HR Policy 116: Recruitment Privacy Policy


 

1.0 Purpose

1.1 Aviation Training Consulting, LLC. ("we," "us," or "our") is committed to safeguarding the personal information of individuals who apply for employment with us. This policy explains how we collect, use, store, and protect candidate information, with consideration for applicable U.S. privacy laws, the California Consumer Privacy Act (CCPA/CPRA), and federal cybersecurity standards outlined in CMMC 

2.0 Level 2 / NIST SP 800-171.


2.0 Scope

2.1 This policy applies to all candidate-facing websites, job portals, and submission forms. It governs the handling of personally identifiable information (PII) and other sensitive data collected during the recruitment process, including information that may qualify as Controlled Unclassified Information (CUI) under DoD contracts.


3.0 Policy- Recruitment  and Candidate Privacy

3.1 Information We Collect

We may collect the following categories of personal information:

• Identifiers (e.g., full name, mailing address, email, phone number)

Government-issued IDs (e.g., SSN, driver’s license, passport)

• Employment & Education History (e.g., resumes, certifications)

• Demographic Information (optional; for compliance reporting)

• Device Data (e.g., IP address, browser fingerprint from job portal)

• Audio/Video Data (e.g., interviews, recorded assessments)


All collected information is subject to Access Control and Audit Requirements in accordance with NIST SP 800-171 to ensure confidentiality, integrity, and traceability.

 

3.2 Use of Collected Information

We apply technical and administrative safeguards to protect your data, including but not limited to:

• Role-based access controls 

• Encryption at rest and in transit 

• Centralized logging and event tracking 

• Secure system configurations and vulnerability management

Data collected is retained only as long as necessary per Retention Policy Controls and securely disposed of using NIST-compliant methods.


3.3 Data Protection and Security Controls

We apply technical and administrative safeguards to protect your data, including but not limited to:

• Role-based access controls 

• Encryption at rest and in transit 

• Centralized logging and event tracking 

• Secure system configurations and vulnerability management 

Data collected is retained only as long as necessary per Retention Policy Controls and securely disposed of using NIST-compliant methods.


3.4 Third-Party Access and Data Sharing

• We may share candidate information with:

• Authorized background screening vendors and HR service providers

• Government authorities as required by law or contract

DoD customers or auditors for verification of compliance-related qualifications Data collected is retained only as long as necessary per Retention Policy Controls and securely disposed of using NIST-compliant methods.


3.5 Retention and Disposal

• Personal data will be retained only for as long as necessary to fulfill the purpose of the recruitment process or as required by law.

• Candidates may request the deletion of their data at any time, subject to legal obligations and company policies.

 

Candidate information is retained in accordance with applicable DoD contract requirements and CUI handling rules. When no longer needed, data is sanitized or destroyed per NIST SP 800-88 standards and documented in accordance with our audit policies.

 

3.6 Your Privacy Rights

You may request to:

• Candidates have the right to access, rectify, or delete their personal information held by the company.

• Candidates can withdraw their consent for data processing at any time, which may impact their application process.

• Candidate may request a copy of their submitted information.

 

Requests can be submitted via email to: atc-hr@atc-hq.com. To ensure the security and integrity of CUI/PII, all such requests will be processed with identity verification.


3.7 California Residents – CCPA/CPRA Rights

California residents may:

• Know what categories of personal data we collect and for what purpose.

• Request correction or deletion of your personal data.

• Opt-out of sharing or selling of sensitive information.

• Limit use of sensitive information to authorized, contract-specific purposes.

• Non-discrimination for exercising your rights.


 

To exercise these rights, email atc-hr@atc-hq.com or call 405-443-3970. For more details, see the California Privacy Notice: https://oag.ca.gov/privacy/ccpa


4.0 Changes and compliance reviews


4.1 Information We Collect

We may collect the following categories of personal information:

• The company will regularly review and update this policy to ensure ongoing compliance with relevant data protection laws and best practices.

• All employees involved in recruitment will receive training on privacy principles and data protection responsibilities.


5.0 Contact Information


5.1 As a candidate for employment, you may contact:

Human Resources

Aviation Training Consulting, LLC

123 W. Commerce St. Suite 424

Altus, OK 73522

atc-hr@atc-hq.com

405-443-3970