This policy explains how Explorador ATS handles personal data in Explorador ATS. It covers two quite different groups of people, and the distinction matters, so it comes first.
1.Two roles, two groups of people
If you signed up for an account
You are a customer. We are the controller of your account data — your name, email, password hash, workspace and billing details — and we decide how it is used, within the limits of this policy.
If you applied for a job through a workspace
Your data was given to a company that uses our software. That company is the controller; we are their processor, acting on their instructions. We do not decide what happens to your application, and we cannot delete it on our own initiative.
If you want your application removed, ask the company you applied to — they have a one-click delete that removes the record and the resume file permanently. If you cannot reach them, write to us at info@exploradorats.com and we will identify the controller and pass your request on.
2.What we collect
From account holders
- Name, email address and a hashed password (we never store the password itself).
- Workspace name, branding and settings.
- Billing contact and subscription status. Card numbers go directly to Stripe and never touch our servers.
- Operational logs — IP address, browser, timestamps — kept for security and debugging.
From applicants, on behalf of our customers
- Name, email, phone, location and links you provide.
- Your resume file and the text extracted from it.
- Cover letters and answers you submit with an application.
- Notes, ratings, stage history and interview records created by the hiring team about your application.
We ask customers not to store special-category data — health, biometric, religious and similar — and the product provides no field for it. We cannot prevent a customer typing it into a free-text note, which is one reason those notes are deleted along with the rest of a record.
3.Why we process it
- To provide the Service — performance of our contract with the customer.
- To secure it — our legitimate interest in preventing abuse, fraud and unauthorised access.
- To bill for it — performance of contract, and our legal obligation to keep financial records.
- To support customers — our legitimate interest in answering questions they ask us.
We do not process anyone's data for advertising, and we do not sell or share personal information as those terms are defined under the CCPA. We do not use candidate data to train machine learning models.
4.Automated processing
The Service extracts fields from uploaded resumes and produces a match score against a job description. Where a workspace enables AI-assisted parsing, resume text is sent to Anthropic for that purpose and is not retained by them for training.
These outputs are suggestions shown to a human recruiter. The Service does not reject, rank or filter anyone automatically, and no decision with legal or similarly significant effect is made by the software alone. What the hiring company then does with the score is a matter for them, and several jurisdictions place obligations on them when they use it.
5.Who else touches the data
We use a small number of providers to run the Service. Each is bound by contract to process data only on our instructions.
| Provider | Purpose | Data | Region |
|---|---|---|---|
| Vercel | Application hosting and content delivery | All data in transit; request logs | United States |
| Neon | Managed PostgreSQL database | All stored account, candidate and resume data | United States |
| Stripe | Subscription billing and payment processing | Billing contact and payment details of account holders only | United States |
| Resend (Amazon SES) | Delivery of transactional and candidate email | Recipient address, subject and body of messages sent from the app | United States |
| Anthropic | Optional AI-assisted resume parsing and match scoring | Resume text, where the workspace has enabled AI parsing | United States |
We will give customers notice before adding a provider that processes candidate data. We may also disclose data if legally compelled, in which case we will tell the affected customer unless we are prohibited from doing so.
6.Where data is stored
All data is stored in the United States. If you are in the UK, EEA or Switzerland, that is an international transfer, made under the European Commission's Standard Contractual Clauses together with the technical measures described below.
7.How long we keep it
- Candidate records — for as long as the customer keeps them. Workspaces can set a retention window, after which inactive records are deleted automatically. Deletion is immediate and permanent, including the resume file.
- Account data — for the life of the workspace, then 30 days after termination.
- Backups — on a rolling window, purged no later than 35 days after the live record is deleted.
- Billing records — seven years, as tax law requires.
- Security logs — 30 days.
8.How it is protected
- Encrypted in transit (TLS) and at rest.
- Passwords hashed with bcrypt; never recoverable, only reset.
- Every database query is scoped to a single workspace, so one customer's data cannot be returned to another.
- Resume files are served only to authenticated members of the owning workspace.
- Access to production systems is limited to those who need it.
No system is perfectly secure. If a breach affects your personal data we will notify the relevant supervisory authority within 72 hours where required, and tell affected customers without undue delay.
9.Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent. Exercising these rights will not lead to discriminatory treatment.
Account holders can exercise most of these directly in the app, or write to info@exploradorats.com. We respond within 30 days.
Applicants should contact the company they applied to, for the reason given in section 1. Write to us if you cannot identify or reach them.
If you are in the UK or EEA you may also complain to your local data protection authority.
11.Children
The Service is for use by businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's data has been submitted, tell us and we will remove it.
12.Changes
We will post any change here and update the date at the top. For changes that materially affect how we handle personal data, we will notify customers by email at least 30 days beforehand.
13.Contact
Privacy questions and rights requests: info@exploradorats.com. Our Terms of Service cover everything else.