GDPR, EU AI Act Annex III point 4a and EU hosting
No automatic rejection. The decision is human.
rekruto assesses candidates — two regimes apply at once, and neither is optional. GDPR governs every candidate record; the AI Act governs the assessment engine, classified as high-risk. Both sets of duties are built into the product and split between us (provider) and the hiring company (deployer).
Who owns what
Compliance is shared; the table states which side owns each duty, so a company's DPO and our product team read from one page.
| Duty | rekruto (provider / processor) | Hiring company (deployer / controller) |
|---|---|---|
| Candidate disclosure | Supplies wording, components and the notice | Publishes the notice, owns accountability |
| DPIA | Provides the template and technical documentation (art. 11) | Performs, signs off and keeps it current |
| EU database registration (art. 27) | Registers the system before market placement | Verifies the entry before go-live |
| Bias assurance | Runs the suite, blocks failing versions, quarterly report | Reviews the report and acts on patterns |
| Retention and erasure | Implements anchors, deletion jobs, crypto-shredding | Sets the anchors, answers erasure requests |
| Human oversight (art. 14) | Builds the oversight UI, decision records and audit log | Reviews candidates, records reasons, informs |
| Security | Implements art. 32 measures and the evidence pack | Approves the annex, performs its own review |
What the product does — and never does
Guaranteed in the product
- The score stays hidden until the candidate file is opened.
- The recruiter can reorder, discount a score entirely and record the reason.
- Rejection letters are drafts — reviewed, edited and sent by the recruiter.
- Every AI-authored email and portal message identifies itself (art. 50(1)).
- An immutable audit log covers reads, exports, score views and shares.
- Model versions without a passing bias suite are blocked before rollout.
rekruto never
- Sends a rejection automatically — at any tier.
- Degrades the loop when a model is down: the fallback scorer is deterministic.
- Sends candidate data to models that train on it.
- Puts national ID numbers in a corpus: the pattern is caught at upload.
- Negotiates with candidates about scores or rounds — the portal replies neutrally.
- Re-opens a concluded application on its own.
Candidate rights
The rights are product features on all three tiers — not an Enterprise add-on. That is a consequence of candidates having rights regardless of your subscription.
Human review
The candidate can request a fresh human-only review. The recruiter is prompted to re-read the file while the score panel stays hidden.
Access and insight
The candidate can see which documents were read, which questions the AI asked, and which evidence the ranking rests on.
Edit
Errors in candidate details can be corrected; the corrected version is what future assessments read.
Erasure
Erasure happens by crypto-shredding: content is encrypted per application, and erasure destroys the key. Restored backups cannot resurrect the deleted content.
Export and portability
The candidate's data can be exported in a structured, machine-readable format.
The right to say no
The candidate can decline AI assessment. The application is then handled only by the recruiter, with no advantage or disadvantage.
Frequently asked questions
Is rekruto a high-risk system under the AI Act?
Yes — and the documentation says so. Systems for "recruitment or selection of natural persons" are high-risk under Annex III, point 4a. Because the engine profiles candidates, the art. 6(3) exception can never be used. The high-risk duties have applied since 2 August 2026. rekruto is the provider; the hiring company is the deployer.
Does the AI make the decision?
No. The AI proposes, a human confirms — and that is a hard product rule, not a policy. GDPR art. 22 covers decisions based solely on automated processing; rekruto's human-in-the-loop design sits outside art. 22(1). The art. 13(2)(f) transparency duty and the AI Act accuracy duties are not removed by that.
Where does the data live, and who can see it?
EU hosting. Candidate content is encrypted per application, and contact fields are column-encrypted. Access requires a role, and every read, export and score view writes to an audit log retained 12 months and anonymised on candidate erasure.
Is candidate data used to train models?
No. Models run through a gateway of EU-resident, no-training providers. The candidate contact block (name, address, email, phone, photo, national identifiers) is stripped before text enters a corpus — and a chunk whose text matches contact-block patterns is refused at write time rather than redacted after the fact.
What about bias?
A bias suite runs on every model version: synthetic candidate pairs test whether results systematically deviate on protected characteristics. A failing version is blocked before rollout, and the results ship quarterly. The suite is a regression tripwire — not proof of non-discrimination in the real world, and thresholds are a policy choice.
This page is written by the product team and states intended controls and the reasoning behind them. It is not legal advice — every marker must be resolved by qualified counsel covering EU law and Danish employment practice before the feature it touches goes live.
See the loop on your own position
Create the position, seed the candidates and follow the question rounds from the first email.