Data Protection & Privacy Summary
Regulatory Alignment & Compliance Posture
APRNJobs.org designs its privacy and data protection program to align with major U.S. state privacy laws and international privacy frameworks where applicable, including:
- California Consumer Privacy Act (CCPA), as amended by CPRA
- Texas Data Privacy and Security Act (TDPSA)
- Colorado Privacy Act (CPA)
- Virginia Consumer Data Protection Act (VCDPA)
- Connecticut Data Privacy Act (CTDPA)
- Utah Consumer Privacy Act (UCPA)
- GDPR and UK GDPR (where applicable)
We apply consistent privacy, security, and data minimization practices across all users, including employers, recruiters, and job seekers.
Important note for healthcare partners:
APRNJobs.org does not function as a HIPAA Covered Entity or Business Associate and is not intended for the collection or processing of Protected Health Information (PHI). The platform is designed for recruitment and employment purposes only.
Data Collected & Purpose Limitation
We collect only the data necessary to operate a recruitment platform, including:
- Contact information and account details
- Professional credentials and licensure (e.g., APRN, NP, CRNA)
- Employment history, resumes, and application materials
- Platform usage and engagement data
- Billing metadata for paid services (no full payment card storage)
We do not request or require clinical, patient, diagnostic, or treatment data. Users are instructed not to submit sensitive or health-related personal data unless specifically required for lawful recruitment screening purposes.
Data Roles & Partner Responsibilities
- APRNJobs.org acts as an independent data controller for data processed on its platform.
- Employers and staffing partners act as independent data controllers for applicant data they receive through the platform.
Once applicant data is transmitted to a partner organization, that organization’s privacy policy, retention practices, and security controls apply. APRNJobs.org does not control downstream partner processing.
Security Safeguards
APRNJobs.org implements administrative, technical, and physical safeguards designed to protect personal data, including:
- Encrypted data transmission
- Role-based access controls
- Secure hosting infrastructure
- Monitoring for unauthorized access and abuse
- Metadata stripping from uploaded documents where technically feasible
While no system can guarantee absolute security, APRNJobs.org follows industry-aligned security practices appropriate for a recruitment and hiring platform.
Vendor & Subprocessor Management
We engage vetted service providers for:
- Cloud hosting and infrastructure
- Payment processing
- Analytics and performance monitoring
- Email delivery and customer support tooling
All service providers are contractually bound to process data only on our instructions and to maintain appropriate security and confidentiality controls.
Data Minimization, Retention & Deletion
- Data is collected only as necessary for platform functionality.
- User accounts and applicant data are retained only as long as needed for recruitment, operational, and legal purposes.
- Users may request access, correction, or deletion of personal data in accordance with applicable law.
- Certain data may be retained longer where required to meet legal, audit, or dispute-resolution obligations.
Privacy Rights & User Controls
APRNJobs.org supports privacy rights under applicable laws, including:
- Right to access personal data
- Right to correction
- Right to deletion (subject to legal exceptions)
- Right to data portability
- Right to opt out of targeted advertising where applicable
We honor Global Privacy Control (GPC) browser signals where legally required.
Data Sharing & Advertising Controls
Applicant data is shared with employers only when a job seeker actively applies or opts to share their profile.
Limited online identifiers may be shared with analytics and advertising partners with consent where required.
APRNJobs.org does not knowingly sell sensitive personal data.
Incident Response & Legal Cooperation
APRNJobs.org maintains procedures for identifying, responding to, and mitigating security incidents. Where legally required, affected parties and regulators are notified in accordance with applicable breach notification laws.
We cooperate with lawful requests from regulators and authorities while maintaining appropriate safeguards for user privacy.
Contractual Readiness
For enterprise partners and hospital systems, APRNJobs.org can provide:
- Data Processing Addendum (DPA)
- Privacy Policy and Cookie Policy
- Vendor security posture documentation (as available)
Contact for Compliance & Vendor Review
Privacy & Compliance: aprnjobs@gmail.com
General Inquiries: aprnjobs@gmail.com
