Monitored company
Celtra
clause.watch tracks 2 legal documents published by Celtra (celtra.com), re-reading each one every six hours. Below is what each document covers, in plain English.
Candidate Privacy Policy
Candidate Privacy Policy — Key Terms and Risks
1. Data Collection & Usage
Celtra may collect:
- Identity and contact information, such as your name, email address, résumé/CV, and other information identifying you.
- Recruitment information, including references and background-check information, where applicable.
- Information from third parties, including LinkedIn, Glassdoor, Indeed, JobMatch, Facebook, Recruiterbox, and recruiting agencies.
- Analytics data, including information collected through Google Analytics cookies and similar technologies.
- Materials you voluntarily submit to demonstrate your skills or abilities.
Celtra says it uses this information for recruitment and candidate evaluation. If you are hired, recruitment information becomes part of your employment record. You may opt out of recruitment emails and job-opening notifications.
Important limitation: The document’s “How we use your Information” section appears incomplete—it says “Celtra will use your Information to:” but does not provide the promised list of purposes. This makes the scope of permitted use less clear than it should be.
Submitted materials are generally used only for evaluation, but Celtra may independently develop or use ideas, products, or technologies similar to those in your materials. Submission does not give you protection against similar internal or third-party development.
You are responsible for obtaining consent from references before giving Celtra their information.
2. User Rights
The policy states that residents of the European Economic Area or Australia have certain rights, but the actual list of rights is missing from the supplied document. It likely intended to address rights such as access, correction, deletion, restriction, or objection, but this cannot be confirmed from the text provided.
Requests must be sent to an email address that is also missing from the document, with the subject line “Data Subject Request.” Celtra may request identity verification, reject unreasonable or impractical requests where local law permits, and take a reasonable time to respond.
The policy also says you may request deletion or updating of your information and may request return or destruction of submitted materials.
3. Third-Party Sharing
Celtra may share information with:
- Its affiliates and subsidiaries worldwide.
- Recruitment agencies and other recruitment-service providers.
- Service providers processing information on Celtra’s behalf.
- Government authorities or other parties where legally required.
- Buyers or successor entities in a merger, acquisition, restructuring, asset sale, bankruptcy, or insolvency.
Service providers are expected to use reasonable security measures and process information only to provide services for Celtra. However, the policy allows broad corporate-transaction disclosures, potentially including sale or transfer of candidate information.
4. AI/ML Training
The policy does not state that candidate information is used to train artificial-intelligence or machine-learning models. It also does not expressly prohibit such use. The incomplete description of permitted uses creates some uncertainty. If AI screening, automated decision-making, or model training is important to you, request clarification from Celtra before submitting information.
5. Key Obligations and Restrictions
- Provide accurate information and obtain permission from references.
- Understand that cookies and analytics technologies may collect information.
- Accept that information may be transferred internationally, including to the United States.
- Do not assume submitted ideas or materials will remain exclusive or legally protected from similar development.
- Continued use of recruitment services generally indicates acceptance of policy changes, subject to the policy’s statement that material changes will not be enforced without explicit consent.
6. Security, Liability & Disputes
Celtra promises “reasonable” technical and organizational safeguards, but says no security system is perfect. It does not guarantee that information will never be accessed by unauthorized persons or become publicly available, and it disclaims responsibility for third-party circumvention of security measures.
The policy contains no clear dispute-resolution procedure, governing-law clause, arbitration requirement, or liability cap in the text provided. It therefore does not explain how privacy disputes must be brought or what damages may be recoverable. Other Celtra terms or applicable law may address these issues.
7. Retention and Changes
Celtra may retain information as long as needed for recruitment or a legitimate business purpose, and may keep it for up to two years to consider you for future positions. After deletion, it may retain:
- Limited information to avoid contacting you again.
- Anonymous information for analytics, planning, and reporting.
- Information needed for legal compliance, disputes, enforcement, or technical security purposes.
Celtra may update the policy. It recommends checking regularly and will post notice of material changes on www.celtra.com/careers, including their effective date. The policy says material changes will not be enforced without explicit consent, although it also refers generally to acceptance through continued use.
Privacy Policy
Privacy Policy Overview
Policy date: August 26, 2024
Applies to: Website visitors, Celtra platform users, marketing contacts, and people who interact with digital advertisements created or delivered through Celtra.
1. Data Collection & Usage
Celtra collects different information depending on how you interact with it:
- Contact and professional information: Name, email, job title, employer, address, and phone number when you contact Celtra, attend events, request demonstrations, take courses, or use the platform.
- Billing information: Employer bank details, credit-card information, expiration date, billing ZIP code, and similar payment data when required. Payment processing may be handled by third-party providers.
- User activity data: IP address, browser/device type, language, referring and exit pages, URLs, dates and times, pages visited, and time spent on the Website or platform.
- Service data: Incoming IP addresses and technical connection information, used for security, fraud detection, platform availability, and troubleshooting advertising errors.
- Ad interaction data: Time viewing ads, page and video views, clicks, IP address, device ID, GPS coordinates, advertising identifiers such as IDFA/AAID, and information voluntarily entered into ad forms.
Celtra uses data to provide and improve its services, operate the platform, communicate with users, process payments, support customers, measure advertising effectiveness, detect fraud, and deliver more tailored advertising.
Cookies and similar technologies may track activity across websites, apps, and devices. Celtra cookies used on behalf of customers last up to 90 days, although they may be renewed when a device is encountered. Other companies may combine Celtra-related data with information they independently collect.
2. User Rights
EEA/European users
Where Celtra is the data controller, users may generally request:
- Access to their personal data
- Correction or updating of inaccurate data
- Deletion, subject to legal retention requirements
- Withdrawal of consent or objection to processing
- Opt-out from marketing communications
- Information about qualifying automated decisions
- The ability to complain to a data-protection authority
Requests should be sent to privacy@celtra.com with “Data Subject Request” in the subject line. Celtra may verify identity and may redirect requests to its customer when Celtra acts only as a processor.
California users
CCPA/CPRA rights may include access, correction, deletion, information about collection and disclosure, opting out of certain sales or automated decision-making, and non-discrimination. However, the California notice expressly excludes many business representatives and individuals whose data Celtra handles as a service provider—including most platform users and end users. End users are generally directed to the relevant advertiser, publisher, or agency.
Celtra states it does not sell personal information as defined by California law, but third-party advertising cookies are used.
3. Third-Party Sharing
Celtra may share data with:
- Its advertising customers, including advertisers, publishers, agencies, and their agents
- Vendors providing hosting, analytics, support, billing, database, marketing, and other operational services
- Corporate affiliates
- Courts, regulators, law enforcement, or government authorities when legally required
- Buyers or successor entities during a merger, acquisition, asset sale, bankruptcy, or similar transaction
- Parties involved in fraud prevention, security, contract enforcement, or protection of Celtra’s rights
Customers and advertising partners may use tracking technologies and combine data across websites, apps, and devices under their own privacy policies. This creates a significant risk that advertising-related data will be used beyond Celtra’s direct control.
4. AI/ML Training
Celtra may use third-party services incorporating AI or machine learning for customer services and internal efficiency.
The policy states that Celtra does not use vendors that train AI/ML models using confidential customer data or individuals’ personal data. It also says Celtra does not use AI/ML for automated employment decisions. However, it does not clearly state whether Celtra trains its own models using de-identified, aggregated, or non-personal data.
5. Key User Obligations and Restrictions
- Users must be at least 13 years old.
- Do not submit personal data if you do not consent to its transfer to the United States.
- Users should manage cookies through browser settings and unsubscribe from marketing emails when desired.
- Review third-party privacy policies before submitting information through linked websites or social-media features.
- Businesses using Celtra should ensure they have appropriate authority, notices, and consents for data supplied to Celtra.
6. Liability & Disputes
The policy does not specify governing law, arbitration, venue, or a formal dispute-resolution process.
Celtra uses “reasonable” security measures but disclaims any guarantee that data will be secure or viewed only by authorized people. It says it cannot control third parties with whom users share data and accepts no liability for improper third-party access. Celtra also disclaims responsibility for external websites and their data practices. These provisions materially limit practical recourse, although applicable privacy laws may override some limitations.
7. Changes
Celtra may revise the policy at its discretion. Material changes will generally be posted on the Website’s home page; sometimes advance notice will be provided. Continued use of the Website or services after posting is treated as acceptance, so users should review the policy regularly.
Change history
2026-09-06 · Candidate Privacy Policy
Structured Summary of Important Changes
1. No Express Authorization to Train AI Models
- The revised policy does not expressly authorize Celtra, its affiliates, or service providers to use Candidate Information, resumes, application materials, or other personal data to train, fine-tune, validate, or improve AI models.
- It also does not state that candidate data will be excluded from AI training.
- The revised language permits use of anonymous, non-PII data for business planning, hiring-trend analysis, internal reporting, and other legitimate business interests. This could potentially include AI-related analytics if the data is genuinely anonymized, but it is not a clear AI-training authorization.
- Service providers may process information only to provide services on Celtra’s behalf. This appears to restrict independent use of candidate data, although the policy does not specifically address AI vendors, model providers, or whether data is retained in provider training systems.
2. Broader and More Flexible Data-Use and Sharing Framework
- The former specific list of uses—such as verifying information, conducting checks, managing recruitment, assessing eligibility, and processing applications—is replaced with narrower language stating that access will be limited to Celtra personnel evaluating candidates.
- Sharing provisions are reorganized and expanded to include:
- Celtra affiliates and subsidiaries;
- third-party recruitment service providers;
- service providers processing information on Celtra’s behalf;
- legally required disclosures; and
- disclosures in mergers, acquisitions, reorganizations, asset sales, bankruptcy, or insolvency.
- The transaction language now expressly says Celtra may “disclose, sell, transfer, or share” assets, including Candidate Information. This creates a significant risk that candidate data may be transferred to a buyer or successor.
3. Retention Changes
- The policy now allows retention for as long as needed for recruitment services or where Celtra has a “legitimate business purpose.”
- Candidate Information may be retained for up to two years to consider candidates for future roles.
- After deletion, Celtra may retain:
- limited PII to avoid contacting the candidate again; and
- anonymous, non-PII for business planning, hiring analysis, reporting, and other legitimate interests.
- Materials may be returned or destroyed after review or upon earlier request, which is a helpful clarification.
4. International Transfers and Rights
- The policy expressly states that servers are located in the United States and that information from outside the US will be transferred there.
- New or expanded rights are provided for residents of the EEA and Australia, including access, correction, deletion, objection, withdrawal of consent, marketing opt-out, and information about significant automated decisions.
- Celtra may verify identity and reject requests that are unreasonable or impractical.
5. Security and Drafting Risks
- Security language now refers to “reasonable technical and organizational security measures,” but emphasizes that no measures are impenetrable and disclaims responsibility for third-party circumvention or public disclosure.
- The diff appears to contain substantial formatting and structural corruption, including merged section headings, missing or incomplete contact details, and potentially confusing consent language. The final policy should be carefully redrafted before publication.
2026-08-29 · Privacy Policy
2026-08-28 · Candidate Privacy Policy
Summary of Important Changes
1. AI-model training
- No express authorization to use Candidate Information or application materials to train AI models appears in the revised language.
- The updated purposes include analyzing information in “aggregate” and “anonymous” form for business planning, hiring trends, internal reporting, and legitimate business interests.
- However, the policy does not define “anonymous” or explain whether de-identified information could be used to develop, improve, test, or train AI systems. It also does not expressly state that resumes, interview responses, skills materials, or other candidate submissions will be excluded from AI training.
- The deletion section permits retention of anonymous, non-PII information for business purposes. If information is not truly anonymized, it could remain usable for analytics or potentially AI development.
- Risk: Candidates do not receive a clear, specific disclosure about AI processing or a dedicated opt-out/right concerning AI training. Celtra should clarify whether AI tools are used in recruiting and whether candidate data or submitted materials are used to train models.
2. Expanded purposes for using information
The revised policy replaces a narrower statement focused on limiting access and evaluating candidates with a detailed list of purposes, including:
- recruitment administration and application processing;
- reference and background checks;
- contacting candidates about jobs, events, and newsletters;
- immigration and work-permit assistance;
- aggregate and anonymous business analysis;
- legitimate business interests; and
- compliance with laws, legal processes, and government requests.
Risk: The purposes are materially broader, particularly “legitimate business interests,” and may permit additional internal uses beyond evaluating the specific application.
3. Broader sharing and disclosure
The policy now expressly allows sharing with:
- Celtra affiliates and subsidiaries;
- third-party recruitment service providers; and
- service providers acting on Celtra’s behalf.
It also permits disclosure where considered appropriate or useful, for legal reasons, or in connection with a merger, acquisition, reorganization, asset sale, bankruptcy, or insolvency.
Risk: “Appropriate or useful” is broader and less objective than the former wording. The policy does not identify specific providers, locations, international transfer safeguards, or limits on downstream processing.
4. Retention and deletion
- The former specific retention period of up to two years is replaced with retention for as long as needed to provide services or for a legitimate business purpose.
- Materials may still be returned or destroyed after review or upon earlier request.
- After deletion, Celtra may retain limited PII, anonymous/non-PII data, and information needed for legal, dispute, enforcement, or security purposes.
Risk: The revised policy removes a clear maximum period, creating greater uncertainty about how long candidate data may be retained.
5. Expanded privacy rights
For EEA and Australian candidates, the policy adds or clarifies rights to:
- access, correction, and deletion;
- object to or withdraw consent;
- opt out of marketing;
- obtain information about automated decisions with significant or legal effects; and
- complain about processing.
These additions improve transparency, although Celtra may decline requests where legally permitted and may retain data despite deletion requests.
2026-08-27 · Candidate Privacy Policy
Summary
The supplied diff only states that approximately 435 words were removed. It does not identify which clauses, definitions, rights, or obligations were deleted.
AI Training and Customer Data
- No determination is possible from the information provided about whether the document’s provisions on AI-model training changed.
- The removed text could potentially have addressed:
- Whether customer data may be used to train, fine-tune, or improve AI models;
- Whether usage is permitted by default or requires customer consent;
- Use of customer prompts, inputs, outputs, metadata, or derived data;
- De-identification, anonymization, or aggregation requirements;
- Opt-out or deletion rights;
- Restrictions on human review or disclosure to third-party AI providers;
- Ownership of or rights in model weights, outputs, or derived models; and
- Data retention, security, and deletion after termination.
Potential Legal Risk
Because the deleted language is not provided, the principal risk is loss of protections or increased ambiguity. If the removed provisions limited use of customer data for AI training, their deletion could broaden the provider’s ability to use that data. Conversely, if the deleted language contained the provider’s authorization to train models, its removal could restrict or eliminate that permission.
The effect also depends on whether other sections contain:
- Broad licenses to use customer content;
- Rights to use data for “service improvement,” analytics, or product development;
- Exceptions for de-identified or aggregated information;
- Confidentiality and data-processing restrictions; or
- Specific AI-training terms elsewhere in the agreement.
Required Information
A reliable legal analysis requires the actual deleted text, preferably a complete redline showing:
1. The clauses before and after the change;
2. Any replacement language;
3. Definitions of “Customer Data,” “Content,” “Usage Data,” and similar terms; and
4. Related provisions on confidentiality, data protection, intellectual property, and AI services.
On the current record, no specific change to AI-training rights can be confirmed.
2026-08-27 · Privacy Policy
2026-08-27 · Privacy Policy
2026-08-27 · Candidate Privacy Policy
Summary
The supplied diff does not contain the actual amended contract language. It only states:
> “Added approximately 435 words to the document”
Accordingly, it is not possible to identify:
- The specific legal or commercial changes;
- New obligations, permissions, disclaimers, or liabilities;
- Changes to data ownership, confidentiality, privacy, security, or use rights;
- Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether such use is subject to consent, opt-out rights, anonymization, aggregation, retention limits, or restrictions on human review; or
- Whether the changes apply to historical data, future data, content submitted by users, or derived data.
AI-Training Review
No AI-training language is included in the provided diff. The statement that approximately 435 words were added does not reveal whether the new terms:
- Permit the provider to use customer content or personal data for model training;
- Permit use of prompts, outputs, feedback, metadata, or usage information;
- Allow disclosure to affiliates, contractors, or third-party model providers;
- Grant the customer an opt-out or require affirmative consent;
- Limit training to de-identified, aggregated, or non-personal data;
- Give the provider ownership of trained models or model outputs derived from customer data; or
- Preserve confidentiality and deletion obligations after termination.
Required Information
Please provide the actual redline text, including the additions and deletions marked with {}, [], and []{}. Without the substantive language, no reliable legal-risk analysis can be performed.
2026-08-24 · Privacy Policy
2026-08-23 · Privacy Policy
2026-08-23 · Candidate Privacy Policy
Key Changes and Risks
1. No express AI-training authorization
- The revised policy does not expressly state that Candidate Information, resumes, interview materials, or other submitted data may be used to train, fine-tune, evaluate, or improve AI models.
- It also does not expressly prohibit such use.
- The former “aggregate and anonymous” analytics language is replaced with broader language permitting retention of anonymous, non-PII for business planning, hire-trend analysis, internal reporting, and other legitimate business interests.
- Risk: If Celtra or its vendors use recruitment data in AI systems, the policy does not clearly explain that practice, the categories of data involved, whether data is de-identified, or whether candidates can object or opt out. “Anonymous” data may still create re-identification or model-memorization concerns if de-identification is inadequate.
2. Narrower stated use of Candidate Information
The prior list expressly described uses including:
- verifying information;
- reference and background checks;
- managing the recruitment relationship;
- contacting candidates about suitable opportunities;
- assessing eligibility;
- processing job applications;
- recruitment events and newsletters;
- immigration assistance; and
- aggregate, anonymous analysis.
The revised wording primarily states that Celtra will use reasonable safeguards to limit access to personnel evaluating candidates, with separate provisions addressing marketing, employment records, cookies, and sharing.
Risk: The revised policy is less transparent about the full purposes for which information may be processed. It may create ambiguity about whether previously listed activities—particularly background checks, candidate communications, immigration assistance, and eligibility assessment—remain authorized.
3. Expanded sharing and disclosure
The revision expressly permits disclosure to:
- Celtra affiliates and subsidiaries;
- third-party recruitment service providers;
- service providers acting on Celtra’s behalf;
- parties where legally required; and
- parties involved in a merger, acquisition, reorganization, asset sale, bankruptcy, or insolvency.
The revised service-provider language says providers will process information solely to provide services, which is a useful limitation. However, the transaction language permits Celtra to disclose, sell, transfer, or share some or all assets, including Candidate Information.
Risk: Candidate data may be transferred to new owners or transaction counterparties without separate notice or consent. The policy does not identify vendor categories, locations, safeguards, or restrictions on secondary use, including AI-related use by vendors.
4. Retention changes
- The revision introduces a clearer retention period of up to two years to consider candidates for future positions.
- It permits retention where Celtra has a “legitimate business purpose.”
- Materials may be returned or destroyed after review or upon earlier request.
- After deletion, Celtra may retain limited PII to avoid future contact and anonymous/non-PII for business purposes and legal or technical requirements.
Risk: “Legitimate business purpose” is broad and does not establish a firm maximum retention period for all data.
5. International transfers and rights
- The revision states that servers are located in the United States and that information from outside the US will be transferred there.
- Rights are expanded for residents of the EEA and Australia, including access, correction, deletion, objection, withdrawal of consent, marketing opt-out, and information about significant automated decisions.
- Requests may be rejected where unreasonable or impractical, and identity verification may be required.
6. Security disclaimer
The revision adds detailed disclaimers that security is not perfect, Celtra cannot guarantee authorized access, and it is not responsible for third-party circumvention or publicly available information.
Risk: These provisions may reduce perceived responsibility for security incidents and should not be read as eliminating statutory data-security obligations.
2026-08-22 · Candidate Privacy Policy
Summary
The supplied diff does not include the actual contractual language that was added, deleted, or replaced. It only states:
> “Added approximately 435 words to the document”
Accordingly, the legal and commercial impact cannot be reliably assessed.
AI Training and Customer Data
No language is provided addressing whether customer data may be:
- Used to train, fine-tune, or improve AI models;
- Shared with model providers or other third parties;
- Used in aggregated, de-identified, or anonymized form;
- Retained for model-development purposes after termination;
- Subject to an opt-out, consent requirement, or customer approval;
- Excluded from training when it contains personal, confidential, or regulated information.
Because the underlying text is missing, it is not possible to determine whether the new provisions create or expand rights to use customer data for AI training.
Potential Risks Requiring Review
The added language should be checked for:
1. Broad data-use rights — permissions covering “improvement,” “analytics,” “research,” or “product development” may implicitly authorize AI training.
2. De-identification standards — “de-identified” data may still create re-identification or confidentiality risks if the standard is vague.
3. Third-party disclosures — data may be transferred to cloud providers, AI vendors, or affiliates.
4. Retention — training data may be retained indefinitely, including after contract termination.
5. Confidentiality and privacy conflicts — AI-use rights may conflict with confidentiality obligations, data-protection laws, or customer restrictions.
6. Lack of control — the customer may lack notice, approval, audit, deletion, or opt-out rights.
7. Liability allocation — the amendment may disclaim responsibility for model outputs, misuse, breaches, or regulatory violations.
Required Information
Please provide the actual added, deleted, and replacement wording. Without the text of the amendment, no definitive conclusion can be reached about the customer’s data rights or any AI-training authorization.
2026-08-22 · Candidate Privacy Policy
Summary
- The diff states that approximately 435 words were removed, but it does not identify which provisions, definitions, or sections were deleted.
- Because the actual deleted text is unavailable, the legal and commercial impact cannot be reliably determined.
AI Training and Customer Data
- The provided diff does not show whether any language was added, removed, or changed regarding:
- Use of customer data to train, fine-tune, or improve AI models;
- Use of customer prompts, inputs, outputs, or usage data for machine learning;
- Whether customer data may be used for service improvement or product development;
- Opt-out or consent requirements;
- De-identification, aggregation, or anonymization standards;
- Restrictions on using confidential or personal data for AI training;
- Ownership of data, model inputs, outputs, or derivatives; or
- Retention, deletion, or human-review practices relating to AI systems.
Potential Risks
The deletion of approximately 435 words could create material risk if it removed provisions addressing:
- Data-use permissions: The customer may have broader or less clearly limited rights regarding use of its data.
- AI-training restrictions: A prohibition or opt-out right may have been deleted, potentially allowing customer data to be used for model training.
- Confidentiality and privacy: Deleted safeguards could permit broader internal or third-party access to customer information.
- Ownership and license scope: Deleted limitations could expand the provider’s license to use customer content or derived data.
- Security and deletion obligations: Removed commitments could weaken protections concerning retention, deletion, or security controls.
- Liability and indemnity: Deleted remedies or responsibility provisions could leave the customer with less protection if data is misused.
Required for Definitive Analysis
Please provide the actual 435 deleted words, or a redline showing the surrounding provisions. Without the deleted text, it is not possible to determine whether the changes affect AI training or to identify specific new legal risks.
2026-08-21 · Candidate Privacy Policy
Key Changes and Risks
1. Expanded purposes for using candidate data
The revised policy replaces a relatively narrow description of using information to provide recruitment services and evaluate candidates with a substantially broader list of purposes, including:
- Processing applications and assessing eligibility;
- Reference and background checks;
- Contacting candidates about future opportunities, events, and newsletters;
- Assisting with immigration matters;
- Aggregate and anonymous analysis for business planning, hiring trends, internal reporting, and legitimate business interests;
- Compliance with laws, legal processes, and government requests.
Risk: The “legitimate business interests” and aggregate-analysis purposes are broad and may permit additional internal uses beyond evaluating the current application. The policy does not clearly define how information will be anonymized or aggregated.
2. No express AI-model training authorization
The diff does not expressly state that Candidate Information, resumes, interview materials, or other submitted data may be used to train, fine-tune, test, or improve artificial-intelligence or machine-learning models.
However:
- The new language allowing aggregate, anonymous analysis and internal reporting could potentially support analytics or AI-related development if data is genuinely anonymized.
- The policy does not address whether AI tools may be used in recruiting, whether candidate data may be input into third-party AI systems, or whether automated screening or decision-making will occur.
- The new right to request information about automated decisions that legally or significantly affect a candidate suggests that automated decision-making may be contemplated, but it does not confirm that such systems are used or explain their operation.
Recommended clarification: Add an explicit statement confirming whether Candidate Information is or is not used for AI training, and address human review, automated screening, third-party AI providers, retention of prompts/outputs, and opt-out or objection rights.
3. Broader sharing and disclosure rights
The policy continues to permit sharing with affiliates, subsidiaries, and third-party recruitment providers, but the wording is broadened to include disclosures where Celtra considers them “appropriate or useful.” It also expressly covers mergers, acquisitions, reorganizations, asset sales, bankruptcy, and insolvency.
Risk: Candidate data may be transferred to a wider range of entities and potentially sold, transferred, or shared in a corporate transaction. The policy gives limited detail about international transfers or safeguards.
4. Longer and more flexible retention
The prior specific retention period of up to two years for future opportunities is replaced with retention for as long as needed to provide services or for a legitimate business purpose, subject to legal and technical requirements.
Risk: This removes a clear maximum period and may permit longer retention. Deleted data may still include limited PII, anonymous information, and data needed for legal, dispute, enforcement, or security purposes.
5. Expanded privacy rights
The revision adds or clarifies rights to:
- Access, correction, and deletion;
- Opt out of marketing;
- Obtain information about automated decisions;
- Withdraw consent;
- Object to processing;
- Submit complaints.
These rights are limited by applicable law, identity verification, reasonable-response periods, and permitted refusal grounds.
6. Security language is less reassuring
The former security section’s specific safeguards is replaced with general “reasonable technical and organizational security measures,” alongside expanded disclaimers that security and public availability cannot be guaranteed.
Risk: The policy provides less concrete assurance regarding access controls and third-party security.
2026-08-21 · Privacy Policy
2026-08-20 · Privacy Policy
2026-08-20 · Candidate Privacy Policy
Summary
The diff only states that approximately 435 words were removed from the document. It does not identify which provisions were deleted or provide the original and revised wording.
AI Training and Data Use
- No determination is possible regarding whether the changes affect:
- Use of customer data to train, fine-tune, or improve AI models;
- Whether customer data may be used for product development or analytics;
- Restrictions on using customer prompts, inputs, outputs, or personal information;
- De-identification, aggregation, or anonymization requirements;
- Opt-out or consent rights;
- Data retention and deletion obligations;
- Human review or vendor access to customer data; or
- Ownership and permitted use of AI-generated outputs.
- If the removed text previously restricted AI training or required customer consent, its deletion could materially expand the provider’s rights to use customer data. Conversely, the deleted text may have been permissive or otherwise unrelated.
Other Potential Legal Risks
Because the deleted language is not provided, it is also impossible to assess whether the changes affect:
- Confidentiality obligations;
- Data protection and privacy compliance;
- Security commitments and breach notification;
- Intellectual-property ownership or licenses;
- Liability caps, indemnities, or exclusions;
- Service levels and termination rights;
- Data return or deletion upon termination; or
- Subprocessors and third-party disclosures.
Overall Assessment
The change is not legally assessable from the information provided. A statement that 435 words were removed is insufficient to determine the effect of the amendment. The deleted text, together with the surrounding provisions or a clean revised version, is needed for a reliable analysis—particularly to determine whether customer data may now be used to train or improve AI models.
2026-08-19 · Candidate Privacy Policy
Summary
The provided diff does not include the actual amended contractual language. It only states:
> “Added approximately 435 words to the document”
Accordingly, it is not possible to identify:
- Changes to the parties’ rights or obligations;
- New liability, indemnity, confidentiality, or termination risks;
- Changes to data ownership, licensing, or permitted uses;
- Whether customer data may be used to train, fine-tune, evaluate, or improve AI models;
- Whether such use is subject to consent, opt-out rights, anonymization, retention limits, or security restrictions; or
- Whether the provider may share customer data with affiliates, subcontractors, or third-party AI providers.
Please provide the full redlined text, including the additions shown in {}, deletions shown in [], and replacements shown in []{}. Once provided, the changes can be analyzed for their legal effect and any AI-training provisions can be separately identified.
2026-08-18 · Privacy Policy
2026-08-18 · Candidate Privacy Policy
Summary
Nature of the Change
- The diff states that approximately 435 words were removed from the document.
- No replacement language or surviving text is provided.
- Because the deleted language is not shown, the specific legal effect of the change cannot be determined from this diff alone.
AI Training and Customer Data
- The diff does not identify whether any language concerning the use of customer data to train, fine-tune, evaluate, or improve AI models was removed.
- However, if the deleted 435 words included provisions addressing:
- use of customer content or personal data for AI training;
- provider rights to retain or create derivative data;
- human review or model-quality monitoring;
- opt-out or consent mechanisms;
- restrictions on using confidential information; or
- deletion, anonymization, or segregation of customer data,
then the deletion could materially change the customer’s privacy, confidentiality, intellectual-property, and regulatory risk.
Potential Legal Risks
Depending on what was removed, the deletion may:
- Expand the provider’s practical rights by eliminating restrictions on data use or retention.
- Remove customer protections, such as confidentiality obligations, purpose limitations, security requirements, or deletion commitments.
- Eliminate an AI-training prohibition or opt-out, potentially allowing customer data to be used for model development.
- Create ambiguity about whether customer inputs, outputs, metadata, or usage data may be used to train models.
- Remove remedies or audit rights relating to unauthorized data use.
- Affect compliance with privacy and data-protection laws, contractual confidentiality obligations, or sector-specific requirements.
Recommended Follow-Up
The deleted 435 words should be obtained and compared with the current version before approval. In particular, confirm whether the final agreement expressly states:
1. Whether customer data may be used to train or improve AI models.
2. Whether such use requires consent or an opt-out.
3. Whether confidential information and personal data are excluded.
4. How long data is retained and when it is deleted.
5. Whether the provider may use de-identified or aggregated data.
6. What security, confidentiality, and breach obligations apply.
Bottom line: The supplied diff is insufficient to determine whether AI-training rights changed, but the deletion may have removed important customer-data protections.
2026-08-18 · Candidate Privacy Policy
Summary of Important Changes
1. Expanded purposes for using candidate data
Celtra’s permitted uses are substantially expanded. Candidate Information may now be used to:
- Provide recruitment services and manage the application relationship;
- Verify information and conduct reference/background checks;
- Assess eligibility and process applications;
- Contact candidates about jobs, events, newsletters, and immigration/work-permit assistance;
- Conduct aggregate and anonymous analysis for business planning, hiring trends, internal reporting, and legitimate business interests;
- Comply with laws, regulations, legal processes, and enforceable governmental requests.
Risk: The purposes are broader and less limited to evaluating a candidate for a specific role. “Legitimate business interests” and “appropriate or useful” sharing are flexible standards that may permit secondary uses not clearly anticipated by candidates.
2. Expanded sharing and disclosure
Celtra may share Information with:
- Affiliates and subsidiaries worldwide;
- Third-party recruitment service providers;
- Service providers acting on Celtra’s behalf;
- Parties involved in mergers, acquisitions, reorganizations, asset sales, bankruptcy, or insolvency;
- Authorities where legally required.
The prior language more clearly limited service providers to processing Information solely for Celtra. The revised language retains that limitation but also adds broader sharing where Celtra considers it “appropriate or useful.”
Risk: More recipients and corporate-transaction disclosures increase confidentiality, international-transfer, and downstream-processing risks.
3. AI-model training
The revised policy does not expressly state that Candidate Information, resumes, interview materials, or other submissions will be used to train artificial-intelligence or machine-learning models. It also does not expressly prohibit such use.
However, the broad permissions for:
- Aggregate/anonymous analysis;
- Legitimate business interests;
- Service-provider processing; and
- Automated decision-related disclosures
could create ambiguity if recruitment vendors or internal systems use candidate data in AI development, testing, profiling, or model improvement.
Key concern: Candidates do not receive a clear statement about whether their data is used to train AI models, whether de-identification is required, whether vendors may retain inputs, or whether candidates can opt out. This should be clarified expressly.
4. New automated-decision rights
Candidates may request information about automated decisions using their PII that have legal or similarly significant effects. The policy also adds rights to withdraw consent and object to processing.
Risk: These rights suggest Celtra may use automated decision-making, but the policy does not explain whether AI screening or ranking is actually used, what human review exists, or how candidates can challenge a decision.
5. Retention and deletion
The fixed two-year retention period is removed and replaced with retention for as long as needed for recruitment or a legitimate business purpose, subject to legal and technical requirements. Candidates receive broader correction and deletion rights, although Celtra may retain limited PII, legally required information, dispute-related data, and anonymous information.
Risk: The new retention standard is less definite and may permit longer retention than two years.
2024-08-26 · Privacy Policy
The publisher records this document as revised on this date (“Last updated: August 26, 2024”).
Between 2020-08-05 and 2021-10-09 · Candidate Privacy Policy
Summary
Scope of the Changes
The diff indicates that approximately 435 words were added to the document. However, the actual added language is not provided, so the legal and commercial impact cannot be assessed reliably.
Customer Data and AI Training
- The diff does not include the text of the additions.
- It is therefore impossible to determine whether the document now:
- Permits the provider to use customer data to train, fine-tune, validate, or improve AI models;
- Allows use of customer prompts, inputs, outputs, usage data, or metadata for those purposes;
- Applies different rules to personal data, confidential information, or de-identified data;
- Makes AI training use automatic, optional, or subject to customer consent or opt-out;
- Allows data to be shared with affiliates, subcontractors, or third-party AI providers;
- Requires deletion, retention limits, security controls, or restrictions on re-identification; or
- Gives the customer ownership or control over models trained using customer data.
Potential Legal Risks Requiring Review
Depending on the missing language, the additions could materially change:
- Confidentiality: Customer information may no longer be restricted solely to providing the services.
- Privacy and data protection: Broader processing may create compliance issues under applicable privacy laws and contractual data-processing obligations.
- Intellectual property: The provider may claim rights to use customer data, derived data, or model improvements.
- Security and disclosure: Data could potentially be transferred to affiliates, vendors, or model providers.
- Data retention and deletion: Training-related copies may be retained beyond ordinary service periods.
- Customer control: The customer may lose the ability to prevent use of its data for model development.
- Liability and indemnity: Existing protections may not cover unauthorized disclosure, model leakage, or misuse of customer data.
Required Information
To perform a meaningful review, please provide the actual 435 words added, together with any surrounding provisions that they modify. Particular attention should be given to terms such as “customer data,” “content,” “inputs,” “outputs,” “usage data,” “improve,” “train,” “fine-tune,” “de-identify,” “aggregate,” “service providers,” and “retain.”
Between 2015-04-18 and 2018-06-06 · Privacy Policy