logo
Terms

Terms & Conditions

1. Introduction and scope

Applyfin B.V., a private limited liability company under Dutch law, having its registered office in Utrecht and its place of business at Wittevrouwenstraat 38B, 3512 CV Utrecht, the Netherlands, registered in the trade register of the Chamber of Commerce under number 92570968 (hereinafter: Applyfin, “we”, “us”), is a combined Recruitment Process Outsourcing (RPO) and ATS service provider.

We operate a multi-tenant SaaS Applicant Tracking System with which employers manage their recruitment and selection process, and in addition we carry out, in whole or in part, recruitment and selection activities on behalf of our clients. Our RPO services include, among other things, vacancy marketing and media distribution, active candidate sourcing, pre-selection and screening, candidate communication, and the management of talent pools.

This policy applies to:

  • Our marketing website applyfin.com and related domains;

  • The Applyfin Platform used by our clients;

  • The career pages that we host on behalf of our clients on the (sub)domains linked by them;

  • All RPO and related services that we offer.

We attach great importance to careful and transparent handling of personal data and comply with:

  • The General Data Protection Regulation (GDPR/AVG)

  • The EU AI Act

  • The ISO 27001 standard for information security

Where in this policy we refer to an employer’s segregated environment, we mean the Company: the corporate environment that the employer creates and manages within the Platform, and in which its data, users and vacancies are held. By Data Supplier we mean the specialised external service provider that we query at an employer’s search request (see 4.5). Both terms have the same meaning as in our general terms and conditions and data processing agreement.

2. Processor vs. controller

Which role Applyfin fulfils under the GDPR depends on who determines the purposes and means of the processing.

2.1 Applyfin as processor. For personal data processed within the Applyfin Platform on behalf of our clients, including data of applicants, candidates and referees, and activities such as vacancy marketing, candidate sourcing, pre-selection and candidate communication, we act as processor within the meaning of Article 4(8) GDPR.

In these situations the employer-client is the controller and determines the purposes, legal bases and retention periods. Our mutual obligations are laid down in a data processing agreement as referred to in Article 28 GDPR.

Responsibility follows actual conduct. In the delivery and onboarding of the platform we actively support our clients in meeting the applicable requirements, including the GDPR and the EU AI Act. In doing so we apply the principle that whoever actually carries out a processing operation, delivery or intervention bears responsibility for it. Our responsibility therefore covers in any event:

  • the technical configuration of the platform and the default settings with which it is delivered;

  • the technical operation and the default settings of the Consent functionality, as well as its configuration insofar as we provide that — during onboarding or in the context of support;

  • all AI applications and automated workflows that we develop, deliver and operate within the platform (see also section 9);

  • all changes that we implement and all services that we perform in the context of support and service activities;

  • in the case of managed delivery (RPO): the lawful performance of the recruitment activities that our staff carry out on behalf of the employer, including the duty to inform upon first contact with a candidate (see 4.9).

Demarcation with the client’s responsibility. The client is responsible for the changes and data that it implements or enters into the platform itself, for its own configuration choices, for the setup of the Consent functionality insofar as it carries out or modifies that itself, for maintaining it and for the choice of which non-essential techniques it deploys, and for the lawfulness of the data it enters (see 2.3). Which actions have been performed by Applyfin and which by the client is recorded in the platform’s activity logs, so that this division of responsibility is traceable at all times.

Measures. In our role as processor we take appropriate technical and organisational measures to protect personal data; these are set out in more detail in section 8. The division of responsibility and liability between Applyfin and the client is laid down in the data processing agreement and the general terms and conditions.

2.2 Applyfin as controller. For data that we process for our own business operations, including data of visitors to applyfin.com, prospects, and the business contacts and users of our clients, we determine the purposes and means ourselves. For this processing we are the controller within the meaning of Article 4(7) GDPR.

In addition, we maintain one processing operation that concerns candidates and for which we are the controller ourselves: the suppression list with which we give effect to an objection raised across all of our clients (see 3.3).

2.3 Responsibility of our clients. As controllers, our clients bear their own responsibility for the lawfulness of the processing within their use of the platform. This includes, among other things, a valid legal basis when entering personal data and when commissioning a search, maintaining and correctly configuring the Consent functionality within their own environment, safeguarding GDPR compliance in their own integrations and API connections, and granting access to personal data exclusively to persons authorised to have it.

2.4 Practical consequences for data subjects. Applicants and candidates who have responded to or been approached for a vacancy of a specific employer should address questions or requests primarily to that employer; we support our clients in handling these in a timely and correct manner. For processing operations for which Applyfin is itself the controller, including the suppression list, you can contact us directly via the contact details at the bottom of this statement.

3. Which personal data we process

Data processed via anonymous labour market and campaign metrics (see 4.6), or via anonymised server-side tracking (see 4.8), does not qualify as personal data and falls outside the scope of this section.

In this section we distinguish between processing operations for which Applyfin is the controller, and processing operations for which our client is the controller and Applyfin acts as processor. Which role applies determines to whom you should address a request (see section 2 and section 10).

A. Processing operations for which Applyfin is the controller

3.1 Visitors to applyfin.com and prospects. Name, email address, telephone number, organisation name, job title, correspondence and any data you provide yourself via forms; technical data such as IP address, browser type, device information and visit statistics (insofar as processed with consent).

3.2 Clients and their users. Name and contact details of contact persons and users within client organisations; login credentials; usage data and audit logs; invoicing and payment data (including bank account number or SEPA mandate); contractual and commercial correspondence.

3.3 Suppression list. If you object to being approached or indicate that you do not wish to be approached again, we delete your data and record an irreversible hash value of your email address or profile identifier in a central suppression list. A hash value is an encrypted representation that cannot be traced back to the original data. We do not retain any readable personal data in this respect: the list contains only that hash value and the date of inclusion.

This list is the only processing of candidate data for which we are the controller ourselves. This is necessary because otherwise your objection would apply only at the employer with which you lodged it, and you would come into view again at the next search by another employer. With every search we check the results against this list.

B. Processing operations for which our client is the controller (Applyfin as processor)

In order to fill vacancies, we process personal data of applicants and candidates on behalf of our clients. This data reaches the platform via two routes — the candidate applies themselves, or the candidate is found through a search carried out within the platform — and may subsequently, with consent, be included in the employer’s talent pool. In all of the cases below, the employer-client is the controller: it determines the purpose, legal basis and retention period. Applyfin processes exclusively on the client’s orders and instructions.

3.4 Applicants who apply themselves. Where a candidate responds to a vacancy themselves — via a career page hosted by us or via a linked job board — we process name and address details, contact details, date of birth, CV and cover letter, education and employment history, application status, correspondence between applicant and employer, screening and assessment results, and any additional data requested by the employer.

If the employer has an applicant screened as described in 4.4, we also process additional professional profile data and the source from which it originates.

3.5 Candidates found through a search. Our clients can, whether or not they purchase RPO services, carry out a search within the platform in order to proactively find suitable candidates for a specific vacancy. If the employer purchases managed delivery (RPO), our staff set up and carry out that search on the employer’s behalf and compile the shortlist; in all other cases the employer does so itself. We do not maintain a candidate database of our own: every search is carried out with the Data Supplier at that moment, and the results are shown exclusively to the commissioning employer (see 4.5).

If candidates are selected from those results for the shortlist, we create a record of those selected candidates within the employer’s segregated environment. In doing so we process name, job title and employer, current and previous positions, educational background, skills, location indication, a reference to the candidate’s public profile, enriched contact details including email address and telephone number, and the source from which the data originates.

The non-selected results are not stored. They remain in a temporary cache for a maximum of thirty minutes only, so that a repeated search does not have to be carried out again, and are then automatically erased.

The employer decides on carrying out a search, on compiling its shortlist and on approaching a candidate, and does so on its own legal basis as an employer; if Applyfin performs those actions on its behalf, the employer remains the controller and Applyfin bears responsibility for the lawful performance thereof. We strictly limit the processing to data that is relevant to a possible professional match. We do not process special categories of personal data, unless the employer has a legal basis for this and we have made an additional arrangement in this respect.

3.6 Talent pool participants. Our clients can maintain their own, client-specific talent pool within the platform. For candidates who — whether or not following an earlier application or active approach — have consented to inclusion in an employer’s talent pool, we process additional data such as preferences, availability and interest in specific roles or sectors, and the recorded consent (time, scope and withdrawal). The employer is the controller for its talent pool and determines the purpose, legal basis (usually consent), retention period and the moment of reconfirmation; we process exclusively on its instructions.

3.7 Referees. If an applicant or candidate names you as a reference, we process your name, your relationship to the data subject, your business contact details and the reference you give together with the associated correspondence. This data is used exclusively in the context of the application procedure for which you have been named. The employer is the controller for this.

3.8 Visitors to our clients’ career pages. If you visit a career page that we host on behalf of an employer, we process on behalf of that employer data that may qualify as personal data: IP address, device and browser data, session and visit data and the consent you have given. The employer is the controller for this and determines, via the Consent functionality, which non-essential techniques are deployed. Processing based on anonymised data (see 4.8) falls outside this.

4. How we collect personal data

We collect personal data via various channels, depending on your role and your interaction with our services. The role that Applyfin fulfils per processing operation — controller or processor — follows from section 3. Anonymised flows (server-side tracking, see 4.8, and campaign metrics, see 4.6) fall outside the scope of this section.

A. Collection for which Applyfin is the controller

4.1 Directly from you. When you visit our website, complete a form, request a trial account or contact our sales or support department, we collect the data that you actively provide yourself.

4.2 From our clients and their users. For the management of client organisations and their user accounts, we collect and retain name and contact details of contact persons and users, login credentials, usage and audit data, and invoicing and payment data. This data is stored in our centrally managed (global) database and not within an individual client’s segregated environment. For this data Applyfin is the controller (see 3.2) and we bear responsibility for its lawful processing and security.

4.3 Via automated system and security logs. In order to safeguard the security, stability and traceability of the platform, we automatically generate logs containing, among other things, IP address, timestamp, browser signature and the action performed.

B. Collection for which our client is the controller

Personal data of applicants and candidates reaches the platform because the candidate applies themselves, because a search is carried out within the platform and candidates are shortlisted, or because the employer enters or uploads the data itself (manually or via integrations). This data is stored within the segregated environment of the employer concerned.

4.4 Directly from applicants. When you apply via a career page that we host on behalf of an employer, or via a linked job board, we collect the data that you provide yourself for the purposes of your application (see 3.4). After you have applied, the employer retains the right to screen your candidacy. In this screening we process both the data you have provided yourself and additional data from public sources and from the Data Supplier (see 4.5), insofar as relevant to assessing a possible match with the role. The employer is the controller for this and determines the purpose and legal basis; we process exclusively on its instructions.

4.5 Via the Data Supplier, at the employer’s search request. If a search is carried out within the platform for a specific vacancy (see 3.5), or an applicant is screened as described in 4.4, we query the Data Supplier at that moment on behalf of the employer. The Data Supplier compiles, updates and enriches professional profile data, drawing on publicly accessible and professional sources, such as professional networking sites, sector-specific platforms and CV databases for which the data subject has given consent to the provider of that database.

We do not maintain a candidate database of our own and query the Data Supplier exclusively on the instructions of an employer with a specific vacancy. In doing so, the Data Supplier acts as a sub-processor under the data processing agreement with that employer (see section 7). We assess this service provider in advance and periodically on the lawfulness of its data collection and record this contractually.

Results that are not selected are not stored; see 3.5 for the temporary cache. On request we will share the specific source from which your data originates, and you can object or request no longer to be approached (see 3.3 and section 10).

4.6 Via job board, distribution and market data partners. We receive application data from job boards and vacancy distribution partners (including Indeed, LinkedIn and related platforms) when a candidate applies via those channels for a vacancy distributed by or on behalf of an Applyfin client. We process this application data on behalf of our clients, within the segregated environment of the employer concerned (see 3.4). In addition, we receive campaign and labour market metrics from media partners in the context of vacancy marketing and posting; this data is aggregated and anonymised, does not qualify as personal data and falls outside the scope of section 3.

C. Cookies and tracking (role depends on the environment)

On our corporate website (applyfin.com), Applyfin is the controller for the tracking; on the career pages that we host on behalf of employers, the employer concerned is the controller and Applyfin acts as processor (see 3.8). In both environments we strictly separate processing operations involving personal data from processing operations based on anonymised data, in accordance with the GDPR and Article 11.7a of the Dutch Telecommunications Act.

4.7 Cookies and client-side tracking. We place cookies that are strictly necessary for the functioning of the service — such as session management, language preference, security and protection against misuse; the statutory exception to the consent requirement in Article 11.7a(3) of the Dutch Telecommunications Act applies to these. If you give explicit consent via our cookie banner, we process additional data that may indeed qualify as personal data, such as a full IP address, behaviour across multiple sessions, and attribution and conversion data, on the basis of your consent (Article 6(1)(a) GDPR). You can withdraw this consent at any time via the cookie settings, without consequences for your use of our services.

All non-essential techniques loaded via the platform are managed via our tag manager and are activated only after consent has been obtained. As long as that consent is absent, no data is sent to third parties.

4.8 Server-side tracking (anonymised, without consent). In order to measure general usage, optimise performance and safeguard security, we apply server-side tracking in which data is already anonymised on the server side: IP addresses are truncated immediately upon receipt, we do not place identifying cookies or fingerprints, and we do not link sessions or visits to an individual visitor. Data is used exclusively in aggregated and statistical form. This data qualifies as anonymised within the meaning of recital 26 GDPR, is not traceable to an individual and does not require consent. We keep this flow technically and organisationally separate from the flow for which consent has been given, so that subsequent linking is excluded; we check this periodically.

A detailed overview of the specific cookies and pixels deployed on our sites can be found in our cookie statement.

D. Duty to inform in respect of data that we have not obtained from you

4.9 How and when you are informed (Article 14 GDPR). If your data does not come from you, but via a search with the Data Supplier (see 3.5 and 4.5), you will be informed of this in accordance with Article 14 GDPR, at the latest at the moment you are first approached.

Who informs you depends on who approaches you. If Applyfin carries out the recruitment on behalf of the employer (managed delivery), we inform you ourselves. If the employer approaches you directly, that obligation rests on the employer; to that end we make standard texts and functionality available within the platform with which the required information is included in the first message.

In both cases, that first message states on whose behalf you are being approached, for which role, and from which source your data originates. For the legal basis, the retention period and your rights, reference is made to this policy, a link to which is included in that message.

If you are placed on a shortlist but are not approached within one month of that placement, your data is deleted or anonymised. Results of a search that do not end up on a shortlist are not stored (see 3.5); no duty to inform arises for that data, because it is not retained and does not lead to an approach.

If, in response to an approach, you indicate that you are not interested or you object, we delete your data and record a hash value in our suppression list (see 3.3), so that you do not come into view again via a search.

5. Purposes and legal bases

We process personal data exclusively for the purposes set out below. For the processing operations in block A we determine the purpose and legal basis ourselves; for the processing operations in block B we act on the instructions and on the legal basis of the employer-client.

A. Processing operations for which Applyfin is the controller

  • Entering into and performing agreements with our clients and providing the platform and our services (Article 6(1)(b) GDPR);

  • Client management, invoicing and accounts receivable management, on the basis of contract and legal obligation (Article 6(1)(b) and (c) GDPR);

  • Maintaining the suppression list, so that an objection raised by you is given lasting effect across all of our clients (Article 6(1)(f) GDPR). Our legitimate interest, and yours as a data subject, is that your objection also works for searches by other employers. For this we retain only a hash value and no readable personal data (see 3.3);

  • Product improvement, security and fraud prevention, including system and security logs, on the basis of legitimate interest (Article 6(1)(f) GDPR);

  • Marketing communication towards existing clients and prospects who have given consent for this or for whom a legitimate interest exists (Article 6(1)(a) or (f) GDPR); you can unsubscribe at any time;

  • Compliance with legal obligations such as tax retention obligations (Article 6(1)(c) GDPR).

B. Processing operations for which our client is the controller (Applyfin as processor)

For the purposes below, the employer-client determines the purpose and legal basis; we process exclusively on its instructions. The legal bases stated are those that the employer usually relies on.

  • Receiving, assessing and managing applications for the purpose of filling vacancies, usually on the basis of the performance or preparation of an employment contract or consent (Article 6(1)(b) or (a) GDPR);

  • Carrying out searches and compiling a shortlist for a specific vacancy (see 3.5), on the basis of the employer’s legitimate interest in filling that vacancy (Article 6(1)(f) GDPR). In doing so, the employer weighs the professional nature of the data and the limited use for one specific vacancy against the data subject’s interest in privacy and being left undisturbed. Personal contact details, including a mobile number, are enriched only where business contact details are lacking and a specific approach follows;

  • Approaching candidates and the communication between candidate and employer in the context of an ongoing procedure, on the employer’s legal basis. The first message complies with the duty to inform under Article 14 GDPR (see 4.9);

  • Requesting and processing references named by an applicant or candidate (see 3.7), on the employer’s legal basis;

  • Managing the client-specific talent pool, usually on the basis of the candidate’s consent (Article 6(1)(a) GDPR).

6. Retention periods

We do not retain personal data for longer than necessary. For the processing operations in block A we determine the retention period; for the processing operations in block B the employer does so as controller.

A. Processing operations for which Applyfin is the controller

  • Prospect data: up to 24 months after the last point of contact, unless you unsubscribe earlier;

  • Data of clients and their users: for the term of the agreement and thereafter in accordance with the statutory retention periods (including a tax retention obligation of 7 years for financial data);

  • Suppression list: for an indefinite period, for as long as this is necessary to continue giving effect to your objection. The list contains only a hash value and the date of inclusion; you can ask us to remove that entry, with the result that you may appear in search results again;

  • Logging and security logs: a maximum of 12 months, unless longer retention is necessary in the context of an incident or a legal obligation.

B. Processing operations for which our client is the controller (Applyfin as processor)

As controller, the employer determines the retention period for applicants, shortlisted candidates, referees and talent pool participants. If the employer does not apply its own period, the standard periods in Article 13.2 of the data processing agreement we have concluded with it apply:

  • applicant data: four weeks after completion of the procedure, or one year if the data subject has consented to this;

  • shortlisted candidates who are not approached: a maximum of one month after placement on the shortlist;

  • shortlisted candidates who have been approached and have not responded: a maximum of six months after the first moment of approach;

  • talent pool participants: a maximum of two years after the last contact or the last update, with a reconfirmation moment before the end of that period.

If you wish to know which period applies to your data, you can request this from the employer concerned; we support the employer in this.

Irrespective of the employer’s instructions, two fixed periods apply: results of a search that are not shortlisted are erased from the cache after a maximum of thirty minutes (see 3.5), and shortlisted candidates who are not approached within one month are deleted or anonymised (see 4.9). We do not carry out an instruction to extend that last period, because it is incompatible with the duty to inform under Article 14(3) GDPR.

Upon expiry of the agreement with an employer, we erase the personal data processed on its behalf, or return it to the employer, at its choice. Copies in back-ups are deleted upon expiry of the regular back-up retention period (see 8.3) and, until that moment, are accessible exclusively for recovery following an incident.

7. Sharing, sub-processors and international transfers

We share personal data with third parties only where this is necessary for the performance of our services, at your request, or where we are legally obliged to do so. With all parties engaged we conclude agreements that comply with Article 28 GDPR.

A. Processors we engage for our own processing operations (Applyfin as controller)

For the processing operations for which we are the controller ourselves, we engage processors on the basis of a data processing agreement, including for:

  • Cloud hosting and infrastructure within the EEA (our global database and corporate website);

  • Payment and collection service providers;

  • Email, communication and notification services for our own communication;

  • Analytics and monitoring tools for applyfin.com.

B. Sub-processors we engage for processing operations on behalf of our clients (Applyfin as processor)

For the processing operations that we carry out on behalf of our clients, we engage sub-processors with the client’s authorisation and under the terms of the data processing agreement (Article 28(2) and (4) GDPR). The procedure for changing sub-processors is laid down in the data processing agreement. These include:

  • Cloud hosting and infrastructure within the EEA for the segregated client environments;

  • The Data Supplier that we query at an employer’s search request (see 4.5);

  • Email and notification services for the purposes of candidate communication;

  • Job distribution partners (where a client chooses to publish vacancies via external channels).

A current overview of our processors and sub-processors is available to our clients on request.

International transfers (both roles). Our primary infrastructure is hosted within the European Union (Germany). Transfers of personal data to a country outside the European Economic Area take place exclusively on the documented instructions of the employer, on the basis of a legal obligation, or because we engage a sub-processor that processes data outside the EEA. In all cases this is done with appropriate safeguards as referred to in Chapter V GDPR, such as the European Commission’s Standard Contractual Clauses or an adequacy decision, supplemented where necessary with additional organisational and technical measures. When announcing a new sub-processor, we state whether it processes data outside the EEA and on what basis.

8. Security — ISO 27001

Applyfin uses the ISO 27001 framework as a guide for the design of its Information Security Management System (ISMS). At the time of publication of this statement we are ISO 27001 ready: our platform, our processes and our policies meet the requirements of the standard, although we are not yet formally certified.

8.1 Core principles for information security. We organise our work on the basis of the three core principles of information security:

  • Confidentiality — data is accessible exclusively to those who are authorised to access it;

  • Integrity — data is accurate, complete and is not modified without authorisation;

  • Availability — data and systems are available when authorised users need them.

8.2 Multi-tenant architecture and data isolation. The Applyfin platform is built according to a multi-tenant architecture. Although the platform is offered from a single codebase, each client’s data is stored in strict logical and physical separation:

  • Separate database per client. Every client environment has its own, isolated database. Client A’s data is not visible or retrievable for client B, and vice versa.

  • Environment-bound access. Every logged-in user and every API call is bound at infrastructure level to one specific client environment. Cross-environment access is technically excluded.

  • Encrypted separation of back-ups. Back-ups are created separately per client environment and stored in encrypted form.

  • No marketing or analytics exchange between clients. One client’s data is never shared with, disclosed to, or used for the marketing or analytics purposes of another client.

  • No cross-client AI training. AI models deployed within the platform are not trained on client data aggregated across client environments. Training data originates from sources for which we have a valid legal basis ourselves, or — where applicable — from data explicitly made available by a client exclusively for the purposes of that specific client.

Two processing operations lie by their nature outside the client environment and therefore fall outside the isolation described above: the temporary cache of search results (see 3.5) and the suppression list (see 3.3). The cache contains only results of an ongoing search by the employer concerned and no data from a client environment; the suppression list contains only hash values and inclusion dates. Neither is used for the purposes of another client.

This architecture ensures that applicants of employer A do not come into view at employer B via Applyfin, and that clients have no insight into one another’s recruitment data, user accounts or statistics.

8.3 Technical and organisational measures. In addition to the architectural separation, we take the following measures, among others:

Technical measures. Encryption of data in transit (TLS 1.3+) and at rest; hardened infrastructure and network segmentation; automated patch management; verified and encrypted back-ups with a regular retention of a maximum of 35 days; central logging and monitoring with alerting on anomalous behaviour; protection against common attack types as described in the OWASP Top 10; periodic vulnerability scans and penetration tests.

Organisational measures. Access policy based on least privilege and need-to-know; multi-factor authentication for staff with access to production; formal risk management process and periodic risk assessments; information security policy and associated procedures; confidentiality obligations and screening of staff; security awareness training; supplier assessments before and during cooperation; defined incident response and business continuity procedures.

Continuous improvement. We periodically evaluate and update our security policy and our measures on the basis of risk analyses, audits, lessons learned from incidents and developments in the threat landscape. Updates do not lower the level of security.

8.4 Data breaches and incident management. For processing operations for which Applyfin is itself the controller, we report a notifiable data breach within 72 hours to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and, where applicable, to data subjects (Articles 33 and 34 GDPR). For processing operations that we carry out on behalf of a client, we inform that client without undue delay and at the latest within 24 hours of becoming aware; the notification to the Dutch Data Protection Authority is for the client as controller.

9. AI applications — EU AI Act

We recognise that AI systems deployed within recruitment and selection qualify under the EU AI Act (Regulation (EU) 2024/1689) as high-risk AI systems within the meaning of Annex III, point 4. We take a restrained and transparent approach to the deployment of AI within the Applyfin platform and the associated RPO services, and design our processes around the requirements that the AI Act imposes on providers and deployers.

9.1 Where AI is deployed within the platform. AI functionality can be used within the Applyfin platform to support, among other things, matching between vacancies and candidates, pre-selection and analysis of application documents, drafting messages to candidates, and summarising interactions. This functionality is switched on or off by our clients at their own discretion; upon activation, clients are made aware of their obligations as a deployer under the AI Act.

9.2 No fully automated decision-making about candidates. We do not take decisions with legal effects or similarly significant effects for a candidate solely on the basis of automated processing. AI outputs such as scores, rankings or recommendations serve to support the recruiter and never constitute a final decision. Every rejection, invitation or comparable decision requires human assessment and confirmation.

9.3 Human oversight (Article 14 AI Act). Our AI functionality is designed so that recruiters can open, assess and overrule AI outputs; so that the reasoning behind a recommendation is made transparent in broad terms; so that recruiters must record their decision independently and not merely by confirming an AI recommendation; and so that AI functionality can be switched off per client, per user or for specific job types.

9.4 Transparency towards candidates (Articles 13, 50 and 86 AI Act). If, as a candidate, you enter a procedure in which AI support is used by the employer, you will be informed of this. You have the right to:

  • Know that AI has been deployed in the assessment of your candidacy and in what way;

  • Receive information about the main logic and the possible consequences of that processing;

  • Request a human review of a decision taken partly on the basis of AI support;

  • Express your point of view and contest the decision;

  • Be informed when you communicate directly with an AI system, such as a chatbot or automated assistant.

You can exercise these rights via the employer in whose procedure you are involved. We support our clients in handling such requests correctly and in good time.

9.5 Data governance and bias mitigation (Article 10 AI Act). We apply a data quality policy for the data on which our AI functionality is developed, validated and tested. We actively aim to detect and mitigate possible bias — on grounds including gender, age, ethnicity or disability — through the selection of representative data, periodic evaluation of model outputs, and the exclusion of protected characteristics as direct or indirect determinants in decision-making models. Training and validation data is not aggregated across client environments; see also 8.2.

9.6 Our role and that of our clients under the AI Act. We act as the provider of AI systems within the platform. Our clients are the deployer when they use this AI functionality within their recruitment process. Both roles carry their own obligations, including registration, monitoring, logging and information to data subjects. We assign these responsibilities explicitly in our documentation and contractual arrangements with clients.

9.7 Prohibited applications (Article 5 AI Act). We do not deploy AI for emotion recognition in the workplace or during job interviews, for social scoring, or for inferring special categories of personal data from biometric data. Clients are not permitted to deploy the platform for such applications.

9.8 Logging and traceability (Article 12 AI Act). The deployment of AI functionality within the platform is logged automatically, in such a way that it can subsequently be traced when and how AI contributed to a process. These logs are available to our clients to substantiate their own AI Act accountability.

10. Your rights as a data subject

Under the GDPR you have the following rights:

  • The right of access to your personal data;

  • The right to rectification of inaccurate or incomplete data;

  • The right to erasure (“the right to be forgotten”);

  • The right to restriction of processing;

  • The right to data portability;

  • The right to object to processing based on a legitimate interest or for direct marketing;

  • The right to withdraw consent previously given;

  • The right to lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).

You can submit a request via the contact details at the bottom of this statement. If you are an applicant, referee or shortlisted candidate and your request relates to data stored within the environment of a specific employer, you should address that employer; the employer is the controller for that data. If your request reaches us directly, we will forward it to the employer without delay and support the employer in handling it in a timely and correct manner.

If you have been approached following an employer’s search, you have the right at all times to object to further processing and to request not to be approached again. We will then delete your data and record a hash value in our suppression list (see 3.3), so that you no longer come into view in searches by other employers either. This use of the suppression list is without prejudice to the employer’s assessment of your objection. On request, we will also share the source from which your data was obtained.

If you request access to or portability of your own personal data, we will also provide the profile fields that we obtain under licence from the Data Supplier. Those fields are subject to a licence restriction that does not permit disclosure to third parties, but that restriction does not apply as against you as the data subject.

11. Changes to this policy

We may amend this Privacy and Information Security Policy from time to time to reflect changes in our services, laws and regulations or security practices. We announce material changes in advance via the platform or by email. We recommend that you consult this page periodically.

12. Contact

Applyfin B.V. Wittevrouwenstraat 38B, 3512 CV Utrecht info@applyfin.com — +31 85 078 6002

For privacy and security-related questions, you can contact us at privacy@applyfin.com.