In minutes, not weeks.

Privacy Policy

Last updated: May 2026

At Upstack.AI, we are committed to protecting your privacy and the security of personal data processed through the Upstack.AI platform, including WorkLab (our AI-powered Applicant Tracking System) and LearnLab (our AI-powered Learning Management System), together with all related websites, APIs, and integrations (collectively, the "Services"). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the choices and rights available to you. It should be read together with our Terms and Conditions.

1. Who We Are & Our Role

The Services are operated by Upstack AI FZ-LLC, a company registered in the Ras Al Khaimah Economic Zone, United Arab Emirates ("Upstack.AI", "we", "us", "our"). Depending on the situation, we act in different roles under data protection law:

  • Controller — for personal data of our direct customers, prospects, and website visitors (e.g., admin and recruiter accounts, billing contacts, marketing recipients).
  • Processor — for personal data that our customers (organizations) submit, generate, or collect through the Services about their candidates and learners (e.g., CVs, interview transcripts, identity verification artifacts, course progress, quiz submissions). In this case, the customer is the controller and we process the data only on their documented instructions, in line with our Terms and Data Processing Addendum.

If you are a candidate or learner, please contact the organization that invited you for questions about their use of your data. We will support that organization in responding to your request.

2. Information We Collect

Information you provide directly:

  • Account information (name, email address, phone number, company details, role, password)
  • Profile and professional credentials, branding assets, reference documents
  • Job postings, course content, assessments, quizzes, and other content you create
  • Candidate and learner content you upload or invite (e.g., CVs, contact details)
  • Communication preferences, support inquiries, feedback
  • Payment and billing information (processed securely via Stripe — we do not store full card numbers)

Information from candidates and learners using the Services:

  • Identification details: name, email, phone number, optional LinkedIn URL
  • CVs and uploaded documents
  • Assessment responses (multiple choice, open-ended, true/false)
  • AI chatbot interview transcripts and scoring
  • Voice interview audio and transcripts (Beta feature, when used) — used to generate text transcripts and to score the interview
  • Identity verification artifacts — government-issued ID image and a selfie photo, where this step is enabled, used solely to verify the candidate's identity
  • Assessment session data, including timing and integrity signals (see Section 5)
  • Course progress, quiz submissions, grades, and learner analytics

Information collected automatically:

  • Device information, browser type and version, operating system
  • IP address and approximate (city/country level) location
  • Log data, request timestamps, error reports
  • Usage and interaction data within the platform (pages viewed, features used)
  • Cookies and similar technologies (see Section 12)

3. How We Use Information

  • To provide, operate, secure, and improve the WorkLab and LearnLab Services
  • To generate AI-assisted outputs you request (job descriptions, interview plans, course content, quizzes, interactive activities, scoring, analytics insights)
  • To authenticate users and protect accounts
  • To process transactions, manage subscriptions, send invoices, and prevent payment fraud
  • To communicate service notices, security alerts, incident notifications, and Terms updates
  • To provide customer support and respond to inquiries
  • To run product analytics, debug issues, and improve performance
  • To comply with legal, regulatory, accounting, and tax obligations
  • With your consent, to send marketing communications you can opt out of at any time

We do not sell personal data, and we do not use customer content (including candidate or learner data) to train our AI models. We may use aggregated, de-identified data to monitor and improve service quality.

4. Voice Data & Biometric Information

When candidates use the voice interview feature or identity verification step, the Services process data that may be considered biometric or sensitive in some jurisdictions:

  • Voice recordings and transcripts are used solely to transcribe and score the interview as part of the assessment the candidate has consented to. They are stored within the candidate's session record and are not used for voiceprint identification.
  • Identity verification (ID image + selfie) is used only to confirm that the person taking the assessment matches the identity provided. The match is performed via our identity verification sub-processor; we and the customer organization can review the result and the captured images for assessment integrity purposes.
  • These features are opt-in at the candidate level, presented with clear notice before capture, and may be disabled by the customer organization.
  • Where applicable law requires explicit consent for biometric processing (including under the GDPR, EU AI Act, UAE PDPL, US state laws such as Illinois BIPA, or similar frameworks), the customer organization is responsible for obtaining that consent. We provide the technical mechanism to capture consent.
  • Biometric and voice artifacts are retained for the period set by the customer or, by default, for the assessment retention period set out in Section 8, and then deleted.

5. AI Processing & Integrity Monitoring

  • Our AI systems generate content (job descriptions, interview plans, course indexes, documents, quizzes, interactive activities) and assist with scoring, grading, and analytics insights.
  • AI outputs are produced probabilistically and are intended to assist, not replace, human decision-making. Customers must review AI outputs before any consequential decision (hiring, rejection, grading, certification).
  • AI integrity monitoring may analyze assessment session signals (such as timing, copy/paste activity, focus changes, and patterns indicative of unauthorized assistance) to flag possible academic or assessment misconduct. Flags are provided as signals for human review only — they do not automatically reject a candidate or learner.
  • Candidates and learners have the right to be informed when AI is being used to assess them and may request human review of AI-assisted decisions where applicable law (including the EU AI Act) requires it. Such requests should be directed to the customer organization that issued the assessment.
  • We do not use customer content to train foundation models, and our AI sub-processors are bound by terms that prevent them from doing so on our behalf.

6. Sign-In with Google, Microsoft & LinkedIn

The Services support sign-in via Google, Microsoft, and LinkedIn for administrators, recruiters, instructors, candidates, and learners. When you sign in with one of these providers, we receive only the data the provider returns under the scopes you authorize.

Google Sign-In — scopes requested:

  • openid — authenticates your identity
  • email — your email address, used to identify your account
  • profile — your name and profile picture, used to personalize the experience

Google Calendar (optional) — additional scopes:

  • https://www.googleapis.com/auth/calendar.events — create, edit, and delete calendar events to schedule interviews and create Google Meet links
  • https://www.googleapis.com/auth/calendar.calendarlist.readonly — view your list of calendars for scheduling purposes

Microsoft Sign-In — data received: your name, email, and a unique identifier from Microsoft Entra ID (formerly Azure AD), used solely to authenticate and identify your account. We do not access your mailbox, OneDrive, Teams, or calendar unless you separately enable a specific integration.

LinkedIn Sign-In — data received: your name, email, and (where you authorize it) public profile information, used solely to authenticate and pre-fill your candidate or user profile. We do not post on your behalf or read your connections.

How we use sign-in provider data:

  • Solely to authenticate, create or link your account, and provide the features you explicitly enabled (e.g., calendar scheduling)
  • We do not use sign-in provider data for advertising
  • We do not sell, rent, or share sign-in provider data with third parties except as needed to provide the feature you authorized
  • Authentication tokens are stored securely; integration tokens are stored only while the integration is active
  • You can revoke access at any time from your Integrations settings, or directly from your Google, Microsoft, or LinkedIn account permissions pages

7. Sharing & Sub-Processors

We share personal data only as needed to operate the Services and only with parties who are bound by appropriate confidentiality and data protection obligations:

  • Customer organizations — if you are a candidate or learner, your assessment results, course progress, and related data are shared with the organization that invited you. This is the core purpose of the Services.
  • Sub-processors — we use carefully selected providers to deliver specific functions, including:
    • Hosting & infrastructure (cloud providers in the EU and other regions)
    • AI model providers (for content generation, transcription, and scoring assistance)
    • Identity verification provider (for the ID + selfie check)
    • Email and SMS delivery providers
    • Payment processor (Stripe)
    • Analytics and product telemetry providers
    • Authentication providers (Google, Microsoft, LinkedIn)
    A current list of named sub-processors is available on request from [email protected].
  • Legal & safety — we may disclose data when required by law, court order, or binding request from a competent authority, or where reasonably necessary to protect the rights, safety, or security of users or the public.
  • Corporate transactions — in the event of a merger, acquisition, or sale of assets, personal data may be transferred to the successor, subject to this Privacy Policy.

We do not sell personal data and do not share it for cross-context behavioral advertising.

8. Data Retention

  • Customer account data is retained for as long as the account is active.
  • Candidate and learner data is retained for the period configured by the customer organization, or by default for up to 3 years from the last interaction, after which it is deleted or de-identified.
  • On account termination, we retain customer data for up to 90 days to allow for export and recovery, then securely delete it (subject to legal-hold or anti-fraud requirements).
  • Voice and identity verification artifacts are deleted in line with the retention period above, or earlier where the customer disables the feature.
  • Backups are rotated on a defined schedule and personal data is removed from backups in the ordinary course as backups age out.
  • We may retain limited data for longer where required by law (e.g., billing records for tax purposes) or to defend legal claims.

9. International Data Transfers

  • Upstack.AI is based in the United Arab Emirates and processes data in the UAE, the European Union, and other regions where our infrastructure and sub-processors operate.
  • For transfers from the EEA, UK, or Switzerland to countries that are not subject to an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum where applicable), supplemented by appropriate technical and organizational measures.
  • For transfers from the UAE, we comply with the cross-border transfer requirements of the UAE Personal Data Protection Law (PDPL).
  • Copies of the relevant transfer mechanisms are available on request from [email protected].

10. Your Rights

Depending on where you live and your relationship to Upstack.AI, you may have rights under the GDPR (EU/EEA), UK GDPR, UAE PDPL, the California Consumer Privacy Act (CCPA/CPRA), and other privacy laws.

GDPR / UK GDPR / UAE PDPL:

  • Right of access — request a copy of your personal data
  • Right to rectification — request correction of inaccurate data
  • Right to erasure — request deletion of your personal data
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing based on legitimate interests, including direct marketing
  • Right to withdraw consent at any time where processing is based on consent
  • Right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, including a right to request human review of AI-assisted decisions where applicable under the EU AI Act
  • Right to lodge a complaint with your local supervisory authority

CCPA / CPRA (California residents):

  • Right to know the categories and specific pieces of personal information collected
  • Right to delete personal information
  • Right to correct inaccurate personal information
  • Right to opt out of "sale" or "sharing" of personal information (we do not sell or share personal information for cross-context behavioral advertising)
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising your privacy rights

To exercise these rights, contact us at [email protected]. If you are a candidate or learner, please contact the organization that invited you first; we will assist them in responding. We will respond within the timelines required by applicable law (typically 30 days under GDPR/UAE PDPL, 45 days under CCPA), and will verify your identity before disclosing personal data.

11. Security

  • Industry-standard encryption for data in transit (TLS) and at rest
  • Role-based access controls and least-privilege access for employees and contractors
  • Regular security assessments, vulnerability testing, and patching
  • Logging, monitoring, and alerting for suspicious activity
  • Employee training on data protection, confidentiality, and incident response
  • Documented incident response procedures

If we become aware of a personal data breach affecting your data, we will notify the affected customer (controller) without undue delay, and in any event within the timelines required by applicable law (under GDPR, controllers must in turn notify their supervisory authority within 72 hours where required). Where we are the controller, we will notify affected data subjects directly when required.

For more details, visit our Security & Compliance page.

12. Cookies & Similar Technologies

We use cookies and similar technologies to operate the Services and improve your experience. We use the following categories:

  • Strictly necessary — required for login, session management, security, and core functionality. These cannot be disabled.
  • Functional — remember your preferences (e.g., theme, language, RTL/LTR direction).
  • Analytics — help us understand how the Services are used and how to improve them. Set only with your consent where required by law.
  • Performance & error tracking — help us detect bugs and degraded performance.

We do not use cookies for cross-site advertising. You can manage cookie preferences through the cookie banner where shown, and through your browser settings. Disabling strictly necessary cookies will prevent the Services from functioning correctly.

13. Children

Administrator, recruiter, and instructor accounts are intended for users aged 18 and over. The Services may be used by candidates or learners under 18 only where the customer organization that invited them has appropriate parental or guardian consent and authority to process their data, in line with applicable law (including the GDPR's age of digital consent and equivalent rules). We do not knowingly collect personal data from children outside this controlled context; if we discover that we have, we will delete it promptly. Customer organizations are responsible for ensuring lawful basis and consent for any minors they invite.

14. EU AI Act

When used for recruitment and candidate evaluation (WorkLab) or for education, training, and assessment of learning outcomes (LearnLab) — both of which fall under Annex III of the EU AI Act — our AI features are designed and documented to align with the Act's requirements: transparency, fairness, human oversight, data governance, accuracy, and security. This reflects alignment by design and is not a certification or conformity mark. Our AI assists, and does not replace, human decision-making. Candidates and learners are informed when AI is used to assess them. Where the EU AI Act applies, customer organizations using our Services for employment-related decisions, education, or training act as the deployer and must ensure those decisions are reviewed by qualified humans before they are made. We maintain documentation of our AI systems, conduct risk assessments, and run bias and fairness reviews of our models. See also Sections 5 and 10.

15. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Services at least 14 days before they take effect, unless a shorter period is required for legal, regulatory, or security reasons. The "Last updated" date at the top reflects the most recent revision.

16. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:

Upstack AI FZ-LLC
FOAM2471, Compass Building
Al Shohada Road, AL Hamra Industrial Zone-FZ
Ras Al Khaimah, United Arab Emirates

Our Compliance & Security Standards

GDPR
CCPA
EU AI Act Aligned
Regional Hosting
AES-256
TLS 1.3

Hosted on AWS infrastructure with SOC 2 Type II & ISO 27001 certified data centers — with data residency available across EU, Middle East, and other regions

Across WorkLab and LearnLab, our AI assists — it does not replace — human hiring, grading, and academic decisions. The "EU AI Act Aligned" badge reflects alignment with the Act's principles by design — transparency, human oversight, and documentation — not a certification. Learn more.

Upstack.AIUpstack.AI

Filter the noise. Interview real candidates. One link works anywhere—no ATS migration needed.

Upstack AI FZ-LLC
FOAM2471, Compass Building
Al Shohada Road, AL Hamra Industrial Zone-FZ
Ras Al Khaimah, United Arab Emirates

Microsoft Store
Publisher: UPSTACK AI
Store ID: 9NT2GR4TDZ0G

© 2022 - 2025 Upstack.AI • All Rights Reserved

Powered By

React
TypeScript
Tailwind
Python
AWS
SSL

Last updated: 21/1/2026