Privacy policy
A description of the data we collect across the ramp-up journey, why we collect it, how it is protected and how it is deleted. Written to be readable, not to hide behind boilerplate.
What Clorrior is, at a glance
Clorrior is a workplace platform used by employers to coordinate interviews, run onboarding, identify skill gaps during ramp-up and recommend training. This policy describes how personal data flows through that journey and how we protect it.
The three data subject types
Our product touches three categories of person, each with different expectations. This policy respects those differences instead of collapsing them into one.
- Candidates - people going through interview loops that our customers coordinate through Clorrior.
- New hires and employees - people whose ramp-up is being tracked, whose skill gaps and training assignments are recorded.
- Workplace users - HR staff, hiring managers and administrators who use Clorrior to do their job.
What we collect - and why
- Scheduling data - availability, calendar events, panel composition. Collected to coordinate interview loops without email chase.
- Onboarding task state - completion status of role-specific onboarding checklists. Collected to prevent day-one gaps and stale tasks.
- Skill-gap signals - task performance, review feedback and self-assessment responses tied to a specific hire. Collected to surface gaps as they appear rather than months later.
- Training assignment and outcome - the specific module recommended, whether it was completed, and whether the subsequent real work shows the gap is closed.
- Account and audit data - login records, changes to sensitive fields, integration configuration.
We do not collect keystrokes, screen recordings, browser activity, biometrics, physical location or any similar surveillance signal. Ramp-up here means outcomes and specific gaps, not activity streams.
How the data is used
Personal data is used to deliver the ramp-up journey - scheduling, onboarding automation, skill-gap identification, matched training and productivity tracking. It is not used to train shared cross-customer models unless a customer opts in explicitly in writing.
Aggregate data (curves, ramp-velocity roll-ups, historical baselines) is computed at the customer level and stays scoped to that customer.
Sharing and third parties
We share personal data only with the third parties needed to operate the service - infrastructure, email delivery, calendar and ATS integrations selected by our customers. All processors are bound by data-processing terms that mirror the commitments in this policy.
We do not sell personal data. We do not share it with advertising networks. The product is paid for by our customers, not by monetising the people whose data flows through it.
Retention
Retention is scoped to the reason data was collected. Interview loop data is retained for the loop plus a customer-configured window. Ramp-up data is retained for the 90-day ramp window and the customer's HR record policy. Aggregate metrics remain as long as the customer relationship is active.
Deletion requests from data subjects are respected inside the constraints of the customer's own retention policy - customers are the controller for their own hire records.
Security
All traffic is served over TLS. Data at rest is encrypted at the storage layer. Access to production data is restricted to a small operations rota and logged. Integrations use the narrowest scopes we can operate with.
A more detailed security description lives on our security page.
Your rights
You may request access to, correction of, or deletion of personal data we hold about you, subject to the customer's own record policy for hire and employee data. Contact us through the Contact page.
Contact
Privacy questions can be routed through our Contact page. Enterprise customers can reach the assigned onboarding partner directly.