Privacy notice
One Career Record. One employer Hiring Record. Separate visibility.
This notice describes Babu account, Portfolio, application, employer-workspace, communications, interview, audit, rights, retention, and controlled-AI data flows.
Version 2026-08-15-beta.2
Who determines the use
- For an employer hiring record, the employer determines the role, process, authorized team, evaluation, decision, and applicable policy configuration.
- Babu operates the service and determines limited account, platform security, abuse prevention, provider operations, and product reliability processing.
- A candidate controls what Portfolio version and evidence are affirmatively submitted or shared, subject to the employer’s retained hiring record after submission.
Data Babu records
- Account identity, organization membership, invitations, roles, assignments, and session-linked access state.
- Candidate Portfolio versions, private files, evidence, applications, configured answers, communications, assessments, interviews, offers, acceptance, and pre-hire handoff records.
- Employer requisitions, jobs, hiring plans, scorecards, debriefs, accountable decisions, offers, audit events, governance policy, legal holds, and operator outcomes.
- Rights cases, notice/consent records, restricted accommodation requests, approved logistics, suppressions, abuse reports, rate-limit evidence, and AI invocation provenance.
Sensitive separation
- Accommodation request details are restricted to authorized coordinators or HR; interviewers see only approved operational logistics.
- Babu Public Beta does not enable voluntary demographic collection in the hiring workflow.
- Ordinary recruiters, sourcers, agency recruiters, interviewers, and hiring managers do not receive the restricted sensitive-data capability through the standard role templates.
Sharing
- Application records are shared only with server-authorized members of the employer workspace and only within the assigned record scope.
- Public or recruiter-discoverable Portfolio evidence is shown only according to candidate visibility, claim selection, request, consent, block, and revocation controls.
- Providers receive only the data needed for an enabled transport or controlled operation. Current provider status is published in the Subprocessors notice.
- Babu does not sell personal data and does not expose provider credentials in candidate, employer, export, or AI provenance records.
Rights requests
Signed-in candidates can open and track access, export, correction, and deletion/anonymization review cases at Privacy & requests. Assisted requests require identity verification. Exports exclude internal notes, sealed scorecards, debrief deliberations, decision rationale, secrets, and other people’s or tenants’ data.
Retention and deletion
Record handling follows the record class, employer policy, applicable minimums, protected handoff state, and legal holds. See the Retention Policy. A deletion request may be deferred with a recorded reason when retention or a legal hold applies.
Contact
Contact privacy@babucareers.com. Do not send medical details in ordinary support email when the in-product restricted accommodation path is available.