VentaHR

Privacy Policy

Effective Date: May 3, 2026

1. Introduction and Scope

VentaHR, Inc. ("VentaHR," "we," "us," or "our") operates a multi-tenant applicant tracking system (ATS) and workforce management platform (the "Platform") that staffing agencies, recruiters, candidates, and facilities use to manage the full employment lifecycle — from job posting and application through onboarding, compliance tracking, VMS integration, and placement.

This Privacy Policy describes how VentaHR collects, uses, stores, discloses, and protects personal data across all roles on the Platform. It applies to:

  • Agency administrators and staff who subscribe to and manage the Platform
  • Candidates who apply for jobs, submit documents, and undergo onboarding
  • Facility users (clients/MSPs) who access submitted candidates and compliance data
  • Recruiters and supervisors using the recruiter and supervisor portals
  • Visitors to VentaHR marketing pages and public job boards

VentaHR acts as a data processor with respect to personal data submitted by agency clients and their candidates. The subscribing agency is the data controller for candidate data entered into their tenant. VentaHR is the data controller for its own business operations data (billing, account management, marketing).

2. Categories of Personal Data We Collect

Given the nature of ATS and staffing compliance operations, the Platform is designed to collect and process substantial amounts of personal information. The categories below reflect actual data types processed by the Platform.

2.1 Candidate Data

The following candidate data is collected through application flows, onboarding tasks, candidate portals, and bulk resume imports:

  • Identity & Contact: Full name, address, email, phone, date of birth, Social Security Number (SSN) — used for I-9, background checks, and payroll onboarding
  • Employment & Education History: Work history, job titles, employers, dates of employment, references, and educational credentials
  • Credentials & Licenses: Professional licenses, certifications, expiration dates, and credential documentation
  • Documents: Uploaded resumes, identification documents, compliance documents, onboarding forms, and e-signature envelopes
  • I-9 and Work Authorization: I-9 form data including employment eligibility information and supporting document details
  • Background Check Data: Background check requests and results processed through integrated background check providers
  • Skills and Assessments: Skills test submissions and results
  • Communication History: SMS messages, email logs, recruiter notes, and candidate activity events
  • Compliance Status: Compliance pack snapshots, compliance overrides, and compliance rollup data
  • Match and Placement Records: Job matches, assignments, offers, placements, shifts, and timesheet data

2.2 Agency and Staff Data

  • Account credentials, names, email addresses, and role assignments for agency staff and recruiters
  • Agency billing information and subscription details
  • Configuration data including branding settings, email templates, automation rules, and API keys
  • Audit logs including configuration change logs, invite logs, and user access markers

2.3 Facility (Client) Data

  • Facility names, addresses, and contact details
  • Facility user accounts, login credentials, and role assignments
  • Facility compliance profiles, overrides, and compliance publishing events
  • Facility group structures and compliance pack assignments

2.4 VMS Integration Data

  • VMS job submissions, external mappings, sync records, and integration event logs
  • Integration credentials and connection tokens for external VMS platforms (e.g., Bullhorn, Beeline, SAP Fieldglass, Shiftboard, StafferLink)

2.5 Usage and Technical Data

  • IP addresses, browser/device type, session identifiers, and access timestamps
  • Platform usage logs, automation logs, email delivery logs, and SMS logs
  • API keys, API usage records, and developer portal access data

3. Legal Basis for Processing

VentaHR processes personal data on the following legal bases:

3.1 Contract Performance

Processing is necessary to perform the SaaS subscription agreement with subscribing agencies and to facilitate employment placement services for candidates.

3.2 Legitimate Interests

VentaHR processes certain data based on legitimate interests, including platform security, fraud prevention, compliance monitoring, and product improvement, where such interests are not overridden by individual rights.

3.3 Legal Obligations

Certain data processing is required by applicable law, including employment verification (I-9), equal employment opportunity recordkeeping, tax reporting obligations, and background check requirements under applicable state and federal law.

3.4 Consent

Where required by law (e.g., for certain SMS communications, marketing, or non-essential cookies), VentaHR or the subscribing agency obtains consent from individuals before processing. Candidates may be asked to consent to specific processing activities through the candidate portal.

4. How We Use Personal Data

TalentBridge uses the data described above for the following purposes:

  • Providing Platform Services: Operating the ATS, compliance management, onboarding workflows, e-signature flows, VMS integrations, and job distribution features
  • Candidate Onboarding and Compliance: Processing I-9 records, background check requests, credential verification, and compliance pack tracking
  • Recruiter Workflows: Matching candidates to jobs, generating outreach messages, managing recruiter assignment queues, and tracking candidate relationship health
  • Communication: Sending SMS and email notifications, onboarding reminders, compliance alerts, and candidate follow-up messages
  • VMS Synchronization: Syncing job orders, candidate submissions, and placement data with connected VMS systems
  • Billing and Account Management: Processing subscription payments, managing agency accounts, and generating billing records
  • Security and Audit: Monitoring for unauthorized access, maintaining audit logs, and conducting tenant isolation audits
  • Analytics and Reporting: Generating agency metrics, recruiter performance reports, compliance reports, and financial metrics for agency administrators
  • Product Improvement: Analyzing aggregated, de-identified usage patterns to improve Platform features and reliability

5. Multi-Tenant Data Isolation

VentaHR is a multi-tenant platform. Each subscribing agency operates within a logically isolated tenant. VentaHR maintains technical and organizational controls to ensure that:

  • Candidate, job, placement, and compliance data belonging to one agency tenant is not accessible to other agency tenants
  • Facility users can only access data for candidates and jobs within their designated agency-facility relationship
  • API keys and integration credentials are scoped to individual agency tenants
  • Audit logs are maintained at the tenant level and are accessible to agency administrators

VentaHR conducts periodic tenant isolation audits to verify that isolation controls remain effective. If a tenant isolation breach is identified, VentaHR will notify affected agencies in accordance with its Incident Response Policy.

6. How We Share Personal Data

6.1 Within the Platform Ecosystem

Candidate data may be shared with facility users (clients/MSPs) to whom the subscribing agency submits a candidate for a job order. Such sharing occurs at the direction of and under the control of the subscribing agency. TalentBridge does not independently share candidate data with facilities without agency instruction.

6.2 VMS and Integration Partners

When an agency activates a VMS integration, candidate and job data may be transmitted to the connected VMS platform. The agency is responsible for ensuring that VMS data sharing complies with applicable privacy obligations. TalentBridge maintains a current list of approved sub-processors on the Security Sub-processors page.

6.3 Service Providers (Sub-Processors)

TalentBridge engages third-party sub-processors to support the Platform, including cloud infrastructure providers, email and SMS delivery services, background check providers, e-signature vendors, and payment processors. All sub-processors are bound by data processing agreements consistent with applicable law.

6.4 Legal Requirements

VentaHR may disclose personal data when required by law, court order, regulatory mandate, or to protect the rights, property, or safety of VentaHR, its clients, candidates, or the public.

6.5 Business Transfers

In the event of a merger, acquisition, or sale of substantially all of VentaHR's assets, personal data may be transferred to the successor entity, subject to continued compliance with this Privacy Policy.

6.6 No Sale of Personal Data

VentaHR does not sell, rent, or trade personal data to third parties for marketing or advertising purposes. This applies to candidate data, agency staff data, and facility user data.

7. Sensitive Personal Data

The Platform is designed to process categories of data that are legally classified as sensitive in many jurisdictions. These include:

  • Social Security Numbers and government-issued identification numbers (I-9 processing, background checks)
  • Financial account information (collected during payroll onboarding, if applicable)
  • Background check results, which may include criminal history information
  • Professional license and credential information, including medical and healthcare credentials
  • Immigration and work authorization status (I-9 records)

VentaHR applies enhanced access controls, encryption, and audit logging to sensitive data fields. Agencies are responsible for collecting appropriate consent and providing required notices to candidates before collecting sensitive data through the Platform.

8. Data Retention

VentaHR retains personal data for as long as necessary to fulfill the purposes for which it was collected, to comply with legal obligations, and as instructed by the subscribing agency.

Default retention guidelines are as follows:

  • Active candidate records: Retained for the duration of the agency subscription plus 3 years, unless the agency requests earlier deletion
  • I-9 records: Retained in compliance with federal requirements (3 years from hire date or 1 year after termination, whichever is later)
  • Background check data: Retained for a maximum of 7 years unless shorter retention is required by applicable law
  • Email and SMS communication logs: Retained for 2 years
  • Audit and access logs: Retained for 3 years
  • Billing records: Retained for 7 years

Agencies may configure custom retention periods within the Platform settings. Upon termination of an agency subscription, TalentBridge will retain agency data for 90 days to support data export requests, after which data will be deleted or anonymized unless longer retention is required by law.

9. Individual Rights

Depending on the jurisdiction in which you are located, you may have the following rights with respect to your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete personal data
  • Deletion: Request deletion of your personal data, subject to legal retention requirements
  • Portability: Request a machine-readable copy of personal data you have provided
  • Restriction: Request that we restrict processing of your personal data in certain circumstances
  • Objection: Object to processing based on legitimate interests
  • Opt-Out of Sale/Sharing (CCPA/CPRA): California residents have the right to opt out of the sale or sharing of personal information; VentaHR does not sell or share personal information as defined under CCPA/CPRA

Candidates wishing to exercise these rights should contact the agency through which they applied, as the agency is the data controller for candidate data. Agencies may submit data subject requests on behalf of candidates through the Platform or by contacting privacy@ventahr.com.

TalentBridge will respond to verified requests within 30 days (or 45 days where permitted by law with notice).

10. Security

VentaHR maintains a comprehensive information security program designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. Security measures include:

  • Encryption of data in transit (TLS 1.2+) and at rest
  • Role-based access controls (RBAC) enforced at the tenant level
  • Multi-factor authentication support for agency and facility user accounts
  • API key management with scoped permissions
  • Automated audit logging of configuration changes, user access events, and data exports
  • Periodic security hardening reviews
  • Incident response procedures

Agencies are responsible for configuring appropriate access controls within their tenant, managing user provisioning, and ensuring that their staff use the Platform securely.

11. International Data Transfers

VentaHR is based in the United States. If you are accessing the Platform from outside the United States, your data will be transferred to and processed in the United States. For agencies serving EU or UK-based candidates, VentaHR can provide Standard Contractual Clauses (SCCs) or other appropriate transfer mechanisms upon request.

12. Cookies and Tracking Technologies

VentaHR uses cookies and similar technologies on the Platform and marketing pages for session management, authentication, security, and analytics. We do not use third-party advertising cookies. For information on managing cookies, please refer to your browser settings. A detailed cookie notice is available on the Platform's marketing pages.

13. Children's Privacy

The Platform is not directed to individuals under the age of 16. VentaHR does not knowingly collect personal data from children under 16. If we become aware that personal data of a minor has been submitted to the Platform, we will take steps to delete it promptly.

14. Additional Rights for California Residents (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). VentaHR does not sell or share personal information as defined under CCPA/CPRA. California residents may request:

  • The categories and specific pieces of personal information collected
  • The categories of sources from which personal information is collected
  • The business or commercial purpose for collecting personal information
  • The categories of third parties with whom personal information is shared
  • Deletion of personal information (subject to exceptions)
  • Correction of inaccurate personal information

To submit a California privacy request, contact privacy@ventahr.com. We will not discriminate against you for exercising your CCPA/CPRA rights.

15. Changes to This Policy

VentaHR may update this Privacy Policy from time to time. When we make material changes, we will notify subscribing agencies via email and/or in-platform notification at least 30 days before the changes take effect. Continued use of the Platform after the effective date constitutes acceptance of the updated policy.

16. Contact Information

For privacy-related inquiries, to exercise your rights, or to report a privacy concern, please contact:

VentaHR Privacy Team

Email: privacy@ventahr.com

Website: app.ventahr.com

Agencies subject to GDPR may designate VentaHR as their data processor by executing a Data Processing Agreement (DPA). Please contact privacy@ventahr.com to request a DPA.