Gloat Privacy Policy
For Customers and End Users

Last updated: May 19, 2025


1. INTRODUCTION

 We, at Gloat Ltd. and our affiliated entities (“Gloat”, “we”, “us”, “our”) we respect our customers’ and their authorized users (“End Users” or “Employee” or “You”) privacy, we are committed to protecting their Personal Information when they use our Talent Marketplace and Skills Foundation platform and related services (together, the “Platform” or “Services”). 

This Policy explains how we collect, use, share and secure personal information when we provide services to our customer (your employer). It also outlines your rights and choices in relation to your personal information. 

This Policy only applies to End Users who are employees, staff, individual contractor to whom our customers grant access to use our Platform and Services. For information collected through our website or marketing activities, please refer to our Website Privacy Policy. 

Personal Information means any details, data or information which may personally identify you or may be used to identify you as an individual. It may also include information about how you use our Platform and Services. 

End Users” or “You” means employees, staff and individual contractors of one of our enterprise customers who have been allowed by our customer to access, interact and use the Platform and the Services (End Users). 


2. WHO WE ARE

Gloat is a Software-as-a-Service (SaaS) provider, offering AI-powered solutions for enterprise talent management. Our Platform helps companies identify internal talent, close skills gaps, and promote career mobility using a skills-based approach. Your employer uses Gloat to support internal job mobility, offer you personalized AI-driven career recommendations, including project matching, mentorship, learning, and workforce planning. Gloat processes employee information to enable these functions and services – but always under your employer’s instructions.
Gloat Platform and Services support employers to transition from traditional HR management to dynamic, skill-based talent management, efficiently responding to modern workforce needs, hybrid work models, and the fast pace of technological change.


3. ROLE AND RESPONSIBILITY

 For this Policy, your employer is the “data controller” of your Personal Information and Gloat is the “data processor” acting on behalf of your employer. Gloat’s processing of End Users data and the security measures implemented to protect such data are detailed in and governed by a written agreement between Gloat and each of its customers. 

As a data processor, Gloat will access, store and use the personal information of the individual End User solely for the purpose of providing the Platform and Service to its Customer and will process the data as instructed by its customer, as detailed in this Policy and in accordance with our agreement with your employer. 

As data controllers, Customers decide which of their employees or other authorized individuals are given access to the Platform and Services. As a data controller they designate the administrator(s) (“Administrator”) who act on behalf of the Customer and can customize and configure the Customer account on the Platform, control the data they put into the Platform, mange individual End User account, access to insights and reports tools and administrator tools. The responsibility for establishing the appropriate policies and legal basis with respect to your personal information lies with your employer, which will process such personal information in accordance with its privacy policy, Gloat has no direct relationship with individual End Users, it does not own or control your Personal Information. If there is any question or query, an individual shall reach out to their employer. 

You hereby acknowledge that you are not legally required to provide us with any information, your participation on the Platform and use of the Services is voluntary. However, you acknowledge that we will not be able to provide you or your Employer with the Services without receiving your Personal Information. 


4. DATA COLLECTION

In the course of providing the Platform and Services Gloat processes certain Personal Information you and/or our customer (e.g. your employee) provided into the Platform. We use Personal Information as necessary to provide the Services, to provide customer services support and technical support, continue developing our services. 

Your Personal Information is collected in several ways: 

During the Platform account setup, your employer and the account Administrator provide us with certain Personal Information, directly or via integrations into your employer’s HRIS or ATS systems. The customer can customize the type of data requested to set up the Platform account and to create a user profile, such data may include but is not necessarily limited to, your identifiers (name, address, email address), current position at the Employer, Job Code, Job Title and Job Family, department, seniority level. 

When you login to the Platform and Services, you will be requested to upload or otherwise provide additional information about you to create your user profile on the Platform, such as your job history, skills and capabilities, education background, professional experience, photo (avatar), resume (CV) data, as well as any other data allowed by your employer. 

A unique identifying number is assigned by Gloat upon the creation of a user profile. 

Customers may choose to use their SSO integration to enable End Users to log into a user profile on customer account, without disclosing username and password to Gloat. The SSO provider will authenticate the End Users and allow or deny access to the Customer account on the Platform. The SSO provider shares with Gloat authentication information about the End Users as an authorized user of the Customer. 

When you use the Platform and/or the Services, Gloat store information created or generated through your interaction and use of the services, such as information you were tagged in, search or commented on, your offering to participate as a mentor to other employees, Information which may be created by the Platform to match you with Mentorship offerings, job opportunities, internal projects, skills suggestions and other information or opportunities offered through the Platform. We also store data about how you use the services, such as login activity, features used, feedback provided. 

We also receive Personal Information related to you that is added to the Services from other resources, including through third parties’ connections made available by your employer who share your Personal Information with us, such as ATS and LMS systems, and combine this data with Personal Information we already have about you. 

We also receive Personal Information for third parties we are using to provide the Services, see below as detailed under DATA SHARING AND DISCLOSURE. 

Specifically, such data may include: name, address, work email address, Employee ID, Job Code, Job Title and Job Family, work location, current position at the Employer and start date, your employee status (employed/terminated), your function, sub-function, department, seniority level, skills, professional history 3 

(positions), educational history, user photo (avatar), military experience, career development desires (salary, tech stack, perks, partiality of position, learning goals, open to remotes and/or relocation offers), volunteering history, mentorship participation, projects history, resume (CV), offering to . Resume (CV) data may include your private email address, residence, current position at the Employer, profile picture, employment and education history. 

Additional Personal Information you choose to share on your user profile, or which is created in The Platform through your interactions on the platform, including skills and capabilities, your career aspirations and desired skills, internal and external job history, including information you may choose to load from other public platforms, such as LinkedIn or your Resume (CV); information you choose to share as part of your offering to participate as a mentor to other employees, and information which may be created by the Platform to match you with mentorship offerings, job opportunities, internal projects, inferred skills and other information or opportunities offered to you by our AI based on your activity and input. 

Information Collected Automatically. In addition to Personal Information identified above, we also collect and/or otherwise generate certain technical data about you by automated means, such as browser type, IP address, operating system type and version, referring URL, session time. The Platform uses server log files, cookies and similar tracking technologies to collect such technical information from you to remember log-in details, to enable certain features of the services, see below for more detailed information. We also use analytics tools. These tools help us understand users’ behavior on our Services, including by tracking content accessed, click/touch, movements, scrolls and keystroke activities. This helps us to identify usages trends, improve our Services performance and user experience. 

Other Methods. When you contact us for customer support services through our chat feature on our Platform, or our website or by email. 

Other information – depending on the services used by your employer, your employer may share additional information and data (non-Personal Information) that may be processed and used, such information may include job title, job family, job description, job code, job grade, skills required for the job title, mapping skills for job, using Gloat’s AI in conjunction with employer’s HR and business knowledge to assist employers identify the base skills needed to conduct a certain job and to identify if there are any gaps within the skills in your organization, providing your employer with a smart tool to build a dynamic organization, manage its workforce with a skills-based approach, understanding skill gaps and planning workforce reskilling and upskilling initiatives to transform your employer business. 


5. HOW WE USE PERSONAL INFORMATION

We use Personal Information to operate and provide our Platform and Services to our customers and oth-erwise to fulfil our agreement with our customers, to provide customer service support and technical sup-port, to communicate with you, to conduct research and development to improve our Platform and Services, to comply with legal obligations, and to secure and protect your Personal Information and the Platform. 

We use Personal Information to facilitate your participation in the Platform and the Services, allow you to access and make use of the Services offered in the Platform for searching, selecting and introduction of project, jobs and other career opportunities withing your employer. Providing you with smart recommenda-tions for roles, projects and learning and career development withing your employer, matching you with open positions, jobs, protects, mentorships published by your employer, create and update your skills pro-file through AI analysis, to empower you to build the right skills to grow your career withing your employer alongside your employer’s needs, and optimize search results. Your employer may choose to utilize op-tional applications and services of Gloat, which enable your employer to understand its workforce skills gaps, planning workforce and managing and facilitating internal talent mobility, such as assign internal hiring, positions and project, on a skilled-based basis. 

If authorized by your employer, we will enable features that are powered by third party generative artificial intelligence (GenAI). Customer Personal Information is not used to train or fine tune GenAI models or for the benefit of the third-party GenAI vendor. Customer Personal Information is not stored by such third party GenAI vendor. 


Some examples of how we use Personal Information: 

  1. Providing, administrating and facilitating access to the Platform, setting up and creating your user profile, and managing customers or End Users preferences on the Platform account. 
  2. disclosing user’s profile, including Personal Information, information relating to your activities and engagement on the Platform, and generated reports, with your employer and the Administrator. 
  3. Provide technical support and troubleshooting of the Services. 
  4. To provide customer support when you contact us via chat enabled on the Platform, or email or via our ticketing system. We use such Personal Information to verify your identity and retrieve your Platform account data related to your inquiries. 
  5. We record conversations with customers, representatives and Administrators calling our customer support services in order to monitor and improve the service quality provided by our customer support services. 
  6. Communications. To communicate with you via email regarding confirmation of account creation, information regarding skills, jobs and other recommendations and suggestions offered for your on the Platform and its progress, if you were tagged in or commented on the Platform; response to End Users inquiries and questions, to provide service announcements and services updates, prod-ucts and services notifications; to communicate with you and contact you to obtain feedback from you regarding the Platform and Services. Sending updates and other relevant massages content via push notifications to End Users mobile devices, which can be managed from the “option” or “setting” page in the mobile application. 
  7. disclose to third party vendors (including to Gloat’s affiliates), service providers, contractors or agents who perform functions on our behalf with respect to the Services (e.g. for hosting services, messaging solutions embedded in the Platform, product intended to improved users experience from the Platform; customer support portal; help center; CV parsing services; recording and upload of videos; CDN and cybersecurity services) see below additional information under “DATA SHAR-ING AND DISCLOSURE”. 
  8. Improve our Platform experience using data analytics. 
  9. compile anonymous or aggregate information to create analytics, reports and to improve Gloat products and services and develop new products and services. 
  10. Secure our systems, Platform and Services. To protect the safety, integrity of our Customer Personal Information, including any data and information uploaded and input in the Platform by our Customer and their End Users, including monitoring, detecting and preventing abuse, fraud, cyberattacks, illegal use or unauthorized access to our Platform or Services. 
  11. We retain information about you to resolve End Users support request and defend ourselves in legal procedures or claims 


Consent. We may use Personal Information as otherwise explicitly and freely authorized by you. 

6. USE OF ARTIFICIAL INTELLIGENCE (AI)

Gloat leverage artificial intelligence technologies including machine learning (AI) to deliver personalized recommendations for jobs, career pathing, skills, learning, mentorship and more. These insights are gen-erated through analysis of your user profile while simultaneously comparing your information to the career path of other anonymized people using the Platform. We provide these personalized recommendations in accordance with the terms of our agreement with our customer. 

We use anonymous, statistical or aggregated information, which may be based on extracts of your Personal Information, for legitimate business purposes including for testing, future development, improvement, con-trol and operation of the Platform and Services, including for training Gloat proprietary AI powered the Platform and the Services. When we use your Personal Information for the above purposes, it is aggregated 5 

and/or anonymized so that no personal data of the End User is processed. It has no effect on your privacy, because there is no reasonable way to extract data from the aggregated information that can be associated with you. We may share such non-personal information with our partners and retain without limitation for as long as it is needed to serve the purposes identified above. 

AI insights and recommendations are assistive only, you always control whether to follow or approve a recommendation or apply for a job or other opportunity offered to you. Automated decisions without human involvement are not made on the Platform. AI will not automatically apply on behalf of an employee for an opportunity for which it recommended. 

You may request clarification on AI-based suggestions or ask for human review by contracting your employer. 


7. DATA SHARING AND DISCLOSURE

We may share your information with: 

Your employer including authorized Administrator, managers or internal HR teams: your user profile, any information provided to us (including your CV, Personal Information and any other information), will be available the Customer (your employer) who has made the Services available to you and to persons des-ignated by your Employer for the purpose of offering available projects and positions within your Employer. Such information may include your Platform account and profile, your engagement and usage data of the Platform, reports and analytics data, feedback about the Services and other queries you direct to us, so we can address such feedback or query as necessary. 

Your user profile may be viewed by other users in your employer account on the Platform but are not viewable by individuals outside of your organization. Your employer determines the account permissions and privileges to enable access to such authorized administrator and hiring managers, which may include: 

Customer other End-Users: When you apply for opportunities (mentoring, projects, positions), the information shared on your profile can be seen on your candidate card whether you are searched for and/or apply to an opportunity. 

Customer Hiring Team: This data may be accessed by the organization’s Hiring Team, responsible for internal recruitment. 

Customer Administrator – Customer administrative personnel offering technical and functional support on the platform can access this information 

We have no control over the individuals assigned by your employer as the account administrator and the right of access and authorization your employer grants to the account administrator and hiring managers, and how they use and disclose your information. Please note that the information we provide will be subject to your employer’s privacy policy, we will not be responsible for any unauthorized use or disclosure made by the Customer and its designated persons. 

Third Parties Services Provider. We do not sell, rent or lease your Personal Information. We may share your Personal Information with a number of third parties service providers (including Gloat’s affiliates), in order to provide the Platform and the Services to our customers, such as cloud vendors, subprocessors providing us processing solutions or other services, including through tools that enable us to analyse your interaction on our Platform and Services, data analysis, support chat and messaging solutions embedded in our Services (e.g. intercom.com) or products intended to improve user experiences from our Platform (e.g. fullstory.com), analytics reports, customer support, information technology and related infrastructure, auditing and cybersecurity services. These third party are bound by confidentiality obligations and are contractually committed to use your Personal Information only for fulfilling their obligations to Gloat. Such third-party service providers may use artificial intelligence, generative artificial intelligence or other similar technologies, for their specific services. Any other sharing of Personal Information is subject to your employer’s authorization and instructions. 

Compliance with Laws and Law Enforcement. We cooperate with government and law enforcement officials (which may include authorities outside your territory) to enforce and comply with the law. We may disclose any data about you to government or law enforcement officials as we believe in good faith to be necessary or appropriate to respond to claims and legal process (including to subpoenas, search warrant or court o), to protect our or a third party’s property and rights, privacy, safety; to protect the safety of the public or any person, or to prevent or stop any activity we may consider to be, or to pose a risk of being, illegal, unethical, inappropriate or legally actionable. 

Other Transfers. In connection with a merger, acquisition, reorganization or sale of all or substantially all of our shares or assets, or in the event of our bankruptcy, We may transfer some or all of our assets, including among others any Personal Information, to another entity, provided that the receiving entity will comply with this Policy as in effect immediately prior to such a transfer (except if we notify you otherwise). 

Gloat and Gloat affiliates. We may also share Personal Information with companies or organizations affiliated with us, such as subsidiaries and parent companies, with the express provision that their use of such Personal Information must comply with this Policy and the Purpose, including for providing customer support, technical support, research and development. 


8. TRANSFER OF DATA OUTSIDE YOUR TERRITORY

We may store, process or maintain your Personal Information in various sites worldwide, outside your country, including in any country where we have facilities (including in the USA, UK, EU and Israel) or in which we engage service providers, including through cloud-based service providers. Our cloud hosting servers located in the EU and in the USA at the choice of our customers. Our sub processors are typically located in the USA, or in other locations as necessary for providing the Platform and Services. Current list of sub processors and their processing locations is available to our Customer and their Administrator. 

When we transfer Personal Information originates from an End Users in the EEA, where transfer to another jurisdiction requires additional safeguards, we will ensure that such processing will only take place if: (a) the non-EEA country receiving the Personal Information ensures an adequate level of data protection; (b) the transfer is made pursuant to a data processing agreement executed between Gloat and the Customer and between Gloat and suppressors and subject to a lawful transfer mechanism, such as the Data Privacy Framework (where applicable) or the Standard Contractual Clauses adopted by the European Commission or the UK Addendum as applicable, which have been incorporated into such data processing agreement. 


9. COOKIES AND TRACKING TECHNOLOGIES

We use server log data, and automated data collection tools, such as cookies and other similar tracking technologies. A cookie is a small text file that we transfer to your computer’s hard disk for record-keeping purposes. We use cookies to provide our Services and to make your usage of the Platform more efficient, all cookies are essential for the proper functioning and use of the Services. We use cookies to remember log-in details and provide secure log-in, enable certain features of the Services (such as chat support, help center); provide a consistent experience; determine the user’s employer domain and improve security and prevent attacks, and measure site, services, or feature usage. 

The data collected or generated through the cookies is either strictly necessary or functional data for the use of the platform. We do not use cookies on our Platform for marketing or advertising. 

You can instruct your browser, by changing its options, to stop accepting cookies or to prompt you before accepting a cookie from the website you visit. If you do not accept cookies, however, you may not be able to use all portions or all functionality of the Services. 


Our Service may contain links to third party websites and applications, such as sharing button to a social media website. However, this Policy applies only to the Service. These other sources may place their own cookies or other files on your computer, collect data or solicit personal information from you, and they follow different rules regarding the use or disclosure of the information that you submit. You acknowledge that after entering into a third-party website or application (by clicking any link) you will no longer be using the Services and you will solely be responsible for the use of any of these third-party websites or applications. We encourage you to read the privacy policies and other terms of the other sources before using their services. 

10. YOUR RRIVACY RIGHTS

For the duration of your employment with your employer, you may, at any time, access, review, modify or delete the Personal Information you have provided and input into the Platform, by logging into your user profile through your employer Platform account.
You may have certain rights, in accordance with appliable law and depending on where you reside, to review your Personal Information stored in our database, and also update, amend and/or delete your information and profile (including your Platform account); request confirmation from us of whether we are processing Personal Information related to you, receive a copy of that data, so that you could verify its accuracy and the lawfulness of its processing, request the correction, amendment or deletion of the data if it is inaccurate, incomplete, outdated or processed in violation of applicable law.
To exercise these rights or make any requests or queries about the Personal Information we process on behalf of our customer (your employer), please contact your employer‘s Administrator. Gloat operates on behalf of your employer and will support these requests per their instructions.

11. SENSITIVE INFORMATION


We do not intentionally collect or process any sensitive information about you (including things like ethnicity, sexual orientation, religious beliefs, union membership or health information). Please avoid sharing such information of this nature in your CV/resume where possible – however, if this data is received as part of a document, then it will be deemed retained pursuant to your explicit consent if such required by applicable laws. 


12. DATA SECURITY

We are concerned with safeguarding your Personal Information. We employ industry-standard security measures designed to protect your Personal Information from loss, theft, damage, unauthorized access or use and disclosure when it is in our possession or control, including reasonable physical, technical and organizational measures which restrict access to Personal Information. These measures provide sound industry standard security, including encryption at rest and in transit, internal access to your data is limited only for personnel who need to access it as part of their job, and regular audits and vulnerability testing. However, although we make efforts to protect your privacy, no system is completely securer from any wrongdoings, malfunctions, unlawful interceptions or access, or other kinds of abuse and misuse. To learn more about the technical and organization measures we maintain please visit our website https://gloat.com/security-and-compliance/

Please contact us if you believe that your data has been compromised or your interaction with us in no longer secure at: [email protected]

13. DATA RETENTION AND DATA DELETION

We retain different types of data for different periods, depending on the purposes for processing the data, our legitimate business purposes as well as pursuant to legal requirements under applicable law. 


We will need to keep Personal Information for as long as necessary to support the purposes of processing under this Policy which is at least as long as you use the Platform or the Services or our contract with the Employer is in effect, unless we are required by applicable law to delete it, or if you exercise your data subject rights to delete the Personal Information. We will normally keep Personal Information for no more than 3 months after termination or cancellation of the contract or Services with the Employer. In certain cases, we will keep your Personal Information for longer, for additional legitimate business purposes, for example, for record keeping, for cyber-security management purposes, legal proceedings and tax issues. We keep aggregated anonymized data without limitation to improve our services and analytics, and to the extent reasonable we will delete or de-identify potentially identifiable information, when we no longer need to process the data. 

14. ADVERTISING AND MARKETING MATERIAL; CHOICE

We may use your email address to contact you when necessary, including in order to send you reminders, offers and to provide you information and notices about the Services. Note that we may include commercial and marketing information in such emails. For example: invite you to participate in our events, product demos, or surveys. We will engage in marketing activities with your consent or where we have a legitimate interest. 

End User can at any time opt-out of receiving non-transactional email by following the unsubscribed link provided in the email communications; or by managing the End User email preferences on its user profile. Customer can also configure the email preferences settings for all End Users in their account Platform. 

At any time, you may unsubscribe our mailing lists or newsletters by sending us an opt-out request to: [email protected]

15. OUR POLICY TOWARD CHILDREN

Our Services are not meant to be used by persons under 18, as such, we do not knowingly collect personal information from minors aged 13 or younger. Insofar as Personal Information may be collected based on Customer or its End Users’ consent, the data subject must be above the age of 18 (or above the age of 13 if this is the legal requirement in your country). If these age requirements are not met, Customer are required to obtain the consent of the parent or guardian to provide and process information in accordance with this Policy; lacking such consent, we will not supply you with Services. 


16. CHANGES TO THIS POLICY

We may change the terms of this Policy from time to time to reflect new services, changes in the Personal Information or relevant laws, by posting notice on our Services (including on our website, with a five (5) day advance notice. However, substantial changes will be effective thirty (30) days after the notice was initially posted. We will inform you of substantial changes through the channels of communication generally used in such circumstances. 

If we need to adapt the Policy to legal requirements, the amended Policy will become effective immediately or as required. 

17. CONTACT US

If you have any concerns or questions about this Policy, please contact your employer’s Administrator, or our Privacy Team at: [email protected]

We work hard to handle your Personal Information responsibly. If you are unhappy about the way we do this, please contact us and we will make good-faith efforts to address your concerns. 



Copyright © 2025, Gloat Ltd. All rights reserved.