Skip to main content
RecruoRecruo

Security & Compliance

Built for Companies Where Data Privacy Isn't Optional

GDPR-ready, encrypted in transit (TLS 1.2+) and at rest (AES-256), with every AI assessment reviewed and signed off by a human recruiter.

Overview

An agency model built around accountable AI

Recruo is a recruitment agency that uses AI agents to screen and interview engineering candidates — and keeps a human recruiter accountable for every decision. The AI drafts the assessment; a person reviews it, signs it off, and owns the shortlist that reaches your team. No candidate is ever rejected by a fully automated decision.

That model shapes how we handle data. Candidate data is processed on a consent-first basis under GDPR, every AI scoring decision leaves an audit trail, and the human-in-the-loop workflow maps directly onto the EU AI Act's requirements for high-risk hiring systems.

GDPR
AES-256
AI Ethics
Consent-First
EU-Ready

GDPR Compliant

Full compliance with EU data protection regulations. Data processing agreements, candidate consent flows, right to deletion, and data retention policies — all built in.

AES-256

Encryption in Transit & at Rest

Encrypted in transit (TLS 1.2+) and at rest (AES-256). Video sessions, scorecards, and candidate data are covered at both layers.

Ethical AI

Full Transparency

Candidates are always informed upfront that the pre-screen is conducted by an AI agent. No hidden recordings, no deceptive practices.

Opt-In

Candidate Consent

Built-in consent flows before every interview. Candidates control their data with clear opt-in, access requests, and deletion rights.

Human-Reviewed

AI Ethics & Safety

Every AI assessment is reviewed and signed off by a human recruiter. Bias monitoring, explainable scoring, and regular audits of model outputs.

Configurable

Data Retention Controls

Configurable retention periods per client. Automatic data purging after defined windows. Your data, your rules.

Questions about security or compliance? Contact us about security & compliance

Data protection

How candidate and client data is handled

Encryption at both layers

Encrypted in transit (TLS 1.2+) and at rest (AES-256) — covering video interview sessions, scorecards, and candidate records.

Controller and processor roles

We act as a data controller for our own operations and as a data processor when we handle candidate data on behalf of clients — governed by a Data Processing Agreement included in every enterprise contract.

Retention and deletion

Retention periods are configurable per client, with automatic purging after defined windows. Candidate data is kept no longer than the recruitment process requires — and is deleted on request.

No special-category data

We do not collect sensitive personal data — nothing revealing racial or ethnic origin, health, biometrics, or political or religious beliefs.

Cross-border safeguards

Where personal data is transferred across borders, contractual clauses with our partners and service providers provide adequate protection, as set out in our privacy policy.

The full detail, including legal bases and cookie usage, lives in our privacy policy.

AI compliance

Human oversight that maps to Article 14

AI systems used for recruitment and selection are classified as high-risk under Annex III of the EU AI Act. The hardest requirement to meet honestly is Article 14 — human oversight that is real, not a rubber stamp.

Transparency (Article 13) is handled at the source: candidates are notified in writing that AI is used before the interview begins, with a consent step at the start of every session. Every engagement ships with a compliance checklist covering notification, audit trails, bias audits, and human review rights.

EU conformity-assessment standards for high-risk AI are still being finalised ahead of the December 2027 deadline, so we track CE marking and EU database registration requirements as they land rather than claiming a certification that does not exist yet.

Interpretability

Every AI assessment ships with explainable reasoning a recruiter can understand — a scorecard with evidence, not just a number.

Ability to override

A human recruiter reviews every AI assessment and can overrule it. No shortlist reaches a client without human sign-off.

Empowered humans

AI is a recommendation engine, not a decision-maker — the recruiter owns the decision, organisationally and in practice.

Recorded oversight

Evaluations and human overrides are logged in a full audit trail of AI scoring decisions, retained for 5+ years.

Candidate rights

The candidate owns the data

Processing is consent-first: candidates are told upfront that the pre-screen is conducted by an AI agent, consent is collected before every interview starts, and we never share candidate information with third parties without explicit consent.

Access — request a copy of the personal data we hold

Rectification — correct inaccurate or incomplete data

Erasure — have personal data deleted on request

Restriction — pause processing while a request is resolved

Objection — stop processing based on legitimate interest

Portability — receive data in a reusable format

Withdrawal of consent — opt out at any time

Human review — of any AI assessment

Requests go to the contact below. We respond within the statutory period and typically resolve requests within one month.

Security practices

What runs on every engagement

Beyond encryption, the interview pipeline is built to keep sessions honest and decisions traceable:

Consent gates before every interview — candidates opt in before any session is recorded or assessed.

Audit logging of every AI scoring decision, including human overrides, retained for 5+ years.

An anti-cheat layer flags screen sharing, suspicious latency, copy-paste behaviour, and eye-tracking anomalies — flagged candidates are re-interviewed by a human.

Recruo Secure Browser fully locks the candidate session on Retained mandates (no tab switching, no external apps), available as an add-on on other plans.

Bias monitoring on model outputs, with quarterly audits across gender, age, disability, and ethnicity shared with every engagement.

Contact

Security & privacy questions

Questions about security, GDPR, the EU AI Act, DPAs, or a data subject request go to [email protected] — the same contact listed in our privacy policy. If your security review needs detail beyond this page, ask: we'll tell you exactly what is in place and what is not.

Integration trust

Evaluation integrations still need auditability.

API and MCP access should keep candidate data controls, human review, and auditable scorecard evidence visible in the workflow, rather than turning hiring decisions into an opaque automation step.

Your next senior hire
shouldn't take 6 weeks.

Get a pre-validated shortlist of 3–5 engineers in 5 business days. At a success fee well below the 22–33% classical agencies charge. EU AI Act aligned by design.