Kandevo AI.

Privacy Policy

Version 0.1-draft · effective 2026-08-08

Template — pending legal review. This document was drafted from what the software actually does, and every statement in it was checked against the code. It has not been reviewed by a solicitor, and it is not legal advice. Do not rely on it as a final policy, and do not put it in front of an enterprise buyer or a DPO until it has been reviewed.

This explains what we collect, why, how long we keep it and what you can ask us to do about it. It is written against what the software actually does — the table names are real, and a test fails if a new personal-data column appears that this page doesn't disclose. If you are a candidate rather than a customer, the section on automated decision-making is the one to read.

Who we are, and which of us is responsible

This policy covers Kandevo AI (trading name, entity to be confirmed) ("we", "us"), the operator of Kandevo AI.

There are two different relationships in this product, and they matter because they decide who you should contact.

For your own account data — your name, email and billing details — we are the controller. We decide how it is used and you can exercise your rights directly with us.

For candidate data — anything about the people you interview — the customer running the interview is the controller and we are the processor. We only handle candidate data on that customer's instructions. If you are a candidate and want your data corrected or erased, contact the organisation that interviewed you; they can instruct us and we will act on it. We will help them, but we cannot lawfully act on a candidate request without them.

Our registered address will be published here once the operating entity is incorporated.

ICO registration is pending and will be published here once issued.

What we collect, and how long we keep it

Set out in full below rather than summarised, because a policy that describes the product in the abstract is not much use to anyone. Table names are given so you can match this against what the software actually does.

CategoryWhat it includesOur roleHow long we keep it
Account dataYour name, work email address, a hashed password (bcrypt — never the password itself), your workspace name, and session records.ControllerFor as long as the account exists, then deleted within 30 days of account closure. Session records are pruned 30 days after they expire or are revoked.
Interview content you createJob descriptions you paste, generated interview kits, the candidate label you choose, scores with their evidence text, pinned observations, simulation transcripts, and integrity notes.ProcessorKept until you delete the interview or close the workspace. We do not apply our own expiry to your interview records — you decide how long they live.
Candidate dataWhatever label you use to identify a candidate (a name, a reference, or a pseudonym — your choice), plus what they wrote or said during simulations and the evidence you recorded against each score.ProcessorSame as your interview content: retained until you delete it. You are the controller of candidate data; we process it on your instructions.
Audit recordsWho did what and when — kit generated, score set, recommendation enabled, decision recorded. Actor and workspace ids, an action name, and a small JSON detail.ProcessorAppend-only and retained for the life of the workspace. These records exist so a hiring decision can be defended later; deleting them on request would defeat their purpose, so they are excluded from routine erasure (see 'When we can refuse').
Password reset tokensWhen you ask to reset your password we store a one-way hash of the link's token, an expiry, and whether it has been used. The link itself exists only in the email we send you.ControllerThe link expires after one hour and works once. The record is deleted 7 days after expiry.
Product feedback you give usIf you answer the in-app prompt: a thumbs up or down, your optional written comment, and the plan and role family it related to. Linked to your user account so we can follow up if you asked us to.ControllerKept for 24 months so we can see whether the product improved. Deleted with your account. Your written comment is never copied into our anonymised product analytics.
Usage and cost recordsCounts of interviews and generations, token counts and cost per model call, plan changes, and anonymised quality signals tagged by role family only.ControllerRetained for 7 years where needed for accounting, otherwise 24 months. Feedback signals carry no candidate identity and no demographic field, by design.
Public-surface recordsA salted one-way hash of your IP address used only to count requests against a rate limit; a count of demo, challenge and practice plays with a date; and daily-challenge leaderboard entries showing 2–3 initials you chose and a score.ControllerRate-limit counters are kept 30 days. Play counts hold no identifier at all. Leaderboard entries are kept for the life of the leaderboard and contain no email, IP or account link.
Prospect data (our own sales records)If you are a business contact we have written to: your company name, your name, your work email, a public job advert you published, and a summary of your public website.ControllerDeleted on request, or within 12 months of the last contact. Reply asking us to stop and we will delete your record and not write again.

What we do not collect

Some of these are more useful than the list above, because they close off the assumptions people reasonably make about hiring software.

Why we are allowed to process it (lawful basis)

Under UK GDPR we need a lawful basis for each purpose. Ours are:

Automated decision-making

This is the part of the policy a candidate should read first.

No hiring decision in this product is made by a machine. The software generates interview material, records evidence, and can draft a summary. It never advances, rejects or ranks a candidate into an outcome on its own. In the code, the field that records a hiring decision has exactly one writer, and it is only reachable from a person clicking a button.

AI-assisted recommendations are available on higher plans, are off by default, are clearly labelled as advisory when on, and enabling them writes a record of who did so. A recommendation is an input for the interviewer, not a decision.

Because of this, Article 22 UK GDPR — the right not to be subject to a solely automated decision with legal or similarly significant effects — is not engaged. If that ever changes, this section will change first and we will tell affected customers before it does.

Who else sees your data (subprocessors)

We use a small number of third parties. Two of them are listed as planned rather than in use, because the honest current state is that they are not yet integrated — we would rather tell you what is coming than quietly add it later.

ProviderWhat they doWhat they seeWhereStatus
Anthropic PBCGenerating interview kits, running simulations, scoring against evidence and drafting reports. Every model call goes through our server; no request is made from your browser.The job description and simulation content sent with each request. Candidate labels are not sent to the model. Anthropic does not train on API content.United States, under Standard Contractual Clauses / a UK addendum.in use
Railway Corp.Application hosting and the managed Postgres database.All data stored by the application, at rest and in transit through the host.ams (Amsterdam, Netherlands). Data is stored in Europe.in use
Resend (Plus Five Five, Inc.), using Amazon SESSending transactional email. Today that is password-reset messages only — this product sends no marketing email and keeps no mailing list.The recipient's email address and the message body. A password-reset message contains a single-use link and nothing else: no candidate data, no interview content and no report is ever sent by email.Processed in Ireland (eu-west-1). Resend is a US company, so that transfer relies on Standard Contractual Clauses with the UK International Data Transfer Addendum.in use
Stripe Payments Europe, Ltd.Taking subscription payments, and calculating VAT on them.Your billing name, email, billing address and VAT number if you give one, plus your payment details. Card details are entered on Stripe's own checkout page and never reach our servers — we could not show you your own card number if you asked. No candidate data, no interview content and no report is ever shared with Stripe.Ireland and the United States.integrated — no live payments taken yet

Cookies

We set one cookie, and it is the kind you cannot consent your way out of because the site cannot work without it.

`kandevo_session` — an httpOnly, SameSite=Lax cookie holding a random opaque token that identifies your signed-in session. It carries no personal data itself; the session record lives on our server. It expires after seven days, or immediately when you sign out.

We do not use analytics cookies, advertising cookies, or third-party trackers. Our page-view analytics, when enabled, is a cookieless self-hosted counter that stores no identifier and cannot follow you between sites.

That is why you are not being shown a cookie banner. Under PECR, consent is required for non-essential cookies; we do not set any. If that ever changes, a banner will appear before it does.

Your rights

If we are the controller of your data — your account, billing, or a prospect record — you can exercise all of these with us directly:

When we can refuse an erasure request

Two cases, stated plainly because a policy that implies erasure is unconditional is misleading.

Audit records. The audit trail is append-only by design — enforced by database rules, not just by our code — because its purpose is to let a hiring decision be defended or challenged months later. Erasing it on request would remove the record that protects the candidate as much as the customer. We will restrict it, and we will tell you exactly what it holds, but we will not delete it while the workspace exists.

Accounting records. We must keep invoice and payment records for seven years.

In both cases we will explain which exemption applies and what we can do instead.

How to make a request

Email privacy@kandevo.ai. We will respond within one month, as UK GDPR requires, and tell you sooner if the request is complex enough to need an extension.

If you are a candidate rather than a customer: contact the organisation that interviewed you. They control your interview data and can instruct us to act. If you cannot reach them, tell us and we will do what we can to help you find the right contact — but we cannot delete a customer's records on a third party's request without their instruction.

Security

The measures that are actually in place, rather than a list of adjectives:

International transfers

Our AI provider processes requests in the United States. That transfer relies on Standard Contractual Clauses with the UK International Data Transfer Addendum.

Database hosting: ams (Amsterdam, Netherlands). Data is stored in Europe.

We do not currently offer a choice of hosting region. An earlier draft of this policy said you could pick an EU or UK region; that described a capability we do not have, so it has been removed. If you have a hard data-residency requirement, tell us before you buy — we would rather lose the sale than promise residency we cannot deliver today.

Children

This is a tool for professional hiring and is not directed at children. We do not knowingly collect data about anyone under 16. If you believe we have, tell us and we will delete it.

Changes to this policy

This is version 0.1-draft, effective 2026-08-08.

If we make a change that materially affects how we handle your data, we will email account holders before it takes effect rather than silently updating this page.

Questions about this document: privacy@kandevo.ai. See also our Trust & Compliance page, which explains the commitments this policy formalises — and is backed by tests that fail if a commitment stops being true.