1. Scope and our data-protection roles
This policy applies to VRS LLC, Amman, Hashemite Kingdom of Jordan, trading as VRSJO and providing VRS Recruit and related recruitment, HR, knowledge-base, and AI-enabled services (collectively, the Services).
Our role depends on the relationship and the purpose of the processing:
- VRS as controller. We decide why and how data is processed for our website, business inquiries, security, accounts, billing, our own recruitment and talent network, and agency recruitment where we determine the recruitment purpose.
- A customer as controller; VRS as processor. A customer or hiring organization normally controls candidate and workforce data in its VRS Recruit workspace. We process that data on its documented instructions. Questions about a particular application should usually be directed to that organization first.
- Independent or joint roles. Where VRS sources candidates, maintains a reusable talent network, or jointly determines a recruitment campaign, VRS and the hiring organization may each have controller duties. We will identify the relevant controller in the application or campaign notice where required.
Contact: Email hamzah@vrsjo.com or write to VRS LLC, Amman, Jordan. This mailbox is our privacy contact; it is not presented as a named Data Protection Officer until VRS formally appoints and registers the required individual.
2. Personal data we process
| Category | Examples |
|---|---|
| Identity and contact | Name, email, phone, location, current role or company, professional profile links, and account identifiers. |
| CV and application | CV or résumé, employment, education, skills, languages, portfolio or video links, screening answers, cover text, desired role, source or referral, and consent record. |
| Recruitment decisions | Pipeline stage, recruiter notes, shortlists, interview feedback, assessments, scores, rankings, pass/fail results, offers, placements, and reasons recorded by authorized users. |
| Assessment integrity | Tab or window visibility, fullscreen changes, focus changes, clipboard and right-click events. VRS does not use webcam or microphone proctoring for these checks. |
| Meetings and communications | Email, SMS, WhatsApp and call content or metadata; meeting attendance; recordings, transcripts, summaries, action items, files and attachments. |
| Connected services | Data you or your organization chooses to connect from services such as Google email, calendar, Drive or Sheets, scheduling tools, communications tools, or other customer-enabled integrations. |
| Account, security and device | Login events, session and passkey metadata, IP address, user agent, approximate country, authentication and MFA events, audit records, diagnostic and error data. |
| Commercial and support | Company, billing contact and address, tax ID, plan, seats, invoices, usage, support messages, requested services, hiring volume and urgency. We do not ask for or store payment-card numbers in VRS Recruit. |
Free-text fields and uploaded documents can contain information we did not request. Please avoid providing health, biometric, religious, political, criminal-record, national-identity, financial, or other sensitive information unless the relevant controller has clearly requested it and has a lawful basis.
3. Where data comes from and what is optional
We receive personal data:
- directly from you through forms, applications, interviews, meetings, messages, account settings, and support;
- from a VRS customer, hiring organization, recruiter, referrer, agency partner, or authorized workspace user;
- from professional sources you made public or allowed another party to share, such as a professional profile or portfolio;
- from customer-enabled email, calendar, storage, communications, and workflow integrations; and
- automatically from browsers, devices, security systems, and service logs.
Fields marked required are needed to provide the requested service or consider an application. Other fields are voluntary. If you decline required data or a required consent, we may be unable to process the request or application. You can withdraw consent going forward by contacting the controller identified in the relevant form or notice.
4. Why we process data and our legal bases
We process data only for stated, specific purposes. The legal basis varies by country. In Jordan, we rely on explicit, documented, purpose- and duration-specific prior consent unless processing is permitted without consent by applicable law. Where the GDPR applies, we may rely on consent, a contract, a legal obligation, protection of vital interests, or legitimate interests that are not overridden by your rights.
| Purpose | Typical legal basis |
|---|---|
| Respond to inquiries, provide requested services, manage accounts, and perform customer agreements. | Consent; steps requested before a contract; performance of a contract; applicable statutory permission. |
| Receive applications, source candidates, assess suitability, communicate, schedule, interview, select and place candidates. | Explicit consent or statutory permission in Jordan; consent, contract-related steps, legal obligations, or legitimate recruitment interests where GDPR permits. |
| Parse CVs, score or rank applications, grade assessments, summarize interviews, detect integrity events, and run customer-configured workflow automation. | The relevant recruitment basis plus the specific profiling notice and safeguards described below. |
| Provide connected email, calendar, storage, communications, signing and workflow features. | Your or the customer’s instruction and consent; contract performance. |
| Secure the Services, prevent abuse, authenticate users, diagnose failures, keep audit records, and defend legal claims. | Legal obligation, statutory permission, contract, and legitimate security or legal interests where available. |
| Invoice customers, maintain tax and commercial records, and manage subscriptions. | Contract and legal obligations. |
| Measure website performance and, only after consent where required, product usage. | Necessary operation and security; consent for non-essential analytics. |
We do not sell personal data or use candidate data for third-party advertising. We do not use Google user data for advertising, and our use of Google API data is limited to the user-facing features you or your organization authorize.
5. AI, profiling and automated workflow actions
VRS Recruit uses automated rules and AI-enabled services in recruitment. Depending on the features a hiring organization enables, the system may:
- extract and structure information from a CV or application;
- compare a candidate with job criteria and generate a score, rank, explanation or recommendation;
- grade free-text assessment answers and produce pass/fail or confidence results;
- summarize interviews, meetings and communications;
- record assessment-integrity events; and
- trigger a configured workflow action, including moving, shortlisting, hiding, advancing or rejecting an application.
Relevant application content—including a candidate’s name, CV-derived employment, education, skills, languages and location—may be sent to the AI provider configured for that feature. AI output can be incomplete, inaccurate or biased. The customer or hiring organization selects the criteria and automation, controls the hiring purpose, and is responsible for lawful configuration, meaningful human oversight, and the final employment decision.
Request review. If an automated score or action may have materially affected you, contact the hiring organization identified on the role page to ask for an explanation, correction or human review. You may also email hamzah@vrsjo.com; we will route or assist with the request as appropriate. You may object to unnecessary, excessive, discriminatory, unfair or unlawful profiling under applicable law.
7. International processing and transfers
VRS is based in Jordan. The primary application and database environment is hosted in Germany, while Cloudflare and feature providers may process data through global networks or in other countries listed in our DPA. Those countries may have different privacy laws.
Before transferring data outside Jordan, the relevant controller must assess the recipient’s protection and satisfy Articles 14 and 15 of Jordan’s Personal Data Protection Law. For transfers subject to the GDPR, we use an adequacy decision where available or an appropriate Article 46 safeguard, normally the European Commission’s 2021 Standard Contractual Clauses, together with transfer assessments and supplementary measures where required. See Section 12 of our DPA.
8. How long we keep data
We retain personal data only for as long as needed to provide the Services, follow customer instructions, maintain security and business records, resolve disputes, and meet legal obligations. A legal hold, active dispute, fraud investigation or statutory duty may extend a period. Some records are anonymized rather than deleted.
| Record type | Normal period or criterion |
|---|---|
| Website and business inquiries | Until the request is resolved and while reasonably needed for follow-up, relationship management, disputes or legal obligations. You may ask us to close and delete an inquiry. |
| VRS-controlled candidate profiles and talent-network records | Normally up to 1,095 days (three years) after the last update, unless you withdraw consent, request earlier deletion, agree to continued retention, or law requires otherwise. |
| Customer-controlled candidate and workspace data | The customer’s configured period and documented instructions, subject to platform category defaults and applicable law. |
| Meeting recordings | Normally 90 days; a customer may configure or lawfully request a different period. |
| Meeting transcripts and related assets | Normally one year. Certain summaries may remain with the recruitment record until the customer deletes them or the applicable record period ends. |
| Outreach and recruitment communications | Normally up to two years. |
| Security, audit, commercial and dispute records | Up to seven years where needed for integrity, accountability, tax, contractual or legal purposes. |
| Backups | Rolling backup copies may remain for up to 180 days and are protected from ordinary use until overwritten or deleted. |
Deletion is not instantaneous across active systems, provider systems and backups. We verify the request, apply applicable exceptions, delete or anonymize supported active records, and instruct relevant processors. Residual copies remain protected and are not restored to ordinary use except for disaster recovery or legal necessity.
10. Security measures
We use measures proportionate to the processing risk, including HTTPS, Cloudflare edge and bot protection, private database networking with encrypted connections, provider-managed encryption at rest, restricted secrets management, secure production cookies, account verification and MFA/passkey support, workspace role and object-scope authorization, product-edition boundaries, file-type validation, audit records, error monitoring, and point-in-time recovery and rolling backups.
No system can be guaranteed completely secure. Please protect account credentials, use multi-factor authentication where available, and report suspected misuse to hamzah@vrsjo.com. If a serious breach requires notice, the responsible controller will notify affected people and regulators within the periods required by applicable law.
11. Your choices and rights
Depending on applicable law and our role, you may request:
Access and a copy
Know whether data is processed and receive eligible personal data.
Correction
Correct, complete or update inaccurate information.
Deletion or concealment
Delete or hide eligible data, subject to legal and contractual exceptions.
Restriction or objection
Limit processing or object to unnecessary, excessive, discriminatory, unfair or unlawful processing and profiling.
Portability
Receive or transfer eligible data in a usable format.
Consent withdrawal
Withdraw consent going forward without affecting earlier lawful processing.
Human review
Seek an explanation and human review of a qualifying automated decision.
Complaint
Raise a concern with us and an applicable supervisory authority without retaliation.
Email hamzah@vrsjo.com with your name, relationship to VRS, the relevant hiring organization or workspace, and the request. We may ask for proportionate identity verification. If a customer controls the data, we will send the request to that customer or assist it. We respond within the period required by the law that applies to the request; GDPR requests are normally answered within one month.
12. Children and sensitive information
The Services are designed for business users and working-age candidates, not children. Do not submit data for a person who lacks legal capacity unless an authorized parent, guardian or other lawful representative has provided the required authorization and the relevant controller has established a lawful process.
Customers must not configure screening, scoring or automation to use protected or sensitive characteristics unlawfully. VRS prohibits biometric identification, emotion inference, discriminatory scoring, and the collection of sensitive data without a documented necessity, lawful basis, clear notice and appropriate safeguards.
13. Questions, complaints and regulators
Please contact hamzah@vrsjo.com first so we can investigate and respond. You will not be penalized for making a good-faith privacy complaint.
- In Jordan, you may contact the Personal Data Protection Unit at the Ministry of Digital Economy and Entrepreneurship or use the official portal at pdp.gov.jo.
- In the EEA, you may complain to the supervisory authority where you live or work. The European Data Protection Board lists its members.
14. Policy changes and contact details
We review this policy when our services, providers or legal obligations change. We will post the updated version here with a new effective date and, where required, provide additional notice or request renewed consent. Material changes do not retroactively expand consent.
VRS LLC
Amman, Hashemite Kingdom of Jordan
Privacy, legal and security: hamzah@vrsjo.com