Last updated: 19 August 2026. This statement explains how HRBlade uses artificial intelligence in hiring, what data those functions read, where that data is processed, and what controls you and your candidates have. It is written to answer the questions an EU customer needs answered under Regulation (EU) 2024/1689 (the AI Act) and Regulation (EU) 2016/679 (the GDPR), without requiring an NDA.
The provider of the HRBlade platform for the European Union is AMISCON GLOBAL S.L., NIF B70862099, Valencia, Spain. Contact: info@hrblade.com.
Some of this matters more than the rest, so it goes first.
HRBlade uses large language models through vendor APIs. The models are general-purpose commercial models; we do not build or train our own. Each function takes a defined input, returns a defined output, and writes that output to the application record where a recruiter can see it.
Reads the text of a CV and the structured profile fields, compares them against the vacancy title, description and requirements, and returns a score from 0 to 100 with a breakdown by experience, skills and education, plus matched and missing skills and a short written summary. The score is advisory. It ranks and highlights; it does not decide.
Reads the transcript of each answer together with the question that was asked, and returns a score from 0 to 100 with sub-scores for relevance, depth and clarity, plus a list of strengths and weaknesses. Scores for individual answers are averaged into an application-level score.
Reads all answers and their individual analyses and produces a written summary for the recruiter, plus a score per competency where the vacancy defines competencies.
Converts recorded answers and call recordings into text. This is transcription only. No properties of the voice itself are retained or assessed.
Converts candidate profiles into numerical vectors so that recruiters can search the talent pool in natural language and find similar candidates. This surfaces candidates for a human to look at.
An AI agent conducts a structured telephone interview using questions the customer has defined. The agent states that it is an AI at the start of every call, in the language of the call, and this disclosure cannot be switched off or edited away by the customer. If the candidate asks whether they are speaking to a person, the agent answers plainly that it is an AI.
Estimates whether a written answer was produced by a generative model. This is a signal for the recruiter, not a verdict, and it is not used to reject anyone automatically.
Adaptive cognitive assessments are scored by a deterministic psychometric engine, not by a language model.
Depending on which functions the customer has enabled, the following may be sent to the model vendor for processing:
Audio is sent for transcription only where server-side transcription is in use. See section 4.
We do not collect gender, date of birth, age, nationality, ethnicity, religion, disability, marital status or any other special category of data as structured fields, and we do not ask candidates for them. Where a CV happens to contain such information in its free text, it reaches the model as part of that text. The scoring prompts instruct the model to disregard name, gender, age, origin and employment gaps, and this is one of the things bias testing checks (section 5).
No. Candidate data is not used to train, fine-tune, or otherwise improve any model. We use vendor APIs under terms that exclude API inputs and outputs from model training. We do not build models of our own, we do not maintain training datasets of candidate data, and no candidate data is shared with any vendor for any purpose other than returning the result of the specific request.
For customers served by AMISCON GLOBAL S.L., all customer and candidate data is stored in the European Union. The application servers, the database, the search index, the vector store and the object storage holding CVs, recordings and attachments are all located in Amsterdam, the Netherlands.
The speech-to-text engine runs on our own infrastructure in the same location and is the default for interview transcription, which means interview audio is not sent to any third party. The vector database and the search index are likewise self-hosted.
Text sent for analysis is processed by our AI model vendor. Where that processing takes place outside the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses (Decision 2021/914) together with a transfer impact assessment, and, where the vendor is certified, by the EU-US Data Privacy Framework. We are moving inference for European customers onto EU-resident model endpoints; customers who require this contractually today should raise it with us and we will confirm the current status for their tenant in writing.
The current list of sub-processors, with the role and jurisdiction of each, is available on request at info@hrblade.com and is provided as part of our Data Processing Agreement. We notify customers before adding a sub-processor that processes candidate data.
Because we deliberately do not collect demographic data, we cannot compute selection rates by protected group from our own records, and inferring protected characteristics in order to test would itself create a new category of sensitive processing. We therefore test by controlled comparison, which is the method best suited to a system of this kind.
The method: a fixed set of candidate profiles is built so that the profiles are identical in qualifications and differ in exactly one signal at a time. The signals varied are the ones known to carry bias in hiring, including forename as a proxy for gender and ethnicity, age markers such as graduation year, gaps in employment history, and non-native phrasing. Each variant is run through the same scoring path a real candidate would take, and we measure:
The audit runs on a scheduled basis and again whenever the underlying model, a scoring prompt or a threshold changes. Findings are remediated before the change ships. AI-authorship detection is included in the audit, because that class of tool is known to misfire on non-native speakers.
Where a customer collects voluntary self-identification data from candidates and asks us to analyse real outcomes, we can do so on their data. In that case we report the proportion of records with missing demographic data and the range the impact ratio could take across that missing data, because an impact ratio quoted without its missing-data range can be misleading.
A summary of the most recent audit is available to customers and prospective customers on request.
Every AI-influenced decision about a candidate is written to a decision log that records what kind of decision it was, which feature and which model produced it, the score, the threshold that applied, the rule that fired, the outcome, and whether a person reviewed it and who. The log stores a cryptographic digest of the assessed material rather than the material itself, so the record survives erasure of the candidate's personal data. This is what a customer uses to answer a candidate who asks why a decision was taken, and what a supervisory authority would be shown.
Default retention periods, all configurable per customer:
Deletion runs automatically on a daily schedule. Erasure requests are processed on a daily schedule and remove the CV, transcripts, AI analyses, scores, embeddings and vectors, not only the profile row.
Yes, and at more than one level.
Under the AI Act, HRBlade is the provider of the AI system and the customer who uses it to hire is the deployer. Under the GDPR, the customer is the controller of candidate data and HRBlade is a processor. The obligations split accordingly.
Ours: designing the system so that human oversight is possible and effective, data governance and bias testing, technical documentation, logging, accuracy and robustness, instructions for use, security, notifying customers of material changes, and reporting serious incidents.
The customer's: using the system according to our instructions, assigning oversight to people who have the competence, authority and time to exercise it, ensuring the input data they control is relevant, monitoring operation, keeping their own logs, informing candidates and, in most European jurisdictions, informing employee representatives before putting the system into service. In Spain, Article 64.4.d of the Workers' Statute gives works councils a right to be informed of the parameters, rules and instructions on which algorithms affecting access to employment are based, including profiling; we provide a document written for that purpose on request.
Regulation (EU) 2026/1744 moved the application of the AI Act's high-risk obligations for standalone Annex III systems from 2 August 2026 to 2 December 2027. The transparency obligations in Article 50 were not deferred and have applied since 2 August 2026; the prohibitions in Article 5 have applied since 2 February 2025. We comply with what is in force today and are building towards the December 2027 regime. We class our screening, ranking and evaluation features as high-risk under Annex III point 4 and do not seek to rely on the Article 6(3) exemption, because that exemption is unavailable to any system that performs profiling.
We provide the documentation expected of a provider under the AI Act and the GDPR to customers and prospective customers on request, including what a deployer needs in order to meet its own obligations. Write to info@hrblade.com and tell us what your legal or procurement team needs, and we will send the relevant documents.
Changes to which model a function uses, and to scoring logic, are recorded and dated. We publish a model changelog and notify affected customers in advance of any change that could materially affect scoring behaviour, with at least 30 days' notice, so that a customer can re-run their own validation before the change takes effect. Every such change triggers the bias audit described in section 5 before it ships.
Candidates are told, before an interview and when they apply, that AI is used, what it does, and that a person makes the hiring decision. A candidate may ask for a human review of a decision and for an explanation of how their answers were assessed. Requests reach the customer, who is the controller, and we provide the underlying decision record so the customer can answer. Candidates may also request access to, correction of, or erasure of their data.
Questions about this statement, requests for any document listed in section 9, or any concern about how an AI function has behaved: info@hrblade.com.