Data Processing Agreement
Version 1.4 · effective 2026-09-19
Required by UK GDPR Article 28. This forms part of our Terms and applies to every workspace on every plan, including Free, from the moment you first process candidate data. You do not need to sign anything.
What this is, and when it applies
This Data Processing Agreement forms part of the Terms of Service between you (the "Controller") and Kandevo Limited ("Processor", "we", "us"). It applies automatically to every workspace, on every plan including Free, from the moment you first process candidate data using the service. You do not need to sign anything separately.
It is required by Article 28(3) of the UK GDPR, which says a processor may only process a controller's personal data under a binding written contract containing the terms set out below.
Where this document and the Terms of Service conflict on the processing of candidate data, this document governs.
1. Subject matter, duration, nature and purpose
Subject matter. Providing structured interview software: generating interview kits from a job description, running work-sample simulations, recording interviewer observations and evidence, producing reports, and — on plans where it is available — scoring an asynchronous screening exercise the candidate completes.
Duration. For as long as your workspace exists. Section 7 says what you can export and delete, and what happens on termination.
Nature. Storage, organisation, retrieval, analysis by a large language model, and generation of text derived from the above.
Purpose. Only to provide the service to you, and to keep it secure and working. We do not process candidate data to develop the product, to train any model, or for any purpose of our own. Section 9 states the one narrow exception and what it excludes.
2. Types of personal data and categories of data subject
Categories of data subject. Candidates you interview or screen. Separately, your own users — that data is covered by the Privacy Policy, where we are the controller, not this agreement.
Types of personal data, in the tables named:
- `sessions` — the label or name you give a candidate, and the interview's timing and state.
- `scores` and `observations` — your interviewers' written evidence about what a candidate said and did, and the ratings attached to it.
- `sim_runs` — what a candidate wrote or chose during a work-sample simulation.
- `screening_results` — a candidate's own written answer to an asynchronous exercise, the name they optionally gave, and the observations generated from it.
- `audit_events` — a record of who did what and when, including decisions about a candidate.
- Special category data is not requested and has no field. A candidate may nevertheless disclose it unprompted in free text — a health condition, a caring responsibility. Section 9 says what we do about that. You remain responsible for having an Article 9 condition if you rely on such information.
3. We process only on your documented instructions
We process candidate data only on your documented instructions. Your instructions are: these Terms, this agreement, your configuration of the service, and the actions your users take in it. We will not process candidate data for any other purpose.
If we believe an instruction infringes UK GDPR or other data protection law, we will tell you and may pause that processing until it is resolved.
This includes transfers. We will not transfer candidate data to a third country except as described in section 6, and will tell you before adding any new destination.
If we are required by law to process beyond your instructions, we will tell you first unless that law forbids it.
4. Confidentiality
Everyone we authorise to process candidate data is bound by a duty of confidentiality that survives the end of their engagement. Today that is a very short list: Kandevo Limited has no employee or contractor with access to production candidate data.
We will tell you in this document before that changes.
5. Security (Article 32)
The measures we actually operate, stated so you can hold us to them rather than as adjectives:
- Encryption in transit for all traffic, with HSTS. Encryption at rest by the hosting provider. Database connections outside the private network require TLS.
- Passwords stored as salted hashes, never recoverable. Sessions are opaque server-side tokens, revocable immediately.
- Workspace isolation enforced in every database query, not in the interface — a query for another workspace's data returns nothing rather than being hidden.
- The audit trail is append-only, enforced by database rules: UPDATE and DELETE against it do nothing, including by us.
- The candidate's name and the label you give an interview are never sent to the AI provider. What a candidate types into an answer is sent as written, so a name they include themselves travels with it.
- Point-in-time recovery on the database, with a continuous backup archive held by our hosting provider. Deleted data is removed from the live database immediately and ages out of that archive as the recovery window rolls forward; we do not restore a backup in order to recover data a customer has deleted.
- We have not completed an independent security audit or penetration test. We say so here rather than let you assume otherwise.
6. Sub-processors
You give general authorisation for us to engage the sub-processors listed in the Privacy Policy, which names each one, what it does, what it sees and where it is.
We will publish any addition to that list at least 30 days before it starts processing your data. If you object within those 30 days, tell us; if we cannot resolve it, you may terminate and we will refund any unused prepaid period.
Every sub-processor is bound by terms no less protective than these.
Candidate data is stored in ams (Amsterdam, Netherlands), inside the UK/EEA. Our AI provider processes requests in the United States under Standard Contractual Clauses with the UK International Data Transfer Addendum; the candidate's name and your label for the interview are not included in those requests, though anything a candidate types into an answer is.
7. Candidate rights, deletion and return
You are the controller, so a candidate's request comes to you. We will assist you in responding, and will not answer a candidate directly about your data beyond telling them to contact you.
The service gives you the means to do this yourself: you can export a workspace's data at any time, and delete either a single interview or the entire workspace. Screening submissions are removed with the workspace; ask us and we will delete an individual one for you.
On termination, nothing is deleted on a timer. You can export the whole record from inside the product at any time, and delete the workspace yourself whenever you choose — that removes every interview, every candidate answer and the audit trail, and needs your password. If you would rather we did it, instruct us in writing and we will, then confirm when it is done.
One exception, stated plainly: the append-only audit trail cannot be edited or deleted while the workspace exists, because a trail that can be rewritten is not a trail. It records that a decision happened and who made it, and it does hold short excerpts of interview content — the evidence an interviewer typed against a score, the text of an observation they pinned, a decision note. Those excerpts are capped at a few hundred characters each and exist so a score can be shown to have had evidence behind it. Treat the trail as interview material, because that is what it is. It is deleted with the workspace.
8. Assistance, breach notification and audit
Breaches. We will tell you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your candidate data, with what we know: what happened, which data and roughly how many people, the likely consequences, and what we are doing. You decide whether to notify the ICO or the individuals — it is your call as controller, and the 72-hour clock in Article 33 is yours.
Assistance. We will help you, taking account of the nature of processing and what we know, with your obligations under Articles 32 to 36 — security, breach notification, and data protection impact assessments.
Audit. We will give you the information you reasonably need to show compliance with this agreement, and will contribute to an audit or inspection you or an auditor you appoint conducts, on reasonable notice and no more than once a year unless there has been a breach or the ICO requires it.
9. What we do NOT do with candidate data
Stated as commitments, because they are the ones most worth holding us to:
- No training. Candidate data is never used to train or fine-tune any model, ours or anyone else's. Our AI provider does not train on API content.
- No automated decision. Nothing in the product makes or recommends a hiring decision without a person. Observations and counts are evidence for a human to read; the decision field can only be written by a signed-in user, and the record shows who wrote it.
- No profiling across candidates, no ranking of one candidate against another except where you explicitly compare them, and no scoring of a candidate against anyone but the role.
- No enrichment. We do not look candidates up online, buy data about them, or add anything to their record that you or they did not provide.
- No demographic analytics. The anonymised quality data that helps us improve the product is grouped by role family only, and every row is filtered to strip identifiers and demographic fields before it is written.
- No selling, ever. Candidate data is not sold, licensed or shared for anyone else's marketing.
- No special-category screening. We do not solicit, detect, index or analyse special category data. If a candidate volunteers something of that kind in a free-text answer, it is held only as part of that answer, and in any evidence excerpt an interviewer chooses to quote from it (section 7): it is never copied into our quality analytics, never used to categorise them, and it is deleted with the interview, or with the workspace for excerpts in the audit trail. This is the section §2 points to.
10. Liability, and this document's status
Liability under this agreement is subject to the limits in the Terms of Service, except where those limits cannot lawfully apply.
This agreement is written to describe what the software actually does. Every commitment in it was checked against the running system, and our tests fail if the product starts handling personal data in a way this document does not disclose. If your legal team needs changes, tell us — we would rather agree wording that is true than sign wording that sounds better.
This is version 1.4, effective 2026-09-19 — the same version as the Terms and Privacy Policy it forms part of. A document that is incorporated by another but versioned separately is a document nobody can prove the state of on a given date.
We will give account holders at least 30 days' notice by email of any change that materially reduces your rights or increases your obligations.
Questions, objections to a sub-processor, or audit requests: privacy@kandevo.ai.