Legal
Privacy policy
How cofeeds collects, uses, protects, and shares your information — and how to exercise your rights, wherever you are.
Last updated: June 30, 2026
1. About this policy
This Privacy Policy ("Policy") describes how Cofeeds ("cofeeds", "we", "us", "our"), an international talent marketplace headquartered in Trois-Rivières, QC, Canada, collects, uses, discloses, and protects personal information about you when you use the cofeeds platform and services.
This Policy applies to all users of the Platform: Candidates (individuals who create AI-assessed profiles), Employers (organizations that search and unlock Candidate profiles), and website visitors. It covers personal information collected through our website, application, APIs, and any related services.
This Policy is designed to meet our obligations under multiple data protection frameworks, including Quebec's Act respecting the protection of personal information in the private sector (Law 25), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), and the UK General Data Protection Regulation (UK GDPR).
A French version of this Policy is available at /fr/privacy. For Quebec users, both versions have full legal effect.
For a plain-language summary of our regional privacy commitments — including Quebec Law 25, PIPEDA, GDPR, CCPA/CPRA, and UK GDPR — see our Trust center.
2. Who we are and how to contact us
cofeeds is operated by Cofeeds, headquartered in Trois-Rivières, QC, Canada. We process personal information as both a data controller (for Candidate Data we collect directly) and a data processor (for Employer-submitted data we process on Employers' behalf).
- Privacy Officer (Canada / Law 25 / PIPEDA): privacy@cofeeds.com
- Data Protection Officer (EU/EEA — GDPR): dpo@cofeeds.com
- UK Representative (UK GDPR): ukprivacy@cofeeds.com
- General support: support@cofeeds.com
- Security incidents: security@cofeeds.com
We acknowledge privacy requests within 5 business days and respond fully within applicable legal timelines.
3. Information we collect
We collect personal information in three ways: directly from you, automatically through your use of the Platform, and from third parties.
3A. Information you provide directly
- Account registration — your name, email address, and role (Candidate or Employer), provided directly or via Google OAuth sign-in.
- Candidate profile — your resume or CV (which may include employment history, education, skills, certifications, and links to professional profiles); the audio and video recording and transcript of your AI voice interview; and any additional profile information you choose to add.
- Employer profile — your company name, billing email, company description, and job postings including role title, requirements, responsibilities, compensation, location, and any interview configuration preferences you set.
- Contact and demo requests — your name, work email, phone number, company name, company size, role, message content, language preference, and marketing consent choice.
- Communications — messages you send to cofeeds support, privacy requests, or messages sent through the Platform's messaging feature between Employers and Candidates.
- Payment information — billing name and email. Full payment card details are collected and stored exclusively by our payment processor; cofeeds does not store full card numbers or CVV codes.
3B. Information we collect automatically
- Usage data — pages visited, features used, actions taken, session duration, and navigation paths within the Platform, collected through application-level logging.
- Device and connection data — IP address, browser type and version, operating system, device type, and general geographic location (country/region, derived from IP).
- Error and performance data — error messages, stack traces, performance metrics, and route context collected via our monitoring provider for reliability and security monitoring.
- Cookies and similar technologies — see Section 13 for details.
3C. Information from third parties
- Google sign-in — if you sign in via Google, we receive your name, email address, and profile picture from Google, subject to your Google privacy settings.
- Payment processor — our payment processor shares transaction confirmation, billing status, and fraud signals with us, but not your full payment details.
- Inferred data — we generate derived data about you, including AI-produced scores, embeddings, role-fit ratings, and profile summaries, based on the information you provide. This derived data is treated as your personal information.
3D. Special categories of personal information
We do not intentionally collect special categories of personal information (also known as sensitive personal information), including racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data processed for unique identification, health data, or data concerning sexual orientation.
Candidates should not include this type of information in their resumes or interviews. If you inadvertently include it, we will process it only to the extent necessary to operate the Platform and will not highlight or emphasize it to Employers. If you believe sensitive information has been processed inappropriately, contact privacy@cofeeds.com.
4. How we use your information
We use the personal information we collect for the following purposes:
- Providing the Services — creating and maintaining your Account; building and displaying your Candidate profile; enabling Employer job postings; generating semantic embeddings and match rankings; facilitating Unlocks and messaging between Employers and Candidates.
- AI interview and assessment — conducting, recording, transcribing, and scoring your AI voice interview; generating profile assessments and fit ratings; creating and storing vector embeddings for semantic matching.
- Employer matching — identifying and ranking Candidate profiles relevant to an Employer's posted roles using semantic similarity between role requirements and Candidate profiles.
- Payments and billing — processing Unlock purchases and Subscription payments; generating invoices; managing payment disputes and chargebacks.
- Communications — sending transactional emails (account confirmations, interview completion, profile live notifications); responding to support, privacy, and sales inquiries; delivering in-Platform notifications.
- Security and integrity — detecting and preventing fraud, abuse, and unauthorized access; monitoring for policy violations; maintaining audit logs.
- Platform improvement — analyzing usage patterns to improve features, performance, and user experience; developing and testing new AI models and matching algorithms.
- Legal compliance — complying with applicable laws, responding to legal process, and enforcing our Terms of Service.
We do not use personal information to serve behavioural advertising to users or to sell personal information to data brokers or marketing platforms.
5. Legal bases for processing
We process personal information on the following legal bases. Where multiple bases apply, we rely on the most appropriate one for the specific processing activity.
- Performance of a contract (GDPR Art. 6(1)(b) / Law 25 consent-implied) — processing necessary to create your Account, provide the Services you have requested (including building your Candidate profile, running AI interviews, enabling Employer access via Unlocks, and processing payments), and to perform our contractual obligations to you.
- Consent (GDPR Art. 6(1)(a) / Law 25 explicit consent) — for the recording and automated analysis of AI interviews; for optional marketing communications; and for the use of non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legitimate interests (GDPR Art. 6(1)(f) / PIPEDA Schedule 1) — for security monitoring and fraud prevention; product improvement and analytics; operating and improving the matching algorithm; and sending service-related communications about features relevant to your use. We have conducted balancing tests and concluded that these interests are not overridden by your privacy rights.
- Legal obligation (GDPR Art. 6(1)(c) / Law 25) — for compliance with tax and accounting obligations; response to regulatory requests, court orders, or law enforcement; data breach notification requirements; and maintaining records required by employment or data protection law.
- Vital interests (GDPR Art. 6(1)(d)) — in rare cases where processing is necessary to protect the vital interests of a person.
6. AI and automated processing
cofeeds uses artificial intelligence and machine learning throughout the Platform. This section explains how AI is used and what it means for you.
What AI does. Our AI systems:
- Parse and extract structured information from resumes and CVs;
- Conduct real-time voice interviews through a conversational AI agent;
- Transcribe interview audio to text and generate semantic embeddings;
- Score interviews and generate profile assessments using large language models;
- Create numerical vector representations of Candidate profiles and job requirements for semantic similarity search;
- Rank Candidates against Employer roles based on semantic similarity scores.
What AI does not do. AI outputs are decision-support tools. cofeeds's AI does not:
- Make final hiring decisions — all hiring decisions are made by Employers;
- Process facial expressions, emotions, or biometric markers;
- Access social media profiles or external data sources without your explicit input;
- Generate scores based on protected characteristics such as gender, race, age, or disability.
Accuracy and limitations. AI outputs are probabilistic estimates. They may contain errors, biases, or inaccuracies. cofeeds does not represent that its AI systems are bias-free or that they satisfy the requirements of any jurisdiction's AI regulation. Employers must conduct their own human review of all Candidates before making employment decisions.
Your rights regarding AI processing. You have the right to: (a) request human review of any Automated Assessment; (b) receive a meaningful explanation of the logic and key factors applied to your assessment; (c) object to the use of your data for automated profiling. Contact privacy@cofeeds.com to exercise any of these rights.
7. How we share your information
We do not sell your personal information. We share it only in the following circumstances:
- With Employers (Unlocks). When an Employer purchases an Unlock for your profile, they receive your full Candidate profile, contact information, interview transcript, and Automated Assessment. Employers contractually agree to use this data only for legitimate recruiting purposes and to protect it as Confidential Information.
- With service providers (subprocessors). We share personal information with the third-party subprocessors listed in Section 9, solely to provide and operate the Platform. Each subprocessor is bound by data processing terms that require them to protect the data they process.
- With affiliates. We may share personal information within our corporate group for the purposes described in this Policy, subject to the same protections.
- For legal compliance. We may disclose personal information to courts, law enforcement, regulatory authorities, or government agencies where required by Applicable Law, a court order, or legal process. We will, where legally permissible, attempt to notify you before disclosing your personal information in response to legal process.
- In corporate transactions. If cofeeds is involved in a merger, acquisition, financing, restructuring, bankruptcy, or sale of assets, your personal information may be transferred to the successor entity, subject to a commitment to honor this Policy.
- With your consent. We may share your personal information for purposes not described here if you provide explicit consent.
8. International data transfers
cofeeds operates globally. Your personal information may be processed and stored outside your province or country — including in the United States — by cofeeds and its subprocessors. Some of these countries may not provide the same level of data protection as your home jurisdiction.
When we transfer personal information across international borders, we implement appropriate safeguards, which may include:
- Standard Contractual Clauses (SCCs) — for transfers from the EU/EEA to third countries, we rely on SCCs approved by the European Commission (Decision 2021/914) and conduct transfer impact assessments where required;
- UK International Data Transfer Agreements (IDTAs) — for transfers from the UK to third countries;
- Quebec Law 25 privacy impact assessments — for transfers of personal information outside Quebec, we conduct a privacy impact assessment to ensure that the information receives comparable protection;
- Contractual protections — all cross-border subprocessors are bound by data processing agreements containing appropriate transfer safeguards.
You may request a copy of the transfer safeguards applicable to your data by contacting privacy@cofeeds.com.
9. Subprocessors
We use the following subprocessors to operate the Platform. We maintain a current subprocessor list and notify Employers of additions as described in our Terms.
Category
Provider
Purpose
Data processed
Core platform
Cloud hosting & database provider
Database, authentication, file storage, real-time, audit logging
Account data, profiles, resumes, interview recordings, application records, audit events
Payments
Payment processor
Checkout, billing, invoicing, payment events, tax records
Billing email, transaction references, processor-managed payment credentials
Email delivery
Transactional email provider
Transactional email, candidate notifications, contact requests
Email address, message content, delivery metadata
Error and performance monitoring
Error & performance monitoring provider
Error tracking, performance profiling, reliability monitoring
Error traces, route context, anonymized session data, operational logs
AI interview
Voice interview provider
Conducting real-time AI voice interviews
Audio and video stream, interview session context
AI scoring and matching
Large language model provider
Interview transcript scoring, profile assessment generation
Interview transcripts, resume data, role requirements
Semantic search
Embeddings provider
Text embeddings for role-candidate matching
Resume text, job requirements (anonymized for embedding)
Async pipeline
Job orchestration provider
Background job orchestration (resume processing, scoring)
Job IDs and processing status; no personal data stored
We will notify Employers at least 30 days in advance of adding a new subprocessor that handles Employer personal data. Additions required for security or legal compliance may take effect with shorter notice. You may object to a new subprocessor by contacting privacy@cofeeds.com; if the objection cannot be resolved, you may terminate your account without penalty for the affected services.
10. Data retention
We retain personal information only for as long as necessary for the purposes described in this Policy, and in any event only for so long as permitted or required by Applicable Law. Our standard retention periods are:
Data category
Retention period
Basis
Account and profile data (active)
Duration of account
Contract performance
Resume/CV and extracted data
Duration of account
Contract performance
AI interview recordings
24 months from interview date, or account deletion (whichever earlier)
Legitimate interest / Law 25
Interview transcripts, scores, embeddings
Duration of account
Contract performance
Employer job postings
Duration of account + 12 months
Legitimate interest
Consent records
7 years from consent
Legal obligation
Contact and demo request data
24 months from submission
Legitimate interest
Payment and transaction records
7 years from transaction
Legal obligation (tax law)
Security and audit logs
24 months
Legitimate interest / security
Data breach records
Minimum 5 years
Legal obligation (Law 25 / GDPR)
When your account is deleted, we remove or irreversibly de-identify your personal information within 30 days, except for records we must retain by law (such as transaction records and consent logs) or that are necessary to resolve disputes, enforce our agreements, or maintain security records. You may request deletion at any time through your account settings or by contacting privacy@cofeeds.com.
11. Security
We implement a layered security program designed to protect personal information from unauthorized access, disclosure, alteration, and destruction. Our measures include:
- Encryption in transit. All communications between your browser or app and the Platform are encrypted using TLS 1.2 or higher. API communications use the same standard.
- Encryption at rest. Personal data — including profile data, resumes, and interview transcripts — stored in our database is encrypted at rest. Interview recordings are stored in private, encrypted cloud storage buckets.
- Access controls. Role-based access controls (RBAC) limit cofeeds personnel access to personal data on a need-to-know basis. Access to production systems is restricted and logged.
- Private storage. Resume files and interview recordings are stored in access-controlled private storage buckets with signed, time-limited access URLs. They are not publicly accessible.
- Audit logging. Material access, modification, and deletion events affecting personal data are logged in tamper-evident audit logs retained for 24 months.
- Vulnerability management. We conduct regular security reviews of our codebase and infrastructure, and address identified vulnerabilities according to severity.
- Subprocessor security. Third-party subprocessors are assessed for security posture before onboarding and are contractually required to maintain appropriate security measures.
- Least privilege. AI subprocessors receive only the minimum data necessary to perform their specific function (e.g., the transcript scoring API receives transcripts, not full account data).
No security system is impenetrable. We cannot guarantee that our security measures will prevent every unauthorized access or breach. We continually evaluate and improve our security posture. If you discover a security vulnerability, please report it responsibly to security@cofeeds.com.
12. Data breach notification
In the event of a personal information breach, our response process includes:
- Internal response. We maintain an incident response plan. Upon detection of a potential breach, we immediately contain the incident, assess its scope and impact, and document our findings.
- Regulatory notification. Where required by Applicable Law, we will notify the relevant supervisory authority:
- Commission d'accès à l'information (CAI, Québec) — as soon as feasible, and in any event within the timeframe required by Law 25;
- Office of the Privacy Commissioner of Canada — for PIPEDA-covered breaches presenting a real risk of significant harm;
- Relevant EU supervisory authority — within 72 hours of becoming aware, as required by GDPR Article 33;
- UK Information Commissioner's Office — within 72 hours, as required by UK GDPR Article 33.
- Individual notification. We will notify affected individuals without undue delay where the breach creates a real risk of significant harm, providing: a description of the nature of the breach; the categories and approximate number of individuals and records involved; likely consequences; and measures taken to address the breach.
- Employer notification. Where a breach involves Candidate Data held by Employers (following an Unlock), we will notify affected Employers as promptly as practicable so they can take protective action.
- Breach register. We maintain a register of all security incidents and personal data breaches, as required by GDPR Article 33(5) and Law 25.
13. Cookies and tracking technologies
We use cookies and similar technologies to operate and improve the Platform. We do not use cookies to build advertising profiles or sell your data.
Category
Description
Purpose
Duration
Control
Essential
Session management and authentication (authentication cookies)
Required
Session duration
Cannot be disabled — required for login
Functional
Language preference (cf_locale), signup role (cf_role)
Service personalisation
10 minutes (signup flow)
Disabled via cookie settings
Analytics
Anonymous usage telemetry via our monitoring provider
Product improvement
30 days
Disabled via cookie settings
You can manage your cookie preferences on our cookie settings page. Essential cookies cannot be disabled as they are required for the Platform to function. Disabling functional cookies may affect your experience.
Do Not Track. Some browsers support a Do Not Track (DNT) signal. We currently do not alter our data practices based on DNT signals, as there is no industry-wide standard for what DNT means. We do not engage in cross-site tracking for advertising purposes regardless of DNT status.
14. Your privacy rights
Your rights depend on your location and the applicable law. You may exercise any of the rights below by contacting us at privacy@cofeeds.com. We will verify your identity before actioning any request and will respond within the timelines required by Applicable Law.
14A. Rights for all users
- Access. Request a summary of the personal information we hold about you.
- Correction. Request correction of inaccurate or incomplete data.
- Deletion. Request deletion of your personal information, subject to legal retention obligations and active dispute resolution.
- Consent withdrawal. Withdraw consent for AI interview recording and automated analysis at any time. Withdrawal does not affect prior processing.
- Human review. Request human review of any Automated Assessment affecting you, and receive a meaningful explanation of the criteria and logic applied.
- Complaint. Lodge a complaint with the relevant supervisory authority in your jurisdiction (see contacts below).
14B. Quebec and Canada (Law 25 / PIPEDA)
- Access (s. 27, Law 25). Request access to your personal information and how it is being used. We respond within 30 days (extendable by 30 days with notice).
- Correction (s. 28, Law 25). Request correction of inaccurate, incomplete, or ambiguous personal information.
- Portability (s. 27(1), Law 25). Request that we communicate your personal information to you or to a third party of your choice in a structured, commonly used, technological format.
- Withdrawal of consent (s. 8, Law 25). Withdraw consent at any time; we will cease processing the affected data unless we have a legal basis to continue.
- Right to be informed of automated decisions. Request information about automated profiling decisions that affect you and request human review.
- Complaint — CAI: Commission d'accès à l'information du Québec, cai.gouv.qc.ca
- Complaint — OPC: Office of the Privacy Commissioner of Canada, priv.gc.ca
14C. European Union and European Economic Area (GDPR)
- Right of access (Art. 15). Obtain a copy of your personal data and information about how it is processed.
- Right to rectification (Art. 16). Correct inaccurate or complete incomplete personal data.
- Right to erasure / right to be forgotten (Art. 17). Request deletion of your personal data where it is no longer necessary for the purpose collected, where you withdraw consent, or where processing was unlawful.
- Right to restriction (Art. 18). Request that we restrict processing of your data while a dispute is resolved.
- Right to data portability (Art. 20). Receive your personal data in a structured, commonly used, machine-readable format and have it transmitted to another controller.
- Right to object (Art. 21). Object to processing based on legitimate interests (including profiling for matching purposes). We will cease unless we can demonstrate compelling legitimate grounds.
- Rights related to automated decisions (Art. 22). Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. You may request human review, express your point of view, and contest the decision.
- Response timeline. We respond to GDPR requests within 30 days, extendable by 60 days for complex or numerous requests with notice.
- Complaint. Lodge a complaint with your EU member state's supervisory authority. A list of authorities is available at edpb.europa.eu.
14D. United Kingdom (UK GDPR)
- UK users hold the same rights as described in Section 14C, under the UK GDPR and the Data Protection Act 2018.
- Response timeline. We respond within one calendar month, extendable by two months for complex requests.
- Complaint — ICO: Information Commissioner's Office, ico.org.uk, 0303 123 1113.
14E. California (CCPA / CPRA)
- Right to know. Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the categories of third parties with whom we share it.
- Right to delete. Request deletion of your personal information, subject to exceptions (legal obligations, security, active transactions, etc.).
- Right to correct. Request correction of inaccurate personal information.
- Right to opt out of sale or sharing. cofeeds does not sell or share personal information for cross-context behavioural advertising. No opt-out is required, but you may submit a request to confirm this.
- Right to limit use of sensitive personal information. We do not use sensitive personal information beyond what is necessary to provide the Services. No limitation request is required, but you may submit one to confirm.
- Right to non-discrimination. We will not discriminate against you for exercising your CCPA/CPRA rights.
- Authorized agent. You may designate an authorized agent to make CCPA/CPRA requests on your behalf by providing written authorization or power of attorney.
- Shine the Light (Cal. Civ. Code § 1798.83). California residents may request information about personal information shared with third parties for their direct marketing purposes. cofeeds does not share personal information with third parties for direct marketing.
- Response timeline. We respond within 45 days, extendable by 45 days with notice.
- Contact: privacy@cofeeds.com with "CCPA Request" in the subject line.
15. Privacy request handling
All privacy requests are handled through a documented process:
- Intake and acknowledgment. We acknowledge all privacy requests within 5 business days of receipt and assign them to our Privacy Officer.
- Identity verification. Before actioning any request, we verify the identity of the requester to ensure we are disclosing to or deleting the data of the correct person. Verification methods are proportionate to the sensitivity of the request.
- Scope determination. We assess which data is in scope — which may include Account data, profile data, interview data, Employer Unlock records, messaging history, billing records, and support communications.
- Response. We respond within the applicable legal timeline with either: (a) the information or action requested; (b) a reasoned explanation for any partial or complete denial; or (c) an extension notice where permitted by law.
- Recordkeeping. We maintain a record of all privacy requests, the identity verification method used, the scope of the request, our response, and any retained legal or security exceptions, as required by Law 25 and GDPR.
16. Data Processing Agreements (DPA)
Enterprise Employers who are subject to GDPR, UK GDPR, CCPA/CPRA, Quebec Law 25, or other data protection laws requiring formal data processing agreements may request a DPA by emailing privacy@cofeeds.com.
Our standard DPA includes: a description of the data processing activities; cofeeds's obligations as a data processor; subprocessor management; security obligations; assistance with data subject requests; data breach notification to Employers; return or deletion of data on contract termination; and audit rights. The DPA supplements our Terms of Service and, in the event of conflict on data protection matters, the DPA prevails.
Where required, the DPA incorporates EU Standard Contractual Clauses (SCCs, Module 2: Controller to Processor) and/or UK IDTAs for cross-border transfers.
17. Children's privacy
The Platform is not directed to, and we do not knowingly collect personal information from, anyone under the age of 18. If you are under 18, do not use the Platform.
If we become aware that we have collected personal information from a person under 18 without parental consent, we will delete that information promptly. If you believe a minor has submitted personal information to us, please contact privacy@cofeeds.com.
18. Third-party links and services
The Platform may contain links to third-party websites or integrate third-party services (such as LinkedIn profile imports or calendar scheduling tools). cofeeds does not control and is not responsible for the privacy practices, content, or security of any third-party website or service. We encourage you to review the privacy policies of any third-party services you use. Clicking a third-party link from our Platform does not mean we endorse that site.
19. Changes to this policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The date of the most recent update is shown at the top of this page.
For material changes — meaning changes that significantly affect your privacy rights or how we use your personal information — we will provide at least 30 days' advance notice by email to the address on your account, and by posting a prominent notice on the Platform. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
For minor changes (such as clarifications, corrections, or updates to contact information), we will update this page without additional notice.
20. Contact, Privacy Officer, and DPO
To exercise your rights, ask questions about this Policy, or reach our Privacy Officer or Data Protection Officer, use the following contacts:
- Privacy requests and Privacy Officer (Canada / Law 25 / PIPEDA): privacy@cofeeds.com
- Data Protection Officer (EU/EEA — GDPR): dpo@cofeeds.com
- UK privacy representative (UK GDPR): ukprivacy@cofeeds.com
- California privacy requests (CCPA/CPRA): privacy@cofeeds.com — include "CCPA Request" in the subject line
- DPA requests: privacy@cofeeds.com — include "DPA Request" in the subject line
- Security incidents and vulnerability reports: security@cofeeds.com
- General support: support@cofeeds.com
Cofeeds · Trois-Rivières, QC, Canada
