.png)
Illumio, Inc. Recruiting and Hiring Privacy Statement
October 29, 2025
This Privacy Statement describes the practices of Illumio, Inc. and its subsidiaries around the world (”Illumio,” “us,” "our" or “we”) regarding the collection, use and disclosure of personal information (“personal data”) collected from you in order to perform our obligations under the law, consider your application for employment with us and onboard you as an employee of Illumio if we offer you a position with us.
This Privacy Statement provides you with information about the type of data we collect, why we collect it, with whom we share it and how we protect it during the recruiting and hiring process.
This Privacy Statement does not form part of any contract of employment should you be offered employment by us and does not cover the handling of our employee personal data. We cover the collection and processing of employee personal data through internal policies, processes and notices.
For additional information about our collection, use and disclosure of personal data from users on our websites at www.illumio.com, please go to https://www.illumio.com/legal/privacy-policy.
Personal Data We Collect
You may choose to register with our applicant tracking system or provide information to one of our recruiters in order to receive information about new job postings, make inquiries about job openings or apply for a position with Illumio.
When you do, we will collect the following types of personal data:
- name;
- contact information (physical address, e-mail address(es), telephone number(s)); and
- other identifying data required by applicable laws.
You may also provide us with additional personal data about yourself including, for example, education, work history and references. After you register in our applicant tracking system, you will be asked to upload a prepared resume or build a resume using skills fields or, if you so choose, import information from your social media account. If you do, we require you to provide certain information.
The personal data we request and that you voluntarily choose to provide will depend on the job you are seeking. If you do not provide the information required, we may be unable to process your application.
Unless requested for a specific legal obligation, you should not provide data relating to your:
- racial or ethnic origin;
- political opinions;
- philosophical or religious beliefs;
- membership of a trade union or political party;
- physical or mental health;
- sexual life or sexual orientation; or
- criminal convictions or offences.
If you provide us with personal contact information about another person, for example, by providing a reference or job referral, it is your responsibility to ensure that the person is aware and consents to you providing his/her personal contact information.
We may also receive personal data from third parties. For example, if you have been hired through a third party staffing or recruiting firm, we will receive information on your experience and qualifications. Those providing candidate referrals also provide personal data to us. Where permitted or otherwise authorized by law, information received from third parties may include the results of background checks.
How We Process Personal Data
We use the personal data you provide to:
- manage your registration in our applicant tracking system;
- communicate with you about the recruiting and hiring process, set up and conduct interviews and assessments;
- conduct background checks, as required or legally permitted by applicable local law;
- process your job application;
- conduct onboarding activities if you are offered a position, such as issuance of a badge, training, assignment of equipment and access to systems;
- comply with legal requirements;
- keep your record for future hiring needs, including for the purpose of communicating with you and providing you with information regarding potential career opportunities that suit your profile; and
- operate and improve our applicant experience that may include sending you a survey about your experience.
If you are hired, we will use your personal data for onboarding, including to set up necessary business processes for your employment with Illumio such as payroll, training, benefits, administration of your participation in applicable benefit plans offered by Illumio, expense reimbursement, performance management, company directory listing and access to company facilities, network and applications.
Where required by law, we provide aggregated statistics about candidates using the personal data you submit. These statistics are anonymous.
At all times, we will process your personal data fairly and lawfully. We will handle your personal data in accordance with this statement unless it conflicts with stricter requirements of applicable law in which case applicable law will prevail.
Use of AI/ML Technologies in Recruiting and Interviewing
Illumio may use artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the recruiting and interviewing process. These tools are designed to support our hiring teams and improve consistency, efficiency, and fairness in candidate evaluation.
Application Screening
AI/ML tools may be used to assess applications against job-specific qualifications. These assessments help identify potentially qualified candidates but do not make automated hiring decisions. All applications are reviewed by human recruiters. Candidates may opt out of AI/ML-assisted screening by completing this opt-out form (also provided in the application interface.) Opting out will not negatively impact your application, which will be reviewed manually
Interview Notetaking
Illumio may also use AI-powered tools to assist with interview documentation. These tools join interviews as silent participants and generate structured summaries and feedback. Notes are stored securely and are accessible only to authorized personnel. Interviewers may edit or delete AI-generated notes at any time. Candidates will be notified prior to interviews where AI tools are used and may opt out of AI-assisted note-taking without penalty. Opt-out instructions will be provided in the interview invitation or application interface.
Jurisdiction-Specific Notice
For candidates in jurisdictions with specific legal requirements (e.g., New York City), Illumio complies with applicable laws regarding notice, consent, and opt-out periods. For example, NYC applicants have the right to take at least 10 business days to decide whether to proceed with submitting their application through an AI-assisted process.
Notice for New York City Residents: When applying for jobs through the Ashby career site, AI and ML technologies may be used in connection with your application. You have a right to take at least 10 business days to decide whether to proceed with submitting your information through this process. By continuing, you confirm your understanding of this notice. If you choose to proceed before the 10-business-day period expires, you are making a knowing and voluntary decision to do so.
Candidate Communications
Illumio may contact job applicants via SMS/text message for recruitment-related communications, including interview scheduling, application status updates, and other transactional notices. These messages are sent only with the candidate’s prior consent and are not used for marketing purposes unless separately authorized.
By providing your mobile number during the application process, you consent to receive text messages from Illumio for recruitment purposes. You may opt out at any time by replying “STOP” or using the opt-out mechanism provided in the message. Opting out will not affect your application status or consideration.
How We Protect Personal Data
We use reasonable security procedures and technical and organizational measures to protect against accidental or unlawful destruction, loss, disclosure or use of personal data we handle. Our network and systems used to provide services are governed by corporate Information security policies, which are based upon standards, including International Organization for Standardization (ISO) 27001 and National Institute of Standards and Technology (NIST). We limit access to and use of your personal data to authorized persons and trusted third parties who have a reasonable need to know the information in order to perform our services and business operations and who are bound by confidentiality obligations.
Illumio is subject to the investigatory and enforcement powers of the Federal Trade Commission. Illumio is responsible for and may be held liable in the event of onward transfers to third parties. Provided that an individual has invoked binding arbitration by delivering notice to Illumio organization and following the procedures and subject to conditions set forth in Annex I of Principles, Illumio is obligated to arbitrate claims and follow the terms as set forth in Annex I of the DPF Principles.
How Long We Retain Personal Data
Illumio retains your personal data only for as long as necessary to fulfill the purposes for which it was collected. These purposes include evaluating applications, complying with legal obligations, and considering candidates for future employment opportunities. If a candidate is not hired, Illumio may retain their personal data for up to two years from the date the last position they applied for is closed. This retention period allows Illumio to consider the candidate for other roles that may arise. However, candidates may request deletion of their personal data at any time, and such requests will be honored unless a legal or regulatory obligation requires continued retention. Instructions for submitting a deletion request are provided in the “How to Exercise Rights in Relation to Personal Data” section of the policy.
If you are offered and accept employment with Illumio, the personal data we collected during the application and recruitment process will become part of your employment record and we may use it in connection with your employment consistent with our employee personal data use and privacy policies. In certain cases, Illumio may be required to retain specific records for longer than the standard period to comply with legal requirements, such as audit obligations or dispute resolution processes.
Where no further legitimate basis exists to retain identifiable personal data, Illumio may anonymize and aggregate candidate data during the initial retention period. This anonymized data, which no longer identifies individuals, may be retained beyond the two-year window for analytical and compliance purposes.
How to Exercise Rights in Relation to Personal Data
We rely on you to provide accurate, complete and current personal data to us. If you need to correct or update the personal data you provided to us, please email us at [email protected].
You may have certain rights in relation to your personal data, subject to to local data protection laws. If you would like further information in relation to these or would like to exercise any of them, please contact us at [email protected]. Depending on the applicable laws these our rights may include:
- to obtain confirmation from us if we are processing your personal data;
- to access any personal data we hold about you;
- to request that we correct inaccurate personal data and to have incomplete data completed;
- to object to the processing of your personal data;
- to prevent the processing of your personal data for direct marketing purposes;
- to provide your personal data to a third party provider of services;
- to receive a copy of any personal data which we hold about you;
- to restrict processing of your personal data; and
- to erase your personal data we are holding about you.
We will consider all such requests and provide our response within a reasonable period (and in any event any time period required by applicable law). You may submit personal data requests by contacting us at [email protected]. Please note, however, that certain personal data may be exempt from such requests in certain circumstances. If an exception applies, we will tell you this when responding to your request. We may request you provide us with information necessary to confirm your identity before responding to any request you make.
In compliance with the EU-U.S. DPF (as defined below) and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF (as defined below), Illumio commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.
How We Process and Transfer Personal Data Across International Borders
Illumio is a global enterprise based in the United States with operations in countries around the world. Authorized Illumio personnel and third parties acting on our behalf may access, use and process personal data collected from you in a country that is different from the country where you entered the personal data, which may have less stringent data protection laws. As a network security company, Illumio has implemented global privacy practices for processing personal data protected under various data protection laws. Illumio transfers personal data between the countries in which we operate in accordance with the standards and conditions of applicable data privacy laws, including standards and conditions related to security and processing and acceptable transfer mechanisms.
Illumio complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Illumio has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. Illumio has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
Changes to this Privacy Statement
Any personal data that we process is subject to the Privacy Statement in effect at the time such personal data is processed. We may, however, modify and revise this Privacy Statement from time to time. If we make any material changes to this Privacy Statement, we will notify you of such changes by posting the updated Privacy Statement on this website or through other means, and we will indicate when such changes will become effective.
Questions?
Please contact us at [email protected] if you have any questions about our Privacy Policy.