Privacy Policy
Last updated 7 July 2026
This policy explains what personal data Fios AI collects, why, on what legal basis, who we share it with, how long we keep it, and the rights you have over it. It covers visitors to this website, candidates who take an AI-assisted assessment, and the recruiters who use the platform.
1. Who is the data controller
The data controller is MJL Executive Ltd, trading as Fios AI (“Fios AI”, “we”, “us”). We are established in Ireland. MJL Executive Ltd is registered in Ireland under company registration number 616079, registered office 27 Charlestown Park, St. Margaret’s Road, Dublin 11, D11 E2FY, Ireland.
Where a recruiting organisation invites you to an assessment, that organisation and Fios AI each have a role under data protection law. In general the recruiting organisation decides to assess you for a role (and is a controller for that decision), while Fios AI provides and operates the assessment system. The precise split is set out in our written agreement with each recruiting organisation.
You can reach us about any privacy matter at privacy@fiosai.io.
2. Data we collect on this website
If you join our waitlist or request a demo, we collect the work email address you provide, and a spam-prevention token, so we can contact you about early access and about Fios AI. We use this on the basis of your consent, and you can ask us to delete it at any time by emailing privacy@fiosai.io. We do not use it for anything other than talking to you about Fios AI, and we do not sell it.
3. Data we process in the platform
When you take an assessment, we only collect the data needed for the modules a recruiting organisation has enabled. Depending on the role, this may include:
4. Our lawful basis
We rely on the following bases under Article 6 (and Article 9 for special-category data) of the GDPR:
We do not use your assessment data to train AI models, and we do not use it beyond the role you applied for.
5. AI, automated processing and human decisions
Fios AI is an AI-assisted recruitment system. Under the EU AI Act this is a high-risk use of AI in employment, and we design the product accordingly.
6. Our impact assessment
Because this processing is large-scale, uses AI to evaluate people, and can involve special-category (biometric) data, we have carried out a Data Protection Impact Assessment under Article 35 of the GDPR to identify and reduce the risks to you. It is reviewed before the service goes live and kept up to date as the product changes.
7. Who we share data with, and international transfers
Your assessment result is shared with the recruiting organisation that invited you. To run the service we use a small number of sub-processors, each under a data processing agreement and acting only on our instructions: Supabase (EU database and storage), Vercel (hosting), Anthropic (the AI model), Resend (email) and Stripe (billing for recruiters only).
Where a sub-processor is outside the European Economic Area, we rely on an appropriate transfer safeguard under Chapter V of the GDPR: the recipient’s certification under the EU-US Data Privacy Framework, the European Commission’s Standard Contractual Clauses, or both. You can request a copy of the safeguards that apply to any transfer of your data by emailing privacy@fiosai.io.
8. How long we keep your data
9. Your rights
Under the GDPR you have the right to access your data, have it corrected, ask us to delete it, receive it in a portable format, withdraw consent, object to or restrict certain processing, and not be subject to a solely automated decision. Where we rely on legitimate interests, you can ask for a copy of our legitimate-interests assessment.
To exercise any right, email privacy@fiosai.io. You also have the right to complain to a supervisory authority. In Ireland this is the Data Protection Commission (dataprotection.ie).
10. How we protect your data
We apply technical and organisational measures appropriate to the sensitivity of the data: encryption at rest, access controls and row-level security so each organisation only sees its own data, short-lived signed links for recordings, and append-only audit logs of consent and decisions. No system is perfectly secure, and we keep these measures under review.
11. Data protection contact and age
Our point of contact for any data protection matter is our Data Protection contact, at privacy@fiosai.io. We are not required to appoint a statutory Data Protection Officer at our current scale; if that changes, we will name one here. Fios AI is intended for adults; it is not directed at, and we do not knowingly process the data of, anyone under 16.
12. Changes
We may update this policy as the product changes; the date at the top shows the current version, and material changes will be notified where appropriate.