Legal
Data Processing Agreement
Written by the Krudo team, not yet reviewed by an external lawyer. It describes what the product does today, measured against the code, and we would rather publish that than a polished document nobody checked.
1. Roles of the parties
This agreement forms part of the Terms of Service and applies to every subscription. For candidate data you are the controller and Krudo SAS is the processor: you decide that an application is assessed, and we carry it out on your documented instructions. Your instructions are this agreement, the Terms, and what you do in the product.
For your own users' account data, Krudo is the controller and the Privacy Policy governs it.
If we ever believe an instruction breaches data protection law, we tell you and may pause that processing until it is resolved.
2. Subject matter and duration
The subject matter is the assessment of job applications you already hold, to help you tell a genuine application from a fabricated one. Processing starts when you connect an applicant tracking system or submit an application, and lasts as long as your workspace exists.
There is no fixed retention period for assessment records, and this agreement does not pretend otherwise. Three periods are enforced in the product: audit events are removed after 24 months, on-server backups are kept for three days, and every shared report link and exported file carries an expiry set when it is created. Everything else stays until you ask for it to go, or until the workspace closes.
3. Nature and purpose of processing
Collection from your applicant tracking system, storage, structured analysis, comparison against public and commercial sources, scoring, and making the result available to your team. One further purpose is worth naming because it crosses files: applications are grouped by a salted hash of the address they were sent from, which is how a series of applications submitted from one place becomes visible.
The assessment is automated. The decision is not: a score is information for a person, who reads the reasons and decides. Using a score as the sole ground for rejection is forbidden by the Terms, and the notice for candidates tells the person assessed how to ask for a human review of any decision taken with it.
Nationality, name and declared country carry no weight in the score. The only geographic signal compares where an application was submitted from with the location the application itself states, and it is weighted below the level at which any single signal can move a candidate across the threshold.
4. Categories of data and data subjects
Data subjects are the people who applied to you, and the members of your team who use Krudo.
For applicants: name, e-mail address, telephone number, the location and the current employer the application states, the links supplied with it, the record your applicant tracking system returns, the CV and its attachments, the address the application was submitted from and a salted hash of it, and everything the checks derive from those: per-check results, signals, score, band, and the notes and verdicts your team records.
The CV is listed above because we hold it. The server writes the file it downloads from your applicant tracking system to its own disk and re-reads it while a check runs. We are removing that step so that only derived text remains; until it is removed, the file is covered by every obligation in this agreement.
For your team: name, work e-mail address, role, sessions, and the audit trail of their actions. We ask for no special-category data, and nothing in the product is designed to process any. If a CV contains some, it is held incidentally and no check reads it deliberately.
5. Sub-processors
You give general authorisation for the sub-processors listed on thesub-processors page. That page is generated from the same declaration the product's own tests check, so a service cannot reach the product without reaching the list.
We give 30 days' notice before adding one, and you may object in writing within that period. If the objection cannot be resolved, you may terminate the affected part of the service without penalty for the remainder of the term. Every sub-processor is bound by obligations no weaker than these, and we stay responsible to you for what they do.
6. Security measures
Traffic is encrypted in transit and the service exposes no public port of its own: it is reachable only through our provider's tunnel. Each workspace holds its own database file, and a request carrying one workspace's identity cannot read another's. Access tokens and share links are stored hashed. Submission addresses used for grouping are salted and hashed.
Administrative access is limited to named people and uses keys, not passwords. Actions on a candidate record are written to an append-only log with the person, the time and the route. Backups are encrypted, and restoring from one is rehearsed rather than assumed. A scanner runs before every change is published and refuses source code containing candidate data.
We hold no security certification and this agreement does not claim one. We notify you without undue delay, and in any case within 48 hours of becoming aware, of any breach affecting your data, with what we know at that point and what we are doing about it.
7. Data subject rights
Requests belong to you: you are the controller and the answer is yours to give. We help you give it. A request that reaches us first is acknowledged within 24 hours and forwarded to you with a reference, and we do not answer it in your place.
In practice we can give you, for one candidate, everything the workspace holds about them and the reasons recorded against their application, in a form you can send on. We can correct a field and re-run the assessment on the corrected value. We can erase the record. Each of those is done within five working days of your asking, and sooner when a legal deadline is running.
8. Deletion and return
You can export your assessments at any time during the subscription, and for 30 days after it ends. After that we delete the workspace, its database and its stored documents, and the deletion reaches our backups as those roll over.
Erasing one candidate is done by a person, not a button. We remove the mirrored application and candidate record, the stored document, the derived cross-candidate signals, and we write a marker that stops a later sync from restoring any of it from your applicant tracking system. That marker matters: without it, the next routine sync would put the record straight back. The record in your own system is yours and we do not touch it.
We make our records available for an audit of this agreement once a year, on 30 days' notice, and sooner after a breach. We would rather answer a questionnaire in writing than host a visit, and we will say so, but we will not refuse.
Questions about this document: legal@krudo.ai · Data requests: privacy@krudo.ai · Security: security@krudo.ai