Personal information deserves more than compliant storage.
This is not legal fine print or a list of certifications. It is the standard Job Collar intends to be held to: remember deeply so people repeat less, disclose honestly, protect access and make leaving straightforward.
The person belongs to themselves. The relationship has a history. The data has provenance. The customer retains the freedom to leave.
Four commitments.
No long-term lock-in. Job Collar operates on a 28-day/monthly cycle. Subject to the agreed notice and account terms, a customer can leave and export the data that belongs to their business.
The agency can take its permitted company data and history. Separately, a person's continuous career and relationship context is designed to remain intelligible as they move between employers and roles — always subject to permissions and source controls. Where privacy, confidentiality or a third-party licence prevents something moving, we identify what was excluded and why.
Each recruiter has their own permissioned Job Collar, reducing shared-data ambiguity and unnecessary administration while preserving agency controls, consent, access rules and auditability. Connections to other systems are designed to be revocable and permission-limited — the standard we are building toward, not a finished architecture.
Job Collar may preserve an agency's commercial and relationship history without pretending the people described by that history are owned by the software or the agency.
Connected, not captive.
This statement of intent sits beside, and does not replace, the detailed privacy policy, subscription terms and security documentation.
The privacy veil.
The privacy veil keeps personal and excluded information outside Job Collar's intelligence layer. Only authorised, relevant relationship signals are used, according to the recruiter's permissions and the agency's controls.
Personal enough to understand your desk. Permissioned enough to know where the boundary is.
Nothing personal is connected automatically. With the individual recruiter's authorisation — and only where the agency has enabled it — Job Collar can draw permitted relationship signals from LinkedIn and professional contacts, phone contacts, and Outlook or Gmail contacts, email and calendar context.
Administrators decide which connectors are available, to whom, and under what access rules. Availability differs by workspace: JobAdder remains the current live system-of-record integration, while personal contact, email and calendar sources are configured by the agency and connected where authorised.
Each connection is limited by the scopes that provider grants and the recruiter approves. Accessible fields depend on workspace configuration, provider permissions and user consent — so what a connection can see is not uniform across sources.
We favour contacts, metadata and relevant relationship context — who you know, who you have spoken to, and when. Private message content is not ingested by default.
The privacy veil keeps personal and excluded information outside Job Collar's intelligence layer. Where a recruiter or agency marks something excluded, it is not used to produce suggestions. Job Collar does not decide unilaterally what counts as private — the recruiter's permissions and the agency's controls do.
A connection can be disconnected by the individual, and access can be withdrawn by the agency or at the provider. Exact revocation behaviour depends on the connector and the provider's own controls.
Where a signal is used, the intent is that its source and reason travel with it, so a suggestion can be explained rather than merely trusted. Depth of audit detail is implementation-dependent and varies by connector.
Some of the behaviour described here is implementation-dependent and differs by connector, provider and workspace configuration. We would rather say that plainly than imply a uniform guarantee.
In practice.
Operational data is available only inside authenticated workspaces. The public site cannot access customer records.
We keep the amount of personal information sent to third-party services to what's needed for the feature to work.
Suggested drafts and next steps are always reviewable and editable by a human before anything is sent.
We work with approved, controlled connections and respect the terms of the systems we sit alongside.
Shared responsibility.
Security is a joint effort. Job Collar provides sensible defaults, safe patterns and clear controls. Customer administrators manage who has access, keep integrations current, and configure the product to their own policies.
Operational features live inside your authenticated workspace.
Detailed information.
For a detailed walk-through — including current portability tooling, data flows and hosting arrangements — please get in touch. We share this material with prospective customers on request.