Recruiting Data Privacy
Status: April 2026
Who we are
Prior Labs GmbH is the company responsible for your data when you apply to any role at Prior Labs.
Contact: privacy@priorlabs.ai
What we collect
We only collect what we actually need to assess your application. Here’s what that looks like in practice
What you give us
- Your name, email address, and phone number
- Your CV, cover letter, and any work samples you choose to share
- Links to LinkedIn, GitHub, or a personal portfolio
- Answers to any application or pre-screening questions
- Right-to-work documents, where we’re required to check these before making an offer
What we create during the process
- Notes from interviews and technical assessments
- Internal communications between hiring team members about your application
- A record of where you are in the process and any scheduling
What we get from other sources
- Publicly available information from LinkedIn or similar professional platforms
- Information provided by anyone who refers you to us
- References from people you nominate
- Background check results, only after we make you a conditional offer, and only where the law permits it for the role in question
How we use your data
We use Ashby to manage applications. Ashby may sort or filter applications automatically, but we do not make any final hiring decision without a human reviewing your application. We may also use AI tools to record and transcribe your interview, in order to better assess your suitability for a role, as well as for internal analysis connected to your application and staff training purposes. We use your information to:
- Assess your application for a specific role
- Communicate with you throughout the process
- Run interviews and technical assessments
- Check your right to work where required
- Carry out background checks after a conditional offer
- Improve how we hire, using aggregated and anonymised analytics
- Keep you in mind for future roles, only if you separately opt in to this
We process your data to evaluate your application, meet our legal obligations as an employer, and with your separate consent, to keep you in mind for future roles. Where we rely on a legitimate interest (such as improving our hiring process), we make sure it doesn’t override your rights.
Who we share your data with
We don’t sell your data. We don’t share it for advertising. We only share it where necessary to run our recruitment process
How long we keep your data for
If you are successful and accept an offer of employment with us, any relevant personal data collected during your pre-employment period will become part of your personnel records and will be retained in accordance with specific country requirements and with the privacy notice applicable to Prior Labs employees.
If unsuccessful, we keep your application for a limited time before deleting it:
- EEA: 6 months
- United States: up to 24 months
These periods exist so we can consider you for future roles and keep records of our hiring process where required by local law. After the retention period, your data is permanently deleted or irreversibly anonymised. You can ask us to delete your data sooner at any time, just email privacy@priorlabs.ai.
Your rights
You have the right to:
- See what data we hold about you
- Correct anything that’s wrong or out of date
- Ask us to delete your data
- Object to how we’re using your data
- Withdraw your talent pipeline consent at any time, without any penalty
- Not be treated differently for exercising any of these rights
We’ll respond to your request within one month and we won’t charge you a fee.
International Transfers
We're based in Germany and the US, and some of the tools we use (like our applicant tracking system) are based in the US too. That means your data sometimes moves between Europe and the US. When personal data moves from the EU to the US, we use standard data transfer agreements that are approved by the European Commission to make sure your data stays protected.
Security
We use appropriate technical and organisational measures to keep your data secure. This includes encrypted storage and transmission, access controls so only the people who need your data can see it, and regular security reviews of the tools we use. We require the same standards from any third party that handles data on our behalf.
If a data breach occurs that is likely to affect you, we will notify you and the relevant authorities promptly, within 72 hours for EU data, and as quickly as possible for US data.