Candidate Privacy & Visibility Notice
Who can see a candidate's profile, the Four-State Model, and candidate controls — in plain language.
> *This document is part of Kempian's Trust Center documentation. It is reviewed periodically and does not constitute legal advice. Draft v0.2 — pending final legal review before publication.*
This Notice is written for candidates. It explains, in plain language, who can see your profile on Kempian, what our AI systems do with your information, and what choices and controls you have. It is a companion to Kempian's Privacy Policy, which covers the full legal detail across all user types, and Kempian's AI Transparency Notice, which explains Kempian's AI functionality in more technical depth. This Notice can be read on its own, but where it summarises a legal basis or a technical detail, the Privacy Policy and AI Transparency Notice are the fuller reference.
Throughout, "Kempian" refers to the platform operated by Adept AI Inc..
1. The Four-State Model: What It Means for You
Every candidate record on Kempian is in exactly one of four privacy states at any given time, under what Kempian calls its Four-State Model: Internal, Marketplace, AI-Discovered, and Connected. The state determines what recruiters can see about you and how they can reach you. You can move between states, and some transitions require your explicit action.
State 1 — Internal (ATS-imported)
How you get here: An employer or staffing agency you've already applied to, or that already represents you, imports your record from its own applicant tracking system (for example, Greenhouse, Bullhorn, or Lever) into Kempian.
What "visible" means: Your full record, including contact details, is visible to recruiters at that organisation. That's because the organisation already lawfully holds your data through its own prior relationship with you — an application, a submission, or similar. Kempian does not add new visibility here beyond what the importing organisation already had.
State 2 — Marketplace (self-registered)
How you get here: You create a profile directly on Kempian.
What "visible" means: Your profile, skills, and AI match data are visible to recruiters searching the marketplace, but your personal contact details are hidden. A recruiter who wants to reach you must message you through Kempian's in-platform relay, request a connection, or invite you to apply — they cannot see your email or phone number unless and until you accept a connection.
State 3 — AI-Discovered
How you get here: Kempian's AI sourcing agents identify a profile matching a role from external or public sources (for example, a professional network profile). You have not applied, registered, or interacted with Kempian at this point.
What "visible" means: No personal data is shown to recruiters at all — there's no consent relationship with you yet. Instead of contact details, recruiters see AI-derived engagement insights only: an estimated likelihood of response, a preferred contact channel, a general best-contact window, openness to relocation or remote work, and an estimated notice period. This lets a recruiter decide whether outreach is worthwhile without seeing anything that identifies you personally.
A recruiter can trigger AI-mediated outreach, but cannot see your contact details until you respond. This restriction cannot be turned off by any employer or organisation setting — it's a fixed rule of the platform.
Kempian is designed to include a clear notice in the first outreach message at this stage, naming the actual source where your profile was found (for example, "we identified your public GitHub profile"). This is a commitment Kempian is still building toward — it isn't a confirmed, universally live feature yet. Until it's fully rolled out, treat any first-contact message from Kempian as the authoritative source on how your information was found.
If you are located in India, Kempian's default approach is to restrict or disable AI-discovery sourcing for India-located candidates, pending confirmation from Indian counsel on how this activity fits within India's data protection law.
If you are not contacted, Kempian is designed to auto-delete an AI-discovered record within 30 days of it being created, if that record was tied to a specific open role rather than a general talent pool. This is the retention rule Kempian is committing to. Full engineering enforcement is still being confirmed.
State 4 — Connected
How you get here: You accept a connection request, respond to outreach, or otherwise choose to enable sharing with a recruiter or employer.
What "visible" means: Your profile becomes visible according to your own per-field permissions — you control, field by field, what a connected recruiter can see (for example, you might share your phone number but not your current employer, or vice versa). This is set through your Privacy Settings, described in Section 3. Critically, no organisation-level setting can override your own field-level choices once you're Connected — this is a fixed rule, not a preference an employer can turn off.
Moving between states
You generally move from State 2 or State 3 toward State 4 by accepting a connection request or responding to outreach. If your record was imported into State 1 by an organisation you already have a relationship with, that state reflects the organisation's own data holding, not a Kempian-driven consent step. You can also close your account entirely at any time (Section 6).
2. Who Can See Your Profile, and What Kempian's AI Processes
The table below summarises what recruiters and Kempian's AI systems can access at each state.
| State | Recruiters can see | Recruiters can do | Kempian AI processes |
| Internal | Full record, including contact details | Contact directly | Matching, resume-derived fields |
| Marketplace | Profile, skills, match data (no contact details) | Message via relay, request connection, invite to apply | Matching, resume-derived fields |
| AI-Discovered | Engagement insights only (no personal data) | Trigger AI-mediated outreach only | Sourcing/discovery, matching |
| Connected | Whatever you've enabled, field by field | Contact via candidate-enabled channels only | Matching, resume-derived fields |
Employers are the organisations recruiters act on behalf of. An employer never sees more than what its recruiters can see through the platform, and cannot override the invariants described above.
3. How AI Matching Uses Your Profile
Kempian's AI matching component scores and ranks candidates against job requirements using your CV content, employment history, and other profile data, together with the job's stated requirements. The output is a score/ranking plus a plain-language explanation of the contributing factors — a "Why this match?" summary — so recruiters can understand why you were surfaced for a role. Where relevant, this explanation can also point out qualifications or experience the role is looking for that your profile doesn't yet show. That gives you a clearer, more actionable picture — not just why you matched, but what a stronger match for that role might look like.
This output is a recommendation only. Kempian's AI does not shortlist, reject, or hire anyone. A human recruiter or employer decision-maker reviews match results and makes the actual decision about whether to contact, progress, or decline a candidate.
Kempian is implementing human-confirmation checkpoints across AI-assisted profile updates — including resume-parsed fields — as part of its ongoing compliance program. You can always review and correct any AI-derived field on your profile. Full technical detail on how matching and resume parsing work, including which AI providers are involved, is in the AI Transparency Notice.
4. Consent Choices: At Registration and in Privacy Settings
At registration, you're asked a single, clear question about who can contact you — this sets your baseline visibility and contact preference and determines how your profile behaves as a Marketplace (State 2) record.
In your Privacy Settings page, you get more granular, per-field control. Once you're Connected (State 4) with a recruiter or employer, you can choose exactly which fields they see — for example, contact details, current employer, salary expectations, or availability — independently of one another. You can change these settings at any time, and, as noted in Section 1, no organisation can override your field-level choices once set.
5. Your Privacy Timeline
Kempian gives you visibility into your own consent and access history through a Privacy Timeline — a per-candidate, timestamped record of consent events, disclosures, and access to your data. This can include when your profile moved between states, when a recruiter viewed your data, or when you granted or withdrew a permission. You can view and export your Privacy Timeline directly. If you cannot yet see a complete timeline in your account, contact us using the details in Section 9 and we will provide the underlying information directly.
6. Deleting Your Account
You can request deletion of your Kempian account and candidate profile at any time. What happens next depends on your record type and Kempian's target retention policy:
- Self-registered profiles (Marketplace/Connected): subject to deletion upon request, and otherwise retained for 2 years from your last active login before Kempian gives notice and deletes unless you renew.
- ATS-imported profiles: governed by the importing organisation's own retention practice and instructions, since that organisation holds an independent relationship with you; Kempian will direct deletion requests to the appropriate process.
- AI-discovered, uncontacted profiles: intended to auto-delete within 30 days of creation if you were never contacted (see Section 1).
- Certain records Kempian retains regardless of an account deletion request. For example: AI matching decision/audit records and prompt/response logs (retained a minimum of 10 years to meet EU AI Act traceability requirements); records of your own rights requests (retained 5 years); and consent history (retained for the duration of processing plus 3 years). These retention periods exist to meet legal and audit obligations and are described in full in the Privacy Policy's retention table.
Kempian processes deletion requests in line with the categories above and will confirm completion of your request.
7. Downloading and Exporting Your Data
You can request an export of your Kempian profile data, including the data underlying your Privacy Timeline where available, through your account settings or by contacting us using the details in Section 9. We aim to provide this in a commonly used, portable format.
8. Objecting to AI Matching or Outreach, and Requesting Human Review
You can object to AI-driven matching or AI-mediated outreach at any time, including:
- Opting out of further AI-discovery outreach if you were reached as a State 3 (AI-Discovered) candidate.
- Objecting to your profile being used in AI matching more generally, where this processing relies on legitimate interests or consent (see the Privacy Policy, Section 5, for the legal-basis detail).
- Requesting human review of any AI-generated output that affected how your application or profile was treated — for example, asking a recruiter to explain a match result or to review your profile manually rather than relying solely on the AI-generated "Why this match?" summary.
Because AI outputs are recommendations that a human recruiter or employer must act on, you can also raise concerns directly with the recruiter or employer you are engaging with, in addition to contacting Kempian.
To submit any of these requests, use the contact details in Section 9.
9. Contact and Requests
| Purpose | Contact |
| Account deletion, data export, consent withdrawal, objections to AI processing, or requests for human review | privacy@kempian.com |
| Data Protection Officer, for broader data-protection questions | DPO name/contact — to be appointed, reachable via privacy@kempian.com |
| India Grievance Officer (DPDP Act), for candidates located in India | Grievance Officer name/contact — to be appointed, reachable via privacy@kempian.com |
For the full legal basis, retention schedule, and cross-jurisdictional detail behind everything summarised in this Notice, see Kempian's Privacy Policy. For technical detail on how Kempian's AI systems work, including current limitations, see the AI Transparency Notice.
10. Related Documents
This Notice should be read alongside:
- Kempian Privacy Policy
- Kempian AI Transparency Notice
- Kempian Terms and Conditions
Kempian — Candidate Privacy & Visibility Notice — v0.3 (Draft) — July 2026