Privacy Policy
Version 0.1-draft · effective 2026-08-08
This explains what we collect, why, how long we keep it and what you can ask us to do about it. It is written against what the software actually does — the table names are real, and a test fails if a new personal-data column appears that this page doesn't disclose. If you are a candidate rather than a customer, the section on automated decision-making is the one to read.
Who we are, and which of us is responsible
This policy covers Kandevo AI (trading name, entity to be confirmed) ("we", "us"), the operator of Kandevo AI.
There are two different relationships in this product, and they matter because they decide who you should contact.
For your own account data — your name, email and billing details — we are the controller. We decide how it is used and you can exercise your rights directly with us.
For candidate data — anything about the people you interview — the customer running the interview is the controller and we are the processor. We only handle candidate data on that customer's instructions. If you are a candidate and want your data corrected or erased, contact the organisation that interviewed you; they can instruct us and we will act on it. We will help them, but we cannot lawfully act on a candidate request without them.
Our registered address will be published here once the operating entity is incorporated.
ICO registration is pending and will be published here once issued.
What we collect, and how long we keep it
Set out in full below rather than summarised, because a policy that describes the product in the abstract is not much use to anyone. Table names are given so you can match this against what the software actually does.
| Category | What it includes | Our role | How long we keep it |
|---|---|---|---|
| Account data | Your name, work email address, a hashed password (bcrypt — never the password itself), your workspace name, and session records. | Controller | For as long as the account exists, then deleted within 30 days of account closure. Session records are pruned 30 days after they expire or are revoked. |
| Interview content you create | Job descriptions you paste, generated interview kits, the candidate label you choose, scores with their evidence text, pinned observations, simulation transcripts, and integrity notes. | Processor | Kept until you delete the interview or close the workspace. We do not apply our own expiry to your interview records — you decide how long they live. |
| Candidate data | Whatever label you use to identify a candidate (a name, a reference, or a pseudonym — your choice), plus what they wrote or said during simulations and the evidence you recorded against each score. | Processor | Same as your interview content: retained until you delete it. You are the controller of candidate data; we process it on your instructions. |
| Audit records | Who did what and when — kit generated, score set, recommendation enabled, decision recorded. Actor and workspace ids, an action name, and a small JSON detail. | Processor | Append-only and retained for the life of the workspace. These records exist so a hiring decision can be defended later; deleting them on request would defeat their purpose, so they are excluded from routine erasure (see 'When we can refuse'). |
| Password reset tokens | When you ask to reset your password we store a one-way hash of the link's token, an expiry, and whether it has been used. The link itself exists only in the email we send you. | Controller | The link expires after one hour and works once. The record is deleted 7 days after expiry. |
| Product feedback you give us | If you answer the in-app prompt: a thumbs up or down, your optional written comment, and the plan and role family it related to. Linked to your user account so we can follow up if you asked us to. | Controller | Kept for 24 months so we can see whether the product improved. Deleted with your account. Your written comment is never copied into our anonymised product analytics. |
| Usage and cost records | Counts of interviews and generations, token counts and cost per model call, plan changes, and anonymised quality signals tagged by role family only. | Controller | Retained for 7 years where needed for accounting, otherwise 24 months. Feedback signals carry no candidate identity and no demographic field, by design. |
| Public-surface records | A salted one-way hash of your IP address used only to count requests against a rate limit; a count of demo, challenge and practice plays with a date; and daily-challenge leaderboard entries showing 2–3 initials you chose and a score. | Controller | Rate-limit counters are kept 30 days. Play counts hold no identifier at all. Leaderboard entries are kept for the life of the leaderboard and contain no email, IP or account link. |
| Prospect data (our own sales records) | If you are a business contact we have written to: your company name, your name, your work email, a public job advert you published, and a summary of your public website. | Controller | Deleted on request, or within 12 months of the last contact. Reply asking us to stop and we will delete your record and not write again. |
What we do not collect
Some of these are more useful than the list above, because they close off the assumptions people reasonably make about hiring software.
- No special category data. We never ask for, and the product has no field for, race, ethnicity, religion, health, disability, sexual orientation, trade-union membership, or biometric data.
- No demographic data in our quality analytics. The table that feeds product improvement is grouped by role family — 'sales', 'operations' — and a database constraint prevents it holding anything else.
- No CV or resume parsing, and no automated sifting of applications.
- No candidate-side tracking. We do not fingerprint devices, run session recording, or track candidates across sites.
- No behavioural advertising, and no sale or sharing of personal data with advertisers or data brokers. Ever, on any plan.
- No training on your data. We do not train models on your interviews, and our AI provider does not train on API content.
Why we are allowed to process it (lawful basis)
Under UK GDPR we need a lawful basis for each purpose. Ours are:
- Contract — running your account, providing the interview tooling you signed up for, and taking payment.
- Legitimate interests — keeping the service secure, preventing abuse of the free surfaces, maintaining the audit trail, and improving the product using anonymised signals. We have weighed these against your interests; the audit trail in particular exists to protect candidates as much as customers.
- Legitimate interests — business-to-business outreach to a work email address about a product relevant to your job. You can stop it in one reply and we will delete your record.
- Legal obligation — retaining accounting records.
- For candidate data we act on our customer's instructions, and it is that customer's responsibility to have a lawful basis for the interview and to tell candidates what is happening. Our product is built to make that easy rather than optional: the Trust page commitment that candidates are always informed is not a slogan, and the product requires the interviewer to confirm it before a session starts.
Automated decision-making
This is the part of the policy a candidate should read first.
No hiring decision in this product is made by a machine. The software generates interview material, records evidence, and can draft a summary. It never advances, rejects or ranks a candidate into an outcome on its own. In the code, the field that records a hiring decision has exactly one writer, and it is only reachable from a person clicking a button.
AI-assisted recommendations are available on higher plans, are off by default, are clearly labelled as advisory when on, and enabling them writes a record of who did so. A recommendation is an input for the interviewer, not a decision.
Because of this, Article 22 UK GDPR — the right not to be subject to a solely automated decision with legal or similarly significant effects — is not engaged. If that ever changes, this section will change first and we will tell affected customers before it does.
Who else sees your data (subprocessors)
We use a small number of third parties. Two of them are listed as planned rather than in use, because the honest current state is that they are not yet integrated — we would rather tell you what is coming than quietly add it later.
| Provider | What they do | What they see | Where | Status |
|---|---|---|---|---|
| Anthropic PBC | Generating interview kits, running simulations, scoring against evidence and drafting reports. Every model call goes through our server; no request is made from your browser. | The job description and simulation content sent with each request. Candidate labels are not sent to the model. Anthropic does not train on API content. | United States, under Standard Contractual Clauses / a UK addendum. | in use |
| Railway Corp. | Application hosting and the managed Postgres database. | All data stored by the application, at rest and in transit through the host. | ams (Amsterdam, Netherlands). Data is stored in Europe. | in use |
| Resend (Plus Five Five, Inc.), using Amazon SES | Sending transactional email. Today that is password-reset messages only — this product sends no marketing email and keeps no mailing list. | The recipient's email address and the message body. A password-reset message contains a single-use link and nothing else: no candidate data, no interview content and no report is ever sent by email. | Processed in Ireland (eu-west-1). Resend is a US company, so that transfer relies on Standard Contractual Clauses with the UK International Data Transfer Addendum. | in use |
| Stripe Payments Europe, Ltd. | Taking subscription payments, and calculating VAT on them. | Your billing name, email, billing address and VAT number if you give one, plus your payment details. Card details are entered on Stripe's own checkout page and never reach our servers — we could not show you your own card number if you asked. No candidate data, no interview content and no report is ever shared with Stripe. | Ireland and the United States. | integrated — no live payments taken yet |
Cookies
We set one cookie, and it is the kind you cannot consent your way out of because the site cannot work without it.
`kandevo_session` — an httpOnly, SameSite=Lax cookie holding a random opaque token that identifies your signed-in session. It carries no personal data itself; the session record lives on our server. It expires after seven days, or immediately when you sign out.
We do not use analytics cookies, advertising cookies, or third-party trackers. Our page-view analytics, when enabled, is a cookieless self-hosted counter that stores no identifier and cannot follow you between sites.
That is why you are not being shown a cookie banner. Under PECR, consent is required for non-essential cookies; we do not set any. If that ever changes, a banner will appear before it does.
Your rights
If we are the controller of your data — your account, billing, or a prospect record — you can exercise all of these with us directly:
- Access — a copy of your personal data.
- Rectification — correct anything inaccurate.
- Erasure — delete your data, subject to the exceptions below.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in a machine-readable form. Your interview records and audit trail can be exported.
- Objection — object to processing based on legitimate interests, including outreach.
- Withdraw consent — where we relied on consent, though mostly we do not.
- Complain — to the Information Commissioner's Office at ico.org.uk. We would rather you came to us first, but that is your right and not conditional on doing so.
When we can refuse an erasure request
Two cases, stated plainly because a policy that implies erasure is unconditional is misleading.
Audit records. The audit trail is append-only by design — enforced by database rules, not just by our code — because its purpose is to let a hiring decision be defended or challenged months later. Erasing it on request would remove the record that protects the candidate as much as the customer. We will restrict it, and we will tell you exactly what it holds, but we will not delete it while the workspace exists.
Accounting records. We must keep invoice and payment records for seven years.
In both cases we will explain which exemption applies and what we can do instead.
How to make a request
Email privacy@kandevo.ai. We will respond within one month, as UK GDPR requires, and tell you sooner if the request is complex enough to need an extension.
If you are a candidate rather than a customer: contact the organisation that interviewed you. They control your interview data and can instruct us to act. If you cannot reach them, tell us and we will do what we can to help you find the right contact — but we cannot delete a customer's records on a third party's request without their instruction.
Security
The measures that are actually in place, rather than a list of adjectives:
- Passwords are hashed with bcrypt. We cannot see your password and cannot recover it — only reset it.
- Sessions are server-side and revocable. Signing out genuinely ends the session rather than only clearing your browser's copy, and a password reset revokes every existing session.
- Our AI provider's API key is held server-side only and is never exposed to a browser. Every model call is proxied through our own server with authentication and rate limits.
- Workspace data is isolated per customer, and every query that reads interview data is scoped to the workspace that owns it.
- The audit trail cannot be modified or deleted by the application, because the database refuses those operations outright.
- Data is encrypted in transit (TLS) and at rest by our hosting provider.
- We have not yet completed an independent security audit or a SOC 2 examination. When we do, this section will say so and name the auditor.
International transfers
Our AI provider processes requests in the United States. That transfer relies on Standard Contractual Clauses with the UK International Data Transfer Addendum.
Database hosting: ams (Amsterdam, Netherlands). Data is stored in Europe.
We do not currently offer a choice of hosting region. An earlier draft of this policy said you could pick an EU or UK region; that described a capability we do not have, so it has been removed. If you have a hard data-residency requirement, tell us before you buy — we would rather lose the sale than promise residency we cannot deliver today.
Children
This is a tool for professional hiring and is not directed at children. We do not knowingly collect data about anyone under 16. If you believe we have, tell us and we will delete it.
Changes to this policy
This is version 0.1-draft, effective 2026-08-08.
If we make a change that materially affects how we handle your data, we will email account holders before it takes effect rather than silently updating this page.