How ReKPal handles your hiring data: what we access, where it lives, who can see it, and what happens when you leave.
ReKPal reads written interview evidence your team has already created, along with related hiring data from your ATS. Access is read-only and scoped to the roles you enable. ReKPal does not join interviews, does not use meeting bots, and does not record audio or video and does not enrich data from any external sources.
No. ReKPal does not train models on customer or candidate data, and we do not build shared or cross customer models. Our AI processing runs under a commercial agreement with Zero Data Retention terms, meaning content sent for processing is not retained by the provider after a response is returned and is not used to train their models.
We have signed BAAs with third party vendors that we work with. We notify customers in advance of any addition so you have the opportunity to object. We do not sell data or share it outside this list.
Customer data is stored in North American cloud regions. Data is encrypted in transit and at rest using industry-standard encryption, and customer environments are logically separated. Production data is never used in demos, sales materials, or testing.
Access is limited to the people who need it to operate and support the service, granted on a least-privilege basis with individual accounts and multi-factor authentication. Support access to your data happens at your request and with your knowledge. Everyone with access is bound by confidentiality obligations.
You control retention. Data is kept for the period defined in your agreement and can be deleted on request at any time. On termination, we delete or return customer data within 30 days, excluding anything we are required to retain by law, and confirm deletion in writing. Pilots can be set to delete automatically on completion.
Candidate data reaches ReKPal through your ATS, so you remain the controller and ReKPal acts as your processor. When a candidate exercises a right of access, correction, or deletion under GDPR, PIPEDA, CCPA, or similar laws, we act on your instruction within the timelines set out in our data processing agreement. We do not respond to candidate requests independently.
No. ReKPal organizes evidence your panel has already produced. It does not produce a hire or no-hire output. This keeps ReKPal outside the category of automated employment decision tools that carry specific obligations under laws such as New York City Local Law 144, the Illinois AI Video Interview Act, Colorado’s AI legislation, and the EU AI Act.
Not yet, and we would rather say so directly. ReKPal is an early-stage company and SOC 2 Type II is on our roadmap. We operate the controls that underpin it today: encryption in transit and at rest, least-privilege access with multi-factor authentication, logical customer separation, vendor review before any sub processor is added, a written incident response process, and a data processing agreement reviewed by external counsel. We are glad to walk your security team through our posture and complete your questionnaire.
We maintain a written incident response process covering detection, containment, investigation, and notification. If an incident affects your data, we notify you without undue delay and within the timeframe committed in our agreement, then follow up with a written summary once the investigation closes.
Write to rekpal@pbalabsca.com and we will respond within two business days. Our data processing agreement and current sub-processor list are available on request.