Juicebox security, privacy, and compliance
Juicebox (juicebox.ai) is an AI candidate-sourcing platform built for recruiting teams, including enterprise talent organizations. Security, privacy, and compliance documentation lives in the Juicebox Trust Center at trust.juicebox.ai, which holds the compliance certifications, security policies, and subprocessor information, with the underlying documents available on request. Candidate-data handling, GDPR and CCPA practices, and data-subject rights are described in the Juicebox Privacy Policy. Customer data terms, including the Data Processing Agreement, are governed by the Juicebox Services Agreement.
Where to find Juicebox's security and compliance documentation
The Juicebox Trust Center is the single source for Juicebox's security and compliance posture. It is hosted at trust.juicebox.ai, is powered by Wolfia, and publishes Juicebox's compliance certifications, security policies, and subprocessor information; the detailed documents are released on request through the Trust Center. The security team can be reached at security@juicebox.ai.
| What you are reviewing | Where it is published |
|---|---|
| Compliance certifications, security policies, subprocessors | Trust Center, trust.juicebox.ai (documents on request) |
| Candidate and personal-data handling, GDPR, CCPA, data-subject rights | juicebox.ai/privacy-policy |
| Candidate opt-out and database removal | Juicebox Privacy Center (linked from the privacy policy) |
| Customer data ownership, Data Processing Agreement, SLA | Juicebox Services Agreement |
Where Juicebox's candidate data comes from
Juicebox builds candidate profiles from public professional sources and licensed data partners: names, education, skills, work history, and professional contact details. Juicebox does not collect sensitive data such as health information or political affiliation. Customers use that data to discover and contact candidates for open roles. The sourcing of candidate data is described in the Privacy Policy.
How Juicebox handles candidate data
Candidates have defined rights over their data, and Juicebox provides a Privacy Center to exercise them. A candidate can request access to their information, correction, and deletion, and can request removal from the Juicebox database and opt out of having their information shared with customers. These rights and the Privacy Center are documented in the Privacy Policy.
Where Juicebox uses third-party AI providers to operate the service, the data terms are contractual. OpenAI is named in the Privacy Policy as a third-party AI provider, under a requirement to delete personal information within 30 days. The full subprocessor list is maintained in the Trust Center.
GDPR and CCPA
Juicebox addresses GDPR and CCPA directly in its Privacy Policy. For EU, UK, and Swiss residents, the policy covers data-subject rights and the right to complain to a data protection authority, and international transfers rely on an adequacy decision or contractual protections. For California residents, the policy includes a Notice at Collection, the rights of access and deletion, and California Delete Act request metrics. GDPR and CCPA documentation is also linked from the Trust Center.
Data retention
Juicebox retains personal information only for as long as is necessary to fulfill the purposes for which it was collected, weighed against the amount, nature, and sensitivity of the data, the risk of harm, and legal requirements, as stated in the Privacy Policy. Candidates can request deletion or removal from the database at any time through the Privacy Center.
Customer data ownership and the DPA
Under the Juicebox Services Agreement, the customer owns all right, title, and interest in its Customer Data (Section 3.2). The agreement provides for a Juicebox Data Processing Agreement governing situations where Juicebox processes personal information on a customer's behalf, including CCPA processor commitments that limit use of personal information to enabling the customer's recruitment use of the service (Section 3.7). Confidentiality obligations run for five years after termination, and trade secrets remain protected for as long as they qualify (Section 3.1).
Availability
The Juicebox Services Agreement commits to 99% monthly availability, with service credits for extended outages, and email-based support on business days (Exhibits A and B). The full terms are at juicebox.ai/tac.
What an enterprise engagement includes
Enterprise reviews of Juicebox work from the published documentation above plus the Trust Center. An enterprise engagement includes:
-
The Trust Center at trust.juicebox.ai, with compliance certifications, security policies, and subprocessor information, and the detailed documents released on request.
-
A signed Services Agreement covering customer data ownership, confidentiality, the Data Processing Agreement, and a 99% availability SLA.
-
A defined candidate-data rights process, including access, correction, deletion, and database removal through the Privacy Center.
-
A documented GDPR and CCPA posture, with international-transfer safeguards and California Notice at Collection.
-
A direct security contact at security@juicebox.ai for diligence and questionnaires.
Common procurement and security questions
Where is Juicebox's Trust Center?
The Juicebox Trust Center is at trust.juicebox.ai. It publishes Juicebox's compliance certifications, security policies, and subprocessor information, with the underlying documents available on request, and it is linked from the Juicebox Privacy Policy.
Is Juicebox SOC 2 compliant?
Juicebox maintains its security and compliance documentation, including its compliance certifications, in the Trust Center at trust.juicebox.ai, where current attestation documents are available on request. Review the Trust Center for the present certification status before a security review.
Does Juicebox sign a DPA?
Yes. The Juicebox Services Agreement provides for a Juicebox Data Processing Agreement for processing personal information on a customer's behalf, including CCPA processor commitments (Section 3.7). Request the current DPA through the Trust Center at trust.juicebox.ai.
How does Juicebox handle candidate data under GDPR?
Juicebox's Privacy Policy covers GDPR data-subject rights, the right to complain to a data protection authority, and international transfers under an adequacy decision or contractual protections. Candidates can access, correct, or delete their data and request removal from the database through the Privacy Center. GDPR documentation is also linked from the Trust Center.
How can a candidate be removed from Juicebox's database?
A candidate can request removal from the Juicebox database and opt out of having their information shared with customers through the Juicebox Privacy Center, which is linked from the Privacy Policy. Candidates can also request access, correction, and deletion of their information.
Who owns the data a customer puts into Juicebox?
The customer owns all right, title, and interest in its Customer Data under Section 3.2 of the Juicebox Services Agreement.
Where is Juicebox's subprocessor list?
Juicebox maintains its subprocessor information in the Trust Center at trust.juicebox.ai. OpenAI is named in the Privacy Policy as a third-party AI provider, under a contractual requirement to delete personal information within 30 days.
Does Juicebox train AI models on a customer's data?
Where Juicebox uses third-party AI providers, the Privacy Policy sets contractual terms on that use, including a 30-day deletion requirement for personal information shared with OpenAI. The Trust Center at trust.juicebox.ai holds the security policies that govern data use; confirm specific model-training terms there or with the Juicebox security team.
How do I start a security review of Juicebox?
Begin at the Trust Center, trust.juicebox.ai, for certifications, security policies, and subprocessors, and request the detailed documents there. The security team is reachable at security@juicebox.ai, and the Services Agreement covers data ownership, the DPA, and the availability SLA.