Security review
What your security team asks, answered here
This page is the security review packet for the Enterprise plan. It sets out what data the board holds, where it sits, who else touches it and how access works. The data processing agreement is below and is signed on the account. If a question is not answered here, write to [email protected] and we will answer it in writing.
What we hold
- From employers
- Company name and site, the contact and billing addresses, the seats you invite with their email addresses and roles, listing content, the billing address and PO number on your invoice, and your ATS credentials if you connect one. Card numbers are never in our systems.
- From job seekers
- Email address, alert settings (role, timezone, salary floor), and for each application the name, timezone, salary expectation, an optional link and an optional note. No resumes are stored and no identity documents are asked for.
- What we do not hold
- No passwords, for anyone. Both job seekers and employer seats sign in with a one-time code sent to their address, so there is no password database to lose. No card numbers: payment pages belong to Stripe. No special category data.
Where it sits, and who else touches it
The application and its database run on a dedicated virtual server at Hetzner in Ashburn, Virginia, United States. These are the subprocessors involved, and no others:
| Subprocessor | What for | Data involved |
|---|---|---|
| Hetzner Online GmbH | Hosting, Ashburn, Virginia | Everything the application stores |
| Cloudflare, Inc. | DNS and the TLS edge in front of the site | Request metadata in transit |
| Stripe, Inc. | Payments, invoicing, PO billing | Billing contact, company name, invoice data, card data (held by Stripe, never by us) |
| Postmark (Wildbit, LLC) | Sending transactional email: codes, alerts, applications, invoices | Recipient address and message content |
| Microsoft Clarity | Site analytics on the public pages | Usage metadata from public pages |
How access is controlled
- Employer seats are scoped by role. A Recruiter seat posts roles and reads applicants and cannot reach billing; a Viewer seat changes nothing. Every action checks the role on the server, not in the browser.
- Taking a seat away ends that person's session immediately. The record of who was on the team stays, so there is an audit trail.
- API keys carry scopes (read listings, publish listings, read applicants) and are stored as hashes. A key is shown once, at creation, and cannot be read back afterwards.
- ATS credentials are encrypted before they are written to the database and are never displayed again.
- Server access is by SSH key only, for the operations account that deploys the application.
- Payment pages are hosted by Stripe. Card data never reaches our servers, in any form.
Retention and deletion
Listings and applications stay on the account while the plan runs, so your hiring history remains readable. When a plan ends, listings come off the board and the applicant list closes. On written request we delete or return the account data within 30 days, except records we have to keep for accounting, which are the invoices themselves.
Data processing agreement
This is the full text we sign. Enterprise accounts sign it on the plan page, which records the legal entity, the signatory and the date, and keeps the countersigned copy available to your legal team.
Data processing agreement
Between LatestRemote (the processor, referred to as "we") and the customer named on the account (the controller, referred to as "you"). It applies for as long as we process personal data on your behalf and takes precedence over the terms of service on the subject of data protection.
1. Subject and duration
We process personal data to run the job board for you: to publish your listings, to collect applications, to send alerts to job seekers who asked for them, to give your seats access, to push applicants into the applicant tracking system you connect, and to bill you. Processing lasts as long as your plan runs, plus the deletion period in clause 8.
2. Categories of data and of people
People: your employees and contractors who hold seats, and job seekers who apply to your listings. Data: names, email addresses, timezone, salary expectations, an optional link and an optional note supplied by the applicant, plus account and billing details you give us. We do not ask for, and you must not send us, special category data within the meaning of Article 9 of the GDPR.
3. Our obligations
We process personal data only on your documented instructions, which the use of the service constitutes, and for no purpose of our own. We keep it confidential, we restrict access to the people who need it to operate and support the service, and we apply the technical measures described in the security overview: sign-in without passwords, one-time codes, role-scoped seats, hashed API keys, encrypted ATS credentials, TLS in transit and key-based server access.
4. Subprocessors
We use the subprocessors listed on the security overview page, each under a written agreement with data protection terms no less protective than these. You authorise them. If we add or replace one, we update that page and tell you by email at least 30 days beforehand, and you may object in writing; if the objection cannot be resolved you may terminate the affected part of the service and receive a pro rata refund of prepaid fees.
5. International transfers
The service is hosted in the United States. Where you transfer personal data from the European Economic Area, the United Kingdom or Switzerland, the parties adopt the European Commission's standard contractual clauses for controller-to-processor transfers (Module Two), which are incorporated into this agreement by reference, together with the UK International Data Transfer Addendum where the United Kingdom applies.
6. Security incidents
If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any case within 72 hours of becoming aware, at the account contact address, with what we know at the time: what happened, which data is affected as far as we can tell, and what we are doing about it. We keep you updated as the picture changes and we help with any notification you have to make.
7. People exercising their rights, and audits
If someone contacts us about data we hold for you, we pass the request to you rather than answering for you, unless the law requires otherwise, and we help you answer it. On request, once in any twelve months, we answer your security questionnaire in writing and provide the information you need for your records. The security overview page counts as that information for a standard review.
8. Deletion and return
When the plan ends, listings come off the board and the applicant list closes. On your written request we delete or return the account data within 30 days, other than invoices and payment records we must keep for accounting and tax.
9. Liability and law
This agreement does not change the limits of liability in the terms of service. Where the GDPR applies, nothing here limits a data subject's rights against either party under it.