Phenom
Phenom · Agent platform · US · www.phenom.com
services/phenom.yamlVendor data-handling terms
The policy describes Phenom as processor for its clients' candidate and employee data and does not state whether that data is used to train models.
“We may be asked by our Clients to amend, update, or delete your personal information on behalf of our Clients in which case we will do so in accordance with the terms of our contract with our Clients.”
“Your personal information may be transferred to, stored, and processed in a country other than the one in which it was provided, which may not be regarded as ensuring an adequate level of protection of your personal information under applicable law. / When we do transfer your personal information, we put in place appropriate safeguards (such as standard contractual clauses) in accordance with applicable data protection laws.”
Domains and endpoints
observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.
| Host | Role | Source |
|---|---|---|
| api.phenom.com | api | observed |
| phenom.com | app | observed |
Assessment
Reasoning: An HR and talent platform with AI matching and chat, deployed under enterprise contracts. The public policy does not address training on candidate data; the contract does. Candidate and employee data is Art. 9-adjacent (recruitment decisions) and the deploying employer is controller. Unrated until contract terms are verified publicly.
Flags: Training use of candidate data not stated publicly · Automated recruitment decisions (EU AI Act Annex III) · Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.
Changelog
- 2026-09-16Documented. Retention and transfer terms verified against the Phenom privacy policy; training use not stated.
- 2026-09-15Listed from the Unseen catalogue with observed domains.
Corrections
Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.