Rounds — Candidate Capture
Privacy Policy
Effective 15 August 2026 · Last updated 15 August 2026
This document is a privacy policy. It is not legal advice, and it is not a substitute for it. It contains bracketed placeholders that must be completed before publication, and it should be reviewed and approved by qualified counsel in each relevant jurisdiction before any person relies upon it.
This Policy governs the Processing of Personal Data carried out in connection with the browser extension published as Rounds — Candidate Capture for Google Chrome and Mozilla Firefox, and the associated Rounds recruitment service with which that extension communicates. It is to be read together with any agreement executed between the Operator and a Subscriber, including any data processing agreement.
1. Definitions and Interpretation
1.1 In this Policy, the following capitalised terms have the meanings given to them below, and cognate expressions are construed accordingly.
- “Account Data”
- means Personal Data relating to a Subscriber User that is created or used for the purpose of establishing and maintaining access to the Extension and the Service, as further described in clause 3.2.
- “Candidate”
- means a natural person whose professional details are Processed by a Subscriber through the Extension or the Service for the purpose of recruitment sourcing.
- “Candidate Data”
- means Personal Data relating to a Candidate that is Processed through the Extension or the Service, including the web address of a public professional profile, name, professional headline, current employer, location, the address of a profile image, a professional summary, any email address entered by a Subscriber User, any notes recorded by a Subscriber User, and any Match Assessment relating to that Candidate.
- “Controller”
- has the meaning given in Article 4(7) of the GDPR, being the natural or legal person which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
- “Diagnostic Data”
- means technical information describing a fault in the operation of the Extension, as further described in clause 3.6.
- “Extension”
- means the browser extension published under the name “Rounds — Candidate Capture”, distributed for Google Chrome under the extension identifier hddlaegjmlgennpoojjjdlhjebbfibom and for Mozilla Firefox under the add-on identifier rounds-extension@rounds.so, in each case including any update to it.
- “GDPR”
- means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, and, where applicable, that Regulation as it forms part of the law of the United Kingdom by virtue of the European Union (Withdrawal) Act 2018 (the “UK GDPR”), together with all national implementing legislation.
- “Local Device Data”
- means the limited information the Extension retains in the storage area allocated to it by the browser on the Subscriber User’s own device, as further described in clause 3.7.
- “Match Assessment”
- means the weighted score and accompanying written reasoning produced by the Service, at the express request of a Subscriber User, comparing a Candidate against a role held in the Subscriber’s Workspace.
- “Operator”, “Rounds”, “we”, “us” or “our”
- means [LEGAL ENTITY NAME], the entity identified in clause 2.1, which publishes the Extension and operates the Service.
- “Personal Data”
- has the meaning given in Article 4(1) of the GDPR, being any information relating to an identified or identifiable natural person, and, for the purposes of section 13, includes “personal information” as defined by the CCPA.
- “Policy”
- means this privacy policy, as amended from time to time in accordance with section 16.
- “Processing”
- has the meaning given in Article 4(2) of the GDPR, and “Process”, “Processes” and “Processed” are construed accordingly.
- “Processor”
- has the meaning given in Article 4(8) of the GDPR, being a person which Processes Personal Data on behalf of a Controller.
- “Service”
- means the Rounds recruitment platform operated by the Operator, comprising the Rounds web application and the service reachable at https://s1.rounds.so with which the Extension communicates.
- “Subscriber”
- means the organisation that holds an account with the Service and whose personnel are authorised to use the Extension.
- “Subscriber User”
- means a natural person authorised by a Subscriber to use the Extension under that Subscriber’s account.
- “Workspace”
- means the area of the Service in which a Subscriber’s records, including Candidate Data, are held and to which that Subscriber’s authorised personnel have access.
1.2 In this Policy, unless the context otherwise requires:
- headings are for convenience only and do not affect interpretation;
- the words “including”, “includes” and “in particular” are to be read as if followed by the words “without limitation”;
- the singular includes the plural and the plural includes the singular;
- a reference to a statute or statutory provision is a reference to it as amended, extended, re-enacted or replaced from time to time; and
- a reference to a clause or section is a reference to a clause or section of this Policy.
1.3 This Policy does not describe the Processing carried out by a Subscriber within its own Workspace beyond what is set out in section 8, nor the Processing carried out by any third party whose website or service a Subscriber User chooses to visit.
2. Identity and Contact Details of the Controller
2.1 The Operator is [LEGAL ENTITY NAME], a company incorporated in [JURISDICTION OF INCORPORATION] under company number [COMPANY REGISTRATION NUMBER], whose registered office is at [REGISTERED ADDRESS], trading as “Rounds”.
2.2 All privacy enquiries, and all requests made under section 9 or section 13, should be addressed to privacy@rounds.so or, in writing, to the registered office identified in clause 2.1, in each case marked for the attention of the privacy contact.
2.3 The Operator’s data protection officer, where one is appointed pursuant to Article 37 of the GDPR, may be contacted at [DATA PROTECTION OFFICER CONTACT — state “not appointed” if no appointment is required].
2.4 The Operator’s representative appointed under Article 27 of the GDPR, where such an appointment is required, is [EU ARTICLE 27 REPRESENTATIVE], and its representative for the purposes of the UK GDPR is [UK ARTICLE 27 REPRESENTATIVE].
2.5 The Operator acts as Controller in respect of Account Data and Diagnostic Data, and as Processor in respect of Candidate Data. The allocation of roles is set out in full in section 8 and qualifies every other provision of this Policy.
3. Categories of Personal Data Processed and Lawful Bases
3.1 The Extension Processes only the categories of Personal Data set out in this section 3. The Extension does not read, record, or transmit the content of the web pages a Subscriber User visits; it performs no operation until the Subscriber User opens it; and it does not compile or retain a record of the pages a Subscriber User has visited.
3.2 Account Data. When a Subscriber User signs in, the Extension Processes that person’s email address, an account identifier issued by the authentication provider, and a limited-life credential that authorises subsequent requests to the Service. Authentication is performed by Firebase Authentication, a sign-in service provided by Google. Where the Subscriber User elects to sign in with a Google account, the browser’s sign-in facility returns an identity statement limited to that person’s sign-in identifier, email address and basic profile details. The Operator does not receive, see, or store the Subscriber User’s password. The lawful bases are Article 6(1)(b) of the GDPR (Processing necessary for the performance of a contract with, or at the request of, the Subscriber User) and Article 6(1)(f) (the legitimate interests of the Operator and the Subscriber in securing accounts and preventing unauthorised access).
3.3 Active Tab Address Data. At the moment the Subscriber User opens the Extension, and only at that moment, the Extension reads the web address of the active browser tab in order to determine whether a public professional profile page is open. Where such a page is open, the Extension transmits that web address to the Service so that the Service may return the record it holds for that address. No other browsing information is read, and no address is transmitted at any other time. The lawful bases are Article 6(1)(b) of the GDPR (Processing necessary to take steps at the request of the Subscriber User) and Article 6(1)(f) (the legitimate interests described in section 4).
3.4 Candidate Data. The Extension displays, and permits the Subscriber User to record, the categories of Candidate Data defined in clause 1.1, namely the web address of the public professional profile, the Candidate’s name, professional headline, current employer, location, the address of a profile image and a professional summary as held by the Service, together with any email address and any notes entered by the Subscriber User. In respect of Candidate Data the Operator acts as Processor and the Subscriber acts as Controller. The Subscriber determines and documents the lawful basis on which Candidate Data is Processed, which will ordinarily be Article 6(1)(f) of the GDPR (legitimate interests in business-to-business recruitment sourcing, as described in section 4) or, where the Subscriber so elects or applicable law so requires, Article 6(1)(a) (consent).
3.5 Match Assessment Data. Where a Subscriber User expressly requests it, the Service produces a Match Assessment comparing a Candidate against one or more roles held in the Subscriber’s Workspace. Match Assessments are Candidate Data, are Processed on the same lawful basis as the underlying Candidate Data, and are subject to section 10.
3.6 Diagnostic Data. In builds of the Extension for which error reporting has been enabled, technical details of a fault are transmitted to Sentry, an error-monitoring service, so that the Operator may identify and correct defects. Diagnostic Data does not include Candidate Data. Where error reporting has not been enabled for a build, no Diagnostic Data is collected or transmitted. The lawful basis is Article 6(1)(f) of the GDPR (the legitimate interests of the Operator and of Subscribers in the security, stability and correct operation of the Extension).
3.7 Local Device Data. The Extension retains on the Subscriber User’s own device, in the storage area allocated to it by the browser, only: (a) the most recently detected public professional profile address and the details the Service returned for it; (b) an indicator that a signed-in session exists; and (c) the state of a check, performed at most once per day, for the availability of a newer version of the Extension. Each new detection overwrites the previous one. This information remains on the device, and is removed when the Subscriber User uninstalls the Extension or clears the browser’s data for it. The lawful bases are Article 6(1)(b) and Article 6(1)(f) of the GDPR.
3.8 Browser permissions. The Extension requests only those browser permissions necessary for the operations described above, namely the ability to read the address of the active tab when it is opened, the use of the browser’s sign-in facility, and the use of the storage area allocated to it. Its permission to communicate over the network is confined to the address of the Service.
3.9 Special categories. The Operator does not seek, and the Extension is not designed to Process, special categories of Personal Data within the meaning of Article 9 of the GDPR or Personal Data relating to criminal convictions and offences within the meaning of Article 10. Subscriber Users must not enter such data into any free-text field, and clause 8.4 applies.
3.10 Where the provision of Account Data is necessary for the performance of a contract, a Subscriber User who declines to provide it cannot be given access to the Extension. There is no statutory obligation to provide any of the data described in this section 3.
4. Legitimate Interests Balancing Statement (Article 6(1)(f))
4.1 This section records the assessment made under Article 6(1)(f) of the GDPR in respect of the Processing identified in clauses 3.2, 3.3, 3.4, 3.6 and 3.7 as resting, wholly or in part, on legitimate interests.
4.2 Purpose test. The interests pursued are: (a) the interest of a Subscriber in identifying and evaluating candidates for roles it is recruiting, being an established and lawful business activity; (b) the interest of the Operator in providing the Extension and the Service to Subscribers; (c) the interest of both in maintaining the security, integrity and correct operation of the Extension; and (d) the interest of Candidates in being considered for professional opportunities relevant to the professional information they have chosen to publish.
4.3 Necessity test. The Processing is limited to what is necessary for those interests. Only the address of the active tab is read, and only when the Extension is opened; no page content is read; the categories of Candidate Data are confined to professional details relevant to the assessment of a Candidate for a role; and no less intrusive means of achieving the same result, such as the manual re-entry of the same professional details, would be materially less intrusive while remaining workable at scale.
4.4 Balancing test. The Processing concerns professional rather than private life, and relates to information the Candidate has elected to make publicly available on a professional network for professional purposes, such that the use of that information for recruitment sourcing is within the reasonable expectations of the Candidate. The Processing is confined to a business-to-business recruitment context. It does not involve advertising, the sale of Personal Data, or any profiling other than the Match Assessments a Subscriber User expressly requests and reviews. Access to Candidate Data is confined to the Subscriber’s Workspace. Special categories of Personal Data are not sought, and the Extension is not directed at children. Having regard to those matters and to the safeguards described in sections 9 and 11, the interests identified in clause 4.2 are not overridden by the interests or fundamental rights and freedoms of the Candidate.
4.5 Outcome and right to object. The Processing may accordingly proceed on the basis of Article 6(1)(f). A Candidate retains the right, under Article 21 of the GDPR, to object at any time on grounds relating to his or her particular situation, and the right to object at any time and without justification to Processing for direct marketing purposes. Objections may be made as described in section 9. The full record of this assessment, and any assessment maintained by a Subscriber, is available on request to the extent it is held by the Operator at [RECORD OF LEGITIMATE INTERESTS ASSESSMENT REFERENCE].
5. Sources of Personal Data and Transparency under Article 14
5.1 Personal Data Processed in connection with the Extension originates from the following sources:
- the Subscriber User, who signs in, opens the Extension, and enters the Candidate’s email address and any notes;
- the browser, which supplies the web address of the active tab at the moment the Extension is opened;
- the Service’s own records for the public professional profile identified by that web address, which records may in turn derive from public professional profiles and other publicly accessible professional sources;
- the authentication provider identified in clause 3.2; and
- where error reporting is enabled, the Extension itself, in the form of Diagnostic Data.
5.2 Candidate Data is ordinarily not obtained from the Candidate. Where Personal Data has not been obtained from the data subject, Article 14 of the GDPR requires the Controller to provide the information specified in that Article within a reasonable period and in any event within one month, or at the latest at the time of first communication with the data subject. As between the Operator and the Subscriber, the Subscriber is the Controller of Candidate Data and is accordingly responsible for discharging that obligation, as confirmed in clause 8.4.
5.3 The Operator assists the Subscriber in discharging that obligation by publishing this Policy at https://app.rounds.so/privacy, by describing in it the categories of Candidate Data Processed and their sources, and by responding to enquiries addressed to privacy@rounds.so.
5.4 Article 14(5). Article 14(5)(b) of the GDPR provides that the obligation in Article 14(1) and (2) does not apply where the provision of the information proves impossible or would involve a disproportionate effort, or where it is likely to render impossible or seriously impair the achievement of the objectives of the Processing; in such a case the Controller must take appropriate measures to protect the data subject’s rights, freedoms and legitimate interests, including making the information publicly available. The Operator’s publication of this Policy is intended as such a measure. Reliance on Article 14(5)(b) is not a general waiver: it must be assessed and documented case by case by the Controller, weighing the number of data subjects, the age of the data and any appropriate safeguards, and the Subscriber remains responsible for that assessment and its documentation in respect of Candidate Data.
5.5 Nothing in this Policy obliges the Operator to give notice to Candidates on a Subscriber’s behalf, unless the Operator has agreed to do so separately and in writing.
6. Purposes of Processing and Retention Periods
6.1 Personal Data is Processed for the following purposes and for no other purpose:
- authenticating a Subscriber User and maintaining that person’s signed-in session;
- recognising whether the page open in the active tab is a public professional profile page, and retrieving from the Service the record it holds for that page so that the Subscriber User may review it;
- recording a Candidate, together with any notes and email address entered by the Subscriber User, in the Subscriber’s Workspace;
- producing a Match Assessment against roles held in the Subscriber’s Workspace, where the Subscriber User expressly requests one;
- transmitting a Candidate to a role, in every case only after the Subscriber User has expressly confirmed that step;
- maintaining the security, availability and correct operation of the Extension and the Service, and identifying and correcting defects;
- responding to enquiries and to requests made under section 9 or section 13; and
- complying with legal obligations to which the Operator is subject and establishing, exercising or defending legal claims.
6.2 Personal Data is not Processed for advertising, is not sold or otherwise made available to any third party for consideration, is not shared for cross-context behavioural advertising, and is not used for any profiling other than the Match Assessments a Subscriber User expressly requests and reviews.
6.3 Personal Data is retained for no longer than is necessary for the purposes for which it is Processed, as follows:
- Account Data is retained for the duration of the Subscriber User’s account and thereafter for [RETENTION PERIOD — ACCOUNT DATA].
- Candidate Data is retained in the Subscriber’s Workspace under the Subscriber’s control until the Subscriber deletes it, until a request for erasure is given effect, or until the expiry of [RETENTION PERIOD — CANDIDATE DATA], whichever occurs first.
- Match Assessment Data is retained for so long as the underlying Candidate Data is retained, and in any event no longer than [RETENTION PERIOD — MATCH ASSESSMENT DATA].
- Diagnostic Data, where collected, is retained for [RETENTION PERIOD — DIAGNOSTIC DATA].
- Correspondence relating to enquiries and to requests made under section 9 or section 13 is retained for [RETENTION PERIOD — CORRESPONDENCE AND RIGHTS REQUESTS] in order to evidence compliance.
- Local Device Data is retained on the device only until it is overwritten by a subsequent detection or until the Extension is uninstalled or the browser’s data for it is cleared.
6.4 Personal Data deleted from active records is removed from routine backup copies within [BACKUP DELETION PERIOD], during which period it is not accessible for any operational purpose.
6.5 The Operator may retain Personal Data beyond the periods stated in clause 6.3 where, and for so long as, retention is required by applicable law or is necessary for the establishment, exercise or defence of legal claims, in which case the Personal Data is Processed only for that purpose.
7. Disclosures, Processors and International Transfers
7.1 The Operator does not sell Personal Data and does not disclose it otherwise than as set out in this section 7.
7.2 Candidate Data recorded through the Extension is made available within the relevant Subscriber’s Workspace to the personnel that Subscriber has authorised. The Subscriber controls who those persons are.
7.3 The Operator engages the following categories of Processor and sub-processor, each of which Processes Personal Data only on the Operator’s documented instructions and under a written contract containing the obligations required by Article 28(3) of the GDPR:
- Firebase Authentication, provided by Google — authentication of Subscriber Users and maintenance of signed-in sessions.
- Sentry — error monitoring, and only in respect of builds of the Extension for which error reporting has been enabled.
- [HOSTING PROVIDER] — hosting and storage of the Service and of the records held in Workspaces.
- [ANY FURTHER SUB-PROCESSORS] — [FUNCTION].
The current list of sub-processors, including the legal entity, the function performed and the countries in which Processing takes place, is maintained at [SUB-PROCESSOR LIST LOCATION] and is available on request.
7.4 The Operator may in addition disclose Personal Data to its professional advisers, auditors and insurers where necessary and subject to obligations of confidentiality, and to a successor entity in connection with a merger, acquisition, reorganisation or sale of assets, in which case the recipient is bound by terms no less protective than this Policy and data subjects are notified in accordance with section 16.
7.5 The Operator may disclose Personal Data where required to do so by applicable law, by a court of competent jurisdiction, or by a competent regulatory or law-enforcement authority. Where the Operator is lawfully permitted to do so, it will notify the affected Subscriber before making such a disclosure.
7.6 International transfers. Personal Data is Processed and stored in [HOSTING REGION]. Where Personal Data is transferred outside the European Economic Area, the United Kingdom or Switzerland, that transfer is made on the basis of an adequacy decision of the European Commission or of the competent United Kingdom authority where one applies to the recipient country, or otherwise on the basis of the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, together with the United Kingdom International Data Transfer Addendum where relevant, and subject to a transfer risk assessment and any supplementary measures that assessment identifies. The applicable transfer mechanism for each recipient is [TRANSFER MECHANISM PER RECIPIENT]. A copy of the relevant safeguards may be requested at privacy@rounds.so.
7.7 The Operator may add to or replace its sub-processors. It will give affected Subscribers not less than [SUB-PROCESSOR NOTICE PERIOD] notice of any such change, during which the Subscriber may object on reasonable data protection grounds.
8. Allocation of Roles; Subscriber Undertakings and Indemnity
8.1 The Operator is the Controller of Account Data, of Diagnostic Data, and of Personal Data Processed through its own websites and correspondence, and Processes that data for the purposes and on the lawful bases stated in sections 3 and 6.
8.2 In respect of Candidate Data, the Subscriber is the Controller and the Operator is the Processor. The Subscriber determines the purposes and means of that Processing, including which Candidates are recorded, which roles they are assessed against, and whether and when a Candidate is transmitted to a role.
8.3 The Operator Processes Candidate Data only on the Subscriber’s documented instructions, save where required to do otherwise by applicable law, in which case the Operator will inform the Subscriber of that requirement before Processing unless the law prohibits it. The Subscriber’s use of the Extension and of the Service, including each operation initiated by a Subscriber User, constitutes such an instruction.
8.4 Subscriber undertakings. The Subscriber warrants, represents and undertakes to the Operator that, at all times:
- it has and will maintain a valid lawful basis under Article 6 of the GDPR, and any further condition required by applicable law, for each Processing operation it instructs in respect of Candidate Data, and that it has documented that basis;
- it has provided, or will provide, the information required by Articles 13 and 14 of the GDPR to each Candidate, or has properly assessed and documented reliance on an exemption, including the exemption in Article 14(5)(b) described in clause 5.4;
- it will not give the Operator any instruction that would cause the Operator to breach applicable data protection law, and acknowledges that the Operator may decline, and will inform the Subscriber of, any instruction it considers to be in breach;
- it will receive, assess and respond to requests made by Candidates in exercise of their rights, within the periods required by applicable law, with such assistance from the Operator as is required by Article 28(3)(e) of the GDPR;
- it will take reasonable steps to ensure that Candidate Data it records is accurate, relevant and limited to what is necessary for the purposes for which it is Processed, and will keep it up to date;
- it will not enter into any field of the Extension any special category of Personal Data within the meaning of Article 9 of the GDPR, any data relating to criminal convictions or offences within the meaning of Article 10, or the Personal Data of any person known or reasonably suspected to be under the age of 18;
- it will comply with all laws applicable to its recruitment activities, including employment, equal treatment and anti-discrimination law, and with the terms of use of any third-party website or service from which professional information originates; and
- it will maintain appropriate security in respect of the credentials and access rights of its Subscriber Users, and will promptly withdraw access from any person who ceases to be authorised.
8.5 Indemnity. To the maximum extent permitted by applicable law, the Subscriber shall indemnify, defend and hold harmless the Operator and its officers, directors, employees, agents and sub-processors against all claims, demands, proceedings, investigations, liabilities, fines, penalties, awards, damages, losses and reasonable costs and expenses (including reasonable legal fees) suffered or incurred by any of them, to the extent arising out of or in connection with: (a) any breach by the Subscriber of clause 8.4; (b) any instruction given by the Subscriber that is unlawful or that infringes the rights of any person; (c) any use of the Extension or the Service by the Subscriber or a Subscriber User that is outside the purposes stated in section 6; or (d) any failure by the Subscriber to provide the information required by Articles 13 and 14 of the GDPR or to respond to a data subject’s request as required by applicable law.
8.6 Nothing in clause 8.5 limits or excludes any right of a data subject, including the right to compensation under Article 82 of the GDPR, nor any liability of the Operator that arises from the Operator’s own breach of its obligations as a Processor under Article 28 of the GDPR or of any obligation imposed on it directly by applicable data protection law.
8.7 Where a data processing agreement has been executed between the Operator and a Subscriber, that agreement governs the Processing of Candidate Data and prevails over this Policy to the extent of any inconsistency. The applicable agreement is [DATA PROCESSING AGREEMENT REFERENCE].
9. Rights of Data Subjects
9.1 Subject to the conditions and exemptions in applicable law, every data subject, whether a Subscriber User or a Candidate, has the right:
- to obtain confirmation as to whether Personal Data concerning him or her is Processed and, where it is, to obtain access to that data and to the information specified in Article 15 of the GDPR;
- to obtain the rectification of inaccurate Personal Data and the completion of incomplete Personal Data (Article 16);
- to obtain the erasure of Personal Data (Article 17);
- to obtain the restriction of Processing (Article 18);
- to object to Processing carried out on the basis of legitimate interests, on grounds relating to his or her particular situation, and to object at any time and without justification to Processing for direct marketing purposes (Article 21);
- to receive the Personal Data he or she has provided in a structured, commonly used and machine-readable format and to have it transmitted to another Controller, where the conditions of Article 20 are met;
- to withdraw consent at any time, where Processing is based on consent, without affecting the lawfulness of Processing carried out before the withdrawal; and
- to lodge a complaint with a supervisory authority (Article 77).
9.2 Rights may be exercised by writing to privacy@rounds.so. To enable the request to be identified and actioned, the request should state that it concerns the Rounds — Candidate Capture extension, identify the right relied upon, and, in the case of a Candidate, include the web address of the public professional profile concerned.
9.3 Where the Operator has reasonable doubts as to the identity of the person making a request, it may request such further information as is necessary to confirm that identity. Information provided for that purpose is used only for verification and is deleted once the request has been concluded.
9.4 The Operator responds to a request without undue delay and in any event within one month of receipt. That period may be extended by up to two further months where necessary, taking account of the complexity and number of requests, in which case the Operator informs the requester of the extension and of the reasons for it within one month of receipt. No fee is charged, save that where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Operator may charge a reasonable fee or refuse to act on the request, in each case giving reasons and informing the requester of the right to complain to a supervisory authority and to a judicial remedy.
9.5 Where a request concerns Candidate Data, the Operator acts as Processor and the relevant Subscriber, as Controller, is responsible for determining the response. The Operator will forward such a request to the relevant Subscriber without undue delay and in any event within [FORWARDING PERIOD], will inform the requester that it has done so, and will assist the Subscriber by appropriate technical and organisational measures. The Operator will not itself erase, rectify or disclose Candidate Data except on the Subscriber’s instruction or where applicable law requires it to act.
9.6 A data subject may lodge a complaint with the supervisory authority of the Member State of his or her habitual residence, place of work, or the place of the alleged infringement, and, in the United Kingdom, with the Information Commissioner’s Office. The Operator’s lead supervisory authority, where one applies, is [LEAD SUPERVISORY AUTHORITY]. Data subjects are invited, but not required, to raise the matter with the Operator first.
10. Automated Processing and Match Assessments
10.1 A Match Assessment is produced only where a Subscriber User expressly requests one, and consists of a weighted score and written reasoning comparing a Candidate against a role held in the Subscriber’s Workspace.
10.2 A Match Assessment is advisory. No decision producing legal effects concerning a Candidate, or similarly significantly affecting a Candidate, is taken by the Extension solely by automated means. The Subscriber User reviews the Match Assessment and must expressly confirm the step before a Candidate is transmitted to a role.
10.3 The Subscriber, as Controller, is responsible for ensuring that meaningful human review is maintained in its own recruitment processes and for compliance with Article 22 of the GDPR and any equivalent provision of applicable law governing automated decision-making in employment. A Candidate may request, through the channel in clause 9.2, an explanation of the information used in a Match Assessment concerning him or her, and such a request is handled in accordance with clause 9.5.
11. Security Measures
11.1 The Operator implements technical and organisational measures appropriate to the risk, in accordance with Article 32 of the GDPR, including:
- transmission of all data between the Extension and the Service over encrypted connections;
- authentication performed by a specialist provider, with credentials of limited life, and no handling of Subscriber User passwords by the Extension;
- confinement of access to Candidate Data to the Workspace of the Subscriber concerned;
- minimisation on the device, the Extension retaining only the limited information described in clause 3.7;
- the principle of least privilege in the browser permissions requested, as described in clause 3.8;
- restriction of the Operator’s personnel access to Personal Data to those who require it for the purposes stated in section 6, subject to obligations of confidentiality; and
- review and testing of the Extension before each release.
11.2 No method of transmission over the internet, and no method of electronic or physical storage, is perfectly secure. While the Operator takes the measures described in clause 11.1, it cannot and does not guarantee the absolute security of Personal Data, and any transmission is undertaken at the sender’s own risk to the extent permitted by applicable law.
11.3 In the event of a personal data breach, the Operator will, where it acts as Controller, notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and will communicate the breach to affected data subjects where required by Article 34 of the GDPR. Where it acts as Processor, the Operator will notify the affected Subscriber without undue delay after becoming aware of the breach and will provide the assistance required by Article 28(3)(f).
11.4 The Subscriber is responsible for the security of its own systems, for the confidentiality of its Subscriber Users’ credentials, and for promptly reporting to the Operator any suspected unauthorised access to its Workspace.
12. Children
12.1 The Extension and the Service are intended solely for use by professional users in a business context. They are not directed to, and are not intended for use by, any person under the age of 18, or under the age of 16 where applicable law sets that lower threshold as the relevant age for the purposes of this clause. Use of the Extension requires an account held by or through a Subscriber.
12.2 The Operator does not knowingly Process Personal Data relating to any person below the applicable age stated in clause 12.1, and clause 8.4(f) prohibits a Subscriber from entering such data.
12.3 Any person who believes that Personal Data relating to a person below the applicable age has been provided to the Operator should write to privacy@rounds.so. The Operator will take reasonable steps to have that data deleted without undue delay, and will notify the relevant Subscriber where the data forms part of Candidate Data.
13. Notice to Residents of California and Other United States Jurisdictions
13.1 This section supplements the remainder of this Policy and applies to residents of the State of California for the purposes of the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (together, the “CCPA”), and, so far as applicable, to residents of other United States states with comparable legislation. Terms used in this section have the meanings given to them by that legislation.
13.2 In the twelve months preceding the date of this Policy, the Operator has collected the following categories of personal information:
- Identifiers — name, email address, account identifier, and the web address of a public professional profile;
- Professional or employment-related information — professional headline, current employer, location, professional summary, and notes recorded by a Subscriber User;
- Internet or other electronic network activity information — limited to the web address of the active browser tab at the moment a Subscriber User opens the Extension;
- Inferences — in the form of Match Assessments; and
- Technical fault information — where error reporting is enabled for a build, as described in clause 3.6.
The sources of that personal information are set out in section 5, the business and commercial purposes for its collection in section 6, the categories of recipient in section 7, and the retention criteria in clause 6.3.
13.3 The Operator does not sell personal information and does not share personal information for cross-context behavioural advertising, and has not done so in the twelve months preceding the date of this Policy. The Operator does not knowingly sell or share the personal information of consumers under 16 years of age.
13.4 The Operator does not collect sensitive personal information for the purpose of inferring characteristics, and does not use or disclose sensitive personal information for any purpose that gives rise to a right to limit its use under the CCPA.
13.5 Subject to the exceptions in applicable law, a consumer has the right: to know the categories and specific pieces of personal information collected about him or her, the sources, the purposes and the categories of recipient; to delete personal information; to correct inaccurate personal information; to opt out of the sale or sharing of personal information, none of which is conducted; to limit the use of sensitive personal information, which is not collected for a purpose engaging that right; and not to receive discriminatory treatment for exercising any of these rights. The Operator does not offer financial incentives in exchange for personal information.
13.6 Requests may be made by writing to privacy@rounds.so, and may be made by an authorised agent who provides written proof of authorisation. The Operator will acknowledge a request within 10 business days and will respond within 45 calendar days, which period may be extended by a further 45 calendar days where reasonably necessary, with notice of the extension. Verification is carried out in accordance with clause 9.3. Where applicable state law provides a right of appeal against a refusal, an appeal may be submitted to the same address.
13.7 Where the Operator acts as a service provider to a Subscriber in respect of Candidate Data, it Processes that information only on the Subscriber’s behalf and for the business purposes specified in section 6, retains, uses and discloses it for no other purpose, and forwards consumer requests to the Subscriber in accordance with clause 9.5.
14. Disclaimers, Limitation of Liability and Severability
14.1 This Policy describes the Operator’s Processing practices as at the Effective Date. It is provided for information and for the discharge of the Operator’s transparency obligations. Except to the extent required by applicable data protection law, or expressly agreed in a separate executed agreement, this Policy does not create contractual rights or obligations.
14.2 To the maximum extent permitted by applicable law, the Operator disclaims all warranties, conditions and representations of any kind, whether express, implied or statutory, in relation to the Extension and the Service, including any implied warranty of merchantability, satisfactory quality, fitness for a particular purpose, accuracy, or non-infringement, and any warranty that operation will be uninterrupted or error-free. Match Assessments and any professional details displayed in the Extension are provided on an “as is” basis, without warranty as to their accuracy, completeness, currency or suitability for any recruitment decision, and must be verified by the Subscriber before being relied upon.
14.3 To the maximum extent permitted by applicable law, the Operator shall not be liable for any indirect, incidental, special, consequential, exemplary or punitive damages, nor for any loss of profits, revenue, business, anticipated savings, goodwill, or loss or corruption of data, howsoever arising and whether in contract, tort (including negligence), breach of statutory duty or otherwise, even if advised of the possibility of such loss; and the Operator’s aggregate liability arising out of or in connection with this Policy and the Processing it describes shall not exceed [LIABILITY CAP].
14.4 Nothing in this Policy operates to exclude or limit any liability that cannot lawfully be excluded or limited, including liability for death or personal injury caused by negligence, liability for fraud or fraudulent misrepresentation, and any liability to a data subject under Article 82 of the GDPR or under any other mandatory provision of applicable data protection law.
14.5 The Operator is not responsible for the privacy practices or the content of any third party, including the professional network whose page a Subscriber User has open when the Extension is used, the browser vendor through whose store the Extension is distributed, and any website reached from a link in this Policy. The privacy notices of those third parties apply to their own Processing.
14.6 Severability. If any provision or part-provision of this Policy is or becomes invalid, illegal or unenforceable, it shall be deemed modified to the minimum extent necessary to make it valid, legal and enforceable. If such modification is not possible, the relevant provision or part-provision shall be deemed deleted. Any modification to or deletion of a provision or part-provision under this clause shall not affect the validity and enforceability of the rest of this Policy, which shall continue in full force and effect.
14.7 No failure or delay by the Operator in exercising any right or remedy under this Policy constitutes a waiver of that or any other right or remedy, and no single or partial exercise of it prevents any further exercise.
15. Governing Law and Venue
15.1 This Policy and any dispute or claim arising out of or in connection with it or its subject matter, whether contractual or non-contractual, are governed by and construed in accordance with the laws of [JURISDICTION], without regard to its conflict-of-law rules.
15.2 The courts of [JURISDICTION] have exclusive jurisdiction to settle any such dispute or claim.
15.3 Clauses 15.1 and 15.2 do not deprive any data subject of the protection of mandatory provisions of the law of his or her habitual residence, nor of the right to bring proceedings before the courts identified in Article 79 of the GDPR or to lodge a complaint under clause 9.6.
16. Changes to this Policy
16.1 The Operator may amend this Policy from time to time, including to reflect changes in the Extension, the Service, applicable law or regulatory guidance. The current version is always published at https://app.rounds.so/privacy and bears an Effective Date and a Last Updated date.
16.2 Where an amendment is material, the Operator will give notice not less than [NOTICE PERIOD] before the amendment takes effect, by [NOTICE METHOD — for example, electronic message to Workspace administrators and a notice displayed in the Service], and the amended Policy will state its new Effective Date.
16.3 Amendments that are not material, including corrections and clarifications, take effect upon publication.
16.4 Continued use of the Extension after the Effective Date of an amended Policy constitutes acknowledgement of that Policy. Where Processing is based on consent and an amendment alters the purposes for which Personal Data is Processed, fresh consent will be obtained before the amended purposes are pursued.
16.5 Previous versions of this Policy are available on request at privacy@rounds.so.
17. Effective Date and Contact
17.1 This Policy takes effect on 15 August 2026 and was last updated on 15 August 2026. It supersedes all previous privacy notices published for the Extension.
17.2 All communications concerning this Policy should be addressed as follows:
- [LEGAL ENTITY NAME], trading as Rounds
- [REGISTERED ADDRESS]
- Electronic mail: privacy@rounds.so
- Website: www.rounds.so
Rounds — Candidate Capture. Privacy Policy, version of 15 August 2026.
← Back to the extension page