Recruiter Code of Conduct
Professional-conduct standards for recruiters using Kempian: privacy, communication, and responsible AI use.
This Code sets out professional-standards expectations for recruiter users of Kempian.
> *This document is part of Kempian's Trust Center documentation. It is reviewed periodically and does not constitute legal advice. Draft v0.2 — pending final legal review before publication.*
This Recruiter Code of Conduct ("Code") sets out professional-standards expectations for recruiter users of Kempian — both in-house recruiters and agency/staffing recruiters. It applies in addition to the general obligations in the Kempian Terms and Conditions, and adds more specific rules for recruiters. Recruiters using Kempian agree to comply with this Code as a condition of continued access to the Platform.
This Code should be read alongside the AI Acceptable Use Policy (detailed rules on permitted and prohibited uses of Kempian's AI Features), the AI Transparency Notice (how Kempian's AI Features work and their current limitations), the Candidate Privacy & Visibility Notice (the four-state privacy model in full), and the Privacy Policy.
1. Purpose and Scope
This Code applies to every individual recruiter user of Kempian, whether employed directly by a hiring organisation ("in-house") or by a staffing or recruitment agency acting on a client's behalf ("agency"). It governs how recruiters interact with candidates, handle candidate data, use Kempian's AI Features, and conduct onward submission of candidates to third-party clients. Organisation accounts are responsible for making sure their recruiter users know about this Code and comply with it.
2. Professional Behaviour Standards
Recruiters agree to always treat candidates respectfully, professionally, and without abuse. This includes:
- responding to candidate messages, applications, or connection requests promptly, without unnecessary delay, once a recruiter has initiated contact;
- using courteous, professional language in all candidate-facing communications, including AI-assisted or AI-drafted messages a recruiter chooses to send;
- not using the Platform to harass, intimidate, demean, or discriminate against a candidate; and
- treating candidate time and effort (for example, time spent on an application or interview process) as a professional courtesy owed a response, wherever reasonably practicable.
3. Privacy Obligations and the Four-State Model
Kempian's candidate records each carry one of four privacy states — Internal, Marketplace, AI-Discovered, or Connected — which determines what a recruiter may see and do with respect to that candidate. Full detail is set out in the Candidate Privacy & Visibility Notice; recruiters are expected to understand and respect that model. In summary, recruiters must:
- Not attempt to extract, infer, or independently verify hidden contact details for candidates in the Marketplace or AI-Discovered states. Where contact information is not shown, this is a deliberate platform control, not a gap to work around. Recruiters must not attempt to identify a candidate's direct contact details outside the Platform — for example, by searching external sources or contacting mutual connections.
- Use the platform-relay or AI-mediated outreach channel as designed for Marketplace and AI-Discovered candidates. Do not attempt to contact them any other way while they remain in a non-connected state.
- Not re-contact a candidate outside the Platform once the candidate has declined an outreach, connection request, or opportunity. Recruiters must respect a candidate's decision not to proceed. They must not use information learned through the Platform to pursue that candidate through other channels after a decline.
- Recognise that certain visibility rules are fixed platform invariants — no organisation setting can override them. For example, an AI-Discovered candidate's contact data is never exposed before they respond to outreach. And a Connected candidate's own field-level sharing permissions always control, regardless of any organisation-level configuration.
If a recruiter is unsure whether an action fits a candidate's privacy state, they should apply the more restrictive interpretation and, where appropriate, ask for guidance internally before proceeding.
4. Candidate Communication Standards
Recruiters agree to:
- represent open roles accurately, including compensation (where disclosed), location, seniority, and core requirements, and not to materially overstate or misrepresent a role to induce a candidate to engage;
- avoid misleading job descriptions, including AI-generated draft descriptions that have not been reviewed for accuracy before being shown to a candidate (see Section 6);
- provide candidates with reasonably timely status updates as they progress (or do not progress) through a hiring process, recognising that recruiters generally do not control an employer's ultimate hiring timeline; and
- avoid "ghosting" candidates — that is, ceasing communication with a candidate who has engaged in an active process without any status update or closure. This is an aspirational standard reflecting good recruiting practice. Recruiters should make reasonable efforts to provide closure to candidates who have reached later stages of a process (for example, after an interview). Resourcing and volume may limit what's practicable at earlier stages.
5. Consent and Disclosure Obligations
Recruiters must obtain and respect candidate consent as embedded in the Platform's design, and must not attempt to bypass the relay-messaging or connection model described in Section 3. Specifically, recruiters must:
- rely on the consent and disclosure mechanisms built into the Platform (connection requests, relay messaging, AI-mediated outreach) rather than seeking to obtain candidate consent or contact information through informal or off-platform means;
- honour a candidate's opt-out, objection, or decline promptly, and not attempt to re-engage a candidate who has opted out through any channel, on-platform or off; and
- if a candidate raises a data-protection request or objection (for example, a request not to be contacted, or a request about their data), route it through the appropriate in-platform mechanism or escalate it to privacy@kempian.com. Do not attempt to resolve it informally outside the Platform's audit trail.
Kempian records all consent, disclosure, and access events relating to a candidate on that candidate's Privacy Timeline, as described in the Candidate Privacy & Visibility Notice. Recruiters should assume their platform actions are logged as part of that record.
6. Fair Hiring and Non-Discrimination
Recruiters must comply with applicable equal-employment and anti-discrimination law in every jurisdiction in which they recruit or hire, including (as applicable):
- U.S. federal and state law, including Title VII of the Civil Rights Act and EEOC guidance on disparate impact and algorithmic hiring tools;
- EU/UK non-discrimination and equal-treatment principles, including the non-discrimination principles reflected in the GDPR's approach to automated processing; and
- India's equal-opportunity norms applicable to employment.
In addition, recruiters must not:
- use an AI-generated match score, ranking, or explanation to justify a discriminatory screening decision, or rely on an AI output to hide or excuse a decision that is itself discriminatory;
- use a protected characteristic (or a proxy for one — for example, a name, neighbourhood, school, or career-gap pattern standing in for age, gender, ethnicity, disability, pregnancy, or another protected ground) as a basis for filtering, ranking, or rejecting a candidate; or
- request or use information about a candidate's protected characteristics except for a legitimate, lawful purpose that the relevant jurisdiction expressly permits (for example, lawful equal-opportunity monitoring carried out through an appropriate, separate process).
Recruiters remain personally and professionally responsible for the lawfulness of their own hiring-related decisions and conduct. Kempian's AI Features do not transfer or diminish that responsibility. See Section 7 below.
7. Responsible Use of AI Tools
Recruiters using Kempian's AI Features (Candidate Matching, Resume Parsing, the Job Creation Assistant, and the Chat Assistant) agree to:
- review AI-generated match scores, rankings, and outreach drafts before acting on them. AI outputs are recommendations or drafts only. They are designed to support, not replace, a recruiter's own judgment;
- never treat an AI match score or ranking as the sole or automatic basis for rejecting, deprioritising, or declining to consider a candidate. A rejection or deprioritisation decision must reflect the recruiter's own review, not an unreviewed AI output;
- review and correct AI-generated or AI-derived candidate profile fields (for example, resume-parsed data) whenever the recruiter becomes aware they are inaccurate. This is a matter of good practice and a requirement of this Code, consistent with the Human Review Gate described in the AI Transparency Notice; and
- review AI-generated job descriptions and outreach messages for accuracy and appropriateness before sending or publishing them, consistent with Section 4.
The AI Acceptable Use Policy sets out detailed, feature-by-feature rules on permitted and prohibited AI use, and recruiters must separately comply with it. This section summarises the professional-conduct expectations that apply specifically to recruiters' use of AI outputs in candidate-facing decisions.
8. Data Handling Obligations
Recruiters agree to:
- not export candidate data outside the Platform, except where the recruiter's organisation already has an independent, lawful basis for that data (for example, an Internal-state record already lawfully held in the organisation's own ATS). Any such export must also be consistent with the Terms and Conditions, the Candidate Privacy & Visibility Notice, and the Privacy Policy;
- not share Platform login credentials with any other person, including colleagues at the same organisation — each individual recruiter should use their own account;
- keep any candidate data a recruiter is permitted to access confidential and use it only for the recruiting purpose for which it was made available; and
- promptly report suspected data incidents to security@kempian.com or the applicable internal escalation contact, as soon as reasonably practicable after becoming aware of the issue. This includes suspected unauthorised access, suspected data loss, or a suspected breach of this Code by another user.
9. Agency-to-Client Onward Submission
If an agency recruiter wants to submit a candidate's profile to a third-party end client (for example, via a vendor management system or a client-facing view), the recruiter must tell the candidate before the submission occurs. Kempian logs this disclosure as part of the candidate's Privacy Timeline (see the Candidate Privacy & Visibility Notice).
Recruiters must:
- follow current in-platform guidance for onward submission (see also the Terms and Conditions and the Candidate Privacy & Visibility Notice); and
- escalate to privacy@kempian.com or the relevant internal contact if unsure how to proceed in a specific case.
10. Consequences of Violation
Violation of this Code may result in escalating consequences, consistent with the suspension and termination provisions of the Terms and Conditions, including:
- a warning and requirement to remediate the conduct;
- temporary suspension of Platform access, including suspension of specific features (for example, AI-mediated outreach or export functionality);
- termination of the recruiter's account or, where the conduct is attributable to an organisation's pattern of use, termination of the organisation's account; and
- where applicable, reporting to the relevant employer or agency organisation, and cooperation with lawful requests from regulators or affected candidates.
The severity of any consequence will generally reflect the nature, intent, and impact of the conduct, and whether it is a first or repeated instance. However, Kempian reserves the right to act immediately and without prior warning in cases of suspected fraud, discrimination, harassment, or a serious data-protection violation, consistent with the Terms and Conditions.
Related Documents
This Code should be read together with: the Terms and Conditions, the Privacy Policy, the Candidate Privacy & Visibility Notice, the AI Transparency Notice, and the AI Acceptable Use Policy.
Kempian — Recruiter Code of Conduct — v0.3 (Draft) — July 2026