Version 2.0, effective April 2026

AI Transparency Notice

This notice addresses EU AI Act, UK DUAA 2025, GDPR Article 13(2)(f), India DPDP Act 2023, Illinois AI Employment Law, and equivalent global transparency requirements.

1. Classification: EU AI Act Risk Assessment

Candoora has assessed its AI systems against the EU AI Act. Candoora’s AI serves candidates exclusively. No employer or recruiter accesses Candoora AI outputs, and Candoora does not influence employer hiring decisions. Candoora’s systems are classified as General Purpose AI applications, not high-risk employment AI systems.

Fit Scorecard

Visible only to the candidate. It informs the candidate’s own decision whether to apply and does not flow to employers.

Seniority analysis

Advises the candidate on self-presentation. Employers receive no input from Candoora.

ATS simulation

Simulates how a resume may be parsed before submission. Candoora has no relationship with employer ATS systems.

Annual review

Risk classification is reviewed annually and will be updated if employer-facing features are developed.

2. Complete AI Systems Inventory

SystemInputOutputModelLegal effect / override
Resume ParserCV filesStructured skills, roles, and tenuresAnthropic Claude API plus NLP pipelineNo. User can edit profile data.
Fit ScorecardParsed profile and job listingMatch score, dimension scores, and Gap ClosersVector embeddings, Pinecone, and rule-based scoringNo. Advisory only.
ATS SimulatorResume contentReadability scores and formatting risksRules-based parser, no LLMNo. User controls all changes.
Seniority AnalyserResume language and structureSeniority classification and suggested reframingAnthropic Claude APINo. Accept, edit, or reject per suggestion.
Bullet RewriterIndividual resume bulletsSuggested rewrites at appropriate seniority registerAnthropic Claude APINo. No auto-apply.
Interview Prep QGenStory assets, role type, and companyTailored practice questionsAnthropic Claude APINo. User controls session.
STAR ScorerPractice answerDimension scores and written feedbackAnthropic Claude APINo. Practice feedback only.
Insider IntelCompany name and public sourcesPre-interview briefingAnthropic Claude API plus web scrapingNo. Advisory and labelled AI-generated.
Referral DrafterContact, company, and job contextWarm intro message draftAnthropic Claude APINo. User must review and explicitly send.

3. What Candoora’s AI Never Does

Makes hiring, rejection, or shortlisting decisions for any employer.
Shares user data with any employer, recruiter, or company without explicit user direction.
Sends communications automatically on behalf of users.
Takes consequential action without explicit user confirmation.
Processes biometric data, voice data, or video in the current platform.
Uses identifiable user data to train AI models.
Scores or penalises users based on special category personal data.

4. Bias Mitigation and Fairness

  • Annual bias audits of Fit Scorecard and ATS simulation models, with results reviewed by the DPO.
  • Special category personal data in a CV is not extracted, scored, or used in analysis.
  • Scoring dimensions are limited to skills, experience, domain, culture alignment, and logistics, not identity characteristics.
  • Illinois AI Employment Law non-discrimination standards are applied globally.
  • Users can report biased or inaccurate outputs to fairness@candoora.com.

5. Human Oversight Architecture

Candoora maintains meaningful human oversight through technical architecture, not just policy.

Accept/Edit/Reject framework for every bullet rewrite suggestion.
Explicit send requirement for referral messages. The system cannot auto-send.
AI Preferences toggle so users can disable AI-powered analysis features.
Output labelling so users know what is AI-produced.
Monthly product review of sampled AI outputs for quality and bias issues.
Feedback button on AI outputs, with reports reviewed within 5 business days.

6. Future AI Features

Candoora’s roadmap includes a possible video mock interview feature that may involve voice analysis. Before any such feature launches, Candoora will conduct a DPIA, obtain explicit granular standalone consent, satisfy Illinois BIPA written consent requirements for Illinois users, assess Australian Privacy Act, LGPD, and PDPA requirements, and update this Notice at least 30 days before launch.

7. Model Provider: Anthropic

Candoora uses Anthropic’s Claude API as its primary AI model. Anthropic API policies prohibit use of API-submitted data to train models. Resume and career data submitted through the API does not improve Claude. Anthropic operates as a sub-processor under Candoora’s DPA, and model version changes will be reflected in this AI Transparency Notice.