
Socure’s Candidate & Employee Privacy Notice
Last updated – Sep 08, 2026
Hello there!
Socure Inc. (“Socure”) is committed to protecting personal privacy, which includes the security of Personal Information that we hold and use. This Candidate and Employee Privacy Notice (“Privacy Notice”) covers the collection and use of Personal Information we collect and process of our job recruits and job applicants (our “candidates”), as well as our employees. If you have questions, or wish to exercise your legal privacy rights, please use our Data Rights form or email us at privacy@socure.com. As it pertains to requests to correct and/or delete your Personal Information, Socure shall make good faith efforts to correct and/or delete such Personal Information and shall instruct applicable third parties with whom it has disclosed such Personal Information, unless such correction and/or deletion is not feasible, is unduly burdensome, and/or violates applicable law.
This Privacy Notice is not a contract and does not create any legal rights or obligations. This Privacy Notice also is not intended to replace other notices or disclosures we may provide to you in connection with your application for a job or your role in our organization, which will supersede any conflicting disclosures contained in this Privacy Notice. We are the “Controller” of the Personal Information we hold about you, because we determine why and how it is used.
When we use the term “Personal Information” in this Privacy Notice, we mean information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to you within the context of you acting as a job candidate or employee. It does not include aggregated or de-identified information that is maintained in a form that is not capable of being associated with or reasonably linked to you.
During the recruiting process, when you apply for a job with us, and if you become an employee, we collect Personal Information about you directly or from third parties with your approval, which may include without limitation:
- Identifiers, such as your full name, email address, home address, date of birth and telephone number, professional and educational information.
- Professional History & Qualifications, such as your previous employers, positions and work experience, professional licenses, certificates or other qualifications, and employment references or referrals.
- Educational History & Qualifications, such as your highest level of education, the schools you attended and when you were in attendance, degrees, certificates, or other educational qualifications you earned, and your transcripts or educational references.
- Financial Information, such as your bank account details, tax information, salary, bonus, benefits, 401(k), expenses, and equity grants, and other information necessary to administer payroll, taxes, benefits to the extent required by law.
- Other Application and Interview Information, such as any personal information or technical assessment results you choose to provide to us in your interview or application, CV, resume, transcripts, or other supporting documentation.
- Identity, Citizenship and Immigration Information, such as your identity documents, work permits, visas, and other information and documentation required to verify your eligibility to lawfully work in the United States.
- Information Received from Third Parties, such as the results of a professional-reference check and the summary and/or actual results of your background check conducted in accordance with Socure’s policy and practice, as well as applicable law.
- Performance, such as reviews, performance evaluations, written warnings, discipline, and promotions.
- Time Off, such as prior, current, or future paid time off, medical leaves of absence, or other leaves of absence or time off.
- Termination, such as separation and other off-boarding related documentation.
- Sensitive Personal Information, including characteristics of protected classifications, such as demographic information or information about your gender, race, ethnicity, and disabilities, but only when permitted under applicable laws. We process this personal data for a variety of reasons, and this will vary in our different jurisdictions. Our reasons for processing this data include:
- Where it is necessary to comply with local requirements and applicable law. For example, we may use this information to comply with anti-discrimination laws and government reporting obligations;
- To monitor and ensure equal treatment and opportunity;
- To provide work related accommodations or adjustments, to provide health and insurance benefits to you and to your dependents, and to manage absences from work.
- Where the processing of this personal data is not required by law, we will seek your consent to process your data and, in the consent mechanism, we will explain the purposes for which we will use your data. This will be voluntary, and you may decide whether or not to give consent.
- Workplace, Device, Usage, and Content data, such as account log in and other credential or access information; the contents of your communications via any format (e.g., mail, email, text messages, and messenger applications like Slack).
- Verification Information, as a condition of employment and based on our legitimate interest in securing our workplace, we may require you to verify your identity using our identity verification and fraud detection services. When using such services, we will collect personal information, including sensitive personal information like photos and biometrics, per our published Global Services Privacy Notice and Document & Biometric Verification Privacy Notice.
Providing certain Personal Information described above, such as identity, citizenship, and immigration documentation, or financial information necessary for payroll and benefits administration, is necessary for us to process your application or continue your employment. If you do not provide this information, we may be unable to proceed with your application, offer you employment, or continue your employment relationship, as applicable.
Socure does not interview or employ individuals under 18 years of age, and as such, does not have any actual knowledge that it sells or shares personal information belonging to a minor.
Depending on where you reside, you have the same categories of data rights, including the right to know, access, correct, delete, restrict processing, object to processing, receive your data in a portable format, withdraw consent, and lodge a complaint with your applicable data protection or supervisory authority. This is described in the “Your Rights & Choices” section of our Global Services Privacy Notice.
How to exercise these rights. To exercise any of these rights in connection with your candidacy, visit our Data Rights Form. If you are a current employee, you can update most of your personal information directly in Workday; for rights not available through Workday, please also use our Data Rights Form. Because data rights vary by where you live, some rights may or may not apply to you, and we may not be able to fulfill a request if the law does not grant you the right you are attempting to exercise. Because data rights vary by where you live, some rights may or may not apply to you, and we may not be able to fulfill a request if the law does not grant you the right you are attempting to exercise.
Verification. To help protect the security of your Personal Information, we will take reasonable steps to verify your identity before completing your request.
Authorized agent. You may designate an authorized agent to submit a request on your behalf, subject to verification of both your identity and the agent’s authority to act for you.
Limitations. There are situations where we may not be able to grant a request. For example, where the law requires us to keep a record, where granting it would undermine legitimate business, security, or legal interests, where it would infringe on someone else’s privacy, or where the right is not available to you based on where you live.
Although we often collect the Personal Information described above directly from you, we may also collect certain information from references, recruiters, job related social media sites (such as LinkedIn), and publicly available sources. In addition, we may also collect this information through service providers and other third parties that collect it on our behalf, such as communications providers, scheduling providers, application providers, and background check providers.
We, and our approved service providers, use the Personal Information we collect during the recruiting process, when you apply for a job with us, and as part of your employment only as reasonably necessary for our business purposes. Such business purposes include to:
- identify you as a potential candidate and review your application for a position with us;
- verify the information provided to us in connection with your application or received from other sources;
- verify your identity;
- determine your eligibility and suitability for the potential position or other opportunities with us;
- facilitate the recruiting and interview process;
- communicate with you about the status of your application or other opportunities with us that may be of interest to you;
- assess and improve the performance and success of our recruiting and hiring process;
- offer you employment with Socure;
- onboard you as a Socure employee and ensure you may receive compensation, benefits, and equity awards associated with your employment;
- undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by Socure;
- to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by Socure;
- help ensure security and integrity to the extent the use of your personal information is reasonably necessary and proportionate for those purposes;
- fulfill contractual obligations to you and other third parties; and
- comply with applicable laws, rules, regulations, legal proceedings and government investigations, including relating to tax reporting and immigration matters.
Characteristics of protected classifications under applicable federal, state, and/or local law are used only to understand and analyze the distribution of applicants and employees and are not considered in interview or employment decisions such as hiring or promotions, unless specifically permitted or required by law. We rely on several legal grounds to process your Personal Information. In many cases, processing is necessary to perform our contract with you, or to take steps at your request prior to entering into one. For example, evaluating your application, extending an offer, or administering your employment, compensation, and benefits. We also rely on our legitimate interests to manage our recruiting and hiring process, secure our workplace and systems, and manage our workforce, and on our legal obligations to comply with requirements such as tax reporting, employment verification, and anti-discrimination reporting.
Where we rely on your consent to process your Personal Information, we will seek that consent at the time we collect it, and you may withdraw your consent at any time.
In certain circumstances, Socure may use automated tools, which may be supported by artificial intelligence, to help assess your application. For example, we may review your resume or conduct pre-screening assessments against the qualifications for a role. These tools produce a result based on the information you provide, which we may use to help decide whether to move your application forward.
Your right to a human review. Where a tool like this is used to make a decision that produces a legal effect or similarly significantly affects you, you have the right to request human intervention, express your point of view, and contest the decision. To request a review, contact us at privacy@socure.com.
California and other U.S. state applicants. Depending on where you live, you may have additional rights related to our use of automated decision-making technology, including the right to receive notice before it is used and, in some cases, the right to opt out or access information about the ADMT use. To exercise these rights, contact us as described in “How to Contact Us.”
The Personal Information described above is regularly disclosed, including within the past twelve months, only to those third-party service providers retained by Socure for the discrete purposes set forth herein, and will be retained for no longer than is reasonably necessary for the disclosed business purpose. Neither Socure, nor its service providers (which include, without limitation, human resources information systems, Internet application tracking tools, background checks providers, immigration support, payroll and benefits providers, equity platforms, and performance management tools), sells your Personal Information. Similarly, Socure does not share your Personal Information for cross-context behavioral advertising.
From time to time, for business purposes, Socure may also need to disclose your Personal Information to the following third parties:
- professional advisors, such as lawyers, auditors, bankers and insurers, where necessary in the course of the professional services that they render to us;
- service providers who help us with our hiring process, including applicant-tracking software and talent-acquisition services;
- our corporate affiliates – depending on your location, we may share your personal information with members of the Socure Talent Acquisition and related teams who are based in other countries or may work for corporate affiliates;
- governmental agencies or public bodies such as a court of law, arbitral tribunal, law enforcement agency or other third party, where required or otherwise permitted by law; or
- a third party as part of a business transaction such as a merger or acquisition.
We only keep your Personal Information for as long as we actually need it, consistent with our data retention practices and applicable law.
Exactly how long varies by the type of information and whether you are a candidate or an employee. When we decide how long to keep something, we consider:
- how much information it is, and how sensitive it is;
- the risk of harm if it were used or disclosed without authorization;
- why we’re processing it, and whether we could achieve the same purpose without keeping it as long;
- our legal obligations around tax, health and safety, and employment, including any actual or potential disputes or investigations;
- our contractual obligations and rights;
- our legitimate interests;
- any mandatory retention periods or statutes of limitations under applicable law; and
- guidance from relevant data protection authorities.
Once we no longer need your information for the purposes we collected it for, we securely delete it.
We protect the personal information described in this Notice using the same safeguards described in our Global Services Privacy Notice, including encryption in transit and at rest, strict access controls, and recurring audits under our ISO 27001 and SOC 2 Type 2 certifications. While we try our best, no safeguard can fully guarantee against a security incident.
Socure stores personal information in the United States, and it may be transferred to and processed there if you’re located elsewhere. Where required, we rely on cross-border transfer safeguards such as the EU-U.S., UK, and Swiss Data Privacy Frameworks and Standard Contractual Clauses as described in our Global Services Privacy Notice.
Please do not email us your identity documents, selfies, or other personal information. If you are having trouble submitting your documents or need help troubleshooting or understanding the outcome of a specific transaction, please contact the Customer who sent you to us.
To contact the Socure Privacy team, including our Data Protection Officer (DPO), you may email privacy@socure.com or call 1-888-690-3709. Our DPO is Socure’s General Counsel and VP of Legal, Aviad Levin-Gur.
Pursuant to Article 27 of the General Data Protection Regulation (GDPR), Socure has appointed the European Data Protection Office (EDPO) as its GDPR Representative in the EU. You may contact EDPO regarding matters pertaining to the GDPR: (1) by using EDPO’s online request form; or (2) by writing to EDPO at Avenue Huart Hamoir 71, 1030 Brussels, Belgium.
Pursuant to Article 27 of the UK GDPR, Socure has appointed the EDPO UK Ltd as its UK GDPR representative in the UK. You may contact EDPO UK regarding matters pertaining to the UK GDPR and/or complaints under section 164A of the Data Protection Act 2018 (“DPA 2018”) as amended by the Data (Use and Access) Act 2025 (“DUAA”): (1) by using EDPO’s online request form; or (2) by writing to EDPO UK at Unit 33, Waterside, Schooner Court, 44-48 Wharf Road, London, N1 7UX, United Kingdom.
Please contact us if you have any complaints. If you are a UK and EU individual and your complaint is not addressed by us within the applicable timeframe, you may contact the EDPO by using the relevant EDPO’s online request forms above. If your complaint under the EU-U.S. (including the U.K. extension) and Swiss-U.S. DPF isn’t resolved, you may refer it, free of charge, to Data Privacy Framework Services, operated by BBB National Programs — visit this website for details. If it still isn’t resolved, you may, under certain conditions, invoke binding arbitration for residual claims — see here for more information.