Privacy and data protection

Kadroflow Privacy Notice

A layered notice for platform users, candidates and workers. It explains when Kadroflow acts as controller or processor and how AI-assisted features affect personal data.

Version: 2026-07-26Effective: after legal approval; draft dated 26 July 2026

Operator / provider: Kadroflow; Kranj. Stefetova ulica; 95550449; support@kadroflow.com

1. Scope and layered notices

This notice explains how the Kadroflow operator handles personal data for its website, accounts, subscriptions, security and support. It also explains the usual role split when a Customer uses the platform for recruitment or HR records.

The Customer organisation must give candidates and workers its own notice. The short candidate notice, cookie notice and AI notice below supplement this platform notice; they do not replace a Customer's legal duties.

2. Who is responsible

For Kadroflow's own account, billing, website, security, abuse-prevention, support and legal-compliance purposes, the controller is Kadroflow, at Kranj. Stefetova ulica. Contact: support@kadroflow.com.

[INFORMATION REQUIRED] Verify the operator's full registered name, registration number, VAT status, telephone, representative and whether a data protection officer must be appointed. If appointed, publish the DPO's direct contact.

3. Controller and processor roles

A Customer normally decides why and how candidate, applicant, interview and workforce data are used. For that processing, the Customer is controller and Kadroflow processes the data on the Customer's documented instructions as processor. Candidates should normally exercise rights with the organisation running the recruitment process.

Kadroflow is an independent controller for its own account administration, billing, security logs, abuse prevention, legal claims and compliance. If Kadroflow ever determines an additional purpose for Customer Data—such as training a general model—that role and lawful basis must be assessed and disclosed before the use begins. This notice does not authorise that use.

4. Data categories and sources

  • Account and organisation: name, work email, authentication identifiers, workspace, role, permissions, preferred language and settings.
  • Commercial: selected plan, subscription state, billing contact, tax identifiers and payment status. Full card details are handled by the payment provider, not stored in Kadroflow application tables.
  • Technical and security: IP-derived security events, device/session metadata, login and audit events, timestamps, failure records and support diagnostics.
  • Customer-controlled recruitment and HR data: identities, contact details, CVs, employment and education history, skills, application stages, notes, evaluations, source, communications, interviews, recordings, transcripts, offers, documents, tasks and activity history.
  • AI inputs and outputs: content a user submits to an AI feature, instructions, extracted facts, scores, summaries, drafts and related provenance where implemented.

Data may come from the account holder, Customer users, a candidate, an authorised integration, a referral or a public professional source selected by the Customer. The Customer must record and disclose indirect sources where GDPR Article 14 applies.

5. Purposes and lawful bases

  • Provide and administer accounts: contract or steps requested before contract; GDPR Article 6(1)(b).
  • Billing, tax and accounting: contract and legal obligations; Articles 6(1)(b) and 6(1)(c).
  • Security, audit, fraud and service integrity: legitimate interests in protecting customers, people and systems; Article 6(1)(f), balanced against user rights.
  • Support and requested communications: contract and legitimate interests; Articles 6(1)(b) and 6(1)(f).
  • Defend legal claims and comply with authorities: legal obligation or legitimate interests; Articles 6(1)(c) and 6(1)(f).
  • Optional marketing or non-essential analytics: consent where legally required. The preference control must allow refusal and withdrawal without reducing core service.

The Customer, not Kadroflow, must identify and document its lawful basis for recruitment and HR purposes. A generic platform checkbox does not provide the Customer with candidate consent.

6. Special-category and high-risk data

Customers should not upload health, disability, biometric, racial or ethnic origin, political, religious, trade-union, sexual-life, criminal-conviction or similarly sensitive information unless it is strictly necessary, lawful, access-restricted and covered by an applicable GDPR Article 9 or 10 condition and national law. Kadroflow does not infer permission merely because a free-text field accepts the data. Customers must avoid family status, pregnancy and other information unrelated to the role.

7. Candidate privacy notice

If you applied directly: the organisation named in the vacancy or communication is normally the controller. It uses your application to assess and administer the recruitment process. It must tell you its legal basis, recipients, retention period, whether data are required, and how to exercise rights.

If a recruiter created your record, imported a CV, received a referral or sourced you: the recruiting organisation must identify the original source and provide the GDPR Article 14 information no later than the first communication, first disclosure or one month after collection, whichever applicable deadline occurs first. A public profile does not remove that duty.

Kadroflow hosts and processes the record for that organisation. Send a recruitment request to the recruiting organisation first. If you cannot identify it or believe Kadroflow is responsible for its own processing, contact support@kadroflow.com.

8. AI, scoring, profiling and human decisions

Kadroflow can assist users with extraction, summaries, drafting, comparison, scoring and transcription. Depending on configuration and use, this can involve profiling. Inputs and outputs may contain candidate or worker data and may be sent to a configured AI provider on the Customer's instruction.

Outputs may be wrong or biased. Kadroflow's intended workflow requires a trained person to review source evidence, understand limitations and make the decision. The Service must not be configured or used to make a decision producing legal or similarly significant effects solely by automated means. A Customer that uses automation beyond this intended workflow must independently assess GDPR Article 22, applicable employment law and the EU AI Act.

[INFORMATION REQUIRED] Before production AI use, publish the verified model/provider, contracting entity, processing region, retention, human-review and model-training position; complete the DPIA and AI Act role/classification assessment; and document contest and correction procedures.

9. Interview recordings and transcripts

Recording and transcription are controlled by the Customer. The Customer must notify every participant before recording, establish the appropriate lawful basis, collect consent where required, provide a non-recorded route where required, restrict access and set a short retention period. Kadroflow processes the audio, transcript and related metadata only on documented instructions except where law requires otherwise.

10. Recipients and subprocessors

Data may be available to authorised Customer users, Kadroflow personnel who need it for support or security, professional advisers, public authorities where legally required, and approved infrastructure, communications, payment or AI subprocessors needed to provide requested features.

The repository identifies technical integrations, but it does not prove the exact production contracting entities, regions or transfer terms. We therefore do not present those integrations here as a verified legal subprocessor list. [INFORMATION REQUIRED: publish a dated subprocessor list with purpose, entity, country, region, transfer mechanism and change-notice process before launch].

11. International transfers

Where personal data leave the EEA, the responsible party must use an applicable GDPR Chapter V mechanism—such as an adequacy decision or approved standard contractual clauses—and complete any required transfer assessment and supplementary measures. [INFORMATION REQUIRED] No particular adequacy status, Data Privacy Framework participation, SCC module or hosting region is claimed until the production contracts and tenant configuration are verified.

12. Cookies and browser storage

The reviewed application source uses a sidebar_state cookie for seven days to remember a user-interface preference. It also uses browser storage for authentication/session state, language, theme, active workspace, drafts, view preferences and workflow continuity. Some working storage can contain Customer Data and is scoped and cleared through application controls.

Strictly necessary storage supports login, security and requested preferences. Non-essential analytics or advertising technology must remain off until the user has made a freely given choice; refusal must be as easy as acceptance and withdrawal must remain available.

[INFORMATION REQUIRED] Run a production browser/network scan across the marketing site, authentication, application and payment journey. Reconcile actual names, providers, purposes, durations and recipients with the final consent banner. Source review alone cannot prove the deployed cookie inventory.

Banner copy: “Kadroflow uses necessary storage for sign-in, security and preferences. With your permission, optional analytics may help us improve the service. Rejecting optional storage will not affect core functions.” Buttons: Reject optional, Accept selected, Manage choices.

13. Retention and deletion

We keep our controller-side account, billing, security and legal records only as long as needed for the relevant purpose and applicable legal or limitation periods. Customer-controlled candidate and HR records remain subject to the Customer's documented schedule and deletion instructions.

Production currently includes customer-driven record/workspace deletion and short-lived technical records in some workflows, but the repository does not establish one verified end-to-end period for candidates, recordings, account closure or backups. [INFORMATION REQUIRED: approve the retention schedule, implement automatic rules where promised, and verify backup expiry before publishing specific periods].

14. Security

Repository evidence includes authentication, optional multi-factor authentication, role and organisation checks, row-level access policies, private storage patterns, time-limited file access, server-side checks for sensitive operations, request throttling, audit events and browser security headers. Measures are reviewed according to risk.

These statements are not a certification or guarantee. Deployment settings, data regions, restore tests, incident response, vendor controls and policy effectiveness must be verified in production. Users must protect credentials, devices, role assignments and connected accounts.

15. Your rights

Subject to legal conditions, you may request access, correction, deletion, restriction, portability, object to processing based on legitimate interests, withdraw consent without affecting earlier lawfulness, and obtain safeguards information for a transfer. You may also request information about automated processing and challenge a solely automated significant decision where Article 22 applies.

For a recruitment record, contact the recruiting Customer. For a Kadroflow account, website, billing or security matter, email support@kadroflow.com. We may need proportionate information to verify identity and route the request. We will not require more data than necessary.

16. Complaints and supervisory authority

You can complain to the supervisory authority where you live, work or believe an infringement occurred. In Slovenia, this is the Information Commissioner of the Republic of Slovenia. We invite you to contact us first so we can investigate, but that is not a condition of your right to complain.

17. Children and account eligibility

Kadroflow business accounts are not directed to children and may be created only by a person aged at least 18 acting for a business or professional organisation. Candidate records can concern younger applicants only where the recruiting Customer has a lawful employment-related reason and applies the protections required by law.

18. Changes, legal sources and contact

We will date new versions and provide appropriate notice before a material change. A new purpose incompatible with the original purpose will not be introduced merely by editing this notice; it requires its own assessment and, where required, consent.

This draft was grounded in the EU General Data Protection Regulation, the EU AI Act, Slovenia's ZVOP-2, ZDR-1 and ZEKom-2. It requires final review against the implemented product and contracts.

Privacy contact: support@kadroflow.com. Postal contact: Kranj. Stefetova ulica.