Privacy Policy
Version 1.4 · effective 2026-09-19
This explains what we collect, why, how long we keep it and what you can ask us to do about it. It is written against what the software actually does — the table names are real, and a test fails if a new personal-data column appears that this page doesn't disclose. If you are a candidate rather than a customer, the section on automated decision-making is the one to read.
Who we are, and which of us is responsible
This policy covers Kandevo Limited ("we", "us"), the operator of Kandevo AI.
There are two different relationships in this product, and they matter because they decide who you should contact.
For your own account data — your name, email and billing details — we are the controller. We decide how it is used and you can exercise your rights directly with us.
For candidate data — anything about the people you interview — the customer running the interview is the controller and we are the processor. We only handle candidate data on that customer's instructions. If you are a candidate and want your data corrected or erased, contact the organisation that interviewed you; they can instruct us and we will act on it. We will help them, but we cannot lawfully act on a candidate request without them.
Kandevo Limited is a company registered in England and Wales, number 17427689, with its registered office at C/O GP Fund Solutions UK Limited, Mocatta House, Trafalgar Place, Brighton, BN1 4DU.
We are registered with the Information Commissioner's Office under ZC234302.
What we collect, and how long we keep it
Set out in full below rather than summarised, because a policy that describes the product in the abstract is not much use to anyone. Table names are given so you can match this against what the software actually does.
| Category | What it includes | Our role | How long we keep it |
|---|---|---|---|
| Account data | Your name, work email address, a hashed password (bcrypt — never the password itself), your workspace name, and session records. | Controller | For as long as the account exists. Sign-in session records are deleted automatically 30 days after they expire or are revoked — that one runs on its own, during sign-in, so it needs no scheduler to be true. Closing an account is a button: "Delete this workspace" removes every interview, every candidate answer, the audit trail and the account itself, and needs your password. Nothing is deleted on a timer — the decision and the moment are yours. |
| Interview content you create | Job descriptions you paste, generated interview kits, the candidate label you choose, scores with their evidence text, pinned observations, simulation transcripts, and integrity notes. | Processor | Kept until you delete the interview or close the workspace. We do not apply our own expiry to your interview records — you decide how long they live. |
| Candidate data | Whatever label you use to identify a candidate (a name, a reference, or a pseudonym — your choice), plus what they wrote or said during simulations and the evidence you recorded against each score. | Processor | Same as your interview content: retained until you delete it. You are the controller of candidate data; we process it on your instructions. |
| Audit records | Who did what and when — kit generated, score set, recommendation enabled, decision recorded. Actor and workspace ids, an action name, and a small JSON detail. | Processor | Append-only and retained for the life of the workspace. These records exist so a hiring decision can be defended later; deleting them on request would defeat their purpose, so they are excluded from routine erasure (see 'When we can refuse'). |
| Practice interviews you run on yourself | If you hold a candidate account, each practice interview you run is kept against your account: the role you practised, the exercise, when, and the score with its dimension breakdown. The transcript and the observations are shown to you during the round and are not kept. This is your own history, shown back to you so you can see movement over time. No employer sees it, and it is not connected to any assessment an employer invited you to. | Controller | Kept while your account exists, so the history stays useful. Deleting your account deletes it. |
| Screening invitations | When a company sends you an async exercise we store a one-way hash of the link's token, when it opens and expires, which exercises it runs, any note the company wrote for you, and the company's own private reference for the invitation — which may be a name they typed, so it can identify you. The link itself exists only in the message they sent you. | Processor | The invitation is deleted when the company deletes its workspace, and the link stops working at the expiry the company chose — up to 30 days. |
| Payments and interview credits | What was bought, when, the price before VAT, the VAT Stripe collected, the currency, and how many interviews remain. Card details are never stored here or anywhere on our systems — Stripe holds those. | Controller | Purchase records are kept for seven years: HMRC requires accounting records to be kept for six years from the end of the financial year they relate to, and we keep them a year longer to be safe, so they survive the deletion of a workspace. Remaining credits are deleted with the workspace. |
| Email confirmation and two-factor sign-in | To confirm your address we store a one-way hash of the link's token, the address it was sent to, an expiry, and whether it has been used — the link itself exists only in the email. If you turn on two-factor sign-in we also store one-way hashes of your ten recovery codes, and which of them have been spent. We never hold a usable token or a usable recovery code. | Controller | Confirmation links expire after 24 hours, work once, and the record is deleted 7 days after expiry. Sign-in codes sent by email expire in minutes, work once, and the record is deleted a day after expiry. Recovery-code hashes last as long as two-factor is on; turning it off deletes them, and a spent one is kept marked as spent so it cannot be re-issued. |
| Password reset tokens | When you ask to reset your password we store a one-way hash of the link's token, an expiry, and whether it has been used. The link itself exists only in the email we send you. | Controller | The link expires after one hour and works once. The record is deleted 7 days after expiry. |
| Product feedback you give us | If you answer the in-app prompt: a thumbs up or down, your optional written comment, and the plan and role family it related to. Linked to your user account so we can follow up if you asked us to. | Controller | Kept for 24 months so we can see whether the product improved. Deleted with your account. Your written comment is never copied into our anonymised product analytics. |
| Usage and cost records | Counts of interviews and generations, token counts and cost per model call, plan changes, and anonymised quality signals tagged by role family only. | Controller | Retained for 7 years where needed for accounting, otherwise 24 months. Feedback signals carry no candidate identity and no demographic field, by design. |
| Public-surface records | A salted one-way hash of your IP address used only to count requests against a rate limit; a count of demo, challenge and practice plays with a date; and daily-challenge leaderboard entries showing 2–3 initials you chose and a score. | Controller | Rate-limit counters are deleted automatically after 30 days — they are hashed and hold no address, but a counter nobody needs is a row nobody should keep. Play counts hold no identifier at all. Leaderboard entries are kept for the life of the leaderboard and contain no email, IP or account link. |
| Prospect data (our own sales records) | If you are a business contact we have written to: your company name, your name, your work email, a public job advert you published, and a summary of your public website. | Controller | Deleted on request, and reviewed at 12 months from the last contact — that review is a person going through the list, not an automatic job, and we would rather say so than imply a timer that does not exist. Reply asking us to stop and we will delete your record and not write again. |
What we do not collect
Some of these are more useful than the list above, because they close off the assumptions people reasonably make about hiring software.
- No special category data is requested. We never ask for, and the product has no field for, race, ethnicity, religion, health, disability, sexual orientation, trade-union membership, or biometric data. A candidate can still volunteer something of that kind in a free-text answer — a health condition, a caring responsibility — and if they do, it is stored as part of their answer. The DPA says what happens to it.
- No demographic data in our quality analytics. The table that feeds product improvement is grouped by role family — 'sales', 'operations' — and every row is passed through a filter that strips candidate identifiers and demographic field names before it is written. A database check additionally requires the role family to be present, so a row cannot be saved without one.
- No CV or resume parsing, and no automated sifting of applications.
- No candidate-side tracking. We do not fingerprint devices, run session recording, or track candidates across sites.
- No behavioural advertising, and no sale or sharing of personal data with advertisers or data brokers. Ever, on any plan.
- No training on your data. We do not train models on your interviews, and our AI provider does not train on API content.
Why we are allowed to process it (lawful basis)
Under UK GDPR we need a lawful basis for each purpose. Ours are:
- Contract — running your account, providing the interview tooling you signed up for, and taking payment.
- Legitimate interests — keeping the service secure, preventing abuse of the free surfaces, maintaining the audit trail, and improving the product using anonymised signals. We have weighed these against your interests; the audit trail in particular exists to protect candidates as much as customers.
- Legitimate interests — business-to-business outreach to a work email address about a product relevant to your job. You can stop it in one reply and we will delete your record.
- Legal obligation — retaining accounting records.
- For candidate data we act on our customer's instructions, and it is that customer's responsibility to have a lawful basis for the interview and to tell candidates what is happening. The product does not leave the candidate to take that on trust: every candidate sees, on their own device before they begin, what is being recorded and that a human makes the decision.
Automated decision-making
This is the part of the policy a candidate should read first.
No hiring decision in this product is made by a machine. The software generates interview material, records evidence, and can draft a summary. It never advances, rejects or ranks a candidate into an outcome on its own. In the code, the field that records a hiring decision has exactly one writer, and it is only reachable from a person clicking a button.
AI-assisted recommendations are available on higher plans, are off by default, are clearly labelled as advisory when on, and enabling them writes a record of who did so. A recommendation is an input for the interviewer, not a decision.
Because of this, Article 22 UK GDPR — the right not to be subject to a solely automated decision with legal or similarly significant effects — is not engaged. If that ever changes, this section will change first and we will tell affected customers before it does.
Who else sees your data (subprocessors)
We use 5 third parties. The status column says exactly where each one stands. We will add a provider to this table before it starts processing your data, not after.
Speaking your answer instead of typing it is the one thing on this site that sends data somewhere we have not listed, and it is worth explaining rather than leaving out. Practice Mode has a microphone button that transcribes speech into the answer box. The transcribing is done by your own web browser, not by us — which means the audio may go to whoever makes your browser, typically Google for Chrome or Apple for Safari, under your relationship with them and not ours. We never receive the audio. It is not recorded, not sent to our servers, and not stored anywhere by us; only the text you end up with is submitted, exactly as if you had typed it. That is why the companies involved are not in the table above — we do not engage them and they do not process anything on our behalf — and it is also why the button says so in plain words before you press it. Nothing uses the microphone unless you press it and your browser asks your permission.
| Provider | What they do | What they see | Where | Status |
|---|---|---|---|---|
| Anthropic PBC | Generating interview kits, running simulations, producing observations against evidence and drafting reports. Every model call goes through our server; no request is made from your browser. | The job description and simulation content sent with each request. Candidate labels are not sent to the model. Anthropic does not train on API content, and under its published policy may retain requests for up to 30 days for trust-and-safety purposes before deleting them. | United States, under Standard Contractual Clauses / a UK addendum. | in use |
| Railway Corp. | Application hosting and the managed Postgres database. | All data stored by the application, at rest and in transit through the host. | ams (Amsterdam, Netherlands). Data is stored in Europe. | in use |
| Resend (Plus Five Five, Inc.), using Amazon SES | Sending transactional email: password resets, address-confirmation links, sign-in codes for email two-factor, and alerts to our own operator when something fails. This product sends no marketing email and keeps no mailing list. | The recipient's email address and the message body. Messages to you contain a single-use link or code and nothing else: no interview content and no report is ever sent to a customer by email. Operator alerts carry an error's type, message and first stack frames. They are written not to include personal data, but an error message can quote a fragment of whatever the failing call was handling, and we would rather say that than claim it cannot happen. | Processed in Ireland (eu-west-1). Resend is a US company, so that transfer relies on Standard Contractual Clauses with the UK International Data Transfer Addendum. | in use |
| Stripe Payments Europe, Ltd. | Taking subscription payments, and calculating VAT on them. | Your billing name, email, billing address and VAT number if you give one, plus your payment details. Card details are entered on Stripe's own checkout page and never reach our servers — we could not show you your own card number if you asked. No candidate data, no interview content and no report is ever shared with Stripe. | Ireland (Stripe Payments Europe, Ltd.) and the United States (Stripe, Inc.). The onward transfer to the US is covered by the safeguards in Stripe's own data processing agreement, which we accept as part of using them; ask us and we will point you at the current version. | integrated — no live payments taken yet |
| Functional Software, Inc. (Sentry) | Error reporting. When something in the application fails, a report is sent so that we find out before a customer has to tell us. | The error's type and message, where in the application it happened, and the first few lines of the stack trace. Our alerts are written not to include personal data, but an error message can carry a fragment of whatever the failing call was handling — a database error might quote an email address — and we would rather say that than claim it cannot happen. Candidate answers, interview content and reports are never sent deliberately. | Frankfurt, Germany (Sentry's EU region) for the reports themselves. Sentry is a US company and keeps our own account, organisation settings and project keys in the United States whichever region is chosen; that transfer relies on Standard Contractual Clauses with the UK International Data Transfer Addendum. | in use |
Cookies
We set two cookies, and both are the kind you cannot consent your way out of because the thing you are doing cannot work without them. Neither is used for advertising or tracking, and there is no third-party cookie of any kind.
`kandevo_session` — set when you sign in, so the next page knows it is still you. Deleted when you sign out.
`kandevo_join_…` — set on a candidate's own device when they open an interview link, so that link works on that device and not on a second one. It holds a random secret (we store only its hash), no name and no answer. For a live interview it expires within hours; for a screening link it lasts as long as the link does, up to 30 days.
We do not use analytics cookies, advertising cookies, or third-party trackers. Our page-view analytics, when enabled, is a cookieless self-hosted counter that stores no identifier and cannot follow you between sites.
That is why you are not being shown a cookie banner. Under PECR, consent is required for non-essential cookies; we do not set any. If that ever changes, a banner will appear before it does.
Your rights
If we are the controller of your data — your account, billing, or a prospect record — you can exercise all of these with us directly:
- Access — a copy of your personal data.
- Rectification — correct anything inaccurate.
- Erasure — delete your data, subject to the exceptions below.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in a machine-readable form. Your interview records and audit trail can be exported.
- Objection — object to processing based on legitimate interests, including outreach.
- Withdraw consent — where we relied on consent, though mostly we do not.
- Complain — to the Information Commissioner's Office at ico.org.uk. We would rather you came to us first, but that is your right and not conditional on doing so.
When we can refuse an erasure request
Two cases, stated plainly because a policy that implies erasure is unconditional is misleading.
Audit records. The audit trail is append-only by design — enforced by database rules, not just by our code — because its purpose is to let a hiring decision be defended or challenged months later. Erasing it on request would remove the record that protects the candidate as much as the customer. We will restrict it, and we will tell you exactly what it holds, but we will not delete it while the workspace exists.
Accounting records. We keep invoice and payment records for seven years: HMRC requires six from the end of the financial year, and we keep them a year longer.
In both cases we will explain which exemption applies and what we can do instead.
How to make a request
Email privacy@kandevo.ai. We will respond within one month, as UK GDPR requires, and tell you sooner if the request is complex enough to need an extension.
If you are a candidate rather than a customer: contact the organisation that interviewed you. They control your interview data and can instruct us to act. If you cannot reach them, tell us and we will do what we can to help you find the right contact — but we cannot delete a customer's records on a third party's request without their instruction.
Security
The measures that are actually in place, rather than a list of adjectives:
- Passwords are hashed with bcrypt. We cannot see your password and cannot recover it — only reset it.
- Sessions are server-side and revocable. Signing out genuinely ends the session rather than only clearing your browser's copy, and a password reset revokes every existing session.
- Our AI provider's API key is held server-side only and is never exposed to a browser. Every model call is proxied through our own server with authentication and rate limits.
- Workspace data is isolated per customer, and every query that reads interview data is scoped to the workspace that owns it.
- The audit trail cannot be modified or deleted by the application. Database rules discard any update or delete against it, so a stray query cannot rewrite history — note that such a statement reports success and simply has no effect, rather than raising an error.
- Data is encrypted in transit (TLS) and at rest by our hosting provider.
- We have not yet completed an independent security audit or a SOC 2 examination. When we do, this section will say so and name the auditor.
International transfers
Our AI provider processes requests in the United States. That transfer relies on Standard Contractual Clauses with the UK International Data Transfer Addendum.
Database hosting: ams (Amsterdam, Netherlands). Data is stored in Europe.
We do not currently offer a choice of hosting region. An earlier draft of this policy said you could pick an EU or UK region; that described a capability we do not have, so it has been removed. If you have a hard data-residency requirement, tell us before you buy — we would rather lose the sale than promise residency we cannot deliver today.
Children
This is a tool for professional hiring and is not directed at children. We do not knowingly collect data about anyone under 16. If you believe we have, tell us and we will delete it.
Changes to this policy
This is version 1.4, effective 2026-09-19.
If we make a change that materially affects how we handle your data, we will email account holders before it takes effect rather than silently updating this page.