Data Processing Agreement
Version 0.1-draft · effective 2026-08-08
Required by UK GDPR Article 28. This forms part of our Terms and applies to every workspace on every plan, including Free, from the moment you first process candidate data. You do not need to sign anything.
What this is, and when it applies
This Data Processing Agreement forms part of the Terms of Service between you (the "Controller") and Maya Aboukhater, trading as Kandevo AI ("Processor", "we", "us"). It applies automatically to every workspace, on every plan including Free, from the moment you first process candidate data using the service. You do not need to sign anything separately.
It is required by Article 28(3) of the UK GDPR, which says a processor may only process a controller's personal data under a binding written contract containing the terms set out below.
Where this document and the Terms of Service conflict on the processing of candidate data, this document governs.
1. Subject matter, duration, nature and purpose
Subject matter. Providing structured interview software: generating interview kits from a job description, running work-sample simulations, recording interviewer observations and evidence, producing reports, and — on plans where it is available — scoring an asynchronous screening exercise the candidate completes.
Duration. For as long as your workspace exists, and for the deletion window in section 7 afterwards.
Nature. Storage, organisation, retrieval, analysis by a large language model, and generation of text derived from the above.
Purpose. Only to provide the service to you, and to keep it secure and working. We do not process candidate data to develop the product, to train any model, or for any purpose of our own. Section 8 states the one narrow exception and what it excludes.
2. Types of personal data and categories of data subject
Categories of data subject. Candidates you interview or screen. Separately, your own users — that data is covered by the Privacy Policy, where we are the controller, not this agreement.
Types of personal data, in the tables named:
- `sessions` — the label or name you give a candidate, and the interview's timing and state.
- `scores` and `observations` — your interviewers' written evidence about what a candidate said and did, and the ratings attached to it.
- `sim_runs` — what a candidate wrote or chose during a work-sample simulation.
- `screening_results` — a candidate's own written answer to an asynchronous exercise, the name they optionally gave, and the observations generated from it.
- `audit_events` — a record of who did what and when, including decisions about a candidate.
- Special category data is not requested and has no field. A candidate may nevertheless disclose it unprompted in free text — a health condition, a caring responsibility. Section 9 says what we do about that. You remain responsible for having an Article 9 condition if you rely on such information.
3. We process only on your documented instructions
We process candidate data only on your documented instructions. Your instructions are: these Terms, this agreement, your configuration of the service, and the actions your users take in it. We will not process candidate data for any other purpose.
If we believe an instruction infringes UK GDPR or other data protection law, we will tell you and may pause that processing until it is resolved.
This includes transfers. We will not transfer candidate data to a third country except as described in section 6, and will tell you before adding any new destination.
If we are required by law to process beyond your instructions, we will tell you first unless that law forbids it.
4. Confidentiality
Everyone we authorise to process candidate data is bound by a duty of confidentiality that survives the end of their engagement. Today that is a very short list: Maya Aboukhater, trading as Kandevo AI is a sole trader, and no employee or contractor has access to production candidate data.
We will tell you in this document before that changes.
5. Security (Article 32)
The measures we actually operate, stated so you can hold us to them rather than as adjectives:
- Encryption in transit for all traffic, with HSTS. Encryption at rest by the hosting provider. Database connections outside the private network require TLS.
- Passwords stored as salted hashes, never recoverable. Sessions are opaque server-side tokens, revocable immediately.
- Workspace isolation enforced in every database query, not in the interface — a query for another workspace's data returns nothing rather than being hidden.
- The audit trail is append-only, enforced by database rules: UPDATE and DELETE against it do nothing, including by us.
- Candidate names and labels are never sent to the AI provider.
- Point-in-time recovery on the database, with a continuous backup archive.
- We have not completed an independent security audit or penetration test. We say so here rather than let you assume otherwise.
6. Sub-processors
You give general authorisation for us to engage the sub-processors listed in the Privacy Policy, which names each one, what it does, what it sees and where it is.
We will publish any addition to that list at least 30 days before it starts processing your data. If you object within those 30 days, tell us; if we cannot resolve it, you may terminate and we will refund any unused prepaid period.
Every sub-processor is bound by terms no less protective than these.
Candidate data is stored in ams (Amsterdam, Netherlands), inside the UK/EEA. Our AI provider processes requests in the United States under Standard Contractual Clauses with the UK International Data Transfer Addendum; candidate names and labels are not included in those requests.
7. Candidate rights, deletion and return
You are the controller, so a candidate's request comes to you. We will assist you in responding, and will not answer a candidate directly about your data beyond telling them to contact you.
The service gives you the means to do this yourself: you can export a workspace's data, and delete a session, a candidate's record, or the entire workspace, at any time.
On termination, you can export your data for 30 days. After that we delete it, and we will delete it sooner on your written instruction.
One exception, stated plainly: the append-only audit trail cannot be edited or deleted while the workspace exists, because a trail that can be rewritten is not a trail. It records that a decision happened and who made it — it does not hold interview content. It is deleted with the workspace.
8. Assistance, breach notification and audit
Breaches. We will tell you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your candidate data, with what we know: what happened, which data and roughly how many people, the likely consequences, and what we are doing. You decide whether to notify the ICO or the individuals — it is your call as controller, and the 72-hour clock in Article 33 is yours.
Assistance. We will help you, taking account of the nature of processing and what we know, with your obligations under Articles 32 to 36 — security, breach notification, and data protection impact assessments.
Audit. We will give you the information you reasonably need to show compliance with this agreement, and will contribute to an audit or inspection you or an auditor you appoint conducts, on reasonable notice and no more than once a year unless there has been a breach or the ICO requires it.
9. What we do NOT do with candidate data
Stated as commitments, because they are the ones most worth holding us to:
- No training. Candidate data is never used to train or fine-tune any model, ours or anyone else's. Our AI provider does not train on API content.
- No automated decision. Nothing in the product makes or recommends a hiring decision without a person. Observations and counts are evidence for a human to read; the decision field can only be written by a signed-in user, and the record shows who wrote it.
- No profiling across candidates, no ranking of one candidate against another except where you explicitly compare them, and no scoring of a candidate against anyone but the role.
- No enrichment. We do not look candidates up online, buy data about them, or add anything to their record that you or they did not provide.
- No demographic analytics. The anonymised quality data that helps us improve the product is grouped by role family only, and every row is filtered to strip identifiers and demographic fields before it is written.
- No selling, ever. Candidate data is not sold, licensed or shared for anyone else's marketing.
10. Liability, and this document's status
Liability under this agreement is subject to the limits in the Terms of Service, except where those limits cannot lawfully apply.
This agreement is a draft pending legal review, like the rest of our legal pages. It is written to describe what the software actually does, so that a reviewer is checking accuracy rather than drafting from nothing. If your legal team needs changes, tell us — we would rather agree wording that is true than sign wording that sounds better.
Questions, objections to a sub-processor, or audit requests: privacy@kandevo.ai.