Privacy Policy

Updated May 17, 2024

View the Privacy policy for United States | Canada | Mexico | United Kingdom | European Economic Area | Other

Plum.io Inc. (“Plum”, “we”, “us” or “our”) recognizes that privacy is important in all our interactions. Accordingly, we have developed this privacy policy (“Privacy Policy”) to explain how we collect, use, process, transfer, and disclose any Personal Information we collect from you, generally as part of our services and through your use of our website and/or platform.

By accessing or visiting our website, registering for and using our services and platform, or otherwise interacting with us, you are agreeing to the terms of this Privacy Policy and, as applicable, the Plum Terms of Service. We may update this Privacy Policy from time to time in order to reflect changes to our privacy practices or for other operational, legal, or regulatory reasons. If we make material changes to this Privacy Policy, we will post the revised policy on this website. By continuing to use our website, platform, or other Plum services after these changes are posted, you agree to the revised Privacy Policy.

The following is a short summary of the key elements of this Privacy Policy. You can read the full version of the Privacy Policy following the summary.

Summary of Privacy Policy

We collect personal information to promote and market our services.

When you contact us directly or engage with us through our website and social media, we may collect the following personal information:

  • First and last name
  • Contact information
  • Information about how, when, and where the interaction occurred
  • Content of conversations
  • The hardware and software you use to interact with us
  • Your device identifier
  • Your mobile network information
  • The settings you use on our services
  • Your network location
  • Your IP address and
  • Information about the webpages you visited prior to coming to our website.

We may share this information with:

We may collect certain Personal Information from third parties, such as LinkedIn, Lusha, and ZoomInfo. Such Personal Information may include your name, email address, employer, job title, location, and phone number.

When you create an account on our platform, we collect personal information to deliver, manage, and improve our services.

We collect information necessary to identify you:

  • first and last name,
  • email address,
  • and other contact information such as mailing address, and telephone number;

If you use our platform to discover your employment potential and / or apply for jobs, we collect information necessary to assess your potential and to identify opportunities. This information includes:

  • information regarding your cognitive ability and personality and other career-related attributes;
  • information about your work history, work preferences (including preferred work locations), and employment status;
  • job experience, job preferences, and status;
  • location of residence and/or locations in which you are willing to work;

We may ask you to provide us with demographic information such as:

  • your age or age group,
  • your inclusion in one or more protected groups (e.g., race / ethnicity, gender, disability status)

We use this information to conduct research and to assess our algorithms for potential bias. The provision of this information is completely voluntary. This information will not be shared without your express consent. This information will not be used directly or indirectly to assess your potential or to identify opportunities.

If you require an accommodation when completing the Plum Discovery Survey, a record of the accommodation including the nature of the accommodation will be kept. This information is used internally by Plum to improve our platform and processes. It may also be used when assessing our algorithms for bias.

We provide a facility for job candidates to upload cover letters and resumes to facilitate the job application process. By using this facility, you consent to share the personal information contained in these documents with Plum. Plum may use this information to:

  • With your express consent, facilitate the submission of a cover letter and resume to a job application,
  • Use the content of these documents to facilitate the completion of your profile,
  • and to Analyse the content to produce anonymous aggregate reports.

We may collect certain Personal Information from prospective employers or your current employer, including:

  • first and last name;
  • contact information, such as your email address, and preferred language;
  • confirmation that you were hired or placed by an employer using our services.

The following usage information may be collected automatically through your web browser or device:

  • information about how, when, and where you use our services;
  • the hardware and software you use to interact with our services;
  • your device identifier; your mobile network information;
  • the settings you use on our services; your network location;
  • your IP address;
  • and information about the webpages you visited prior to coming to our website.

We may use your Personal Information for the following purposes or purposes compatible therewith:

  • provide you with information about our services and the use of our website;
  • provide you with support, including accommodations, and handle inquiries;
  • improve the quality and functionality of the website, enhance your experience, create new services (including customized services), change/cancel existing services, or for statistical purposes;
  • if you, as a visitor to our website, so choose, to present you relevant content, marketing materials, and advertisements, by analyzing your interests from the web pages you visit and online services you use (users of our platform will not be subject to any ad tracking or targeted advertisements solely as a result of being a user);
  • communicate with you about our services, including updates or newsletters;
  • conduct surveys and market research;
  • deliver content that may be of interest to you;
  • ensure that our website remains functioning and secure;
  • generate anonymized or aggregated information, which we use for our business purposes at our sole discretion;
  • investigate, prevent, or act on any illegal activities or violations of our Terms of Service;
  • and comply with any applicable law and assist law enforcement agencies as required.

We may share your Personal Information with the following parties:

You have the following choices:

Depending on the services or your use of our website, your choices may include the following:

  • Access and Correction: You can access, update, correct, or delete most of your Personal Information via the Account tab of the My Plum section when you log in to the latest version of the Plum service or by emailing privacy@plum.io and providing your first name, last name, and email address. We will correct, update, or delete any Personal Information that is under our custody or control (i.e., for which we are “controller”), subject to legal and contractual restrictions. You can ask us to make these changes for you. Depending on your jurisdiction of residence, you may also have additional rights in relation to your personal information. See our full privacy policy below for more information.
  • Cookies Settings and Preferences: You may disable cookies and other tracking technologies through the settings in your browser. While doing so may negatively affect your experience with the use of our website, it will not prevent us from transacting with you.
  • Marketing Emails: Plum seeks to comply with applicable electronic marketing laws. We provide you with an opportunity to let us know your preference in terms of receiving promotional e-mail when you register for our service, provide us with Personal Information, or when we send e-mails.
  • Opt-Outs: If you have signed up to receive marketing emails from us, you may unsubscribe through the unsubscribe footer in all e-mails, or by replying to these messages with a request for opt-out. In addition, for marketing conducted via our website, you can request deletion of your marketing records and all associated website tracking (cookies) by emailing privacy@plum.io.
  • Online Behavioural Advertising: You can opt-out of the use of your Personal Information for the purposes of Online Behavioural Advertising by using the advertising service provider “opt out” options or by visiting Your Ad Choices at http://youradchoices.ca/choices.

    The advertising partners whom we use to provide us with advertising-related services are as follows:

How to contact us:

For more information about this Privacy Policy, our privacy practices, or to obtain access to or correction of your Personal Information, or to exercise other rights you may have under applicable laws, please contact our Data Protection Officer at privacy@plum.io or by using the contact details below:

Plum.io Inc.
ATTN: Data Protection Officer
151 Charles St. W. Suite 100
Kitchener, Ontario N2G 1H6
Canada

Full version of Privacy Policy

  1. This Privacy Policy covers the following information:
  2. Types of Personal Information We Collect and Why
  3. Consent
  4. How we share Personal Information
  5. How to access and update your Personal Information or preferences
  6. How we protect your Personal Information
  7. Retention of Personal Information
  8. User choices about receiving email
  9. "Do Not Track" Signals
  10. Privacy Protection for Children
  11. Residents of Nevada
  12. Residents of California
  13. Residents of the European Economic Area ("EEA") and the United Kingdom ("UK")
  14. Residents of Mexico
  15. Residents of Canada
  16. How we make updates to this Privacy policy
  17. How to contact us for more information

1. Types of Personal Information We Collect and Why

Personal Information means any information, recorded in any form, about an identifiabl individual or an individual whose identity may be inferred or determined from such information, either alone or in combination with other information. Personal Information may or may not include business contact information, depending on the jurisdiction.

Personal Information does not include anonymized aggregated data from which the identity of an individual cannot be determined. We may use your Personal Information to generate statistical or aggregated information about the website's use and/or your inputs into the platform and share, publish, post, disseminate, transmit, or otherwise communicate or make available such information to business partners and any other third party, at our sole discretion. We may take your Personal Information and render it non-identifiable (anonymize), following which we may use this anonymized information for any purpose, at our sole discretion. This information will be used by Plum for the continuous improvement of our services, in the creation of industry reports (trend analysis), and in academic research. The purposes for which we use anonymized and/or de-identified information may change with time. Our Privacy Policy will be updated to reflect any changes and or new uses.

By using Plum's website, services, platform, or engaging with Plum directly, you consent to the use of your Personal Information to generate anonymized, and/or aggregated data that cannot be linked to you or used to identify you. Plum is the owner of such de-identified, anonymized, and/or aggregated data (e.g., anonymized dataset of responses to the Discovery Survey) and reserves the right to use such data in any way it determines appropriate.

1.1 Personal Information Collected through Sales and Marketing Channels

1.1.1 Website Usage

(a) Information Collected: We automatically obtain certain information about your use of our website. Specific types of usage information that may be collected automatically are described below:

  • information about how, when, and where you use our services;
  • the hardware and software you use to interact with our services;
  • your device identifier;
  • your mobile network information;
  • the settings you use on our services;
  • your network location;
  • your IP address; and
  • information about the webpages you visited prior to coming to our website.

(b) How Is It Collected and for What Purpose: We use cookies to collect the above usage information when you visit our website for the purposes of operating our website, improving performance of our website, and serving advertisements to users.

You may disable performance and/or marketing cookies using the Cookies control panel. You may be able to block specific cookies via your browser settings, but this may prevent you from accessing certain features of the website. You can learn more about cookies by visiting www.allaboutcookies.org, which includes additional useful information on cookies and how to block cookies using different types of browsers. Note that while declining cookies may negatively affect your user experience on our website, it will not prevent us from transacting with you (unless the declined cookies are strictly necessary to operate our website)].

Log Files: In order to properly manage our website, we may anonymously log information on our systems, and identify categories of visitors by items such as domains, IP address, browser type, referring page, and time of visit. These statistics are used to manage the operational efficiency of our systems.

Online Behavioural Advertising and Ad Tracking: As part of our ad delivery and reporting, we log page views and collect information from our website visitors (not platform users) for the purpose of delivering ads or providing advertising-related services, including providing a specific advertisement on a particular type of browser or time of day; statistical reporting in connection with the activity on a website; and tracking the number of ads served on a particular day to a particular website (tracking web analytics data). To do so, we collect information about the type of browser, referrer, and operating system of website visitors, as well as the domain name, day and time of visit, and page(s) visited. We do so across multiple web domains owned or operated by different entities.

You can opt-out of (or withdraw consent to) the use of your Personal Information for the purposes of Online Behavioural Advertising by contacting us, or by visiting Your Ad Choices at http://youradchoices.ca/choices, or by using the opt-out option provided by our advertising partners. The Your Ad Choices opt-out tool allows you to opt-out of any advertising networks participating in the self-regulatory program for online behavioural advertising. However, note that opt-outs will not be effective if your browser is configured to reject cookies, or if you subsequently erase your cookies, use a different computer, or change browsers.

The advertising partners whom we use to provide us with advertising-related services are as follows:

(c) Retention of Information: Any visitor logs or log files are retained only for as long as required to fulfill the purposes for which it was collected, and not more than 24 months. Visitor logs or other log files related to an ongoing security incident may be retained until no longer required by the incident response.

1.1.2. Registered Visitors

(a) Information Collected: We may collect the following information when you fill out forms on our website, email us, or otherwise engage with us:

  • First and last name
  • Email
  • Telephone number
  • Employer/company/industry
    • Number of employees
    • Company name
    • Job role/title
    • ATS provider
  • Product or service interest
  • Opinions about our products or services

(b) How Is It Collected and for What Purpose: This information is provided by you. We will use such information to contact you to provide you with further information about our products or services and to improve our products or services. We may share this information with partners in order to conduct joint marketing and sales activity.

(c) Retention: Any information collected through forms on our website, by email, or other communications with you will be retained for 18 months.

1.1.3. Online Conference Participants

(a) Information Collected: With your consent, we may record or transcribe conversations conducted using video and teleconferencing platforms.

(b) How is it Collected and for What Purpose: This information is collected by the video or teleconferencing platform used to conduct the conference. We use this information for quality control, staff training, and for requirements analysis.

(c) Retention: Recordings and transcriptions will be retained only for as long as required to fulfill the purposes for which it was collected, and not more than 18 months.

1.1.4. Collection from Third Parties

(a) Information Collected: We work closely with third parties (including business partners, advertising networks, analytics, and search information providers) and may receive Personal Information about you from them. Third parties include, but are not limited to, LinkedIn, Lusha, ZoomInfo, and Reveal. We may collect the following information from third parties:

  • First and last name
  • Email
  • Telephone number
  • Employer/company/industry
    • Number of employees
    • Company name
    • Job role/title
    • ATS provider
  • Product or service interest
  • Opinions about our products or services

To learn more about how our third party service providers collect, use, and disclose personal information, please review their respective privacy policies:

(b) How is it Collected and for What Purpose: Information is provided by third-parties services who have established a legal basis for the provision of such information and entered into a contract with Plum. We process this Personal Information based on our legitimate business interest in providing direct marketing about our products and services, or with your consent, if required under applicable law. Such data obtained from third parties will be kept in accordance with the same privacy practices as described in this Privacy Policy and with any additional restrictions imposed by the third party that shared your Personal Information. We may share this information with partners to conduct joint marketing and sales activity.

(c) Retention: Information collected from third parties will be retained only for as long as required to fulfill the purposes for which it was collected, and not more than 18 months.

1.2. Personal Information Collected from Platform Users

1.2.1.Service Account

(a) Information Collected: To create an account and leverage the services offered on Plum's Platform, users will be required to provide certain Personal Information upon registration, such as an email address, first name, last name, mailing address, and telephone number.

(b) How Is It Collected and for What Purpose: Your first name, last name, and email address is provided by you when you create an account. These data may also be provided to Plum by an employer when you apply for a job or are an employee for the purpose of contacting you and establishing an account. All other registration

(c) Retention: We will retain your registration information for as long as your account is active and for a maximum of 12 months thereafter. All such Personal Information will be stored on Plum's server infrastructure, provided by Amazon Web Services (AWS).

1.2.2. Service Activity Logs

(a) Information Collected: Plum automatically collects activity-related Personal Information when you use our Platform. Such information may include system events, references to Service Account, and IP address and browser details.

(b) How It Is Collected and for What Purpose: We utilize network logs, firewall logs, and application logs to collect the above information. Such information is used to provide support to our Platform users, improve our products and services, and monitor platform security and investigate (as needed). None of the information collected will be used for targeted advertising.

(c) Retention: Service activity logs will be retained only for as long as required to fulfill the purposes for which they were collected, and not more than24 months (subject to any ongoing or anticipated investigations).

1.2.3. The Plum Profile

(a) Information Collected: Plum collects your responses to the questions of the Plum Discovery Survey. After you complete the Survey, and based on your responses, Plum generates your specific Plum Profile. The Plum Profile contains the assessment of your personality, problem-solving ability, and social intelligence, and describes your Talents. Note that there is no Personal Information implicitly or explicitly contained within the Survey responses. The information collected will be considered Personal Information to the extent that it is associated with a user account.

(b) How It Is Collected and for What Purpose: We collect this information directly from you via your completion of the Discovery Survey. We use such information to:

  • create a database of anonymized responses to the Discovery Survey;
  • improve our products and services;
  • conduct research;
  • provide platform users with information about their Talents;
  • permit the user to share all or a portion of their Plum Profile;
  • compute a match score against a set of requirements ("Plum Match Criteria");
  • compute a leadership potential rating;
  • provide tools to help employers and trusted partners source users for opportunities;
  • personalize the user's experience in a variety of ways, such as providing tailored job postings, development resources, and social forums;
  • provide other reports to customers (e.g., internal benchmarks).

Your Plum Profile is shared only with employers and platforms to which you have given consent. See Section 2 - Consent for important information related to your Plum Profile.

(c) Retention: The association between an individual and their Talent data is maintained as long as the individual maintains an account on the Plum Platform. The individual is responsible for initiating the deletion of their account data.

Retention of Personal Information provided in reports (i.e., disclosed by Plum to its employer customers) is governed by the customer's data governance regime.

For reports that have not been exported or otherwise disclosed to customers (in which case the report will reside in customers' systems and be governed by their policies), in Plum's systems, when an association between an individual and their Talent data is removed, it is removed from all reports.

1.2.4. Work Profile

(a) Information Collected: We may provide you with the opportunity to provide additional information about your work history, work preferences (including preferred work locations), employment status, work-related skills, education, and professional qualifications.

(b) How is it collected and for What Purpose: This information is collected from you through the platform. It is collected with your consent and is not required to use the platform. This information is used:

  • to personalize the user's experience in a variety of ways, such as providing tailored job postings,
  • to conduct research, and
  • improve our products and services.

You may consent to share this information with employers and trusted partners for the purpose of identifying and evaluating candidates for employment opportunities.

You may also consent to share your work profile on social media platforms.

(c) Retention: Plum will retain this information for as long as you maintain an account on the platform. You may change or delete this information at any time by logging into the platform and managing your profile.

1.2.5. Diversity Information

(a) Information Collected: We may provide you with the opportunity to provide us with information concerning your inclusion in various demographic groups (e.g., age, ethnicity, gender, disability)

(b) How It Is Collected and for What Purpose: This information is collected from you through the platform. It is collected with your consent and is not required to use the platform. This information is used:

  • to assess our product or services for compliance with respect to labour, human rights, and other relevant legislation and regulations,
  • to conduct research,
  • to improve our products and services,
  • to personalize the user's experience in a variety of ways, such as providing tailored job postings, development resources, and social forums.

This information will not be used in any form to assess the suitability of a candidate for employment opportunities.

(c) Retention: Plum will retain this information for as long as you maintain an account on the platform. You may change or delete this information at any time by logging into the platform and managing your profile.

1.2.6. Candidate Documents (Resume and Cover Letter)

(a) Information Collected: For individuals using our Talent Acquisition services, we may collect Personal information contained in your resume and cover letter.

(b) How It Is Collected and for What Purpose: You provide such Personal Information directly to Plum to facilitate the sharing of your resume/cover letter for job applications.

(c) Retention: Plum will retain such Personal Information for as long as you maintain an account with us. You may modify or delete this information at any time by using the platform.

1.2.7. Customer Provided Observations (Notes and Feedback)

(a) Information Collected: Plum receives certain observations from its employer customers, including free-form notes, feedback, and indicators such as "Hired" (Talent Acquisition) or "Placed" (Talent Management), and direct supervisor details (if the "Hired" indicator appears) (collectively, "Customer Provided Observations").

(b) How It Is Collected and for What Purpose: Customer Provided Observations are collected and used by the customer according to the customer's privacy policy and practices. Plum uses feedback and indicators to:

  • facilitate customer processing,
  • improve our products and services.

Free-form notes are not used by Plum. We store these on behalf of our customers

(c) Retention: Customer Provided Observations are retained for as long as the employer maintains an active account with us and for a period of up to 12 months thereafter.

1.2.8. Opportunity Interest/Job Application

(a) Information Collected: Plum collects information related to the type of employer and/or opportunities an individual has explicitly expressed interest in or applied to.

(b) How It Is Collected and for What Purpose: When you use our services to apply to a job with a prospective employer, we will use this information to provide you with a list of employers and jobs that you have applied to. We will also ask about your interest in other opportunities. This information is used:

  • To personalize the list of opportunities we present to you
  • To share, with your consent, your interest in opportunities with the hiring organization,
  • To compute statistics and prepare reports for our customers.

(c) Retention: Plum will retain job application information for as long as you maintain an account with us and opportunity interest information for as long as your employer maintains an active account with us and for a period of 12 months thereafter.

1.3. Data Acquired from Third Parties

PWe work closely with third parties (including business partners, advertising networks, analytics, and search information providers) and may receive Personal Information about you from them. Third parties include, but are not limited to, LinkedIn, Lusha, and ZoomInfo.

  • Personal Information obtained from LinkedIn include name, email, employer, and job title, and this data is publicly available information.
  • Personal Information obtained from Lusha include name, email, employer, job title, location, and phone number, and this data is not publicly available information.
  • Personal Information obtained from ZoomInfo include name,-e-mail addresses, phone numbers, and other business-related information such as title, time in a role

We process this Personal Information based on our legitimate business interest in providing direct marketing about our products and services. Such data obtained from third parties will be kept in accordance with the same privacy practices as described in this Privacy Policy and with any additional restrictions imposed by the third party that shared your Personal Information.

2. Consent

Unless permitted by law, Personal Information is collected, with consent of the individual concerned to the collection, use, and disclosure of that information.

By accessing or visiting our website, registering for and using our services and platform, or otherwise interacting with us, you are agreeing to the terms of this Privacy Policy and, as applicable, the Plum Terms of Service.

The Plum service equips employers with the data to hire, develop, retain, and promote workers. When you apply for a position with an employer that uses the Plum service, you consent to share your name, email address, Personal Information contained within a resume and/or cover letter, and assessment scores with the employer; that is, you consent to the transfer of control of this information to the employer. The employer may use this information for processing the current application and subsequent applications and other purposes in accordance with their privacy policy.

For the Talent Management service (e.g., employees of an employer that is using the Plum services), Plum acts solely as a sub-processor on behalf of the employer. The legal basis for collection is determined between you and your employer, or on the basis of consent, if required by applicable law.

You are free to refuse or withdraw your consent to our further use and sharing of your Personal Information that is under our custody and control (i.e., for which we are the "controller") at any time upon reasonable, advance notice. Your withdrawal of consent will not operate retroactively. It should be noted that our services may only be offered if you provide us with certain Personal Information. Consequently, if you choose not to provide us with the required Personal Information, we may not be able to offer you these services. We will inform you of the consequences of the withdrawal of consent.

3. How We Share Personal Information

Plum may disclose the data collected from users and website visitors, including Personal Information, to the following parties, including parties that may be located outside of Canada:

  • individuals or organizations who are our advisors or consultants;
  • employers who have subscribed to Plum's Talent Acquisition and/or Talent Management services, where you have authorized such sharing;
  • the following advertising, marketing, and analytics services providers, who target advertisements to website users:
  • other service providers, including individuals or organizations who are, or may be, involved in maintaining, reviewing, and developing our systems, procedures, and infrastructure including testing or upgrading of our computer system, and providing the cloud-based infrastructure for our data processing and storage.

Demographic information that has not been de-identified or anonymized will not be shared

Under certain circumstances, Plum will be obliged or permitted to disclose your information without your consent:

  • Law Enforcement: Plum may disclose Personal Information to third parties without your consent for any of the following reasons: (i) to comply with any law, regulation, or order of a court, administrative agency, or government tribunal; (ii) to cooperate with Government investigations; (iii) to help prevent fraud or to enforce or protect the rights of Plum or its subsidiaries, and to pursue available remedies or limit any damages that we may sustain; or (iv) where it is necessary to protect the rights, privacy, safety, or property of an identifiable person or group.
  • Other Third Parties: Plum may disclose Personal Information to other third parties without your consent where required or permitted by law, including where: (i) the information is public as permitted by law; (ii) it is necessary to proceed with or complete a "business transaction", such as purchase and sale of an organization or assets, a merger or amalgamation, making of a loan, charge, lease or licensing, or other prescribed business activity; (iii) it is reasonable for the purposes of investigating a breach of an agreement, or actual or suspected illegal activity; or (vi) it is necessary to identify an individual who is injured, ill, or deceased, or (vii) due to an emergency that threatens the life, health, or security of an individual.

Where obliged or permitted to disclose information without consent, Plum will not disclose more information than is required.

4. How to Access and Update Your Personal Information or Preferences

You may access most of your Personal Information under the Account tab of the My Plum section when you log in to the latest version of the Plum services. You may also request to access your Personal Information by emailingprivacy@plum.io and providing your first name, last name, and email address. We will correct, update, or delete any Personal Information we have about you that is within our custody and control, unless we are required to keep it by law.

To guard against fraudulent requests for access, we may require sufficient information to allow us to confirm that the person making the request is authorized to do so before granting access or making corrections.

If you have signed up to receive marketing emails from us, you may unsubscribe through the unsubscribe footer in all e-mails, or by replying to these messages with a request for opt-out. In addition, for marketing conducted via our website, a user can request deletion of their marketing records and all associated website tracking (cookies) by emailingprivacy@plum.io.

Please be advised that in certain circumstances, Plum processes your Personal Information on behalf of your employer or a prospective employer and does not have custody and control of your Personal Information (i.e., is not the "controller", to the extent that term appears in applicable law). In such circumstances, Plum will direct your request to your employer or the prospective employer (i.e., the data "controller", to the extent that term appears in applicable law), and it will be the sole responsibility of the employer or prospective employer to respond to your request.

5. How We Protect Your Personal Information

5.1. Security of Your Personal Information

Plum follows industry recognized standards on information security management to safeguard your Personal Information. Our information security systems apply to people, processes, and the technology we employ:

  • information that we collect through forms on our website are stored in our CRM and marketing automation platform (HubSpot);
  • information that we collect through our platform is stored on servers hosted by Amazon Web Services (AWS) hosted primarily in the United States, that use standard physical, technical, and organizational security procedures and practices appropriate to the nature of the information in an effort to protect information from unauthorized access, destruction, use, modification, or disclosure.

We further protect Personal Information by restricting access to it to those employees that require access to the information in order to provide our services or website.

Please note that confidentiality and security can never be 100% assured when information is transmitted or stored electronically.

5.2. Cross-Border Transfer or Storage of Information

We may use service providers located outside of your jurisdiction of residence and, if applicable, your Personal Information may be processed and stored in a foreign jurisdiction and therefore may be subject to access by or disclosure to foreign law enforcement authorities under the laws of those jurisdictions. You may request information from Plum on the jurisdictions in which Plum and/or its service providers will process Personal Information.

6. Retention of Personal Information

Plum retains the Personal Information provided upon registration (e.g., name, email address, cover letter/resume) for legitimate business purposes, or with your consent, as required under applicable law, and to comply with the law, except when we receive a valid erasure request for Personal Information for which we are the controller or that is under our control. You may request to delete your account by emailing privacy@plum.io and providing your first name, last name, and email address. Please note that in circumstances where your Personal Information is under the control or another party (e.g., your Employer) on whose behalf we are providing services and act as processor, we will direct your request to that other party.

When your Personal Information is no longer required for the purposes for which it was collected, we will destroy, delete, erase, or convert it into an anonymous form. If we learn that we have unintentionally stored Personal Information (e.g., if we become aware that a URL that we store contains Personal Information), we will use commercially reasonable efforts to anonymize or purge this information.

7. User Choices About Receiving Email

Users may receive e-mails regarding their account and associated services. Users may also receive emails with information about our services or offers by us or by our affiliates, unless the users indicate they do not want to receive them. Plum seeks to comply with applicable electronic marketing laws with respect to such communications.

Users have an opportunity to let us know their preference in terms of receiving promotional e-mails during the registration process on our platform, when they provide us with Personal Information through website forms or otherwise, or when we send users e-mails. This option applies to promotional e-mails only. Plum may find it necessary to send users e-mails relating to their account or services.

8. "Do Not Track" Signals

Some internet browsers incorporate a "Do Not Track" feature that signals to websites you visit that you do not want to have your online activity tracked. Given that there is not a uniform way that browsers communicate the "Do Not Track" signal, the website and platform do not currently interpret, respond to, or alter their practices when they receive "Do Not Track" signals.

9. Privacy Protection for Children

Plum does not knowingly permit children under the age of 16 to become registered users of our platform and to use our services, without proven parental consent. Plum does not knowingly collect or solicit Personal Information about children under 16, except with their parent or guardian's express consent.

10. Residents of Nevada

Nevada law allows Nevada residents to opt-out of the sale of certain types of Personal Information. Subject to several exceptions, Nevada law defines "sale" to mean the exchange of certain types of Personal Information for monetary consideration to another person. Plum does not currently sell Personal Information as defined in the Nevada law. However, if you are a Nevada resident, you still may submit a verified request to opt-out of sales and we will record your instructions and incorporate them in the future if our policy changes. Opt-out requests may be sent to privacy@plum.io.

11. Residents of California

Plum does not disclose Personal Information obtained through our website, services, or platform to third parties for their direct marketing purposes. Accordingly, we have no obligations under California Civil Code § 1798.83.

12. Residents of the European Economic Area ("EEA") and the United Kingdom ("UK")

This section contains additional information that we as controller must communicate to individuals located in the EEA and the UK in case we process their Personal Information in relation to the offering of services to them or the monitoring of their behavior, pursuant to the European Union's general data protection regulation (the "EU GDPR") as applicable in the EEA and as retained in the laws of the UK further to the European Union (Withdrawal) Act 2018 (the "UK GDPR" and, together with the EU GDPR, the "GDPR").

For each purpose for which Personal Information may be processed, the corresponding legal basis under the GDPR is as follows:

Purpose

GDPR legal basis

Provide you with our services and the use of our website.

(i) For an individual customer, it is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

(ii) For an individual representing a customer, it is necessary for the purposes of the legitimate interests pursued by us in entering into and/or performing such contract.

Provide you with support and handle inquiries.

It is necessary for the purposes of the legitimate interests pursued by us in ensuring and improving the quality, security, and functionality of our services.

Improve the quality and functionality of the website, enhance your experience, create new services (including customized services), change/cancel existing services, or for statistical purposes.

It is necessary for the purposes of the legitimate interests pursued by us in ensuring and improving the quality, security, and functionality of our services.

If you, as a visitor to our website, so choose, to present you relevant content, marketing materials, and advertisements, by analyzing your interests from the web pages you visit and online services you use (users of our platform will not be subject to any ad tracking or targeted advertisements solely as a result of being a user).

(i) In case of use of cookies that are not strictly necessary for the operation of our website, you gave us your consent to store cookies on your terminal equipment and collect information from your terminal equipment for the purposes of improving our services;

(ii) Otherwise, it is necessary for the purposes of the legitimate interests pursued by us in marketing our services.

Communicate with you about our services, including updates or newsletters.

(i) For an individual potential customer receiving electronic solicitations who did not already purchase similar services from us, you gave us your consent;

(ii) In all other cases, it is necessary for the purposes of the legitimate interests pursued by us in marketing our services.

Conduct surveys and market research.

It is necessary for the purposes of the legitimate interests pursued by us in marketing our services.

Deliver content that may be of interest to you.

(i) In case of use of cookies that are not strictly necessary for the operation of our website, you gave us your consent to store cookies on your terminal equipment and collect information from your terminal equipment for the purposes of improving our services;

(ii) Otherwise, it is necessary for the purposes of the legitimate interests pursued by us in marketing our services.

Ensure that our website remains functioning and secure.

It is necessary for the purposes of the legitimate interests pursued by us in ensuring and improving the quality, security, and functionality of our services.

Generate anonymized or aggregated information, which we use for our business purposes at our sole discretion.

It is necessary for the purposes of the legitimate interests pursued by us in algorithms and services and contributing to industry reports and academic research.

Investigate, prevent, or act on any illegal activities or violations of our Terms of Service.

(i) It is necessary for the purposes of the legitimate interests pursued by us of asserting our legal rights;

(ii) Alternatively, it is necessary for the purposes of the legitimate interests pursued by law enforcement agencies.

Comply with any applicable law and assist law enforcement agencies as required.

(i) It is necessary for the purposes of compliance with a legal obligation to which the controller is subject;

(ii) Alternatively, it is necessary for the purposes of the legitimate interests pursued by law enforcement agencies.

Where the legal basis under the GDPR is consent, one has the right to withdraw his or her consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

We may make decisions based solely on automated processing which produces legal effects concerning you or similarly significantly affect you within the meaning of article 22 of the GDPR when we decide whether you pose a fraud or money laundering risk because our processing reveals that you display behavior consistent with money laundering or fraudulent conduct, that your behavior is inconsistent with your previous use of our services, or that you appear to have deliberately hidden your true identity. In relevant cases, we also check whether or not a specific customer is listed on a so-called sanction list. A record of any fraud or money laundering risk will be retained by the fraud prevention agencies, and may result in others refusing to provide services, financing or employment to you.

We may transfer your Personal Information outside the EEA and the UK to, in addition to Canada, the U.S.A. as well as other countries where such service providers are located. An adequacy decision from the European Commission pursuant to Directive 95/46/EC avails under article 45 of both the EU GDPR and the UK GDPR in case of transfers to private-sector organisations in Canada governed by the Personal Information Protection and Electronic Documents Act as well as organisations in Andorra, Argentina, Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Switzerland, Uruguay and (under the EU GDPR) the United Kingdom. In other cases, involving processing of Personal Information of individuals in the EEA or the UK subject to the GDPR, unless one of the exemptions of article 49 of the GDPR avails, appropriate safeguards are in place in accordance with article 46 of both the EU GDPR and the UK GDPR - namely standard contractual clauses as approved by the European Commission and/or, as the case may be, the UK government.

The GDPR grants data subjects certain rights such as the right to request from the controller access to and rectification or erasure of Personal Information or restriction of processing concerning the data subject and to object to processing as well as the right to data portability, it being noted that each of these rights can be exercised only if certain conditions set forth in the GDPR are met. Data subjects also have the right to lodge a complaint with a supervisory authority.

13. Residents of Mexico

Un aviso de privacidad que cumple con las leyes mexicanas está disponible en Aviso De Privacidad: www.plum.io/privacy-mexico.

14. Residents of Canada

Under certain circumstances and subject to applicable data protection laws, you may also be entitled to request additional information regarding our data governance practices, including details regarding what information is collected about you, the categories of persons who have access to your information, and how long your information will be retained for. You may also be entitled to request that we cease communicating your information, or de-index any hyperlink attached your name that provides access to your personal information by a technological means.

15. How We Make Updates to This Privacy Policy

We may update this Privacy Policy from time to time in order to reflect changes to our privacy practices or for other operational, legal, or regulatory reasons. Therefore, we recommend that you read it periodically. If we make material changes to this Privacy Policy, we will post the revised policy on this Website. By continuing to use Plum services after these changes are posted, you agree to the revised policy.

16. How to Contact Us for More Information

If you have any questions about your Personal Information or this policy, or if you would like to make a complaint about how Plum processes your Personal Information, please contact Plum by email at privacy@plum.io or by using the contact details below:

Plum.io Inc.
ATTN: Data Protection Office
151 Charles St. W. Suite 100
Kitchener, Ontario N2G 1H6
Canada

Plum will work with users to resolve any concerns users have about this Privacy Policy. If we are unable to resolve your privacy concerns, you may have the right to complain to the relevant data supervisory/regulatory authority in your jurisdiction of residence.