KANDIDATOR - TERMS OF SERVICE
These Terms of Service (“Terms”) govern the access to and use of the Kandidator software-as-a-service recruitment platform (“Service”) available at https://www.kandidator.com, operated and provided by Digihey d.o.o., Vilima Korajca 29, 10000 Zagreb, Croatia, OIB: 28945260733 (“Digihey”, “we”, “us”, or “our”). By creating an account, checking the acceptance box, or accessing the Service, you (“Customer”) agree to these Terms. For enterprise customers, a separate written agreement may override specific clauses of these Terms.
0. DEFINITIONS
“Customer” means a legal entity or an individual acting for purposes related to their trade, business, craft, or profession who subscribes to, accesses, or uses the Service.
“Authorized Users” means employees or contractors authorized by the Customer to use the Service.
“Candidate Data” means personal data relating to job candidates uploaded or processed by the Customer.
“Customer Data” means all data submitted to the Service by or on behalf of the Customer.
“Subscription Plan” means the selected pricing plan.
“AI Features” means artificial intelligence–powered functionalities used solely in an assistive capacity.
1. NATURE OF SERVICE
Kandidator is a cloud-based SaaS platform for recruitment workflows, candidate management, AI-assisted selection, and database search. The Service is provided solely as a tool; Digihey does not perform hiring or recruitment on behalf of Customers. Digihey does not determine the legal basis, lawfulness, or compliance of Customer’s recruitment activities. The Customer remains solely responsible for any HR/legal obligations arising from use of the Service, including the explicit responsibility for preventing employment discrimination and bias when using the platform.
2. ACCEPTANCE & ACCOUNT CREATION
2.1 Acceptance occurs by checkbox confirmation, by signing an enterprise agreement, or by continued use of the Service after these Terms are made available.
2.2 The Customer represents that they have authority to enter into binding agreements.
2.3 The Service is intended solely for business or professional purposes and is not intended for personal or consumer use.
3. SUBSCRIPTION, PRICING & BILLING
3.1 The Service is provided on a subscription basis (monthly/annual).
3.2 Fees are payable in advance, non-refundable (except where required by law).
3.3 Subscriptions renew automatically unless cancelled before renewal date.
3.4 Digihey may adjust pricing with prior notice; enterprise agreements may define custom pricing.
3.5 Value Added Tax (VAT) or similar taxes are charged where applicable.
4. USE OF SERVICE
Customer responsibilities include:
- providing lawful access to data processed in the platform;
- obtaining candidate consent or other valid legal basis;
- configuring access roles and user permissions;
- ensuring data accuracy and legality of communications, including strict compliance with the CAN-SPAM Act (USA), PECR (UK), and applicable EU ePrivacy regulations regarding outreach. The Customer is solely responsible for practices regarding outreach, selection decisions, and communication with candidates.
5. AI FEATURES
5.1 AI features are assistive only and cannot make or trigger automated hiring decisions.
5.2 AI output may contain errors; Customer must validate content before use.
5.3 AI features use third-party AI processing services. Customer Data is not used to train AI models.
5.4 Customer may not rely on AI output as legal, compliance, or factual advice.
5.5 Customer must ensure mandatory human oversight (human-in-the-loop) over all AI recommendations and is responsible for complying with local AI regulations (e.g., EU AI Act, NYC Local Law 144). For more details, please review our [AI Transparency Notice].
6. FAIR USE & EXCESSIVE CONSUMPTION
If Customer usage materially exceeds plan capacity (e.g. high volumes of emails, AI queries, data exports, system-impacting automation), Digihey may:
- request plan upgrade,
- apply throttling or rate limits,
- change pricing proportionally,
- suspend abusive usage.
Digihey may also take such measures where Customer usage, in Digihey’s commercially reasonable judgment, exceeds internal technical, operational, or infrastructure capacity limits, even if specific thresholds are not expressly defined in the applicable Subscription Plan or Fair Use Policy. Fair Use thresholds and rules are defined in the Fair Use & Excessive Consumption Policy, which forms an integral part of these Terms.
7. SERVICE AVAILABILITY
Digihey will use commercially reasonable efforts to maintain a 99% uptime target (non-binding), excluding:
- planned maintenance,
- emergency maintenance,
- force majeure events,
- failures of third-party infrastructure.
This is not a guarantee, nor an SLA. No service credits apply unless agreed in writing (Enterprise Customers may refer to their specific SLA & Support Policy).
8. RESTRICTIONS & ACCEPTABLE USE
Customer may not:
- use the Service to violate laws or rights of individuals;
- scrape, mine, or import unlawfully obtained personal data;
- spam or mass-contact candidates without legal basis or in violation of CAN-SPAM and PECR rules;
- share credentials or circumvent access controls;
- reverse engineer, copy, or resell the Service without consent. Any breach may lead to immediate suspension or termination.
9. DATA PROTECTION & APPLICABLE LAWS
9.1 Processing of personal data is governed by Applicable Data Protection Laws (including EU GDPR, UK GDPR, UK Data Protection Act 2018, and applicable US State Privacy Laws).
9.2 For Customer recruitment activity: Customer = Controller, Digihey = Processor.
9.3 For Digihey internal recruitment: Digihey = Controller.
9.4 The Data Processing Agreement (DPA) forms an integral part of these Terms.
9.5 Digihey provides technical and organizational measures; Customer maintains compliance obligations related to hiring and communication.
10. SUBPROCESSORS & THIRD-PARTY SERVICES
Customer authorizes Digihey to engage Subprocessors and third-party service providers necessary for the operation of the Service, including:
- Supabase (database, authentication and storage)
- Vercel (hosting, deployment and cookieless web analytics)
- Postmark (transactional email)
- OpenAI (assistive AI processing)
- Google (Chrome Extension functionality)
- AWS (Amazon Textract processing and backup storage for deleted files for up to 30 days)
- Stripe (payment processing)
- Slack (registration notifications)
- Microsoft Entra ID (optional user authentication)
Digihey may engage additional or replacement Subprocessors as required to provide or improve the Service. Any such changes will be reflected in the Subprocessor List, and Customers will be notified where required by applicable data protection law.
Any international transfers of personal data outside the EU/EEA or the UK will be carried out in accordance with applicable data protection laws and, where required, supported by an adequacy decision, the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement or Addendum, or another legally recognized transfer mechanism, as further described in the DPA and Subprocessor List.
11. TERMINATION
11.1 Customer may terminate by cancelling subscription; access ends at the end of the billing period.
11.2 Digihey may immediately and without prior notice terminate/suspend if use is unlawful, unpaid, abusive, or threatens system integrity.
11.3 Upon termination:
access is revoked,
Customer will receive exported data within 30 days in a structured, machine-readable format to ensure smooth transition of services in compliance with the EU Data Act,
Digihey deletes data according to the Data Retention Policy.
12. INTELLECTUAL PROPERTY
All rights in the Service belong to Digihey. No ownership transfers to Customers. Customer retains ownership of Customer Data. Customer grants Digihey a limited license to host, process, and transmit Customer Data solely to provide the Service.
13. LIMITATION OF LIABILITY
To the maximum extent permitted by law:
Digihey’s liability is limited to amounts paid in the preceding 3 months,
Digihey is not liable for indirect, incidental, or consequential damages,
no liability for decisions made by Customer using the Service. Nothing excludes liability where prohibited by Croatian law.
14. INDEMNIFICATION
Customer indemnifies Digihey against claims arising from:
unlawful processing of personal data,
violations of third-party rights,
misuse of the Service,
and any claims related to employment discrimination, hiring bias, or violation of local AI regulations arising from the Customer's use of the Service.
15. GOVERNING LAW & DISPUTES
These Terms are governed by the laws of the Republic of Croatia. Exclusive venue: Trgovački sud u Zagrebu (Commercial Court in Zagreb).
16. MODIFICATIONS
Digihey may update these Terms to reflect legal, technical, or commercial developments. Material changes will be communicated before entering into effect.
17. CONTACT
Digihey d.o.o. Vilima Korajca 29, 10000 Zagreb. General & Privacy contact: hello@kandidator.com.
KANDIDATOR - SECURITY OVERVIEW
This Security Overview describes the technical and organizational measures implemented by Digihey d.o.o. (“Digihey”, “we”, “us”) to protect personal data processed through the Kandidator platform (“Service”). This document supports compliance with: GDPR Article 32, UK GDPR, Data Protection Act 2018, applicable US state privacy laws, and applicable Croatian and EU data protection laws.
1. SHARED RESPONSIBILITY MODEL
Security is a shared responsibility between Digihey and the Customer.
2. INFRASTRUCTURE & HOSTING
Kandidator uses the following third-party infrastructure and service providers:
Vercel – application hosting, deployment and cookieless web analytics
Supabase – database, authentication and storage
AWS – temporary document storage for Amazon Textract processing and backup storage for deleted files for up to 30 days
Postmark – transactional email delivery
OpenAI – AI-assisted processing
Microsoft Entra ID – optional user authentication through a Microsoft account
Infrastructure providers are selected based on security, reliability and compliance standards.
3. DATA PROTECTION MEASURES
Encryption in transit using TLS 1.2 or higher
Encryption at rest using industry-standard algorithms
Secure session management and token-based authentication
Role-based access control within the platform
4. ACCESS CONTROL & IDENTITY MANAGEMENT
Access to production systems is limited to authorized Digihey personnel
Principle of least privilege is applied
Internal access is logged and reviewed
Passwords are hashed and never stored in plain text Customers are responsible for managing user roles and revoking access when necessary.
5. APPLICATION SECURITY
Source code repositories are access-restricted
Changes are reviewed before deployment
Dependency monitoring and patching is performed regularly
Rate limiting and request throttling protect against abuse
6. AI SAFETY
AI features are assistive only
No automated decision-making under GDPR Article 22
AI providers do not train models on Customer Data
Human review is strictly required before any action is taken based on AI output.
7. BACKUP & DISASTER RECOVERY
Files deleted from the active Service may remain in AWS S3 backup storage for up to 30 days, after which they are automatically deleted.
8. INCIDENT RESPONSE
In the event of a confirmed security incident or personal data breach:
Immediate containment measures are applied
Root cause analysis is conducted
Affected Customers are notified without undue delay
Digihey cooperates with Customers in fulfilling GDPR notification obligations.
9. EMPLOYEE & INTERNAL SECURITY
Personnel with system access are subject to confidentiality obligations. Security awareness is maintained as part of internal processes, and access rights are reviewed periodically.
10. CUSTOMER RESPONSIBILITIES
Customers must: maintain secure passwords and devices, prevent unauthorized access to accounts, configure access roles responsibly, and report suspected security incidents promptly.
11. LIMITATIONS & DISCLAIMERS
Digihey does not guarantee absolute security. Security measures are designed to reduce risk to an acceptable industry standard level.
12. UPDATES
This Security Overview may be updated to reflect evolving security practices or legal requirements. Material changes will be communicated where appropriate.
13. CONTACT
For security-related inquiries or incident reporting: hello@kandidator.com, Digihey d.o.o., Vilima Korajca 29, 10000 Zagreb, Croatia.
KANDIDATOR - DATA PROCESSING AGREEMENT (DPA)
This DPA forms an integral part of the Terms of Service. This Data Processing Agreement (“Agreement” or “DPA”) is entered into between: Customer (“Controller”) and Digihey d.o.o., Vilima Korajca 29, 10000 Zagreb, Croatia, OIB: 28945260733 (“Processor” or “Digihey”), for processing of personal data through the Kandidator platform (“Service”) according to Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other Applicable Data Protection Laws (including UK GDPR, UK Data Protection Act 2018, and applicable US State Privacy Laws).
1. SCOPE & PURPOSE
Digihey will process personal data solely for the purpose of providing, maintaining and improving the Service and associated technical support, as further defined in the Terms of Service. No processing shall occur beyond documented Customer instructions.
2. TERM
This DPA remains in effect for the duration of the Customer’s Subscription or until the deletion of all Customer Data by Digihey.
3. SUBJECT MATTER OF PROCESSING
3.1 Categories of Data Subjects May include: job applicants (candidates), Customer personnel with platform access, individuals contacted by Customer within recruitment processes.
3.2 Types of Personal Data May include: contact information, CV/portfolio details, recruitment process history, communication records and notes, identifiers and usage metadata.
3.3 Special Categories of Data The Service is not intended for special category data under Article 9 GDPR or equivalent Applicable Data Protection Laws. If Customer processes such data, they acknowledge full responsibility for legal basis and compliance.
4. ROLES & RESPONSIBILITIES
Customer (Controller)
determines the purpose and lawful basis for processing,
provides notice to and manages rights of data subjects,
instructs Digihey regarding retention and deletion.
Digihey (Processor)
processes Customer Data only on instruction,
maintains technical and organizational security measures,
supports Customer in fulfilling select compliance obligations.
5. INSTRUCTIONS & AI FEATURES
Digihey shall process Customer Data only:
as necessary to provide the Service,
according to this DPA and the Terms of Service,
based on Customer’s documented instructions. If Digihey believes an instruction violates Applicable Data Protection Laws, Digihey will notify Customer.
5.1 Digihey processes Customer Data only on documented instructions for the purposes of providing the Service.
5.2 Digihey does not engage in automated decision-making, including profiling, that produces legal effects or significantly affects individuals, as defined under Article 22 GDPR.
5.3 All AI features in the Service are assistive only and do not operate without human intervention. Any hiring, selection or rejection decisions are made solely by the Customer or its personnel.
5.4 The Customer remains responsible for compliance with Article 22 GDPR and equivalent global AI and privacy laws where applicable, including providing transparency, lawful grounds, and safeguards for affected data subjects.
5.5 The Customer (as Controller) is strictly obliged to independently conduct a Data Protection Impact Assessment (DPIA) where required, and to maintain their own documentation demonstrating mandatory human oversight over AI recommendations, to comply with global standards including the EU AI Act, UK ICO guidelines, and US regulations such as NYC Local Law 144.
6. SUBPROCESSORS
Customer provides general authorization for Digihey to engage subprocessors necessary for operating the Service, such as:
Supabase (database, authentication and storage)
Vercel (hosting, deployment and cookieless web analytics)
Postmark (transactional email)
OpenAI (assistive AI processing)
Google (Chrome Extension functionality)
AWS (Amazon Textract processing and backup storage for deleted files for up to 30 days)
Stripe (payment processing)
Slack (registration notifications)
Microsoft Entra ID (optional user authentication)
Digihey ensures that subprocessors are bound by equivalent data protection obligations. The current list is maintained in the Subprocessor List. Customer may object on reasonable grounds under Applicable Data Protection Laws. If the objection cannot be resolved, Customer may terminate the subscription.
7. INTERNATIONAL DATA TRANSFERS
Where Customer Data is transferred outside the EU/EEA or the UK, Digihey ensures that the transfer is carried out in accordance with applicable data protection laws and, where required, supported by:
Standard Contractual Clauses (SCCs);
the UK International Data Transfer Agreement or Addendum;
an applicable adequacy decision, including the EU-US Data Privacy Framework where applicable;
another legally recognized transfer mechanism; and
supplementary technical and organizational safeguards where required.
8. SECURITY MEASURES
Digihey implements appropriate technical and organizational measures (TOMs) in accordance with Applicable Data Protection Laws (e.g., GDPR Art. 32), including:
encryption in transit and at rest,
access control and authentication,
incident response mechanisms,
staff confidentiality obligations,
disaster recovery and backup strategies. A summary is available in the Security Overview.
9. PERSONAL DATA BREACH
In case of a confirmed personal data breach affecting Customer Data, Digihey shall notify the Customer without undue delay and provide information reasonably required for Customer to fulfill reporting obligations under Applicable Data Protection Laws. Customer is responsible for notifying supervisory authorities or affected individuals, unless otherwise mutually agreed in writing.
10. AUDITS
Customer may request an audit once per calendar year, subject to: 30 days’ notice, reasonable scope, confidentiality obligations, and exclusion of proprietary source code review. Digihey may satisfy audit requirements via third-party reports, attestations, or remote assessments.
11. DATA SUBJECT REQUESTS
If Digihey receives a rights request (e.g., Art. 15–22 GDPR or US State Privacy rights) related to Customer Data, Digihey will:
direct the request to the Customer, or
assist Customer where reasonably necessary.
12. RETENTION & DELETION
Upon termination or written request:
Customer may retrieve data;
Customer Data is removed from active systems in accordance with the Customer’s instructions. Deleted files may remain in AWS S3 backup storage for up to 30 days and are automatically and permanently deleted upon expiry of that period, unless retention is required by applicable law.
13. LIABILITY
Liability is governed by the Terms of Service. Nothing in this Agreement limits rights or protections where prohibited under applicable law.
14. GOVERNING LAW
This DPA is governed by the laws of the Republic of Croatia. Jurisdiction: Commercial Court in Zagreb.
15. ORDER OF PRECEDENCE
In case of conflict:
Signed enterprise agreement (if applicable)
This DPA
Terms of Service
16. EXECUTION
This DPA is accepted:
via Terms of Service checkbox (standard accounts), or
via signature (enterprise customers).
KANDIDATOR - SUBPROCESSOR LIST
This Subprocessor List identifies the third-party vendors (“Subprocessors”) engaged by Digihey d.o.o. (“Digihey”) to support the delivery and operation of the Kandidator platform and related services. A “Subprocessor” is a third party that may process personal data on behalf of Customers, in accordance with Digihey’s Data Processing Agreement (DPA) and applicable data protection laws.
1. ACTIVE SUBPROCESSORS
Subprocessor: Supabase · Location: EU (Central Europe - eu- central-1) · Purpose: Database hosting, authentication and storage · Category of Data Processed: Candidate data and user account data · Transfer Safeguards: EU data hosting; SCCs where applicable.
Subprocessor: Vercel, Inc. · Location: EU / US · Purpose: Application hosting, infrastructure and cookieless web analytics · Category of Data Processed: Application logs, request metadata and aggregated, non-identifying usage data · Transfer Safeguards: SCCs
Subprocessor: Postmark · Location: EU / US · Purpose: Transactional email services · Category of Data Processed: Email metadata, including sender, recipient and delivery status · Transfer Safeguards: SCCs
Subprocessor: OpenAI · Location: US / EU · Purpose: Assistive AI processing · Category of Data Processed: CV documents and other Input text submitted for AI processing · Transfer Safeguards: SCCs
Subprocessor: Google LLC · Location: Global · Purpose: Chrome Extension operations · Category of Data Processed: Data captured locally through user-initiated browser activity · Transfer Safeguards: SCCs and applicable adequacy decisions
Subprocessor: Amazon Web Services, Inc. (AWS) · Location: United States (US East) · Purpose: Temporary document storage for Amazon Textract processing and backup storage for up to 30 days · Category of Data Processed: CV documents and extracted text · Transfer Safeguards: AWS Data Processing Addendum and SCCs, where applicable
Subprocessor: Stripe · Location: EU / US · Purpose: Payment processing and subscription billing · Category of Data Processed: Billing, subscription and transaction data · Transfer Safeguards: SCCs, where applicable
Subprocessor: Microsoft Corporation - Microsoft Entra ID · Location: EU?US · Purpose: Optional user authentication through a Microsoft account · Category of Data Processed: User account identifiers and authentication data · Transfer Safeguards: Microsoft Data Protection Addendum and SCCs, where applicable
Subprocessor: Slack Technologies, LLC · Location: US / Global · Purpose: Registration notifications through Slack webhook · Category of Data Processed: User email address · Transfer Safeguards: Slack Data Processing Addendum and SCCs, where applicable
2. OPTIONAL OR CONDITIONAL SUBPROCESSORS
(The following Subprocessors are not active by default and are engaged only if required by specific Service features or Customer configuration.) | Subprocessor | Location | Purpose | Notes | | :--- | :--- | :--- | :--- | | Analytics providers | EU / US | Product analytics (aggregated) | Non-identifying, anonymized where possible | | Customer support | EU / US | Live chat & support requests | Optional activation per Customer | | Content delivery | Global | CDN & network optimization | Not always active |
3. INTERNATIONAL DATA TRANSFERS & RISK ASSESSMENTS
Some Subprocessors may process personal data outside the EU/EEA or the UK. Such transfers are carried out in accordance with applicable data protection laws and, where required, supported by:
Standard Contractual Clauses (SCCs);
the UK International Data Transfer Agreement or Addendum;
an applicable adequacy decision, including the EU-US Data Privacy Framework where applicable;
another legally recognized transfer mechanism; and
supplementary technical and organizational safeguards where required.
Customers provide general authorization for Digihey to engage Subprocessors in accordance with the Data Processing Agreement (DPA).
4. CUSTOMER RIGHT TO OBJECT
Customers may object to a Subprocessor only on reasonable and GDPR-grounded causes. If an objection cannot be resolved, the Customer may terminate the subscription with no penalty for the remaining term.
5. UPDATES TO THIS LIST
Digihey may update this list to reflect operational or legal changes. Material changes will be posted here and, where necessary, communicated to Customers.
6. CONTACT
Questions regarding Subprocessors may be directed to: hello@kandidator.com Digihey d.o.o., Vilima Korajca 29, 10000 Zagreb, Croatia.
KANDIDATOR - DATA RETENTION & DELETION POLICY
This Data Retention & Deletion Policy (“Policy”) explains how long personal data is retained within the Kandidator platform (“Service”) and how data is deleted, in accordance with the GDPR and applicable data protection laws. This Policy forms an integral part of the Terms of Service, Privacy Policy, and Data Processing Agreement (DPA).
1. PURPOSE
The purpose of this Policy is to ensure that personal data is:
retained only for as long as necessary,
processed lawfully and transparently,
securely deleted or anonymized when no longer required.
2. ROLES & RESPONSIBILITIES
2.1 Customer as Data Controller When Customers use Kandidator to manage recruitment, they act as Data Controllers and are responsible for:
defining lawful retention periods,
obtaining and managing candidate consent,
ensuring deletion or anonymization when data is no longer needed.
2.2 Digihey as Data Processor Digihey acts as Data Processor and processes Customer Data solely according to documented instructions and this Policy.
2.3 Digihey as Data Controller (Internal Use) When Digihey uses Kandidator for its own recruitment or administrative purposes, Digihey acts as Data Controller.
3. RETENTION PERIODS
3.1 Digihey Internal Recruitment For recruitment conducted by Digihey:
candidate data is retained for 2 years from the last interaction,
prior to expiration, Digihey may request renewed consent,
if consent is not renewed, the data is deleted without undue delay. This reflects common recruitment practice and GDPR proportionality principles.
3.2 Customer-Controlled Recruitment Data For Customers using Kandidator:
retention periods are defined and controlled by the Customer,
Digihey does not independently determine how long candidate data is retained,
Customers may configure retention rules within the Service where available. Digihey retains Customer Data only for the duration of the subscription, unless otherwise instructed.
3.3 Account & Billing Data Certain personal data may be retained longer where required by law, including:
invoices, contracts, and accounting records,
records required under Croatian tax and accounting law. Such data may be retained for up to 10 years.
4. DATA DELETION PROCEDURE
4.1 Deletion Upon Termination
Upon subscription termination:
Customer may export their data during a 30-day notice period in a structured, machine-readable format, in compliance with the EU Data Act.
Digihey deletes Customer Data after the export window.
Access to the Service is revoked.
4.2 Deletion Upon Request Customers may request deletion of data at any time. Upon deletion, Customer Data is removed from the active Service and is no longer available to the Customer. Deleted files may remain in AWS S3 backup storage for up to 30 days before being automatically deleted.
5. BACKUPS & DISASTER RECOVERY
Deleted files may remain in AWS S3 backup storage for up to 30 days. During this period, they are not available through the active Service and are automatically deleted upon expiry of the applicable AWS S3 lifecycle period.
6. ANONYMIZATION
Where appropriate, Digihey may anonymize data instead of deleting it, ensuring that individuals can no longer be identified. Anonymized data may be used for:
aggregate analytics,
product improvement,
statistical reporting.
7. LEGAL HOLDS & EXCEPTIONS
Data may be retained beyond standard periods if required for:
legal or regulatory compliance,
defense of legal claims,
cooperation with authorities. Such retention is limited to the scope and duration required by law.
8. DATA SUBJECT RIGHTS
Data subjects may request deletion, restriction, or access in accordance with Applicable Data Protection Laws (including EU GDPR, UK GDPR, and US State Privacy laws). Requests relating to Customer-controlled data are handled by the Customer. Digihey will assist Customers where required under the DPA. Requests may be submitted to: hello@kandidator.com.
9. SECURITY OF DELETION
All deletions are performed using secure methods designed to prevent data recovery, consistent with industry standards and Digihey’s Security Overview.
10. POLICY UPDATES
This Policy may be updated to reflect legal or operational changes. Material changes will be communicated where required.
11. CONTACT
For questions regarding data retention or deletion: hello@kandidator.com Digihey d.o.o., Vilima Korajca 29, 10000 Zagreb, Croatia.
KANDIDATOR - PRIVACY POLICY
This Privacy Policy describes how Digihey d.o.o. (“Digihey”, “we”, “us”, “our”) collects, uses, stores, and protects personal data processed through the Kandidator platform and website (“Service”).
This Policy applies to:
Visitors of kandidator.com,
Customers (organizations using the Service),
Authorized Users (individuals operating within Customer accounts),
Job candidates whose information Customers process within the Service.
This Policy complies with the Applicable Data Protection Laws, including the EU GDPR, UK GDPR, UK Data Protection Act 2018, and applicable US State Privacy Laws.
1. DATA CONTROLLER & DATA PROCESSOR ROLES
Depending on context:
Where Digihey acts as a Data Processor, such processing is governed exclusively by the Data Processing Agreement (DPA) entered into between Digihey and the Customer. This Privacy Policy does not replace or modify the terms of the DPA. Depending on the context of processing, Digihey may act either as a Data Processor or as a Data Controller, as described below: (a) Data Processor – when providing the Service to the Customer and processing personal data entered by the Customer for recruitment and candidate management purposes. (b) Data Controller – only in respect of personal data processed for Digihey’s own internal recruitment or administrative purposes, which is governed by Digihey’s Privacy Policy.
2. CONTACT INFORMATION
Digihey d.o.o. Vilima Korajca 29, 10000 Zagreb, Croatia, OIB:
28945260733. General & Privacy contact: hello@kandidator.com Supervisory authority: AZOP — Croatian Data Protection Authority
3. PERSONAL DATA WE PROCESS
3.1 Candidate Data (Processor) When a Customer uses the Service to manage recruitment, the following categories may be processed:
identification data (name, contact information),
CVs, portfolios, employment/education history,
communication records and interview notes,
recruitment statuses (screening, interview, hired, rejected),
consent history and retention preferences.
Customer is solely responsible for: defining the lawful basis (e.g., consent, legitimate interest), providing notice to candidates, and maintaining candidate retention rules.
3.2 Customer & Authorized User Data (Controller): To operate and administer accounts: company information, user profiles and emails, login credentials (hashed), subscription history and billing metadata, platform usage logs.
3.3 Technical & Analytics Data: To secure and improve the Service we may collect: IP address, device/browser metadata, access timestamps and error logs, feature usage metrics (aggregated and anonymized).
4. PURPOSES & LEGAL BASIS
No automated decision making with legal effect is performed.
5. AI FEATURES
Kandidator includes optional AI features to support recruitment workflow.
AI is assistive only.
No automated decisions or profiling under GDPR Art. 22.
AI output may contain inaccuracies and must be reviewed by a human user.
Customer Data is not used to train AI models.
To ensure compliance with the EU AI Act, UK ICO guidelines, and applicable US regulations (such as NYC Local Law 144), human oversight is strictly required. For detailed information on our AI operations and Customer responsibilities, please review our [AI Transparency Notice].
6. COOKIES & TRACKING
The Service uses cookies and local storage for: authentication, session stability, and anonymized analytics (where legally permitted). Marketing cookies are not used within the app by default. Full details are provided in our Cookie Policy.
7. SHARING AND SUBPROCESSORS
Digihey engages vetted third-party subprocessors and service providers to operate the Service, including: Supabase (database, authentication and storage), Vercel (hosting and deployment), Postmark (transactional email), OpenAI (assistive AI processing), Google (Chrome Extension functionality), AWS (document processing and backup storage), Stripe (payments), Slack (registration notifications) and Microsoft Entra ID (optional user authentication). A full list is maintained in our Subprocessor List.
Where personal data is transferred outside the EU/EEA or the UK, Digihey applies appropriate transfer safeguards as described in Section 11 of this Policy and in the Subprocessor List.
8. SECURITY
We apply technical and organizational measures pursuant to GDPR Art. 32, including: encryption in transit and at rest, controlled access and least privilege access for personnel, secure authentication and password hashing, and incident response procedures. Further detail is provided in our Security Overview.
9. RETENTION
9.1 Digihey internal recruitment Candidate data is retained for 2 years from last interaction, unless renewed with consent. If consent is not renewed, data is deleted.
9.2 Customer-controlled recruitment Retention is defined by Customer. Digihey processes and deletes data according to Customer instruction.
9.3 Deleted Customer Data may remain in AWS S3 backup storage for up to 30 days before being automatically and permanently deleted. Backup data is not used for ordinary processing.
10. DATA SUBJECT RIGHTS
Individuals may exercise the following rights (subject to GDPR and Applicable Data Protection Laws, including UK GDPR and US State Privacy laws): access to their data, rectification, deletion, restriction of processing, portability, and objection. Customer requests (related to data they control) will be redirected to the respective Customer. US State Privacy Rights: In compliance with applicable US State Privacy laws (such as CCPA/CPRA), Digihey does not "sell" or "share" personal data for cross-context behavioral advertising. Requests to Digihey: hello@kandidator.com
11. INTERNATIONAL DATA TRANSFERS
Personal data may be transferred outside the EU/EEA or the UK where necessary to provide the Service. Such transfers are carried out in accordance with applicable data protection laws and, where required, are supported by an adequacy decision, including the EU-US Data Privacy Framework where applicable, the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement or Addendum, or another legally recognized transfer mechanism. Further information is provided in the DPA and Subprocessor List.
12. CHILDREN
The Service is not intended for, and does not knowingly process data of, individuals under 16 years of age.
13. LIMITATION OF RESPONSIBILITY
Digihey provides the Service as a tool. Digihey does not decide: lawful basis for Customer recruitment activity, communication legality, candidate targeting or outreach decisions, or compliance of Customer HR practices. Customer assumes full responsibility for compliance with local and international laws.
14. CHANGES TO THIS POLICY
Digihey may update this Policy to reflect legal, operational, or technical changes. Material changes will be communicated prior to enforcement.
15. CONTACT
For privacy concerns: hello@kandidator.com, Vilima Korajca 29, 10000 Zagreb, Croatia.
KANDIDATOR - FAIR USE & EXCESSIVE CONSUMPTION POLICY
This Fair Use & Excessive Consumption Policy (“Policy”) governs the acceptable level of resource usage of the Kandidator platform (“Service”) provided by Digihey d.o.o. (“Digihey”, “we”, “us”). This Policy forms an integral part of the Terms of Service and applies to all Customers and Authorized Users.
1. PURPOSE
The purpose of this Policy is to ensure platform stability, performance, and fair access for all Customers, while allowing Digihey to manage infrastructure resources responsibly.
2. FAIR USE PRINCIPLE
“Fair Use” means usage of the Service that:
aligns with the selected Subscription Plan,
reflects normal recruitment and HR operations of a business,
does not negatively affect system performance or other Customers. Fair Use applies across all features, including but not limited to storage, data processing, email delivery, AI features, and integrations.
3. EXCESSIVE CONSUMPTION
Excessive Consumption occurs when usage:
materially exceeds typical usage patterns for the subscribed plan,
creates disproportionate load on infrastructure,
threatens service stability, security, or email deliverability,
circumvents plan limitations through automation or workarounds.Examples include (non-exhaustive):
unusually high volume of email sending (e.g. mass outreach or bulk campaigns),
excessive AI queries or continuous automated prompting,
frequent large-scale imports or exports of candidate data,
high-frequency database queries or API calls,
scraping-like behavior or continuous Chrome Extension data extraction. Usage thresholds are not hard limits and are evaluated contextually. In addition to any quantitative indicators, Digihey may determine, in a commercially reasonable manner, that specific usage patterns negatively affect system stability, service quality, infrastructure costs, or the ability to provide the Service to other Customers, even if formal usage thresholds have not been exceeded.
4. EMAIL SENDING LIMITATIONS
To maintain deliverability and platform integrity:
email sending is subject to rate limits and volume controls,
unusually high email volumes may be throttled or temporarily suspended,
Customers must comply with applicable anti-spam laws. Digihey is not responsible for blacklisting or reputation damage caused by Customer email practices.
5. AI FEATURE LIMITATIONS
AI features are designed for assistive use and subject to usage limits. Excessive AI usage includes:
automated or continuous prompt execution,
use of AI features for bulk processing without human review,
usage patterns that degrade performance or exceed plan assumptions. Digihey may restrict AI features or require plan upgrades in response to excessive use.
6. DATA ACCESS, EXPORT & AUTOMATION
Customers may not:
repeatedly export large volumes of data in short timeframes,
automate exports to replicate the Service externally,
use the Service as a data extraction tool rather than recruitment software. Excessive or abusive automation may result in immediate restrictions.
7. DIGIHEY RESPONSE MEASURES
If Excessive Consumption is detected, Digihey may, at its discretion:
Notify the Customer of unusual usage,
Request usage adjustments or optimization,
Apply temporary throttling or rate limits
Restrict specific features (email, AI, exports),
Require upgrade to a higher Subscription Plan,
Adjust pricing to reflect actual resource usage (with notice),
Suspend or terminate access if stability is at risk. Such actions do not constitute service failure or breach by Digihey.
8. PRICING ADJUSTMENTS
Where Excessive Consumption persists across billing cycles, Digihey may:
propose a revised pricing model,
require migration to a plan appropriate to actual usage,
suspend access if Customer refuses a reasonable adjustment.
9. FORCE MAJEURE & THIRD-PARTY LIMITATIONS
Digihey is not liable for usage interruptions or limitations caused by:
cloud infrastructure outages,
email provider limitations,
AI service provider constraints,
force majeure events.
10. NO WAIVER OF CUSTOMER RESPONSIBILITY
This Policy does not transfer responsibility for lawful usage or compliance to Digihey. Customers remain responsible for their recruitment practices and legal compliance.
11. UPDATES
This Policy may be updated to reflect technical capacity, legal requirements, or business changes. Material updates will be communicated where required.
12. CONTACT
For questions regarding this Policy: General & Privacy contact: hello@kandidator.com.
KANDIDATOR - COOKIE POLICY
This Cookie Policy explains how Digihey d.o.o. (“we”, “us”, “our”) uses cookies and similar technologies on the Kandidator website and platform (“Service”). This Policy applies to:
kandidator.com (marketing and app access),
the Kandidator web application,
the Kandidator Chrome extension (where applicable). For general privacy practices, please see our Privacy Policy.
1. WHAT ARE COOKIES?
Cookies are small text files placed on your device to enable core functionality, enhance performance, and analyze usage. Cookies may be “session” (deleted when you close your browser) or “persistent” (stored until removed or expired). This Policy also applies to similar technologies such as:
localStorage / sessionStorage,
tracking pixels (where legally permitted),
device identifiers and technical telemetry.
2. TYPES OF COOKIES WE USE
Category: Strictly necessary · Purpose: Login, security and account access · Legal basis: Required to provide the service, consent is not required under applicable ePrivacy rules · Examples: Session cookies and authentication tokens
Category: Functional · Purpose: Preferences, language settings and improved user experience · Legal basis: Legitimate interest or consent, depending on the configuration · Examples: User-interface settings and saved filters
Category: Cookieless Analytics · Purpose: Performance measurement and aggregate usage insights; not used for profiling · Legal basis: Legitimate interests under Art. 6(1)(f) GDPR; no cookies used · Examples: Aggregated page-view metrics through Vercel Web Analytics
Category: Email Delivery · Purpose: Monitoring email delivery and performance through Postmark · Legal basis: Legitimate interest for service diagnostics · Examples: Delivery status indicators
Strictly necessary cookies are essential for the operation of the Service and do not require user consent under applicable ePrivacy laws, as they are required to provide the functionality explicitly requested by the user. Marketing or advertising cookies are NOT used inside the Kandidator app by default. If implemented in the future (on marketing pages only), consent will be requested in advance.
3. COOKIE CONSENT
The current configuration of the Service does not use analytics or marketing cookies requiring user consent. Vercel Web Analytics operates without the use of cookies. Accordingly, a cookie consent banner is not displayed solely for this analytics functionality.
Strictly necessary cookies and similar technologies may be used to provide authentication, security and session functionality.
If non-essential cookies or similar technologies requiring consent are introduced in the future, users will be provided with a consent mechanism before those technologies are activated. Consent may be withdrawn at any time.
4. THIRD-PARTY COOKIES & SERVICES
The Service may rely on trusted third-party infrastructure providers, including:
Provider: Supabase · Purpose: Authentication and Storage · Data Affected: Session identifiers
Provider: Vercel · Purpose: Hosting, routing and cookieless web analytics · Data Affected: Request metadata and aggregated, non-identifying usage data
Provider: Postmark · Purpose: Email delivery tracking · Data Affected: Email metadata
Provider: OpenAI · Purpose: Assistive AI processing · Data Affected: Prompts, no cookies
Provider: Google · Purpose: Chrome Extension operations · Data Affected: Extension data stored locally in the browser
Provider: Amazon Web Services · Purpose: Document text extraction through Amazon Textract and backup storage for up to 30 days · Data Affected: Uploaded documents and extracted text
Provider: Stripe · Purpose: Payment processing and billing · Data Affected: Billing details and transaction information
Provider: Microsoft Entra ID · Purpose: Optional user authentication through a Microsoft account · Data Affected: User account identifiers and authentication data
Cookies or local storage from these providers may apply in accordance with each provider’s privacy policy. Some listed providers may process data without placing cookies on the user’s device.
5. INTERNATIONAL DATA TRANSFERS
If data collected through cookies or similar technologies is processed outside the EU/EEA or the UK, the transfer will be carried out in accordance with applicable data protection laws and, where required, supported by:
Standard Contractual Clauses (SCCs);
the UK International Data Transfer Agreement or Addendum;
an applicable adequacy decision, including the EU-US Data Privacy Framework where applicable;
another legally recognized transfer mechanism; and
supplementary safeguards where required.
Further details are provided in the Subprocessor List.
6. MANAGING COOKIES
You may adjust cookie settings by:
using any consent or preferences tool made available through the Service, where applicable,
blocking cookies in your browser settings,
clearing stored data via browser tools. Note: Disabling essential cookies may prevent normal use of the Service.
7. RETENTION PERIOD
Retention periods vary depending on cookie type or similar technology used:
Type: Strictly necessary · Duration: Session duration or for as long as required for platform operation
Type: Functional · Duration: Until manually cleared or expiry (up to 12 months)
Type: Cookieless Analytics · Duration: The temporary visitor identifier is discarded after 24 hours; aggregated analytics data is retained according to the applicable Vercel account settings
Type: Email deliverability metrics · Duration: Retained only for the minimum period necessary for service diagnostics
8. UPDATES TO THIS POLICY
This Policy may be updated to reflect legal, technical or commercial changes. Material updates may be communicated via the Service.
9. CONTACT
For questions or concerns about this Cookie Policy: hello@kandidator.com Digihey d.o.o., Vilima Korajca 29, 10000 Zagreb, Croatia.
KANDIDATOR - ACCEPTABLE USE POLICY (AUP)
This Acceptable Use Policy (“Policy” or “AUP”) applies to all Customers and Authorized Users accessing the Kandidator platform, browser extension, and related services (“Service”) provided by Digihey d.o.o. (“Digihey”, “we”, “us”). By using the Service, Customers agree to comply with this Policy. Breach of this Policy may result in suspension or termination of access.
1. PURPOSE OF THIS POLICY
The purpose of this Policy is to ensure lawful, responsible, and secure use of the Service. This Policy supplements the Terms of Service and forms a binding part of the Customer’s subscription.
2. GENERAL PRINCIPLES
Users must, at all times:
use the Service only for lawful business purposes,
comply with applicable laws (EU, UK, US, and local jurisdictions),
protect access credentials and account information,
ensure that all data uploaded is collected and processed lawfully. The Customer is solely responsible for the legal basis for processing personal data within the Service.
3. PROHIBITED USE
The Service may not be used to:
3.1 Unlawful Processing
upload, store, or process personal data without a lawful basis (e.g. GDPR consent or legitimate interest),
scrape or import personal data from LinkedIn or other platforms in violation of their terms.
3.2 Communication Misconduct
send unsolicited bulk emails (“spam”),
contact individuals without transparency or opt-out mechanisms,
violate CAN-SPAM (USA), PECR (UK), or EU ePrivacy rules when applicable.
3.3 Data Abuse
artificially inflate or manipulate KPIs, analytics, or system metrics,
create duplicate accounts to bypass subscription limits,
store data of individuals under 16 years of age.
3.4 Security & Technical Misuse
attempt to gain unauthorized access to other accounts or systems,
perform penetration testing, reverse engineering, or decompilation,
deploy automation, bots, or scripts that overload system resources.
4. AI FEATURES - ACCEPTABLE USE
AI features within the Service are assistive only and may not be used to:
perform automated hiring or rejecting decisions,
automatically score or profile candidates in violation of Article 22 GDPR,
generate or store special category data without a lawful basis,
rely on AI output as factual, legal, or compliance advice. All AI-generated outputs must be reviewed by a human before use.
5. RESPONSIBILITIES OF THE CUSTOMER
The Customer is responsible for:
validating candidate consent or legal basis for data storage,
configuring user permissions and access roles,
ensuring internal staff are trained on privacy and compliance basics,
removing access when personnel leave the organization,
informing Digihey of any suspected breach or misuse.
6. EMAIL AND OUTREACH RULES
Emails sent from the Service must:
clearly identify the sender,
include accurate contact information,
provide a method for individuals to request removal or opt-out. Customers must comply with applicable outreach legislation. Digihey is not responsible for Customer outreach practices.
7. CHROME EXTENSION USE
When using the Kandidator Chrome Extension, the Customer must ensure:
data extraction is lawful and permitted by the source platform,
individuals are informed when required,
no automated scraping or bulk extraction tools are used. Browser-based data capture is initiated by the user, not by Digihey.
8. SYSTEM LOAD, RATE LIMITING & FAIR USE
Customers may not engage in excessive consumption of platform resources. Examples include:
overuse of API requests or database queries,
extraordinary bulk imports/exports,
high-volume email traffic that risks deliverability,
excessive AI query automation. Digihey may apply throttling, require a plan upgrade, or adjust pricing in line with the Fair Use Policy.
9. SUSPENSION & TERMINATION
Digihey may, at its discretion and without liability:
issue warnings,
temporarily restrict access,
suspend specific features (e.g., emailing or AI),
terminate access for severe or repeated violations. Where commercially reasonable, Digihey will notify the Customer and attempt resolution prior to termination.
10. NO WAIVER OF CUSTOMER COMPLIANCE
Nothing in this Policy transfers legal responsibility to Digihey. Customers are responsible for:
compliance with GDPR and other laws,
transparency with candidates,
accuracy and lawfulness of stored data.
11. UPDATES
This Policy may be updated to reflect legal, technical, or operational requirements. Material changes will be communicated.
12. CONTACT
To report violations or ask questions about this Policy: hello@kandidator.com Digihey d.o.o., Vilima Korajca 29, 10000 Zagreb, Croatia.
KANDIDATOR - AI TRANSPARENCY NOTICE
This AI Transparency Notice explains how Artificial Intelligence (AI) is utilized within the Kandidator platform (“Service”) provided by Digihey d.o.o. (“Digihey”). This document is designed to provide transparency and ensure compliance with global regulatory frameworks, including the EU AI Act, UK Information Commissioner's Office (ICO) guidelines, and applicable US state and city laws (such as NYC Local Law 144).
1. NATURE AND ROLE OF AI IN KANDIDATOR
Kandidator includes optional AI features designed to support and streamline the recruitment workflow.
Assistive Only: All AI features within the Service are assistive only and cannot make or trigger automated hiring decisions.
AI Processing: AI requests and Candidate Data may be processed through OpenAI’s API to provide the requested AI-assisted functionality.
No Model Training: Customer Data and Candidate Data are strictly not used to train our AI models or the models of our subprocessors.
Subprocessors: Digihey engages OpenAI for assistive AI processing, which operates under strict confidentiality and standard contractual clauses (SCCs).
2. NO AUTOMATED DECISION-MAKING
Digihey and the Kandidator platform do not engage in automated decision-making, including profiling, that produces legal effects or significantly affects individuals, as defined under Article 22 of the GDPR. Any hiring, selection, scoring, or rejection decisions are made solely by the Customer or its personnel.
3. MANDATORY HUMAN OVERSIGHT (HUMAN-IN-THE-LOOP)
Certain AI-assisted processing of new applications may occur automatically in the background. Manual CV extraction may also be initiated by the user. These functions do not make or trigger hiring, selection or rejection decisions. AI output may contain errors or inaccuracies; therefore, the Customer must review and validate AI-generated content before using it to take any action affecting a candidate. Customers may not rely on AI output as factual, legal or compliance advice.
4. CUSTOMER (DEPLOYER) OBLIGATIONS
When using Kandidator's AI features to rank or recommend candidates, the Customer acts as the Controller and/or Deployer of the AI system. The Customer is solely responsible for ensuring lawful and fair use of the AI features.
To comply with the EU AI Act, UK ICO guidelines on AI tools in recruitment, and applicable US laws (such as NYC Local Law 144), the Customer must ensure the following:
Data Protection Impact Assessment (DPIA): The Customer is responsible for conducting a DPIA for AI candidate processing, where required by law.
Bias and Fairness Monitoring: The Customer must monitor the AI's output to prevent employment discrimination and perform testing for bias and discriminatory effects in their hiring process.
Candidate Notification: Where required by local jurisdictions (e.g., NYC Local Law 144), the Customer must provide independent bias audit summaries and proper notifications to candidates about the use of automated tools in the hiring process.
Lawful Basis: The Customer must secure a lawful basis (such as GDPR-compliant consent or legitimate interest) for processing candidate data using AI.
5. SPECIAL CATEGORIES OF DATA & BIOMETRICS
The Service is not intended for processing special categories of data under Article 9 of the GDPR or processing biometric data (such as analyzing facial features or voice). If the Customer utilizes AI features to process such data, they assume full responsibility for establishing the legal basis and obtaining specific candidate consent.
6. UPDATES TO THIS NOTICE
This Notice may be updated to reflect changes in AI functionality, legal requirements, or technological advancements.
7. CONTACT
For questions regarding our AI practices or this Notice, please contact: hello@kandidator.com Digihey d.o.o., Vilima Korajca 29, 10000 Zagreb, Croatia