This Data Processing Agreement ("DPA") governs Kanvis's processing of personal data on behalf of an organisation that uses the Service to hire ("Customer," "you"). It forms part of, and is incorporated by reference into, the Recruiter Terms of Service (the "Agreement").
This DPA takes effect automatically when an organisation accepts the Recruiter Terms. You do not need to sign a separate copy. If your legal team needs a countersigned version, or a copy of the Standard Contractual Clauses with the annexes completed for your organisation, write to privacy@kanvis.me.
If there is a conflict, the order of precedence is: (1) the Standard Contractual Clauses incorporated by Section 9, (2) this DPA, (3) the Recruiter Terms, (4) the Terms of Use.
1. Definitions
- "Data Protection Law" means all laws applicable to the processing of personal data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended ("CCPA"), and the data protection laws of Pakistan, the United Arab Emirates, and the Kingdom of Saudi Arabia to the extent they apply.
- "Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Sub-processor," "Supervisory Authority" carry the meanings given in the GDPR. Where the CCPA applies, "Business," "Service Provider," "Consumer," "Sell," and "Share" carry the meanings given there.
- "Candidate Data" means Personal Data relating to applicants, imported candidates, and other individuals whose information Customer processes through the Service for recruitment purposes.
- "Covered Processing" means Kanvis's processing of Candidate Data as a Processor on Customer's behalf, as scoped by Section 2 and described in Annex 1.
- "SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.
- "Security Incident" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Candidate Data.
- "Service" has the meaning given in the Terms of Use.
2. Roles of the Parties
Kanvis operates a two-sided platform, and the two sides carry different roles. Getting this boundary right matters, so it is stated explicitly rather than left to inference.
A. Where Customer is Controller and Kanvis is Processor
For the following, Customer is the Controller and Kanvis is the Processor acting on Customer's documented instructions:
| Processing | What it covers |
|---|---|
| Job definition | The structured job description, custom application questions, required fields, private screening criteria, and scoring rubric Customer creates. |
| Application records | Each Application submitted to Customer's role: the frozen candidate profile snapshot, interview transcript and answers, custom answers, match score and its breakdown, eligibility and coverage signals. |
| The AI interview | Running the planner-driven interview against Customer's role, using Customer's questions and criteria. |
| Scoring and ranking | Scoring each application against Customer's rubric and ranking the applicant pool. |
| The Decision Board and Shortlist QA | Generating shortlist/backup/reject recommendations for Customer's pool and answering Customer's questions about it. |
| Recruiter-private data | Recruiter notes, pipeline stages, activity logs, and internal labels. |
| Bulk CV import | CVs Customer uploads, the sourced candidate records created from them, and their scores. |
| Candidate communications | Emails Customer drafts, approves, and sends to candidates through the Service. |
B. Where Kanvis is an independent Controller
Kanvis is an independent Controller, not a Processor, for:
- The candidate-side platform: a candidate's account, Talent Graph profile, public profile page, AI Twin, résumé and outreach tools, JD Mentor analyses, and workspace. Candidates are Kanvis's own users and Kanvis determines those purposes and means.
- Kanvis's own operation of the Service: security, abuse prevention, billing, service analytics, support, and improvement of the Service, in each case as described in the Privacy Policy.
- Personal Data of Customer's own personnel (recruiter accounts, seats, invitations, contact details).
Kanvis's processing as an independent Controller is governed by the Privacy Policy, not by this DPA. Customer's instructions do not extend to it, and Customer has no right under this DPA to direct Kanvis to delete, disclose, or alter a candidate's own account or public profile.
C. The boundary in practice
A candidate exists on Kanvis before, during, and after any application to Customer. Customer's rights run to the application record, not to the person. Deleting Customer's account, or Customer instructing deletion under Section 8, removes Customer's copy of the application record; it does not delete the candidate's own Kanvis profile, and it does not delete records Kanvis must retain as Controller.
D. Independent obligations
Each party complies with Data Protection Law applicable to it in its own role. Customer is responsible for the lawfulness of the Candidate Data it provides and of the instructions it gives — including having a lawful basis and, where the data comes from a source other than the candidate, having given the notice required by Article 14 GDPR or its local equivalent.
3. Customer Instructions
- Kanvis processes Candidate Data only on Customer's documented instructions, including for international transfers, unless required to do otherwise by law to which Kanvis is subject. Where law compels processing, Kanvis will inform Customer before processing unless the law prohibits it on important grounds of public interest.
- The Agreement, this DPA, and Customer's configuration and use of the Service constitute Customer's complete documented instructions. Additional instructions must be agreed in writing and may be chargeable if they require material effort.
- Kanvis will tell Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend performance of that instruction until it is withdrawn or amended.
- Kanvis does not sell Candidate Data, does not share it for cross-context behavioural advertising, and does not use it for advertising.
- Kanvis does not use Candidate Data processed under this DPA to train, fine-tune, or otherwise develop general-purpose AI models, and does not permit its AI sub-processors to do so. Kanvis may use aggregated, de-identified statistics that cannot reasonably be re-identified in order to measure and improve the Service's accuracy and reliability, and will not attempt to re-identify them.
4. Confidentiality
Kanvis ensures that every person authorised to process Candidate Data is bound by an appropriate obligation of confidentiality (contractual or statutory), receives training appropriate to their role, and has access only where needed to perform the Agreement.
5. Security
- Kanvis implements and maintains appropriate technical and organisational measures to protect Candidate Data against a Security Incident, taking into account the state of the art, cost, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects. The measures in force are described in Annex 2.
- Kanvis may update the measures over time, provided it does not materially reduce their overall protection.
- Customer is responsible for its own side: seat hygiene, credential security, promptly revoking members who leave, and configuring the Service appropriately for its risk.
6. Sub-processors
- Customer gives Kanvis general written authorisation to engage Sub-processors. The current list is in Annex 3.
- Kanvis imposes on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for each Sub-processor's performance.
- Change notice. Kanvis will give Customer at least 30 days' notice before a new Sub-processor begins processing Candidate Data, by updating Annex 3 and notifying the email addresses on Customer's account. To receive these notices, keep an owner email current.
- Objection. Customer may object on reasonable, documented data-protection grounds within the notice period. Kanvis will work in good faith to offer a change in configuration or an alternative. If none is available within a reasonable period, Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the unused term. That is Customer's sole remedy for an objection.
7. Data Subject Rights and Assistance
- Kanvis will assist Customer, by appropriate technical and organisational measures and insofar as possible, in fulfilling Customer's obligation to respond to requests to exercise Data Subject rights (access, rectification, erasure, restriction, portability, objection, and rights concerning automated decision-making).
- Self-service first. The Service already lets Customer read, export, correct, and delete application records, notes, imported CVs, and job data through the recruiter interface. Customer should use those controls before asking Kanvis for help.
- Requests received by Kanvis. If a Data Subject contacts Kanvis directly about data Kanvis processes for Customer, Kanvis will not respond substantively other than to acknowledge and redirect, and will forward the request to Customer without undue delay — except where the request concerns Kanvis's own controller-side processing of that person (their Kanvis account or public profile), which Kanvis handles itself.
- Automated decision-making. Where a Data Subject asks for human review of, or an explanation of, a decision about their application, Customer is responsible for providing the human review — Kanvis does not make hiring decisions. Kanvis will supply Customer, on request, with the information needed to explain how a score and recommendation were produced: the rubric applied, the frozen inputs, the per-requirement breakdown, and a plain-language description of the logic. Kanvis will not disclose the underlying model weights or the prompts that constitute its trade secrets, and will work with Customer to give a meaningful explanation without them.
8. Deletion and Return
- During the term, Customer may delete Candidate Data at any time using the Service's own controls (including per-item deletion of imported CVs and the retention job that purges them in bulk), and may export application data through the recruiter interface.
- On termination or expiry of the Agreement, Kanvis will, at Customer's election, delete or return Candidate Data. Absent a written election within 30 days of termination, Kanvis will delete it.
- Deletion completes within 90 days of the election or of the 30-day window closing, except for copies in routine backups, which are deleted or overwritten on Kanvis's normal backup cycle and remain subject to this DPA until they are.
- Kanvis may retain Candidate Data where required by law, and will keep it protected and process it only for the purpose the law requires.
- Section 2(C) applies: deletion under this Section removes Customer's records. It does not delete a candidate's own Kanvis account or profile, which exists independently of Customer.
9. International Transfers
- Kanvis processes Candidate Data on infrastructure located in the United States (Google Cloud, region
us-central1, and Vercel). Sub-processors may process from other locations as noted in Annex 3. - Where Candidate Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference and apply, as follows:
- Module Two (Controller to Processor) applies to transfers from Customer as Controller to Kanvis as Processor. Module Three (Processor to Processor) applies where Customer is itself a processor for a third party.
- Clause 7 (docking) applies. In Clause 9(a), Option 2 (general written authorisation) applies with the 30-day notice period in Section 6. In Clause 11, the optional independent dispute-resolution body is not used. In Clause 17, the governing law is the law of Ireland. In Clause 18(b), the forum is the courts of Ireland.
- Annex I is completed by Annex 1 and Annex 3 of this DPA and the parties' details in the Agreement; Annex II is completed by Annex 2 of this DPA.
- UK transfers: the UK International Data Transfer Addendum (version B1.0) is incorporated and amends the SCCs for UK transfers. Table 4 is completed as "neither party" may end the Addendum on a change to the Approved Addendum.
- Swiss transfers: references to the GDPR are read as references to the Swiss FADP; the competent authority is the FDPIC; "Member State" does not restrict Swiss Data Subjects from suing in Switzerland.
- Kanvis does not rely on the EU–US Data Privacy Framework. It is not certified under it. The SCCs are the transfer mechanism.
- Transfer impact. Kanvis has assessed the risk of United States government access to Candidate Data and considers the SCCs, combined with the supplementary measures in Annex 2 (encryption in transit and at rest, access control, minimisation, and Kanvis's policy of challenging overbroad demands), to provide protection essentially equivalent to that guaranteed in the EEA. Kanvis will provide its transfer impact assessment to Customer on request and will notify Customer if it becomes unable to comply with the SCCs.
- Government demands. Kanvis will notify Customer of any binding request from a public authority for Candidate Data unless legally prohibited, will seek to redirect the authority to Customer, will challenge requests it considers unlawful or overbroad, and will disclose only the minimum required.
- Other regions. Where Pakistani, UAE, or Saudi law restricts transfer of Candidate Data outside that country, Customer must not upload that data to the Service without first satisfying itself that a lawful transfer mechanism exists and telling Kanvis what it is. Kanvis does not currently offer in-country hosting in those jurisdictions.
10. Security Incidents
- Kanvis will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident affecting Candidate Data.
- The notice will describe, so far as known: the nature of the incident and the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Where the information is not all available at once, Kanvis will provide it in phases without undue further delay.
- Kanvis will take reasonable steps to contain and remediate the incident and will cooperate with Customer's own notification obligations to Supervisory Authorities and Data Subjects.
- Notification is not an admission of fault by Kanvis.
11. Impact Assessments and Prior Consultation
Taking into account the nature of the processing and the information available to it, Kanvis will provide reasonable assistance to Customer with data protection impact assessments and prior consultation with a Supervisory Authority under Articles 35 and 36 GDPR — and with a fundamental rights impact assessment where Customer owes one as a deployer under the EU AI Act. Kanvis maintains documentation about the interview planner, the scoring pipeline, and the recommendation engine for exactly this purpose; ask privacy@kanvis.me.
12. Audit
- Kanvis will make available to Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor it mandates.
- In the first instance, Kanvis will satisfy this by providing its security documentation, this DPA's annexes, and written answers to a reasonable security questionnaire.
- An on-site or hands-on audit may be requested where Customer reasonably believes documentation is insufficient, or following a Security Incident affecting Customer. It requires 30 days' written notice, is limited to once per twelve months (unless required by a Supervisory Authority or following an incident), must occur in business hours without unreasonable disruption, is subject to confidentiality, and must not compromise the data of Kanvis's other customers or candidates. Kanvis may charge its reasonable costs for audits beyond the annual one.
13. CCPA and United States State Privacy Law
Where Kanvis processes Personal Data as a Service Provider to Customer as a Business under the CCPA:
- Kanvis is prohibited from selling or sharing that Personal Data; from retaining, using, or disclosing it for any purpose other than performing the Service, or outside the direct business relationship with Customer; and from combining it with Personal Data from other sources except as permitted for a service provider.
- Kanvis certifies that it understands and will comply with these restrictions.
- Kanvis will assist Customer in responding to Consumer requests, and will notify Customer if it determines it can no longer meet its obligations.
- Customer may take reasonable and appropriate steps to stop and remediate unauthorised use.
- Equivalent terms apply where another United States state privacy law imposes analogous "processor" or "service provider" contract requirements.
14. Liability and Term
- Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Law does not permit them to be limited. Nothing here limits any Data Subject's rights under the SCCs.
- This DPA takes effect when Customer accepts the Agreement and continues while Kanvis processes Candidate Data, and thereafter for so long as any obligation survives.
- This DPA is governed by the law stated in the Agreement, except that Section 9's SCC-specific choices of law and forum control for the SCCs.
Annex 1 — Details of the Processing
Subject matter. Provision of the Kanvis recruiting service to Customer.
Duration. The term of the Agreement, plus the deletion window in Section 8.
Nature and purpose. Hosting; parsing documents; conducting a planner-driven AI interview; freezing immutable snapshots; scoring applications against Customer's rubric; ranking the applicant pool; generating shortlist/backup/reject recommendations and pool summaries; storing recruiter-private notes and pipeline state; drafting and sending Customer-approved candidate communications; supporting Customer.
Categories of Data Subjects.
- Applicants to Customer's roles.
- Individuals whose CVs Customer uploads through bulk CV import ("sourced candidates"), who may not have any relationship with Kanvis.
- Customer's own personnel who hold seats.
Categories of Personal Data.
- Identity and contact: name, email address, phone number, location, profile image, links to social and professional profiles.
- Professional history: employment, education, skills, projects, awards, certifications, publications and intellectual property, governance roles, volunteering, external activities, recommendations.
- Candidate-authored narrative: summaries, motivations, values, working preferences, FAQs.
- Application records: interview transcripts, answers to Customer's questions, declines, match score and per-requirement breakdown, eligibility and coverage signals, AI recommendation and its plain-word confidence label.
- Documents: uploaded CVs, cover letters, portfolio media, and the text parsed from them.
- Recruiter-generated: notes, pipeline stage, activity log, sent communications.
- Technical: identifiers, timestamps, and logs generated by use of the Service.
Special categories. Kanvis does not ask for special-category data and instructs candidates not to provide it. Free-form CVs and interview answers can nonetheless reveal health, religion, ethnic origin, trade-union membership, or similar. Customer must not solicit special-category data through custom questions or private criteria, must not use it in screening, and remains responsible for identifying an Article 9 condition if it processes any it receives. Kanvis applies the same security measures to all Candidate Data.
Frequency. Continuous for the duration of the Agreement.
Retention. As set by Customer's own retention policy and the controls in Section 8. Imported CVs additionally have a retention purge Customer can request. Absent Customer instruction, Kanvis retains application records for the term of the Agreement.
Competent Supervisory Authority (SCC Annex I.C). The authority of the EEA Member State in which Customer is established, or — where Customer is not established in the EEA — the authority of the Member State where Customer's EU representative is established or where the Data Subjects are located.
Annex 2 — Technical and Organisational Measures
Encryption. All traffic between clients, Kanvis services, and sub-processors is encrypted in transit with TLS. Data at rest in the database and object storage is encrypted using the cloud provider's managed encryption.
Access control. Authentication is Firebase-token-based on every authenticated request. Recruiter access is scoped to a single organisation at the database-query level: every recruiter query filters on the requester's organisation, and records outside it are not returned. A single sign-in identity can be either a candidate or a recruiter, never both. Team invitations are token-based, time-limited, and bound to a signed cookie so a leaked token alone cannot claim a seat.
Internal service isolation. Traffic between Kanvis's backend and its AI service requires an internal key header. Background workers verify signed identity tokens. Authentication tokens are never placed into an AI prompt.
Segregation and minimisation. Customer's private screening criteria never reach a candidate-facing surface or a candidate-facing prompt. Recruiter notes and pipeline data are excluded from every candidate-facing response by separate serialisers. Candidate-visible score detail is filtered by an explicit allow-list that fails closed.
Input integrity. Candidate-supplied text reaching any recruiter-facing AI surface is delimited and marked as evidence rather than instruction, and hidden-text and prompt-injection findings in uploaded documents are recorded and surfaced to Customer non-punitively. Automated tests assert this at build time.
Availability and resilience. Managed, replicated cloud infrastructure with automated database backups and point-in-time recovery. Long-running work is queued so failures are retried rather than lost.
Rate limiting and abuse control. Per-endpoint rate limits, per-IP caps on public surfaces, and connection pooling defend against scraping and resource exhaustion.
Logging and monitoring. Application logging, error and exception capture, and per-application activity logs recording recruiter actions. Personal data is kept out of routine INFO-level logs.
Personnel. Access on a need-to-know basis, under confidentiality obligations. Production changes are deployed through a reviewed pipeline; direct production mutation is restricted to the operator.
Deletion. Per-item deletion of imported CVs including the stored file; a bulk retention purge; soft-delete followed by removal for candidate accounts.
Kanvis is a small company and does not currently hold ISO 27001 or SOC 2 certification. Customers who need one should raise it before contracting.
Annex 3 — Sub-processors
| Sub-processor | Role | Data processed | Location |
|---|---|---|---|
| Google Cloud Platform (Google LLC / Google Cloud EMEA) | Application hosting (Cloud Run), database (Cloud SQL), object storage, queueing | All Candidate Data | United States (us-central1) |
| Google Firebase Authentication (Google LLC) | Authentication and identity | Account identifiers, email addresses | United States |
| Google — Gemini API (Google LLC) | Large language model inference: parsing, interview wording, evidence labelling, narratives, drafts | Content submitted for processing (CV text, JD text, interview turns, profile data) | United States |
| LlamaIndex, Inc. — LlamaParse | Parsing PDF and DOCX documents into structured text | Uploaded CVs, JDs, and other documents | United States |
| Vercel Inc. | Frontend hosting and content delivery | Request data; rendered public pages | United States and global edge network |
| Resend (Plus Five Five, Inc.) | Transactional and Customer-approved candidate email delivery | Recipient email address, subject, message body | United States |
| PostHog, Inc. | Product analytics and error capture | Usage events, technical identifiers, exception data | United States |
No sub-processor is authorised to use Candidate Data to train its own models. Kanvis uses paid API tiers where the provider's terms exclude such use.
Kanvis may replace or add to this list under Section 6. To be notified, keep an owner email current on your account, or write to privacy@kanvis.me to be added to the sub-processor notice list.
Contact
Email: privacy@kanvis.me