AI data privacy and candidate consent

Last updated: August 19, 2026

Kula's AI features process candidate data — resumes, interview recordings, application answers, and more. This article covers what data each AI feature actually touches, whether Kula trains models on it, how AI use is disclosed to candidates, and where to point a customer's security or legal team for a deeper compliance review.

Who can do this: This is a reference article. Consent settings (once available) are configured by Super Admin and Admin under Settings → Privacy & compliance — see "Candidate privacy & GDPR consent" for that configuration in detail.

Where to find it: Org-level AI toggles live in Settings → AI & Kula teammates. Consent-related settings, where applicable, live in Settings → Privacy & compliance.


What candidate data each AI feature uses

  • Fraud detector. Resume, LinkedIn profile, email address, phone number, location, and device information captured during the application. This is cross-referenced against public information and application patterns to produce a verdict. All of it is either submitted by the candidate directly or captured automatically during application — none of it is sourced from a third party outside the application flow.

  • AI Notetaker. Interview audio, the resulting transcript, and an AI-generated summary. These are treated as your Customer Data under Kula's DPA, not Kula's own data.

  • Screener (AI Scoring). The candidate's application answers and resume content, scored against job criteria you define.

  • Coordinator. Candidate phone number, and the content of scheduling calls — every call is recorded and transcribed.

  • AI Application Assistant. Reads from data already on the candidate's profile (scorecards, emails, notes, transcripts, application details) to generate summaries and answer questions; it doesn't collect new data of its own, and it respects existing permission rules (private notes, restricted fields, offer details) rather than surfacing them more broadly.

  • Resume parsing/autofill. The uploaded resume file itself, parsed to prefill application or profile fields.

Does Kula train AI models on candidate data?

No. Kula's product team has confirmed directly that it does not train, fine-tune, or otherwise improve any AI models using customer data — including interview transcripts, summaries, or audio processed by subprocessors.

Kula's DPA declares the subprocessors that handle this data. If a customer's security team needs this in writing rather than as a support answer, route the request to your account team for a formal response rather than relying on this article as the contractual source.

How AI use is disclosed to candidates

Disclosure today isn't handled by one account-wide setting — it varies by feature:

  • Fraud detector discloses itself automatically. When enabled on a job, a disclosure that the organization uses AI to screen applications for fraud is added to that job's application page without any extra setup on your part.

  • AI Notetaker has no default recording-consent language. Kula doesn't insert anything into the interview invite by default, because the right wording varies by customer and jurisdiction — you're expected to add your own consent language to the invite if you want it there. If a candidate says they don't want to be recorded, a recruiter can turn off the Notetaker for that interview before it starts, or remove it from the call after it's already joined.

  • General AI-use disclosure today is a manual, per-job practice: add a line to the job description and/or add a Yes/No consent question as a custom application form section (Job → Job Post → Application Form → Add Section → Add Question). A dedicated Consent Management capability that would add this disclosure automatically and manage opt-outs is in active development — see the release-status caveat in Needs Verification before telling a customer it's live.

Data retention

At the account level, once a Kula account is cancelled, data is held for 15 days (during which it can still be pulled or restored on request), then permanently deleted. Access to the account itself stops immediately on cancellation or suspension — there's no grace period for continued use, even though the data itself persists briefly afterward.

At the candidate/record level, there's no explicit, customer-configurable retention or auto-deletion for AI-generated content like Notetaker transcripts and summaries today. This is intended to be addressed by the Candidate Consent Management feature (setting a consent validity period and auto-anonymizing on expiry, which would also scrub interview recordings, transcripts, and summaries) — see "Candidate privacy & GDPR consent" for what that's designed to do and its current rollout status.

Compliance resources

For broader AI-compliance questions — GDPR, EU AI Act, and similar — Kula publishes an independent third-party audit at trust.warden-ai.com/kula/ai-scoring, including an EU AI Act–specific page, refreshed via monthly audits. This is the standard first response to a customer's security or compliance review of Kula's AI, and it has been the deciding factor in at least one real enterprise deal's compliance review.


Good to know

  • Only Fraud detector's AI-use disclosure is automatic. Every other AI feature's candidate-facing disclosure is something you add yourself today — a job description line, an application form consent question, or interview invite language.

  • Kula does not train AI models on your customer data, including data processed by AI subprocessors — confirmed directly by Kula's product team, though not yet cited from a published policy document.

  • Account data is held 15 days after cancellation, then permanently deleted — useful to know if a customer asks what happens to their data if they leave.

  • There's no per-candidate, self-service retention control for AI-generated content (Notetaker transcripts/summaries) yet — this is intended to arrive via the Candidate Consent Management feature, whose current release status should be confirmed before promising it to a customer.

  • Anonymizing a candidate is not yet a complete erasure guarantee — known gaps mean some downstream systems can still act on or repopulate an anonymized candidate's data. Don't oversell this to a customer with strict erasure requirements.

  • The Warden AI trust center (including its EU AI Act page) is the right first stop for a customer's AI compliance questionnaire — it's been the deciding factor in at least one real enterprise deal.

FAQ

  • Does Kula train its AI models on our candidate data? No — confirmed directly by Kula's product team, for data processed by AI subprocessors as well as Kula itself.

  • Do we need to tell candidates AI is used in our hiring process? Increasingly this is a legal requirement in some jurisdictions. Today, add this to your job description and/or a consent question on the application form. Fraud detector is the one feature that discloses itself automatically.

  • Does Kula automatically add recording-consent language to interview invites for the AI Notetaker? No — Kula doesn't add default language because it varies by customer and jurisdiction. Add your own line to the interview invite, and turn off or remove the Notetaker for a specific interview if a candidate objects.

  • What happens to our data if we cancel our Kula account? It's held for 15 days (during which it can still be restored), then permanently deleted. Account access itself stops immediately on cancellation, not after a grace period.

  • If we anonymize a candidate, is their data completely erased everywhere? Not guaranteed yet — there's a known, open gap where some downstream systems (e-signature, the AI Coordinator, background-check resyncs) can still act on or repopulate an anonymized candidate's data. See "Candidate privacy & GDPR consent" for the full picture.

  • Where do we point our security team for an AI compliance review? trust.warden-ai.com/kula/ai-scoring, including its EU AI Act–specific page — an independent, monthly-refreshed third-party audit. For a specific law not covered there, check with your account team.

Need help?

If you have questions about AI data handling, candidate consent, or compliance documentation, reach out to us at support@kula.ai or use the in-app chat.