Operator / provider: Kadroflow; Kranj. Stefetova ulica; 95550449; support@kadroflow.com
1. Scope and layered notices
This notice explains how the Kadroflow operator handles personal data for its website, accounts, subscriptions, security and support. It also explains the usual role split when a Customer uses the platform for recruitment or HR records.
The Customer organisation must give candidates and workers its own notice. The short candidate notice, cookie notice and AI notice below supplement this platform notice; they do not replace a Customer's legal duties.
2. Who is responsible
For Kadroflow's own account, billing, website, security, abuse-prevention, support and legal-compliance purposes, the controller is Kadroflow, at Kranj. Stefetova ulica. Contact: support@kadroflow.com.
[INFORMATION REQUIRED] Verify the operator's full registered name, registration number, VAT status, telephone, representative and whether a data protection officer must be appointed. If appointed, publish the DPO's direct contact.
3. Controller and processor roles
A Customer normally decides why and how candidate, applicant, interview and workforce data are used. For that processing, the Customer is controller and Kadroflow processes the data on the Customer's documented instructions as processor. Candidates should normally exercise rights with the organisation running the recruitment process.
Kadroflow is an independent controller for its own account administration, billing, security logs, abuse prevention, legal claims and compliance. If Kadroflow ever determines an additional purpose for Customer Data—such as training a general model—that role and lawful basis must be assessed and disclosed before the use begins. This notice does not authorise that use.
4. Data categories and sources
- Account and organisation: name, work email, authentication identifiers, workspace, role, permissions, preferred language and settings.
- Commercial: selected plan, subscription state, billing contact, tax identifiers and payment status. Full card details are handled by the payment provider, not stored in Kadroflow application tables.
- Technical and security: IP-derived security events, device/session metadata, login and audit events, timestamps, failure records and support diagnostics.
- Customer-controlled recruitment and HR data: identities, contact details, CVs, employment and education history, skills, application stages, notes, evaluations, source, communications, interviews, recordings, transcripts, offers, documents, tasks and activity history.
- AI inputs and outputs: content a user submits to an AI feature, instructions, extracted facts, scores, summaries, drafts and related provenance where implemented.
Data may come from the account holder, Customer users, a candidate, an authorised integration, a referral or a public professional source selected by the Customer. The Customer must record and disclose indirect sources where GDPR Article 14 applies.
5. Purposes and lawful bases
- Provide and administer accounts: contract or steps requested before contract; GDPR Article 6(1)(b).
- Billing, tax and accounting: contract and legal obligations; Articles 6(1)(b) and 6(1)(c).
- Security, audit, fraud and service integrity: legitimate interests in protecting customers, people and systems; Article 6(1)(f), balanced against user rights.
- Support and requested communications: contract and legitimate interests; Articles 6(1)(b) and 6(1)(f).
- Defend legal claims and comply with authorities: legal obligation or legitimate interests; Articles 6(1)(c) and 6(1)(f).
- Optional marketing or non-essential analytics: consent where legally required. The preference control must allow refusal and withdrawal without reducing core service.
The Customer, not Kadroflow, must identify and document its lawful basis for recruitment and HR purposes. A generic platform checkbox does not provide the Customer with candidate consent.
6. Special-category and high-risk data
Customers should not upload health, disability, biometric, racial or ethnic origin, political, religious, trade-union, sexual-life, criminal-conviction or similarly sensitive information unless it is strictly necessary, lawful, access-restricted and covered by an applicable GDPR Article 9 or 10 condition and national law. Kadroflow does not infer permission merely because a free-text field accepts the data. Customers must avoid family status, pregnancy and other information unrelated to the role.
7. Candidate privacy notice
If you applied directly: the organisation named in the vacancy or communication is normally the controller. It uses your application to assess and administer the recruitment process. It must tell you its legal basis, recipients, retention period, whether data are required, and how to exercise rights.
If a recruiter created your record, imported a CV, received a referral or sourced you: the recruiting organisation must identify the original source and provide the GDPR Article 14 information no later than the first communication, first disclosure or one month after collection, whichever applicable deadline occurs first. A public profile does not remove that duty.
Kadroflow hosts and processes the record for that organisation. Send a recruitment request to the recruiting organisation first. If you cannot identify it or believe Kadroflow is responsible for its own processing, contact support@kadroflow.com.
8. AI, scoring, profiling and human decisions
Kadroflow can assist users with extraction, summaries, drafting, comparison, scoring and transcription. Depending on configuration and use, this can involve profiling. Inputs and outputs may contain candidate or worker data and may be sent to a configured AI provider on the Customer's instruction.
Outputs may be wrong or biased. Kadroflow's intended workflow requires a trained person to review source evidence, understand limitations and make the decision. The Service must not be configured or used to make a decision producing legal or similarly significant effects solely by automated means. A Customer that uses automation beyond this intended workflow must independently assess GDPR Article 22, applicable employment law and the EU AI Act.
[INFORMATION REQUIRED] Before production AI use, publish the verified model/provider, contracting entity, processing region, retention, human-review and model-training position; complete the DPIA and AI Act role/classification assessment; and document contest and correction procedures.
9. Interview recordings and transcripts
Recording and transcription are controlled by the Customer. The Customer must notify every participant before recording, establish the appropriate lawful basis, collect consent where required, provide a non-recorded route where required, restrict access and set a short retention period. Kadroflow processes the audio, transcript and related metadata only on documented instructions except where law requires otherwise.
10. Recipients and subprocessors
Data may be available to authorised Customer users, Kadroflow personnel who need it for support or security, professional advisers, public authorities where legally required, and approved infrastructure, communications, payment or AI subprocessors needed to provide requested features.
The repository identifies technical integrations, but it does not prove the exact production contracting entities, regions or transfer terms. We therefore do not present those integrations here as a verified legal subprocessor list. [INFORMATION REQUIRED: publish a dated subprocessor list with purpose, entity, country, region, transfer mechanism and change-notice process before launch].
11. International transfers
Where personal data leave the EEA, the responsible party must use an applicable GDPR Chapter V mechanism—such as an adequacy decision or approved standard contractual clauses—and complete any required transfer assessment and supplementary measures. [INFORMATION REQUIRED] No particular adequacy status, Data Privacy Framework participation, SCC module or hosting region is claimed until the production contracts and tenant configuration are verified.
13. Retention and deletion
We keep our controller-side account, billing, security and legal records only as long as needed for the relevant purpose and applicable legal or limitation periods. Customer-controlled candidate and HR records remain subject to the Customer's documented schedule and deletion instructions.
Production currently includes customer-driven record/workspace deletion and short-lived technical records in some workflows, but the repository does not establish one verified end-to-end period for candidates, recordings, account closure or backups. [INFORMATION REQUIRED: approve the retention schedule, implement automatic rules where promised, and verify backup expiry before publishing specific periods].
14. Security
Repository evidence includes authentication, optional multi-factor authentication, role and organisation checks, row-level access policies, private storage patterns, time-limited file access, server-side checks for sensitive operations, request throttling, audit events and browser security headers. Measures are reviewed according to risk.
These statements are not a certification or guarantee. Deployment settings, data regions, restore tests, incident response, vendor controls and policy effectiveness must be verified in production. Users must protect credentials, devices, role assignments and connected accounts.
15. Your rights
Subject to legal conditions, you may request access, correction, deletion, restriction, portability, object to processing based on legitimate interests, withdraw consent without affecting earlier lawfulness, and obtain safeguards information for a transfer. You may also request information about automated processing and challenge a solely automated significant decision where Article 22 applies.
For a recruitment record, contact the recruiting Customer. For a Kadroflow account, website, billing or security matter, email support@kadroflow.com. We may need proportionate information to verify identity and route the request. We will not require more data than necessary.
16. Complaints and supervisory authority
You can complain to the supervisory authority where you live, work or believe an infringement occurred. In Slovenia, this is the Information Commissioner of the Republic of Slovenia. We invite you to contact us first so we can investigate, but that is not a condition of your right to complain.
17. Children and account eligibility
Kadroflow business accounts are not directed to children and may be created only by a person aged at least 18 acting for a business or professional organisation. Candidate records can concern younger applicants only where the recruiting Customer has a lawful employment-related reason and applies the protections required by law.
18. Changes, legal sources and contact
We will date new versions and provide appropriate notice before a material change. A new purpose incompatible with the original purpose will not be introduced merely by editing this notice; it requires its own assessment and, where required, consent.
This draft was grounded in the EU General Data Protection Regulation, the EU AI Act, Slovenia's ZVOP-2, ZDR-1 and ZEKom-2. It requires final review against the implemented product and contracts.
Privacy contact: support@kadroflow.com. Postal contact: Kranj. Stefetova ulica.
