Privacy

Privacy notice

Last updated June 8, 2026

This is the public-facing notice. If your organization has signed a data processing agreement (DPA) or a business associate agreement (BAA) with us, that agreement controls in case of conflict.

Who we are

Astris HR is a workforce intelligence platform operated by Astris HR, Inc. We help refugee resettlement organizations, workforce development boards, and employers hire across language and credential gaps — and we follow up with hired workers at 30, 90, 180, and 365 days.

When you upload a resume, complete a candidate profile, post a job, or use any feature of Astris HR, you're interacting with systems we own and operate. This notice explains what data goes in, what we do with it, and the choices you have.

What we collect

From candidates

  • Identifiers: name, preferred name, email, phone, mailing address.
  • Employment history, education, skills, certifications, languages.
  • Work authorization status (e.g. asylee, refugee, permanent resident, US citizen) and country of origin — only where the candidate or their caseworker enters it.
  • Transportation status, schedule constraints, language proficiency, support needs (childcare, transit), and other inputs that affect matching.
  • Resume files (PDF, DOCX, image) and any documents uploaded by the candidate's caseworker.
  • Consent records — what you agreed to, when, in what language, and which version of the disclosure was shown.

From organization and employer users

  • Account details: name, email, role, organization affiliation, Microsoft Entra ID identifier (when SSO is used).
  • Job descriptions, hiring decisions, pipeline movements, employer ratings of candidates.
  • Feedback you submit on parses, matches, or translations.

Collected automatically

  • Server logs: IP address, user agent, request paths, timestamps.
  • Audit trail: which user performed which action on which record (immutable, enforced by a database trigger).
  • First-party analytics on aggregated usage. We do not use third-party advertising trackers.

From third parties

  • Employer quality signals (e.g. Glassdoor, Indeed) used to compute an Employer.qualityScore. Only public aggregate signals — never anything tied to an individual reviewer.

How we use it

  • Matching: we score every candidate against every relevant open job using a 7-component scorer plus pgvector embedding similarity plus a retention forecast. The score and rationale are visible to the candidate, their caseworker, and (when the employer engages with the match) the employer.
  • Parsing: we send resume and JD text — and, for scanned documents, the PDF image — to a large language model (currently Anthropic Claude) to extract structured fields. The model returns structured data; we store it in your account.
  • Embeddings: we send short summaries of candidates and jobs to an embedding service (currently Azure OpenAI text-embedding-3-large) to generate 1536-dim vectors that power semantic search.
  • Follow-up: after a placement, we send multilingual SMS and email at 30, 90, 180, and 365 days. The candidate can stop these at any time by replying STOP or via the link in the message.
  • Product improvement: when you rate a parse or translation, we use your rating and any correction you provide as a few-shot example to improve the next parse for similar inputs. Original parsed values are never used to retrain a base model.
  • Security and compliance: audit logs, anomaly detection, abuse prevention, legal obligations.

Special handling for candidate data

The people Astris HR serves are often refugees, immigrants, and others in vulnerable situations. We take three positions that go beyond standard SaaS practice:

  • Self-validation before matching. A candidate's profile is not eligible for matching until the candidate (or the candidate's caseworker on their behalf) has reviewed and approved what Astris HR parsed about them. The candidate sees this review in their preferred language.
  • We do not sell or rent candidate data, period. Not aggregate, not anonymized, not as "research data." Subprocessors are listed below and are bound by contract.
  • Work authorization and country of origin are sensitive. We store these only when the candidate or their caseworker enters them, only show them to authorized users in their tenant, and never use them as ad-targeting attributes.

Subprocessors

We use a small set of vendors to operate the service. Each is listed below with what they process. Where applicable, we have executed a BAA or DPA. We notify customers in advance of any material change to this list.

Microsoft AzurePostgreSQL, Blob Storage, Container Apps, Communication Services (SMS/email), Entra ID (SSO). US (East US 2).
AnthropicResume + JD text and (for scanned PDFs) PDF images for parsing and explanations. US.
Azure OpenAI (Microsoft)Embedding text for candidate and job vectors. US.
GitHub (Microsoft)Source code hosting and CI.

Where data lives

Production data is stored in Microsoft Azure's East US 2 region. Backups are encrypted and held in the same geographic region. We do not transfer personal data outside the United States in the ordinary course of operating the service.

How long we keep it

  • Candidate profiles: as long as the candidate's case is active with your organization, plus the retention period your organization has set (defaults: 7 years after case closure, configurable per tenant).
  • Job records and placements: as long as the employer's account is active, plus 7 years.
  • Audit logs: 7 years, immutable.
  • Follow-up communication content: 24 months.
  • Server logs: 30 days at the application tier; aggregated longer for security forensics.

You can request earlier deletion in the cases described in "Your rights" below.

Your rights

If you are a candidate whose data is in Astris HR — or a user of the platform on behalf of one — you can:

  • See what we have about you (export as JSON or PDF).
  • Correct anything that's wrong.
  • Withdraw consent to be matched. Existing matches are not retracted; future matching stops.
  • Ask us to delete your record. We will, unless we have a legal obligation to retain it (e.g. an active grant audit trail at a workforce board).
  • Opt out of follow-up SMS or email at any time. Reply STOP to any SMS; use the unsubscribe link in any email.

To exercise any of these, email privacy@astrishr.com. We respond within 30 days. If you can't reach us through your caseworker or the platform itself, you can also contact your state's data protection authority.

Automated decisions

Astris HR scores candidate-job fit and predicts retention. These scores are advisory: a human (a caseworker or hiring manager) makes every actual decision about referral, interview, or hire. You can request the rationale for any score we generated — the breakdown is built into the platform UI for every match.

Children

Astris HR is not intended for use by individuals under 16, and we do not knowingly collect personal data from children. If you believe a minor's data is in Astris HR, contact us at the email above and we will delete it.

Security

Encryption in transit (TLS 1.3) and at rest (Azure-managed TDE), Microsoft Entra ID for SSO with MFA for administrative roles, per-request tenant scoping in the application layer, and immutable audit logs enforced by a database trigger. See our security posture page for the longer technical detail.

Changes to this notice

If we make material changes, we'll update the "last updated" date at the top of this page and, for changes that affect how we use candidate data, send a notice to the org admins on each account.

Contact

Privacy questions: privacy@astrishr.com. Security reports: security@astrishr.com. General contact: /contact.