Legal
Data Handling & Anonymity Policy
Last updated: March 1, 2026
1. Overview
This Data Handling & Anonymity Policy describes how HireSignal collects, processes, anonymizes, and stores candidate feedback data. Our approach is designed to maximize data utility while ensuring complete anonymity for report submitters.
2. Data Collection
HireSignal collects structured feedback through standardized questionnaires. Data collected includes: categorical responses to structured questions; scaled ratings (1-5) on specific experience dimensions; optional free-text fields for additional context (subject to moderation). We deliberately do not collect: real names, email addresses, or contact information of anonymous submitters; IP addresses or device fingerprints; precise dates, locations, or other potentially identifying metadata.
3. Anonymization Process
Our multi-layer anonymization process includes: (a) Metadata Stripping: all connection metadata (IP, user agent, timestamp precision) is removed at the point of submission; (b) Content Anonymization: moderators identify and remove or generalize any personally identifiable information within response text; (c) Temporal Generalization: specific dates are generalized to month/quarter to prevent correlation; (d) Geographic Generalization: specific office locations are generalized to metro area or region level.
4. Data Processing
Anonymized data is processed to generate: individual dimension scores for each report; aggregate SignalScore calculations per employer; trend analysis over time; industry and peer benchmarking comparisons. All processing uses anonymized data only. No individual report can be traced back to its submitter.
5. Minimum Aggregation Thresholds
To prevent statistical identification, HireSignal enforces minimum aggregation thresholds: employer-level metrics require a minimum of 10 reports before publication; department-level analytics require a minimum of 25 reports; no time-period metric is published with fewer than 5 reports in that period. These thresholds are designed to prevent small-sample identification risks.
6. Data Storage
All data is stored in encrypted databases (AES-256) hosted on SOC 2 Type II compliant infrastructure in the United States. Anonymized report data and raw (pre-anonymization) data are stored in separate, isolated databases. Raw data is retained for a maximum of 30 days for moderation and quality assurance purposes, after which it is permanently deleted.
7. Access Controls
Access to data is strictly controlled: only the moderation team can access pre-anonymization data, and only during the 30-day moderation window; employer subscribers access only aggregate analytics through their dashboard; HireSignal engineering staff access anonymized data only, through audited and logged processes.
8. Data Deletion
Report submitters cannot request deletion of individual anonymized reports, as the anonymization process makes it impossible to associate specific reports with specific individuals. Employer subscribers may request deletion of their account data, which will be processed within 30 days.
9. Third-Party Data Sharing
HireSignal does not share raw or individually identifiable data with any third party. We may share anonymized, aggregate statistics for: academic research partnerships (with IRB approval); industry benchmark reports published on our Insights page; regulatory compliance when required by law.
10. Incident Response
In the event of a data security incident, HireSignal will: notify affected parties within 72 hours; engage independent forensic investigators; provide regular updates throughout the investigation; implement corrective measures to prevent recurrence. Our anonymization architecture means that even in the event of a breach, individual submitters cannot be identified from stored data.
11. Contact
For questions about our data handling practices, contact our Data Protection Officer at dpo@hiresignal.com.