Fernain legal

Fernain Privacy Policy

Last updated: September 9, 2026

Plain language first

The no-nonsense read

This summary is here for clarity. It does not replace or change the complete document below, which controls.

  • Who decides what happens to information depends on the situation. Fernain manages its own website, account, billing, security, and business records; customer organizations direct many workspace and member workflows; employers and other recipients may have separate responsibilities.
  • Fernain uses information to provide, support, secure, and administer the services and purposes that apply. Uploading private content, applications, prompts, or outputs is not blanket permission to reuse them for unrelated model training, advertising, or general product development.
  • AI and connected resources are used only when enabled and within the applicable instructions, permissions, disclosed purposes, and approved provider or destination. Provider terms can differ, and disconnecting a provider does not recall information already sent.
  • Candidate discovery is limited to profiles candidates choose to make discoverable. Fernain may charge partners for access, and partners may charge companies, so some laws may treat that disclosure as a sale even though private applications and non-discoverable records stay outside the lookup. Candidates can opt out of future discovery.
  • Privacy rights and retention depend on the person, service, organization, recipient, and applicable law. Requests can be sent to legal@fernain.com.

The complete document

1. Scope and Responsibility

Fernain LLC ("Fernain," "we," "us," or "our") develops software for membership organizations and teams. This Policy explains how personal information is handled in connection with Fernain-operated websites, direct enquiries, and applicable Fernain Services.

A Customer is an organization or individual that orders or subscribes to a Fernain Service. A User is an individual who accesses a Service, including an administrator, member, employer representative, candidate, or other participant. Individual Users have rights in their own information even when they do not purchase a subscription.

The public website presents Fernain's offerings and a way to contact us. Website and enquiry information is addressed below. Account, Jobs, Creation, AI, credential, payment, and other product descriptions apply only to the features you actually use and the processing that is enabled. Shared sign-in or a common interface does not authorize combining information across organizations or products.

Responsibility depends on the particular purpose, rather than on who owns a subscription:

  • Fernain's own purposes: Fernain determines how to handle its website enquiries, business relationships, and applicable account administration, billing, security, and legal records. Where the relevant law uses the term, Fernain acts as a controller or business for those purposes. The relevant product notice and agreement identify any more specific allocation.
  • Processing for a Customer: An organization may instruct Fernain to host and process workspace, membership, application, or other information for its purposes. Fernain then acts as a processor or service provider where applicable, under the relevant agreement and data-processing agreement ("DPA"). The organization's notice explains its decisions and uses.
  • Other recipients' own purposes: An employer receiving an application, a sponsoring membership organization administering its program, or a recipient of a published portfolio may determine its own subsequent uses. Their notices and applicable law govern those activities; they are not all Fernain's processors.

A personal profile or candidate portfolio is not automatically owned or fully controlled by an organization because the individual also uses its workspace. An organization administrator's access must be limited to that organization's authorized scope and the notices and permissions that apply.

Where we act for a Customer, contact that organization about its purposes and instructions. You may also contact legal@fernain.com; we will identify the appropriate handling of your request and assist as required. This allocation does not remove Fernain's own legal duties or your nonwaivable rights.

2. Information and Sources

The information involved depends on your interaction and the enabled Service. Not every category below is collected from every person.

Interaction or categoryInformation that may be involvedSource and intended purpose
Website and direct enquiriesName, work email, phone number, organization, area of interest, enquiry text, submission identifier, and correspondenceYou or your representative; responding, arranging a demonstration, managing the relationship, and maintaining a secure enquiry record
Website technical activityIP address, browser/device details, request times, pages requested, security and error records, and browser-storage identifiers if usedYour browser and relevant website providers; delivery, security, and any separately disclosed measurement
Accounts and relationships, when enabledName, email, account identifiers, authentication information, affiliations, roles, preferences, and support requestsYou, an authorized organization administrator, or a configured identity provider; account access and administration
Jobs and community participation, when enabledResumes, portfolios, profiles, job postings, applications, qualifications, messages, membership or event information, and decisions supplied by the relevant organizationYou, an employer, a sponsoring organization, or an authorized integration; the workflow you use and its identified recipients
Workspace and Creation content, when enabledDocuments, files, software, media, reports, comments, collaboration history, and personal information within those materialsYou, collaborators, an organization, or a configured resource; creating, storing, collaborating, and authorized sharing
Connected resources and AI, when enabledSelected source content, prompts, attachments, outputs, saved memory, derived search representations such as embeddings, and execution or support recordsYou, authorized collaborators, configured integrations, and generated activity; the approved feature and purposes explained in Section 6
Transactions, when enabledPurchases, invoice details, billing contacts, payment-method references, transaction identifiers, fees, credits, payment status, refunds, and disputesYou, the relevant seller or organization, and payment providers; administering the transaction and required records
Credentials, when enabledHolder identifiers, eligibility information supplied by the organization, credential status, presentation data, and verification activityYou, the responsible organization, and verification interactions; issuance, maintenance, and the disclosed verification purpose
Service operations, when enabledAccess and activity records, timestamps, device/network information, usage and billing measures, errors, security events, and audit historyYour activity, Customer configurations, and service providers; operation, support, security, and accountability

Content can include sensitive personal information depending on what people submit. Do not submit information unnecessary for the requested task. A feature that requests sensitive information is subject to the notices, permissions, and additional protections required for that information. A Customer's upload is not, by itself, permission for every use.

3. Purposes and Limits

For the relevant interaction, Fernain handles information to respond to enquiries; provide and administer the selected Service; authenticate accounts; support authorized collaboration and sharing; carry out Customer instructions; process agreed transactions; maintain credential functions; troubleshoot; detect and address fraud or unauthorized access; maintain appropriate records; and meet legal obligations.

We limit the use of website relationship records and product information to the purposes that apply to them. Broad references to "improving services" do not authorize Fernain to reuse private workspace content, resumes, applications, AI prompts, or outputs for unrelated model training, advertising, or general product development. Any such additional purpose requires a separately assessed lawful basis or authority, clear disclosure, and consent where required; existing commitments still apply.

Customer instructions are limited by the DPA, applicable law, and the rights of individuals. A contract with an organization does not let it authorize a use it has no right to permit. Fernain remains responsible for duties that apply to its own processing.

4. Jobs, Public Content, and Organization Visibility

A resume, portfolio, job listing, branded page, or other material can have different audiences. Before you submit or publish through an enabled feature, we explain whether the material will be public, shared with an employer or other identified recipient, or restricted to an authorized workspace. Check the audience shown for the particular feature before sharing.

For Hire and internal candidate lookup: Company lookup includes only profiles candidates choose to make discoverable to that audience. Fernain may charge partners for access, and authorized partners may sell company access or provide it without charge. Buying or receiving access does not make private applications or other non-discoverable records available through candidate lookup. Candidates can opt out of discovery; doing so changes their participation in future discovery and does not recall copies already received by others. See Section 8 for this commercial access model and applicable privacy choices.

If you make material public, anyone who can access it may view, copy, index, or redistribute it. Search engines and other recipients may retain copies after you change or remove it. A restricted job application is not automatically a public portfolio. An employer may retain an application under its own lawful requirements after receiving it; its privacy notice explains that use.

An organization's administrators may access information within their authorized workspace to administer accounts, membership, applications, or other organizational workflows. This does not automatically include your unrelated organizations, personal profile, private materials outside that workspace, or other product activity. Consult the relevant organization's notice for its visibility and monitoring practices.

Customer branding or a custom domain does not by itself identify every party's privacy role. The notice for the application, publication, or purchase identifies the responsible organization and relevant recipients. Shared sign-in and related products do not alone permit cross-organization access or a combined personal dossier.

5. Cookies, Browser Storage, Analytics, and Marketing

Websites and Services may use cookies or similar browser storage for functions such as maintaining a session or remembering settings. Hosting and security systems may also receive technical request information. Before using optional analytics or advertising technologies, we will explain the relevant purposes and recipients and obtain any consent or provide any choices required by applicable law. This commitment does not imply that a particular consent banner or preference tool is currently available.

You can generally manage browser storage through your browser settings, although blocking necessary storage may affect a Service. Browser settings do not necessarily stop server-side processing or erase information already collected.

If you receive promotional email from Fernain, you can use the unsubscribe instructions in the message or contact legal@fernain.com. Necessary account, contractual, or security messages may continue.

6. AI and Connected Resources

When an AI feature is enabled, processing may include prompts, selected documents and files, outputs, saved agent or workspace memory, embeddings used for retrieval, and execution, diagnostic, or support records. These records may contain personal information even when they are derived from source material. Saving a memory or making information searchable can create an additional retained copy.

For an enabled AI feature, we explain the purpose and permitted audience through its notice and configuration. Being able to read a document, join a workspace, or connect a resource does not by itself authorize sending its contents to an AI provider. Access permissions and authorization for the destination and AI purpose are separate requirements.

Fernain AI may support a Customer's own provider account or an offering arranged by Fernain; any local option depends on the feature actually available. For a Customer-selected provider, the Customer's account terms may govern that provider's processing. A provider Fernain appoints to process information on a Customer's behalf falls within Fernain's applicable DPA and subprocessor obligations. The relevant agreement and feature notice describe the provider's role for that route.

The provider, account plan, settings, contract, and processing location can affect retention, training, human access, and other uses. No single promise about every provider's no-training or zero-retention treatment is made here. A local model option does not necessarily prevent cloud handling of account, billing, synchronization, telemetry, or support information; any such flows must be disclosed before describing an option as local-only.

Fernain does not currently use information submitted by or processed for Customers or individual Users—including files, prompts, outputs, saved AI memory, connected-source content, and derived copies—to train general-purpose models beyond providing a service specifically requested and authorized by the relevant Customer or User. Model work directed by the appropriate Customer or User, if offered and requested, is distinct from training for Fernain's own general purposes. Before expanding this use, we will clearly disclose the proposed purpose in advance, obtain the separate authorization and any consent required, and respect commitments made when the information was collected. Updating this Policy alone does not authorize retroactive use of previously collected information. This statement concerns Fernain's own practices; third-party provider practices depend on the applicable route and agreement.

A provider substitution or fallback must stay within the applicable authorization, destination restrictions, privacy commitments, and required notices or consent. If those limits cannot be met, the request must not proceed through that alternative without the needed authorization. Shared agents or memory do not automatically authorize sharing across organizations or unrelated personal workspaces.

Disconnecting an integration or revoking future access does not recall data already sent to a provider or delete retained source copies, outputs, memories, embeddings, caches, or audit records. Their handling depends on the applicable retention process, instructions, provider arrangement, and law. See Section 10 for deletion and retention, and contact legal@fernain.com for help identifying the relevant route.

7. Recipients and Disclosure

Depending on the purpose and configuration, information may be disclosed to:

  • Service providers and subprocessors: providers of hosting, databases, communications, support, security, payments, and permitted AI processing, to perform their contracted functions. Their status and obligations depend on the service and actual agreement.
  • Customer organizations and authorized administrators: information within their authorized organizational scope, for the purposes described in the relevant notice and agreement.
  • Recipients you or an authorized organization direct: employers receiving applications, collaborators, selected integration providers, credential verifiers, or the public where publication is authorized. Some recipients act independently and have their own notices.
  • Professional advisers and authorities: where necessary for advice, compliance with law, legal claims, or proportionate protection against fraud, abuse, security threats, or harm, subject to applicable restrictions.
  • Parties to a business transaction: where needed for a proposed or completed financing, acquisition, reorganization, or similar transaction, with appropriate confidentiality and other safeguards. A transaction does not itself cancel existing privacy commitments or permit incompatible new uses without the necessary steps under law.

An organization cannot authorize access to another organization's information simply because it uses the same platform. Fernain-appointed providers are not all independent recipients, and Customer-selected recipients are not all Fernain subprocessors.

8. Paid Candidate Discovery and Privacy Choices

Fernain Jobs includes a commercial access model in which Fernain sells access to partner organizations, and authorized partners may sell access to companies or provide it without charge. Where that access includes candidate discovery, companies can look up only the profiles candidates choose to make discoverable. A candidate can opt out of that discovery as described in Section 4.

This arrangement gives recipients access to information within the authorized audience and purpose; it does not transfer ownership of a candidate's content or permit unrestricted export, reuse, or onward distribution. A company receiving access without charge does not change the fact that the partner may have paid Fernain for access.

Privacy laws can treat making information available for money or other value as a "sale" in some circumstances. They may separately regulate advertising-related "sharing" or targeted advertising. How those rules apply depends on the actual arrangement and applicable law; a candidate's discoverability choice does not automatically establish a legal exemption or waive statutory rights.

The candidate discovery opt-out controls participation in that feature. It is distinct from any legally applicable sale, sharing, or advertising opt-out, including any required preference-signal handling. Where such legal requirements apply, Fernain will provide the required notice and choices. Contact legal@fernain.com to exercise applicable rights or request information about the relevant processing. This contact supplements any additional method required by law.

Before materially changing the purposes or audiences of these disclosures, we will explain the change in advance, obtain the separate authorization and any consent required, and provide applicable choices. A Policy update alone does not authorize new uses of information collected under an earlier commitment. Existing rights, instructions, and commitments continue to apply.

9. Payments and Credentials

Payments, when enabled: Payment providers may receive billing and payment information needed for a transaction. Fernain may receive transaction identifiers, payment-method references, status, invoice information, refunds, credits, and dispute records. The actual flow determines whether a provider acts for Fernain, a marketplace seller, an organization, or for its own regulated purposes.

Credentials, when enabled: The responsible organization determines eligibility and admission requirements; Fernain may perform technical issuance, status management, and verification functions. For an enabled credential feature, the relevant notice explains the information shown to a verifier, the verification purpose, and any event records retained. Presenting a credential does not itself authorize access to underlying source records.

A wallet pass, QR code, PDF, or screenshot may retain information outside Fernain after revocation or deletion of the original record.

10. Retention, Disconnection, and Deletion

We retain personal information only for as long as needed for the purpose for which it is handled, valid Customer instructions where applicable, and legal or contractual requirements. Retention varies by category; a need to keep some security or compliance records does not justify keeping all content indefinitely.

CategoryWhat determines retention
Enquiries and business correspondenceTime needed to address the enquiry, maintain the relationship, and meet any applicable recordkeeping requirement
Account and profile informationThe active relationship, account-closure process, User rights, and any narrowly justified retained records
Workspace content, resumes, portfolios, and applicationsThe relevant person's authority, Customer instructions, workflow purpose, published retention notice, and export/deletion process; recipients' copies may have separate lawful retention
AI prompts, outputs, memory, embeddings, and tracesThe feature purpose, saved-content settings, diagnostic needs, applicable agreement, and the provider route; removing one source may require separate handling of derived records
Transaction and credential recordsFulfillment, status or verification needs, dispute periods, accounting requirements, and applicable legal obligations
Security, audit, and support recordsA defined and proportionate security, accountability, or support purpose and applicable legal requirements
Caches and backupsThe limited recovery or performance purpose, applicable expiry or rotation arrangements, and propagation of a deletion request

Disconnecting a resource or revoking permission prevents authorized future use as applicable, but is not a deletion request for copies already made. Closing a workspace, cancelling a subscription, deleting a personal account, and deleting data held by an independent employer or provider are also separate actions.

If information must be retained for law, a dispute, or another valid limited purpose, we restrict its use to that purpose and delete it when no longer required. Copies in backups may remain until removed through the applicable backup cycle; they remain protected and subject to applicable deletion obligations if restored. Contact legal@fernain.com for information about retention or deletion for a particular Service.

11. Security

Fernain is responsible for maintaining safeguards appropriate to the information it handles and the requirements of applicable law and agreements. Customers and Users are responsible for devices, credentials, permissions, and configurations under their control. No system is completely secure.

Report a suspected security or privacy incident to legal@fernain.com without including passwords, provider keys, or unnecessary sensitive information. Incident handling and any required notifications remain subject to applicable law and agreed obligations.

12. Privacy Requests and Choices

Depending on your location, the applicable law, Fernain's role, and the information involved, you may have rights to:

  • Request access to information, details of its processing and disclosure, and an available portable copy.
  • Correct inaccurate information or request deletion, subject to lawful exceptions.
  • Restrict or object to certain processing, or withdraw consent where processing relies on consent; withdrawal does not invalidate earlier lawful processing.
  • Opt out of covered sales, sharing, targeted advertising, or certain profiling, and limit certain sensitive-information uses where applicable.
  • Use an authorized agent, appeal a decision on a request, or complain to a competent regulator where those rights apply.
  • Exercise applicable rights without unlawful discrimination or retaliation.

Send a request to legal@fernain.com. Describe the requested action and the Service or organization involved; do not send a password or unnecessary identity documents. Fernain may need proportionate information to verify identity or an agent's authority and protect other people. Verification must be appropriate to the type of request. We do not require identity verification for an opt-out request where applicable law prohibits it, or require you to create an account merely to exercise a right. Any request for additional evidence will be limited to what is necessary.

Where Fernain determines the relevant purpose, Fernain will handle the request under applicable requirements. Where Fernain processes for an organization, it may route the request to that organization and assist under the DPA and law. We will not redirect a request about your independent account to a workspace administrator merely because you also use that workspace. If an independent employer or other recipient controls its copy, its request process may also be relevant.

If a request is refused or limited, Fernain will explain the reason and any applicable review or appeal process, subject to lawful restrictions. An applicable appeal can be sent to legal@fernain.com with "Privacy appeal" in the subject and the earlier request reference. We will respond within the time required by applicable law.

13. Children, Students, and Youth Programs

Our website provides information about software for organizations and teams. Membership organizations may also serve students or other young people. Any product participation by a minor is subject to the eligibility rules and required permissions for that offering; this Policy does not itself authorize a minor to create an account. A youth-related offering requires the notices, consent, and safeguards applicable to its audience and processing.

Customers are responsible for notices and permissions within their control. Fernain remains responsible for obligations that apply to its own activities and cannot transfer all children's-privacy duties to a Customer.

If you believe a child's information has been collected or used without required permission, contact legal@fernain.com. Fernain will assess the concern and take the restriction, deletion, notice, or other action required by applicable law. Do not send additional information about the child beyond what is needed to identify the concern.

14. International Processing

Information may be processed where the relevant Fernain operation, Customer-selected integration, or service provider operates. The locations and transfer arrangements depend on the product and provider actually used; they are not determined by Fernain's registered mailing address. Any agreed location restrictions continue to apply.

Where applicable law restricts an international transfer, Fernain is responsible for complying with the requirements that apply to its part of the transfer. Contact legal@fernain.com for information about processing locations and applicable safeguards for the Service you use. A Customer-selected integration may also have its own location and transfer terms.

15. Changes to This Policy

Fernain will update the Policy when its relevant practices or legal requirements change and update the date shown above. Material changes will receive the notice and, where required, consent appropriate to the change and applicable law before the new use begins.

A policy update does not itself authorize a materially different use of information collected under an earlier commitment. Contractual restrictions, valid Customer instructions, and mandatory rights continue to apply.

16. Contact

Fernain LLC
Privacy and legal enquiries: legal@fernain.com
Registered mailing address: 8 The Green, Ste B, Dover, DE 19901, United States

Back to Fernain

PrivacyTerms
© 2024-2026 Fernain LLC.Built in NYC