Document ID: PC-PRIV-001 Document Owner: PreCognise — Privacy Officer Version: 1.0 Effective Date: June 1, 2026 Review Date: December 1, 2026 (Pilot Review), annually thereafter Classification: Public
1. Introduction
PreCognise ("PreCognise," "we," "us," or "our") is committed to protecting the privacy and personal information of all individuals who use our platform. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with the PreCognise platform, a verification-first employability infrastructure that enables candidates to build portable, verified professional identities and connects them with institutions and employers.
This is designated as the Pilot Privacy Policy and governs all activity during the pilot implementation with educational institutions and employers. As part of our pilot governance process, we have scheduled a formal review by December 1, 2026 to incorporate partner feedback, privacy officer recommendations, and operational learnings.
This policy applies to all users of the PreCognise platform, including:
- Candidates: students, graduates, job seekers, and professionals
- Institutions: postsecondary colleges, universities, and training providers
- Employers and Recruiters: organizations accessing the PreCognise talent pool
- Visitors: individuals browsing our website or accessing public-facing content
PreCognise is incorporated in Canada and operates in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. For users in the United Kingdom, we apply the standards of the UK GDPR respectively. Where local legislation imposes stricter requirements than PIPEDA, the stricter standard applies.
PreCognise is currently operating selected platform features within a pilot and validation phase with participating educational institutions, employers, workforce development organizations, and individual users. During this period, PreCognise may refine platform functionality, verification workflows, AI-enabled features, data governance processes, and operational procedures based on participant feedback, partner requirements, regulatory guidance, and product development needs.
This Privacy Policy reflects PreCognise's current privacy practices and commitments and applies to all users participating in pilot activities and ongoing platform operations. The policy will be formally reviewed within six (6) months of its effective date, or sooner if material changes to the platform, applicable legislation, or data processing activities occur.
Any material changes to this Privacy Policy will be communicated to users in accordance with Section 12, "Changes to This Policy."
2. Definitions
| Term | Definition | |---|---| | Personal Information | Any information about an identifiable individual, excluding business contact information used solely for business communication | | Sensitive Personal Information | Personal information warranting heightened protection, including biometric data, background check results, psychometric assessments, immigration status, and health-related data | | Verified Credential | A credential validated through PreCognise's verification process or an authorized third-party verification partner | | Portable Professional Identity | A candidate's verified, reusable profile containing structured credentials and career data | | Processing | Any operation performed on personal information, including collection, storage, use, disclosure, or deletion | | Third-Party Partner | A service provider engaged by PreCognise to perform specific platform functions such as background checks or credential verification | | Anonymized Data | Information that has been processed so that an individual can no longer be identified, directly or indirectly, using reasonable means. Anonymized data is not intended to be re-identified and may be used for statistical analysis, platform improvement, and reporting purposes. | | Pseudonymized Data | Personal information that has been modified to replace direct identifiers with codes, tokens, or other substitutes, but which may still be linked to an individual through additional information maintained separately and subject to appropriate safeguards. |
3. Information We Collect
3.1 Information Provided Directly by Candidates
- Identity Information: Full name, email address, phone number, profile photograph
- Professional Information: Work history, job titles, employer names, dates of employment, references
- Educational Information: Institution names, programs, degrees, graduation dates, academic records
- Skills and Competencies: Self-declared skills, certifications, project experience, work-integrated learning records
- Career Preferences: Job preferences, target roles, geographic preferences, availability
- Video and Multimedia: Video pitch recordings, text-based elevated pitches
- Psychometric and Self-Assessment Data: Responses to optional psychometric, behavioural, personality, and self-reflection assessments completed voluntarily by candidates to support personal career development, self-awareness, and profile enhancement
- Biographical Information: Professional summary, career narrative, personal statement
3.2 Verification Data
When candidates initiate credential verification, we collect and process:
- Education Verification: Academic transcripts and institutional confirmation data processed in partnership with authorized education verification providers
- Employment Verification: Reference contact information and employment confirmation data
- Background Check Data: Criminal record check results, credit history (where applicable and consented), and global watchlist screening results, processed by licensed third-party background check providers
- Identity Verification: Government-issued identification data used solely to confirm identity during verification; not retained beyond the verification process unless required by law
- Verification activities, including identity verification, credential verification, criminal record checks, and credit checks, are optional services that require candidate participation and consent before processing occurs.
3.3 Information Related to Institutions
Participating educational institutions may promote PreCognise to students, graduates, alumni, and other learners through communications, events, career services, or other outreach activities.
In the standard onboarding process, individuals register directly with PreCognise and voluntarily provide their personal information and profile content. PreCognise does not require participating institutions to provide student records, enrollment data, academic records, or other personal information to enable account creation.
Where a candidate chooses to verify educational credentials, academic information may be obtained directly from the candidate and/or through authorized verification processes initiated with the candidate's consent.
3.4 Information Provided by Employers and Recruiters
- Organization name, contact information, and billing details
- Job posting content and hiring requirements
- Search queries and candidate shortlisting activity
- Hiring outcome confirmations (where provided)
3.5 Automatically Collected Information
- Usage Data: Pages visited, features used, session duration, search queries conducted on the platform
- Device and Technical Data: IP address, browser type, operating system, device identifiers
- Authentication Data: Login events, session tokens managed through our authentication infrastructure
- AI Interaction Logs: Anonymized records of AI Career Coach interactions used for platform improvement
3.6 Information from Third Parties
- Professional Network Integration: With candidate consent, professional history imported from connected professional network accounts
- Verification Partners: Confirmation results returned from authorized verification providers
- Ecosystem Partners: Work-integrated learning records and skills assessment data from authorized integration partners, where integration is active and consent has been provided
4. How We Use Personal Information
PreCognise uses personal information only for the purposes for which it was collected, or for purposes that a reasonable person would consider appropriate given the circumstances.
4.1 Core Platform Functions
| Purpose | Legal Basis (PIPEDA) | Legal Basis (GDPR) | |---|---|---| | Creating and maintaining candidate profiles | Consent | Consent | | Performing credential verification | Consent | Consent | | Generating AI-powered job match recommendations | Consent / Legitimate Interest | Consent | | Enabling employer and recruiter access to verified profiles | Consent | Consent | | Providing AI Career Coach and Human Career Coach services | Consent | Consent | | Operating psychometric and behavioural assessments | Consent | Consent | | Tracking employment outcomes for institutional reporting | Consent / Contract | Legitimate Interest |
4.1.1 AI-Assisted Recommendations and Decision Support
PreCognise uses artificial intelligence (AI) technologies to support services such as job matching, career recommendations, profile enhancement suggestions, resume generation, skills identification, and career coaching assistance.
AI-generated outputs are intended to provide recommendations, insights, and decision-support information only. PreCognise does not use AI systems as the sole basis for making employment, hiring, admission, credentialing, or other significant decisions affecting individuals.
Employers, recruiters, educational institutions, and candidates remain responsible for independently evaluating information and making their own decisions. Where AI-assisted recommendations are provided, human judgment and review remain an essential part of the decision-making process.
Users may contact PreCognise to request additional information about the use of AI-enabled features or to exercise applicable rights related to automated processing under relevant privacy legislation.
4.2 Platform Operations and Improvement
- Monitoring platform performance, security, and reliability
- Detecting and preventing fraud, abuse, and unauthorized access
- Improving matching algorithm accuracy using aggregated, anonymized data
- Conducting internal analytics on platform usage patterns
4.3 Communications
- Sending transactional notifications (account activity, verification status, job matches)
- Delivering platform updates and service announcements
- With explicit consent: sending marketing communications and career development content
5. Candidate Control and Data Sharing
5.1 User-Controlled Sharing
Candidates retain ownership and control of the personal information, profile content, and verified credentials they provide through the PreCognise platform. Candidates control which elements of their profile are visible and to which parties.
Candidates may share their verified profile with a specific employer, recruiter, or other authorized party without making it broadly searchable. Verified credentials, once issued, belong to the candidate and are intended to support a portable professional identity that can be reused throughout their educational and career journey.
Candidates may modify profile visibility settings, share information, or revoke sharing permissions at any time through their account settings, subject to any legal or regulatory retention requirements.
5.1.1 Psychometric and Self-Assessment Information
Participation in psychometric, behavioural, personality, and self-assessment activities is entirely optional. These assessments are intended to support candidate self-reflection, career exploration, and personal development.
Assessment responses and results are collected only with the candidate's participation and consent. In Canada, psychometric and personality assessment results are not shared with employers, recruiters, or educational institutions as part of candidate profiles, matching activities, or hiring processes unless the candidate expressly chooses to share such information where functionality permits.
PreCognise does not use psychometric or personality assessment results as the sole basis for employment recommendations, candidate ranking, or other significant decisions affecting individuals.
5.2 Employer and Recruiter Access
Employers and recruiters access candidate profiles only where: the candidate's profile is set to discoverable, or the candidate has explicitly shared it; the employer holds an active, authorized account; and access is logged and auditable. Employers do not receive raw verification source data — they receive verified status indicators and structured profile data only.
5.3 Institutional Access
Institutions may access aggregate outcome data for their cohort, not individual profile detail beyond what was shared by the candidate. Individual candidate status data is accessible only where the candidate has consented to institutional visibility.
6. Disclosure to Third Parties
PreCognise does not sell personal information. We disclose personal information only in the following circumstances.
6.1 Authorized Service Providers
| Provider Category | Purpose | Data Shared | |---|---|---| | Background check providers | Criminal record, credit, and identity verification | Name, identity data, consent confirmation | | Education credential verification providers | Academic credential validation | Name, institution, program details | | Cloud infrastructure providers | Platform hosting, database, and file storage | All platform data within encrypted infrastructure | | AI model providers | AI Career Coach, semantic matching, resume generation | Anonymized or pseudonymized prompt data | | Authentication and identity management provider | User authentication, session management | Email, authentication tokens | | Payment processing provider | Subscription and verification billing | Billing information only |
6.2 Legal and Regulatory Requirements
We may disclose personal information where required by law, court order, or regulatory authority, or where necessary to protect the safety of individuals or the security of the platform.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, personal information may be transferred to a successor entity subject to equivalent privacy protections. Affected users will be notified in advance.
7. Data Retention
PreCognise retains personal information only for as long as necessary for the purpose for which it was collected, in accordance with the GDPR storage limitation principle (Article 5(1)(e)) and PIPEDA. Retention periods are documented and reviewed annually.
| Data Category | Retention Period | Basis | |---|---|---| | Active candidate profile | Account life; dormant account review at 24 months of inactivity | Legitimate interest (service continuity); user notified before deletion | | Deleted or closed account data | Purged within 30 days of account closure | Right to erasure; GDPR Article 17 | | Verification records | 6 years (UK) / 7 years (Canada) | Limitation Act 1980 (UK); CRA and provincial limitation periods (Canada) | | Background check results — full details | 6 months from verification date or hiring decision | ICO guidance; UK GDPR Article 10 (criminal offence data) | | Background check — confirmation record only | Account life; deleted within 30 days of account closure | Legitimate interest (platform integrity) | | Employment outcome data (identifiable) | 18 months from outcome date | Institutional reporting cycle; anonymized thereafter | | Employment outcome data (aggregated) | 5 years | Statistical purpose; outside GDPR scope once anonymized | | AI interaction logs (anonymized) | 2 years | Platform improvement; anonymized data used for analytical and service improvement purposes | | Billing records | 7 years | Statutory financial records requirement (HMRC / CRA) | | Access audit logs | 3 years | Compliance and regulatory readiness |
8. Your Privacy Rights
8.1 Rights Under PIPEDA (Canadian Users)
- Right of Access: Request a copy of the personal information we hold about you
- Right to Correction: Request correction of inaccurate or incomplete information
- Right to Withdraw Consent: Withdraw consent for non-essential processing at any time
- Right to Complain: File a complaint with the Office of the Privacy Commissioner of Canada
8.2 Additional Rights Under GDPR (UK and EU Users)
- Right to Erasure ("Right to Be Forgotten"): Request deletion of your personal data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Restriction: Request that processing be restricted pending review or dispute
- Right to Object: Object to processing based on legitimate interests
- Rights Related to Automated Decision-Making: Request human review of significant automated decisions
To exercise any of these rights, contact: info@precognise.co
9. Security
PreCognise implements a privacy-by-design security architecture, including:
- Encryption in transit: All data encrypted using industry-standard TLS protocols
- Encryption at rest: All stored personal data encrypted within our cloud infrastructure
- Role-Based Access Control (RBAC): Access restricted to authorized personnel on a need-to-know basis
- Authentication controls: Multi-factor authentication available for all account types
- Vulnerability management: Security scanning integrated into the development workflow
- Audit logging: Access to personal data by platform administrators is logged and reviewable
In the event of a data breach posing a real risk of significant harm, PreCognise will notify affected individuals and the applicable regulatory authority within required timeframes (72 hours under GDPR; as soon as feasible under PIPEDA).
10. Children and Minors
The PreCognise platform is intended for users who are 16 years of age or older. We do not knowingly collect personal information from individuals under 16 without verifiable parental or guardian consent.
11. Data Residency and International Data Transfers
PreCognise's infrastructure is hosted in Canada, and personal information collected through the platform is stored and processed in Canada.
As of the effective date of this Privacy Policy, PreCognise does not transfer candidate personal information outside Canada for storage or processing as part of its standard operations.
Should PreCognise engage service providers that process personal information outside Canada in the future, affected users will be notified and appropriate contractual, technical, and organizational safeguards will be implemented in accordance with applicable privacy legislation.
12. Changes to This Policy
When material changes are made, we will notify users by email or prominent in-platform notice at least 14 days before the changes take effect.
13. Contact Us
Privacy Officer, PreCognise Inc. Email: info@precognise.co 35 Charles St W, Suite 716 Toronto, Ontario, M4Y 1R6
Regulatory bodies:
- Canada: Office of the Privacy Commissioner of Canada — www.priv.gc.ca
- UK: Information Commissioner's Office — ico.org.uk
Version History
| Version | Date | Summary of Changes | |---|---|---| | 1.0 | June 2026 | Initial release |