Last Updated: September 24, 2026
Personal Information Privacy Policy
Global Core Policy
Raise (part of the Ian Martin Group of Companies; “Raise”, “we”, “us” and “our”) respects the privacy of our candidates, contractors, employees, suppliers and clients. This policy explains how we collect, use, disclose, retain and destroy (collectively, “Handle”) personal information in connection with our websites and services, and the choices and rights available to you.
This policy applies to websites with a URL that includes the raiserecruiting.com, raise.team, or raise.jobs domain names, including but not limited to www.raiserecruiting.com, www.raise.jobs, apply.raise.jobs, training.raise.jobs, raise.team and support.raise.jobs (together, the “Website”). Talent community pages hosted on third-party platforms, such as LiveHire, are governed by the privacy policies of those platforms and operate alongside Raise services (together, the “Online Services”). It is designed to meet or exceed the requirements of the privacy laws applicable to our operations (“Privacy Laws”).
Table of Contents
1. Which policy applies to you
This document is our global core policy. It applies to everyone whose personal information we Handle. If you are in a jurisdiction listed below, the indicated provisions or supplement also apply to you, and where a supplement differs from this policy, the supplement governs:
- North America:
- Canada: individuals in Canada, this core policy is your policy, applied in accordance with PIPEDA and applicable provincial Privacy Laws;
- United States: individuals in the United States, see Schedule A (United States Supplement) of this policy, issued under applicable US state privacy and biometric privacy laws;
- Singapore: individuals in Singapore, see Schedule B (Singapore Supplement) of this policy, issued under the Personal Data Protection Act 2012;
- EEA / UK: individuals in the European Economic Area and the United Kingdom, see Schedule C (EEA/UK Supplement) of this policy, issued under the EU and UK General Data Protection Regulation (“GDPR”).
Supplements state only what differs from this core policy; everything else in this document continues to apply.
2. Definitions
- Personal Information: any information or opinion relating to an identified or identifiable individual that Raise collects, receives, creates or derives, whether directly from the individual or from another source. This term includes any equivalent category of information protected under applicable Privacy Laws.
- Biometric Data: a biometric identifier (such as a fingerprint, iris scan or face geometry scan) or information derived from it that is used to identify an individual. In Raise’s processes this includes selfie images analyzed using facial-recognition or face-matching technology to confirm identity.
Cookies: a small text file that may be placed on your device when you visit parts of our websites or use certain portal features.
- GDPR and EU/UK Cookie Law: the EU and UK General Data Protection Regulation and the Privacy and Electronic Communications Regulations, as applicable to our Handling of the personal information of individuals in the EEA and UK.
In this policy, the singular includes the plural, “including” means “including without limitation”, references to statutes include their amendments, and headings do not form part of the policy
3. Privacy Officer and Data Protection Officer
Raise has appointed Kelsey Pawlak, a member of our senior management team, as our Privacy Officer and Data Protection Officer (“DPO”). The Privacy Officer & DPO oversees compliance with this policy and applicable Privacy Laws, responds to enquiries, investigates complaints and oversees remedial measures, and serves as the designated Data Protection Officer wherever Privacy Laws require one, including under Singapore’s PDPA (see the Schedule B, Singapore Supplement) and, where applicable, the GDPR.
Contact for all privacy matters:
- Kelsey Pawlak, Privacy Officer & Data Protection Officer · Email: privacy@raiserecruiting.com
- Mail: Kelsey Pawlak, Privacy Officer & DPO, Raise, 610 Chartwell Road, Suite 101, Oakville, ON L6J 4A5, Canada
4. Personal information we collect
Information you provide
We collect personal information to facilitate the hiring process, manage employment and engagement relationships, provide the Online Services, and improve our user experience. Depending on your relationship with us, this may include:
- Contact Information: This includes full name, address, email address, and phone number.
- Identification Verification Information: This may include Social Security number (or equivalent national identification number), passport, driver’s license, or other government-issued identification details and biometric information.
- Location verification: This may include IP address, proof of residence, including home address verification.
- Application & Qualification Information: Including Resumes, references, specific application information.
- Payroll Information: Current and historical payrolling & banking information, including business banking and invoice information for Independent Consultants.
- Background Check Information: Authorization to request background checks, including criminal history, credit history, employment verification, and DMV checks if applicable.
- Drug and Alcohol Tests: Authorization to request drug and alcohol tests where applicable to the client and job requirements
- Legal Authorization: Documentation related to the candidate’s eligibility to work in the country, such as work permits or visas.
- Benefits Enrollment: For where it applies, information required for enrollment in employee benefits programs, such as health insurance, retirement plans, and other perks.
- Emergency Contact Information: Contact details for individuals to be notified in case of emergency.
- Demographic Information: Optional demographic information such as gender, race, ethnicity, and veteran status, which may be collected for affirmative action or diversity initiatives.
Information we collect automatically
When you visit our websites or interact with our emails, we automatically collect technical information such as IP address, browser type, internet service provider, referring and exit pages, operating system, date/time stamps and clickstream data (“Log Data”). We use Log Data to verify location for remote positions, analyse trends, administer and secure our websites, and compile aggregated, non-identifying statistics. Log Data is retained temporarily, though it may be kept longer for security purposes. In some jurisdictions, including the EEA and UK, this information is Personal Information, and we treat it in accordance with this policy.
The information we collect automatically includes:
- Identifiers, such as your internet protocol (IP) addresses and browser type; and
- Internet, website or other electronic network activity, such as your internet service provider (ISP), referring/exit pages, operating system, date/time stamp, and clickstream data.
Cookies
We may collect information through cookies and similar technologies when you visit our websites. Strictly necessary cookies are used to make our websites function and cannot be switched off. For all other cookies, including functional, performance and analytics cookies, we ask for your consent through the cookie banner displayed when you first visit our websites, where consent is required by applicable law, including in the EEA and UK. You can change or withdraw your cookie preferences at any time through the cookie settings on our websites, and you can also manage cookies through your browser settings. For more information, visit allaboutcookies.org.
Job alerts, assistance requests and communications
If you sign up for job alerts or request assistance with your search, we collect the information you provide, such as your name, email address, industry of interest, experience level and any resume you upload. When you contact us by email or through the Website, we use your contact information and the content of your message to review, process and respond to it. All communications will be handled in accordance with this Privacy Policy.
SMS communications
Raise may collect and use your mobile number to send employment-related SMS text messages, such as onboarding, scheduling, timekeeping, payroll/invoice updates, and one-to-one support. By providing your mobile number and opting in, you consent to receive these messages.
No mobile opt-in or text message consent will be shared with third parties or affiliates for marketing purposes. We may share your mobile number with service providers solely to send messages on our behalf; they may not use it for their own purposes.
Opt-Out & Assistance:
Reply STOP to cancel. You can cancel Raise Messaging at any time by replying STOP to any message. After you send STOP, we will send one final message confirming that you have been
unsubscribed, and you will no longer receive messages from the Program. You can also opt out of, or back in to, text messages at any time by updating your preferences in your Raise App. To rejoin, simply opt in again as you did the first time and we will resume sending messages to you.
Disclosure:
Consent is not a condition of employment.
Standard message and data rates may apply, and message frequency may vary.
5. How we use personal information
We Handle personal information for the following purposes, which we notify to you at or before collection:
- to carry out our staffing and workforce services, matching candidates to opportunities and fulfilling client staffing requests;
- to process applications, verify identity and eligibility to work, arrange interviews and assessments, and complete onboarding, payroll and engagement administration;
- to provide and improve the Online Services and personalize your experience;
- to comply with legal obligations, cooperate with public authorities, courts and regulators, protect our rights and property, prevent fraud and misuse, and respond to lawful requests;
- to review compliance with applicable contracts and terms of use; and
- for other purposes we notify to you in advance or for which we obtain your consent.
6. Consent and your choices
We Handle personal information with your consent for the purposes we have notified, or as otherwise permitted or required by applicable Privacy Laws. We do not require, as a condition of providing a product or service, consent beyond what is reasonably necessary to provide it.
You may withdraw your consent at any time on reasonable notice by contacting us at privacy@raiserecruiting.com. We will explain the likely consequences of withdrawal (for example, that we may no longer be able to consider you for opportunities or administer your engagement) and will cease the relevant Handling unless retention or use is required or permitted by law.
7. Use of artificial intelligence
Raise uses AI technologies to support recruitment and employment processes, such as organizing candidate information and matching candidate profiles with job opportunities. These tools support human decision-making and do not replace it: people are involved in shortlisting and engagement decisions, and AI-generated outputs are reviewed before being relied upon. For more information, see our Responsible Use of AI Policy or contact us at privacy@raiserecruiting.com.
8. Sharing of personal information
Companies within the Raise group may share personal information among themselves for the purposes described in this policy. Raise group companies are located in Canada, the United States, Singapore, India, Ghana, Peru and the Philippines, and you may be contacted from any of these locations. Each location follows the security protocols described in this policy.
We do not sell personal information. We disclose it to third parties only:
- to trusted service providers that Handle it on our behalf for hosting, operations, customer service, surveys or other operational, marketing, financial or technical functions, under contractual data protection obligations;
- to prospective employers and clients in order to carry out our staffing services;
- to employer-of-record, payroll, screening, identity-verification and similar partners engaged for your assignment;
- where required or permitted by law, including for investigations, fraud prevention, litigation or other legal proceedings; and
- in connection with outsourcing, sale or reorganization of our business, subject to appropriate safeguards;
- with your consent, where consent is required under applicable Privacy Laws or where we otherwise choose to rely on consent.
Where we disclose personal information to service providers or other commercial recipients, we require appropriate safeguards restricting their use and further disclosure of the information to what is reasonably necessary for the relevant purpose and protecting it against unauthorized access, alteration or disclosure. Disclosures to public authorities, courts, regulators or law-enforcement bodies are made only where required or permitted by applicable law.
9. International transfers and storage
Your personal information is stored on secure servers retained by Raise. As Raise operates globally, your data may be transferred to countries other than the one in which it was collected.
Where personal information is transferred internationally, we ensure the recipient provides a standard of protection comparable to that required by the Privacy Laws applicable to the transfer.
10. Security and data breach response
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the personal information we hold, including access controls limiting personal information to staff who need it for a specific task, encryption in transit, and vendor security requirements.
We maintain security and data breach response procedures, whereas if a breach were to occur, we assess the potential threat promptly and notify regulators and affected individuals where and when required by applicable Privacy Laws (including the mandatory notification regimes in Canada, US states, Singapore and the EEA/UK, as applicable). Our service providers are contractually required to report data incidents to us without undue delay.
11. Retention
We retain personal information only as long as necessary for the purposes for which it was collected and to meet legal, regulatory and business requirements. For example, employment standards legislation prescribes minimum retention periods for certain employment records. Personal information may be retained longer where it is relevant to a complaint, investigation or litigation, or where a longer period is required or permitted by law. Jurisdiction supplements set out specific retention schedules where required. When personal information is scheduled for destruction, it is destroyed or anonymized in a secure and permanent manner; our service providers are instructed to follow the same standards.
12. Accuracy
We make reasonable efforts to keep personal information accurate, complete and current, particularly where it is used to make a decision that affects you or is disclosed to others. Please notify us of changes to your personal information in a timely manner. We may verify the identity of anyone requesting an update and validate the accuracy of proposed changes.
13. Your privacy rights
Depending on your location and subject to applicable law, you may have the following rights in relation to the personal information we hold about you. We respond to requests within the timelines required by the applicable Privacy Laws.
- Informed: to know how your personal data is collected, used, stored, and shared;
- Access: to request what personal information we hold about you and how it has been used and disclosed;
- Correction: to request correction of inaccurate or incomplete information;
- Erasure: to request deletion of personal information, subject to legal exceptions;
- Withdrawal of consent: to withdraw consent on reasonable notice (see Section 6);
- Restriction and objection: to request restriction of, or to object to, certain processing;
- Portability: to request transfer of your data to another organization or to you;
- Automated decision-making: not to be subject to decisions made solely by automated means that have legal or similarly significant effects;
- Non-discrimination: to exercise your rights without discriminatory treatment.
Requests should be sent to our Privacy Officer & DPO, Kelsey Pawlak, at privacy@raiserecruiting.com or by mail to the address in Section 3. We will verify your identity before responding to the request. Where we cannot fulfil a request for a reason permitted by applicable law (for example, legal privilege, confidential commercial information, or information generated in a formal dispute resolution process), we will explain the reason. Where permitted, we may charge a reasonable fee for access requests and will provide an estimate first.
Complaints
Complaints should be submitted in writing to the Privacy Officer & DPO, Kelsey Pawlak, with the relevant facts. We investigate all complaints and respond with our findings and any remedial action. You may also complain to your local data protection authority: for Singapore, the Personal Data Protection Commission (pdpc.gov.sg); for the EEA/UK, your national supervisory authority; for Canada, the Office of the Privacy Commissioner, or the applicable provincial privacy commissioner, depending on which Privacy Law applies.
14. Children and Minors
Our recruitment and workforce services are intended for individuals who are legally eligible to work or otherwise engage with Raise. Where we process personal information about a minor, we do so in accordance with applicable Privacy Laws, including obtaining consent from a parent or legal guardian where required.
15. Changes to this policy
We may amend this policy from time to time to reflect changes to the Website, applicable laws or our services. Changes are indicated by an amended Effective Date, and a revision history is available
on written request. If we make revisions that materially change how we use or share your personal information, we will provide appropriate notice and, where required by applicable Privacy Laws, obtain consent before implementing those changes.
Schedule A
United States Supplement
This Schedule applies to individuals in the United States and is issued under applicable US state privacy laws, including comprehensive state privacy statutes and state biometric privacy statutes. Where it differs from the core policy, this Schedule governs. The United States does not have a single national privacy law; each state imposes its own requirements, and we apply the law of the state where you reside.
A1. Categories, purposes and retention
The categories of personal information we collect are described in Section 4 of the core policy, the purposes in Section 5, and retention in Section 11. We collect sensitive personal information (including government identifiers, biometric information, and demographic information you volunteer) only for the purposes of verifying identity and eligibility to work, administering employment and engagements, meeting legal obligations, and supporting voluntary diversity initiatives, and we do not use it to infer characteristics about you.
A2. Biometric information
Where identity verification for your application or assignment uses biometric information, such as a selfie image analysed using face-matching technology:
- we will inform you in writing that biometric information is being collected, the specific purpose, and the retention period, and we will obtain your written consent (including electronic consent) before collection;
- you may decline; declining means we will offer an alternative verification method where available, or you may not be able to proceed with the specific assignment requiring it, but you remain eligible for opportunities that do not;
- we do not sell, lease, trade or otherwise profit from biometric information;
- we do not disclose biometric information except to the identity-verification provider engaged for your assignment, with your consent, or where required by law;
- we permanently destroy biometric information when the initial purpose for collecting it has been satisfied, or within three years of your last interaction with us, whichever occurs first, and earlier where a specific state law requires it; and
- we protect biometric information using the same or a more protective standard of care than we apply to other confidential and sensitive information.
This Schedule serves as our publicly available written policy on biometric information retention and destruction.
A3. Your state privacy rights
Depending on your state of residence, you may have the rights described in Section 13 of the core policy, including to know, access, correct, delete, and obtain a portable copy of your personal information, and to opt out of targeted advertising, sale, or profiling in furtherance of decisions producing legal or similarly significant effects. We do not sell personal information or process it for targeted advertising or such profiling. We respond to rights requests within the timeframes required by the applicable state law. If we refuse a request, you may appeal by replying to our refusal or writing to privacy@raiserecruiting.com, and we will respond to your appeal within the period required by your state’s law, including instructions on contacting your state Attorney General if you disagree with the outcome.
A4. Submitting requests and verification
You or your authorised agent may submit requests to privacy@raiserecruiting.com or by mail to the address in Section 3. We will verify your identity, and your agent’s authority, before responding. We will not discriminate against you for exercising any right.
Schedule B
Singapore Supplement
This Schedule applies to individuals in Singapore and is issued under Singapore’s Personal Data Protection Act 2012 (the “PDPA”). Where it differs from the core policy, this Schedule governs.
B1. Organisation and Data Protection Officer
The organisation responsible for your personal data in Singapore is Raise Business Solutions Singapore Pte. Ltd. 20 Anson Road, Level 6 #02, Twenty Anson, Singapore 079912. Our designated Data Protection Officer (DPO) is Kelsey Pawlak, reachable at privacy@raiserecruiting.com.
B2. Consent and withdrawal
We collect, use and disclose personal data only for purposes notified at or before collection, with your consent or as otherwise permitted under the PDPA. You may withdraw consent at any time on reasonable notice to the DPO; we will explain the likely consequences of withdrawal and cease the relevant collection, use or disclosure unless retention is required or permitted by law.
B3. Sharing of Personal Information
We will collect, use and disclose the personal data you provide in this application to assess and process your application and to facilitate the recruitment process for opportunities with the applicable end client.
This may include:
- sharing relevant application information with end client for review, assessment and hiring decisions;
- contacting you by email, phone call, SMS or WhatsApp about your application, interview process, onboarding or related employment matters;
- conducting or facilitating pre-employment requirements, including background checks, reference checks, medical examinations, identity verification, right-to-work verification and other screening or onboarding requirements, where applicable; and
- if you are selected for employment or engagement, using and disclosing personal data reasonably necessary to establish and administer your employment or engagement, including for onboarding, payroll processing, benefits administration, tax and statutory reporting, immigration or work authorization requirements, timekeeping, payment administration and other employment-related purposes.
For these purposes, Raise may disclose relevant personal data to third parties involved in the recruitment, onboarding and employment process where required, and other service providers acting on Raise’s behalf.
These third parties may be located in Singapore or elsewhere. Your personal data may therefore be transferred to, stored in, or accessed from locations outside Singapore by Raise, its clients, affiliates or service providers (see B6 for overseas transfers).
B4. NRIC, FIN and national identifiers
In line with PDPC advisory guidelines, we request your NRIC, FIN or a copy of an identity document only where required by law or necessary to verify your identity to a high standard, generally at the later stages of recruitment or onboarding. National identifiers are subject to heightened access, security and retenti
B5. Biometric data
Where a client assignment requires biometric identity verification, we will ask for your separate, explicit consent at that point. You may decline; declining means you cannot take that particular assignment but you remain eligible for opportunities that do not require it.
B6. Overseas transfers
Where we transfer your personal data outside Singapore, including to our processing operations in Canada and the United States, we comply with the PDPA Transfer Limitation Obligation by ensuring the recipient is bound by legally enforceable obligations (written contracts, binding corporate arrangements, or recognised certifications such as Global CBPR Forum certifications) to provide a standard of protection comparable to the PDPA.
B7. Data breach notification
If a data breach is assessed as notifiable under the PDPA (likely significant harm to affected individuals or of significant scale), we will notify the Personal Data Protection Commission (the “PDPC”) as soon as practicable and no later than three calendar days after that assessment, and will notify affected individuals where required.
B8. Retention
For candidates and contractors in Singapore, we keep your personal data only as long as necessary for the purposes described above and to meet our legal, tax and business requirements. The PDPA does not set a fixed retention period. It requires us to stop keeping your data, or to anonymise it, once we no longer have a legal or business need for it. The periods below reflect that.
If you are engaged, we retain your data for the duration of your engagement and six years after it ends; if you join a talent network but are not engaged, up to 24 months from your most recent interaction (you may ask to be removed at any time); if you are not selected and do not join a network, 12 months from that decision. We review retained candidate data at least annually and securely delete or anonymise data when no legal or business need remains.
B9. Access and correction
You may request access to your personal data and information about its use and disclosure over the past year, and request correction of errors or omissions, by contacting the DPO. We respond within 30 days or tell you in writing when we will respond. A reasonable fee may apply to access requests (estimate provided first). Refusals permitted or required by the PDPA will be explained.
B10. Marketing and Do Not Call
We do not send marketing calls, texts or voice messages to Singapore telephone numbers unless you have given clear consent or we have checked the number against the relevant Do Not Call Registry. The Do Not Call requirements do not apply to messages that are excluded under the PDPA, including messages sent solely to promote an employment opportunity without any marketing element and certain service-related messages.
B11. Complaints
Complaints may be made to the DPO. If we cannot resolve your concern, you may contact the PDPC at www.pdpc.gov.sg.
Schedule C
EEA / UK Supplement
This Schedule applies to individuals in the European Economic Area and the United Kingdom, including our staff, candidates and business contacts there, and is issued under the EU and UK GDPR. Where it differs from the core policy, this Schedule governs.
C1. Controller and Data Protection Officer
The controller of your personal data is the Raise group entity with which you have a relationship, acting on behalf of the Ian Martin Group of Companies. Our Data Protection Officer is Kelsey Pawlak, reachable at privacy@raiserecruiting.com.
The controller responsible for your personal data is: For individuals in the EEA & UK: Privacy Office – privacy@raiserecruiting.com
C2. Legal bases for processing
We process your personal data only where a legal basis applies: performance of a contract (for example, administering your application, employment or engagement); compliance with a legal obligation (for example, tax, social security and employment law); our legitimate interests (for example, operating and securing our services, workforce planning and business administration), balanced against your interests and rights; or your consent, where we ask for it. Special category data (such as health or biometric data) is processed only where a condition under Article 9 of the EU GDPR or UK GDPR, as applicable, is met and any additional requirements under applicable national law are satisfied. Personal data relating to criminal convictions and offences is processed only where authorized by applicable law and subject to appropriate safeguards.
C3. Your rights
In addition to the rights in Section 13 of the core policy, you have the right to withdraw consent at any time without affecting prior processing, and the right to lodge a complaint with your national supervisory authority (or the UK Information Commissioner’s Office). We respond to rights requests within one month, extendable by two further months for complex requests, in which case we will tell you.
C4. International transfers
Where your personal data is transferred outside the EEA or UK, including to our operations in Canada and the United States, we rely on an applicable adequacy decision or adequacy regulation, or another transfer mechanism recognized under the EU GDPR or UK GDPR, as applicable. Canada’s adequacy status is limited to processing covered by PIPEDA. Information about the relevant transfer mechanism may be requested from the DPO.
C5. Retention
We retain personal data in accordance with Section 11 of the core policy and the statutory retention periods applicable in your country of employment or engagement.