Privacy Policy
How Kempian collects, uses, and protects personal data across candidates, recruiters, and employers (GDPR, CCPA/CPRA, India DPDP).
*This document is part of Kempian's Trust Center documentation. It is reviewed periodically and does not constitute legal advice. Draft v0.2 — pending final legal review before publication.*
This Privacy Policy explains how Kempian collects, uses, shares, and protects personal data when candidates, recruiters, and employer/organisation users use the Kempian platform ("Platform"). Read it alongside two companion documents: the AI Transparency Notice, which explains Kempian's AI functionality, and the Candidate Privacy & Visibility Notice, which explains in plain language who can see a candidate's profile and when.
1. Who Kempian Is
Kempian is operated by Adept AI Inc., a Delaware corporation, principal place of business at registered address ("Kempian," "we," "us," or "our").
For most personal data described in this Policy, Kempian is the data controller (or, under India's DPDP Act, the data fiduciary). When an employer or staffing agency imports candidate data from its own applicant tracking system ("ATS"), that organisation is usually the controller for that data. Kempian then acts as its processor under a separate data processing agreement.
2. Scope of This Policy
This Policy covers personal data Kempian processes for three groups of users:
- Candidates — people with a profile on Kempian, whether self-registered, imported via an employer's or agency's ATS, or identified through Kempian's AI-discovery sourcing.
- Recruiters — in-house or staffing-agency users who search, message, and shortlist candidates for an employer.
- Employers/organisations — the businesses, healthcare systems, and staffing agencies that contract with Kempian.
Each group has different data touchpoints and, in places, different rights and legal bases. We address these separately below where relevant.
3. What Data We Collect, and How It Reaches Us
3.1 Candidate data and the three sourcing channels
Candidate data reaches Kempian through one of three channels. The channel affects both the data involved and the legal basis Kempian relies on:
1. ATS import — an employer or agency imports candidate records from its own systems. The importing organisation typically already has a lawful basis for this data. Kempian processes it mainly as a processor, on that organisation's instructions.
2. Self-registration — a candidate creates a profile directly on Kempian and makes explicit choices about visibility and contact.
3. AI-discovery / sourcing — Kempian's AI sourcing tools identify candidate profiles from external or public sources. No consent relationship exists at the point of discovery, so these records carry extra restrictions. See Section 5 and the AI Transparency Notice.
Candidate data may include: name and contact details; resume/CV content; employment history; education; skills; certifications and professional licences; location; salary expectations; availability and notice period; and engagement signals (such as how a candidate has responded to past outreach). We treat professional licences and certifications — for example, a clinical licence number, given Kempian's healthcare-sector focus — as occupational-qualification data. This is not special-category health data under GDPR Article 9, unless the specific content collected reveals health information in substance.
3.2 Recruiter and employer data
For recruiters and employer/organisation administrators, Kempian collects account and contact details, organisation affiliation, role/permissions, usage and activity data, and messages sent through the Platform.
3.3 Platform-derived data
Kempian also generates data by operating the Platform: AI match scores and rationale, AI-derived engagement insights, consent and disclosure history (a candidate's Privacy Timeline), and audit/decision logs.
4. How and Why We Use AI to Process Personal Data
Kempian uses AI in four areas — collectively, the AI Features: Candidate Matching (scoring and ranking candidates against job requirements), Resume Parsing (extracting structured data from CVs), a Job Creation Assistant (drafting job descriptions), and an in-platform Chat Assistant. Matching and Resume Parsing process candidate personal data; the Job Creation Assistant and Chat Assistant generally do not.
AI-generated outputs — match scores, rankings, and resume-derived profile fields — are recommendations only. A human recruiter or employer must review and act on any AI output that could affect a candidate. Kempian's AI does not make final hiring, rejection, or shortlisting decisions — we call this the Human Review Gate. Kempian is rolling out human-confirmation checkpoints across all AI-assisted profile updates as part of its ongoing compliance program. Candidates and recruiters can always review and correct AI-derived data. For full technical detail, including current known limitations, see the standalone AI Transparency Notice.
Consent for AI processing of candidate data follows Kempian's Four-State Model (Internal, Marketplace, AI-Discovered, Connected), tied to how a candidate's record entered Kempian and what the candidate has agreed to. The Candidate Privacy & Visibility Notice is the authoritative, candidate-facing guide to how this model works and what it means for visibility. This Policy relies on that Notice for those details and covers only the legal-basis implications below.
5. Legal Bases for Processing (GDPR)
Where GDPR applies, Kempian relies on:
- Contract (Art. 6(1)(b)) — to provide the Platform to registered candidates, recruiters, and employers.
- Consent (Art. 6(1)(a)) — for candidate choices made at registration about contact and visibility, and for AI-outreach or marketing communications where we seek consent.
- Legitimate interests (Art. 6(1)(f)) — for the initial discovery and first-outreach step of AI-discovery sourcing (AI-Discovered candidates). We balance this against candidate rights and expectations and record it in a documented Legitimate Interest Assessment.
- Legal obligation (Art. 6(1)(c)) — where Kempian must retain or disclose data to comply with the law.
We do not rely on legitimate interest for candidates subject to India's DPDP Act (see Section 7). India's consent-first regime does not generally recognise a basis comparable to GDPR Article 6(1)(f). AI-discovery sourcing is restricted by default for India-located candidates until Indian counsel confirms a lawful basis.
6. California and Other US State Privacy Laws (CCPA/CPRA)
This section applies to California residents and, where equivalent laws apply, residents of other US states.
Categories of personal information we collect include identifiers (name, contact details), professional/employment information, education information, platform usage information, inferences (including AI match scores and engagement insights), and, in some cases, resume/CV content that may include categories the CCPA treats as sensitive — for example, information suggestive of citizenship/immigration status or union membership, if present in a CV. We do not intentionally collect health data, racial or ethnic origin, or precise geolocation as a matter of ordinary product function.
Sale and sharing. Kempian's confirmed position on whether it "sells" or "shares" personal information under the CCPA/CPRA — to be finalized before publication.
Your rights. California residents, and residents of states with equivalent laws, have the right to know, delete, correct, opt out of sale/sharing, and opt out of certain automated decision-making technology ("ADMT") uses. You can also limit use of sensitive personal information. Submit requests through the unified process in Section 12.
Automated decision-making technology (ADMT). California's CPRA ADMT regulations take effect January 1, 2027. They add pre-use notice, risk-assessment, and opt-out/access requirements for automated processing used in "significant decisions," which may include hiring-related decisions. Kempian's candidate-matching functionality is a likely candidate for coverage. See the AI Transparency Notice for detailed, ADMT-specific disclosures.
7. India — Digital Personal Data Protection Act, 2023 (DPDP)
Where the DPDP Act applies, Kempian (or the Kempian entity designated for India operations) acts as the data fiduciary.
- Purpose-specific, separately withdrawable consent for distinct processing activities — CV ingestion, AI matching, sharing with employers, and career-recommendation communications. You can withdraw each independently.
- No reliance on legitimate interest. AI-discovery sourcing is restricted by default for India-located candidates until Indian counsel confirms a lawful basis.
- Data principal rights to access, correction, erasure, nomination of a representative, and grievance redressal.
- Grievance Officer: Grievance Officer name/contact — to be appointed.
- Cross-border transfer of India-located data principals' data, where the DPDP Act permits it, is addressed in Section 10.
- Timeline. The DPDP Act's substantive obligations become enforceable on 13 May 2027.
8. Cookies and Tracking Technologies
Kempian's website and Platform use cookies and similar technologies, grouped into essential, functional, analytics, and marketing categories. Where the law requires it, we provide a consent mechanism to accept or reject non-essential categories, and you can change your preferences at any time. For full detail — vendor names, retention periods, and category-by-category purposes — see the standalone Cookie Policy, which governs on this topic.
9. Third Parties and Sub-Processors
Kempian shares personal data with a limited set of third parties necessary to operate the Platform:
- AI sub-processors. Kempian uses OpenAI, Anthropic, and HuggingFace to power the AI Features (see Section 4 and the AI Transparency Notice). Kempian is the deployer of these third-party models and stays responsible for their outputs, regardless of which provider generated them. Our data-handling terms with these providers are set out in the Subprocessor List and the AI Governance Statement.
- Infrastructure and operational vendors for hosting (cloud hosting provider and region), payments (payment processor), email/communications (email delivery provider), and analytics (analytics provider). See the Subprocessor List for full detail.
- Employers/agencies. Depending on a candidate's privacy state, we disclose data to the employer or agency the candidate has connected with, applied to, or been imported by. See the Candidate Privacy & Visibility Notice.
- Onward disclosure by agencies to end clients. When a staffing agency submits a candidate to its own client — for example, a hospital or health system — Kempian requires the agency to disclose this to the candidate. We log the disclosure and submission event on the candidate's Privacy Timeline.
Kempian does not sell personal data to third parties for their own independent marketing purposes.
10. International Data Transfers
Kempian operates across the EU/UK, the United States, and India, so personal data may move between these regions, including to the sub-processors described in Section 9.
When personal data from the EU/UK moves to a country without an adequate level of protection, Kempian relies on the Standard Contractual Clauses — and, for UK transfers, the UK International Data Transfer Addendum — or another lawful transfer mechanism. We apply these across our vendor and sub-processor agreements. For India-originating data, cross-border transfer is addressed in Section 7 and stays subject to India's transfer conditions under the DPDP Act.
11. Data Retention
| Data category | Retention |
| Candidate profile (self-registered, Marketplace/Connected) | 2 years from last active login, then notice + deletion unless renewed |
| Candidate profile (ATS-imported) | Governed by the importing organisation's own retention practice/instructions |
| Candidate profile (AI-discovered, uncontacted) | Auto-deleted if not contacted within 30 days of record creation |
| AI matching decision/audit records, LLM prompt & response logs | Minimum 10 years (EU AI Act Art. 12 traceability) |
| Employer/agency account data | Duration of contract + 7 years |
| Rights requests (access/erasure) records | 5 years from resolution |
| Consent records | Duration of processing + 3 years |
| Unsuccessful-applicant talent pool retention (EU guidance) | 6–12 months unless the candidate actively renews consent |
Kempian is rolling out automated retention enforcement across all data categories above as part of its ongoing compliance program.
12. Your Rights and How to Exercise Them
Depending on the law that applies to you — GDPR, UK GDPR, the DPDP Act, CCPA/CPRA, or other applicable law — you may have the right to:
- Access the personal data Kempian holds about you.
- Correct inaccurate or incomplete data.
- Erase your data, subject to exceptions such as retention required by law or AI-audit traceability under Section 11.
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interests, including AI-discovery outreach.
- Port your data — receive it in a portable format, or have it sent to another controller where feasible.
- Withdraw consent at any time, without affecting the lawfulness of processing that already happened.
Kempian runs a unified rights-request process across jurisdictions. Submit requests to privacy@kempian.com, and the appropriate regional team will handle them based on where you're located and which law applies. Candidates also have self-service tools described in the Candidate Privacy & Visibility Notice, including data export and account deletion.
13. Children and Minors
Kempian is for people 18 years of age or older. We do not knowingly collect personal data from anyone under 18.
14. Changes to This Policy
Kempian may update this Policy to reflect changes in the Platform, applicable law, or our data practices. We will notify you of material changes through the Platform or by other reasonable means before they take effect. The footer below shows the most recent revision date.
Related Documents
Read this Policy together with: the Terms and Conditions, the AI Transparency Notice, the Candidate Privacy & Visibility Notice, the Cookie Policy, the Subprocessor List, and the Data Processing Addendum.
Contact
- Privacy rights requests and general privacy questions: privacy@kempian.com
- Data Protection Officer: DPO name/contact — to be appointed, via privacy@kempian.com
- India Grievance Officer (DPDP Act): Grievance Officer name/contact — to be appointed, via privacy@kempian.com
- Enterprise procurement / DPA requests: trust@kempian.com
Kempian — Privacy Policy — v0.3 (Draft) — July 2026