California Applicant Privacy Notice

This Notice applies to job applicants who reside in California pursuant to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, “CPRA”). It describes how Mitek Systems, Inc. (“Mitek,” “we,” “us”) collects, uses, and discloses personal information about California job applicants, and the rights you have with respect to that information.

Our clients and employees trust and expect that we will protect their personal information in accordance with the promises we make. “Personal information” means any information pertaining to an identified or identifiable individual and may include, for example, email addresses, contact details and any similar information provided to us in the course of our business operations. Personal information that is de-identified or anonymized is not considered personal information. This Privacy Policy details our commitment to your privacy.

1. Personal Information We Collect

During the hiring process, Mitek collects the following categories of personal information:

Identifiers:

Name, email address, phone number, postal address, IP address, and other similar identifiers provided during the application process.

Government-Issued Identification and Sensitive Personal Information:

Passport, driver’s license, or other government-issued identity document; immigration and work authorization status. This information is classified as sensitive personal information under the CPRA.

Biometric Identifiers and Biometric Information:

Facial geometry data derived from a selfie image collected during identity verification. This information is classified as sensitive personal information under the CPRA.

Professional and Employment Information:

Current and prior employer information, job titles, employment dates, professional references, and other information contained in your resume or application.

Education Records:

Educational institutions attended, degrees and certifications obtained, dates of attendance, and other information contained in your resume or application.

Background Check Information:

Criminal history (where permitted by applicable law), credit history (where relevant to the role), and other information obtained through third-party background check providers.

Communications:

Correspondence and communications between you and Mitek during the hiring process, including interview notes and assessments.

Inferences:

Inferences drawn from the above categories to evaluate your candidacy, such as assessments of skills, qualifications, and fit for the role.

2. How We Use Your Personal Information

Mitek uses the personal information described above solely for the following purposes:

  • Verifying your identity prior to and during the hiring process
  • Evaluating your qualifications and suitability for employment
  • Conducting background and reference checks
  • Complying with applicable legal and regulatory obligations, including employment and immigration laws
  • Protecting the security and integrity of Mitek’s hiring process
  • Communicating with you about your application

Mitek will not use your personal information, including sensitive personal information, for purposes beyond those listed above without providing you with additional notice and, where required, obtaining your consent.

3. How We Disclose Your Personal Information

Mitek does not sell or share your personal information with third parties for advertising or marketing purposes.

We may disclose your personal information to the following categories of third parties, solely as necessary to carry out the purposes described above:

  • Service providers and contractors — including identity verification vendors, background check providers, applicant tracking system providers, and HR platform vendors, who are contractually obligated to use your data only on Mitek’s behalf
  • Government and regulatory authorities — where required by law, legal process, or to protect Mitek’s legal rights
  • Successor entities — in the event of a merger, acquisition, or sale of all or part of Mitek’s business, subject to standard confidentiality obligations

4. Retention

Biometric identifiers and biometric information will be permanently destroyed within 30 days of the completion of identity verification.

All other personal information collected during the hiring process will be retained for in accordance with Mitek’s Candidate Privacy Policy. Where your application results in employment, your information will be transferred to your employee record and retained in accordance with Mitek’s employee data retention policy.

5. Your California Privacy Rights

As a California resident, you have the following rights under the CPRA with respect to your personal information:

Right to Know:

You have the right to request that Mitek disclose the categories and specific pieces of personal information it has collected about you, the categories of sources from which it was collected, the purposes for collection, and the categories of third parties to whom it has been disclosed.

Right to Access:

You have the right to request a copy of the specific pieces of personal information Mitek has collected about you.

Right to Delete:

You have the right to request that Mitek delete personal information it has collected from you, subject to certain exceptions, including where retention is required to complete the hiring process, comply with a legal obligation, or protect against fraudulent or illegal activity.

Right to Correct:

You have the right to request that Mitek correct inaccurate personal information it holds about you.

Right to Limit Use of Sensitive Personal Information:

You have the right to direct Mitek to limit its use and disclosure of your sensitive personal information — including your biometric data, government-issued ID data, and immigration status — to the purposes for which it was collected, as described in this Notice.

Right to Opt Out of Sale or Sharing:

You have the right to opt out of the sale or sharing of your personal information. Mitek does not sell or share your personal information.

Right to Non-Retaliation:

Mitek will not retaliate against you for exercising any of your rights under the CPRA.

6. How to Submit a Privacy Rights Request

To exercise any of the rights described above, you may:

We will respond to verified requests within 45 days of receipt. If we require additional time, we will notify you within the initial 45-day period and may extend our response by an additional 45 days where reasonably necessary.

To protect your privacy and security, we will verify your identity before processing your request. We may ask you to provide information sufficient to confirm you are the person about whom we collected personal information.

If we deny your request, in whole or in part, you have the right to appeal our decision by contacting us at privacy@miteksystems.com with the subject line “Privacy Rights Appeal.” We will respond to your appeal within 45 days.

7. Contact Us

For questions about this Notice or Mitek’s privacy practices, please contact us:

8. Changes to This Notice

Mitek reserves the right to update this Notice at any time. Where changes are material, we will provide notice by updating the effective date above and, where appropriate, notifying you directly.

Last Updated: March 2026