Privacy Policy, StepsConnect
Website, ATS platform and related services
Version 2.0, last updated: 25/01/2025
This Privacy Policy explains how STEPS SRL, trading as StepsConnect ("StepsConnect", "we"), processes personal data when you use:
hire.stepsconnect.com may host our clients' career pages and application flows. The privacy notice addressed to candidates is provided by each client company, acting as Data Controller.
app.stepsconnect.com is the environment candidates use to manage their application and related communications, where enabled by the client.
Important for candidates. When you apply for a position published by a company that uses StepsConnect, the Data Controller is the client company running the recruitment process. StepsConnect processes candidate data as Data Processor, on behalf of that company and on its instructions.
How to read this policy
- If you visit our website or contact us: sections 3.1, 5, 14 and 15.1.
- If you are a client company or a platform user: sections 2.1, 3.2, 5, 6, 11 and 15.1.
- If you are a candidate: sections 2.2, 3.3, 7, 8, 13 and 15.2.
1. Data Controller and contact details
2. Scope and privacy roles
2.1 Processing where StepsConnect acts as Data Controller
StepsConnect acts as Data Controller when it processes personal data for:
- browsing and security of the website and portals;
- handling demo requests, contact requests and pre-contractual or commercial communications;
- entering into and performing the contract with the client company;
- creating and managing accounts and access rights for users enabled by the client, for registration, security, support and service administration purposes.
This covers the data of the client's legal representative and of its commercial, administrative and technical contacts, as well as the data of the users the client enables to access the platform.
2.2 Processing where StepsConnect acts as Data Processor
When a candidate applies for a position managed through the StepsConnect platform, StepsConnect processes the candidate's data as Data Processor, on behalf of the client company acting as Data Controller. Purposes, legal bases and retention periods for candidate data are determined by the client company, which provides candidates with its own privacy notice through the application form or career page.
3. Categories of personal data processed
3.1 Website visitors and commercial contacts
- identification and contact data: name, email, phone number, company and role;
- content of requests submitted through forms or by email;
- technical data: IP address, device and browser, logs and security data;
- cookie preferences, including the granular choices you make.
3.2 Clients and platform users
- identification and contact data of the client's representatives;
- account data: name, email, credentials managed by the authentication system, application role and permissions assigned by the client;
- access and usage logs, kept as an audit trail and record of security events;
- support data: content of tickets and operational communications;
- administrative and accounting data relating to the client and its representatives.
3.3 Candidates, on behalf of the client
- data entered in the application form: contact details and professional information;
- CV, attachments and answers to the screening questions configured by the client.
StepsConnect does not require the collection of special categories of personal data under Article 9 GDPR. The fields and information requested from candidates are defined and managed by the client, in compliance with applicable law.
4. Sources of personal data
- Directly from the data subject, when you complete a form on our website, contact us, use the platform as a client's user or, as a candidate, submit information and attachments through a client's application form.
- From the client, when it creates or manages the accounts of enabled users and when it configures workflows, forms and fields of the recruitment process.
- From third parties chosen by the client, through the enabled integrations, for example job boards from which StepsConnect receives applications.
5. Purposes, legal bases and retention
The table below covers processing where StepsConnect acts as Data Controller. For candidate data, processed as Data Processor, purposes, legal bases and retention are determined by the client company.
| Purpose |
Legal basis |
Retention |
| Handling demo requests, contact requests and pre-contractual communications |
Art. 6(1)(b), pre-contractual measures |
24 months from closure of the request, unless a contractual relationship is entered into |
| Managing commercial relationships and organising contacts in the CRM |
Art. 6(1)(f), legitimate interest in commercial activity |
24 months from the last meaningful contact, unless a contractual relationship is entered into |
| Entering into and performing the contract with the client, and operational communications |
Art. 6(1)(b), performance of a contract |
Term of the contract, then as required by law |
| Creating and managing accounts, access control and permissions |
Art. 6(1)(b), performance of a contract, and Art. 6(1)(f), security |
Term of the contract and up to 24 months after termination |
| Technical support and ticket management |
Art. 6(1)(b), performance of a contract |
24 months from closure of the ticket |
| System security, fraud and abuse prevention, incident management, technical logs |
Art. 6(1)(c) and Art. 6(1)(f), legal obligation and legitimate interest in security |
Application audit logs 180 days. Encrypted backups with 30-day retention |
| Accounting, tax obligations, contract and dispute management |
Art. 6(1)(c), legal obligation, and Art. 6(1)(f), establishment or defence of legal claims |
10 years under Article 2220 of the Italian Civil Code |
| Managing applications through the ATS platform |
Determined by the Data Controller, that is the client company |
Determined and configurable by the client company. Limited technical copies, such as backups, according to the service policy |
At the end of the periods indicated, data is deleted or anonymised, unless retention is required by a legal obligation or is necessary to establish, exercise or defend a legal claim.
6. Whether providing data is mandatory
Providing the data indicated as necessary to enter into the contract, to enable accounts and to deliver the service is a contractual requirement: refusal makes it impossible to activate the relationship or to grant access to the platform. Providing data for optional commercial purposes is voluntary and refusal has no consequences on the performance of the contract.
7. Artificial intelligence features
The platform offers AI-based support features, for example semantic candidate search, application tagging, summaries of previous experience and job description drafting. These are assistive tools, always accompanied by an equivalent non-AI feature, and can be switched off by the client at any time.
- Single provider and location. All AI features are delivered through Google Vertex AI in the europe-west1 region (Belgium). Candidate data is not transferred outside the European Economic Area for these purposes.
- No training. Data sent to the provider is not used to train or fine-tune any model. This is a binding contractual guarantee.
- Minimisation. Before any transmission to the provider, CV text undergoes technical removal of direct identifiers such as name, email, phone number, tax code and address.
- No automated decision-making. AI outputs are assistive and non-binding. No action in the recruitment process follows automatically from an AI output without an assessment by the recruiter.
8. WhatsApp channel, optional feature
StepsConnect may provide a WhatsApp-based feature, through Meta infrastructure, to support parts of the recruitment process, for example application-related communications, screening questions and interview scheduling. The feature is disabled by default and must be expressly enabled by the client company.
Where the channel is used:
- the client company, as Data Controller, is responsible for providing the privacy notice to candidates and for collecting opt-in before starting any communication;
- the contractual relationship is with Meta Platforms Ireland Ltd; transfers to Meta group companies in the United States take place under the Standard Contractual Clauses 2021/914, processor-to-processor module, set out in the WhatsApp Business Data Transfer Addendum, and Meta adheres to the EU-US Data Privacy Framework;
- Meta retains messages for a maximum of 30 days, for delivery and retransmission purposes. Once received, messages are stored on the platform within the EU;
- Meta does not use message content for advertising or profiling purposes and does not apply its own artificial intelligence features to it.
9. Job board integrations
StepsConnect sends job boards only the data of the job posting and receives applications according to the integrations enabled by the client. Job boards are selected by the client, which is their contractual counterparty; StepsConnect acts as technical integrator within the ATS service.
10. Recipients and sub-processors
Data is processed by authorised StepsConnect personnel, instructed under Article 29 GDPR, and may be disclosed to the providers of services necessary to operate the platform and manage the relationship.
| Recipient |
Service |
Role and location |
| Google Cloud EMEA Limited |
Cloud infrastructure, database, AI inference, logs, backups, authentication |
Processor under Art. 28. Database and application services in the EU. Firestore eu3 and europe-west1. Firebase Authentication on US infrastructure |
| Elasticsearch B.V. |
Vector storage for semantic search indexes |
Processor under Art. 28. Elastic Cloud on GCP europe-west1, EU |
| Vercel Inc. |
Frontend hosting and delivery |
Processor under Art. 28. EU region configured, Frankfurt. Company incorporated in the United States |
| Meta Platforms Ireland Ltd |
WhatsApp messaging channel, only in deployments where it is enabled |
Processor under Art. 28. EU contract, group infrastructure in the United States |
| CRM, communication and support service providers |
Management of commercial contacts and support tickets |
Processors under Art. 28 |
| Accounting and employment consultants, legal advisers |
Administrative and tax obligations, defence of legal claims |
Processors or independent controllers depending on the service provided |
| Public authorities and supervisory bodies |
Obligations provided for by law |
Independent controllers |
An up-to-date list of sub-processors, including names, is available on request at admin@stepsconnect.com or at the certified email address indicated in section 1. Data is not disseminated and is not sold or transferred to third parties for their own marketing purposes.
11. International transfers
Processing normally takes place within the European Union. Candidate data and all AI processing remain entirely within the EU. The following transfers are in place, covered by appropriate safeguards:
| Component |
Destination |
Categories of data |
Safeguards |
| Firebase Authentication (Google) |
United States |
Account identifiers and credentials managed by the provider |
Standard Contractual Clauses 2021/914 included in the Google Cloud DPA, plus supplementary measures. Regionalisation of the service is on the roadmap |
| Vercel Inc. |
EU, company incorporated in the United States |
Technical metadata for frontend delivery |
EU region configured. Standard Contractual Clauses 2021/914 included in the provider's DPA |
| WhatsApp Business API (Meta), only where the channel is enabled |
United States, Meta group |
Phone number, message content and any attachments |
Contract with Meta Platforms Ireland. Standard Contractual Clauses 2021/914, processor-to-processor module, and Meta's adherence to the EU-US Data Privacy Framework |
The transfer relating to authentication is structural and concerns account data only, which is distinct from candidate data, and the latter remains within the EU.
12. Security measures
StepsConnect implements appropriate technical and organisational measures under Article 32 GDPR, including:
- encryption in transit with TLS 1.2 or higher and encryption at rest across the cloud infrastructure;
- role-based access controls and multi-factor authentication on administrative and privileged access;
- logical multi-tenant segregation of data by client;
- application audit logs retained for 180 days and encrypted backups with 30-day retention;
- vulnerability management with defined remediation times, 15 days for high and critical findings, 45 days for medium, 90 days for low;
- penetration testing carried out by an independent third-party provider;
- ISO/IEC 27001 certification process under way.
In the event of a personal data breach affecting processing carried out as Data Processor, StepsConnect informs the client company in accordance with the terms and procedures set out in the contract.
13. Automated decision-making
Data processed by StepsConnect as Data Controller is not subject to automated decision-making, including profiling, producing legal effects or similarly significantly affecting data subjects under Article 22 GDPR.
As regards candidates, the platform's AI features are assistive: they do not automatically exclude candidates, do not produce suitability scores and do not determine progression through the recruitment process, which always remains a decision of the client company's recruiter.
14. Cookies and similar technologies
The website uses technical cookies, strictly necessary for operation and security, and analytics or marketing cookies, activated only with express consent given through the banner. If you refuse non-essential cookies, only technical, security and functional cookies remain active. Your choices can be changed at any time through the "Cookie settings" link on the website, where categories, durations and providers are also listed.
15. Your rights
15.1 Website visitors, commercial contacts, clients and platform users
You may exercise at any time the rights provided for by Articles 15 and following of the GDPR: access, rectification, erasure, restriction of processing, data portability where applicable, objection to processing based on legitimate interest, and withdrawal of consent where processing is based on consent, without affecting the lawfulness of processing carried out beforehand.
Requests should be sent to admin@stepsconnect.com or to the certified email address steps.edu@legalmail.it. We respond within one month of receipt, a period that may be extended by two further months for complex or numerous requests, with notice to the data subject. We may ask you to verify your identity before acting on the request.
15.2 Candidates
If you applied for a position managed by a company that uses StepsConnect, your rights must be exercised towards that company, which is the Data Controller. Requests received directly by StepsConnect are forwarded to the client company and handled within the limits of our role as Data Processor.
16. Lodging a complaint with a supervisory authority
If you consider that the processing of your personal data infringes applicable law, you may lodge a complaint with the competent supervisory authority. In Italy: Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, garante@gpdp.it, certified email protocollo@pec.gpdp.it. This is without prejudice to your right to bring proceedings before the courts.
17. Updates and versioning
This Privacy Policy may be updated to reflect regulatory, organisational or service changes. The most recent version is always available on this page, showing the version number and the date of the last update.
The policy is made available to users during registration to the platform, as a condition for account activation. StepsConnect keeps a record of acknowledgement, including user identifier, date and time and the version of the policy. Material changes are notified to the client company's representatives at the contact details set out in the contract.
This English version is provided for convenience. In case of discrepancy, the Italian version of this Privacy Policy prevails.