Data Privacy FAQ
9 min
this guide outlines frequently asked questions from security and legal teams this faq page is for informational purposes only although we do our best to keep this information up to date, you should always refer to our terms https //www ashbyhq com/resources/terms , privacy policy https //www ashbyhq com/resources/privacy , or your signed agreements with ashby for the most accurate information reach out to support\@ashbyhq com mailto\ support\@ashbyhq com if you have questions not addressed on this page data privacy faq overview protecting the privacy of your data is very important to us at ashby, just as we know that protecting the privacy of your candidates' and employees' data is important to you we offer flexible tools you can use to integrate ashby with your compliance processes, letting your team stay focused on an efficient and effective recruiting pipeline our tools are used by organizations around the world who are subject to regulatory environments including the general data protection regulation (gdpr), the california consumer privacy act (ccpa), and others if you're an ashby user or admin, all the information you need to use our features is right here within the ashby knowledge base, including documentation for user permissions docid\ i5jhibmkqhyobnnvrl8rk anonymizing and deleting candidates docid\ dmwv1t1xms0rsjf7bb9vc compensation docid 0zkrmoq 22rnbdt3kwgum data privacy and compliance docid 0xpiflekfhkukbufqkhi9 surveys & questionnaires docid\ rlbgzsgqlmqckgbbnyqyp the rest of this document contains answers to common questions from security and legal teams with more specific technical, operational, or implementation concerns to help you decide if ashby is the right fit for you frequently asked questions ashby permissions what are the ashby permission levels? there are three levels of global access that can be assigned to users limited access elevated access organization admin ashby assigns users limited access by default you can assign specific access roles for jobs, locations, and departments to elevated access users and organization admins to provide or limit access as needed for more information on permissions and to view the default access roles, see user permissions docid\ i5jhibmkqhyobnnvrl8rk can i create custom access roles? yes, you can create custom access roles to determine the specific areas of ashby that users with that role can access for more information, see manage access roles docid\ be1gtv2r0jgx do5mdnr can changes to user permissions be viewed? yes on the employees page in admin , organization admins can click on a user's profile and navigate to the history tab to view a log of permission changes the log includes a timestamp, the changes made, and the name of the user who made them anonymizing and deleting candidates looking for instructions for deleting or anonymizing a candidate? see anonymizing and deleting candidates docid\ dmwv1t1xms0rsjf7bb9vc ashby offers two options for permanently erasing candidate personally identifiable information (pii) hard deletion and anonymization hard deletion permanently removes all data associated with the candidate this includes pii as well as metadata and historical information about the hiring process and outcome this may be preferred when the data is erroneous or is otherwise reducing reporting accuracy anonymization permanently removes pii from the candidate record ashby retains metadata and non identifiable information for historical reporting purposes most organizations prefer this as their default deletion method, since it meets regulatory requirements for data erasure without sacrificing hiring process insights when is the data permanently erased? when you anonymize a candidate from within ashby, the erasure takes place immediately and cannot be undone from within ashby when you delete a candidate, ashby first "soft deletes" it, but this can be undone by the same user, an admin, or by ashby support after 10 days, ashby permanently erases it from our application database after the backup retention window of 30 days expires, ashby permanently erases the data from our backend what fields are considered pii for the purpose of anonymization? any candidate data field tagged internally as potential pii must be anonymized when new candidate data fields are added to the platform, we evaluate them to determine if they constitute pii and mark them accordingly the list of anonymized fields includes, but is not limited to name email addresses phone numbers education & employment history candidate custom fields social links notes follow ups files emails scorecards for any required fields that can't be totally removed, such as candidate name, ashby replaces the data with random ids, such as "candidate 014a9974 b9d4 4619 9276 8e69326dc8f0", or the string "this data has been anonymized " does ashby have a fedramp ato? no ashby does not have a federal risk and authorization management program (fedramp) authorization to operate (ato) ashby is designed to store and process recruiting related data, not sensitive public or governmental records if you decide to use ashby, you need to take responsibility for not sharing this sensitive data with us however, we do have organizations with stricter compliance requirements who are happily using ashby after implementing technical measures that guarantee any sensitive data is filtered out before it reaches our systems reach out if you're considering that! can ashby execute a hipaa baa? no ashby cannot execute a health insurance portability and accountability act (hipaa) business associate agreement (baa) ashby is designed to store and process recruiting related data, not sensitive protected health information if you decide to use ashby, you need to take responsibility for not sharing this sensitive data with us however, we do have organizations with stricter compliance requirements who are happily using ashby after implementing technical measures that guarantee any sensitive data is filtered out before it reaches our systems reach out if you're considering that!