Privacy · Version 2026.07
Privacy notice
This notice explains who uses personal data in DAWN, why it is used, who receives it, how long it is kept and the choices available to you.
Effective 28 July 2026 · Last reviewed 28 July 2026
1. Scope and key terms
This notice applies to DAWN's web application, conversational interface, account services, recruitment and workforce features, voice and telephone features, support channels and other DAWN services that link to it. DAWN is operated by Stockholm IT Academi AB, organisation number 559337-9141, Sweden. In this notice, "DAWN", "we", "us" and "our" refer to Stockholm IT Academi AB.
"Organisation" means an employer, customer or other entity that manages a DAWN workspace. "User" includes candidates, applicants, employees, managers, recruiters, human resources professionals, administrators and people using public DAWN features.
2. Who is responsible for your data
When DAWN is the controller
We act as controller when we decide how and why personal data is used for direct account registration, authentication, service security, product administration, support, legal compliance and communications with us.
When an organisation is the controller
An organisation normally acts as controller for candidate, applicant, employee and workforce data that it collects, imports, creates or manages through DAWN. In that setting, we act as its processor under its documented instructions and the applicable data processing agreement. The organisation decides the purposes, legal bases, access, retention and employment decisions. Its own privacy notice must explain those choices.
Contact the relevant organisation first about organisation-controlled data. We will assist the organisation with requests as required by law and contract. Contact us directly about DAWN-controlled data or if you do not know which organisation is responsible.
3. Personal data we process
| Category | Examples |
|---|---|
| Account and identity | Name, email address, telephone number, password hash, verification status, account role, authentication method and identity-provider reference. |
| Organisation and access | Employer details, workspace membership, invitation status, assigned role, permissions and administrative actions. |
| Candidate and workforce records | Profile, CV, experience, education, skills, certificates, salary information, preferences, applications, leave and other employment records made available in DAWN. |
| Recruitment and interview records | Job applications, answers, interview schedules, notes, recordings, transcripts, assessments, AI-assisted scores, reviewer decisions and application status. |
| Conversations and files | Messages, conversation identifiers, attachments, extracted document text, approvals, requested actions and generated responses. |
| Voice and telephony | Audio, transcripts, generated speech, telephone number, call state and provider references. DAWN's call audit ledger is designed to store hashed destination and message values instead of their plain content. |
| Technical and usage data | IP address, session and device information, timestamps, security events, diagnostics, feature usage, AI provider, model, latency, token usage, cost estimate and redacted error information. |
| Support and communications | Support requests, correspondence, feedback, incident details and communication preferences. |
4. Where personal data comes from
We receive personal data from:
- you, when you register, speak, type, upload or take an action;
- an organisation, administrator, recruiter, manager or authorised colleague;
- candidates, referees or other people who lawfully provide workforce information;
- identity, recruitment or professional services that you or an organisation choose to connect; and
- technical events generated when DAWN, a device or an approved provider processes a request.
If an organisation obtains data about you from another source, that organisation is responsible for giving you the information required by law, including the source and categories of data.
5. Purposes and legal bases
| Purpose | DAWN's legal basis when we are controller |
|---|---|
| Create and operate an account | Performance of the user agreement and steps requested before entering it. |
| Authenticate users and protect the service | Performance of the agreement, compliance with law and our legitimate interests in preventing misuse, securing data and maintaining reliable services. |
| Provide conversation, document, voice and support features | Performance of the agreement and our legitimate interests in operating and supporting the service requested by the user. |
| Maintain reliability and improve DAWN | Our legitimate interests in diagnosing faults, measuring performance and improving usability, using minimised or aggregated information where practical. |
| Meet legal and regulatory duties | Compliance with legal obligations and, where necessary, establishment, exercise or defence of legal claims. |
| Optional processing requiring a choice | Consent where the law requires it. Consent can be withdrawn at any time without affecting earlier lawful processing. |
When we rely on legitimate interests, we assess the necessity of the processing, its expected benefit and its effect on your rights. We do not rely on that basis where your interests, rights or freedoms override ours.
For organisation-controlled recruitment and workforce processing, the organisation determines and must communicate its own legal basis. Depending on the context, this may involve employment law, a contract, legal duties, legitimate interests or consent. DAWN does not decide that basis for the organisation.
6. Sensitive and employment data
Workforce information can reveal health, disability, trade union membership, ethnicity, religion, sexual orientation, biometric identity data or other special categories of personal data. Organisations must not collect or use such data through DAWN unless the processing is necessary, proportionate, transparent and supported by both a legal basis and an applicable condition for special category data.
Do not place sensitive data, criminal-offence data or another person's confidential information in a conversation or attachment unless it is required for the task and you are authorised to use it. DAWN may restrict a feature where the requested processing is incompatible with its intended safeguards.
7. AI and automated processing
DAWN uses AI to interpret requests, retrieve authorised context, generate text or speech, transcribe audio, summarise information and prepare permitted actions. The information sent to an AI provider is limited to the context selected for the requested capability, subject to system configuration and the organisation's instructions.
DAWN's employment-related AI output is intended as assistance for meaningful human review. It does not independently authorise a final decision about hiring, rejection, promotion, dismissal, pay, performance, leave or another decision with legal or similarly significant effect. A qualified and authorised person must be able to inspect the relevant information, correct errors, disregard the output and make the decision.
If an organisation configures or uses AI output in a way that amounts to profiling or automated decision-making, it must identify the legal basis, provide required information about the logic and consequences, complete any required impact assessment, and provide human intervention and a way to contest the decision. See the AI use notice for detailed safeguards and prohibited uses.
8. Voice, telephone and interview features
When a voice feature is started, audio may be sent to a configured speech provider for transcription or speech generation. When a telephone feature is started, the destination number, call instructions and status may be sent to the configured carrier. Interview recordings and transcripts may be stored where the feature and organisation settings require them.
The organisation initiating an interview, recording or telephone call must provide any notice and obtain any consent required in the participant's country. A participant must be given a lawful alternative where consent is required and is not freely given. Recording or transcription must stop when the lawful basis no longer applies.
9. Browser and device storage
DAWN uses browser storage and necessary account cookies to keep a user signed in, maintain session security, complete identity-provider redirects and remember interface choices such as theme and navigation mode. These technologies are used to provide and secure requested features, not for third-party behavioural advertising.
Signing out clears the active DAWN account state from the application. A browser or device may retain cached files or preferences until they are cleared through browser or device settings.
11. International transfers
A provider or authorised recipient may process personal data outside the European Economic Area. Where a transfer is not covered by an adequacy decision, we use an applicable safeguard such as the European Commission's Standard Contractual Clauses and assess whether supplementary technical, contractual or organisational measures are required. A copy or description of the relevant safeguard can be requested, subject to necessary protection of confidential information.
An organisation's choice of provider, integration or processing region can affect transfer arrangements. The organisation must assess transfers it directs independently.
12. Retention and deletion
We keep personal data for no longer than its purpose requires. The applicable period is determined as follows:
| Record | Retention rule |
|---|---|
| Account and organisation administration | Kept while the account or workspace is active, then only for account closure, security, legal claims and mandatory record-keeping. |
| Recruitment and workforce records | Kept under the controller organisation's documented schedule and instructions, subject to employment, discrimination, tax, accounting and claims requirements that apply to it. |
| Conversations, attachments, audio and transcripts | Kept for the active task and the organisation's configured record lifecycle. Content selected for preservation as an employment record follows the organisation's schedule for that record. |
| Security, reliability and AI usage records | Kept for the period needed to investigate incidents, prevent abuse, demonstrate authorised use and resolve disputes. Where possible, content is replaced by hashes, counts or redacted metadata. |
| Backups | Removed through the controlled backup rotation cycle. Restored data remains subject to the original deletion rule. |
We may preserve a limited record where law, a legal hold, fraud prevention or an active dispute requires it. When retention ends, the data is deleted or irreversibly anonymised. Contact the controller for the precise schedule applying to a specific workforce record.
13. Security
We use technical and organisational measures selected according to the nature, scope, context and risk of the processing. These include access controls, password hashing, expiring authentication tokens, controlled server-side provider credentials, encrypted network transport, data minimisation, service boundaries, event records and incident procedures. No internet service can guarantee absolute security.
Read Security at DAWN for responsibilities and reporting instructions. Do not send passwords, API keys, verification codes or unnecessary personal data in a security or support report.
14. Your data protection rights
Subject to the conditions and exceptions in applicable law, you may:
- request access to your personal data and a copy of it;
- correct inaccurate or incomplete data;
- request deletion or restriction of processing;
- receive portable data where the right applies;
- object to processing based on legitimate interests;
- withdraw consent at any time;
- request human intervention, express your view and contest a qualifying solely automated decision; and
- complain to a competent supervisory authority.
Send a request to the organisation for organisation-controlled data, or to privacy@dawnhcm.com for DAWN-controlled data. We may need proportionate information to verify your identity and authority. We normally respond within one month. The period may be extended by up to two further months for a complex or numerous request, in which case the controller will explain the reason within the first month.
Rights are not absolute. A request may be limited where law protects another person, requires retention or provides another exception. A fee may be charged, or a request refused, only where the law permits, including for a manifestly unfounded or excessive request.
15. Complaints, questions and changes
Contact privacy@dawnhcm.com with a privacy question, rights request or concern. If an organisation controls the data, identify that organisation and your relationship with it so the request can be routed securely.
You may complain to the Swedish Authority for Privacy Protection, IMY, or the supervisory authority in the EEA country where you habitually live, work or believe an infringement occurred. The IMY complaint service explains how to file a complaint.
We will publish a new version and effective date when this notice changes. We will provide additional notice before a material change takes effect where required by law.