Global Privacy Policy

(UK GDPR / EU GDPR / US Privacy Laws)

Retaind.ai Ltd — Last updated: March 2026

This Privacy Policy explains how Retaind.ai Ltd ("Retaind.ai", "we", "our", or "us") collects, uses, processes, and protects personal data when individuals interact with the Retaind.ai recruitment intelligence platform.

This policy applies globally and is designed to comply with:

  • UK GDPR & Data Protection Act 2018
  • EU General Data Protection Regulation (GDPR)
  • California Consumer Privacy Act (CCPA) / CPRA
  • Applicable US employment and privacy laws
  • EU Artificial Intelligence Act transparency obligations

1. Who We Are

Retaind.ai Ltd operates the Retaind.ai recruitment intelligence platform, which enables organisations and recruiters to conduct structured recruitment campaigns.

Contact: privacy@retaind.ai

2. Categories of Personal Data Collected

We collect personal data in the following categories.

Account Data

  • Name
  • Email address
  • Job title
  • Organisation name
  • Login credentials

Candidate Data

Where individuals participate in recruitment campaigns:

  • Name and contact information
  • Curriculum vitae or employment history
  • Education and qualifications
  • Skills and experience
  • Questionnaire responses
  • Behavioural assessment responses
  • Video interview recordings
  • Interview transcripts
  • Candidate evaluation reports

Technical Data

  • IP address
  • Device identifiers
  • Browser type
  • Platform usage logs

3. Sources of Personal Data

Personal data may be obtained from:

  • the individual directly
  • recruiting organisations
  • recruiters using the platform
  • integrations with applicant tracking systems
  • publicly available professional information (where permitted)

4. Purpose of Processing

Personal data is processed to:

  • provide recruitment assessment tools
  • conduct benchmarking and role alignment analysis
  • generate candidate evaluation reports
  • administer recruitment campaigns
  • maintain system security
  • comply with legal obligations

5. Legal Basis for Processing

Under GDPR frameworks we rely on the following legal bases:

  • Contractual Necessity — Processing required to provide platform services.
  • Legitimate Interests — Employers and recruiters have a legitimate interest in evaluating candidates for employment.
  • Consent — Certain processing activities such as video recording and AI-assisted analysis rely on explicit candidate consent.
  • Legal Obligations — Where processing is required by law.

6. Automated Processing and AI Transparency

Retaind.ai uses AI-assisted technologies to analyse recruitment information. These technologies may:

  • summarise interview responses
  • analyse behavioural questionnaire results
  • identify alignment with role benchmarks

However:

  • the system does not make automated hiring decisions
  • the system does not automatically reject candidates
  • final hiring decisions are made by human recruiters or employers

This approach complies with GDPR Article 22 (Automated Decision-Making), EU AI Act transparency requirements, and US EEOC guidance on AI hiring tools.

7. Data Sharing

We do not sell personal data.

Personal data may be shared with:

  • authorised client organisations
  • recruitment agencies
  • cloud hosting providers
  • service providers supporting platform functionality
  • regulators where legally required

8. International Data Transfers

Data may be transferred internationally where required for service delivery. Where data is transferred outside the UK or EEA, we implement safeguards including:

  • Standard Contractual Clauses (SCCs)
  • secure hosting infrastructure
  • contractual privacy protections

9. Data Retention

Personal data is retained only as long as necessary. Typical retention periods:

  • Candidate assessment data — 12–24 months
  • Account data — Until account deletion

Retention periods may vary based on local employment laws.

10. Individual Rights

Depending on jurisdiction, individuals may have the right to:

  • access personal data
  • correct inaccurate information
  • request deletion
  • restrict processing
  • object to processing
  • request data portability

California residents may additionally request disclosure of categories of personal data collected, deletion of personal data, and opt-out of data sale (Retaind.ai does not sell data).

Requests may be submitted to: support@retaind.ai

11. Security

We implement technical and organisational security measures including:

  • encryption
  • access controls
  • audit logging
  • secure cloud infrastructure
  • role-based access permissions

12. Complaints

Individuals in the UK may contact the ICO. EU residents may contact their local supervisory authority. US residents may contact relevant state regulators.

13. Changes to This Policy

This policy may be updated periodically. Updates will be published on the website.


Data Processing Agreement (Global DPA)

This Data Processing Agreement ("DPA") forms part of the Retaind.ai Terms of Service. It governs the processing of personal data under GDPR, UK GDPR, US privacy laws, and EU AI Act obligations for high-risk AI systems.

1. Roles

  • Controller — The organisation using the platform to evaluate candidates.
  • Processor — Retaind.ai Ltd.

2. Scope of Processing

The processor will process personal data solely to deliver the platform services. Processing activities include:

  • storage of recruitment data
  • behavioural assessment analysis
  • video interview transcription
  • AI-assisted insight generation
  • candidate reporting

3. Categories of Data Subjects

  • job applicants
  • recruiters
  • client organisation staff
  • platform users

4. Categories of Personal Data

May include:

  • identification data
  • employment history
  • questionnaire responses
  • behavioural assessment data
  • video interview recordings
  • interview transcripts

5. Processor Obligations

The processor agrees to:

  • process data only on documented instructions
  • ensure staff confidentiality
  • maintain appropriate security
  • support data subject rights
  • notify breaches promptly
  • delete or return data upon request

6. Subprocessors

Retaind.ai may use subprocessors for cloud infrastructure, AI processing services, transcription services, and analytics platforms. All sub-processors must comply with equivalent data protection obligations.

7. Data Breach Notification

Retaind.ai will notify the controller without undue delay after becoming aware of a data breach.

8. Assistance to Controller

The processor will assist controllers with data subject rights requests, regulatory investigations, impact assessments, and compliance with AI transparency obligations.

9. Data Protection Impact Assessments

Where required under GDPR or AI regulations, the processor will support controllers in performing Data Protection Impact Assessments (DPIAs).

10. Data Deletion

Upon termination of services, data will be deleted or returned unless required by law to retain.


Candidate Consent and AI Transparency Statement

(EU AI Act + GDPR + US AI Hiring Laws)

Before participating in a recruitment campaign using Retaind.ai, candidates must acknowledge this notice.

1. Purpose

The platform assists employers in evaluating candidates through structured recruitment assessments.

2. Data Collected

Candidates may be asked to provide:

  • CV information
  • questionnaire responses
  • behavioural assessment responses
  • video interview responses

3. AI-Assisted Analysis

The platform uses artificial intelligence tools to analyse recruitment information. These tools may generate interview summaries, behavioural insights, and alignment analysis with role benchmarks.

4. Human Decision-Making

AI tools provide decision support only. They do not automatically accept candidates, automatically reject candidates, or determine employment outcomes. All hiring decisions are made by human recruiters or employers.

5. Video Interview Recording

Video interviews may be recorded and transcribed. Recordings may be analysed to identify behavioural evidence relevant to the role.

6. Transparency Requirements

This notice is provided to comply with GDPR automated processing transparency rules, EU AI Act transparency requirements, and US automated employment decision tool regulations.

7. Candidate Rights

Candidates may request access to their data, request correction, request deletion, and withdraw consent where applicable. Withdrawal of consent may prevent continuation in the recruitment process.

8. Consent Confirmation

By proceeding with the recruitment assessment you confirm that:

  • you understand that AI-assisted tools are used
  • you consent to the processing of your data for recruitment evaluation
  • you understand hiring decisions are made by humans

Acceptable AI Use Policy

(EU AI Act + US AI Hiring Laws + EEOC)

1. Purpose

This policy governs the responsible use of artificial intelligence within the Retaind.ai platform. The platform is designed to support evidence-based recruitment evaluation while maintaining fairness and human oversight.

2. Permitted Uses

Users may use AI features for candidate behavioural analysis, interview summarisation, benchmarking comparisons, and candidate evaluation reporting.

3. Prohibited Uses

Users must not use the platform to:

  • make fully automated hiring decisions
  • discriminate against candidates unlawfully
  • infer protected characteristics
  • profile candidates using demographic attributes
  • attempt psychological diagnosis

4. Fair Hiring Compliance

Users must ensure hiring practices comply with Equal Employment Opportunity laws, anti-discrimination legislation, and fair hiring standards.

5. Human Oversight

All AI outputs must be reviewed by human decision-makers. The platform is designed to support human judgment rather than replace it.

6. Bias Mitigation

Retaind.ai aims to minimise bias through structured benchmarking frameworks, consistent evaluation criteria, and transparent reporting structures. Users remain responsible for ensuring fair hiring practices.

7. Transparency to Candidates

Users must inform candidates when AI-assisted analysis is used and when interviews may be analysed by automated tools.

8. Compliance Monitoring

Retaind.ai may monitor platform usage to ensure compliance with this policy. Misuse may result in account suspension.


AI Risk Management Framework

(EU AI Act Article 9 compliant)

Purpose

This framework establishes the procedures used by Retaind.ai to identify, assess, mitigate, and monitor risks associated with the use of artificial intelligence within the Retaind.ai recruitment platform.

The framework is designed to comply with EU AI Act (High-Risk AI Systems), UK AI Regulatory Principles, US employment AI guidelines (EEOC, FTC), and ISO 23894 AI Risk Management concepts.

1. Scope

This framework applies to all AI components within the Retaind.ai platform including behavioural assessment analysis, candidate benchmarking comparisons, interview transcript analysis, candidate evaluation reporting, and alignment and conflict detection models. These systems are used to support recruitment decisions but do not autonomously make hiring decisions.

2. Risk Categories

Retaind.ai evaluates risks across five primary domains:

  • Fundamental Rights Risk — Potential risk of unfair or discriminatory treatment of candidates (biased scoring outcomes, unequal impact across demographic groups, opaque algorithmic decision logic).
  • Data Risk — Risk arising from poor data quality or misuse of personal data (incomplete candidate data, inaccurate transcripts, training data bias).
  • Model Risk — Risk associated with AI model behaviour (model drift, inaccurate inference, over-generalisation).
  • Operational Risk — Risk associated with system implementation (incorrect benchmarking configuration, misinterpretation of AI insights, misuse of outputs).
  • Governance Risk — Risk arising from lack of transparency or oversight (automated decisions without human review, inadequate documentation, failure to audit system outputs).

3. Risk Mitigation Measures

Retaind.ai implements mitigation measures including:

  • Structured Benchmarking — Candidate evaluation is based on pre-defined role benchmarks, reducing subjective bias.
  • Multi-source Evaluation — The system integrates multiple inputs including CV data, behavioural questionnaires, and structured interview responses, reducing reliance on single signals.
  • Neutral Reporting — AI outputs highlight alignment areas and areas for further exploration. The system never recommends hiring decisions.
  • Human Decision Authority — Human recruiters and hiring managers retain final decision-making responsibility.

4. Continuous Monitoring

Risk monitoring processes include model performance monitoring, fairness testing, anomaly detection, and audit logging. Risk reviews occur at least annually or after significant system updates.

5. Incident Reporting

Any identified AI-related risk or incident will trigger a risk assessment, internal investigation, mitigation plan, and documentation update. Serious incidents will be reported to regulators where required.


Algorithmic Fairness and Bias Mitigation Policy

(EU AI Act Article 10 + EEOC guidance)

1. Fairness Principles

The Retaind.ai platform is designed to minimise bias in candidate evaluation, ensure transparent evaluation criteria, and support fair hiring practices.

2. Prohibited AI Behaviours

The system must not infer protected characteristics, use demographic information in scoring, perform facial recognition or emotion detection, or generate psychological diagnoses.

Protected characteristics include race, gender, religion, disability, sexual orientation, and age.

3. Bias Testing Procedures

Bias testing is performed periodically to detect adverse impact. Tests may include:

  • Statistical Parity Analysis — Evaluate whether candidate outcomes disproportionately impact protected groups.
  • Disparate Impact Analysis — Assess whether model outputs violate the four-fifths rule used by US employment law.
  • Benchmark Sensitivity Testing — Test whether slight variations in benchmark definitions disproportionately affect candidate scoring.

4. Data Integrity

Bias mitigation also includes validating data quality, monitoring transcript accuracy, and removing irrelevant signals.

5. Model Updates

When bias risks are detected, models may be retrained, scoring thresholds adjusted, and system logic updated.

6. Transparency

Users must understand that AI provides analytical insights and final decisions remain human-led.


AI System Technical Documentation

(EU AI Act Article 11)

1. System Overview

The Retaind.ai system provides AI-assisted recruitment analysis designed to support structured hiring processes. The system integrates candidate CV analysis, behavioural questionnaires, video interview transcripts, and role benchmarking models.

2. Intended Purpose

The system is intended to assist recruiters in evaluating candidate alignment with defined role benchmarks, highlight areas of alignment and potential tension, and provide structured interview insights. The system is not designed to automatically determine employment outcomes.

3. System Architecture

  • Data Processing Layer — Handles candidate inputs including CV data, questionnaire responses, and interview transcripts.
  • Benchmarking Engine — Creates role benchmark profiles based on job characteristics, personal characteristics, and motivational drivers.
  • Alignment Analysis Engine — Compares candidate responses with benchmark characteristics. Outputs include alignment scores, correlation indicators, and conflict areas.
  • Reporting Engine — Generates structured reports highlighting skills alignment, behavioural alignment, and areas for further exploration.

4. Training Data

The system uses structured behavioural frameworks, validated psychometric concepts, and rule-based scoring mechanisms. The platform does not rely on demographic data.

5. Limitations

AI outputs may be influenced by quality of input data, incomplete candidate responses, and interpretation of behavioural evidence. Outputs are therefore advisory only.

6. Security Controls

The platform implements encrypted storage, role-based access control, and system monitoring.

7. Compliance

The system is designed to align with EU AI Act transparency principles, GDPR data protection obligations, and US AI hiring regulatory guidance.


Human Oversight Policy

(EU AI Act Article 14)

1. Purpose

This policy ensures that AI outputs generated by the platform remain subject to meaningful human oversight.

2. Principle of Human Control

AI-generated insights are decision-support tools. They must not replace human judgment.

3. Human Oversight Responsibilities

Recruiters and hiring managers must review AI-generated reports, interpret insights within organisational context, and conduct interviews before making hiring decisions.

4. Decision-Making Authority

Only authorised human decision-makers may shortlist candidates, reject candidates, or extend job offers.

5. Review of AI Outputs

Users must treat AI outputs as evidence indicators, areas for further exploration, and structured insights. They must not be interpreted as deterministic conclusions.

6. Escalation of Concerns

Where AI outputs appear inconsistent or misleading, users should review source data, conduct additional interviews, and consult internal hiring teams.

7. Training and Awareness

Users should receive guidance on interpreting AI-generated reports, avoiding over-reliance on AI insights, and ensuring fair hiring practices.

8. Continuous Oversight

Retaind.ai monitors system outputs to ensure transparency, fairness, and compliance with applicable regulations.


AI Governance Charter

Retaind.ai Ltd

Purpose

This AI Governance Charter defines the principles, responsibilities, and governance structure governing the design, deployment, and oversight of artificial intelligence within the Retaind.ai platform.

The charter ensures that AI technologies used in recruitment operate in a manner that is lawful, fair, transparent, accountable, and human-controlled.

1. Scope

This charter applies to all AI technologies deployed within the Retaind.ai platform, including systems used for candidate behavioural analysis, benchmarking alignment analysis, interview transcript interpretation, and structured candidate reporting. These systems assist recruitment processes but do not autonomously make hiring decisions.

2. Core AI Governance Principles

  • Human Authority — AI systems must support human decision-making rather than replace it. Final hiring decisions are always made by human recruiters or employers.
  • Fairness and Non-Discrimination — The system must not intentionally or unintentionally discriminate, infer protected characteristics, or use demographic profiling for hiring outcomes.
  • Transparency — Users and candidates must understand when AI tools are used in recruitment processes. The purpose and limitations of AI outputs must be communicated clearly.
  • Accountability — Retaind.ai retains responsibility for system design, risk mitigation, and governance procedures. Organisations using the platform retain responsibility for hiring decisions.
  • Privacy and Data Protection — All AI systems must comply with applicable data protection laws. Personal data must be processed only where lawful and necessary.
  • Safety and Reliability — AI systems must be designed to minimise error, provide explainable outputs, and avoid deterministic conclusions.

3. Governance Structure

AI governance responsibilities are shared across:

  • Executive Oversight — Responsible for strategic AI governance and compliance.
  • Product & Engineering — Responsible for model design, technical safeguards, and system testing.
  • Compliance & Legal — Responsible for regulatory compliance, privacy oversight, and documentation and audits.

4. Review and Oversight

AI governance practices are reviewed periodically. Major platform updates trigger governance review and risk reassessment.

5. Continuous Improvement

Retaind.ai commits to continuously improving AI systems through monitoring, stakeholder feedback, and regulatory guidance updates.


AI Model Risk Audit Framework

Purpose

This framework establishes procedures for auditing AI systems used within the Retaind.ai platform. The objective is to ensure models remain accurate, fair, reliable, and compliant with regulations.

1. Audit Frequency

AI systems are reviewed annually, following major system updates, and after incidents or anomalies.

2. Audit Categories

  • Data Quality Audit — Evaluate data quality, completeness, bias risk, and representativeness.
  • Model Performance Audit — Evaluate prediction consistency, stability across candidate populations, and model drift.
  • Fairness Audit — Evaluate disparate impact, bias indicators, and fairness metrics.
  • Explainability Audit — Evaluate whether system outputs remain understandable to users.

3. Audit Process

  1. Review training data sources
  2. Test model outputs across varied scenarios
  3. Evaluate fairness indicators
  4. Document findings and remediation

4. Remediation Procedures

Where audit findings reveal risks, models may be retrained, scoring logic adjusted, and governance controls updated.

5. Documentation

All audits are documented for regulatory review.


AI Incident Response Plan

1. Definition of AI Incident

An AI incident may include biased or discriminatory outcomes, incorrect system outputs, data integrity failures, misuse of AI functionality, or security breaches affecting AI systems.

2. Incident Severity Levels

  • Level 1 – Minor Issue — Non-critical issue affecting limited functionality.
  • Level 2 – Moderate Issue — Issue affecting accuracy or reliability of outputs.
  • Level 3 – Critical Incident — Issue that may affect candidate rights or regulatory compliance.

3. Incident Response Process

  1. Detection — Incident identified via user reports, internal monitoring, or audit processes.
  2. Initial Assessment — Evaluate severity, impact, and affected users.
  3. Containment — Actions may include disabling affected features or isolating system components.
  4. Investigation — Investigate root cause including data errors, model behaviour, or operational misuse.
  5. Remediation — Implement corrective actions such as model updates, system fixes, or governance updates.
  6. Notification — Where legally required, regulators may be notified and affected organisations informed.

4. Post-Incident Review

After incident resolution: root cause analysis performed, governance documentation updated, and additional safeguards implemented.

5. Continuous Monitoring

AI systems are regularly monitored to detect anomalies, unexpected outcomes, and model drift.


Responsible AI Statement for Hiring Technology

Our Commitment

At Retaind.ai, we believe artificial intelligence should enhance human decision-making, not replace it.

Our platform is designed to support fairer, more structured, and evidence-based recruitment processes, helping organisations make better hiring decisions while protecting candidate rights and promoting transparency.

We recognise that recruitment technologies can significantly impact individuals' careers and opportunities. For this reason, we are committed to developing and deploying AI systems responsibly, ethically, and in compliance with applicable laws and standards.

Human-Centred Decision Making

Retaind.ai systems are designed to assist recruiters and hiring managers by providing structured insights into candidate information. Our platform does not automatically accept or reject candidates, and it does not make employment decisions. All hiring decisions remain under the control of human decision-makers.

Fairness and Non-Discrimination

We are committed to ensuring our technology supports fair hiring practices. Our systems are designed to:

  • avoid using protected characteristics in candidate evaluation
  • minimise bias through structured benchmarking processes
  • ensure consistent evaluation criteria across candidates
  • support transparency in how candidate insights are generated

We do not use AI to infer sensitive attributes such as race, gender, religion, or other protected characteristics.

Transparency

We believe candidates and employers should understand when AI tools are used in recruitment processes. Retaind.ai supports transparency by informing candidates when AI-assisted analysis may be used, explaining the purpose of AI-generated insights, and ensuring outputs are presented as structured analysis rather than deterministic judgments.

Privacy and Data Protection

We prioritise the responsible handling of personal data. Our systems are designed to comply with the EU General Data Protection Regulation (GDPR), UK GDPR and the Data Protection Act, and applicable US privacy regulations. We minimise data collection and ensure personal information is used only for legitimate recruitment purposes.

Accountability and Governance

Responsible AI requires strong governance. Retaind.ai maintains internal frameworks to oversee the design and operation of our AI systems, including AI risk management procedures, bias testing and fairness monitoring, model documentation and audit processes, and human oversight controls. These governance measures help ensure our technology operates safely, fairly, and transparently.

Continuous Monitoring and Improvement

AI systems require ongoing evaluation. We monitor our systems to ensure they continue to operate as intended and to identify opportunities for improvement. Where potential risks or limitations are identified, we take appropriate action to mitigate them and strengthen our safeguards.

Our Role in the Hiring Process

Retaind.ai provides structured insights that support recruitment decisions. Our platform helps organisations define clearer role benchmarks, assess candidate alignment with role requirements, structure interview evaluation, and reduce reliance on subjective hiring decisions. However, our technology does not replace professional judgment. Employers and recruiters remain responsible for final hiring decisions.

Responsible Use by Organisations

Organisations using the Retaind.ai platform are expected to maintain fair and lawful hiring practices, ensure human oversight of AI outputs, and communicate transparently with candidates about recruitment processes. Responsible AI requires collaboration between technology providers and employers.

Our Ongoing Commitment

As AI technologies continue to evolve, we remain committed to improving our systems and governance practices. We will continue to monitor regulatory developments and industry standards to ensure our technology remains aligned with best practices for responsible AI in recruitment.

Contact

Questions about our responsible AI practices can be directed to:

Retaind.ai Ltd — support@retaind.ai