Privacy

How PractitionerStack handles candidate and client data.

Overview

PractitionerStack provides evidence-based CV screening and recruitment decision support. This page describes how we handle data in connection with our screening service.

Candidate data

Candidate data is handled under the applicable engagement and privacy controls. You must have authority to submit candidate data. Protected characteristics are not scored or inferred. Candidate data is kept out of quotes, invoices, payment records, and sales notes.

Data minimization

We share only the files and fields necessary for the agreed screening service. Payment records are linked to a screening job ID rather than embedding CV content.

Retention

PractitionerStack applies a CEO-approved default retention policy. Source job files (the original job description and candidate CV files) are automatically deleted from active PractitionerStack storage 30 days after successful job delivery. Completed screening reports remain available through the secure Client Portal for 365 days after successful delivery, with a warning 7 days before deletion.

Scheduled deletion removes data from active PractitionerStack storage and client access. Residual encrypted backups, if any, expire according to the normal secure backup lifecycle and are not returned to active use except for legitimate disaster recovery.

Client identity, job IDs, transactional metadata, payment records, and required audit/accounting records may be retained separately according to legitimate business, accounting, and legal requirements. We do not retain full candidate CV contents merely because job metadata is retained.

Any non-standard retention commitment requires privacy, legal, or custom commercial review.

Decision support

PractitionerStack provides decision support. The final hiring decision remains with the employer or recruiter.

Contact

For privacy questions, contact us through the contact page.