1. Introduction and Scope
This Privacy and Security Policy governs the data protection and cybersecurity practices of Flux Hiring (“we,” “us,” or “our”). As a global remote human outsourcing agency, we deploy world-class professionals (“Talent”) to our partner organizations (“Clients”).
Because we operate across international borders, ensuring the integrity of our hardware, the privacy of our Talent, and the strict isolation of our Clients’ proprietary data is fundamental to our operational model. This document establishes how data is handled and enforces the strict boundaries of our Shared Responsibility Model.
2. Definitions
- Talent: The remote professional hired by Flux Hiring to provide services to the Client.
- Client: The company leasing the services of our Talent.
- Endpoint: The physical hardware (laptop/desktop) and baseline software provided directly by Flux Hiring to the Talent.
- Client Data: Any proprietary information, source code, customer data, or internal systems owned by the Client and accessed by the Talent.
- Personal Data: Information that identifies an individual, primarily relating to our Talent’s HR and payroll profiles.
3. Information Collection and Storage
We strictly adhere to the principle of data minimization, collecting only what is necessary for employment, legal compliance, and endpoint security.
A. Talent Data (HR & Payroll)
To legally employ, manage, and compensate our Talent across various jurisdictions, we collect:
- Identification: Passports, national ID cards, and tax identification numbers.
- Contact Information: Physical addresses, personal emails, and emergency contacts.
- Financial Data: Bank account details for payroll processing.
- Storage: This data is siloed in encrypted, access-controlled HR Information Systems (HRIS). It is never shared with the Client beyond standard professional profiles (name, qualifications).
B. Client Corporate Data
For our B2B operations, we collect billing details, corporate contact information, and Master Service Agreements (MSAs). We do not collect, store, or process the operational data that Clients share with Talent.
C. Endpoint Telemetry (Security Data)
We monitor the health and security of the physical endpoints. We collect:
- System health metrics and patch statuses.
- Threat detection alerts and EDR telemetry.
- Network connection metadata (for Zero Trust verification).
- Privacy Guarantee: We do not employ “bossware.” We do not log keystrokes, capture screen recordings of Client work, or read the content of Client emails or databases accessed by the Talent.
4. Equipment Security and Endpoint Management
Flux Hiring provides physical hardware to all onboarded Talent to establish a hardened, uniform security baseline. Bring Your Own Device (BYOD) is strictly prohibited.
Our endpoint security architecture includes:
- Enterprise EDR: Next-generation Endpoint Detection and Response deployed on all machines to block malware, ransomware, and unauthorized scripts in real-time.
- Mobile Device Management (MDM): Centralized administration allowing Flux Hiring to enforce security policies, push mandatory OS updates, and remotely wipe devices.
- Hardware-Level Encryption: Full Disk Encryption (FDE) utilizing BitLocker (or Apple FileVault) backed by TPM 2.0 hardware modules. Data at rest is inaccessible without authorized credentials.
- Access Control: Standard user accounts are stripped of local administrator privileges. Talent cannot disable security tools, alter registries, or install unapproved software.
5. Alignment with NIST Standards
Our security posture is mapped to the National Institute of Standards and Technology (NIST) frameworks to ensure defense-in-depth:
NIST Framework | Implementation at Flux Hiring |
NIST CSF (Core) | Continuous identify, protect, detect, respond, and recover capabilities managed via our Security Operations Center. |
SP 800-207 (Zero Trust) | Perimeter-less security model. Every access request is verified regardless of the Talent’s local network environment. |
SP 800-53 (Controls) | Strict access controls, continuous vulnerability monitoring, and configuration management on all endpoints. |
SP 800-111 (Encryption) | Mandatory, non-bypassable cryptographic protection of data at rest across the entire hardware fleet. |
6. The Shared Responsibility Model
Flux Hiring operates on a strict Shared Responsibility Model. We secure the vessel; the Client secures the cargo.
Area of Responsibility | Flux Hiring | Client Company |
Physical Hardware | Procurement, shipping, and maintenance. | None. |
Endpoint Security | MDM, EDR, OS patching, disk encryption. | None. |
Application Access | None. | Provisioning accounts, VPNs, SaaS tools. |
Identity & Authentication | None. | Enforcing MFA, SSO, and RBAC policies. |
Data Governance | None. | Securing proprietary data and databases. |
Activity Auditing | Monitoring device health and security alerts. | Auditing Talent actions within Client systems. |
7. International Data Transfers and Third Parties
Because we operate globally, Talent Personal Data may be transferred across borders to facilitate payroll and compliance.
- Sub-processors: We utilize vetted third-party vendors (e.g., global payroll providers like Deel or Remote) to execute employment contracts. These vendors are bound by strict Data Processing Agreements (DPAs).
- Legal Compliance: We comply with applicable cross-border data transfer regulations, utilizing Standard Contractual Clauses (SCCs) where required by frameworks such as the GDPR.
8. Incident Response and Breach Notification
Our response protocols are defined by where the incident occurs.
- Endpoint Compromise (Flux Responsibility): If our telemetry detects a severe threat on a Flux endpoint, the device is automatically isolated from the internet via EDR. If we determine the compromised endpoint may have exposed a Client’s environment, we will notify the Client’s designated security contact within 24 hours so they can instantly revoke the Talent’s access credentials.
- Infrastructure Breach (Client Responsibility): If a Client experiences a data breach within their own infrastructure, cloud environments, or software platforms, Flux Hiring holds no liability. We do not manage or store Client operational data.
9. Privacy Rights
Subject to local laws (such as GDPR or CCPA), Talent and Clients have the following rights regarding their data stored by Flux Hiring:
- Right to Access: Request a copy of the personal data we hold.
- Right to Rectification: Request correction of inaccurate data.
- Right to Erasure: Request deletion of personal data (subject to our legal requirements to retain payroll/tax records).
- Right to Restrict Processing: Limit how we use your data under specific circumstances.
10. Data Retention and Deletion
- Talent Data: Retained for the duration of employment and up to 7 years post-termination to comply with international tax and labor laws.
- Client Data: Retained for the duration of the MSA and standard corporate accounting lifecycles.
- Endpoint Decommissioning: Upon contract termination, the MDM system issues a cryptographic wipe command. This destroys the encryption keys, rendering any localized cache of Client data permanently unrecoverable before the hardware is returned or destroyed.
11. Contact Information
For privacy inquiries, security audits, or to exercise your data rights, please contact the Flux Hiring Information Security and Privacy Office:
Email: Info@fluxhiring.com
Phone: +92 323 5126309
Disclaimer: This is a comprehensive baseline policy. Prior to deployment, this document must be reviewed by qualified legal counsel to ensure strict compliance with the specific labor, privacy, and cybersecurity laws of the jurisdictions in which you operate and hire.