1. Controller and processor
RHPrisma, domiciled in the United Mexican States, operates the rhprisma.com site and the app.rhprisma.com portal, and is the controller of administration account data, organization billing data and messages sent through the contact form.
The data of assessed people (employees and candidates) and of those who apply to the Customer vacancies is decided on and controlled by the organization that subscribes to RHPrisma (the "Customer"): the Customer chooses whom to assess, with which instrument and for what purpose. For that data the Customer is the controller and RHPrisma acts as processor, handling it only to provide the service and under the Customer instructions.
As controller, the Customer is responsible for having its own privacy notice towards the people it assesses, having a legal basis to assess them and deciding how it uses the results. RHPrisma makes no decisions about assessed people and does not validate the decisions the Customer makes.
RHPrisma is not intended for people under 18. If the Customer assesses a minor, it is responsible for obtaining the consent of whoever holds parental authority or guardianship.
Contact for privacy matters and to exercise your rights: [email protected].
2. Personal data we process
Administration accounts: name and email of the account you sign in with (Google, Microsoft or a code sent to your email), and your role in the organization (owner, admin or member).
Organization data: legal name, tax ID (RFC), industry, size, name and email of the person in charge of Human Capital and, for paid plans, the tax data for invoicing (tax regime, postal code and CFDI use) and the charge history.
Assessed people: name, email, area, role and internal notes registered by the Customer.
Responses and results: answers, timestamps, folio, computed result (score, health per dimension or risk level) and the IP address the response is sent from. In secure mode we also record how many times the person left the screen and whether the assessment was cancelled as an anomaly.
Technical data: session and sign-in security cookies, and the IP address to prevent abuse (submission limits).
Vacancy applicants: name, email, phone, the CV and the information it contains, the message they send, the stage of the process, the Customer notes, the assessments sent to them and the result of the CV analysis.
Hiring documents, only if the Customer requests them from an applicant: the files the person uploads (for example official ID, CURP, tax status certificate, social security number, birth certificate, proof of address, proof of studies and a bank statement with the CLABE for payroll), the identifiers the system detects in them (CURP, RFC, NSS and CLABE) and the result of their review.
Time tracking and time off, when the Customer has that module: when each person clocks in and out, the hours they log per cost center, who approved them and when, and their time-off requests (type, dates, days, status, who signed them and the reason if rejected), plus the yearly balance of days. The salary band the Customer assigns to each role and, with it, the hourly cost used to cost projects.
Performance reviews: who reviews whom and in what relation (manager, peer, report or self-review), each participant answers and the averages shown.
External staff: name, area, role and notes of the people or suppliers the Customer registers without an email because they are not on its payroll and do not access the portal.
Inventory, when the Customer has that module: which equipment was handed to each person, since when, its brand, model, serial number and tag, and the record of when it was returned.
Contact form: name, email, company and message.
3. Sensitive personal data
Some instruments collect sensitive personal data, especially about health and well-being: the NOM-035-STPS-2018 Reference Guide I (severe traumatic events and their effects), Guides II and III (psychosocial risk factors, including workplace violence) and other well-being surveys.
Before starting any instrument, the person must tick a box stating they have read this Notice and giving express consent to the processing of their answers, sensitive data included. Without that consent the instrument cannot be started. The date and time of consent are stored as evidence together with the response.
This data is used only for the purpose of the instrument and so the Customer can comply with NOM-035. It is protected with reinforced security measures and, within the portal, only the accounts the Customer authorizes can view it (see section 5).
The Guide I result is not a diagnosis: it only indicates whether, under the standard, the person should be referred for a clinical assessment, which must be carried out by a health professional.
CVs may contain sensitive data the person chooses to include, such as health information or beliefs. The job board asks people not to include it, it is not used to evaluate the profile and the artificial intelligence analysis is instructed to ignore it.
Hiring documents may include financial or patrimonial data (the bank account for payroll) and, if the Customer requests a medical certificate, health data. Before uploading the first document, the applicant gives express consent on their tracking page; the date and time are kept as a record.
4. Purposes of processing
Primary purposes, necessary to provide the service: (a) authenticate administrators and control access to the portal. (b) Run assessments: register staff, send email invitations, show the instruments, record answers and compute results. (c) Generate verifiable folios and PDF records. (d) Show the Customer participation progress and NOM-035 compliance. (e) Keep the service secure, including secure mode and abuse prevention. (f) Invoice and charge paid plans. (g) Handle contact messages and rights requests. (h) Recruitment: publish the Customer vacancies, receive applications and CVs, show applicants the progress of their process, email them notices and, when the Customer requests it, analyze the CV with artificial intelligence as an aid to its review. (i) Hiring: receive the documents the Customer requests from the applicant it hires, review them automatically as an aid and let the Customer approve, reject and download them for its personnel file.
The automatic document review only checks that the file can be read, that it looks like the requested document, that it carries the person name and that identifiers are valid. No artificial intelligence is used for this and it approves nothing: each document is approved or rejected by the Customer staff.
The CV analysis is automated and only considers job-related information. No decision is based solely on that analysis: decisions about each applicant are made by the Customer staff. If you applied, you can ask for your profile to be reviewed without the automated analysis.
There are no secondary purposes for portal data: it is not used for marketing, advertising, commercial prospecting or to train third-party models. The only thing measured for an advertising purpose happens on the public site, before an account exists: whether a visit that came from an ad ended in a company being created (section 9). Nothing from the portal, from assessed people or from applicants goes into it.
5. Confidentiality: who sees what
RHPrisma does not show the assessed person their result: it gives them a receipt with a folio. Sharing the result with them is up to the Customer.
In the portal, individual answers and results are shown only to the accounts the Customer authorized within its organization. The Customer decides which of its staff hold those accounts and is responsible for how it uses that information. The monitoring panel shows results in aggregate.
RHPrisma staff do not look at individual answers or results, except when needed to provide support at the Customer request, keep the service secure and running, or meet a legal obligation, and always under a duty of confidentiality.
The public folio verification page confirms the record exists and shows the person name, the instrument, the organization and the date. For NOM-035 questionnaires it does not show the questionnaire name, only "Confidential questionnaire". It shows no answers or results.
PDF records include results and how they were computed, but do not reproduce survey answers.
People who apply to a vacancy see on their tracking page only the stage of their process, without the Customer notes or the analysis of their CV. If documents are requested, they see there which ones are missing and upload them, but nothing can be downloaded from that link: only the Customer accounts can see them.
6. Where the information is stored and for how long
Portal information, CVs included, is stored on the service servers operated by RHPrisma. Traffic between your browser and the service travels encrypted through the Cloudflare network. Within the portal, each organization only accesses its own information.
In your browser, RHPrisma only stores interface preferences (light or dark theme and the guided tour) and portal form drafts; separate from that are the session, measurement and advertising cookies described in section 9. No answers, results or history are stored there.
PDF records are generated when the Customer requests them and are not stored permanently on the server.
Data is kept while the Customer keeps its account active. If it closes the account or requests deletion, the data is removed, except what must be kept under a legal obligation (for example, tax information for the period required by law).
If the organization is on the Free plan, or its paid plan ended and was not renewed, and 10 consecutive months go by without anyone from the organization signing in, its account and all its information are permanently deleted, with prior email notice to its administrators (Terms & Conditions, section 14). RHPrisma does not provide backups: internal ones only serve to recover the service from failures and are deleted automatically after 90 days.
Applicant data, hiring documents included, is kept while the Customer keeps the vacancy and its account, or until it deletes it. The Customer can delete an applicant, their CV, documents and history at any time. Once the documents are added to its personnel file, deleting them from the portal is recommended.
7. Processors and transfers
We do not transfer personal data to third parties for those third parties own purposes, except when required by a competent authority or in the other cases where the law allows it without your consent. The exception is advertising measurement on the public site: what Google Ads receives there (section 9) is also used for its own measurement and advertising purposes, not only under our instructions. That is why it is limited to what that section describes, and nothing from the portal goes into it.
We rely on providers that process the data under our instructions: Google LLC and Microsoft Corporation (sign-in), Cloudflare, Inc. (network, security and site delivery), the configured email provider (Resend or SendGrid) for invitations and notices and Mercado Pago to process payments. RHPrisma does not receive or store card data.
CV analysis with artificial intelligence, only when the Customer requests it, is done by a language model running on RHPrisma servers: the CV is not sent to external artificial intelligence providers.
Some of these providers may process data outside Mexico. These communications to processors do not require your consent under the law.
8. ARCO rights and withdrawal of consent
You may exercise your rights of Access, Rectification, Cancellation and Objection (ARCO), withdraw your consent and limit the use or disclosure of your data by writing to [email protected] with your name, the account or email you took part with, and a clear description of your request. To protect your data, we may ask you to prove your identity or, where applicable, legal representation before handling the request. We will respond within the timeframes set by law.
If you are an assessed person or applied to a vacancy, the controller of your data is the organization that sent you the instrument or published the vacancy: you can contact it directly, or write to us and we will channel your request.
9. Cookies and local storage
The cookies RHPrisma sets are only the strictly necessary ones: "skillcheck_session" keeps you signed in (signed, HttpOnly, SameSite=Lax, expires after 12 hours) and "skillcheck_oauth_state" protects sign-in and is removed once the flow ends. Any other cookie you find on the site is set by Google on the public pages, and those are the ones described below.
Measurement on public pages: the public RHPrisma site (home, pricing, how it works, contact, the welcome page and job boards) uses Google Analytics 4, which sets its own cookies ("_ga") to count distinct visitors and which pages are viewed. Google processes that data as our processor; your IP address reaches it when your browser connects to its servers but, according to its documentation, Analytics 4 does not store it. You can block it with Google’s official opt-out add-on or your browser’s cookie settings, and the site keeps working.
Where we do NOT measure: there is no third-party analytics in the HR portal, the team portal, the questionnaires and exams, or the personal links for certificates, applications and performance reviews. Those URLs contain your identifier and never leave RHPrisma.
Advertising: the Google Ads tag loads on every public page, because without it there is no way to link a visit with the ad it came from. Only one thing is counted, and on a single page: on the public welcome page, whether that visit ended in a company account being created.
When that signup is counted, what travels to Google Ads is: a random single-use reference, which is what keeps a page reload from counting the same signup twice; a fixed value of 1 and the currency MXN, the same for every signup and unrelated to what you pay; the address of the welcome page, which carries nothing of yours (no email, no company, no token); and which site you came from, when it is an external one —if you come from an address RHPrisma does not measure, such as the portal, that is not sent—. As on any site that uses its tag, Google also receives what the tag collects on its own: the address and title of the page you are viewing, the language and characteristics of your browser, the ad click identifier (the "gclid" parameter) when the address you arrived with carries it, and your IP address, which reaches it simply because your browser connects to its servers. Your email, your company name, your plan and the address of any private page are never sent.
To attribute the visit to the ad, Google Ads sets its own cookies on the site domain; the one that always appears is called "_gcl_au". That is where it keeps what it needs to link the signup with the ad, and it is why attribution works even though the click and the signup happen at different moments.
We do not sell data and we do not run profile-based targeted advertising: RHPrisma does not send Google lists of people or portal information to target ads, and the advertising cookies are the attribution ones just described, which only appear on public pages. You can block them from your browser and the site keeps working. If you block the necessary cookies you will not be able to sign in.
Cookieless visit statistics: on public pages and job boards we record which page was opened, which site you came from (for example LinkedIn or Google), the approximate country and city reported by our network provider, and whether it was a phone or a computer. We do not store your IP address: to count distinct visitors we use a fingerprint that changes every day and cannot identify you or follow you from one day to the next. The company that publishes a vacancy only sees these figures in aggregate, never per person. They are kept for 13 months. Private links (assessments and application tracking) are not recorded.
10. Security
We apply reasonable administrative, technical and physical measures: encrypted connections (HTTPS), signed sessions, access control by organization and role, secure mode in assessments and abuse limits. No system is infallible. If we detect a breach that significantly affects your rights, we will inform you as required by law.
11. Changes to this Privacy Notice
Any change to this Notice will be published on this same page with its update date. We recommend reviewing it periodically.
12. Legal framework and authority
This Notice is governed by the Mexican Federal Law on the Protection of Personal Data Held by Private Parties (Official Gazette, 20 March 2025), its regulations and applicable guidelines. If you believe your rights were violated, you may turn to the Secretaría Anticorrupción y Buen Gobierno (Ministry of Anti-Corruption and Good Governance), the authority for personal data held by private parties. Any dispute is subject to the competent laws and courts of the United Mexican States.
Questions, or want to exercise your rights?
Write to us and we will reply within the legal deadlines.
[email protected]