Status — read first
AI-assisted best-effort draft · not legal advice · not lawyer-reviewed.
This document was drafted with AI assistance as a best-effort starting point. No licensed attorney has reviewed, approved, or certified it, and it is not safe to rely on as a binding or compliant document. A qualified attorney in each operating jurisdiction must review and finish it before it is published or enforced. Nothing here claims an audit, certification, corporate registration, or executed contract that has actually happened.
A qualified privacy lawyer must adapt this to each jurisdiction (GDPR, UK GDPR, CCPA/CPRA, PIPEDA, and the US biometric statutes) and confirm every factual claim before it goes live. Several claims below are marked “verify” because they depend on how the running system and vendor contracts are actually configured — do not publish an unverified one.
0. What still has to be confirmed before this is fully enforceable
- The controller identity is now named; the registration detail is not. The controller is Vettika, a service operated by Nexprove (Nexprove operates the Service). GDPR Art. 13/14 and CCPA both also require a way to reach the controller and, in practice, a registered form and address. Counsel confirms Nexprove's corporate form, its incorporation jurisdiction, its registration number, and a real registered postal address, and inserts them in §1. Nothing here should be read as asserting a specific corporate form or number until then.
- An EU/UK Article 27 representative. If Vettika offers interviews to candidates in the EU or UK and has no establishment there, an Art. 27 representative is mandatory now, not later. Appoint or contract one, or geo-gate EU/UK candidates off until you do.
- One retention number. The number in §7 must match the DPA, the retention schedule, and every retention line on the site.
- The audio claim. Do not publish “we never store audio” until engineering confirms whether LiveKit egress actually records. See §7.
- Biometric analysis. Voice audio can be a biometric identifier under Illinois BIPA, Texas CUBI, Washington's My Health My Data Act, and GDPR Art. 9. Counsel must run that analysis and decide whether a BIPA-style written-consent flow is needed. See §3.
1. Who we are
Vettika, a service operated by Nexprove (“we”, “us”) runs a voice-AI service that conducts first-round screening interviews for recruiters. Nexprove is the operator behind the product. We provide the Service across two domains we operate — vettika.com and airecruiter.nexprove.com — and this policy applies identically on both. Registered corporate form, incorporation jurisdiction, registration number, and registered postal address are to be confirmed and inserted by counsel (see §0). Privacy contact: support@vettika.com (a dedicated privacy@ mailbox should be provisioned and routed here). EU/UK Article 27 representative: to be appointed — see §0.
2. Our role
For candidate personal data, the recruiter who runs the campaign is the controller and Vettika is the processor acting on their instructions. For recruiter account data, Vettika is the controller. This is the single role model, and the Terms, the DPA, and the AI-compliance page all state it the same way.
3. What we collect
| Category | Examples | Source | Typical lawful basis (GDPR) |
|---|---|---|---|
| Identity | Name, email | Candidate via apply form, or recruiter import | Contract (Art. 6(1)(b)) / consent (Art. 6(1)(a)) |
| Application data | Resume URL, portfolio URL, free-text answers | Candidate | Contract / consent |
| Interview audio | The candidate's voice during the AI interview | Candidate microphone during the call | Explicit consent (Art. 6(1)(a)) — see the biometric note |
| Interview transcript | Speech-to-text of the interview | Deepgram (STT subprocessor) | Same basis as the audio |
| AI scoring | Rubric scores and rationale | Google Gemini (LLM subprocessor) | Same basis as the audio |
| Account data | OAuth identifier, session data (recruiters) | Better Auth | Contract |
| Security data | IP, device fingerprint for new-device alerts | Login flow | Legitimate interest / legal obligation |
| Telemetry | Cookies, IP, user agent | See the cookie inventory | Consent, where analytics is actually running — verify |
We collect the same categories however you reach the Service (vettika.com and airecruiter.nexprove.com). We do not knowingly collect more than we need to run the interview, produce the report, and operate the recruiter account.
Biometric note (counsel-led). A voice recording, and any voiceprint derived from it, may qualify as biometric information under Illinois BIPA, Texas CUBI, Washington law, and GDPR Art. 9. Vettika does not intentionally build voiceprints or run voice-based identification. That does not settle the legal question. Counsel must analyze whether the audio itself is biometric in each state, and design a written-consent flow if the answer is yes. This policy will not claim “we do not collect biometric data” until that analysis is done.
4. Special-category data
A transcript can incidentally capture special-category data (Art. 9) if a candidate volunteers something about health, religion, and the like. We do not ask for it, and the interviewer is instructed not to pursue it. Where it is transcribed anyway, we rely on the candidate's explicit consent. Counsel to confirm whether the employment-context basis (Art. 9(2)(b)) also applies.
5. How we use it
- Run the interview the candidate agreed to.
- Show the results to the recruiter who started the campaign.
- Run the recruiter's account, billing, and security.
- Detect and prevent abuse, fraud, and misuse of the Service.
- Meet legal obligations (record-keeping, lawful requests).
We do not sell personal data, and we do not “share” it for cross-context behavioral advertising as CCPA/CPRA defines those terms. We do not train foundation models on candidate data. Where a subprocessor supports a zero-data-retention configuration, we intend to use it — but treat that as a target, not a proven fact, until the contract with each provider is confirmed. We do not assert provider-specific zero-retention publicly before it is verified in writing.
6. Automated processing and human review
The Service produces an AI score and rationale to support a recruiter's decision. It is decision-support, not an automated hiring decision: a qualified human recruiter reviews every AI Output before any hiring step, and you can ask for human review of, and an explanation of, any AI Output that affects you (GDPR Art. 22). A candidate may also request a non-AI alternative to the AI interview. The honest status of the underlying AI-Act obligations is on the AI-compliance page.
7. Subprocessors
The single canonical list is below, and the Privacy Policy, the DPA, and the Data page all render from it so they cannot drift apart. We give recruiters advance notice before adding a subprocessor, per the DPA.
| Subprocessor | Purpose | Data categories | Processing location | Transfer mechanism | Retention by subprocessor |
|---|---|---|---|---|---|
| Vercel Inc. (US) | Hosting the web app, APIs, and agent runtime | All categories, at request time | US | DPA + EU SCCs — verify executed + capture version/date | Logs ~30 days |
| Neon, a Databricks company (US) | Managed Postgres for application data | All categories, at rest | US, us-east-1 (production). us-east-2 is the separate QA database and holds no production candidate data | DPA + EU SCCs — verify | Per Vettika's retention schedule |
| LiveKit Inc. (US) | Real-time audio transport for the interview | Interview audio | US | DPA + EU SCCs — verify | Egress/recording behavior must be confirmed — see the audio note |
| Deepgram Inc. (US) | Speech-to-text, via LiveKit Inference | Interview audio (streamed) | US | DPA + EU SCCs — verify | Zero-data-retention target — verify contractually |
| Google LLC (US) | Gemini LLM, via LiveKit Inference, for interviewer dialog and scoring | Transcript snippets, scoring context | US | DPA + EU SCCs — verify | Zero-data-retention target — verify contractually |
| Cartesia Inc. (US) | Text-to-speech for the interviewer voice | Interview turn text (no identity) | US | DPA + EU SCCs — verify | Zero-data-retention target — verify |
| Resend (US) | Transactional email | Recipient email, subject, body | US | DPA + EU SCCs — verify | ~30 days in dispatch logs |
| Upstash Inc. (US) | Rate-limiting store (Redis) | IP and token hashes for rate limits | US | DPA + EU SCCs — verify | Short-lived rate-limit keys |
| Cloudflare Inc. (US) | Turnstile bot/abuse check on auth forms | IP, challenge token | US | DPA + EU SCCs — verify | Per Cloudflare policy |
| Google LLC (OAuth) | Recruiter "Sign in with Google" | Recruiter identity, email, OAuth token | US | DPA + EU SCCs — verify | Token lifetime |
| Have I Been Pwned (HIBP) | Breached-password check at signup | k-anonymized password hash prefix only (no email, no full password) | US/UK | Assess — likely not a personal-data processor given k-anonymity; counsel to confirm | None retained by Vettika's use |
| Stripe Inc. (US) | Recruiter payment processing | Recruiter billing identity, payment metadata | US | DPA + EU SCCs — verify | Per Stripe policy |
| Polar Software Inc. (US) | Alternative billing surface where used | Recruiter billing identity | US | DPA + EU SCCs — verify | Per Polar policy |
Error tracking (Sentry or similar) is not selected. No vendor is listed here until one is actually in use. Vettika gives recruiter customers 30 days' advance notice before adding or replacing a subprocessor; a recruiter who objects may terminate per the DPA.
8. Retention
One number, everywhere. Interview audio (to the extent any is stored), transcript, and AI scoring are kept for 12 months from interview completion, then deleted, unless the candidate is hired — in which case the recruiter's own retention obligations take over. The candidate identity row is kept for 12 months from the last interaction. The full schedule, and the statutory floors and ceilings behind these numbers, are on the Data Handling page, which is the source every other page cites.
The model is retain-by-default via soft-delete plus right-to-erasure on request. A deletion removes the personal content and marks the record deleted, but a non-personal shell is kept briefly so hiring totals and quota counts stay accurate; that shell is hard-deleted within 30 days. When you exercise your right to erasure, the personal fields — name, email, phone, transcript, and AI report — are scrubbed immediately.
How deletion works today — and the two items counsel should still confirm
- Deletion mechanics (built). The model is retain-by-default via soft-delete plus right-to-erasure on request. Tombstone columns (
dataDeletedAt,deletedAt) exist, and a nightly retention job (/api/cron/retention-prune) enforces the schedule: candidate personal data untouched for 12 months is scrubbed automatically, and each scrubbed tombstone is hard-deleted within 30 days. On an explicit erasure request — candidate self-service via the invite link, or the recruiter acting for their own candidate — the personal fields (name, email, phone, transcript, AI report, recruiter notes) are scrubbed immediately across the candidate and interview rows, while non-personal counts are kept so quota and funnel totals stay accurate. The only deletion feature still not built is the optional “signed deletion receipt” some earlier drafts described; counsel confirms this schedule meets each statutory floor before it is relied on. - Audio. Whether any audio file persists depends on the LiveKit egress configuration, which engineering has not confirmed. We do not claim “we never store audio” until that is verified. If egress records, the audio retention row applies and the claim must change.
9. Your rights
Depending on where you live (GDPR Art. 15–22, CCPA/CPRA, and similar laws), you can ask to access, correct, delete, or export your data, object to or restrict processing, and withdraw consent. Withdrawing recording consent mid-interview ends the interview. A human recruiter reviews every AI recommendation before any hiring decision, and you can ask for human review of any AI Output that affects you. You can also complain to your supervisory authority (your local DPA in the EU, the ICO in the UK, the CPPA in California). We do not discriminate against you for exercising any of these rights.
Candidate self-service: export and deletion run through the token links in your invite email. Recruiter self-service: your account settings. For candidate data we hold on a recruiter's behalf, we route your request to that recruiter as the controller, who can erase your personal data on request; we tell you when we have done so. Counsel confirms the response deadlines and that the endpoints actually fulfill each right.
10. International transfers
Data may be processed in the United States and the EU. Both service domains (vettika.com and airecruiter.nexprove.com) are operated from the same infrastructure described on the Data Handling page. EU/UK transfers rely on the EU Standard Contractual Clauses (2021/914) with the UK Addendum where relevant. Counsel confirms the transfer impact assessment is on file and that the SCC module selection is correct.
11. Children
The Service is not for anyone under 16. Do not apply on behalf of a minor.
12. Security
TLS in transit, encryption at rest for the database, least-privilege access, audit logging, and a vulnerability contact at /.well-known/security.txt. Incident handling follows the breach-response runbook, and we notify affected controllers of a personal data breach without undue delay and no later than 72 hours after becoming aware. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security, and penetration testing is planned, not yet completed, and is not represented as done.
13. Changes and contact
We tell recruiters by email and candidates via the apply-page banner at least 30 days before a material change, and every version carries an effective date. Contact: support@vettika.com. Registered address and the Art. 27 representative go here once counsel confirms them (see §0).