Trust and security

How we handle the data you share.

Refery handles CVs, contact details, and hiring plans. This page states what we do with them, which vendors hold them, and how to make a request about your own data. It describes our current practice, not a certification.

Refery has not completed a SOC 2 or ISO 27001 audit. If your procurement process requires one, tell us what you need and by when, and we will tell you honestly whether we can meet it.

Practices

What we do today

Access control

Every internal account requires multi-factor authentication. Access to candidate data follows least privilege and is reviewed when someone joins or leaves. Platform data is protected by row-level security so an account only reaches the records it owns.

Encryption

Data is encrypted in transit with TLS and at rest by our infrastructure providers. Secrets and API keys are stored in the deployment platform, never in the codebase.

Data location

The Refery platform and its database run in the United States (AWS us-east-1 via Supabase). Candidates and clients in the EEA and the UK should read the international transfers section of our Privacy Policy before sharing personal data.

Retention

Candidate information is kept while a search or relationship is active and removed on request, subject to legal exceptions. Details are in the Privacy Policy.

Consent

Candidate profiles are shared with a hiring company only after the candidate agrees. Sharing preferences and companies to exclude are recorded before anything is sent.

Change management

Site and platform changes ship through version control and automated checks. Public pages carry automated tests for accuracy of commercial terms.

Vendors

Who else holds this data

These are the services we use that can hold personal data. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

Vendors, purpose, and the data they may hold
VendorPurposeData
Supabase (AWS us-east-1)Platform database and authenticationCandidate and client records
VercelWebsite and platform hostingRequest logs
Google WorkspaceEmail and documentsCorrespondence, CVs sent by email
SlackInternal coordination and client channelsSearch discussion
Vercel AnalyticsAggregate page-view countsNo cookies and no cross-site identifier

Your data

Making a request

Email hello@refery.io and say what you want: a copy of your data, a correction, deletion, or an objection to processing. We treat the same address as the opt-out route under the CCPA and CPRA.

We will confirm receipt and respond within the period the applicable law allows, and we may need to verify your identity first. Candidates can also ask us to stop sharing their profile at any time, including mid-process.

Full detail is in the Privacy Policy, and the commercial terms are in the Terms of Service.

What we ask of you

  • Do not send confidential employer documents.
  • Do not send someone else’s personal information without their agreement.
  • Tell us before you share sensitive details if you are exploring quietly.
  • Send CVs through the candidate form rather than by attachment where you can.

Updated . This page describes practice and is not legal advice or a contractual commitment; the signed agreement governs each engagement.