Recruitment Privacy Policy (Basecamp)

Open Legal LibraryUpdated 15 Oct 2025

The Recruitment Privacy Policy explains how the company collects, stores, and uses personal data from job applicants during the hiring process. It outlines data retention periods, candidate rights under privacy laws, and the safeguards in place to ensure all applicant information is handled securely and transparently.

Other names:Data Protection PolicyGDPR PolicyPrivacy Notice

Recruitment Privacy Policy

Last updated: [date]

What we collect, where we store it, and how long we keep it

When you apply for a job at [company name] (the company), we may store your data in two places. 1) When you apply, your information is collected via an application form in Workable, our applicant tracking system. 2) If you progress to later selection stages, your information is colocated in [app name] (the application). Candidate data we collect and process in [name of hr software] and [app name] are used for selection purposes only. Access to your personal information is limited to [company name] employees who participate in the selection process.

We collect and store these data because we have a legitimate interest: we are trying to hire for a position and we need information from any candidate who applies for the role. If you apply for a job at [company name], we ask for your explicit consent so that we can accept your application information, transfer it to the US, and review your candidacy.

For more information about your rights to your data, please view our general privacy policy; all the rights outlined there also apply to your data as a candidate.

We keep records in [name of hr software] for all applicants, and [name of hr software] records consist of:

Your job application materials (full name, e-mail address, your answers to any short answer questions required in the application, your cover letter, your CV/resume);

Internal assessment notes about your application;

Emails with you concerning the selection process.

We keep records in [company name] for some applicants, only those who progress to later selection rounds, and [company name] records consist of:

Your job application materials (full name, e-mail address, your answers to any short answer questions required in the application, your cover letter, your CV/resume);

Internal assessment notes about your application and interviews;

Reference contact information and notes on the results of reference checks.

For most candidates, we'll store your data in [name of hr software] and in [app name] until we successfully fill the open position. We'll keep your personal data for up to two years if you advance to a take-home exercise or interview stage of our hiring process. We do this to maintain a pool of recent, qualified applicants, should the position re-open or should we decide to hire for another similar role. You can ask us to access, correct, update, or delete your data at any time by emailing [name of contact] [email].

If you submit an unsolicited job application through a channel other than [name of hr software], you'll receive direction to re-submit your application through [name of hr software]. Any personal information you've included, like a resume, will be immediately deleted.

If you have questions about your personal data as a job applicant, you can contact: [name of contact] [email] [address]

If you are in the EU, you can identify your specific authority to file a GDPR complaint at https://edpb.europa.eu/about-edpb/board/members_en.

This is a preview. The full template is free on GitLaw.

5.0 out of 5 on Google

Read reviews

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

United States note

This version is drafted for US law generally. Contract, employment and consumer rules vary by state — for example on non-competes and at-will employment. Tell GitLaw which state applies and it adjusts the draft.

Jurisdiction
United States of America
European Union
Source
Recruitment Privacy Policy by Basecamp
from Basecamp
Document info
HTML document. Document created on Fri Sep 26th, 2025. Last updated on Wed Oct 15th, 2025.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
European Union
Content Moderation Practices by Mozilla
This document outlines how an organization manages content moderation for user-generated text, images, and software applications. It specifies the human-led review process for reports of illegal or policy-violating content and the subsequent appeals procedure for both reporters and account holders.
Updated 13 Aug 2026
US
About Your Rights by Mozilla
This notice informs users of their rights under a free and open source software license, specifically allowing for the use, modification, and distribution of the source code. It includes placeholders for the software name, company name, and a direct link to the applicable privacy policy.
Updated 13 Aug 2026
US
Incapacitated Policy (Basecamp)
This document outlines the procedure for managing or closing the account of a deceased or incapacitated user. It details the required legal documentation and verification steps for an authorized person to export data or cancel billing.
Updated 13 Aug 2026
Portugal
Privacy Policy (Portugal) by Seedsummit
This privacy notice is for companies in Portugal collecting and processing customer data. It outlines how personal information is handled, stored, and protected in compliance with the General Data Protection Regulation.
Updated 13 Aug 2026
Denmark
Privacy Policy (Denmark) by Seedsummit
This internal data protection policy establishes how a company manages personal information in compliance with the EU General Data Protection Regulation. It defines processing principles such as data minimization and storage limitation, and outlines the responsibilities of a designated IT systems administrator in Denmark.
Updated 13 Aug 2026
England & Wales
Data Breach Notification Policy
This internal policy outlines how an organisation identifies, investigates, and reports personal data breaches to the Information Commissioner's Office (ICO). It establishes a 72-hour reporting window for high-risk incidents and mandates the maintenance of a comprehensive Data Breach Register for all security events.
Updated 13 Aug 2026

Frequently asked questions

A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.

Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.

Yes, read about team plans here.

Describe what you need in the chat and GitLaw will draft it for you.

Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.

Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.

It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.

Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.

Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.

Trusted by 5,000+ businesses

Nexus logoMlabs logoTechstars logo

From template to signed, in one place

Every template opens in an editor with an AI agent alongside it.

1

Open

Pick a template and open it. Nothing to download, and no credit card to start.

Free to open

2

Edit with AI

Describe your situation in chat and the agent adapts the wording, clause by clause.

Tracked changes you can review

3

Send and sign

Share it for negotiation, then collect signatures without leaving GitLaw.

eSign included

Built for your legal work,
with practicing lawyers

Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

Ready to get started?

No sales calls, no credit card. Just chat with GitLaw.

GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.