal Data in the context of an establishment within the European Economic Area, if any;
  2. Offers services to individuals located within the European Economic Area;
  3. Provides job-search, Applicant, recruitment, subscription, or other Platform functionality to individuals located within the EEA;
  4. Monitors or profiles the behavior of individuals located within the EEA to the extent that such behavior takes place within the EEA;
  5. Processes EEA Personal Data on behalf of an Employer that is itself subject to the GDPR.

For purposes of this Policy, the EEA includes the Member States of the European Union together with Iceland, Liechtenstein, and Norway.

4. RELATIONSHIP WITH OTHER POLICIES

This Policy supplements the

  • jobhiring.AI Applicant Privacy Policy;
  • jobhiring.AI Employer Portal Privacy Policy;
  • jobhiring.AI Terms of Service;
  • Data Processing Agreements;
  • Standard Contractual Clauses;
  • internal security procedures;
  • retention procedures;
  • incident-response procedures;
  • AI governance procedures;
  • vendor-management procedures.

Where an inconsistency exists, mandatory requirements of the GDPR prevail.

5. GDPR DEFINITIONS

For purposes of this Policy

Personal Data means information relating to an identified or identifiable natural person. Data Subject means the individual to whom Personal Data relates. Processing means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, alteration, retrieval, consultation, use, disclosure, transmission, dissemination, combination, restriction, erasure, or destruction. Controller means the person or organization determining the purposes and means of processing. Processor means an organization processing Personal Data on behalf of a Controller. Sub-processor means a Processor engaged by another Processor. Profiling means automated processing of Personal Data used to evaluate personal aspects relating to an individual. Special Categories of Personal Data have the meaning provided by Article 9 GDPR. Personal Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data. Supervisory Authority means an independent EEA data-protection authority established under the GDPR.

6. GDPR DATA-PROTECTION PRINCIPLES

Minds Invasion LLC will seek to ensure that Personal Data subject to the GDPR is processed according to the principles contained in Article 5 GDPR.

These principles are

6.1 Lawfulness, Fairness and Transparency

Personal Data must be processed lawfully, fairly, and transparently.

6.2 Purpose Limitation

Personal Data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.

6.3 Data Minimization

Only Personal Data reasonably necessary for a legitimate processing purpose should be collected.

6.4 Accuracy

Reasonable steps should be taken to ensure Personal Data is accurate and kept up to date where necessary.

6.5 Storage Limitation

Personal Data should not be retained in identifiable form longer than necessary.

6.6 Integrity and Confidentiality

Personal Data must be protected using appropriate technical and organizational measures.

6.7 Accountability

Minds Invasion LLC must be able to demonstrate compliance with applicable GDPR requirements.

7. ACCOUNTABILITY

GDPR compliance is not satisfied merely by publishing a Privacy Policy. Minds Invasion LLC will seek to maintain appropriate compliance documentation and operational measures, including where applicable:

  • Records of Processing Activities;
  • Data Processing Agreements;
  • Data Protection Impact Assessments;
  • Legitimate Interest Assessments;
  • transfer assessments;
  • processor inventories;
  • sub-processor records;
  • consent records;
  • security documentation;
  • breach records;
  • retention schedules;
  • Data Subject request records;
  • privacy notices;
  • employee confidentiality requirements;
  • privacy and security training.

8. CATEGORIES OF PERSONAL DATA

jobhiring.AI may process the following categories of Personal Data.

Applicant Information

Including

  • name;
  • email;
  • mobile number;
  • address or location;
  • country;
  • state or province;
  • city;
  • date of birth where applicable;
  • nationality;
  • gender where lawfully collected;
  • Applicant photograph;
  • employment status;
  • availability;
  • salary expectations;
  • work history;
  • education;
  • skills;
  • qualifications;
  • professional licenses;
  • certifications;
  • languages;
  • CV information;
  • job applications;
  • interview information;
  • Applicant status;
  • offer information;
  • electronic signatures.

Applicant KYC Information

Including

  • National ID;
  • passport;
  • government identification;
  • document number;
  • issuing authority;
  • expiry information;
  • identity photograph;
  • verification status.

Employer Representative Information

Including

  • representative name;
  • business email;
  • telephone number;
  • job title;
  • department;
  • organization;
  • Employer Portal activity;
  • login information.

Business KYC Information

Including information contained in

  • Business Licenses;
  • Recruitment Agency Licenses;
  • Commercial Registration Certificates;
  • Certificates of Incorporation;
  • government registrations;
  • proof of business address;
  • authorized-signatory records.

Technical Information

Including

  • IP addresses;
  • browser information;
  • device information;
  • operating system;
  • login records;
  • security events;
  • session information;
  • analytics identifiers.

Recruitment Communications

Including

  • emails;
  • messages;
  • interview communications;
  • support correspondence;
  • VoiceAI interactions;
  • transcripts where applicable;
  • recruitment notifications.

9. SPECIAL CATEGORIES OF PERSONAL DATA

Article 9 GDPR provides enhanced protection for certain categories of Personal Data, including information revealing:

  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade union membership;
  • genetic data;
  • biometric data processed for uniquely identifying a person;
  • health information;
  • information concerning a person’s sex life;
  • sexual orientation.

jobhiring.AI does not require Applicants to provide such information for ordinary recruitment unless legitimately necessary and legally permitted. Applicants should not voluntarily include unnecessary Special Category Data in their CV.

10. PHOTOGRAPHS AND BIOMETRIC DATA

A normal Applicant photograph is not automatically Special Category Personal Data. A facial photograph may become biometric Personal Data under Article 9 where it is technically processed for the purpose of uniquely identifying an individual. If jobhiring.AI introduces facial-recognition, voiceprint, facial-template, or other biometric identification functionality, Minds Invasion LLC will conduct a separate legal assessment before implementation.

Where required, this may include

  • explicit consent;
  • DPIA;
  • Article 9 lawful-condition assessment;
  • enhanced security;
  • restricted retention;
  • separate transparency notices.

11. CRIMINAL-CONVICTION INFORMATION

Personal Data concerning criminal convictions and offenses is governed by Article 10 GDPR. Minds Invasion LLC will not process such information unless authorized by applicable Union or Member State law or otherwise processed under appropriate official authority as required by Article 10. Employers must not use jobhiring.AI to conduct unlawful criminal-background screening.

12. LAWFUL BASIS REQUIREMENT

Every processing activity subject to the GDPR must have a lawful basis. Minds Invasion LLC may rely on one or more lawful bases under Article 6 GDPR.

13. CONTRACTUAL NECESSITY

Article 6(1)(b) may apply where processing is objectively necessary to

  • create an Applicant account;
  • create an Employer account;
  • authenticate users;
  • deliver purchased subscription functionality;
  • process an Applicant’s requested job application;
  • provide Resume Builder functionality;
  • maintain Applicant application status;
  • deliver other requested Platform Services.

Contractual necessity will not be used where processing is merely useful but not objectively necessary to provide the requested service.

14. CONSENT

Article 6(1)(a) may be relied upon where an individual freely gives specific, informed, and unambiguous consent.

Consent may be relevant to

  • optional marketing;
  • certain analytics technologies;
  • non-essential cookies;
  • optional communications;
  • certain recording features;
  • optional data uses.

Where explicit consent is required, Minds Invasion LLC will seek an appropriate affirmative action satisfying GDPR requirements.

15. CONSENT MUST BE FREELY GIVEN

Minds Invasion LLC will not assume that silence, inactivity, or a pre-ticked box constitutes valid GDPR consent.

Consent should be

  • freely given;
  • specific;
  • informed;
  • unambiguous;
  • demonstrable;
  • capable of withdrawal.

Where employment or recruitment circumstances create a power imbalance, consent will not automatically be relied upon if the individual cannot reasonably refuse without disadvantage.

16. WITHDRAWAL OF CONSENT

Where processing is based on consent, Data Subjects may withdraw consent at any time. Withdrawal must be as easy as giving consent. Withdrawal will not affect the lawfulness of processing conducted before consent was withdrawn.

17. LEGITIMATE INTERESTS

Minds Invasion LLC may rely on Article 6(1)(f) where processing is necessary for legitimate interests and those interests are not overridden by Data Subject rights and freedoms.

Potential legitimate interests may include

  • fraud prevention;
  • account security;
  • cybersecurity;
  • Platform integrity;
  • detecting fake accounts;
  • preventing recruitment scams;
  • improving Platform reliability;
  • preventing abuse;
  • limited internal analytics;
  • establishment or defense of legal claims.

Where appropriate, Minds Invasion LLC will conduct a Legitimate Interests Assessment (“LIA”).

18. LEGITIMATE INTEREST ASSESSMENT

An LIA should generally consider

  1. What legitimate interest is being pursued;
  2. Whether the processing is necessary;
  3. Whether a less intrusive method is available;
  4. The nature of the information;
  5. The reasonable expectations of the Data Subject;
  6. The potential impact on the individual;
  7. Available safeguards;
  8. Whether the individual’s rights override the organization’s interests.

19. LEGAL OBLIGATION

Article 6(1)(c) may apply where processing is necessary for Minds Invasion LLC to comply with a legal obligation.

Examples may include

  • regulatory requirements;
  • taxation;
  • accounting obligations;
  • legally binding government requests;
  • compliance with judicial orders.

20. VITAL INTERESTS AND PUBLIC INTEREST

Article 6(1)(d) or Article 6(1)(e) will only be relied upon where their legal requirements are genuinely satisfied. These bases are not expected to be the ordinary basis for operation of jobhiring.AI.

21. PURPOSE AND LEGAL-BASIS MATRIX

Minds Invasion LLC should maintain an internal record broadly identifying applicable purposes and legal bases.

Examples include

Processing ActivityPotential GDPR Basis
Applicant registrationContract
Employer registrationContract
Login/authenticationContract / Legitimate Interests
Applicant job applicationContract
CV storageContract
Applicant KYCLegitimate Interests / Legal Obligation where applicable
Employer KYCLegitimate Interests / Legal Obligation where applicable
Fraud preventionLegitimate Interests
CybersecurityLegitimate Interests / Legal Obligation
Optional marketingConsent or other lawful basis where permitted
Non-essential analytics cookiesConsent where required
Subscription billingContract / Legal Obligation
Record retention for legal claimsLegitimate Interests / Legal Obligation
Required regulatory disclosuresLegal Obligation
AI candidate matchingContract and/or Legitimate Interests depending on implementation
Significant automated decisionsArticle 22 analysis required

The actual basis must be assessed for each specific processing activity.

22. KYC AND IDENTITY VERIFICATION

Applicant KYC may involve processing copies of passports, National IDs, or similar documents. Because government-identification information can create significant identity-theft risks, it should receive heightened protection.

Minds Invasion LLC will seek to apply

  • strict access controls;
  • limited internal access;
  • defined retention periods;
  • encryption where appropriate;
  • audit logging;
  • secure document storage;
  • appropriate deletion procedures.

Where possible, Employers should receive only an identity-verification status instead of unrestricted access to original Applicant identity documents.

23. EMPLOYER BUSINESS VERIFICATION

Business KYC information may be processed to

  • confirm Employer legal existence;
  • verify Recruitment Agency licenses;
  • prevent fake organizations;
  • protect Applicants;
  • prevent recruitment fraud;
  • verify authorization to recruit.

Information about identifiable directors, representatives, or owners contained within business records may constitute Personal Data.

24. DATA MINIMIZATION FOR KYC

KYC does not justify indefinite collection of every field appearing on a document. Where technically and legally feasible, Minds Invasion LLC should consider:

  • extracting only required information;
  • masking unnecessary numbers;
  • reducing unnecessary document accessibility;
  • storing verification results rather than original documents after verification where appropriate.

25. CV INFORMATION

CVs may contain substantial Personal Data. jobhiring.AI must therefore ensure that CV access is connected to legitimate recruitment purposes. Employers should not be given unrestricted access to every Applicant simply because they have an Employer account.

Access may be restricted based on

  • subscription;
  • recruitment relationship;
  • application status;
  • legitimate recruitment purpose;
  • user role;
  • Platform permissions.

26. CV DOWNLOAD CONTROLS

Where available, jobhiring.AI may provide

  • CV download without contact information; and
  • CV download with contact information.

This design may support GDPR principles of data minimization and privacy by default. Employers must not attempt to circumvent contact-information restrictions.

27. ARTIFICIAL INTELLIGENCE

jobhiring.AI may use AI or automated technologies for

  • CV parsing;
  • resume optimization;
  • candidate matching;
  • skills analysis;
  • candidate ranking;
  • recruitment recommendations;
  • interview analysis;
  • interview transcription;
  • VoiceAI screening;
  • fraud detection;
  • job recommendations.

These activities may constitute profiling within the meaning of Article 4 GDPR.

28. TRANSPARENCY ABOUT AI PROCESSING

Where applicable, Data Subjects should be informed that AI or automated processing is being used.

Information should explain in understandable terms

  • the purpose of the processing;
  • the categories of information used;
  • whether profiling is performed;
  • the likely consequences;
  • whether a decision is made solely by automated means;
  • relevant rights available to the individual.

29. AUTOMATED DECISION-MAKING — ARTICLE 22

Article 22 GDPR provides protections concerning decisions based solely on automated processing, including profiling, where such decisions produce legal effects or similarly significantly affect an individual. Employment and recruitment decisions can have significant effects on individuals. Accordingly, jobhiring.AI will not treat AI-generated candidate scores as an unrestricted basis for automatically rejecting or selecting EEA Applicants without an Article 22 assessment.

30. HUMAN OVERSIGHT

Where appropriate, jobhiring.AI should design recruitment workflows so that significant hiring decisions involve meaningful human review. Human review should be genuine rather than ceremonial.

The reviewer should have

  • authority to reconsider the AI result;
  • access to relevant information;
  • ability to correct errors;
  • ability to override recommendations.

31. ARTICLE 22 EXCEPTIONS

Where a solely automated significant decision is used, it must satisfy an applicable Article 22 exception.

Potential exceptions include

  • necessity for entering into or performing a contract;
  • authorization under Union or Member State law with appropriate safeguards;
  • explicit consent.

Where Article 22(2)(a) or Article 22(2)(c) applies, safeguards must include at least the ability to:

  • obtain human intervention;
  • express a point of view;
  • contest the decision.

32. SPECIAL CATEGORY DATA AND AUTOMATED DECISIONS

Additional restrictions apply where automated decision-making uses Special Category Data. Minds Invasion LLC will not use Special Category Data for significant automated recruitment decisions unless all applicable Article 9 and Article 22 requirements are satisfied.

33. AI ACCURACY AND BIAS CONTROLS

AI recruitment functionality should be periodically assessed for

  • accuracy;
  • discriminatory outcomes;
  • disproportionate error rates;
  • inappropriate proxy variables;
  • biased training or configuration;
  • model drift;
  • false matches;
  • inappropriate automated rejection.

Appropriate technical and organizational controls should be implemented where risks are identified.

34. DATA PROTECTION IMPACT ASSESSMENTS

Article 35 GDPR requires a Data Protection Impact Assessment where processing is likely to result in a high risk to individuals. A DPIA should be completed before high-risk processing begins.

35. JOBHIRING.AI DPIA TRIGGERS

Processing activities that should receive particular DPIA consideration include:

  • systematic AI candidate profiling;
  • candidate scoring;
  • automated recruitment decisions;
  • large-scale CV processing;
  • large-scale KYC processing;
  • processing Special Category Data at scale;
  • biometric identification;
  • systematic monitoring;
  • VoiceAI interview analysis;
  • combining multiple Applicant datasets;
  • large-scale international recruitment databases.

36. DPIA CONTENT

A DPIA should include at least

  1. Description of processing;
  2. Processing purposes;
  3. Legitimate interests where applicable;
  4. Necessity assessment;
  5. Proportionality assessment;
  6. Risks to rights and freedoms;
  7. Safeguards;
  8. Security controls;
  9. Mitigation measures.

37. PRIOR CONSULTATION

Where a DPIA identifies residual high risk that cannot be sufficiently mitigated, Minds Invasion LLC should consult the competent Supervisory Authority before commencing the processing as required by Article 36 GDPR.

38. PRIVACY BY DESIGN

Article 25 requires Data Protection by Design and by Default. Privacy considerations should therefore be integrated during development rather than added after deployment.

Engineering and product teams should consider privacy during

  • feature design;
  • database design;
  • API design;
  • AI functionality;
  • Employer permissions;
  • CV access;
  • KYC systems;
  • analytics implementation;
  • integrations;
  • new vendor onboarding.

39. PRIVACY BY DEFAULT

Default Platform settings should, where appropriate

  • limit unnecessary visibility;
  • restrict sensitive information;
  • provide least-privilege access;
  • minimize Applicant exposure;
  • restrict KYC document access;
  • avoid unnecessary public disclosure;
  • minimize retention.

40. TRANSPARENCY REQUIREMENTS

Articles 12, 13, and 14 GDPR require transparent information regarding processing.

Privacy notices should use language that is

  • concise;
  • transparent;
  • intelligible;
  • easily accessible;
  • clear.

Relevant information may include

  • Controller identity;
  • contact information;
  • DPO contact information where applicable;
  • purposes;
  • legal bases;
  • legitimate interests;
  • recipients;
  • transfers;
  • retention;
  • Data Subject rights;
  • right to complain;
  • consent withdrawal rights;
  • automated decision-making information.

41. INFORMATION COLLECTED DIRECTLY

Where Personal Data is collected directly from an Applicant or Employer representative, Article 13 transparency requirements should be provided at or around the time of collection as required.

42. INFORMATION OBTAINED INDIRECTLY

Where an Employer uploads an Applicant CV that jobhiring.AI did not receive directly from the Applicant, Article 14 may apply. Minds Invasion LLC and the relevant Employer should determine which party is responsible for providing the required information.

Applicable notices may need to identify

  • categories of Personal Data;
  • source of the information;
  • processing purposes;
  • legal basis;
  • recipients;
  • retention;
  • rights.

43. CONTROLLER AND PROCESSOR ROLES

Roles must be determined based on actual processing activities rather than labels in contracts.

For example

Minds Invasion LLC as Controller

Minds Invasion LLC may act as Controller for

  • Applicant account registration;
  • Platform authentication;
  • KYC verification conducted for Platform trust and safety;
  • fraud prevention;
  • cybersecurity;
  • billing;
  • Platform analytics;
  • compliance;
  • Platform-level Applicant services.

Employer as Independent Controller

An Employer may act as Controller when deciding

  • which Applicants to recruit;
  • what qualifications are required;
  • who is shortlisted;
  • who is interviewed;
  • who is hired;
  • how exported Applicant data is retained.

Minds Invasion LLC as Processor Minds Invasion LLC may act as Processor where an Employer instructs the Platform to process Applicant Personal Data solely on the Employer’s behalf for a defined recruitment function.

44. JOINT CONTROLLERS

Where Minds Invasion LLC and another party jointly determine both the purposes and essential means of processing, Article 26 joint-controller requirements may apply. Where joint controllership exists, the parties should transparently determine their respective responsibilities. The substance of the arrangement must be made available to Data Subjects where required.

45. DATA PROCESSING AGREEMENTS

Where Minds Invasion LLC acts as a Processor for an EEA Employer Controller, processing must be governed by an Article 28-compliant Data Processing Agreement.

The agreement should address

  • subject matter;
  • duration;
  • nature;
  • purpose;
  • Personal Data categories;
  • Data Subject categories;
  • Controller rights;
  • Controller obligations.

46. PROCESSOR OBLIGATIONS

Where acting as Processor, Minds Invasion LLC must, as applicable

  • process only on documented instructions;
  • ensure confidentiality;
  • implement Article 32 security measures;
  • comply with sub-processor requirements;
  • assist with Data Subject rights;
  • assist with breach compliance;
  • assist with DPIAs;
  • delete or return Personal Data at the end of Services as applicable;
  • provide compliance information;
  • support permitted audits.

47. SUB-PROCESSORS

Minds Invasion LLC may use third-party Sub-processors for activities including:

  • hosting;
  • cloud computing;
  • AI;
  • communications;
  • analytics;
  • identity verification;
  • databases;
  • monitoring;
  • support.

Where Article 28 applies, required authorization and contractual safeguards must be implemented before relevant Sub-processors process Personal Data.

48. SUB-PROCESSOR INVENTORY

Minds Invasion LLC should maintain an accurate internal list of Sub-processors processing GDPR-regulated Personal Data.

The list should identify, where appropriate

  • legal entity;
  • service;
  • processing purpose;
  • processing location;
  • transfer mechanism.

49. INTERNATIONAL TRANSFERS

Chapter V GDPR restricts transfers of Personal Data outside the EEA. Minds Invasion LLC will use a legally recognized transfer mechanism where Chapter V applies.

50. ADEQUACY DECISIONS

Where the European Commission has issued an applicable adequacy decision for the destination country or framework, Personal Data may be transferred in accordance with Article 45 GDPR.

51. STANDARD CONTRACTUAL CLAUSES

Where an adequacy decision does not apply and the relevant transfer qualifies for SCC use, Minds Invasion LLC may implement the European Commission’s applicable Standard Contractual Clauses (“SCCs”). The correct module must be selected depending on the parties’ roles.

Possible modules include

  • Controller to Controller;
  • Controller to Processor;
  • Processor to Processor;
  • Processor to Controller.

52. TRANSFERS TO INDIA

Minds Invasion LLC operates from India. Where EEA Personal Data is transferred to India and no applicable adequacy mechanism covers the transfer, an appropriate Chapter V transfer safeguard must be implemented. This may include applicable SCCs where legally appropriate.

53. TRANSFER IMPACT ASSESSMENTS

Where appropriate, transfers relying on SCCs should be supported by a documented assessment of:

  • transfer circumstances;
  • destination-country law;
  • access by government authorities;
  • nature of the Personal Data;
  • security controls;
  • supplementary safeguards.

Additional technical, contractual, or organizational safeguards should be implemented where necessary.

54. SUPPLEMENTARY TRANSFER SAFEGUARDS

Depending on the transfer, safeguards may include

  • encryption;
  • pseudonymization;
  • strong access controls;
  • minimization;
  • restricted administrative access;
  • contractual commitments;
  • transparency reporting;
  • government-request review procedures.

55. ARTICLE 27 EEA REPRESENTATIVE

Where Article 3(2) GDPR applies to Minds Invasion LLC and the Article 27 exemption does not apply, Minds Invasion LLC must designate in writing a representative within the European Union. The representative should be established in a Member State where relevant Data Subjects are located.

The representative may be contacted by

  • Data Subjects;
  • Supervisory Authorities

regarding GDPR processing matters.

EU Representative Details

[To be formally appointed and published where Article 27 requires appointment.] This information must be updated before Minds Invasion LLC relies on this document as a complete Article 27 compliance notice for affected EEA operations.

56. DATA PROTECTION OFFICER

Article 37 GDPR requires appointment of a Data Protection Officer in specified circumstances, including certain cases involving:

  • large-scale regular and systematic monitoring; or
  • large-scale processing of Special Category Data.

Because jobhiring.AI provides recruitment technology that may involve systematic Applicant profiling, candidate scoring, AI evaluation, and potentially large-scale Personal Data processing, Minds Invasion LLC should formally assess its Article 37 DPO obligations.

Where appointment is legally required, the DPO must

  • have appropriate expertise;
  • operate independently;
  • report to the highest management level;
  • receive adequate resources;
  • not receive instructions regarding performance of DPO duties;
  • avoid conflicts of interest.

DPO Contact Details

[To be formally designated and published where required.]

57. DPO RESPONSIBILITIES

Where appointed, the DPO’s responsibilities may include

  • advising Minds Invasion LLC;
  • monitoring GDPR compliance;
  • awareness and training;
  • advising on DPIAs;
  • cooperating with Supervisory Authorities;
  • acting as contact point for Supervisory Authorities;
  • monitoring privacy governance.

58. RECORDS OF PROCESSING ACTIVITIES

Minds Invasion LLC will maintain Article 30 Records of Processing Activities where required.

Records should identify, as applicable

  • processing purposes;
  • Data Subject categories;
  • Personal Data categories;
  • recipients;
  • international transfers;
  • retention periods;
  • security measures.

Separate records should be maintained for Controller and Processor activities where necessary.

59. DATA RETENTION

Personal Data must not be retained indefinitely merely because storage is technically inexpensive. Retention periods should be linked to a legitimate business, contractual, security, or legal requirement. Minds Invasion LLC should maintain a documented retention schedule.

60. APPLICANT PROFILE RETENTION

Applicant profile information may generally be retained while an Applicant account remains active.

Following closure, information should be

  • deleted;
  • anonymized;
  • or retained only where an appropriate legal basis remains.

61. APPLICATION RECORD RETENTION

Job-application information may be retained for reasonable recruitment, audit, fraud prevention, dispute, or legal purposes. Employers independently retaining downloaded Applicant Data must establish their own lawful retention periods.

62. KYC RETENTION

Copies of Applicant identity documents should not be retained indefinitely.

Retention should be based on

  • verification needs;
  • re-verification needs;
  • fraud-prevention requirements;
  • legal obligations;
  • dispute periods.

Where feasible, the original document should be deleted after the need for retention ends while a limited verification record may be retained where lawful and necessary.

63. EMPLOYER KYC RETENTION

Business-verification documents may be retained while necessary to

  • maintain Employer verification;
  • conduct re-verification;
  • prevent fraud;
  • establish licensing history;
  • meet legal requirements.

Expired documents should be securely replaced or deleted when no longer necessary.

64. SECURITY — ARTICLE 32

Minds Invasion LLC will implement technical and organizational security measures appropriate to risk.

Measures may include

  • encryption;
  • pseudonymization;
  • authentication;
  • access controls;
  • secure password hashing;
  • network protections;
  • logging;
  • monitoring;
  • backup;
  • disaster recovery;
  • vulnerability management;
  • security testing;
  • secure software-development practices.

65. ACCESS CONTROL

Access should follow the principles of

  • least privilege;
  • need to know;
  • role-based access.

Particular restrictions should apply to

  • KYC documents;
  • Applicant contact information;
  • CV exports;
  • administrative systems;
  • security logs.

66. EMPLOYEE AND CONTRACTOR ACCESS

Personnel with access to Personal Data must be subject to appropriate

  • confidentiality obligations;
  • access controls;
  • privacy training;
  • security requirements.

Access should be removed promptly when no longer necessary.

67. SECURITY TESTING

Technical and organizational measures should be periodically tested and evaluated where appropriate.

This may include

  • vulnerability assessments;
  • penetration testing;
  • access reviews;
  • incident exercises;
  • backup recovery tests;
  • security audits.

68. PERSONAL DATA BREACH MANAGEMENT

Minds Invasion LLC will maintain a documented Personal Data Breach process. Potential incidents should be promptly escalated to designated security and privacy personnel.

69. BREACH RISK ASSESSMENT

Each Personal Data Breach should be assessed based on

  • type of Personal Data;
  • volume;
  • sensitivity;
  • identifiability;
  • number of Data Subjects;
  • potential identity theft;
  • financial risk;
  • employment impact;
  • discrimination risk;
  • confidentiality impact;
  • availability of mitigation.

70. SUPERVISORY AUTHORITY NOTIFICATION

Where Minds Invasion LLC acts as Controller and a Personal Data Breach is likely to result in a risk to individuals’ rights and freedoms, the competent Supervisory Authority must be notified without undue delay and, where feasible, within 72 hours after becoming aware of the breach, as required by Article 33. If notification is delayed beyond 72 hours, reasons for the delay should be documented and provided where required.

71. PROCESSOR BREACH NOTIFICATION

Where Minds Invasion LLC acts as Processor, it must notify the relevant Controller without undue delay after becoming aware of a Personal Data Breach affecting Controller Personal Data. Processor contracts may impose additional reporting timelines.

72. COMMUNICATION TO AFFECTED INDIVIDUALS

Where a Personal Data Breach is likely to result in a high risk to Data Subjects, Article 34 may require communication to affected individuals without undue delay.

The communication should explain in clear language

  • nature of the breach;
  • contact point;
  • likely consequences;
  • measures taken or proposed.

73. BREACH REGISTER

All qualifying Personal Data Breaches should be documented, including breaches not reported to a Supervisory Authority.

Records should include

  • facts;
  • effects;
  • risk assessment;
  • remedial action;
  • notification decisions.

74. DATA SUBJECT RIGHTS

Subject to applicable GDPR conditions and exemptions, individuals may have rights including:

  • right to information;
  • right of access;
  • right to rectification;
  • right to erasure;
  • right to restriction;
  • right to portability;
  • right to object;
  • rights concerning automated decision-making;
  • right to withdraw consent;
  • right to complain.

75. RIGHT OF ACCESS

Under Article 15, a Data Subject may request confirmation whether Personal Data concerning them is being processed.

Where applicable, they may receive

  • access to the Personal Data;
  • processing purposes;
  • categories;
  • recipients;
  • retention information;
  • rights;
  • source information;
  • automated-decision information;
  • transfer safeguard information.

76. RIGHT TO RECTIFICATION

Under Article 16, individuals may request correction of inaccurate Personal Data and completion of incomplete Personal Data. Applicants should also be provided reasonable account functionality to update information directly where appropriate.

77. RIGHT TO ERASURE

Under Article 17, Data Subjects may request deletion where applicable.

Examples may include where

  • Personal Data is no longer necessary;
  • consent is withdrawn and no other basis exists;
  • an objection succeeds;
  • processing was unlawful;
  • deletion is required by law.

78. ERASURE IS NOT ABSOLUTE

Deletion may not be required where processing remains necessary for reasons including:

  • legal obligations;
  • establishment, exercise, or defense of legal claims;
  • certain public-interest purposes;
  • other GDPR-recognized exceptions.

Any retained information should remain limited to the applicable lawful purpose.

79. RIGHT TO RESTRICTION

Article 18 may provide a right to restrict processing in circumstances including disputes regarding:

  • accuracy;
  • lawfulness;
  • legitimate-interest objections;
  • retention necessary for legal claims.

Restricted Personal Data should be appropriately flagged and access limited.

80. DATA PORTABILITY

Where Article 20 applies, individuals may request Personal Data

  • provided by them;
  • processed based on consent or contract;
  • processed by automated means

in a structured, commonly used, machine-readable format. Where technically feasible and legally applicable, information may be transmitted directly to another Controller.

81. RIGHT TO OBJECT

Under Article 21, Data Subjects may object to processing based on particular grounds, including certain processing based on legitimate interests. Minds Invasion LLC must assess the objection and determine whether compelling legitimate grounds justify continued processing.

82. DIRECT MARKETING OBJECTION

Where Personal Data is processed for direct marketing, an individual may object at any time. Upon such objection, relevant Personal Data must no longer be processed for those direct-marketing purposes.

83. AUTOMATED-DECISION RIGHTS

Where Article 22 applies, individuals may be entitled to protections concerning significant solely automated decisions.

Applicable safeguards may include

  • human intervention;
  • expressing a point of view;
  • contesting the decision.

84. EXERCISING GDPR RIGHTS

GDPR-related requests may be submitted to

support@jobhiring.ai

Requests may concern

  • Applicants;
  • Employer representatives;
  • other relevant Data Subjects.

85. IDENTITY VERIFICATION FOR REQUESTS

Minds Invasion LLC may request information reasonably necessary to confirm the identity of a person exercising GDPR rights. Verification should be proportionate. The verification process should not unnecessarily collect additional sensitive Personal Data.

86. RESPONSE TIME

GDPR requests must be handled without undue delay and generally within one month of receipt. Where permitted under Article 12, the response period may be extended by up to two additional months where necessary because of complexity or number of requests. The individual must be informed of the extension and reasons within the initial one-month period.

87. FEES FOR RIGHTS REQUESTS

GDPR requests should generally be handled free of charge. Where a request is manifestly unfounded or excessive, particularly because of repetitive character, the GDPR may permit:

  • a reasonable fee; or
  • refusal to act.

Any refusal should be documented.

88. REJECTED REQUESTS

If Minds Invasion LLC declines a request, the Data Subject should be informed as required of:

  • reasons for the decision;
  • right to complain to a Supervisory Authority;
  • right to seek judicial remedy.

89. SUPERVISORY AUTHORITY COMPLAINTS

EEA Data Subjects may have the right to lodge a complaint with a competent Supervisory Authority, particularly in the Member State of:

  • habitual residence;
  • place of work;
  • alleged infringement.

Minds Invasion LLC will cooperate with competent Supervisory Authorities where legally required.

90. EMPLOYER DATA SUBJECT REQUEST RESPONSIBILITIES

Where an Employer is the Controller and Minds Invasion LLC acts as Processor, the Employer is generally responsible for responding to the Data Subject. Minds Invasion LLC will provide reasonable assistance consistent with Article 28 and the applicable Data Processing Agreement.

91. EMPLOYER INDEPENDENT COPIES

If an Employer downloads a CV or Applicant file and stores it in an independent system, Minds Invasion LLC may not be able to delete that Employer-controlled copy. The Employer remains independently responsible for applicable GDPR rights concerning its own copy.

92. RECRUITMENT AGENCY RESPONSIBILITIES

Recruitment Agencies operating in the EEA or handling EEA Personal Data must determine their own GDPR role.

They may be

  • independent Controllers;
  • Processors;
  • joint Controllers

depending on the circumstances. A Recruitment Agency must not assume that jobhiring.AI’s GDPR compliance automatically satisfies the Agency’s own GDPR obligations.

93. EMPLOYER GDPR RESPONSIBILITIES

Employers using the Employer Portal to process EEA Applicant Data must

  • establish an appropriate lawful basis;
  • provide required transparency notices;
  • honor Data Subject rights;
  • maintain appropriate retention periods;
  • implement security;
  • restrict internal access;
  • comply with Article 22 where applicable;
  • comply with Chapter V transfer rules;
  • comply with applicable employment law.

94. DATA EXPORTS BY EMPLOYERS

Employers exporting Applicant information from jobhiring.AI become responsible for protecting the exported information. jobhiring.AI access controls cannot protect an exported copy once it has lawfully left the Platform.

Employers should

  • encrypt exports where appropriate;
  • restrict access;
  • maintain retention controls;
  • prevent unauthorized redistribution.

95. ANALYTICS AND COOKIES

Use of cookies and similar technologies may involve both GDPR and separate electronic-communications or ePrivacy rules. Non-essential analytics or advertising technologies should not be treated as automatically lawful merely because a general Privacy Policy exists. Where consent is legally required, appropriate consent should be obtained before relevant technologies are activated.

96. GOOGLE ANALYTICS

Where Google Analytics is used for EEA visitors, jobhiring.AI should configure the service consistently with applicable consent and data-protection requirements.

Appropriate controls may include

  • cookie consent;
  • analytics-storage controls;
  • retention settings;
  • restricted data collection;
  • appropriate international-transfer arrangements.

97. CHILDREN

jobhiring.AI is primarily intended for persons legally permitted to seek employment and enter relevant contractual arrangements. Where GDPR protections concerning children apply, additional safeguards may be required. The Platform should avoid relying upon parental-consent rules as a substitute for compliance with employment-age restrictions.

98. GOVERNMENT REQUESTS

Requests by governments or law-enforcement agencies for EEA Personal Data should be reviewed by authorized personnel where legally possible.

Minds Invasion LLC should assess

  • legal validity;
  • scope;
  • authority;
  • necessity;
  • applicable transfer obligations.

Where permitted, overbroad or unlawful requests should be challenged.

99. VENDOR DUE DILIGENCE

Vendors processing EEA Personal Data should undergo proportionate privacy and security due diligence.

Assessment may include

  • security measures;
  • processing location;
  • Sub-processors;
  • breach history;
  • certifications;
  • data-retention practices;
  • international-transfer arrangements.

100. VENDOR CONTRACTS

Contracts with processors should contain GDPR-appropriate terms.

Where relevant, contracts should address

  • confidentiality;
  • security;
  • instructions;
  • breach notification;
  • Sub-processors;
  • Data Subject rights;
  • audits;
  • termination;
  • deletion or return;
  • international transfers.

101. STAFF TRAINING

Personnel handling Personal Data should receive appropriate privacy and security training. Training should be proportionate to role.

Personnel dealing with

  • KYC;
  • Applicant data;
  • AI systems;
  • customer support;
  • database administration;
  • security incidents

may require additional specialized training.

102. CONFIDENTIALITY

Employees, contractors, and other personnel with Personal Data access should be bound by appropriate confidentiality obligations. Unauthorized disclosure may result in disciplinary, contractual, or legal consequences.

103. INTERNAL ACCESS REVIEWS

Access permissions should be reviewed periodically.

Reviews should specifically consider

  • former employees;
  • changed roles;
  • administrator privileges;
  • KYC access;
  • production database access;
  • Applicant-data export capabilities.

104. AI DEVELOPMENT DATA

Personal Data used for developing, testing, tuning, or evaluating AI functionality requires its own lawful basis and purpose analysis. Applicant information collected for recruitment must not automatically be considered available for unrelated AI model training. Where Personal Data is proposed for AI training, Minds Invasion LLC should assess:

  • compatibility of purpose;
  • lawful basis;
  • transparency;
  • minimization;
  • ability to anonymize;
  • Data Subject expectations;
  • Article 9 implications;
  • Article 22 implications.

105. ANONYMIZATION

Where information is irreversibly anonymized so that an individual is no longer identifiable by reasonably likely means, the resulting information may fall outside GDPR Personal Data requirements. True anonymization should not be confused with pseudonymization.

106. PSEUDONYMIZATION

Pseudonymized information remains Personal Data where re-identification remains possible using additional information. Pseudonymization may nevertheless be an important security and privacy safeguard.

107. AGGREGATED RECRUITMENT ANALYTICS

Minds Invasion LLC may use appropriately aggregated or anonymized data for:

  • labor-market analytics;
  • Platform statistics;
  • product improvement;
  • recruitment trends;
  • service planning.

Where underlying Personal Data remains identifiable, GDPR obligations continue to apply.

108. DATA QUALITY

AI systems and recruitment decisions may be adversely affected by inaccurate Personal Data.

Reasonable processes should therefore exist to

  • allow Applicants to update CVs;
  • correct employment history;
  • update availability;
  • correct account information;
  • challenge inaccurate automated information.

109. AUTOMATED SCORE EXPLANATIONS

Where legally required, individuals affected by automated processing should receive meaningful information regarding the logic involved rather than proprietary source code.

Information may explain

  • broad factors considered;
  • categories of inputs;
  • significance of processing;
  • potential consequences.

110. NON-DISCRIMINATION

GDPR compliance must operate together with applicable EU and national anti-discrimination requirements. AI systems must not intentionally use sensitive or proxy information to produce unlawful discriminatory recruitment outcomes.

111. EMPLOYMENT CONTEXT

Member States may establish additional rules for processing Personal Data in the employment context under Article 88 GDPR. Employers recruiting in multiple EEA countries must therefore consider local employment privacy laws in addition to GDPR.

112. DOCUMENTATION

Minds Invasion LLC will seek to maintain sufficient evidence to demonstrate compliance.

Documentation may include

  • policies;
  • DPIAs;
  • LIAs;
  • security assessments;
  • contracts;
  • SCCs;
  • Data Subject request logs;
  • breach logs;
  • privacy-design reviews;
  • consent records;
  • training records.

113. INTERNAL GDPR REVIEW

Material new functionality involving Personal Data should undergo a privacy review before production deployment.

Examples include

  • new AI scoring algorithms;
  • facial recognition;
  • new KYC vendors;
  • new Applicant monitoring;
  • new analytics platforms;
  • new international hosting regions;
  • new Applicant-data marketplaces or integrations.

114. AUDITS

Minds Invasion LLC may conduct periodic internal or external GDPR-related audits.

Reviews may assess

  • lawful bases;
  • access permissions;
  • international transfers;
  • retention;
  • processors;
  • security;
  • AI governance;
  • Data Subject rights handling.

115. POLICY VIOLATIONS

Personnel who knowingly violate applicable data-protection requirements may be subject to:

  • access restriction;
  • disciplinary action;
  • contractual consequences;
  • other lawful corrective measures.

116. REGULATORY COOPERATION

Minds Invasion LLC will cooperate with competent EEA Supervisory Authorities to the extent required by law.

This may include

  • responding to inquiries;
  • preserving records;
  • providing compliance information;
  • implementing legally binding orders.

117. GDPR FINES AND ENFORCEMENT

GDPR violations may result in significant regulatory measures. Depending on the provision breached, Article 83 permits administrative fines up to applicable statutory thresholds, which may include percentages of worldwide annual turnover. Minds Invasion LLC therefore treats GDPR compliance as a governance and operational responsibility rather than solely a contractual matter.

118. UK GDPR

The United Kingdom operates a separate data-protection framework following its departure from the European Union. This Policy is primarily an EU/EEA GDPR Policy. UK Personal Data should also be handled according to applicable UK GDPR and UK Data Protection Act requirements.

Separate UK requirements may apply regarding

  • representatives;
  • international transfers;
  • supervisory authority;
  • automated decision-making;
  • local statutory changes.

119. EU AI REGULATION

Compliance with the GDPR does not itself establish compliance with European Union legislation governing artificial intelligence. AI systems used for employment, worker management, recruitment, candidate screening, or selection may have additional regulatory obligations under applicable EU AI legislation. Minds Invasion LLC should maintain a separate AI governance and regulatory-compliance program in addition to this GDPR Policy.

120. POLICY CHANGES

Minds Invasion LLC may update this Policy to reflect

  • GDPR guidance;
  • court decisions;
  • enforcement developments;
  • Platform changes;
  • AI developments;
  • new services;
  • security changes;
  • regulatory requirements.

Material changes should be appropriately communicated.

121. GDPR CONTACT

Questions or requests regarding GDPR compliance may be submitted to

Minds Invasion LLC Privacy & Data Protection – jobhiring.AI DB Gurudev Complex, Phase 2 Sayli Road, Silvassa, India

Email

support@jobhiring.ai

Telephone

+965 66883733

122. EU REPRESENTATIVE

Where Article 27 GDPR requires Minds Invasion LLC to appoint an EU Representative, the representative’s identity and contact details must be published here and in applicable EEA Privacy Notices:

EU Representative

[TO BE APPOINTED]

Address

[TO BE PROVIDED]

Email

[TO BE PROVIDED] The representative must be formally appointed before this section should be represented to EEA users as completed Article 27 compliance.

123. DATA PROTECTION OFFICER

Where Article 37 requires appointment of a Data Protection Officer, the DPO’s information should be published here:

Data Protection Officer

[TO BE APPOINTED / CONFIRMED FOLLOWING ARTICLE 37 ASSESSMENT]

Email

[TO BE PROVIDED] The DPO should be contactable directly by Data Subjects regarding issues relating to processing and GDPR rights.

124. FINAL COMMITMENT

Minds Invasion LLC recognizes that recruitment technology involves information capable of materially affecting individuals’ careers, opportunities, identities, and livelihoods. Accordingly, jobhiring.AI seeks to implement GDPR principles throughout the lifecycle of Applicant and Employer Personal Data.

This includes

  • lawful processing;
  • transparent recruitment;
  • appropriate AI governance;
  • human safeguards;
  • data minimization;
  • secure KYC;
  • restricted Employer access;
  • appropriate international-transfer safeguards;
  • privacy by design;
  • Data Subject rights;
  • breach response;
  • accountability.

GDPR compliance is an ongoing obligation. This Policy must therefore operate together with appropriate technology controls, contracts, internal procedures, risk assessments, staff training, security practices, and management oversight. Legal Entity: Minds Invasion LLC Platform: jobhiring.AI / me.jobhiring.ai Business Address: DB Gurudev Complex, Phase 2, Sayli Road, Silvassa, India Email: support@jobhiring.ai Telephone: +965 66883733 Effective Date: 8 August 2026 Last Updated: 8 August 2026

© 2026 Minds Invasion LLC. All Rights Reserved.

Find Jobs, and Hire Staff faster with AI, powered by jobhiring.AI

REGISTER NOW