What data we collect
From candidates, through the interview service
- Contact details — your name and email address.
- Résumé and professional background — CV, work and education history, skills, qualifications, certificates, and portfolio links.
- Interview data — audio and/or video recordings of the interview; transcripts and structured responses generated from it; and the scores and labels our models produce against the rubric the Client configured.
- Usage and device data — IP address, browser type and version, device and operating-system metadata, pages visited, timestamps, session duration, and basic telemetry.
From website visitors
Contact information you submit through a demo request or form, your marketing preferences, and cookie and analytics data. Cookies are covered in §11.
Why we process data, and on what legal basis
Candidate data — as a processor
We process candidate data on our Clients' documented instructions, for the purposes they define. In practice that means:
- Conducting and recording AI-assisted voice interviews.
- Generating transcripts, summaries, scores and shortlists.
- Detecting fraud and cheating, and running quality controls.
- Delivering the service technically, keeping it secure through logging and access controls, and supporting it.
Under the GDPR, the legal basis is set by the Client — usually performance of a contract, including steps taken before entering one, and/or legitimate interests in assessing candidates efficiently, with consent where consent is required, such as for recordings and certain analytics. Under PIPL, we rely on a lawful basis under Article 13, with separate consent for sensitive personal information, for sharing, and for cross-border transfers where required. Under the PDPO, processing is consistent with Data Protection Principles 1 to 6 covering fair collection, purpose limitation and security.
Website, diagnostics and product safety — as a controller
- Running www.ourlanterns.com and responding to enquiries.
- Securing our services, including fraud prevention and incident detection.
- Aggregated and anonymised analytics, and model safety and evaluation work — without re-identifying you.
- Legal, compliance and accounting obligations.
Here the GDPR bases are legitimate interests, consent where required such as for non-essential cookies, and legal obligation. PIPL processing is as permitted by that law, with separate consent where required. PDPO processing is limited to purposes we have notified or purposes directly related to them.
Automated decision-making and profiling
Our models generate interview summaries and scores from your responses, and Clients use those outputs to prioritise candidates.
Cross-border transfers
Our primary infrastructure is in Hong Kong, and we operate through two affiliated companies — Lantern Lab Limited in Hong Kong and Lantern AI Inc in the United States. If you are in the EU/EEA or Mainland China, or where Clients and users are elsewhere, your data may be accessed from or transferred to a jurisdiction outside your own, including Hong Kong and the United States. Intra-group access is limited to what is needed to deliver and support the service, and is covered by the same contractual safeguards we impose on sub-processors.
- EU/EEA, under the GDPR — we use the European Commission's Standard Contractual Clauses for transfers to third countries, supplemented where appropriate by transfer impact assessments and additional safeguards. These cover transfers to, and access from, both Hong Kong and the United States.
- Mainland China, under PIPL — for outbound transfers we use a mechanism the law permits, including the CAC Standard Contract and its required filings and, where applicable, a security assessment or certification. We also take account of the 2024 Provisions on Promoting and Regulating Cross-Border Data Flows, which introduced certain exemptions and thresholds, and use whichever compliant path fits the data and volumes concerned.
How long we keep it
Unless a Client instructs otherwise or the law requires a different period, these defaults apply, measured from the date of the interview.
| Data | Default retention |
|---|---|
| Raw audio and video | 12 months |
| Transcripts and derived interview metrics | 24 months |
| System logs and security records | 12–24 months |
| Aggregated or anonymised data | No fixed limit — it is no longer personal data |
Clients can shorten or extend these periods in their settings or their contract. When a retention period expires, or when we receive a verified deletion request under §8, we securely delete or anonymise the data.
Security
- Encryption in transit and at rest.
- Role-based access control, multi-factor authentication, and least-privilege access.
- Network isolation, vulnerability management, and audit logging.
- A secure development lifecycle, data minimisation, and regular testing.
- Due diligence on sub-processors, with security controls imposed contractually.
We maintain incident response procedures. Where the law requires it we will notify Clients and/or authorities, and affected individuals — including the GDPR's 72-hour notice to a supervisory authority, and notifications aligned to PIPL and PCPD guidance.
Your rights
Because our Clients are usually the controller, start with the employer you interviewed for. You can also contact us using the details in §13 and we will assist them.
EU/EEA — GDPR
Access, rectification, erasure, restriction, portability and objection, plus the rights relating to automated decision-making in §3. You can lodge a complaint with your local supervisory authority.
Mainland China — PIPL
The right to know and decide, to limit or refuse processing, to access and copy your data, to portability where the conditions are met, to rectification and deletion, to an explanation of automated decision-making, and to withdraw separate consent for sensitive data and cross-border transfers.
Hong Kong — PDPO
Data access and correction rights under DPP6, and the right to object to direct marketing. Complaints go to the Privacy Commissioner for Personal Data.
United States — California and other states
Where we handle candidate data for a Client, Lantern is a service provider under the California Consumer Privacy Act as amended by the CPRA, and the Client is the business. This is the same split described at the top of this page, in California's terms.
- Know and access — the categories and specific pieces of personal information we hold about you, the sources, the purpose, and the categories of third party we disclose to.
- Delete and correct the personal information we hold.
- Opt out of sale or sharing — we do not sell personal information, and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We have not done so in the preceding twelve months.
- Limit the use of sensitive personal information to what is necessary to deliver the service.
- Non-discrimination — we will not treat you differently for exercising any of these rights.
You can use an authorised agent to make a request. We will verify the request against information we already hold rather than asking you for new identity documents. Residents of other US states with comprehensive privacy laws have broadly similar rights, and we handle those requests the same way.
We respond without undue delay, and generally within 30 days, or sooner where local law requires it. Under the CCPA that means acknowledging within 10 business days and responding within 45 days, extendable once where the law allows.
Sub-processors
We keep an up-to-date list of the key sub-processors used to deliver the service. Clients are notified of material changes under our Data Processing Agreement. To request the current list, write to team@ourlanterns.com.
Children and minors
The service is built for job applicants. It is not intended for children, or for anyone below the minimum employment age where they live, and we do not knowingly collect their data. If you believe a minor's data reached us in error, contact us and we will delete it.
Region-specific notices
- EU/EEA — where we rely on legitimate interests we carry out a balancing test, and we can share the key findings on request. International transfers use Standard Contractual Clauses with supplementary measures where needed.
- Mainland China — for cross-border transfers we follow an appropriate path, such as the CAC Standard Contract with its required filings, or another permitted route in light of the 2024 Provisions. We obtain separate consent where it is required for sensitive data and outbound transfers.
- Hong Kong — section 33 of the PDPO is not yet in force, but we adopt the PCPD's recommended model clauses so that overseas transfers get comparable protection.
- United States — Lantern AI Inc is the Lantern entity established in the US. For candidate data it acts as a service provider to the Client under the CCPA and the equivalent terms in other state privacy laws, is contractually barred from using that data for its own purposes, and is bound by the retention limits in §6. Which Lantern entity contracts with your employer is identified in that employer's agreement with us.
Contacting us, and complaints
- Lantern, privacy and DPO — Thomas Chan, Thomas.chan@ourlanterns.com.
- EU/EEA — contact your local supervisory authority. We can help you identify the right one.
- Hong Kong — the Office of the Privacy Commissioner for Personal Data (PCPD).
- Mainland China — you may also raise concerns with the Cyberspace Administration of China or another relevant regulator.
- United States — California residents may complain to the California Privacy Protection Agency or the California Attorney General; residents of other states may contact their own Attorney General.
If you interviewed with Lantern and something felt wrong, you can also write to support@ourlanterns.com. A human reads every escalation.
Changes to this policy
We may update this policy to reflect changes in our practices or in the law. We will notify material changes through the service, on this website, or directly to Clients. The date at the top of this page always shows the current version.
Questions about anything on this page go to Thomas.chan@ourlanterns.com. Lantern AI operates through two affiliated companies:
Hong Kong SAR
Lantern Lab Limited
Unit 314C, InnoCentreUnited States
Lantern AI Inc
2261 Market Street STE 85453, San Francisco, CA 94114