Privacy and data protection
Kadroflow Privacy Notice
A layered notice for platform users, candidates and workers. It explains when Kadroflow acts as controller or processor and how AI-assisted features affect personal data.
Operator / provider: Kadroflow; Kranj. Stefetova ulica; 95550449; support@kadroflow.com
1. Scope and layered notices
This notice explains how the Kadroflow operator handles personal data for its website, accounts, subscriptions, security and support. It also explains the usual role split when a Customer uses the platform for recruitment or HR records.
The Customer organisation must give candidates and workers its own notice. The short candidate notice, cookie notice and AI notice below supplement this platform notice; they do not replace a Customer's legal duties.
2. Who is responsible
For Kadroflow's own account, billing, website, security, abuse-prevention, support and legal-compliance purposes, the controller is Kadroflow, at Kranj. Stefetova ulica. Contact: support@kadroflow.com.
No data protection officer is currently appointed. The operator's full registered legal name and form, complete official address, registration number and VAT status remain subject to verification before production publication.
3. Controller and processor roles
A Customer normally decides why and how candidate, applicant, interview and workforce data are used. For that processing, the Customer is controller and Kadroflow processes the data on the Customer's documented instructions as processor. Candidates should normally exercise rights with the organisation running the recruitment process.
Kadroflow is an independent controller for its own account administration, billing, security logs, abuse prevention, legal claims and compliance. If Kadroflow ever determines an additional purpose for Customer Data—such as training a general model—that role and lawful basis must be assessed and disclosed before the use begins. This notice does not authorise that use.
4. Data categories and sources
- Account and organisation: name, work email, authentication identifiers, workspace, role, permissions, preferred language and settings.
- Commercial: selected plan, subscription state, billing contact, tax identifiers and payment status. Full card details are handled by the payment provider, not stored in Kadroflow application tables.
- Technical and security: IP-derived security events, device/session metadata, login and audit events, timestamps, failure records and support diagnostics.
- Customer-controlled recruitment and HR data: identities, contact details, CVs, employment and education history, skills, application stages, notes, evaluations, source, communications, interviews, recordings, transcripts, offers, documents, tasks and activity history.
- AI inputs and outputs: content a user submits to an AI feature, instructions, extracted facts, scores, summaries, drafts and related provenance where implemented.
Data may come from the account holder, Customer users, a candidate, an authorised integration, a referral or a public professional source selected by the Customer. The Customer must record and disclose indirect sources where GDPR Article 14 applies.
5. Purposes and lawful bases
- Provide and administer accounts: contract or steps requested before contract; GDPR Article 6(1)(b).
- Billing, tax and accounting: contract and legal obligations; Articles 6(1)(b) and 6(1)(c).
- Security, audit, fraud and service integrity: legitimate interests in protecting customers, people and systems; Article 6(1)(f), balanced against user rights.
- Support and requested communications: contract and legitimate interests; Articles 6(1)(b) and 6(1)(f).
- Defend legal claims and comply with authorities: legal obligation or legitimate interests; Articles 6(1)(c) and 6(1)(f).
- Optional marketing or non-essential analytics: consent where legally required. The preference control must allow refusal and withdrawal without reducing core service.
The Customer, not Kadroflow, must identify and document its lawful basis for recruitment and HR purposes. A generic platform checkbox does not provide the Customer with candidate consent.
6. Special-category and high-risk data
Customers should not upload health, disability, biometric, racial or ethnic origin, political, religious, trade-union, sexual-life, criminal-conviction or similarly sensitive information unless it is strictly necessary, lawful, access-restricted and covered by an applicable GDPR Article 9 or 10 condition and national law. Kadroflow does not infer permission merely because a free-text field accepts the data. Customers must avoid family status, pregnancy and other information unrelated to the role.
7. Candidate privacy notice
If you applied directly: the organisation named in the vacancy or communication is normally the controller. It uses your application to assess and administer the recruitment process. It must tell you its legal basis, recipients, retention period, whether data are required, and how to exercise rights.
If a recruiter created your record, imported a CV, received a referral or sourced you: the recruiting organisation must identify the original source and provide the GDPR Article 14 information no later than the first communication, first disclosure or one month after collection, whichever applicable deadline occurs first. A public profile does not remove that duty.
Kadroflow hosts and processes the record for that organisation. Send a recruitment request to the recruiting organisation first. If you cannot identify it or believe Kadroflow is responsible for its own processing, contact support@kadroflow.com.
8. AI, scoring, profiling and human decisions
Kadroflow can assist users with extraction, summaries, drafting, comparison, scoring and transcription. Depending on configuration and use, this can involve profiling. Inputs and outputs may contain candidate or worker data and may be sent to a configured AI provider on the Customer's instruction.
Outputs may be wrong or biased. Kadroflow's intended workflow requires a trained person to review source evidence, understand limitations and make the decision. The Service must not be configured or used to make a decision producing legal or similarly significant effects solely by automated means. A Customer that uses automation beyond this intended workflow must independently assess GDPR Article 22, applicable employment law and the EU AI Act.
Human review is performed by the Customer's HR team, which can inspect source evidence and is responsible for the final decision. Kadroflow does not permit an AI feature to reject, advance, rank or hire a person without human confirmation. The reviewed deployment configuration sends text and vision requests to Mistral's EU API endpoint and uses Cloudflare Workers AI for default speech-to-text. The exact contracting entities, provider retention and access terms, model versions used for each feature, and any Kadroflow-specific model-improvement use still require contractual and production verification. No Customer Data is authorised for training a general-purpose provider model by this notice.
9. Interview recordings and transcripts
Recording and transcription are controlled by the Customer. The Customer must notify every participant before recording, establish the appropriate lawful basis, collect consent where required, provide a non-recorded route where required, restrict access and set a short retention period. Kadroflow processes the audio, transcript and related metadata only on documented instructions except where law requires otherwise.
10. Recipients and subprocessors
Data may be available to authorised Customer users, Kadroflow personnel who need it for support or security, professional advisers, public authorities where legally required, and approved infrastructure, communications, payment or AI subprocessors needed to provide requested features.
Services identified in the reviewed deployment configuration include Cloudflare for application delivery, API infrastructure, private object storage and speech-to-text; Neon for the primary database; Supabase for authentication and remaining Edge Function workloads; Resend for email; Stripe for billing; and Mistral's EU API endpoint for text and vision AI features. Optional Customer-directed integrations include Google Workspace, Microsoft 365 and GitHub. This code-level brand list is not a verified production subprocessor register and must not be treated as one. Before publication, the register must identify the exact contracting entity, role, location, transfer mechanism and change-notice process.
11. International transfers
Where personal data leave the EEA, the responsible party must use an applicable GDPR Chapter V mechanism—such as an adequacy decision or approved standard contractual clauses—and complete any required transfer assessment and supplementary measures. Kadroflow does not claim a particular adequacy status, Data Privacy Framework participation, SCC module or hosting region until the relevant production contract and tenant configuration have been verified.
12. Cookies and browser storage
The reviewed application source uses a sidebar_state cookie for seven days to remember a user-interface preference. It also uses browser storage for authentication/session state, language, theme, active workspace, drafts, view preferences and workflow continuity. Some working storage can contain Customer Data and is scoped and cleared through application controls.
Strictly necessary storage supports login, security and requested preferences. The reviewed source permits Cloudflare Web Analytics endpoints in its security policy but does not itself prove that analytics is enabled in the production dashboard. Production status must be verified. Where consent is legally required for analytics storage or access, analytics must remain off until the visitor makes a freely given choice; refusal must be as easy as acceptance and withdrawal must remain available.
Kadroflow will maintain the deployed cookie and browser-storage inventory from production network scans covering the marketing site, authentication, application and payment journey. The final consent control must reflect the actual names, providers, purposes, durations and recipients.
If non-essential analytics is enabled, a production consent control must be implemented and tested before that analytics runs.
13. Retention and deletion
We keep our controller-side account, billing, security and legal records only as long as needed for the relevant purpose and applicable legal or limitation periods. Customer-controlled candidate and HR records remain subject to the Customer's documented schedule and deletion instructions.
Production includes Customer-driven record and workspace deletion and short-lived technical records in some workflows. Specific periods for candidate records, recordings, account closure and backups will be published only after the complete retention schedule and backup-expiry behavior have been technically verified. Until then, the Customer must define its own documented recruitment-retention schedule and request deletion when the relevant purpose ends.
14. Security
Repository evidence includes authentication, optional multi-factor authentication, role and organisation checks, row-level access policies, private storage patterns, time-limited file access, server-side checks for sensitive operations, request throttling, audit events and browser security headers. Measures are reviewed according to risk.
These statements are not a certification or guarantee. Deployment settings, data regions, restore tests, incident response, vendor controls and policy effectiveness must be verified in production. Users must protect credentials, devices, role assignments and connected accounts.
15. Your rights
Subject to legal conditions, you may request access, correction, deletion, restriction, portability, object to processing based on legitimate interests, withdraw consent without affecting earlier lawfulness, and obtain safeguards information for a transfer. You may also request information about automated processing and challenge a solely automated significant decision where Article 22 applies.
For a recruitment record, contact the recruiting Customer. For a Kadroflow account, website, billing or security matter, email support@kadroflow.com. We may need proportionate information to verify identity and route the request. We will not require more data than necessary.
16. Complaints and supervisory authority
You can complain to the supervisory authority where you live, work or believe an infringement occurred. In Slovenia, this is the Information Commissioner of the Republic of Slovenia. We invite you to contact us first so we can investigate, but that is not a condition of your right to complain.
17. Children and account eligibility
Kadroflow business accounts are not directed to children and may be created only by a person aged at least 18 acting for a business or professional organisation. Candidate records can concern younger applicants only where the recruiting Customer has a lawful employment-related reason and applies the protections required by law.
18. Changes, legal sources and contact
We will date new versions and provide appropriate notice before a material change. A new purpose incompatible with the original purpose will not be introduced merely by editing this notice; it requires its own assessment and, where required, consent.
This draft was grounded in the EU General Data Protection Regulation, the current consolidated EU AI Act, Slovenia's ZVOP-2, ZDR-1 and ZEKom-2. It requires final review against the implemented product and contracts.
Privacy contact: support@kadroflow.com. Postal contact: Kranj. Stefetova ulica.
