Reffem

Privacy Policy

Reffem

Effective Date: November 13, 2025
Last Updated: November 13, 2025

At Reffem ("we," "us," or "our"), we are committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered reference checking platform (the "Service"). By using the Service, you consent to the data practices described in this policy.

1. Information We Collect

1.1. Information from Hiring Managers (Clients)

When you create an account and use our Service, we collect:

  • Account Information: Name, work email address, company name, job title, and password
  • Organization Information: Company details, billing information, and organizational settings
  • Position Information: Job descriptions, position titles, requirements, and hiring criteria
  • Usage Data: Information about how you interact with the Service, including features used, reference checks initiated, and reports accessed
  • Payment Information: Billing address and payment method details (processed securely through third-party payment processors)

1.2. Information from Candidates

When candidates use our Service to provide reference information, we collect:

  • Contact Information: Name, email address, and phone number
  • Resume Information: Professional background, work history, education, and skills (when uploaded)
  • Reference Details: Names, phone numbers, email addresses, and professional relationships of references provided
  • Consent Records: Documentation of consent to contact references and conduct reference checks

1.3. Information from References

When references participate in our AI-powered reference calls, we collect:

  • Contact Information: Name, phone number, and email address
  • Professional Feedback: Responses to questions about the candidate's work performance, skills, and professional conduct
  • Call Recordings: Audio recordings of the AI-powered reference call conversations (with explicit consent)
  • Transcripts: Text transcriptions of reference call conversations
  • Consent Records: Documentation of consent to participate in the reference call and be recorded
  • SMS Communication: Records of text messages sent and received for consent requests and scheduling

1.4. Automatically Collected Information

When you access or use the Service, we automatically collect:

  • Device Information: Device type, operating system, browser type, and unique device identifiers
  • Log Information: IP address, access times, pages viewed, and actions taken
  • Location Information: General geographic location based on IP address
  • Cookies and Similar Technologies: Information collected through cookies, web beacons, and similar tracking technologies

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1. Providing the Service

  • Conducting AI-powered reference calls with professional references
  • Analyzing candidate resumes and job descriptions to generate context-aware questions
  • Processing and transcribing reference call audio recordings
  • Generating comprehensive reference check reports with AI-extracted insights
  • Facilitating communication between hiring teams, candidates, and references
  • Managing user accounts and authentication

2.2. Improving and Developing the Service

  • Training and improving our AI models to conduct more effective reference calls
  • Analyzing usage patterns to enhance features and user experience
  • Conducting research and development for new features
  • Testing and troubleshooting technical issues
  • Evaluating and improving the accuracy of our AI-powered analysis

2.3. Communication and Support

  • Sending transactional messages about your account and reference checks
  • Providing customer support and responding to inquiries
  • Notifying you about changes to the Service or this Privacy Policy
  • Sending SMS notifications for consent requests and scheduling (with explicit consent)

2.4. Security and Compliance

  • Protecting against fraud, abuse, and security threats
  • Enforcing our Terms of Service and other policies
  • Complying with legal obligations and regulatory requirements
  • Maintaining audit trails and compliance documentation

3. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

3.1. With Hiring Teams

Reference feedback and reports are shared with the hiring managers and authorized users within the organization that initiated the reference check.

3.2. With Candidates

We share limited information with candidates about the status of their reference checks (e.g., whether references have been contacted or completed) but do not share the actual feedback provided by references.

3.3. With Service Providers

We share information with third-party service providers who perform services on our behalf, including:

  • Cloud Infrastructure: Hosting, database management, and data storage providers
  • AI and Voice Technology: Providers of large language models, speech synthesis, and speech recognition services
  • Telephony Services: Voice communication infrastructure providers
  • SMS Services: Text messaging delivery services for consent requests and notifications
  • Payment Processing: Payment gateway and billing management services
  • Analytics: Usage analytics and performance monitoring services

These service providers are contractually obligated to protect your information and use it only for the purposes we specify.

3.4. For Legal Reasons

We may disclose your information if required by law or in response to:

  • Valid legal process (subpoena, court order, search warrant)
  • Requests from law enforcement or government agencies
  • Protection of our rights, property, or safety
  • Protection of the rights, property, or safety of our users or the public

3.5. Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and the choices you may have regarding your information.

4. Data Security

We implement industry-standard security measures to protect your information, including:

  • Encryption: End-to-end encryption for sensitive data in transit and at rest
  • Access Controls: Role-based access controls and authentication mechanisms
  • Secure Storage: Encrypted storage for audio recordings, transcripts, and personal information
  • Regular Security Audits: Ongoing security assessments and vulnerability testing
  • Employee Training: Security awareness training for all personnel with data access
  • Incident Response: Procedures for detecting, responding to, and reporting security incidents

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

5. Data Retention

We retain your information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Our retention practices include:

  • Account Information: Retained for the duration of your account and for a reasonable period after account closure for legal and compliance purposes
  • Reference Call Recordings: Retained for the duration agreed upon in our service agreement, typically 1-3 years for audit and compliance purposes
  • Reference Reports: Retained by hiring organizations as part of their employment records
  • Consent Records: Retained for compliance with legal obligations, typically 3-7 years
  • Usage Data: Retained for analytics and service improvement purposes, typically 12-24 months

When we no longer need your information, we will securely delete or anonymize it in accordance with our data retention policies and applicable law.

6. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

6.1. Access and Portability

You have the right to access the personal information we hold about you and, in some cases, to receive a copy of that information in a portable format.

6.2. Correction and Update

You have the right to correct inaccurate or incomplete personal information. You can update your account information directly through the Service or by contacting us.

6.3. Deletion

You have the right to request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, ongoing disputes, or legitimate business purposes). Note that deletion of certain information may limit or prevent your ability to use the Service.

6.4. Objection and Restriction

You have the right to object to certain processing of your personal information and to request that we restrict processing in certain circumstances.

6.5. Withdraw Consent

Where we rely on your consent to process personal information, you have the right to withdraw that consent at any time. This does not affect the lawfulness of processing based on consent before withdrawal.

6.6. SMS Opt-Out

For SMS notifications, you can opt out at any time by replying "STOP" to any message. Once you opt out, you will be added to our Do-Not-Contact list and will not receive further SMS messages from us.

To exercise any of these rights, please contact us at team@reffem.com. We will respond to your request within the timeframe required by applicable law.

7. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from those in your country. We take appropriate safeguards to ensure that your personal information remains protected in accordance with this Privacy Policy, including the use of standard contractual clauses or other approved transfer mechanisms.

8. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information as quickly as possible.

9. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including:

  • The right to know what personal information we collect, use, disclose, and sell
  • The right to request deletion of your personal information
  • The right to opt out of the sale of your personal information (we do not sell personal information)
  • The right to non-discrimination for exercising your CCPA rights

To exercise these rights, please contact us at team@reffem.com.

10. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR), including:

  • The right to access your personal data
  • The right to rectification of inaccurate personal data
  • The right to erasure ("right to be forgotten")
  • The right to restrict processing
  • The right to data portability
  • The right to object to processing
  • Rights related to automated decision-making and profiling

We process your personal data based on the following legal bases:

  • Contract Performance: Processing necessary to provide the Service under our Terms of Service
  • Consent: Where you have given explicit consent (e.g., for SMS notifications and call recordings)
  • Legitimate Interests: For service improvement, security, and analytics
  • Legal Obligations: To comply with applicable laws and regulations

You also have the right to lodge a complaint with a supervisory authority in your jurisdiction.

11. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect and track information about your use of the Service. Types of cookies we use include:

  • Essential Cookies: Necessary for the Service to function properly (e.g., authentication, security)
  • Analytics Cookies: Help us understand how users interact with the Service
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of the Service.

12. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies before providing them with your information.

13. AI and Automated Decision-Making

Our Service uses AI technology to conduct reference calls and analyze feedback. While our AI generates insights and summaries, hiring decisions should not be based solely on automated processing. We encourage hiring teams to review complete reference reports and exercise human judgment in their hiring decisions. If you have concerns about AI-generated content or automated processing, please contact us.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by posting the updated policy on our website and updating the "Last Updated" date. For significant changes, we may provide additional notice (such as email notification). Your continued use of the Service after such changes constitutes your acceptance of the updated Privacy Policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: team@reffem.com

We will respond to your inquiry within a reasonable timeframe.