GDPR · PDPA
This notice explains what personal data Resume Screening AI collects, why, who we share it with, and how to exercise your rights. It is a privacy notice, not a contract, and not a data processing agreement.
Last updated 20 August 2026.
Resume Screening AI (resumescreening.ai) is operated by Ksaitor Media Pte. Ltd. (UEN 201431979G), a company registered in Singapore.
133 Lorong K Telok Kurau
Singapore 425770
Singapore
Privacy requests: [email protected]. We have not appointed a data protection officer, and we have not yet appointed an EU or UK representative.
This notice covers personal data we process in three situations:
This notice covers the public site, accounts, billing, and candidate data a customer uploads, including when that customer or candidate is in the EU or EEA.
We are the controller of account data, billing data, website analytics, support mail, and of a resume a person uploads on their own behalf (for example the AI resume builder or PDF to Word).
We are the processor of candidate resumes and job descriptions a customer uploads or emails in, and of the scores and rationales we generate from them. The customer (the employer or agency) is the controller of that candidate data. They must have a legal basis to collect it and must tell candidates that automated screening is used. A signable data processing agreement is not yet published; email [email protected] if you need one before uploading EU candidate data.
Name, email, company name, profile image (if you sign in with Google), password hash or OAuth tokens, workspace membership, optional OpenAI API key if you bring your own, optional custom ranking fields, country inferred from the request (Cloudflare cf-ipcountry, stored once as signup country), newsletter preference, EU waitlist opt-in time, referral codes, and usage and credit balances.
Stripe customer and subscription identifiers, invoices, plan, and payment status. Card numbers are handled by Stripe; we do not store full card details.
Job title and description, uploaded resume files as parsed text and structured fields (name, contact details, work history, education, and anything else in the document), filenames, scores, written rationales, strengths and weaknesses, recruiter notes, and similarity embeddings. Original files are parsed and are not kept as downloadable originals after processing.
The AI resume builder may create an account from the email you verify. The PDF to Word converter sends extracted text to an AI model to check whether the file is a resume and, if it is, may store the parsed text. Calculators run in the browser and do not need an account.
Emails you send us, account-deletion reasons if you provide one, error reports (which can include user id and email), and server logs (IP address, user agent, timestamps). Inbound Mailgun messages to a job address include the sender, subject, and attached resumes.
We do not collect video, voice, photos of faces, biometrics, or emotion data. We do not scrape social profiles. We do not buy marketing lists of candidates.
Where GDPR applies, we rely on the following bases in Article 6. We do not use candidate resumes to train our own foundation models.
New accounts are added to the product-update list by default. That is service communication about a product you asked for, not a third-party marketing list. Turn it off in Settings at any time.
When you upload or email in someone else's CV, you instruct us to parse it, store the text, compute embeddings (contact details are stripped before embedding), and score it against your job description. Name, email, and phone are removed from the text sent to the ranking model. Graduation years, school names, and other identity signals can still appear in that text. The recruiter view still shows the original name.
You must only upload data you are allowed to process. If you screen people in the EU or EEA, tell them in your own privacy notice that automated processing is used, what it does, and that a person makes the hiring decision. See our EU AI Act and hiring-law page for the employer-side duties.
Candidates who want access or deletion of a CV we hold because an employer uploaded it should contact that employer first. We will help the employer fulfil the request. Candidates who used a public tool themselves can email [email protected].
We use AI models to parse documents, compute similarity, and produce a score and a written rationale against the job description you supply. The product does not reject, advance, hire, or contact a candidate. A person reviews the ranked list and decides.
That is decision support, not a solely automated decision by us that produces legal effects (GDPR Article 22). If you treat the score as the decision and never deviate from it, Article 22 can still apply to you as the employer. Keep a human who is able to disagree.
The AI resume builder is a chatbot. You are interacting with an AI system, not a human recruiter.
We do not sell personal data. We share it with the providers who run the service, and only as needed for the purpose listed. Workspace members see the jobs and resumes in that workspace.
| Provider | What they do | Region |
|---|---|---|
| OpenAI | Resume parsing, ranking, embeddings, resume-builder chat, document classification | United States |
| Voyage AI | Resume and job embeddings, when configured | United States |
| Amazon Web Services | Amazon Textract for document text extraction | United States |
| Cloud Vision OCR fallback, Google sign-in / One Tap, Google Analytics | United States | |
| Stripe | Payments, subscriptions, invoices, billing portal | United States / Ireland |
| Mailgun | Sign-in and transactional email, inbound job applications, product-update list | United States |
| Loops | Product events and contact records for email programmes | United States |
| Functional Software (Sentry) | Error monitoring (may include user id and email) | United States |
| Hotjar | Session analytics, when the Hotjar id is configured | EU, with possible onward transfers |
| Plausible (self-hosted) | Cookieless page analytics at plausible.cjl.ist | Our analytics host |
| Cloudflare | CDN, TLS, and country detection used for the EU pause | Global |
If you paste your own OpenAI API key in Settings, ranking and parsing calls for your workspace go through that key under OpenAI's terms with you.
We may disclose data if required by law, to protect the service, or in a merger or sale of the business, with notice where the law requires it.
We are established in Singapore. Resume text and account data are processed by providers in the United States and other countries that are not covered by an EU adequacy decision. Where GDPR applies, those transfers rely on the provider's GDPR terms and, where they offer them, Standard Contractual Clauses. We do not yet offer EU-region processing or zero-retention agreements with model providers.
You can delete your account in Settings. That removes the user, jobs, workspace membership, and Loops contact. Email [email protected] if you also need a stored resume record removed (including one created via PDF to Word) or a copy of the data we hold about you. Complete, verified erasure of every derived copy (embeddings, caches) is still being tightened.
Where GDPR or a similar law applies, you can ask us to:
Email [email protected]. We may need to verify that the request comes from you. For candidate CVs uploaded by a customer, we will usually point you to that customer and assist them.
You can complain to your local supervisory authority. In Singapore you can contact the PDPC. EU and EEA residents can contact the authority in their country of residence (for example CNIL, BfDI, ICO for the UK after Brexit).
We do not sell personal information. If you are in California you can make the same access and deletion requests at the email above.
We use the following cookies and similar technologies:
rsa_cookie_consent remembers Accept or Reject for six months.Analytics cookies are not strictly necessary. Visitors in the EU and EEA (detected from Cloudflare's country header) see a consent banner before Google Analytics or Hotjar load. Reject is as available as Accept. Plausible does not use cookies and is not gated. .
The service is for recruiting and workplace use. It is not directed at children, and we do not knowingly collect data from anyone under 16.
We use TLS in transit, access controls on the application and database, and hashed passwords. No method of transmission or storage is perfectly secure. If we become aware of a breach that requires notice, we will tell affected customers and authorities as the law requires.
We will update this page when our practices change. The date at the top is the latest version. Material changes will be flagged on this page and, where they affect customers, by email or an in-product notice.
Ksaitor Media Pte. Ltd.
133 Lorong K Telok Kurau, Singapore 425770
[email protected]
Related: Terms of Service, EU AI Act and hiring laws.
Keep reading