Legal
Privacy Policy
Written by the Krudo team, not yet reviewed by an external lawyer. It describes what the product does today, measured against the code, and we would rather publish that than a polished document nobody checked.
1. What we collect
Krudo processes two categories of data, and they are kept apart. Workspace data is about your team: the names and work e-mail addresses of the people who sign in, their sessions, the settings of the workspace, the verdicts and notes they record, and a log of who did what. Assessment data is about an application you already hold in your applicant tracking system.
For an assessment we store what the application already contains: the applicant's name, e-mail address, telephone number, the location they state, their current employer, the links they supplied, the record your applicant tracking system returns for them, and the address recorded when the application was submitted. To that we add what the checks produce: a score, a band, the result of each check, and a salted hash of the submission address used to group applications that arrived from the same place.
Assessments draw only on information that is already public or already in the application. Nothing is fetched from the candidate, and no contact is ever made with them.
This website is separate and collects nothing. It loads no analytics script, sets no advertising cookie and sends no measurement anywhere. If you fill in a form here, we receive what you typed and nothing else.
2. What we never collect
We do not build profiles of people outside your pipeline. We do not sell, share or recycle candidate data. We do not use your data to train shared models. A candidate's nationality, name or declared country is never used as a signal.
We do not log in as anyone, guess a password, or open anything a signed-out visitor could not open. Some checks do query commercial data services, and each of those is named on thesub-processors page with what it receives. We would rather list them than describe the product as if it worked alone.
3. How assessments work
A check compares one thing the application states against a source anyone can query. The results are added up into a score from 0 to 100 and a band, and both are shown next to the reasons that produced them. A high score means the application deserves a closer look. It is never a rejection, and Krudo never rejects anyone: your team decides, and can override any band.
Most checks run on our servers when an application arrives. A few can only run from an analyst's own browser, because they need a logged-in session or the analyst's own network connection. Which check runs where is fixed in the product and is not a per-workspace setting.
Nationality carries no weight. Where an application was submitted from matters in one case only: when the country it was sent from contradicts the country the application itself states. That single signal is deliberately weighted below the level at which any one signal can move a candidate across the threshold on its own.
4. Retention & deletion
There is no fixed retention period for assessment records, and we would rather say so than publish a number nothing enforces. They stay while your workspace exists, because they belong to a file you are keeping anyway, and they go when you ask us or when the workspace is closed.
Three periods are enforced, in code. Audit events are removed after 24 months. Backups of the workspace database are kept on the server for three days, plus any off-box copies your contract provides for. A shared report link and an exported file each carry an expiry set when they are created, and the exported content is dropped the moment the job expires.
About documents. A CV is fetched to be read, and we are removing the step that keeps it. Today the server still writes the file it downloaded from your applicant tracking system to its own disk and re-reads it during a check. Until that changes we treat those files as assessment data: they sit on the same encrypted volume, they are covered by the same erasure route, and we name them here rather than leave them out.
Erasure is done by a person, not by a button. We remove the mirrored application and candidate record, the stored document, the derived cross-candidate signals, and we write a marker that stops a later sync from bringing any of it back from your applicant tracking system. The record in that system is yours and we do not touch it.
5. Your rights (GDPR)
For candidate data the employer is the controller and Krudo is the processor: the employer decides that an assessment happens, and we carry it out on their instruction. For your team's account data, Krudo is the controller.
A candidate can ask what was assessed, ask for a correction, ask for the assessment to be erased, object to it, or ask for a person to review a decision made with it. Write to the employer, or to us at privacy@krudo.ai with the employer's name. We acknowledge within 24 hours, pass the request to the employer with a reference, and answer within one month, which is the period the GDPR sets. The notice for candidates sets out that route in plain language, including the right to contest an automated decision.
None of this removes the right to complain to a supervisory authority, in the country where you live or work.
6. Sub-processors
The providers that run the service, and every external service a check queries, are listed on the sub-processors page, with what each one receives. That list is generated from the same declaration the product is checked against, so a service cannot be added to the product without appearing there.
We give 30 days' notice before adding one. A customer with a signed data processing agreement can object in writing during that period.
7. Security measures
Traffic is encrypted in transit and the service has no public port of its own: it is reachable only through our provider's tunnel. Each workspace has its own database file, and a request carrying one workspace's identity cannot read another's. Access tokens and share links are stored as hashes, never as the secret itself. Submission addresses used for grouping are stored salted and hashed.
Administrative access to the server is limited to named people and goes through keys, not passwords. Actions that touch a candidate record are written to an append-only log with the person, the time and the route. Backups are encrypted. A scanner runs before every change is published and refuses to publish source code containing candidate data.
We hold no security certification and do not claim one. If your procurement process needs evidence, write to security@krudo.ai and we will answer with what we actually do.
8. Contact & DPO
Krudo SAS, Paris, France. Registered office and company number are added to this page when the registration is complete.
privacy@krudo.ai reaches the person responsible for data protection at Krudo. It is read by a human being, and a request sent there does not need a form, a reference or an account.
Questions about this document: legal@krudo.ai · Data requests: privacy@krudo.ai · Security: security@krudo.ai