Privacy and data handling training module
Last reviewed 2026-05-07
<h2>Purpose</h2>
<p>This is the required privacy and data-handling training module for HiringCoachAI personnel. It translates the public privacy policy, data map, and data-classification policy into the day-to-day rules a person must follow before receiving sensitive access.</p>
<p>Complete this module before customer-data access, production access, vendor-dashboard access, source-code access, or ongoing operational responsibility is granted, and annually thereafter.</p>
<h2>1. Use The Minimum Data Needed</h2>
<p>Only access personal data when there is a clear business purpose. Use the smallest amount of data needed to complete the task. If a screenshot, export, log excerpt, or support note can be redacted, redact it before sharing internally.</p>
<p>Customer content includes resumes, cover letters, interview answers, job applications, contact records, account details, support context, and uploaded or pasted career material.</p>
<h2>2. Know The Data Classes</h2>
<p>HiringCoachAI classifies data by where it lives and how sensitive it is:</p>
<table><thead><tr><th>Class</th><th>Plain meaning</th><th>Examples</th></tr></thead><tbody><tr><td>Public</td><td>Intended for publication</td><td>Marketing pages, public trust-center documents</td></tr><tr><td>Internal</td><td>Non-public business information</td><td>Roadmaps, internal process notes</td></tr><tr><td>Confidential</td><td>Customer or business data that could harm someone if exposed</td><td>Resumes, job-search records, emails, support context, audit logs</td></tr><tr><td>Restricted</td><td>Secrets or highly sensitive operational data</td><td>API keys, OAuth tokens, service-account keys, backup keys</td></tr></tbody></table>
<p>If unsure, treat the data as Confidential and ask the Security Officer before moving or sharing it.</p>
<h2>3. Keep Customer Data In Approved Systems</h2>
<p>Do not copy customer data into personal accounts, public documents, unapproved spreadsheets, public issue trackers, consumer AI tools, or local files unless the task requires it and the destination is approved.</p>
<p>If local handling is unavoidable for a short operational task, remove the local copy when the task is complete.</p>
<h2>4. Handle Data Subject Requests Carefully</h2>
<p>Users may request access, export, correction, deletion, objection, restriction, or portability. Do not promise a legal outcome on your own. Route privacy requests to <code>[email protected]</code> or the Privacy Officer.</p>
<p>HiringCoachAI targets a 30-day response window, with extension where the law allows for complex requests.</p>
<h2>5. Report Privacy Issues Immediately</h2>
<p>Report any possible privacy issue immediately, including:</p>
<ul><li>Sending customer data to the wrong person.</li><li>Sharing a document with broader access than intended.</li><li>Finding customer data in an unapproved system.</li><li>Losing a device that may contain customer data.</li><li>Seeing logs, screenshots, or AI prompts that contain unnecessary personal data.</li></ul>
<p>Do not delete evidence. Preserve what happened and escalate.</p>
<h2>6. Respect Prohibited Data Boundaries</h2>
<p>HiringCoachAI is not designed to process health data, payment card numbers, government ID numbers, SSNs, driver's license numbers, or biometric data. If a user includes unexpected regulated data in uploaded or pasted content, treat it as a privacy issue and escalate.</p>
<p>Stripe handles payment card capture. HiringCoachAI stores Stripe identifiers and subscription status, not card numbers.</p>
<h2>7. Use Vendors And AI Tools Only As Approved</h2>
<p>Only approved sub-processors may receive customer data. Standard vendor dashboards, support tools, AI providers, and analytics tools have different data-handling rules, so do not add a new processor or paste customer data into a new tool without approval.</p>
<p>AI-specific handling rules are in <a href="/trust/docs/responsible-ai-training-module">responsible AI training module</a>.</p>
<h2>Acknowledgment</h2>
<p>By acknowledging this module in <code>/admin/onboarding</code>, I confirm that I understand HiringCoachAI privacy and data-handling expectations, will use only the minimum data needed, will keep customer data in approved systems, and will report privacy concerns promptly.</p>