A page you can forward to your legal team.
It should answer the questions a data protection officer will ask, without a meeting. If anything here is not clear enough to act on, that is a defect and we want to hear about it.
Region
Frankfurt, European Union
Default retention
30 days
Who decides
Always a person at the employer
Consent
Obtained by the employer, not by Candora
01
Where the data sits
The application, the database and the serverless functions that handle requests all run in the Frankfurt region.
What is not certified: we hold neither SOC 2 nor ISO 27001. An audit costs months and money and we have not done one. Everything on this page can be checked without a certificate, and where it cannot, that is written down.
- The CV file is parsed in memory and never written to disk or to storage
- Only company and domain details go to external sources. A candidate name never leaves Candora
- Row level security on every table, tenant isolation enforced by the database, not by application code
- Fonts are self-hosted, so no request leaves the browser for a third party
02
What happens to the data over time
A candidate's personal data is removed once the retention period passes. Findings and rule feedback remain with no link to a person, because they are data about the rules. The default period is 30 days, 90 days for expiry monitoring, and it is set per organisation.
- The clock starts at the last check, not at the application date
- Erasure removes claims, findings and source queries, not just a profile
- Anonymisation is not the same as erasure: it keeps the record that a run happened and strips the link to a person. It is used for operational statistics, never as a substitute for erasure
- The audit trail is append-only. The application role has no update or delete rights on the event table, and a database trigger enforces it a second time
- Rule thresholds live in versioned data, so a past decision can be reconstructed with the rules that applied then
03
Who can reach the data
Nobody outside this list.
| Who | Where | Why |
|---|---|---|
| Vercel | Frankfurt region, European Union | Running the application and its serverless functions. |
| Vercel Web Analytics | European Union | Visit counts for the website. Stores no cookies and does not identify a visitor. |
| Resend | eu-west-1 region, European Union | Delivering a message sent from a form on the website. |
Vercel
- Where
- Frankfurt region, European Union
- Why
- Running the application and its serverless functions.
Vercel Web Analytics
- Where
- European Union
- Why
- Visit counts for the website. Stores no cookies and does not identify a visitor.
Resend
- Where
- eu-west-1 region, European Union
- Why
- Delivering a message sent from a form on the website.
This list covers the website.
- No automated decision about a person. There is no path to a rejection in the product, and a test enforces it
- No summary value for a person. That is not a presentation choice, it is a schema-level constraint
- No emotion recognition, no deception detection, no biometric template, no inference from behaviour
- Special categories under Article 9 GDPR are never extracted, stored or displayed, even when a CV offers them
05
Your rights and how to use them
This section is for you as a candidate, not for the employer.
- Access
- You get a listing of what is held about you, including sources and query times.
- Correction
- If a field is wrong it gets corrected, and the audit trail keeps the fact that it was.
- Erasure
- Claims, findings and source queries are deleted, not just a profile.
- Objection
- You can dispute a specific finding.
We answer within one month at the latest, as Article 12(3) GDPR requires.
A person answers, not a form and not a bot.
Is something here not clear enough for your DPO?
Send the question and you get a written answer, not an invitation to a call.