This policy is a working draft for legal review before launch. It records the product rules currently agreed for AppHR World and must be finalized with legal counsel.
Public website boundary
The public website explains the AppHR World model and routes visitors toward the secure account area. It must not publish candidate contact data, documents, passport data, city of origin, private profile fields, unlock status, dossier status, or operational logs.
Private platform data
The platform will store candidate profiles, documents, employer unlocks, agency consent, dossier workflows, billing state, verification logs, and administrative decisions. Access is role-based and follows unlock and consent rules.
Candidate documents
Documents are private. Employers and agencies can receive access only inside the platform and only after the candidate grants the required consent for that context.
Retention principles
Candidate documents can be deleted when deletion rules allow it. Some forms, logs, billing records, and legal audit traces may be retained for defined periods where required by law, fraud prevention, accounting, or legitimate operational need.