← Back to Home
Krinai

GDPR-Compliant Privacy Policy

Last Updated: May 30, 2026

Krinai (“we”, “us”, or “our”) is committed to protecting the privacy of our platform users and applicants. This Privacy Policy details how we collect, process, and protect personal data in compliance with the General Data Protection Regulation (GDPR) and other international data privacy frameworks.

1. Roles under GDPR

Depending on the context of the data collection, Krinai operates in two roles:

  • Data Processor: For data submitted by job applicants through recruiter-defined forms and resumes, Krinai acts as a processor. The recruiter/employer acts as the Data Controller.
  • Data Controller: For account details, billing logs, and administrative settings of recruiters, Krinai acts as the Data Controller.

2. Information We Process

As a processor, we process candidate details submitted on behalf of controllers:

  • Candidate identity (name, email, phone number)
  • Files and resumes (CV uploads, portfolio links)
  • Form answers, MCQ choices, and open-ended text answers

As a controller, we collect:

  • Recruiter name, work email, hashed passwords
  • Subscription data, Lemon Squeezy order references, billing history
  • Audit trails (IP addresses, login timestamps, device user-agents)

3. Purpose and Legal Basis

We process recruiter details under the legal basis of contractual necessity (billing and accounts) and legitimate interest (security auditing). Candidates' details are processed based on the Controller's recruitment requirements and candidate consent.

4. Data Retention & Erasure (GDPR Rights)

Under our commitment to GDPR, we provide tools for:

  • Automated Purges: Controllers can set data retention periods from 90 days to 7 years. Candidate details are permanently hard-deleted from database and MinIO storage once the limit expires.
  • PII Erasure: Controllers can request immediate candidate anonymisation. This nullifies candidate name, email, phone, deletes resume files, and logs the action in the GDPR erasure audit trail.
  • Data Portability: Recruiter dashboard allows downloading all candidate data as CSV/JSON, or downloading resume structures in a ZIP archive.

5. Subprocessors

We engage the following subprocessors to host infrastructure and process payments:

  • Supabase / PostgreSQL: Database hosting (managed instances)
  • MinIO / Redis: Local storage and cache queues
  • Lemon Squeezy: Payment gateways and billing

6. Contact Us

If you have any questions regarding this policy or wish to exercise your GDPR rights, contact our Data Protection Officer at privacy@krinai.io.