Quiet Hire — by The Quiet Engine

Privacy notice

Last updated 22 July 2026

Who we are

Quiet Hire is a recruitment assessment tool operated by The Quiet Engine (Victoriam Sales Ltd, trading as The Quiet Engine), contactable at enquiries@quiet-engine.co.uk.

Two roles: the hiring team and us

If you are a candidate, the hiring team that invited you (the company named on your assessment or interview page) decides why and how your information is used — they are the data controller. Quiet Hire processes your information only on that team's behalf, as their data processor. Questions or requests about your data should go to the hiring team first; you can also contact us and we will pass your request to them.

If you hold a workspace account (a hiring team member), The Quiet Engine is the controller of your account details (name, business email, sign-in records).

What we process about candidates

  • Contact details the hiring team enters (name, email) and their notes.
  • Your CV file and the text extracted from it.
  • Your assessment answers, scores and review outcomes.
  • Where an assessment is proctored (you are always told, and asked, first): webcam snapshots taken during the assessment, recorded video answers, and an event log (for example when the tab loses focus).
  • Interview slot bookings you make through your invitation link.

Where AI is used to read a CV, it extracts verbatim quotes from the CV against the role's scoring criteria or records that no evidence was found — scores are computed arithmetically from that evidence. No AI decision rejects a candidate: every advance/reject decision is made by a person on the hiring team.

How long we keep candidate data

Webcam snapshots and video recordings are deleted automatically 60 days after your assessment is reviewed. The full candidate record (CV, answers, results) is deleted automatically 180 days after the hiring process concludes. A hiring team can shorten or extend these windows within fixed limits; the windows that apply to you are quoted on your assessment page before you start. Deletion covers our copies in the database and in file storage.

Your rights

You can ask the hiring team to access, correct or erase your data at any time — erasure removes the candidate record, CV, analyses, submissions and recordings. You also have the usual UK GDPR rights (access, rectification, erasure, restriction, objection, portability) and the right to complain to the ICO (ico.org.uk).

Where your data lives (sub-processors)

We use a small set of infrastructure providers to run the service:

  • Railway — application hosting
  • Neon — database
  • Cloudflare R2 — file storage (CVs, snapshots, recordings)
  • SendGrid (Twilio) — email delivery
  • Anthropic — AI text analysis (CV and job-description text only)

We never sell candidate or account data, never use candidate data for marketing, and never use it to train AI models.

Connected calendars and mailboxes (workspace accounts)

A workspace member can optionally connect their own Google or Microsoft account so that interviews arranged in Quiet Hire appear on their own calendar and, with Microsoft, so that interview emails send from their own address. If you connect an account, we store encrypted sign-in tokens and the email address of the connected account (shown back to you on the settings page), and:

  • Calendar (Google and Microsoft): we create, and later delete, only the interview events that your own hiring activity in Quiet Hire generates — an event carries the interview time and location, the role and your team's name, and the candidate's and interviewer's names and email addresses. We keep only the identifier of each event we created, so we can remove that same event later, and we act only on those events. We do not read your existing calendar entries.
  • Mailbox (Microsoft): we send interview and candidate emails from your address only as part of your hiring activity — an invitation you send, or the automatic confirmations when a candidate books an interview slot. We cannot and do not read your mail.

When a candidate's data is erased (or a campaign is deleted), we also delete the calendar events we created for them, retrying if your calendar is temporarily unreachable; if the calendar connection has been removed we may be unable to complete the removal, and you can always delete the event directly in your calendar. Disconnecting deletes our stored tokens so they can never be used again; for Google we also ask Google to revoke the grant. You can additionally withdraw access yourself at any time — from your Google account's security settings, or for Microsoft at myapps.microsoft.com. Connected-account data is never sold and never used for advertising, analytics or to train AI models; it is processed only by the infrastructure providers listed above, on our instructions.

Quiet Hire's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Security

Data is encrypted in transit and at rest; uploaded files are stored privately and served only to the workspace that owns them; each workspace's data is isolated at the database level. Workspace API keys are stored encrypted and are never displayed back.

Questions? Email enquiries@quiet-engine.co.uk · Privacy notice · Terms of service