Privacy Policy
Effective date: August 23, 2026 · Version 1.0
Summary
- Correlia is a hiring platform operated by Correlia Inc. Employers use it to manage job openings and to have Corra, our AI interviewer, conduct recorded video interviews.
- This Privacy Policy covers visitors to correlia.ai, demo requests and enquiries, people who use the platform for a Customer (recruiters and administrators), and business contacts.
- If you are a candidate, the employer that invited you controls your data. Our Candidate Privacy Notice (/legal/candidate-privacy-notice) explains in detail how we handle it; this Privacy Policy gives only a short overview.
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- We train our own AI models on interview recordings only with a candidate’s separate, optional consent.
- All data is stored in the United States on Amazon Web Services, encrypted in transit and at rest. Transfers from the EU, UK and Switzerland rely on Standard Contractual Clauses.
- You can access, correct or delete your data, object to our use of it, and opt out of marketing at any time. We honour Global Privacy Control signals.
- Contact: ntitov@correlia.ai.
1. Who we are and scope
1.1 Who we are
Correlia Inc., with its address at 630 Chapel St., New Haven, CT 06510, USA (“Correlia”, “we”, “us”), operates correlia.ai — the website and the Correlia platform, including its subdomains — with our integrations, APIs and support (the “Services”).
Correlia is a business-to-business hiring platform. Employers and recruiters (“Customers”) use it to manage job openings (“Vacancies”), import or upload resumes, invite candidates, and have Corra, an AI interviewer with a computer-generated face and voice, conduct recorded video interviews and produce transcripts, scores, summaries and integrity reports. Humans at the Customer make all hiring decisions.
1.2 Scope
This Privacy Policy applies to website visitors; prospects and anyone who requests a demo or contacts us; people who use the platform for a Customer, such as recruiters, hiring managers and administrators (“Customer Users”, called Authorised Users in the Customer Terms of Service); business contacts; and job applicants to Correlia.
1.3 Controller or processor
A controller (a “business” under California law) decides why and how personal data is used. A processor (a “service provider”) acts on the controller’s instructions.
Correlia is the controller for website visitors, prospects, Customer Users, business contacts and job applicants to Correlia. This Privacy Policy governs that processing.
When a Customer uses the Services to process data about its candidates (“Candidate Data”), the Customer is the controller and Correlia is its processor, acting on documented instructions under the Customer Terms of Service (/legal/terms) and the Data Processing Addendum (/legal/dpa). This covers resume intake, invitations, the interview, scoring, integrity reports, storage and Customer-directed integrations; the Candidate Privacy Notice describes it in detail.
Correlia is an independent controller of Candidate Data only for these limited purposes: (a) operating, securing and protecting the platform, including preventing abuse and fraud against the platform and keeping security logs; (b) complying with law and responding to legal requests; (c) service analytics and product improvement using de-identified or aggregated data; (d) training and improving Correlia’s own AI models on interview recordings, only with the candidate’s separate, optional and explicit consent (“Optional Training Consent”) and only where the Customer has not disabled that option; and (e) communicating with candidates about their data rights.
2. Personal data we collect
2.1 Website visitors
IP address, approximate location derived from it, browser and device type, operating system, language, referring page, pages viewed, time spent, and identifiers set by the cookies described in our Cookie Policy (/legal/cookies).
2.2 Demo requests and contact forms
The details you enter when you request a demo, register for an event or content, or contact us: name, work email address, company, job title, phone number if given, country and your message.
2.3 Customer Users
When your organisation gives you access to the platform, we collect account data (name, work email address, role and permissions, company and preferences); login data (hashed credentials or single sign-on identifiers, session tokens, timestamps, IP address and device); usage data (features used, actions taken, timestamps and diagnostic logs); content you enter (Vacancies, requirements, interview questions, evaluation criteria, comments, pipeline stages, decisions and settings); support communications; and, for billing contacts, billing and invoicing details and payment status. Content you enter about candidates is Candidate Data that we process on your organisation’s behalf.
2.4 Integration data
Customers can connect Correlia to Slack, Ashby, Greenhouse, Linear, Google Calendar, LinkedIn, hh.ru and other job boards, and to their own systems through our MCP server and APIs. When a Customer connects an integration and instructs us to use it, we receive account identifiers, access tokens, messages and commands sent through it, calendar availability and records exchanged with the Customer’s applicant tracking system, which we process as the Customer’s processor. Integration providers act under their own terms and are not our sub-processors.
2.5 Candidates: overview
If you are a candidate, the Customer that invited you decides what data is collected and why. On its behalf we process your identity and contact details; resume and profile data, including data the Customer imports from its applicant tracking system, job boards or public professional profiles; the video and audio recording and transcript of your interview, including live-coding input; AI-generated scores, evaluations, summaries and the integrity report; integrity signals (browser focus, copy and paste, answer timing, text patterns, camera presence including a temporary same-person face check deleted when the interview ends, IP address and device); technical data; communications; and the hiring-process data the Customer records. The Candidate Privacy Notice describes this in full, including what Corra does not do.
2.6 Business contacts and marketing
We keep professional contact details about people at Customers, prospects and partners: name, job title, company, work contact details, professional profile links, interaction history and marketing preferences, obtained from you, your organisation, public sources such as company websites and professional networking sites, events, and business-to-business data providers that supply contact information for sales outreach. When we first contact you using data from another source, we tell you where we obtained it and how to opt out.
2.7 Job applicants to Correlia
If you apply for a role with us, we collect your application, CV, contact details, interview notes, assessment results and references, to evaluate your application and meet legal obligations.
3. How we use personal data and our legal bases
Where the GDPR, the UK GDPR or similar laws apply, we rely on the legal basis listed for each purpose. You can object to processing based on legitimate interests (section 9.1). Where we process Candidate Data as a processor, the Customer determines the legal basis.
- Providing and securing the Services: running the platform, authenticating you, delivering features and keeping the Services available and secure. Legal basis: our contract with you or, where the contract is with your organisation, our legitimate interest in delivering the Services.
- Account management and support: managing accounts, permissions and settings, sending service messages, and answering support requests. Legal basis: contract; legitimate interests.
- Billing: invoicing, collecting payment, managing subscriptions and keeping accounting records. Legal basis: contract; legal obligation.
- Product improvement and analytics: analysing how the Services are used, with de-identified or aggregated data wherever possible, which we commit not to re-identify; Candidate Data is used for this purpose only in that form. Legal basis: legitimate interests.
- Security and abuse prevention: monitoring logs and activity to detect and investigate intrusions, fraud, misuse and breaches of the Customer Terms of Service. Legal basis: legitimate interests; legal obligation.
- Marketing and sales: sending business contacts and Customer Users information about Correlia, product updates and events, and contacting prospects. Legal basis: our legitimate interest in business-to-business marketing, and consent where the law requires it. You can opt out at any time using the unsubscribe link or at ntitov@correlia.ai.
- Legal compliance and claims: meeting legal, tax and regulatory obligations, responding to lawful requests from authorities, enforcing our agreements and handling legal claims. Legal basis: legal obligation; legitimate interests.
- Corporate transactions (section 5.6). Legal basis: legitimate interests.
- Training Correlia’s AI models: using interview recordings, audio and transcripts to train and improve our own models only where the candidate has given Optional Training Consent, as described in the Candidate Privacy Notice. Legal basis: explicit consent. Otherwise we improve our models only with de-identified or aggregated data.
Corra’s outputs about candidates are decision-support for human reviewers at the Customer, as explained in the AI Transparency Statement, “How Corra interviews and evaluates candidates” (/legal/ai-transparency).
4. Cookies and similar technologies
We use cookies, local storage and similar technologies to keep you signed in, remember preferences, keep the Services secure, understand how they are used and, where you agree, measure our marketing. Strictly necessary cookies are always on. Where the law requires it, we ask for consent before setting analytics or marketing cookies, and you can change your choices at any time in the page footer. Our Cookie Policy (/legal/cookies) lists each cookie, its purpose and its lifetime.
We honour Global Privacy Control signals as a valid opt-out of any sale or sharing of personal data and of targeted advertising for that browser. We do neither in any case.
5. How we share personal data
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share personal data only as follows.
5.1 Sub-processors and service providers
Providers that process personal data on our behalf under contracts limiting their use of it: Amazon Web Services, Inc., for hosting, storage, compute and video processing in the United States, and ElevenLabs for speech-to-text, under terms that prohibit training on Correlia data. The AI models used for interview dialogue, evaluation and summaries, and Corra’s avatar rendering and voice synthesis, run on Correlia’s own and open-source models on Correlia’s infrastructure in the United States. Current names and locations are in our Sub-processor List (/legal/sub-processors).
5.2 Customer-directed integrations
When a Customer connects an integration, we send data to the provider on the Customer’s instruction, such as posting an interview summary to Slack or pushing a scorecard to Ashby or Greenhouse. The Customer chooses what is sent, and the provider handles it under its own terms.
5.3 Customers and your organisation
Administrators at a Customer can see their Customer Users’ account details, activity and content. Candidates’ recordings, transcripts, scores, summaries and integrity reports go to the Customer that invited them, which is responsible for any further use, subject to our Customer Terms of Service.
5.4 Professional advisers
Lawyers, accountants, auditors, insurers and other advisers, when they need the data to advise us.
5.5 Legal requirements and protection
When we believe in good faith that the law requires it, to respond to lawful requests from courts or public authorities, or to protect the rights, property or safety of candidates, Customers, Correlia or the public. Where we act as a processor and the law allows, we tell the Customer first.
5.6 Corporate transactions
In a merger, acquisition, financing, reorganisation or sale of assets, personal data may be disclosed to the parties and their advisers under confidentiality obligations and may transfer to the successor, subject to this Privacy Policy.
5.7 With your direction or consent
In other ways you ask for or agree to, such as a testimonial or reference.
6. International transfers
All personal data is stored and processed in the United States on Amazon Web Services. Data protection laws there may differ from those in your country.
For personal data from the EU and EEA, the UK and Switzerland, we rely on the Standard Contractual Clauses in Commission Decision (EU) 2021/914, Module 2 (controller to processor) and Module 3 (processor to processor), with the UK International Data Transfer Addendum and the adaptations required by Swiss law, supported by transfer impact assessments and supplementary measures. Our Data Processing Addendum incorporates these clauses; copies of the clauses we use with sub-processors are available on request.
Correlia intends to self-certify under the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Data Privacy Framework once it is eligible. We do not rely on the Data Privacy Framework unless and until Correlia appears on the official list. If a transfer mechanism we rely on is invalidated, we rely on the other mechanisms described here or another lawful mechanism.
7. How long we keep personal data
We keep personal data only as long as needed for the purposes in this Privacy Policy, to meet legal obligations or to resolve disputes. Our defaults:
- Website analytics: the periods in our Cookie Policy.
- Prospect and business contact data: 24 months after our last meaningful interaction, or until you opt out or object.
- Customer User account data: the life of the account plus 90 days.
- Support correspondence: 24 months after the request is closed.
- Billing records: as long as tax and accounting laws require, typically 7 years.
- Platform security logs: 12 months.
- Candidate Data processed for Customers: recordings, transcripts, AI outputs and integrity signals are kept for the period the Customer configures, by default 12 months after the interview. Customers can delete earlier at any time, and candidates can request deletion, which we coordinate with the Customer (within 30 days under the Illinois Artificial Intelligence Video Interview Act). When a Customer contract ends, we return or export the data on request, delete it within 30 days and purge backups within 90 days.
- Optional Training Consent copies: until consent is withdrawn, after which the recording is removed from training datasets within 30 days. Models already trained are not retrained, but the recording is no longer used.
- Candidate consent records: 5 years after the interview, stored separately from the recording.
- Job applications to Correlia: 12 months after the process ends.
When a period ends we delete or de-identify the data, and backups are purged on the backup cycle, unless the law or a legal claim requires longer retention.
8. Security
We protect personal data with measures appropriate to the risk: TLS encryption in transit and encryption at rest; role-based access controls, least-privilege permissions and multi-factor authentication for staff with production access; logging and monitoring of access to systems and Candidate Data; network segregation and regular patching; secure development practices and vulnerability testing; security and privacy review of sub-processors; staff confidentiality obligations and training; and a documented incident response plan.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach affects you, we will notify you, the affected Customer and the relevant authorities as the law and our contracts require. Report security concerns to ntitov@correlia.ai.
9. Your rights
Your rights depend on where you live and on whether Correlia is the controller or a processor of your data. Where we act as a Customer’s processor, the Customer answers your request; if you contact us, we pass the request to the Customer and help it respond.
9.1 EU and EEA, UK and Switzerland
You have the right to access your personal data and receive a copy; to have inaccurate data corrected; to have your data erased in certain circumstances; to restrict processing; to receive the data you gave us in a portable format; to object to processing based on legitimate interests, and at any time to direct marketing, which we will always stop; to withdraw consent at any time without affecting earlier processing; and not to be subject to a decision based solely on automated processing with legal or similarly significant effects.
We make no such decisions about website visitors, Customer Users or business contacts. Corra’s scores, evaluations, summaries and integrity reports are advisory, and humans at the Customer make hiring decisions. Candidates have the right to human intervention, to express their point of view and to contest an outcome, including under Articles 22A to 22D of the UK GDPR, exercised with the Customer as the Candidate Privacy Notice explains.
You can complain to your local data protection authority, including the Information Commissioner’s Office in the UK and the Federal Data Protection and Information Commissioner in Switzerland. Correlia will publish the details of its EU and UK representatives on this page once they are appointed.
9.2 California
This section supplements this Privacy Policy for California residents under the California Consumer Privacy Act as amended (“CCPA”). For candidates, the Candidate Privacy Notice is our notice at collection and contains the pre-use notices required by the CCPA regulations on automated decision-making technology, which we do not use to make significant decisions about website visitors, Customer Users or business contacts.
In the last 12 months we collected these categories of personal information: identifiers and customer records categories (name, contact details, company, account identifiers, IP address); commercial information; internet or other electronic network activity; approximate geolocation derived from IP address; professional or employment-related information; audio, electronic and visual information (support calls and meetings recorded with notice); inferences drawn from usage data; and sensitive personal information limited to account login credentials. Candidate categories are listed in the Candidate Privacy Notice.
Sources: you; your organisation; automatic collection; integrations on a Customer’s instruction; public sources and business-to-business data providers; and service providers. Purposes and retention: sections 3 and 7. We disclosed each category for a business purpose to service providers and contractors, professional advisers and, for Customer Users, your Customer organisation. We have not sold or shared personal information in the last 12 months, and we use sensitive personal information only to provide the Services and maintain security.
You have the right to know what personal information we collect, use, disclose and share, and to access it; to delete it; to correct it; to limit the use of sensitive personal information; to opt out of sale or sharing, which we do not do; and not to be discriminated against for exercising your rights. We honour Global Privacy Control signals as an opt-out request. An authorised agent may submit a request for you with proof of authority, and we may verify your identity directly. Under California’s Shine the Light law, you may ask once a year whether we disclose personal information to third parties for their direct marketing; we do not.
9.3 Other US states
If you live in Colorado, Connecticut, Virginia, Texas, Oregon or another state with a comprehensive privacy law, you may have the right to confirm whether we process your personal data and access it; correct it; delete it; obtain a portable copy; and opt out of targeted advertising, sale, and profiling in furtherance of decisions with legal or similarly significant effects. Many of these laws exclude data about people acting in an employment or business capacity and data we process as a Customer’s processor; where they apply, we honour them. We do none of these things to website visitors, Customer Users or business contacts. Candidates should direct profiling opt-out or appeal requests to the Customer.
If we decline to act on your request, you can appeal by replying to our decision or emailing ntitov@correlia.ai with “Privacy appeal” in the subject line. We respond in writing within 45 days (60 days where the law allows) with our reasons. If we deny your appeal, you may contact your state Attorney General.
9.4 Canada, Brazil, Australia, Singapore and other countries
Canada: under PIPEDA and provincial laws, you can access and correct your personal data, withdraw consent, and complain to the Office of the Privacy Commissioner of Canada or your provincial commissioner. In Quebec, you can also ask for the information used in a decision based exclusively on automated processing and have your observations heard; candidates exercise this right with the Customer.
Brazil: under the LGPD, you can confirm, access, correct, anonymise, delete and port your data, learn with whom it was shared, revoke consent and request review of decisions taken solely by automated processing. Transfers rely on standard contractual clauses approved by the ANPD.
Australia: we follow the Australian Privacy Principles. You can request access and correction and complain to us, then to the Office of the Australian Information Commissioner. The Candidate Privacy Notice describes automated processing that may affect candidates.
Singapore: we follow the Personal Data Protection Act. You can request access and correction, withdraw consent and contact our data protection officer.
Elsewhere, contact us to exercise the rights your local law gives you, including complaining to your data protection authority.
9.5 How to exercise your rights
Email ntitov@correlia.ai with “Privacy request” in the subject line, or write to the postal address in section 12. Candidates should first contact the employer that invited them.
We verify requests before acting, usually by matching the details you give us against the data we hold; we may ask for more information or for confirmation from the email address on your account. Authorised agents must show evidence of their authority.
We respond within 30 days, or one month where the GDPR or UK GDPR applies, and within 45 days for California requests. We may extend this period where the law allows and will tell you why. If we cannot act on all or part of your request, we will explain why, and you may appeal where section 9.3 applies.
10. Children
The Services are not directed to anyone under 18, and we do not knowingly collect personal data from children. Candidates must be at least 18 (or the age of majority where they live, if higher) and legally able to work in the country of the position; Customers are responsible for inviting only eligible candidates. If you believe a child has given us personal data, email ntitov@correlia.ai and we will delete it.
11. Changes to this Privacy Policy
We may update this Privacy Policy as the Services, the law and our practices change. For material changes, we give notice before they take effect by posting on correlia.ai, emailing Customer account owners, or both, at least 30 days in advance where the law or our contracts require it. Previous versions are available on request.
12. Contact
- Privacy, legal, security and support requests: ntitov@correlia.ai
- Postal address: Correlia Inc., 630 Chapel St., New Haven, CT 06510, USA
- EU and UK representatives (Article 27 GDPR / UK GDPR): Correlia will publish the details of its EU and UK representatives on this page once they are appointed.
Related documents: Candidate Privacy Notice · Candidate Interview Terms (/legal/candidate-terms) · AI Transparency Statement · Customer Terms of Service · Data Processing Addendum · Sub-processor List · Cookie Policy.