Candidate data and responsible AI use
Understand how ProbbAI handles candidate information, uses service providers, and supports human-reviewed hiring decisions.
ProbbAI helps hiring organisations organise candidate evidence, compare it with role requirements, and prepare an AI-assisted hiring debrief.
The hiring organisation normally acts as the data controller and determines why candidate information is processed. ProbbAI normally acts as the data processor and handles that information according to the customer's instructions and applicable agreement.
This page explains how candidate information is handled inside the product. It is product guidance and does not replace the hiring organisation's candidate privacy notice, ProbbAI's formal Privacy Notice, or a Data Processing Agreement.
At a glance
- Candidate information is scoped to the customer organisation.
- ProbbAI creates decision-support reports; it does not make final hiring decisions.
- Customer data is not used to train ProbbAI's internal models or shared, general-purpose AI models.
- Authorised users can delete supported candidate records and associated stored files.
- Interview invitations and shared-report links provide restricted access and should be treated as confidential.
- Automatic customer-configurable retention schedules are not currently available.
Information processed
The information processed depends on the features used by the hiring organisation.
| Category | Examples | Purpose |
|---|---|---|
| Candidate identity | Name, email address, profile details | Identify and manage the candidate record |
| Candidate material | Resume, employment history, skills, qualifications | Compare candidate evidence with role requirements |
| Role context | Job description, responsibilities, skills, seniority | Establish the criteria used in an analysis |
| Interview information | Audio, transcript, answers, consent state, session metadata | Conduct and review an AI voice interview |
| Generated output | Evidence, summaries, scores, concerns, discrepancies, questions | Prepare a hiring-team debrief for human review |
| Account and activity information | Organisation, membership, access and activity records | Operate, secure and administer the service |
Only upload information that is relevant and necessary for the hiring process. Do not intentionally include protected characteristics or unrelated sensitive information in role or candidate material.
How AI is used
ProbbAI uses candidate material and role context to generate a draft assessment, supporting evidence, potential concerns, discrepancies, and follow-up questions. When an AI voice interview is used, relevant interview responses and transcript evidence are also analysed.
ProbbAI does not make a final hiring decision. It creates a report for meaningful human review. AI-generated output may be incomplete or inaccurate, and reviewers must inspect the supporting evidence before taking action.
Model training
ProbbAI's stated product policy is not to use customer candidate data to train internal models. AI services used by ProbbAI must be configured or contracted so that customer data is not used to train shared or general-purpose models. Customers should rely on their applicable agreement for an enforceable commitment.
Candidate information is submitted to an AI service only to provide the analysis, interview, or supporting functionality requested by the customer.
Service providers
ProbbAI uses contracted infrastructure, storage, AI, speech, and email providers to operate the service. The provider and information involved depend on the enabled workflow and production configuration.
| Provider | Purpose | Information potentially processed |
|---|---|---|
| Amazon Web Services | Application hosting, database, backups, and background processing | Accounts, candidate records, reports, transcripts, and operational metadata |
| Cloudflare R2 | Object storage | Uploaded resumes and interview recordings |
| OpenRouter | AI model gateway | Candidate material, role context, transcripts, and generated analysis |
| Model providers selected through OpenRouter | Perform the configured AI operation | Information sent for that specific analysis or interview operation |
| Deepgram | Voice transcription and speech services | Interview audio, transcript content, and session metadata |
| OpenAI | Realtime interview and directly configured AI functionality | Interview content, role context, and relevant candidate evidence |
| Resend | Transactional email delivery | Recipient email address and invitation or account-email content |
The providers used for a particular customer may change as the service evolves. ProbbAI does not currently host a standalone dated subprocessor register. This table is product guidance, not a contractual or complete subprocessor list. Customers should request current authoritative provider information and applicable terms from their ProbbAI representative.
See Service providers and subprocessors for a focused provider summary.
Access and organisation isolation
Authenticated candidate records are scoped to the active customer organisation. Viewer, Member, and Admin roles control what organisation users can read or change.
Before uploading, downloading, deleting, or sharing candidate information, confirm that the correct organisation is selected and that the recipient is authorised.
ProbbAI also uses the following access safeguards:
- object upload and download links are short-lived;
- shared-report links can be revoked by an authorised user;
- interview links are checked against their session status and expiration;
- important organisation activity is recorded for administrative review.
Links, invitations, and exports
Interview invitations and shared-report links grant access to a specific restricted experience. Send them only to the intended recipient, avoid public channels, and revoke or replace a link if it is disclosed unintentionally.
Downloaded resumes and exported PDFs leave the live ProbbAI workspace. The customer is responsible for protecting those copies, limiting onward sharing, and deleting them according to its retention policy.
Retention and deletion
ProbbAI does not currently provide customer-configurable automatic-retention schedules. Candidate information remains available until an authorised customer user deletes the relevant record, the customer account is terminated, or another contractual requirement applies.
When an authorised user deletes a supported candidate record, ProbbAI initiates deletion from active application systems and associated object storage. Some related records may need to be deleted or unlinked separately where the product displays that requirement.
ProbbAI's stated backup-retention period is up to 45 days. Residual copies may remain in protected backups during that period before expiring through the backup lifecycle. Backup copies are maintained for recovery and service-continuity purposes, not for ordinary product access. Customers should rely on their applicable agreement for an enforceable retention commitment.
Deleting a record from ProbbAI does not delete copies that customers or recipients have already downloaded, exported, or copied outside the service.
Candidate requests
Candidates should contact the hiring organisation responsible for their application to request access, correction, deletion, restriction, objection, or information about how their data has been used.
Because the hiring organisation is normally the data controller, it determines how to verify and respond to the request. ProbbAI supports its customer with verified candidate requests where required by the applicable agreement.
If a report contains incorrect candidate information, reviewers should correct the source record where possible and avoid relying on the disputed output until it has been reviewed.
Responsible hiring and accessibility
Do not use a ProbbAI report as the sole basis for a consequential hiring decision.
Reviewers should:
- inspect the source evidence behind generated conclusions;
- correct inaccurate candidate or role information;
- avoid using protected characteristics in hiring decisions;
- consider accessibility needs and reasonable accommodations;
- account for speech-recognition errors, connectivity problems, or interrupted interviews;
- provide an appropriate alternative assessment process when necessary;
- apply independent professional judgement before deciding the next step.
Formal privacy and contractual information
This documentation describes product behaviour. It is not a formal Privacy Notice, Data Processing Agreement, security certification, or complete subprocessor list. ProbbAI does not currently host standalone versions of those documents in this documentation site.
Privacy obligations vary by customer and jurisdiction. Contact the hiring organisation for questions about a specific application or candidate-data request. Contact your ProbbAI representative for applicable contractual privacy, processing, security, and subprocessor terms.