Skip to content
ATSCheck
Back to ATSCheck

Legal

Privacy Policy

How EmKeTech handles personal data in ATSCheck: what we collect, why, where it is stored, who we share it with, how long we keep it, and the rights you have.

Last updated: 15 September 2026

1.Who we are

ATSCheck (atscheck.emketech.com) is a product of EmKeTech. In this policy, “EmKeTech”, “we” and “us” mean the company that provides ATSCheck, and “you” means anyone who visits the website or uses the service.

For personal data processed to provide ATSCheck to its own users, EmKeTech is the controller.

Please send any privacy question or request through our support form.

When an organisation uses ATSCheck HR to review candidates, that organisation is the controller of the candidate data and EmKeTech processes it on the organisation’s behalf. See HR customers and candidate data.

2.Scope of this policy

This policy covers the ATSCheck website, the ATSCheck application and the emails we send about it, across every plan and the Curated service. It explains what personal data we process, why, on what legal basis, who we share it with, how long we keep it and the rights you have.

It does not cover other EmKeTech products, which keep separate accounts and data, or websites operated by others that we link to, including the payment processor’s checkout page, which is covered by that provider’s own privacy notice.

How ATSCheck uses cookies and browser storage is described in more detail in the Cookie Policy.

3.Personal data we process

CategoryWhat it includes
Account detailsYour name, email address, whether your email address is confirmed, the version of the Terms you accepted and when, your plan, and your choice about product news emails. Your password is never stored; we keep only a one-way cryptographic hash of it.
Sign-in and security settingsWhether two-factor authentication is on and which method you use (authenticator app or email codes), the encrypted authenticator secret, one-way hashes of recovery codes, sign-in records (session identifiers stored only as hashes, browser description, times), failed sign-in counters and temporary lockouts.
Resumes (CVs)Files you upload or text you paste, each saved version, the text and structure extracted from them, and file details such as name, type and size. Resumes can contain contact details, work history, education and anything else you choose to include.
Job descriptionsJob postings you paste or save, and the requirements ATSCheck extracts from them.
Analyses and scoresATS compatibility findings, job-match and requirement scores, evidence quotes from your resume, recommendations, rewrite suggestions, and any feedback you give on a result.
Cover lettersCover letters generated for you, the preferences you give (such as tone or instructions) and any edits you save.
Curated requestsThe target role, the optional job description, the optional link to your LinkedIn profile, a text copy of the CV you choose to share, your notes, your recorded consent, the CV wording, cover letters and LinkedIn text our team drafts for you, and the message thread between you and the ATSCheck team.
HR workspace dataWorkspace name and settings, members and their roles, team invitations (the invited email address and a hashed invitation token), job openings and confirmed requirements, assignments, comments and team activity.
HR candidate dataCandidate details added by an organisation (such as name, email, phone, location, source and tags), candidate resumes and files, analyses, comparisons, suggested interview questions, pipeline stages and their history, and recruiter notes.
Billing informationYour plan, subscription status, renewal and cancellation dates, and the payment processor’s customer, subscription and invoice references. Complimentary access and redeemed promo codes are recorded against your account. Card details are entered on the payment processor’s page and never reach ATSCheck.
Security, audit and usage recordsRecords of security-relevant events (for example sign-ins, password and two-factor changes, permission changes, data exports and staff access), usage counters for plan limits, and records of which AI features ran and at what cost. These records do not contain document content.
Abuse-prevention dataA keyed, one-way hash of your IP address used briefly to limit repeated attempts, and the signals processed by the security check on the sign-up and password reset pages (see Cookie Policy).
Emails and supportEmails you send to support and our replies, and a record of the service emails we send you.

ATSCheck does not ask for special category data (such as health, ethnic origin, religion, political opinions or sexual orientation). Please leave it out of the resumes and notes you add. ATSCheck’s analysis is instructed to disregard protected characteristics.

4.Where the data comes from

  • From you, when you create an account, upload or paste documents, use features, contact support or pay.
  • From an organisation using ATSCheck HR, when it adds you as a candidate or invites you to its workspace.
  • From an ATSCheck administrator, when we create an account for you (for example for a customer organisation), in which case we email you so you can sign in and set your own password.
  • From our payment processor, which tells us whether a payment succeeded and the status of your subscription.
  • Generated by ATSCheck, such as analyses, scores, suggestions and security records.

5.Why we use it and our legal bases

PurposeLegal basis (GDPR Article 6)
Providing ATSCheck: creating and running your account, analysing resumes and job descriptions, producing scores, suggestions, rewrites and cover letters, keeping your library and history, running HR workspaces and invitations, and exporting your data.Performance of our contract with you (6(1)(b)).
Delivering the Curated service: members of the ATSCheck team reading the CV, LinkedIn profile and details you share for a request, curating and optimising your CV, drafting cover letters and LinkedIn profile text on your behalf, and replying to you.Performance of our contract with you (6(1)(b)). We also ask for your explicit agreement before a request is sent, so you decide exactly what the team may read.
Subscriptions and payments: taking payment, applying your plan, promo codes and complimentary access, and sending receipts and billing notices.Performance of our contract with you (6(1)(b)).
Service and security emails: email confirmation, password reset, sign-in codes, alerts about security changes, invitations, analysis-ready notices and Curated reply notices.Performance of our contract (6(1)(b)) and our legitimate interest in keeping accounts secure (6(1)(f)).
Keeping ATSCheck secure: confirming email addresses, two-factor authentication, session management, the security check on the sign-up and password reset pages, rate limiting, account lockouts, audit logging and investigating errors and misuse.Legitimate interests (6(1)(f)) in protecting accounts, data and the service from fraud, abuse and automated attacks, which also supports our security obligations under Article 32.
Enforcing plan limits and fair use, and understanding the cost and reliability of features using records that contain no document content.Legitimate interests (6(1)(f)) in operating and improving a sustainable service.
Keeping accounting and tax records.Legal obligation (6(1)(c)).
Responding to support requests and to requests to exercise your rights.Performance of our contract (6(1)(b)) and legal obligation (6(1)(c)).
Establishing, exercising or defending legal claims.Legitimate interests (6(1)(f)).
Occasional product news emails.Consent (6(1)(a)). The option is off unless you turn it on in your account settings, and you can turn it off at any time.

Where we rely on legitimate interests, we have balanced them against your rights and reasonable expectations, and we keep the data involved to the minimum. You can object to this processing; see Your rights.

If you do not provide the data a feature needs, such as your email address or the resume you want analysed, we cannot provide that feature.

6.AI processing

ATSCheck uses AI for some features, with safeguards designed into how it works:

  • ATS compatibility checks, requirement extraction and all score calculations are carried out by ATSCheck’s own rules. AI does not set scores.
  • An AI service provider, acting as our processor, helps classify evidence against job requirements and drafts recommendations, rewrite suggestions, cover letters, candidate summaries and interview questions.
  • Only the document text needed for the task you request is sent. Contact details at the top of a resume (such as name, email, phone, links and address) and lines containing other personal details are withheld, and candidate names are not sent for analysis.
  • If you upload a PDF that contains no readable text, such as a scanned document, and your plan includes reading scanned files, the pages of that file are sent to the AI service provider so the text can be read.
  • Your content is not used to train AI models, by EmKeTech or by the AI service provider. The provider processes it to return a result and may keep it only for a limited period under our agreement, for example for security and abuse monitoring.
  • AI output is checked before you see it: evidence quotes must match your resume text, and generated writing is checked for claims your resume does not support.

The AI service provider is based outside the European Economic Area; see International transfers. More detail is on the AI transparency page.

7.Scores and automated decision-making

ATSCheck calculates scores and evidence statuses automatically. They are guidance: they describe how a document reads and what evidence it contains for a job’s requirements. They do not predict whether you will be invited to an interview or hired.

ATSCheck does not make decisions that have legal or similarly significant effects on anyone within the meaning of Article 22 GDPR. It does not make hiring decisions, never automatically rejects, ranks out or moves a candidate, and does not assess personality or “culture fit”. In ATSCheck HR, only a person in the organisation can change a candidate’s stage.

Organisations using ATSCheck HR must keep meaningful human review of every hiring decision and must not rely on ATSCheck outputs as the only basis for a decision about a candidate.

8.The Curated service

Curated is a service delivered by people: you can ask the ATSCheck team to curate and optimise your CV, draft cover letters and optimise your LinkedIn profile for the roles you are targeting. This is the one part of ATSCheck where people on our team read your content.

  • Before a request is sent, you choose the CV text to share and confirm that the ATSCheck team may read it. You can also give us a link to your LinkedIn profile and a target job description, if you want those included. We keep a text copy of what you shared with the request, together with the date of your agreement.
  • We draft CV wording, cover letters and LinkedIn profile text on your behalf and send them to you in the request. What you do with a draft is your decision; nothing is published or sent anywhere for you.
  • Only authorised ATSCheck team members working on requests can open them, and every time a team member opens a request it is recorded in our audit log.
  • Replies are shown in your account. We email you a notice that a reply is waiting, without the reply itself.
  • You can ask us to close a request and delete what you shared at any time through our support form. This does not affect work already done.

9.HR customers and candidate data

When an organisation adds candidates to ATSCheck HR, the organisation is the controller of that candidate data and EmKeTech processes it on the organisation’s behalf as a processor, following the organisation’s instructions.

  • The organisation is responsible for having a lawful basis to process candidate data and for telling candidates how their data is used, including that ATSCheck is used.
  • The organisation decides how long candidate data is kept. A workspace owner can set candidates to be deleted automatically after 3, 6, 12 or 24 months without activity, or keep them until they are deleted manually. Authorised members can delete a candidate, a job or the whole workspace at any time.
  • Access to a workspace is limited to its active members, according to the roles the organisation assigns.
  • The organisation must keep human review of hiring decisions.
  • EmKeTech uses candidate data only to provide the service to that organisation, never for its own purposes and never to train AI models.

Team invitations are sent by email to the address the organisation enters. Unused invitations expire after 7 days. A data processing agreement is available on request through our support form.

If you are a candidate and want to exercise your rights over data an organisation added, please contact that organisation. If you contact us instead, we will pass your request to the organisation or help you reach it.

10.Access by ATSCheck staff

A small number of authorised ATSCheck administrators operate the service. Their access is limited and recorded:

  • Administrators can see account information needed to support customers and run the service: name, email address, plan and subscription status, account status, whether two-factor authentication is on, sign-in dates, and counts of usage.
  • The administration tools do not show the content of your resumes, job descriptions, analyses, cover letters or HR candidate data. The only content staff can read is what you share in a Curated request.
  • Administrators can, where needed, create an account (you then receive an email to choose your own password), disable or re-enable an account, grant complimentary access, or delete an account. Administrators never set, see or know your password.
  • Administrator actions are recorded in an audit log, and administrator accounts must use two-factor authentication.

11.Who we share data with

We use the following categories of service provider to run ATSCheck. Each acts as our processor under a written agreement, may use the data only to provide its service to us, and must keep it secure. The current list of service providers is available on request through our support form.

Category of providerWhat it doesData involvedLocation
Hosting and infrastructureRuns the website and applicationData passing through the application while a request is handled; operational logs that exclude document contentApplication processing in the EU (Ireland). Public website files may be delivered from a global network.
Database hostingStores all application data, including uploaded filesAll account, library, workspace and candidate dataEU (Ireland)
AI service providerAI-assisted features described aboveMinimised document text and job requirements; scanned PDF pages where neededUnited States
Payment processorCheckout, subscriptions, invoices and receiptsName, email, billing address, payment details (collected directly by the processor), subscription and invoice recordsMay process data outside the EEA
Transactional email deliverySends service, security and billing emailsYour email address and the email content (never resume or candidate content)May process data outside the EEA
Bot protectionRuns the security check on the sign-up and password reset pagesIP address and browser and device signalsGlobal network

The payment processor collects your payment details on its own secure page. For some purposes, such as preventing payment fraud and meeting its own legal obligations, it acts as an independent controller under its own privacy notice, which is available on the checkout page.

We may also disclose personal data:

  • to members of an HR workspace, for data that belongs to that workspace;
  • to professional advisers, such as lawyers and accountants, under a duty of confidentiality;
  • where required by law, or to a court, regulator or law enforcement authority with a valid legal request; and
  • to a buyer or successor if EmKeTech’s business or ATSCheck is reorganised or sold, in which case this policy continues to protect your data.

We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use it for advertising.

12.International transfers

ATSCheck’s database and application processing are hosted in the EU (Ireland). Some service providers, or their sub-processors, process data outside the European Economic Area, in particular the AI service provider, which is based in the United States.

Where personal data is transferred outside the EEA, the transfer relies on appropriate safeguards under Chapter V of the GDPR, such as the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies (for example, the EU–US Data Privacy Framework for certified providers). We also limit what is transferred, as described in AI processing.

You can ask for more information about these safeguards, or a copy of them, through our support form.

13.How long we keep data

We keep personal data only as long as we need it for the purposes above. An automated job runs every day to delete data that has reached the end of its retention period.

DataHow long we keep it
Free plan analyses and results30 days, then deleted automatically.
Free plan resumes and job descriptionsUploaded files are not kept; only the extracted text is. That text and any unsaved job description are deleted once no analysis uses them (at the latest when the related analysis expires).
Saved resumes, files, jobs, analyses and cover letters (paid plans)Until you delete them or delete your account.
Account details and security settingsFor as long as your account exists.
Sign-in sessionsA session ends after 30 days, after 72 hours without activity, or when you sign out. Records of ended sessions are deleted 30 days after the sign-in.
Email confirmation links, password reset links and sign-in codesLinks for confirming your email address expire after 48 hours, password reset links after 60 minutes and sign-in codes after 10 minutes. All are deleted 1 day after they expire.
Rate-limiting records (hashed IP address)1 day.
Daily usage counters for plan limits60 days.
Security and audit records; AI usage records400 days (about 13 months), then deleted automatically.
Billing event records400 days. Your current plan and subscription status are kept for as long as your account exists.
Invoices and payment recordsHeld by the payment processor, and kept for as long as tax and accounting law requires (in Ireland, generally six years from the end of the relevant financial year).
HR candidate dataAccording to the retention period the organisation sets (3, 6, 12 or 24 months without activity), or until an authorised member deletes it.
HR workspaces, jobs, notes and team activityUntil the workspace or item is deleted. Activity records follow the 400-day period above.
Unused team invitationsExpire after 7 days; expired or revoked invitations are deleted 60 days after they were sent.
Curated requests and messagesUntil you ask us to delete them or you delete your account.
Complimentary access and redeemed promo codesFor as long as your account exists. When you delete your account, the promo code record is no longer linked to you.
Support emailsFor as long as we need them to handle your request and any follow-up. You can ask us to delete them at any time.
BackupsDeleted data can remain in encrypted database backups kept by our hosting provider until those backups expire in their normal cycle. Backups are used only to restore the service.

14.Deleting your data and your account

  • You can delete individual resumes, resume versions, saved jobs, analyses and cover letters at any time in ATSCheck.
  • You can delete your account yourself in your account settings. Any active subscription is cancelled first, so you are not charged again. Your account and everything in your personal library are then deleted immediately.
  • If you own an HR workspace, you need to transfer ownership or delete the workspace before deleting your account, so that an organisation’s candidate data is never removed without its decision.
  • ATSCheck administrators can also delete an account, for example at your request or where our Terms allow it. The deletion is recorded in our audit log.
  • After deletion we keep only what we must: a content-free audit record that an account was deleted (not linked to you), AI usage records with your account link removed, and payment records held by the payment processor for legal reasons.

15.How we protect data

We use technical and organisational measures appropriate to the risk, including:

  • Hosting in the EU, with database-level access controls that keep each account’s data and each workspace’s data separate.
  • Encrypted connections (HTTPS) between your browser and ATSCheck.
  • Private files served only through links that expire after 60 seconds.
  • Passwords stored only as one-way hashes; authenticator secrets stored encrypted; tokens and codes stored only as hashes.
  • Email confirmation before first sign-in, optional two-factor authentication (authenticator app or email codes) with recovery codes, and alerts when security settings change.
  • A security check against automated abuse on the sign-up and password reset pages; rate limits and temporary lockouts after repeated failed attempts, on every sign-in as well.
  • Sign-in cookies that cannot be read by scripts on the page.
  • Logs that record events but never document content, names, email addresses or passwords.
  • Limited, audited staff access, as described in Access by ATSCheck staff.

No system is completely secure. If a personal data breach occurs, we will act in line with our obligations under the GDPR, including notifying the supervisory authority and affected people where required. See Data & Security for more detail.

16.Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectification of inaccurate or incomplete data. You can update your name in account settings; to change your email address, contact support from your current address.
  • Erasure of your data. You can delete content and your account yourself, as described in Deleting your data.
  • Restriction of processing in certain circumstances, for example while we check a disputed request.
  • Data portability: to receive the data you provided in a structured, machine-readable format. You can download a JSON export of your account data from your account settings.
  • Object to processing based on our legitimate interests.
  • Withdraw consent at any time where we rely on it, such as product news emails or what you shared in a Curated request, without affecting processing before withdrawal.

How to exercise them. Many rights can be used directly in your account settings. For anything else, contact us through our support form and give your account email address. We may ask you to confirm your identity before acting. We will respond within one month of receiving your request; for complex or numerous requests this can be extended by up to two further months, and we will tell you if that happens. Exercising your rights is free unless a request is manifestly unfounded or excessive.

Complaints. We would like the chance to resolve any concern first, but you have the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live, work or where you believe an infringement occurred. In Ireland the authority is the Data Protection Commission (www.dataprotection.ie).

17.Cookies and browser storage

ATSCheck uses only strictly necessary first-party cookies: atscheck_session keeps you signed in, atscheck_ws remembers your selected HR workspace, and atscheck_mfa holds a pending two-factor sign-in for up to 10 minutes. ATSCheck HR also remembers your focus-mode preference in your browser’s local storage.

We use no analytics, advertising or marketing cookies, which is why there is no cookie consent banner. The full details, including the security check on the sign-up and password reset pages, are in the Cookie Policy.

18.Children

ATSCheck is intended for job seekers and hiring teams and is not intended for anyone under 16. We do not knowingly collect personal data from children under 16. If you believe a child has created an account, contact us through our support form and we will delete it.

19.Changes to this policy

We update this policy when ATSCheck or the law changes, and change the “Last updated” date above. If a change is material, we will tell account holders by email or in the application before it takes effect.

20.Contact

For questions about this policy or your personal data, or to ask for the current list of service providers, contact us through our support form.