Legal

Privacy Policy

Effective date: August 19, 2026

What we collect, where it goes, and how to get a copy or have it deleted.

Kanvis ("Kanvis," "we," "us," "our") runs a two-sided hiring platform. Candidates build a verified professional profile and apply for jobs through it. Organisations post roles and screen applicants against those profiles — including with an AI interview and an automated score.

This policy explains what we collect, why, on what legal basis, who receives it, how long we keep it, and what you can make us do about it. Terms in initial capitals that are not defined here have the meaning given in our Terms of Use.


1. The Two Roles Kanvis Plays

Kanvis is a controller for some processing and a processor for other processing. Which one it is changes who you go to and what we can do for you, so it is set out first.

Kanvis is the controller — we decide the purposes and means — for:

  • Your Kanvis account, your Talent Graph profile, and your public profile page.
  • The candidate tools: Build, the workspace concierge, JD Mentor, STAR Resume, Share and Cover Letter, the AI Twin.
  • Running, securing, supporting, measuring, and improving the Service.
  • Recruiter accounts, seats, and invitations.

Kanvis is a processor, acting on an employer's instructions, for:

  • Your application to a specific role: the frozen snapshot, the interview transcript, your answers, your score and its breakdown, the AI recommendation.
  • Recruiter-private material about you: notes, pipeline stage, activity log.
  • CVs an employer uploaded through bulk CV import, and the sourced records built from them.

What that means for you. For anything on the first list, come to us: privacy@kanvis.me. For anything on the second, the employer is the controller — they decide whether to keep your application, how long, and what to do with it. We will still take your request, help you, and pass it on, and where we can act without their instruction (deleting an imported CV, for example) we will. But we cannot overrule an employer's lawful retention of its own hiring records.

Your profile is not theirs. Employers get a frozen copy of what you submitted. They do not get control of your Kanvis account, and deleting their workspace does not delete you.


2. Information We Collect

A. Information you give us

  • Account information. Name, email address, profile picture, and authentication identifiers from Firebase Authentication (Google Sign-In or an emailed verification code).
  • Documents you upload. Résumés (PDF/DOCX), cover letters, job descriptions, portfolio media, images, and files attached to chat. Stored in Google Cloud Storage; parsed by a document-parsing provider and a language model to extract structured data.
  • Your Talent Graph. Identity (full name, location, summary, tagline, username, profile picture); narrative (professional summary, career objectives, motivations, core values, working preferences); experiences, education, skills, projects, awards, certifications; recommendations, social profiles, portfolio media, working styles, FAQs; and executive entities where relevant (governance roles, philanthropy, intellectual property, external activities).
  • Conversations with our AI. Full transcripts and metadata from Azmuth (the Build agent and workspace concierge), the AI Twin, and the application interview. Chat messages are stored in an append-only ledger so every entry on your profile can be traced back to the conversation that produced it. Voice input is transcribed on our own servers; the audio is not sent to a language model.
  • Application data. Your answers to an employer's questions, the interview transcript, declines, and the frozen snapshots taken at submission.
  • Answers we keep so you are not asked twice. Where an employer's form asks something reusable — notice period, salary expectation, work authorisation, a portfolio link — we store the answer against your account and offer it back the next time a form asks the same thing. You can see and delete these in-product. Some carry a freshness window and are re-confirmed rather than assumed.
  • Equal-opportunity and identity answers required by an employer's form. Disability status, ethnicity, veteran status, gender, date of birth, or a national identity number, only ever because a specific employer's form asked and you chose to answer. See Section 10(A) for exactly how these are handled — they are walled off from your profile, your score, and every AI prompt.
  • A photograph, and other files an employer's form demands. Some forms require a photo, a portfolio PDF, a certificate, or a connection-speed screenshot. We store what you provide so a later application asking for the same thing can reuse it.
  • Job-search preferences and your board activity. The functions, seniority, locations, and employment types you are open to; which roles you saved and which you passed on.
  • JD Mentor inputs. Job descriptions you paste or upload, the parsed result, the frozen profile snapshot used for that analysis, and the resulting score and report.
  • Generated artifacts. STAR résumés (PDF and structured data), outreach drafts, cover letters, and their version histories.
  • Preferences and progress. Onboarding checklist state, cookie choices, the "hide from search" setting, email preferences (recruiters), and workspace settings.
  • Recruiter account data. For members of a hiring organisation: work email, full name, job title, role, invitation state, role context and tone preferences, and email notification preferences. Plus organisation-level context you provide (description, stage, culture, tech stack, hiring philosophy, location, benefits).
  • Waitlist sign-ups. Name, work email, company, company email.

B. Information collected automatically

  • Session and device data. Browser, operating system, device identifiers, IP address, and session identifiers — including the temporary anonymous identifiers created before you sign in.
  • Usage analytics. Pages visited, features used, time spent, interaction sequences, and engagement metrics, captured through PostHog and our own server-side logging.
  • AI interaction metadata. Input and output sequences, which tools ran, conversation flow, progress counters, and completion rates.
  • Profile view analytics. Each visit to your published profile creates a view record. The visitor's IP address is salted with your account identifier and hashed with SHA-256 before storage — it is not reversible, and the same visitor produces a different hash on a different profile. Where the visitor is signed in, we store the link so you can see who viewed. Self-views are never counted, and repeat views from the same address within 24 hours are counted once.
  • Referral attribution. When someone arrives via a referral link, we attribute it to power your referral metrics.
  • Performance and error data. Error logs, exception traces (via PostHog), latencies, and diagnostics.
  • Document integrity findings. When we parse an uploaded document we check for hidden text and prompt-injection attempts. We record the categories and counts of what we found — never the extracted content of the finding itself.

C. What we infer about you

Some of what we hold is not something you told us — we derived it. You have the same rights over it as over anything else, and you can ask us for all of it:

  • Structured profile data extracted by AI from your résumé and your answers, and the narrative text written from it.
  • A profile completeness score and onboarding progress.
  • Match scores, per-requirement breakdowns, eligibility and coverage signals for each application and JD analysis, and the AI recommendation produced for the employer.
  • Learned facts — answers from one interview saved so a later one does not re-ask them, each flagged as safe to show publicly or not.
  • A communication-quality rating derived from your conversations. It is used internally and is not shown to employers on your application.
  • Where an employer records it, the outcome of your application — whether you were shortlisted, rejected, or hired — which we use to check whether our scoring is calibrated.
  • For recruiters: a distilled style profile derived from your Job Builder conversations and published job descriptions, used so the agent writes in your voice.

We do not infer, and do not attempt to infer, protected characteristics — race, ethnicity, religion, health, disability, sexual orientation, political opinion, or trade-union membership — from anything you give us.

D. Anonymous sessions

You can start building without an account. We create a temporary anonymous session and attach your work to it. When you sign in, it is linked to your account and your progress carries over. If it is never claimed, we delete or anonymise it (Section 9).

E. Cookies and local storage

We use cookies and browser storage to keep you signed in, remember preferences, and — with your consent — capture product analytics. The cookie settings link in the site footer lets you review and change your choice at any time. Cookies strictly necessary for authentication and session continuity cannot be switched off while you use the Service.


3. Where Your Information Comes From, If Not From You

Most of what we hold came from you. Two exceptions matter enough to state on their own.

A. An employer uploaded your CV

An organisation using Kanvis can upload CVs it already holds — from referrals, its own sourcing, or its inbox — into a role. When that happens we create a sourced record: your name and contact details as parsed from the CV, your professional history as parsed from it, and a score against that role.

If this is you, then as far as this processing is concerned the employer is the controller and Kanvis is its processor. The employer is required by the Recruiter Terms to have obtained your CV lawfully and to tell you it did this, including who they are, why, and where they got it. If they have not told you, that is their failure, not a licence for us to keep the record.

What we do on our side:

  • The record has no account, no login, and no public page. It cannot be published and does not appear anywhere on the public internet. Only the organisation that uploaded it can see it.
  • You can have it deleted. Email privacy@kanvis.me naming the organisation or role. You do not need an account, you do not have to prove anything beyond identifying the record, and you do not have to give a reason. We will delete the record and the stored file and tell the organisation we did.
  • If you later apply to that role yourself, the sourced record is retired and replaced by your real application.

B. Someone else mentioned you

A candidate's profile can name a recommender, a colleague, or a referee. We hold that information as part of the candidate's profile. If you appear in someone's profile and want to be removed, write to privacy@kanvis.me.


Where the GDPR, the UK GDPR, or a similar law applies, we must have a legal basis for each purpose. This table is that list. "Legitimate interests" always means we have weighed our interest against your rights and concluded ours does not override them; you can ask us for the assessment, and you can object (Section 10).

PurposeWhat it involvesLegal basis
Account and authenticationCreating your account, signing you in, linking an anonymous sessionPerformance of a contract
Building your profileParsing your résumé, running the Build agent, writing Talent Graph entries, keeping the chat ledger as the audit trailPerformance of a contract
Publishing your profileServing kanvis.me/<username> publicly, allowing search-engine indexing, featuring published profiles, running the AI TwinPerformance of a contract (this is the Service you signed up for), with the "hide from search" control in Section 10
Candidate toolsJD Mentor analyses, STAR résumés, outreach and cover-letter drafts, the workspace conciergePerformance of a contract
Applying for a jobRunning the AI interview, freezing snapshots, scoring, and disclosing the application to the employerPerformance of a contract (with you); the employer's own basis is described in Section 5
Reusing what you already told usSaving answers as learned facts so later interviews do not re-ask themPerformance of a contract; you can have any fact removed
Service emailsVerification codes, application status, security notices, policy changesPerformance of a contract / legal obligation
Product updates and tipsOptional emails about new featuresConsent, or legitimate interests where permitted, always with an unsubscribe
Analytics and product measurementUnderstanding which features are used and where people get stuckConsent for non-essential cookies and similar technologies; legitimate interests for server-side measurement
Security, abuse, and integrityRate limiting, bot suppression, detecting scraping and prompt-injection, investigating incidentsLegitimate interests (protecting the Service and its users) / legal obligation
Reliability and quality of our AIReviewing outputs for errors, tuning prompts, detecting regressions in scoring, debugging failed runsLegitimate interests — you can object and we will stop, without losing access
Aggregated insightStatistics about hiring, skills, and labour markets that do not identify anyoneLegitimate interests
Legal claims and complianceResponding to legal requests, defending claims, meeting statutory dutiesLegal obligation / legitimate interests
Corporate transactionsDue diligence and transfer in a merger, acquisition, or sale of assetsLegitimate interests, with notice to you before your data becomes subject to a different policy

We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We do not use it for advertising at all.

We do not use your content to train general-purpose AI models, and our AI providers are contractually barred from training their models on what we send them. Where we improve our own systems, we do so by measuring and tuning as described above — and that is the row you can object to.


5. Automated Decision-Making and AI

This is the section that matters most, so it is written plainly.

A. You are interviewed and scored by software

When you apply to a role on Kanvis:

  1. A deterministic planner — ordinary code, not a language model — chooses the questions. It picks them from the employer's requirements, their custom questions, their private screening criteria (translated into neutral topics; you never see the raw criteria, and neither does the agent that talks to you), and gaps in your profile.
  2. A language model chooses only the wording of each question and follow-up. It has no tools, cannot write to your record, and does not decide what to ask next.
  3. At submission your profile, the job, the organisation, your transcript, and the rubric are frozen. They are never re-derived. Editing your profile later does not change an application you already sent.
  4. Your application is scored against the role's rubric. The arithmetic is deterministic. Language models read evidence and emit labels and booleans; they never assign the numbers. The same inputs give the same score every time — which is what makes a score explainable after the fact.
  5. An AI recommendation of Shortlist, Backup, or Reject is produced for the employer's pool, alongside a plain-word confidence label.

B. A human decides

Kanvis does not shortlist, reject, or hire anyone. The recommendation is advice. Every action with consequence — a stage change, an interview invitation, a rejection email — is taken by a person at the employer.

Under the Recruiter Terms, employers must ensure a competent person actually reviews each case, must not configure or automate the Service to reject applicants without human review, and must provide human review and an explanation when asked. Those obligations are contractual and we enforce them: we can suspend or terminate a workspace that breaches them.

C. Your rights over it

Where the GDPR, the UK GDPR, or a comparable law applies, you have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you — and rejection from a job is exactly the kind of decision that regime is about. Where such a decision is made, you have the right to obtain human intervention, to express your point of view, to contest the decision, and to receive meaningful information about the logic involved and the significance and envisaged consequences.

How to use those rights:

  • Ask the employer first — they are the decision-maker and only they can reconsider their decision. You do not need to know their process; asking is enough.
  • Ask us too, if you want to understand the score. Write to privacy@kanvis.me naming the role. We will tell you the requirements you were scored against, how each was assessed, what evidence was used, what your breakdown was, and what the recommendation was — in plain language. We will not disclose the employer's private screening criteria verbatim, or our model weights and prompts, but we will not hide behind them either: if we cannot explain a score to you in terms you can act on, that is a defect in the product.
  • Tell us if you think a human was not involved. If you believe a decision about you was made without meaningful human review, tell us at privacy@kanvis.me. We will investigate it as a breach of the Recruiter Terms.

C2. Software also decides which jobs you are shown

Scoring is not the only automated judgement we make about you, and the other one happens before you have done anything at all.

We rank the job pool against your profile. From your stated preferences and your Talent Graph we build a profile of what you are looking for, including a numeric representation used to find similar roles. Every posting is then filtered and scored against it, and what reaches your board is the result. The arithmetic is deterministic and the same inputs give the same board.

Filtering means some roles are absent, not merely low. A role you are not eligible for — because of where it can be done, or the seniority band, or the function — is removed rather than ranked last. That is the point of the feature, and it is also the risk in it: a job filtered out is one you never learn existed, so a mistake here is invisible from your side.

Some of the inputs to that filter are themselves AI-generated. For roles we collected from public boards, a language model reads the posting and labels who is eligible to apply. It must quote the posting's own words as evidence, and a label it cannot evidence is downgraded to "unknown" rather than guessed. It can still be wrong.

Nothing here is a decision about you by an employer. No employer sees this ranking, no one is rejected by it, and it creates no record with anyone. It decides what we show you.

Your controls. Edit your preferences at any time and the board is rebuilt. Search directly for anything, including roles the filter would not have surfaced. If you think the board is wrong about you, write to privacy@kanvis.me — under Section 10 you may object to this profiling, and we will tell you why a particular role was or was not shown to you.

Paid placement. Employers may pay to have a role prioritised. This only ever reorders roles you were already eligible for and already matched to — it can move a relevant role up, and it can never insert an irrelevant one or push a better match out of your board.

D. The limits of the score, said out loud

A match score is a structured reading of a job description against a profile. It is not a validated predictor of job performance, not a psychometric assessment, and not a measure of your worth. It can be wrong. It can under-read an unconventional career. It reads what is written down, so it favours people whose experience is easy to write down. We say this to employers too.

E. Where AI is used elsewhere

  • Building your profile. An agent writes Talent Graph entries from your résumé and answers. Everything it writes is linked to the message that produced it, and you can edit or delete any of it.
  • The AI Twin on your public profile. Read-only, grounded in your published profile, with no ability to modify anything. Visitors are told it is AI.
  • JD Mentor, STAR Resume, Share, Cover Letter. Generated on your request from your own data.
  • Recruiter-side agents. The Job Builder, Decision Board, Shortlist QA, and the per-application assistant. Text you wrote that reaches any of these is marked as evidence rather than instruction before it enters a prompt, so that neither you nor a third party can use it to steer a recruiter's tools.
  • Draft answers to an employer's questions. Where you have already told us something in your profile or earlier in the interview, we may pre-write an answer to one of an employer's questions in the first person, so you are not asked the same thing twice. A drafted answer is a suggestion in a box you can edit, and it is not a claim you have made until you send it. It is shown to you on the review screen before anything leaves Kanvis, marked as drafted; pressing Send adopts it as your own words. Read them. If a drafted answer is not true of you, change it or clear it. We deliberately do not feed our own drafts back into your score — being scored on a sentence you never wrote would be indefensible — but an employer receives what you signed off on, and we cannot tell them which sentences you read carefully.

AI output can be wrong. Language models fabricate. Review anything generated about you before you rely on it, and tell us when it is wrong.

F. What we do not do

We do not perform facial analysis, emotion inference, gait or biometric analysis, or personality inference from your appearance or your voice. The application interview is text only — there is no video and no audio in it at all.

The one place audio exists is the microphone button in the candidate chat, which you choose to use. That recording is transcribed to text on our own servers and deleted as soon as the transcription finishes — it is never stored, never sent to a language model, never analysed for tone, accent, confidence, or any other characteristic, and never reaches an employer.

We do not infer protected characteristics from anything, and employers are prohibited from screening on them.


6. Who We Share Information With

We do not sell your personal data. We disclose it in these circumstances and no others.

A. Your published profile — the public

Once your profile is live at kanvis.me/<username> it is readable by anyone on the internet, may be indexed by search engines, and may be cached or archived by third parties beyond our control. The AI Twin is reachable at that URL and answers from your published profile. See Section 10 for the "hide from search" control.

B. Employers you applied to

When you submit an application, the employer receives your frozen profile snapshot, your interview transcript and answers, your score and breakdown, and the AI recommendation. They can add private notes and pipeline state. They keep that record under their own retention policy, and it survives even if you later delete your Kanvis account — we can remove our copy, not theirs.

B2. Employers we apply to on your behalf

Some of the roles on Kanvis are not posted by our customers. We collect them from public job boards so you can search one place instead of ten. Applying to one of those works differently from applying to a Kanvis customer, and the difference matters to your privacy.

The employer is a stranger to us. They have no contract with Kanvis, no Recruiter Terms, and no data-processing agreement. Once your application reaches them they are an independent controller of it, and what they do with it is governed by their own privacy notice, not ours. We cannot delete it, retrieve it, or tell you what became of it.

We lodge it for you. Rather than send you off to fill in the same details again, we complete the employer's own application form using what you signed off on. That may be done by a person on our team or by software acting automatically. Section 5 of the Terms of Use sets out exactly what you authorise when you press Send.

What we send. Your answers to that employer's questions, your name and contact details, your profile, your résumé, a condensed record of your interview, and any files their form required — including, where their form asks for one, a photograph. Where you answered one of the equal-opportunity questions described in Section 10(A), that answer goes too. We do not send our own commentary, our internal notes, or anything about your other applications.

Replies may come to us first. So that an interview invitation does not vanish into an inbox we cannot see and a pipeline cannot go dark exactly when it becomes interesting, we may put a Kanvis-operated address on the employer's form in place of yours, and receive their replies on your behalf. When we do:

  • We store the reply so we can pass it on to you.
  • We read it only to route and support it. We do not use employer correspondence to train anything or to build a profile of you.
  • Your real address is kept with your application either way, and is given to the employer if their form requires it.
  • You can tell us to stop and we will use your own address instead.

Withdrawal has a deadline that we do not control. You can withdraw an application at any time before it is lodged, and it will not be sent. Once it has been sent, we cannot un-send it — you would need to contact the employer directly, and we will help you do that.

C. The organisation that imported your CV

If an employer imported your CV (Section 3(A)), only that organisation sees the sourced record.

D. Service providers (sub-processors)

ProviderWhat it doesWhere
Google Cloud PlatformApplication hosting (Cloud Run), database (Cloud SQL), file storage, background job queuesUnited States (us-central1)
Firebase Authentication (Google)Sign-in, anonymous sessions, email-code verificationUnited States
Google Gemini APILanguage model inference: parsing, question wording, evidence labelling, narratives, drafts, Twin answersUnited States
LlamaParse (LlamaIndex)Converting PDF/DOCX uploads into structured textUnited States
VercelFrontend hosting and content deliveryUnited States and a global edge network
ResendTransactional email and employer-approved candidate emailUnited States
PostHogProduct analytics and error captureUnited States
WorkableSource of publicly posted jobs we collect, and the destination when we lodge an application to one of them on your behalfUnited States / European Union
Our application-lodging serviceKanvis-operated software that completes an employer's own application form with what you signed off onUnited States (us-central1)
SpacemailThe mailbox that receives employer replies where we put a Kanvis address on an application (Section 6(B2))European Union

Each is bound by contract to process data only on our instructions, to keep it confidential, and to secure it. None is permitted to use your content to train its own models. Google Gemini is currently our sole production model provider; the platform can be configured to use other providers, and we will update this table before that changes.

E. Other disclosures

  • Legal. Where required by law, regulation, legal process, or a lawful government request. We will tell you unless we are prohibited from doing so, and we will resist requests we consider unlawful or overbroad.
  • Protection of rights. To protect the rights, safety, and property of Kanvis, our users, or the public — including in response to prompt-injection attacks, scraping, or abuse.
  • Corporate transactions. In a merger, acquisition, reorganisation, or sale of assets. We will give notice before your data becomes subject to a different privacy policy.
  • Aggregated and de-identified data. We may publish or share statistics that cannot reasonably be used to identify you, and we will not attempt to re-identify them.

7. International Transfers

Kanvis operates from infrastructure in the United States — Google Cloud region us-central1, plus Vercel's hosting and edge network. Your data is transferred to, stored in, and processed in the United States, and in any other country where a provider in Section 6(D) operates.

For the EEA, the UK, and Switzerland. Where we transfer personal data out of your region to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, supplemented for the UK by the UK International Data Transfer Addendum and read for Switzerland against the Swiss FADP. We do not rely on the EU–US Data Privacy Framework; we are not certified under it.

We have assessed the risk of government access to data held in the United States and apply supplementary measures — encryption in transit and at rest, access control, minimisation, and a policy of challenging overbroad demands. You can request a copy of that assessment, and the completed clauses, at privacy@kanvis.me.

For Pakistan, the UAE, and Saudi Arabia. These jurisdictions restrict cross-border transfers, and none of them recognises the Standard Contractual Clauses as such. We host all data in the United States and do not offer in-country hosting anywhere.

By creating an account and uploading your data, you consent to it being transferred to and processed in the United States by Kanvis and the providers listed in Section 6(D). That consent is the mechanism we rely on in these regions, alongside the necessity of the transfer to provide the Service you asked for. You can withdraw it by closing your account. If your local law requires more than consent — a registration, a local representative, in-country storage — write to privacy@kanvis.me and we will tell you honestly whether we can meet it rather than claim we already have.


8. Data Retention

WhatHow long
Account and Talent Graph profileWhile your account is open. Deleted within 30 days of a deletion request, subject to the exceptions below
Chat ledgerWhile your account is open — it is the audit trail behind every entry on your profile. Deleted with your account
Published profile pageUntil you delete your account or ask us to take it down. Search-engine caches and third-party archives are outside our control
Applications you submittedHeld by us for the employer while their workspace is active. Their retention policy governs, not ours. On the end of their contract, deleted or returned within the windows in the DPA
Imported CVs and sourced recordsUntil the employer deletes them, the person asks us to, the person claims the record by applying, or the employer's retention purge removes them
JD Mentor analyses, résumés, draftsWhile your account is open; individually deletable in-product
Profile views and referral recordsRetained in coarse, pseudonymised form for your dashboard statistics
Anonymous sessions never claimedKept while they may still be claimed, and deleted on request. We are building an automatic sweep and will state the period here once it runs
Security and application logsA limited period sufficient for security investigation and debugging
BackupsCopies persist in routine automated database backups for a limited period — currently no more than 30 days — after which they are overwritten. Data deleted from live systems is not restored into them
Answers kept for reuse, and files an employer's form requiredWhile your account is open, so a later application can reuse them. Individually deletable — ask us and we will remove any of them
Equal-opportunity and identity answersWhile your account is open. They do not expire on their own, because being re-asked for a national ID number every time is worse, not better. Deleted on request, and deleted with your account
Applications lodged with an employer we do not contract withOur copy follows the row above. Theirs is outside our control entirely — no contract, no DPA, no deletion route through us
Employer replies received at a Kanvis addressKept while your application is live so we can pass them to you, and deleted with your account
Suppression records (addresses never to email again)Kept after account deletion, in one-way hashed form only. This is the one thing we deliberately do not erase: forgetting that you asked us never to email you is how you get emailed again
Legal holdsWhere we must keep something to comply with law or to establish, exercise, or defend a legal claim, we keep only that, only for as long as needed

Trained models. We do not train models on your content, so there is no "your data is inside a model" problem to disclose. If that ever changes, we will say so here first and give you a way to object beforehand.


9. How to Exercise Your Rights

Write to privacy@kanvis.me. There is no form and no fee. We will acknowledge promptly and respond within 30 days, extending only where the law allows and telling you if we do. We will ask for enough information to be confident you are who you say you are — no more.

We do not currently offer a self-serve "delete my account" button or a one-click export; those requests are handled by a person. That is honest rather than ideal, and it does not reduce your rights or lengthen the deadline.

You can also do a great deal in-product without asking us: edit or delete any profile entry, delete a résumé version, a draft, or a chat thread, change your username, and switch on "Hide from search" on the profile settings page (which removes your profile from search, the sitemap, and featured surfaces, and asks search engines not to index it — the direct link keeps working).

If you are unhappy with how we handled a request, tell us and we will escalate it internally. You can also complain to your data protection authority (Section 10).


10. Your Rights by Region

A. EEA, United Kingdom, and Switzerland

You have the right to:

  • Access the personal data we hold about you, and a copy of it.
  • Rectify inaccurate or incomplete data. Most profile data is directly editable in-product.
  • Erase your data ("right to be forgotten"), subject to the limits in Section 8.
  • Restrict processing while a dispute about accuracy or lawfulness is resolved.
  • Portability — receive data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
  • Object to processing based on legitimate interests, including profiling. Where you object to the "reliability and quality of our AI" purpose in Section 4, we will stop, and you keep full access to the Service. Where you object to other legitimate-interests processing, we will stop unless we can show compelling legitimate grounds that override your rights.
  • Withdraw consent at any time, where consent is the basis. Withdrawal does not affect processing already carried out.
  • Not be subject to solely automated decisions with legal or similarly significant effects — see Section 5(C), which is the operative part for hiring.
  • Complain to a supervisory authority in the country where you live, work, or where the issue arose. In the UK, that is the Information Commissioner's Office.

Employer-controlled data. For your application to a specific role, the employer is the controller. Send them your request; we will help and will forward anything sent to us.

Special categories. We never ask for special-category data for our own purposes, and you should not put it in your profile, your CV, or your interview answers — we do not want it and nothing we build uses it.

There is one exception, and it exists only because an employer asked. Some employers' own application forms include equal-opportunity or compliance questions — disability status, ethnicity, veteran status, gender, date of birth, or a national identity number. When you choose to answer one of those in order to complete an application, we store the answer so you do not have to type it again, and we pass it to that employer with your application. That is the whole of it:

  • You are always asked, never inferred. We never derive any of these from your name, your photograph, your CV, your university, or your phone number.
  • You may decline. A declined question is sent as no answer. It is never converted into a "no" on your behalf — answering "no" to "are you a protected veteran?" for someone who declined to say is a false statement made in their name, and we do not make it. We also do not forward the sentence in which you declined.
  • They are walled off inside Kanvis. They are excluded from your public profile, from the snapshot any employer on Kanvis can browse, from your score and from every AI prompt we run. No model we operate ever reads them, and no hiring decision on Kanvis is computed from them.
  • The legal basis is your explicit consent (GDPR Art. 9(2)(a)) given by answering the question and confirming it on the review screen before you send. You can withdraw it: ask us and we will delete the stored values, and you will simply be asked again next time an employer's form requires one.

If you have already included something you would rather we did not hold, edit it out or ask us.

Representatives. We do not currently have an establishment in the EEA or the UK. If we appoint an Article 27 representative, we will name them here.

B. California

If you are a California resident, you have the right to know what personal information we collect, use, disclose, and — if we did — sell or share; to access it; to correct it; to delete it; to limit the use of sensitive personal information; to opt out of sale or sharing; and not to be discriminated against for exercising any of them. California's protections apply to job applicants and employees, not only consumers.

We do not sell personal information and we do not share it for cross-context behavioural advertising — there is nothing to opt out of, and we will say so plainly if that ever changes. The categories we collect, the purposes, and the recipients are in Sections 2, 4, and 6; the retention periods are in Section 8. You may use an authorised agent, and we will verify their authority.

Where an employer uses Kanvis to screen you, the employer is the business and Kanvis is its service provider; direct requests about your application to them.

C. Other United States states

Where a state privacy law gives you rights of access, correction, deletion, portability, opt-out of targeted advertising, sale, or profiling in furtherance of decisions that produce legal or similarly significant effects, and an appeal if we refuse a request, those rights are available to you on the same terms. Write to privacy@kanvis.me. We will tell you the outcome of an appeal in writing with reasons.

D. Pakistan

Pakistan does not yet have a comprehensive data protection statute in force, and no national data protection authority has been established. We are not going to describe rights under a law that has not passed. Instead, we apply the standards in this policy to everyone regardless of where they live — a stated purpose and basis for every processing activity, access, correction, deletion, an explanation of automated decisions, notice of who receives your data, and a route to complain — and you can exercise all of them at privacy@kanvis.me.

Two things to be clear about:

  • Your data is stored and processed in the United States (Section 7). Pakistan's draft legislation would restrict some transfers and, for a category it calls "critical personal data," would require local hosting. We do not host in Pakistan. If a Pakistani law or regulator requires something we cannot provide — localisation, local registration, a local office — we will say so plainly rather than claim a compliance we do not have.
  • By using the Service you consent to that transfer. If you would rather not, do not upload your data; we would rather you knew than found out later.

E. United Arab Emirates

Where the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies to you, it gives you rights of access — including information about automated decisions taken about you — portability, correction, erasure, restriction, and a right to stop processing for direct marketing.

It also gives you the right to object to a decision based on automated processing that produces legal consequences for you. That right is the one this product most obviously engages, and Section 5 is written to serve it: the interview and score are automated, the recommendation is automated, and the hiring decision is taken by a person at the employer. To object, or to ask for human review, contact the employer and — if you want the score explained — write to privacy@kanvis.me.

Your data is processed outside the UAE, in the United States (Section 7). Using the Service constitutes your consent to that transfer.

The DIFC and ADGM operate their own data protection regimes for entities established or processing within those free zones. Kanvis has no DIFC or ADGM establishment. If your employer does, their own obligations under those regimes may apply to their use of the Service, and we will provide system documentation on request.

F. Saudi Arabia

Where the Saudi Personal Data Protection Law (Royal Decree M/19, as amended) applies to you, you have rights of access, correction, deletion, and to be informed about how your data is processed, and you may complain to SDAIA.

Saudi law is consent-first. For candidates in the Kingdom, your consent is the basis on which we process your personal data to provide the Service, in addition to any contractual necessity, and you may withdraw it at any time by closing your account or writing to privacy@kanvis.me. Withdrawal does not affect processing already carried out.

Transfers. Your data is transferred to and processed in the United States (Section 7). We limit what we transfer to what is needed for the purpose, and we do not transfer personal data in a way we believe would compromise the national security or vital interests of the Kingdom. If your organisation requires a transfer risk assessment or a specific safeguard for a Saudi transfer, write to privacy@kanvis.me.

Breach. Where the Saudi PDPL applies, we will notify SDAIA within 72 hours of becoming aware of a personal data breach and will notify affected individuals without undue delay.

G. Everywhere else

If you are somewhere not named above and your local law gives you rights this policy does not describe, exercise them anyway at privacy@kanvis.me. We would rather grant a right we did not have to than argue about jurisdiction.


11. Security

We protect your information with measures appropriate to the risk, including:

  • Encryption in transit (TLS) and at rest.
  • Token-based authentication on every authenticated request, with cross-account authorisation enforced at the database-query level — a query can only ever return your own data, and a recruiter query can only ever return their own organisation's.
  • Strict separation of principals: a sign-in identity is either a candidate or a recruiter seat, never both.
  • Internal-only endpoints between our services protected by an internal key, and background workers protected by signed identity tokens.
  • Authentication tokens are never placed into an AI prompt. They travel in the request body and are held in protected context; the model never sees your credentials.
  • Prompt-injection defence: text a person wrote is marked as evidence, never instruction, before it reaches a recruiter-facing agent, and hidden-text findings in uploaded documents are recorded and surfaced.
  • Rate limiting, per-address caps, and connection pooling against scraping and resource exhaustion.
  • Logging, monitoring, and exception capture, with personal data kept out of routine logs.
  • Signed, short-lived URLs for every stored file, rather than public links.

Kanvis is a small company and does not currently hold ISO 27001 or SOC 2 certification. No system is completely secure. If a breach affects your personal data, we will notify you and the relevant authorities as the law requires.


12. Children

The Service is not for anyone under 16. We do not knowingly collect their personal data, and we delete it if we learn we have. If you believe a minor has given us information, write to privacy@kanvis.me.


13. Changes to This Policy

We may update this policy. When we make material changes we will update the Effective Date and give notice through the Service or by email at least 14 days before they take effect, unless a change must take effect sooner to comply with law. A change of sub-processor within the same category is not, by itself, a material change — but we will still update Section 6(D), and organisations receive advance notice under the DPA.


14. Contact Us

Privacy, data, and rights requests: privacy@kanvis.me Legal and contractual: legal@kanvis.me

We do not currently have a statutory Data Protection Officer. Requests to the address above reach a person who can act on them.