Our privacy policy
RepScout (“we,” “us”) provides an AI-driven recruitment platform as a data processor on behalf of our clients (the “data controllers”). We are committed to processing personal data lawfully, fairly and transparently, implementing appropriate security measures, and enabling our clients to meet their obligations under applicable data-protection laws (e.g. GDPR, UK Data Protection Act 2018). Our obligations and practices are governed by a Master Services Agreement (MSA), a Data Processing Addendum (DPA), and this Privacy Policy.
Data Protection Officer: Tim Pritchard
We process data only on documented instructions from our clients as set out in the MSA and DPA.
Typical legal bases invoked by controllers include:
We do not use candidate data for any secondary purposes (e.g. marketing) unless expressly instructed.
Data Type | Source | Activity |
---|---|---|
Candidate CV, profile details | Uploaded by client or candidate | Parsing, indexing, matching to job requirements |
Audio/video interview files | Captured by platform | Transcription, sentiment analysis, scoring |
Assessment scores & feedback | Generated by AI modules | Aggregation, reporting to controller |
User account credentials | Submitted by client admins | Authentication, authorization, audit logging |
Plan and usage metadata | Derived from platform activity | SLA monitoring, billing, and usage tracking |
Access Control
Network Security
Vulnerability Management
Incident Response
We maintain a current list of subprocessors (e.g. hosting providers, transcription engines, analytics tools).
Each subprocessor is contractually bound by a DPA to:
Current analytics-related subprocessors include:
Transfers outside the EEA/UK only under:
Clients may configure region-specific data residency (e.g. EU-only processing) as per their Order Form.
RepScout interacts with OpenAI's API (see their privacy policy here). The only data shared with OpenAI is the input you feed directly into these AI nodes when running assessments or interacting with assistants. No other information is ever exposed to the AI providers aside from what you choose to submit. We ensure that no data sent to third-party AI providers is stored or used to train their models. We ensure that these third-party providers adhere to strict data protection and privacy standards comparable to ours.
As a processor, we assist controllers with:
We implement an automated retention scheduler (per controller’s bespoke settings) that:
Default retention periods (controller-configurable) mirror industry best practice (e.g. 12 months for active candidates, 6–7 years for payroll records).
This policy is reviewed annually or upon:
Contact For questions, data-subject requests or to request our subprocessor list, please contact:
Data Protection Officer, RepScout AI Ltd. Email: tim@repscout.ai