Kadroflow
Sign in

Privacy and data protection

Kadroflow Privacy Notice

A layered notice for platform users, candidates and workers. It explains when Kadroflow acts as controller or processor and how AI-assisted features affect personal data.

Operator / provider: Kadroflow; Kranj. Stefetova ulica; 95550449; support@kadroflow.com

1. Scope and layered notices

This notice explains how the Kadroflow operator handles personal data for its website, accounts, subscriptions, security and support. It also explains the usual role split when a Customer uses the platform for recruitment or HR records.

The Customer organisation must give candidates and workers its own notice. The short candidate notice, cookie notice and AI notice below supplement this platform notice; they do not replace a Customer's legal duties.

2. Kadroflow Inbox browser extension

What it reads: after you accept the in-extension disclosure and open the side panel from a Gmail or Outlook message, the extension reads the visible sender, subject and message body in that active tab. It uses that content locally to suggest the candidate's name, email address and phone number. The subject and message body are not sent to Kadroflow or stored by the extension.

What it sends: only when you press Import, the extension sends the contact fields you confirmed, the selected job, a duplicate-prevention identifier derived from the open message URL, and the CV and optional certificate files you selected. Those data go over HTTPS to the Kadroflow workspace paired by the user. The extension does not scan folders, read other messages, download inbox attachments, import in the background or collect usage analytics.

Local storage and control: the extension stores the disclosure version and a Kadroflow-issued pairing token in Chrome's local extension storage. The token contains no password, expires after 90 days and can be revoked in Kadroflow or removed by disconnecting. You can reopen the privacy choice in the side panel, and uninstalling the extension removes its local storage.

Retention and use: confirmed candidate records and chosen files follow the Customer workspace's retention and deletion settings. Files rejected during import are not stored. Kadroflow's handling of extension data complies with the Chrome Web Store Limited Use requirements. Extension data is not sold, used for advertising, used to determine creditworthiness or used to train a general-purpose AI model. The dedicated Kadroflow Inbox Privacy Notice presents this boundary on a standalone page for extension users.

3. Who is responsible

For Kadroflow's own account, billing, website, security, abuse-prevention, support and legal-compliance purposes, the controller is Kadroflow, at Kranj. Stefetova ulica. Contact: support@kadroflow.com.

No data protection officer is currently appointed. The operator's full registered legal name and form, complete official address, registration number and VAT status remain subject to verification before production publication.

4. Controller and processor roles

A Customer normally decides why and how candidate, applicant, interview and workforce data are used. For that processing, the Customer is controller and Kadroflow processes the data on the Customer's documented instructions as processor. Candidates should normally exercise rights with the organisation running the recruitment process.

Kadroflow is an independent controller for its own account administration, billing, security logs, abuse prevention, legal claims and compliance. If Kadroflow ever determines an additional purpose for Customer Data—such as training a general model—that role and lawful basis must be assessed and disclosed before the use begins. This notice does not authorise that use.

5. Data categories and sources

  • Account and organisation: name, work email, authentication identifiers, workspace, role, permissions, preferred language and settings.
  • Commercial: selected plan, subscription state, billing contact, tax identifiers and payment status. Full card details are handled by the payment provider, not stored in Kadroflow application tables.
  • Technical and security: IP-derived security events, device/session metadata, login and audit events, timestamps, failure records and support diagnostics.
  • Customer-controlled recruitment and HR data: identities, contact details, CVs, employment and education history, skills, application stages, notes, evaluations, source, communications, interviews, recordings, transcripts, offers, documents, tasks and activity history.
  • AI inputs and outputs: content a user submits to an AI feature, instructions, extracted facts, scores, summaries, drafts and related provenance where implemented.

Data may come from the account holder, Customer users, a candidate, an authorised integration, a referral or a public professional source selected by the Customer. The Customer must record and disclose indirect sources where GDPR Article 14 applies.

6. Purposes and lawful bases

  • Provide and administer accounts: contract or steps requested before contract; GDPR Article 6(1)(b).
  • Billing, tax and accounting: contract and legal obligations; Articles 6(1)(b) and 6(1)(c).
  • Security, audit, fraud and service integrity: legitimate interests in protecting customers, people and systems; Article 6(1)(f), balanced against user rights.
  • Support and requested communications: contract and legitimate interests; Articles 6(1)(b) and 6(1)(f).
  • Defend legal claims and comply with authorities: legal obligation or legitimate interests; Articles 6(1)(c) and 6(1)(f).
  • Optional marketing or non-essential analytics: consent where legally required. The preference control must allow refusal and withdrawal without reducing core service.

The Customer, not Kadroflow, must identify and document its lawful basis for recruitment and HR purposes. A generic platform checkbox does not provide the Customer with candidate consent.

7. Special-category and high-risk data

Customers should not upload health, disability, biometric, racial or ethnic origin, political, religious, trade-union, sexual-life, criminal-conviction or similarly sensitive information unless it is strictly necessary, lawful, access-restricted and covered by an applicable GDPR Article 9 or 10 condition and national law. Kadroflow does not infer permission merely because a free-text field accepts the data. Customers must avoid family status, pregnancy and other information unrelated to the role.

8. Candidate privacy notice

If you applied directly: the organisation named in the vacancy or communication is normally the controller. It uses your application to assess and administer the recruitment process. It must tell you its legal basis, recipients, retention period, whether data are required, and how to exercise rights.

If a recruiter created your record, imported a CV, received a referral or sourced you: the recruiting organisation must identify the original source and provide the GDPR Article 14 information no later than the first communication, first disclosure or one month after collection, whichever applicable deadline occurs first. A public profile does not remove that duty.

Kadroflow hosts and processes the record for that organisation. Send a recruitment request to the recruiting organisation first. If you cannot identify it or believe Kadroflow is responsible for its own processing, contact support@kadroflow.com.

9. AI, scoring, profiling and human decisions

Kadroflow can assist users with extraction, summaries, drafting, comparison, scoring and transcription. Depending on configuration and use, this can involve profiling. Inputs and outputs may contain candidate or worker data and may be sent to a configured AI provider on the Customer's instruction.

Outputs may be wrong or biased. Kadroflow's intended workflow requires a trained person to review source evidence, understand limitations and make the decision. The Service must not be configured or used to make a decision producing legal or similarly significant effects solely by automated means. A Customer that uses automation beyond this intended workflow must independently assess GDPR Article 22, applicable employment law and the EU AI Act.

Human review is performed by the Customer's HR team, which can inspect source evidence and is responsible for the final decision. Kadroflow does not permit an AI feature to reject, advance, rank or hire a person without human confirmation. The reviewed deployment configuration sends text and vision requests to an AI model provider through an EU-hosted API endpoint, and uses a speech-to-text processor that is not pinned to an EU region for default speech-to-text. The exact contracting entities, provider retention and access terms, model versions used for each feature, and any Kadroflow-specific model-improvement use still require contractual and production verification. No Customer Data is authorised for training a general-purpose provider model by this notice.

10. Interview recordings and transcripts

Recording and transcription are controlled by the Customer. The Customer must notify every participant before recording, establish the appropriate lawful basis, collect consent where required, provide a non-recorded route where required, restrict access and set a short retention period. Kadroflow processes the audio, transcript and related metadata only on documented instructions except where law requires otherwise.

11. Recipients and subprocessors

Data may be available to authorised Customer users, Kadroflow personnel who need it for support or security, professional advisers, public authorities where legally required, and approved infrastructure, communications, payment or AI subprocessors needed to provide requested features.

Services used in the current deployment include Cloudflare for application delivery, API infrastructure, private object storage, bot protection on sign-up and application forms where enabled (Turnstile), and speech-to-text; Neon for the primary database; Resend for sending email and, where a Customer uses a forwarding address for job applications, for receiving those emails — including any CV attached — which Resend keeps for a limited period under its own schedule; Hostinger for the support and candidate-reply mailboxes; Stripe for billing; and an AI model provider, reached through an EU-hosted API endpoint, for text and vision AI features. Speech-to-text runs on Cloudflare’s AI inference service, which is not pinned to an EU region. Sign-in is performed by the application itself; no separate authentication provider is involved unless you choose Google sign-in. Supabase, named in earlier versions of this notice, is no longer used. AI providers are listed here by category; the full list of subprocessors, with each AI provider named, is available to Customers under the data processing agreement or on request. Optional Customer-directed integrations include Google (sign-in, Gmail and Calendar), Microsoft 365 (mailbox, calendar and Teams meetings) and, for sourcing searches a recruiter chooses to run, the public GitHub API. Your browser may also contact a small number of third-party hosts directly, and only when you use the feature concerned: a public content-delivery network (jsDelivr) for the PDF viewer’s supporting files, a public host for text-recognition language data when a scanned document is read in your browser, and your browser vendor’s push service if you turn on push notifications, which receives a generic message without Customer Data. This code-level brand list is not a verified production subprocessor register and must not be treated as one. Before publication, the register must identify the exact contracting entity, role, location, transfer mechanism and change-notice process.

12. International transfers

Where personal data leave the EEA, the responsible party must use an applicable GDPR Chapter V mechanism—such as an adequacy decision or approved standard contractual clauses—and complete any required transfer assessment and supplementary measures. Kadroflow does not claim a particular adequacy status, Data Privacy Framework participation, SCC module or hosting region until the relevant production contract and tenant configuration have been verified.

13. Cookies and browser storage

Signing in sets a strictly necessary session cookie that is HttpOnly — page scripts cannot read it. It lasts up to seven days, is renewed while you remain active, ends when you close the browser if you chose not to be remembered, and is never accepted for longer than thirty days; a short-lived companion cookie is used only while a two-factor code is being checked. Three further strictly necessary cookies support single steps: kf_signup_legal and kf_signup_trial carry your acceptance of these documents and any trial code across a Google sign-up (about ten minutes, sent only to the sign-in callback), and kf_interview_score keeps a verified interview-panel member in their scoring session. The application also uses browser storage — not cookies — for language, theme, active workspace, layout and view preferences, drafts, a plan or trial code remembered between pages, and workflow continuity. Public careers pages keep a random key in session storage, which is discarded with the tab, to count visits to an advert without identifying the visitor. Some working storage can contain Customer Data and is scoped and cleared through application controls. Earlier versions of this notice named a sidebar_state cookie and described the session as held in browser storage; the application sets no such cookie, and the session has always been a cookie.

Strictly necessary storage supports login, security and requested preferences. The reviewed source permits Cloudflare Web Analytics endpoints in its security policy but does not itself prove that analytics is enabled in the production dashboard. Production status must be verified. Where consent is legally required for analytics storage or access, analytics must remain off until the visitor makes a freely given choice; refusal must be as easy as acceptance and withdrawal must remain available.

Kadroflow will maintain the deployed cookie and browser-storage inventory from production network scans covering the marketing site, authentication, application and payment journey. The final consent control must reflect the actual names, providers, purposes, durations and recipients.

Optional usage measurement stays off until you allow it under Usage measurement in the website footer. The choice is stored as kf-growth-choice-v1 in local storage until you change it or clear browser storage. After consent, kf-growth-session-v1 in session storage keeps only page, language and source categories and the steps already counted in this tab. Closing the tab ends attribution. You can withdraw using the same footer control. Do Not Track and Global Privacy Control disable collection.

The measurement endpoint sends category-only events to Cloudflare Workers Analytics Engine to assess visits, downloads, signup responses, saved jobs and candidates, and an active paid plan after checkout. It sends no candidate details, user identifiers, full URLs, search terms or referrer addresses to that dataset. This optional dataset is separate from necessary hosting and security request logs. These counts do not establish unique visitors or verified revenue.

14. Retention and deletion

We keep our controller-side account, billing, security and legal records only as long as needed for the relevant purpose and applicable legal or limitation periods. Customer-controlled candidate and HR records remain subject to the Customer's documented schedule and deletion instructions.

Production includes Customer-driven record and workspace deletion and short-lived technical records in some workflows. Specific periods for candidate records, recordings, account closure and backups will be published only after the complete retention schedule and backup-expiry behavior have been technically verified. Until then, the Customer must define its own documented recruitment-retention schedule and request deletion when the relevant purpose ends.

15. Security

Repository evidence includes authentication, optional multi-factor authentication, role and organisation checks, row-level access policies, private storage patterns, time-limited file access, server-side checks for sensitive operations, request throttling, audit events and browser security headers. Measures are reviewed according to risk.

These statements are not a certification or guarantee. Deployment settings, data regions, restore tests, incident response, vendor controls and policy effectiveness must be verified in production. Users must protect credentials, devices, role assignments and connected accounts.

16. Your rights

Subject to legal conditions, you may request access, correction, deletion, restriction, portability, object to processing based on legitimate interests, withdraw consent without affecting earlier lawfulness, and obtain safeguards information for a transfer. You may also request information about automated processing and challenge a solely automated significant decision where Article 22 applies.

For a recruitment record, contact the recruiting Customer. For a Kadroflow account, website, billing or security matter, email support@kadroflow.com. We may need proportionate information to verify identity and route the request. We will not require more data than necessary.

17. Complaints and supervisory authority

You can complain to the supervisory authority where you live, work or believe an infringement occurred. In Slovenia, this is the Information Commissioner of the Republic of Slovenia. We invite you to contact us first so we can investigate, but that is not a condition of your right to complain.

18. Children and account eligibility

Kadroflow business accounts are not directed to children and may be created only by a person aged at least 18 acting for a business or professional organisation. Candidate records can concern younger applicants only where the recruiting Customer has a lawful employment-related reason and applies the protections required by law.

19. Changes, legal sources and contact

We will date new versions and provide appropriate notice before a material change. A new purpose incompatible with the original purpose will not be introduced merely by editing this notice; it requires its own assessment and, where required, consent.

This draft was grounded in the EU General Data Protection Regulation, the current consolidated EU AI Act, Slovenia's ZVOP-2, ZDR-1 and ZEKom-2. It requires final review against the implemented product and contracts.

Privacy contact: support@kadroflow.com. Postal contact: Kranj. Stefetova ulica.

Support