Policies

AI Transparency Notice

How AI features in Hireall work, what they do and do not decide, the human oversight in place and how to raise a concern.

Last updated 23 September 2026
On this page
  1. What AI does in Hireall
  2. What AI does not do
  3. How people stay in control
  4. The data and models behind the features
  5. Fairness, testing and limitations
  6. Your rights as a candidate
  7. Responsibilities of employers using AI features
  8. Regulatory context
  9. Changes and contact

Hireall Technology ("Hireall") builds AI features into its applicant tracking platform to help recruiters read, organise and search applications. This notice explains, for employers and candidates alike, what those features do, what they deliberately do not do, what data they use, how people stay in control and where the applicable rules come from. It supplements our Privacy Policy, Candidate Privacy Notice and Terms of Service.

In one sentence: Hireall's AI suggests; the employer decides. Every AI output is advisory, and our Terms of Service require employers to keep a trained person in the loop and prohibit rejecting a candidate, or taking any other decision that materially affects a candidate, solely on an AI output. Employers can let automation rules that use an AI score move candidates between stages on their own; the platform asks a person before such a rule rejects a candidate or makes an offer. Hireall provides the controls for that review but does not itself check each decision; the employer is responsible for it.

01What AI does in Hireall

FeatureWhat it doesWhat it uses
CV parsingTurns an uploaded CV into a structured profile (skills, titles, education, languages) so recruiters do not retype itThe CV file
Match scoreEstimates how closely an application matches the job description and explains the strengths and gaps it found, criterion by criterionThe application material and the job description
Bulk matchingRuns the match score across many applications for one job so recruiters can prioritise their readingEach application and the job description
Talent-pool searchLets recruiters search their own candidate pool in plain language, for example "backend engineers in Berlin with Go"The employer's candidate records and the query
Job-post draftingDrafts or autofills a job description from a few inputs, for the recruiter to editThe recruiter's inputs
Headcount assistantTurns a note a team member typed into a draft position request for that person to check before sending it, and writes a short assessment of a position request (a summary, risks, recommendations and suggested hiring waves) for the people who decide on it. It does not produce the figures it refers to and does not say whether the request should be approvedThe note the team member typed; the fields of the position request (job title, department, location, number of people, employment type, reason, budget range, target start date and the business justification); and figures calculated on our servers from the employer's own records, such as the median time to hire, the number of applications per hire, the employer's own salary band for the role and how much of the department's hiring plan is already used. Those figures are aggregates: no individual candidate's data is sent. Free text a team member wrote is sent as written; the field naming the person being replaced, and the names of the requester and the approver, are not sent with an assessment
Career compassWrites a development summary for an employee the employer is considering for one of its own roles: what the employee already brings, what the role asks for and suggested next steps. It does not produce the readiness figure and does not say whether the employee should get the roleThe competencies recorded for the employee, the employee's current job title and department, and the target role's title, description and required competencies. The employee's name, contact details and manager's name are not sent
E-mail draftingWrites a draft of a message to a candidate from the purpose, tone and language the recruiter chooses and the notes the recruiter types, or rewrites, shortens, reformulates or translates a message the recruiter has already written. The draft is shown to the recruiter for review and reaches a candidate only if the recruiter puts it into the message and sends itThe notes or draft text the recruiter supplies, the purpose, tone and language chosen, the employer's name and, where the recruiter has selected one of the employer's own jobs, its title. No candidate record is read and no candidate's name, contact details or application material is attached; the placeholders for a candidate's name and the job title are filled in by the platform when the message is sent, not by the model
Document consistency checkLooks at a document a candidate uploaded for a verification item and flags signs of tampering or of an inconsistency with what the candidate stated, so that a person knows to look more closely. It returns a risk flag and a short note; it reaches no conclusion about the candidate, moves no application and rules nobody outThe uploaded file as an image or PDF, the type of the item and the details the candidate entered for it. For a criminal-record or fitness-for-work document the check runs only where the candidate has given the separate explicit consent asked for, and the model's free-text note is not stored for those types

Each action shows its credit cost before it runs. When a recruiter runs an action themselves, they choose whether to run it and which available model to use. When an employer has configured automatic scoring of incoming applications, the system runs that scoring with the settings already chosen for that job or account. If the employer's credits run out, automatic scoring pauses: waiting candidates are kept in a queue and scored in arrival order once credits are available again (a top-up, the monthly allocation or a policy the employer has enabled); nothing about a candidate changes while they wait, and the employer can clear the queue. Employers can turn each feature on or off for their account.

02What AI does not do

  • It does not itself reject any candidate or make an offer to any candidate. An automation rule that uses the AI fit score as a condition can move a candidate to another stage, including the hired stage, and send the message the employer attached to that step, but it asks a person before moving a candidate to the rejected or an offer stage or creating an offer; the control is described below. Other automations the employer configures, which do not use an AI score, can send messages or move applications as the employer has set them up.
  • It does not analyse video-interview recordings, voice, facial expressions or body language. Recordings are made available to the employer's authorised team to review; Hireall does not analyse them with AI.
  • Models are instructed to assess only job-related criteria (skills, experience, education, languages, screening answers and the stated requirements) and not to consider, infer, estimate or mention protected characteristics such as gender, age, race or ethnicity, nationality or origin, citizenship status, religion, disability or health, pregnancy or family status, marital status, sexual orientation, political opinion, trade-union membership, military status or socioeconomic background, or proxies such as names, photos, graduation year, school prestige, address, career gaps or "culture fit". We apply product controls to that effect: we do not send the structured fields for a candidate's name, date of birth, gender or nationality to the model. The same information can still appear in free text such as a CV; the model is instructed to disregard it. Those instructions and controls reduce, but do not eliminate, the possibility of an inaccurate or biased output.
  • Talent-pool search is instructed not to turn a request about gender, age or a similar characteristic into a filter, even if asked, and to apply only job-related criteria and tell the recruiter why. The platform also drops gender and date-of-birth filters if a model still returns them. Other encodings of the same request, for example in free-text keywords, can still appear; that risk is reduced but not eliminated.
  • It does not decide, recommend or score an internal move. Where an employer records its own employees as internal talent, the readiness figure is computed on our servers by comparing the competencies recorded for the employee with those the target role asks for, together with any match score that already exists for them; no model produces that figure, and where neither input exists the Service reports that it cannot measure readiness rather than showing a number. The model writes only the development text, and is instructed not to state whether the employee is suitable, qualified or ready, not to recommend a promotion or an assignment, and not to comment on tenure or on the employee's decision to stay with or leave the employer. The employer chooses whether to share that text with the employee; the readiness figure is for the employer and is not shown to the employee.
  • It does not decide whether a document is genuine and it does not reject anyone. The document consistency check returns a risk flag and a short note for a person to act on: it cannot move an application to another stage, it cannot rule a candidate out, and no automation condition reads it. An employer may not treat the flag on its own as a reason to reject a candidate or to treat a document as false. The check runs on a criminal-record or fitness-for-work document only where the candidate has given the separate explicit consent asked for, and for those types the model's free-text note is never stored.
  • It does not approve, reject or rank a position request, and it does not decide how many people an employer may hire. Whether a request fits the department's hiring plan is worked out on our servers from the plan the employer entered and the requests already approved. Where the employer has switched on automatic approval for a plan line, a request is marked approved in the Service because it fits that plan, never because of an AI output, and the Service does not reject a request automatically. This describes what the Service does with a position request; how an employer decides on that request outside the Service is its own process, which Hireall neither sees nor controls. The figures shown with an assessment (time to hire, applications per hire, the latest date to open the job and the comparison with the employer's own salary band) are calculated from the employer's own records: no model produces them, and no market salary data or external benchmark is used. Any part of the model's text that cites a figure not found in those records is removed before the assessment is shown.
  • It does not look candidates up on the internet or enrich their profiles from external sources.
  • It does not send messages. Where a recruiter has a message to a candidate drafted or rewritten, the result is shown for review and reaches a candidate only once the recruiter puts it into the message and sends it. The model does not choose recipients, does not decide when a message goes out, and does not write a separate version for each candidate: where a draft greets a candidate by name or names the role, the platform fills those placeholders in as the message is sent. A message that an employer's automation sends on its own uses text the employer saved beforehand, which the employer is responsible for reviewing.
  • It does not train on candidate or customer data. Neither Hireall nor its model providers use data submitted through these features to train models.
  • It runs only when a recruiter asks for it, or when an employer has configured automatic scoring of incoming applications or an automation rule that needs a score for a candidate who does not have one yet; even then the result is a score, not a decision to reject, make an offer or hire.

03How people stay in control

  • Explanations, not verdicts. Scores come with the explanation the model returned — the reasoning, matched requirements and gaps it reported — so a reviewer can check that account against the application. That explanation is the model's own account, not independently verified evidence.
  • Override and ignore. Recruiters can disregard any score, re-run it with a different model, or move a candidate regardless of the score. Nothing in the pipeline is gated on an AI score unless the employer sets up an automation rule that uses one. Such a rule may move a candidate to another stage, including when the score is low, but it does not move a candidate to the rejected stage without a member of the hiring team confirming it, and employers must not use another stage in its place.
  • What automation may do with a score. An employer can set up automation rules that use the AI fit score as a condition. By default such a rule runs on its own: it can move a candidate to another stage, including the hired stage, send the e-mail the employer attached to that step, add a note or request a score for a candidate who does not have one. The employer can instead choose, for the whole account or for one job, that every step is first suggested to the hiring team, or that each stage's rule runs on its own only after a super admin has approved it; the platform records who approved it, when and for which version of the rule, and the approval lapses if the rule is changed. Whatever the employer has chosen, such a rule never takes these steps on its own: moving a candidate to the rejected stage, moving a candidate to an offer stage and creating an offer are presented to a person for that candidate, and a rejection is confirmed together with the reasons recorded for it. The same applies to a rejection or offer that follows a placement which AI suggested or made. A rule that uses gender, nationality, military-service or smoking status as a condition may add a note or calculate a score on its own, but every step that would move the candidate, send a message or make an offer waits for a person. Before such a rule acts on its own, the platform also checks the basis of the score itself: where it rests on thin data about the candidate, contradicts the hiring team's own scorecard or sits on the employer's threshold, the step is presented to a person instead of being taken (the employer can switch this check off). Every automatic move is written to the candidate's notes, and every automatic move, suggestion and decision is recorded in the audit log with the score, the rule and the person who decided. The check is based on each stage's role in the process (rejected or offer), not on the name an employer gave it, and applies to every branch of a rule. Employers must not use another stage in place of the rejected stage to turn candidates down by score. This is a technical part of human oversight; it does not replace the employer's own review of each candidate or Hireall's own design and data-protection obligations.
  • Per-feature switches. Administrators enable or disable each AI feature for their organisation.
  • Records. Depending on the feature, a record is kept of the type of operation, whether a user or the system triggered it, the related job or candidate record where there is one, the model used and the time. Administrators can review the audit log and, depending on subscription, export it. Credit-consumption records also show the operation and, where a candidate was involved, the related application. These records help an employer see that an AI feature was used; they do not by themselves provide a complete account of every factor in a hiring decision.
  • Blind hiring. Employers can hide name, photo and gender from evaluators, and hide other evaluators' scores, during assessment.
  • Trained reviewers. We document how each feature works and its limitations on this page, in the product and through the support portal. Our Terms of Service require employers to have a suitably trained person review an output before relying on it for a decision that affects a candidate.

04The data and models behind the features

  • Data used. Only the application material submitted for the specific job, the job description written by the employer and, for talent-pool search, the employer's own candidate records and query. For e-mail drafting, what the recruiter writes in the request or has already written in the message, which recruiters are asked to keep free of personal details. No data from other employers is used.
  • Data used by the headcount assistant. It works on position requests rather than applications. What it uses is listed in the table above: what a team member typed, the fields of the request and aggregate figures from the employer's own records. It is not sent any individual candidate's data.
  • Model providers. Requests are sent through APIs to large-language models from Google (Gemini family) and OpenAI (GPT family). Both providers are bound by API terms that prohibit training on customer data and limit retention. Hireall selects the models offered and shows the model used for each result.
  • Where processing happens. Candidate data is hosted in the EU (Amazon Web Services, Frankfurt). Model providers may process requests in the United States under the transfer mechanisms described in our Data Processing Agreement; only the text needed for the request is sent, and results are stored back in the EU.
  • Retention. Scores and parsed profiles are part of the candidate record; they are deleted or anonymised together with the record, on the employer's instruction or when the record is otherwise deleted. Video-interview recordings follow the retention period of the employer's subscription.

05Fairness, testing and limitations

Language models can be wrong, inconsistent or reflect biases in the material they were trained on. We reduce these risks, but we cannot eliminate them, which is why the features are advisory.

  • Scoring is structured around the requirements stated in the job description (skills, experience, education, languages). The fairness instructions above are part of the model prompt, identifying fields are not sent as structured data, and each score is returned with the explanation the model generated so that reviewers can see what it reported as having been weighed. That explanation is not independently verified evidence.
  • Job-post drafting is instructed to use gender-neutral titles and language and to leave out requirements based on gender, age, marital status, military status, nationality, religion, disability or photographs, and never to ask for salary history.
  • We test the technical controls described on this page, including that an automation using an AI score cannot move a candidate to the rejected or an offer stage or create an offer without a person's confirmation, and that a rule using gender, nationality, military-service or smoking status cannot move a candidate, send a message or make an offer without a person's confirmation. Those tests check that the control mechanism works. They are not tests of model accuracy, of consistency across differently worded job descriptions, or of differences in scores between groups, and we do not treat such evaluations as completed unless they have been carried out and recorded.
  • We review the models offered in the product when providers change them. We do not claim that every model version is re-tested for accuracy or for differences between groups before it is offered.
  • Known limitations: scores depend heavily on the quality of the job description; unusual CV formats can parse imperfectly; performance can vary with the language of the material, the format of the document and the quality of the content; the models do not verify claims made in a CV.

If you believe a feature produced an unfair or inaccurate result, tell the employer or write to privacy@hireall.com. We investigate reports and use them to improve the features.

06Your rights as a candidate

  • Ask the employer whether and how AI features were used in your application. The records described above can help the employer answer; they may not provide a complete explanation of every factor in the decision.
  • Request that a person reviews any assessment that involved AI and explains the decision taken about you.
  • Where EU GDPR Article 22 applies, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
  • Under the UK GDPR as now in force (Articles 22A to 22D), certain solely automated significant decisions are permitted with safeguards, and the prominent rights are to be informed, to contest the decision and to obtain human intervention.
  • Under KVKK Article 11 you may object to a result that arises exclusively from automated analysis and is against you.
  • Hireall's product is designed so that an AI score cannot by itself reject your application or make you an offer. If the employer uses automation, a score may move your application to another stage automatically, including the hired stage; you may ask the employer for a human review at any time. The employer remains responsible for meaningful human review of outputs it relies on. Hireall does not guarantee that no employer using the Service will take a solely automated decision; if you believe one was taken, contact the employer.
  • If you are in a US state or city with rules on automated employment decision tools (for example New York City, Illinois, Colorado or California), then where that employer and that use fall within the law's scope the employer must tell you when such tools are used and, depending on the law, offer an opt-out, an explanation or an appeal.
  • Exercise your other data rights (access, correction, deletion, objection) as described in the Candidate Privacy Notice.

07Responsibilities of employers using AI features

Employers are the controllers of candidate data and, in regulatory terms, the deployers of AI features. These employer duties sit alongside, and do not replace, Hireall's own design and data-protection obligations described above.

Required under the Terms of Service and the Acceptable Use Policy:

  • do not use the Service to make a decision that materially affects a candidate solely through automated processing;
  • ensure that a suitably trained person meaningfully assesses relevant information, has authority to change the result, and reviews an output before relying on it for such a decision — merely approving a score without assessment is not meaningful review;
  • do not use AI features to infer protected characteristics for discriminatory hiring, or to circumvent the fairness safeguards described in this notice.

Where the law that applies to you requires it, and as product recommendations:

  • tell candidates in your privacy notice that AI tools assist the hiring process and how to request human review;
  • if you use automation rules that act on an AI score, say in that notice that an automated score may move an application between stages, make sure a person reviews the candidates such rules do not advance, and do not use a stage or message in place of a rejection;
  • record the human decision you take after review;
  • comply with local rules on automated tools in hiring when your organisation and the use fall within their scope, from the date those rules apply, including New York City Local Law 144 (annual bias audit and candidate notice), the Illinois Human Rights Act provisions on AI in employment decisions (notice to candidates; no discriminatory use, including zip codes as a proxy), Colorado's law on automated decision-making in consequential decisions (including pre-use and adverse-outcome notices from 1 January 2027), the California CCPA regulations on automated decision-making technology (pre-use notice, opt-out and access rights from 1 January 2027) and on risk assessments (for new high-risk processing from 1 January 2026; for processing that began before that date and continues, assessments to be completed by 31 December 2027), and the deployer obligations of the EU Artificial Intelligence Act for employment systems from 2 December 2027; Hireall provides the information on this page, in the DPA and on request to support those obligations;
  • use blind-hiring and sensitive-field settings appropriately for your jurisdiction.

08Regulatory context

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744) classifies AI systems used for recruiting, screening or evaluating candidates as high-risk (Annex III). Its prohibitions, including emotion recognition in the workplace, have applied since 2 February 2025 and its transparency obligations since 2 August 2026; the high-risk requirements for stand-alone Annex III systems (risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness) apply from 2 December 2027. Hireall does not perform emotion recognition or biometric categorisation. The measures described on this page — this notice, the identification of AI features, the fairness instructions and product controls, the records kept for each feature, and the human-oversight controls including the AI-score automation limit — are the transparency and oversight steps we apply today. They are not a representation that Hireall meets every transparency obligation of the Act in full. Hireall is aligning its AI features with the high-risk requirements ahead of 2 December 2027; updates will be published on this page.

In the United Kingdom, Articles 22A to 22D of the UK GDPR (in force since 5 February 2026) govern significant decisions based solely on automated processing. Those articles permit such decisions with safeguards; they do not impose the same default prohibition as EU GDPR Article 22. Hireall's product control on AI scores, and the employer's duty of meaningful human review, are described above. We also follow guidance from the UK Information Commissioner's Office and the European Data Protection Board on AI in recruitment, and the Turkish Personal Data Protection Authority's recommendations on artificial intelligence.

09Changes and contact

We update this notice when we add, change or remove AI features or when the rules change; the date at the top shows the latest revision. Questions and reports: privacy@hireall.com.